The first is that sovereignty is a cornerstone of international law and international relations.
Of course, we need to distinguish, in this regard, between sovereignty, which is typically used
as a general concept that connotes independence, and “territorial sovereignty”, which is an
international legal rule. States will sometimes point to the need to protect their sovereignty,
referring broadly to their political will and autonomy, without necessarily referring to a legal
rule. The two meanings are sometimes conflated, and we need to be very careful when
drawing legal conclusions.
A second, and related point, is that States undoubtedly have sovereign interests in protecting
cyber infrastructure and data located in their territory. However, States may also have
legitimate sovereign interests with respect to data outside their territory. For example, as
governments store more and more of their data by using cloud services provided by third
parties, whose servers are located abroad, how do we describe the interest that they have in
relation to that data? Would the interest in protecting the data not be a sovereign interest in
this case as well? Or, alternatively, when a State conducts a criminal investigation and needs
to access data located abroad from its own territory, under what circumstances does it need
to request the consent of the territorial State? Of course, there are no easy answers to these
questions, and some of them are currently being discussed, such as in the context of the
protocol to the Budapest Cybercrime Convention currently being negotiated to address this
very topic.
These questions reflect an inherent tension between States’ legitimate interest and the
concept of territorial sovereignty, as we understand it in the physical world. In practice, States
occasionally do conduct cyber activities that transit through, and target, networks and
computers located in other States, for example for national defense, cyber-security, or law
enforcement purposes. Under existing international law, it is not clear whether these types of
actions are violations of the rule of territorial sovereignty, or perhaps that our understanding
of territorial sovereignty in cyberspace is substantively different from its meaning in the
physical world.
Another matter closely related to the issue of sovereignty is that of non-intervention.
Traditionally, this concept has been understood as having a high threshold. It has been taken
to mean that State A cannot take actions to “coerce” State B in pursuing a course of action,
or refraining from a course of action, in matters pertaining to State B’s core internal affairs,
such as its economic or foreign policy choices. Its traditional application has focused on
military intervention and support to armed groups seeking the overthrow of the regime in
another State. This could presumably also relate to support given to armed groups in the
cyber domain, such as providing information regarding cyber vulnerabilities of the State.
A more recent issue that has come to the fore relates to interference in national elections.
We concur with the various positions expressed in this regard, such as that which was
presented by former U.S. State Department Legal Adviser Brian J. Egan, and more recently
6/9