questionnaire referred to 14 acts commonly included in notions of cybercrime.3 Responding
countries described widespread criminalization of these 14 acts, with the primary exception of SPAM
offences and, to some extent, offences concerning computer misuse tools, racism and xenophobia,
and online solicitation or ‘grooming’ of children. This reflects a certain baseline consensus on
culpable cybercrime conduct. Countries reported few additional crimes, not mentioned in the
questionnaire. These mostly concerned computer content, including criminalization of obscene
material, online gambling, and online illicit markets, such as in drugs and persons. For the 14 acts,
countries reported the use of cyber-specific offences for core cybercrime acts against the
confidentiality, integrity and accessibility of computer systems. For other forms of cybercrime,
general (non-cyber-specific) offences were used more often. Both approaches were reported,
however, for computer-related acts involving breach of privacy, fraud or forgery, and identity
offences.
While high-level
National approaches to criminalization of cybercrime acts
consensus
exists
Illegal access
regarding broad areas of
Illegal interception
criminalization, detailed
Illegal interference
analysis of the provisions
Cyber‐specific
Computer misuse tools
in source legislation
offence
Breach of privacy
General offence
reveals
divergent
Fraud
or
forgery
approaches.
Offences
Both
Identity offences
involving illegal access to
Not an offence
Copyright or trademark
computer systems and
offences
data differ with respect to
SPAM
the object of the offence
Personal harm
(data,
system,
or
Racism and xenophobia
information),
and
Child pornography
regarding
the
Solicitation or grooming
criminalization of ‘mere’
Terrorism support
offences
access or the requirement
Source: Study cybercrime questionnaire. Q25‐38. (n=61)
for further intent, such as
to cause loss or damage. The requisite intent for an offence also differs in approaches to
criminalization of interference with computer systems or data. Most countries require the interference
to be intentional, while others include reckless interference. For interference with computer data, the
conduct constituting interference ranges from damaging or deleting, to altering, suppressing,
inputting or transmitting data. Criminalization of illegal interception differs by virtue of whether the
offence is restricted to non-public data transmissions or not, and concerning whether the crime is
restricted to interception ‘by technical means’. Not all countries criminalize computer misuse tools. For
those that do, differences arise regarding whether the offence covers possession, dissemination, or
use of software (such as malware) and/or computer access codes (such as victim passwords). From
the perspective of international cooperation, such differences may have an impact upon findings of
dual-criminality between countries.
Several countries have adopted cyber-specific crimes for computer-related fraud, forgery and
identity offences. Others extend general provisions on fraud or theft, or rely on crimes covering
3
Illegal access to a computer system; illegal access, interception or acquisition of computer data; illegal data interference or system
interference; production, distribution or possession of computer misuse tools; breach of privacy or data protection measures;
computer-related fraud or forgery; computer-related identity offences; computer-related copyright and trademark offences;
computer-related acts causing personal harm; computer-related acts involving racism or xenophobia; computer-related
production, distribution or possession of child pornography; computer-related solicitation or ‘grooming’ of children; and
computer-related acts in support of terrorism offences.
xx