cyber infrastructures, a State’s exercise of its jurisdiction may have unavoidable and immediate repercussions for the cyber infrastructure of other States.10 While this does not limit a State’s right to exercise its jurisdiction, due regard has to be given to potential adverse effects on third States. By virtue of sovereignty, a State’s political independence is protected and it retains the right to freely choose its political, social, economic and cultural system. Inter alia, a State may generally decide freely which role information and communication technologies should play in its governmental, administrative and adjudicative proceedings. Foreign interference in the conduct of elections of a State may under certain circumstances constitute a breach of sovereignty or, if pursued by means of coercion, of the prohibition of wrongful intervention.11 Moreover, by virtue of its sovereignty, a State may decide freely over its foreign policy also in the field of information and communication technologies.12 Furthermore, a State’s territorial sovereignty is protected. Due to the rootedness of all cyber activities in the actions of human beings using physical infrastructure, cyberspace is not a deterritorialized forum.13 In this regard, Germany underlines that there are no independent ‘cyber borders’ incongruent with a State’s physical borders which would limit or disregard the territorial scope of its sovereignty. Within its borders, a State has the exclusive right – within the framework of international law – to fully exercise its authority, which includes the protection of cyber activities, persons engaging therein as well as cyber infrastructures in the territory of a State against cyber and non-cyber-related interferences attributable to foreign States.14 As a corollary to the rights conferred on States by the rule of territorial sovereignty, States are under an ‘obligation not to allow knowingly their territory to be used for acts contrary to the rights of other States’15 – this generally applies to such use by State and non-State actors. The ‘due diligence principle’, which is widely recognized in international law, is applicable to the cyber context as well and gains particular relevance here because of the vast interconnectedness of cyber systems and infrastructures. Germany agrees with the view that cyber operations attributable to States which violate the sovereignty of another State are contrary to international law.16 In this regard, State sovereignty constitutes a legal norm in its own right and may apply directly as a general norm also in cases in which more specific rules applicable to State behaviour, such as the prohibition of intervention or the use of force, are not applicable. Violations of State 10 11 12 13 14 15 16 For example, restrictive regulatory or enforcement activities regarding important internet nodes in the territory of one State may seriously impair the functioning of networks of other States. See below, at II.b). See Tallinn Manual 2.0 (note 4), rule 3 (‘external sovereignty’). Ibid., rule 1, commentary, para. 5. Ibid., rule 2 with commentary, para. 2. See International Court of Justice (ICJ), Corfu Channel case (United Kingdom of Great Britain and Northern Ireland v. Albania), Judgement of 9 April 1949, I.C.J. Reports 1949, 4, 22; Permanent Court of Arbitration (PCA administering institution), Island of Palmas Case (or Miangas), United States of America v. The Netherlands, Arbitral Award (M. Huber) of 4 April 1928, (1928) II RIAA 829, 839. Cf. Tallinn Manual 2.0 (note 4), rule 4. 3

Select target paragraph3