50
CYBER CRIME & CYBER SECURITY
TRENDS IN AFRICA
adopted in Malabo in June 2014.4 That treaty reflects a strong commitment by Member States of
the African Union to establish a secure and trusted foundation for the information society. It covers a
broad range of measures ranging from electronic transactions, to the protection of personal data, cyber
security and also cyber crime.
Given that this treaty is rather new and is yet to be tested in practice, and given its broad scope, the
present report uses the Budapest Convention on Cyber Crime5 as reference. This Convention is more
specifically focusing on cyber crime and electronic evidence, including international cooperation, and is
increasingly being used in Africa.
The Convention on Cyber Crime was opened for signature in Budapest, Hungary, in 2001. Elaborated by
the Council of Europe with the participation of Canada, Japan, South Africa and the USA it is open for
accession by any State prepared to implement it and to engage in international cooperation. By April
2016 it had 49 Parties and a further 17 States that had been invited to accede or have signed it.
The Budapest Convention is backed up by the Cyber Crime Convention Committee representing the
Parties to this treaty and capacity building programmes.6
It would seem that the African Union Convention on Cyber Security and Personal Data Protection and
the Budapest Convention on Cyber Crime complement each other.
Concepts and Definitions
In terms of concepts and definitions, States should define “computer system” in a broad sense to
encompass also devices such as smart phones, tablets or others while remaining technology neutral.
Article 1.a of the Budapest Convention offers an example.7 Similarly, for criminal law purposes, “service
providers” should comprise all types of service providers as proposed in Article 1.c Budapest Convention. While a general definition of “computer data” will be required (see Article 1.b), a specific definition of
“traffic data” should be foreseen (see Article 1.d).
In criminal investigations, the data most often needed is “subscriber information”. This type of information is less privacy-sensitive than traffic or content data. It will, therefore, be useful to define “subscriber
information” separately so that a lighter regime for access to and sharing of subscriber information
can be established while traffic and in particular content data require stricter safeguards. Article 18.3
Budapest Convention offers a definition of “subscriber information”.
Substantive Criminal Law: Conduct to Be Defined as a Criminal Offence
In terms of substantive law States should criminalise illegal access, illegal interception, data interference, system interference, misuse of devices, computer-related forgery, computer-related fraud, child
pornography and offences related to infringements of copyright and related rights.
Substantive criminal law under the Budapest Convention on Cyber Crime
4
5
6
7
Article 2
Illegal access to a computer system
Article 3
Illegal interception of non-public transmissions to, from or within a computer system
Article 4
Data interference
Article 5
System interference
Article 6
Misuse of devices
https://ccdcoe.org/sites/default/files/documents/AU-270614-CSConvention.pdf
http://conventions.coe.int/Treaty/Commun/QueVoulezVous.asp?NT=185&CM=8&DF=&CL=ENG
In 2014, a dedicated Cyber Crime Programme Office of the Council of Europe became operational in Bucharest, Romania, and is
responsible for capacity building programmes on cyber crime and electronic evidence worldwide.
See also the Guidance Note on the notion of “computer system“ http://www.coe.int/en/web/cybercrime/guidance-notes