logistical limitations. Suspects frequently use anonymization and obfuscation technologies, and
new techniques quickly make their way to a broad criminal audience through online crime
markets.
Law enforcement cybercrime investigations require an amalgamation of traditional and
new policing techniques. While some investigative actions can be achieved with traditional
powers, many procedural provisions do not translate well from a spatial, object-oriented
approach to one involving electronic data storage and real-time data flows. The study
questionnaire referred to ten cybercrime investigative measures, ranging from generic search and
seizure to specialized powers, such as preservation of computer data.4 Countries most often reported
the existence of general (nonNational approaches to investigative measures for cybercrime
cyber-specific) powers across
all investigative measures. A
Search
number of countries also
Seizure
reported
cyber-specific
Cyber‐specific power
Order for subscriber
legislation,
notably
for
data
General power
ensuring
expedited
Order for traffic data
Both
preservation of computer data
Order for content data
No power
and
obtaining
stored
subscriber
data.
Many
Real‐time traffic data
countries reported a lack of
Real‐time content data
legal power for advanced
Expedited preservation
measures, such as remote
computer forensics. While
Remote forensics
traditional procedural powers
Trans‐border access
can be extended to cyberSource: Study cybercrime questionnaire. Q42‐51. (n=55)
situations, in many cases such
an approach can also lead to
legal uncertainties and challenges to the lawfulness of evidence gathering, and thus the admissibility
of evidence. Overall, national approaches to cybercrime investigative powers show less core
commonality than for criminalization of many cybercrime acts.
Irrespective of the legal form of investigative powers, all responding authorities use
search and seizure for the physical appropriation of computer equipment and the capture of
computer data. The majority of countries also use orders for obtaining stored computer data
from internet service providers. Outside of Europe, however, around one third of countries
report challenges in compelling third parties in an investigation to provide information. Around
three-quarters of countries use specialized investigative measures, such as real-time collection
of data, or expedited preservation of data. Use of investigative measures typically requires a
minimum of initial evidence or a report of a cybercrime act. More intrusive measures, such as
those involving real-time collection of data or accessing of data content, often require higher
thresholds, such as evidence of a serious act, or demonstration of probable cause or reasonable
grounds.
The interplay between law enforcement and internet service providers is particularly
complex. Service providers hold subscriber information, billing invoices, some connection logs,
location information (such as cell tower data for mobile providers), and communication
4
Search for computer hardware or data; seizure of computer hardware or data; order for subscriber information; order for stored
traffic data; order for stored content data; real-time collection of traffic data; real-time collection of content data; expedited
preservation of computer data; use of remote forensic tools; and trans-border access to a computer system or data.
xxii