Czech Republic Position paper on the application of international law in cyberspace
14. Therefore, assessed on a case-by-case approach and taking into account specific circumstances of
the case, intervention in the internal or external affairs of the Czech Republic by cyber means may
constitute a violation of the prohibition of intervention.
Due Diligence
15. Due diligence stems from a general international law principle that States must ensure that
territory and objects over which they enjoy sovereignty are not used to harm the rights of other
States. Due diligence entails that “it is every State’s obligation not to allow knowingly its territory
to be used for acts contrary to the rights of other States.”13 Thus, in the cyber domain, due diligence
requires States to take all reasonable and feasible measures concerning activities in cyberspace
falling under their jurisdiction in order to prevent, eliminate or mitigate potentially significant harm
to legally protected interests of another State.
16. There exist, to this day, divergent views on the precise normative character, scope, and content of
due diligence in cyberspace. In the opinion of the Czech Republic, due diligence, under the
conditions stated below, may be considered an obligation in its own right.
17. Due diligence equally applies in cyberspace as concluded by the UN GGE in 2015.14 The Czech
Republic is of the view that every State has an obligation to act against unlawful and harmful cyber
activities emanating from or through its territory provided that it is aware of, or should reasonably
be expected to be aware of, such activities. Due diligence applies in particular to activities of
private individuals that violate the rights of other States, when harmful activities cannot be
attributed to a particular State in accordance with the rules governing state responsibility or where
only insufficient proof for such attribution exists.
18. The due diligence obligation is only triggered when the target State suffers serious adverse
consequences. There is no universally accepted threshold of harm in international law and each
case should be evaluated individually. The Czech Republic maintains that such harm does not need
to be necessarily limited to physical damage to objects or physical injuries to persons by cyber
means and could encompass other serious non-physical harm, resulting, for example, from the
interference with or impairment of the use and operation of critical infrastructure. Such situations
could also encompass, for example, malicious activities in cyberspace causing serious adverse
consequences to medical and healthcare facilities in the Czech Republic.15
19. To ensure compliance with the due diligence obligation, States should take measures that may be
reasonably expected, in the given context and circumstances, to act against harmful cyber
activities that violate a right of another State. In procedural terms, due diligence might encompass
a duty to inform and cooperate in the case of transboundary harm. At the same time, the means
13
Corfu Channel Case (United Kingdom v Albania); Merits, International Court of Justice (ICJ), 9 April 1949, Rep
4, p. 22.
14
See para. 13 (c) of the UN GGE 2015 Report.
15
See also The Oxford Statement on the International Law Protections Against Cyber Operations Targeting the
Health Care Sector. Oxford Institute for Ethics, Law and Armed Conflict
6