neutral’ in their text. They do not specifically list devices that might be considered as computer systems or information systems. In most contexts, this approach is considered good practice, insofar as it mitigates the risk of new technologies falling outside of legal provisions and the need for continuous updating of legislation.81 Based on the core concept of processing computer data or information, it is likely that provisions typically apply to devices such as mainframe and computer servers, desktop personal computers, laptop computers, smartphones, tablet devices, and on-board computers in transport and machinery, as well as multimedia devices such as printers, MP3 players, digital cameras, and gaming machines.82 Under the concept of ‘processing computer data or information,’ it is strongly arguable that any device, such as a wireless or fixed router, that connects to the internet is also included. Storage devices such as hard disk drives, USB memory sticks or flash cards may or may not strictly be part of the ‘computer system’ or ‘information system.’ But, where they are not, they can still be relevant objects through separate legal provisions. Only one international or regional instrument attempts a ‘lower technology’ limit on the description of a computer system – stating that the term does not include an ‘automated typewriter or typesetter, a portable hand held calculator, or other similar device.’83 As the world moves towards an ‘internet of things’ and nano-computing, descriptions such as ‘computer system’ or ‘information system’ will likely need to be interpreted as encompassing a greater range of devices.84 In principle, however, the core concept of ‘automated processing of information’ would likely be sufficiently flexible to include, for instance, a monitoring and control smart chip with NFC and IP connectivity, built into a household appliance. ‘Computer data’ or ‘computer information’ is commonly described as a ‘representation of facts, information or concepts that can be read, processed, or stored by a computer.’ Some approaches clarify that this includes a computer program.85 Others are silent on the point. The difference between the formulations ‘machine-readable’ and ‘can be read, processed or stored by a computer system (or information system)’ is likely of a semantic nature only. In practice, computer data or information likely includes data or information stored on physical storage media (such as hard disk drives, USB memory sticks or flash cards), data or information stored in the memory of a computer system or information system, data or information transmissions (whether wired, optical, or radio frequency), and physical displays of data or information, such as in printout form or on a device screen. While recognizing the use of different approaches to terminology, this Study makes use of the terms ‘computer system’ and ‘computer data’, which it treats as equivalent to ‘information system’ and ‘computer information.’ Categories of cybercrime While the term ‘cybercrime’ is not amenable to a single description, the question arises whether cybercrime objectives, features, or modus operandi can be identified in general terms, rather than (or in addition to) by reference to a list of individual cybercrime acts. As noted above, one 81 82 83 84 85 See, for example, Explanatory Report to the Council of Europe Cybercrime Convention, ETS No. 185. A Guidance Note of the Council of Europe Cybercrime Convention Committee (T-CY) also reaches the conclusion that the definition of ‘computer system’ in Article 1(a) of the Council of Europe Cybercrime Convention covers developing forms of technology that go beyond traditional mainframe or desktop computer systems, such as modern mobile phones, smart phones, PDAs, tablets or similar. See Council of Europe. 2012. T-CY Guidance Note 1 on the notion of ‘computer system.’ T-CY (2012) 21, 14 November 2012. COMESA Draft Model Bill, Part 1, Art. 1(b). For a review of potential developments and regulatory challenges associated with the internet of things see European Union, 2009. Communication from the Commission to the European Parliament, the Council, the European Economic and Social Committee and the Committee of the Regions. Internet of Things – An Action Plan for Europe. COM (2009) 278 Final, 18 June 2009. Council of Europe Cybercrime Convention, Art. 1(b). 14

Select target paragraph3