cent used the word ‘cybercrime’ in the title or scope of legislative provisions.60 Rather, legislation
more commonly referred to ‘computer crimes,’61 ‘electronic communications,’62 ‘information technologies,’63 or
‘high-tech crime.’64 In practice, many of these pieces of legislation created criminal offences that are
included in the concept of cybercrime, such as unauthorized access to a computer system, or
interference with a computer system or data. Where national legislation did specifically use
cybercrime in the title of an act or section (such as ‘Cybercrime Act’), the definitional section of the
legislation rarely included a definition for the word ‘cybercrime.’65 When the term ‘cybercrime’ was
included as a legal definition, a common approach was to define it simply as ‘the crimes referred to in this
law.’66
In a similar manner, very few international or regional legal instruments define cybercrime.
Neither the Council of Europe Cybercrime Convention, the League of Arab States Convention, nor
the Draft African Union Convention, for example, contain a definition of cybercrime for the
purposes of the instrument. The Commonwealth of Independent States Agreement, without using
the term ‘cybercrime,’67 defines an ‘offence relating to computer information’ as a ‘criminal act of which
the target is computer information.’68 Similarly, the Shanghai Cooperation Organization Agreement
defines ‘information offences’ as ‘the use of information resources and (or) the impact on them in the
informational sphere for illegal purposes.’69
The definitional approaches apparent from national, international and regional instruments
inform the method adopted by this Study. The Study does not seek to ‘define’ cybercrime per se.
Rather, it identifies a list, or ‘basket’, of acts which could constitute cybercrime. This has the
advantage of placing the focus on careful description of the precise conduct to be criminalized. As
such, the word ‘cybercrime’ itself may be better not considered as a legal term of art.70 It is notable
that this is equivalent to the approach adopted by international instruments such as the United
Nations Convention against Corruption.71 This instrument does not define ‘corruption’, but rather
obliges States Parties to criminalize a specific set of conduct which can be more effectively
described.72 ‘Cybercrime’ is therefore best considered as a collection of acts or conduct.
Describing surrounding concepts
It is also instructive to examine descriptions of surrounding concepts, such as ‘computer’,
‘computer system’, ‘data’ and ‘information.’ Their meaning is inherent to understanding the objects
and/or protected legal interests which cybercrime acts concern. A review of international and
regional instruments shows two main approaches: (i) terminology based on ‘computer’ data or
60
61
62
63
64
65
66
67
68
69
70
71
72
Study cybercrime questionnaire. Q12.
See, for example, Malaysia, Computer Crimes Act 1997; Sri Lanka, Computer Crime Act 2007; Sudan, Computer Crimes Act 2007.
See, for example, Albania, Electronic Communications in the Republic of Albania, Law no. 9918 2008; France, Code des postes et
des communications électroniques (version consolidée) 2012; Tonga, Communications Act 2000.
See, for example, India, The Information Technology Act 2000; Saudi Arabia, IT Criminal Act 2007; Bolivarian Republic of
Venezuela, Ley Especial contra los Delitos Informáticos 2001; Vietnam, Law on Information Technology 2007.
See, for example, Serbia, Law on Organization and Competence of Government Authorities for Combating High-Tech Crime
2010.
See, for example, Botswana, Cybercrime and Computer Related Crimes Act 2007; Bulgaria, Chapter 9, Criminal Code SG No.
92/2002; Cambodia, Draft Cybercrime Law 2012; Jamaica, Cybercrimes Act 2010; Namibia, Computer Misuse and Cybercrime Act
2003; Senegal, Law No. 2008-11 on Cybercrime 2008.
See for example, Oman, Royal Decree No 12/2011 issuing the Cybercrime Law; Philippines, Cybercrime Prevention Act 2012.
The original agreement is in Russian language and uses the term ‘преступление в сфере компьютерной информации’, rather
than the contemporary equivalent to ‘cybercrime’: ‘киберпреступности.’
Commonwealth of Independent States Agreement, Art. 1(a).
Shanghai Cooperation Organization Agreement, Annex 1.
See also International Telecommunication Union, 2011. Understanding Cybercrime: A guide for Developing Countries.
United Nations. 2004. Convention against Corruption.
Ibid., Arts. 15 et seq.
12