cyber infrastructures, a State’s exercise of its jurisdiction may have unavoidable and
immediate repercussions for the cyber infrastructure of other States.10 While this does not
limit a State’s right to exercise its jurisdiction, due regard has to be given to potential
adverse effects on third States.
By virtue of sovereignty, a State’s political independence is protected and it retains the right
to freely choose its political, social, economic and cultural system. Inter alia, a State may
generally decide freely which role information and communication technologies should play
in its governmental, administrative and adjudicative proceedings. Foreign interference in the
conduct of elections of a State may under certain circumstances constitute a breach of
sovereignty or, if pursued by means of coercion, of the prohibition of wrongful intervention.11
Moreover, by virtue of its sovereignty, a State may decide freely over its foreign policy also in
the field of information and communication technologies.12
Furthermore, a State’s territorial sovereignty is protected. Due to the rootedness of all
cyber activities in the actions of human beings using physical infrastructure, cyberspace is
not a deterritorialized forum.13 In this regard, Germany underlines that there are no
independent ‘cyber borders’ incongruent with a State’s physical borders which would limit or
disregard the territorial scope of its sovereignty. Within its borders, a State has the exclusive
right – within the framework of international law – to fully exercise its authority, which
includes the protection of cyber activities, persons engaging therein as well as cyber
infrastructures in the territory of a State against cyber and non-cyber-related interferences
attributable to foreign States.14
As a corollary to the rights conferred on States by the rule of territorial sovereignty, States
are under an ‘obligation not to allow knowingly their territory to be used for acts contrary to
the rights of other States’15 – this generally applies to such use by State and non-State actors.
The ‘due diligence principle’, which is widely recognized in international law, is applicable
to the cyber context as well and gains particular relevance here because of the vast
interconnectedness of cyber systems and infrastructures.
Germany agrees with the view that cyber operations attributable to States which violate
the sovereignty of another State are contrary to international law.16 In this regard, State
sovereignty constitutes a legal norm in its own right and may apply directly as a general
norm also in cases in which more specific rules applicable to State behaviour, such as the
prohibition of intervention or the use of force, are not applicable. Violations of State
10
11
12
13
14
15
16
For example, restrictive regulatory or enforcement activities regarding important internet nodes in the territory of
one State may seriously impair the functioning of networks of other States.
See below, at II.b).
See Tallinn Manual 2.0 (note 4), rule 3 (‘external sovereignty’).
Ibid., rule 1, commentary, para. 5.
Ibid., rule 2 with commentary, para. 2.
See International Court of Justice (ICJ), Corfu Channel case (United Kingdom of Great Britain and Northern
Ireland v. Albania), Judgement of 9 April 1949, I.C.J. Reports 1949, 4, 22; Permanent Court of Arbitration (PCA administering institution), Island of Palmas Case (or Miangas), United States of America v. The Netherlands,
Arbitral Award (M. Huber) of 4 April 1928, (1928) II RIAA 829, 839.
Cf. Tallinn Manual 2.0 (note 4), rule 4.
3