The ESCWA Cyber Legislation Digest 1. The general conditions required for the legal processing of personal electronic records. This addresses issues related to the definition of what constitutes a personal record and the principles that allow for its processing. Also addressed are the responsibilities of those parties who are processing such records and the rights of the person whose data is being processed, in order to know what is being processed and how. 2. The setup of suitable control agencies whose main concerns are the protection of electronic personal records. Such agencies will be responsible for the protection of all such records as well as the control of the processing of such records and the authorization for their processing. Such agencies will also have the authority to issue penalties in case of transgressions or improper access as well as blocking access to specific records or halting their processing. 3. Judicial recourses, responsibilities and sanctions. This covers the rights of the owners of personal data to refer to special courts regarding the processing of such personal records. Also addressed are issues related to compensation in the case of transgressions and the cases where such transgressions are allowed by law. 4. The transfer of personal data to countries outside the Arab region. Issues such as the responsibilities of the parties conducting such transfers are addressed as well as the various assurances of such parties to the owners of the safety and security of their records as part of the individual’s rights. 5. Codes of conduct covering articles required to regularize rules that can be used to control the protection of personal records. This directive identifies seven chapters as follows: Chapter 1: Chapter 2: Chapter 3: Chapter 4: Chapter 5: Chapter 6: Chapter 7: General Provisions The Official Control Agency General Conditions for the Processing of Personal Data Judicial Recourses, Responsibilities and Sanctions The Transfer of Personal Data to Countries outside the Arab Region Code of Conduct Final Provisions Their related sections and articles are listed in Appendix A. Directive 5: Cybercrime With the exponential increase in the penetration of laptops, mobiles and easily accessible networks, a paradigm shift resulted in the generation of a new form of crime, aptly called cybercrime. Gone is the need for criminal equipment and instruments. Any individual with sufficient competence can be party to a wide range of crime categories using ICT facilities. The nature of crimes can also be moral, financial, vandalistic and based on blackmail. The range of crimes is complex and vast making it resistant to counter development using ICT 16

Select target paragraph3