include the use of a certificate issued by a third party certification authority or service provider, similar in nature to the services provided by notary publics in EAC member states. Due to the critical role of such entities in the security of the process, the legislation will often establish a regulatory framework governing the provision of such services. This framework may include a licensing or accreditation scheme designed to control market entry. In addition, a raft of criteria will be laid down concerning the manner in which the service provider operates, including the attribution of liability in the event of a failure to meet the criteria. Experience of such regimes to date, however, suggests that they are very complex and difficult to implement and operate. As such, they have often proven unable to facilitate secure electronic transactions. The Task Force recommends that Partner States give consideration to granting delegated authority to a specified government ministry or department to adopt relevant secondary regulations concerning digital signatures and the provision of certification services (R.13). The Task Force makes the following additional recommendations in respect of electronic signatures: 2.3 • That Partner States provide for a statutory definition for ‘signatures’ and ‘electronic signatures’ • That Partner States should support the principle of technology neutrality and promote interoperability in respect of ‘electronic signatures’ technologies • That Partner States should identify and recognise internationally standards in relation to the use and operation of electronic signatures • That Partner States should consider the need for an institutional framework to support the provision of certification and related services at both a national and regional level (R.14). Cybercrime Generally legislative initiatives in the area of computer or cybercrime have two distinct objectives. First, there is a need to amend or supplement existing criminal law to reflect the use of ICTs to commit a range of traditional offences or to engage in undesirable acts against ICTs and the data they process. Second, there is a need to reform criminal procedure rules to facilitate the investigation and prosecution of those that engage in criminal acts using or against ICTs by law enforcement agencies. The Task Force recommends that Partner States should undertake reform of their criminal laws to specifically provide for cybercrimes (R. 15). 2.3.1 Substantive offences 14

Select target paragraph3