Section III
HIPCAR – Cybercrime/e-Crimes
(15) Remote Forensic Software
One of the aspects that was intensively discussed during the negotiation of the legislative text was the
conduct of sophisticated investigation procedures. The drafters took note of reports about the use of
remote forensic software in national investigations. With regard to the definition of remote forensic
software they decided to highlight the possible fields where such software could be used (keystroke
logging and transmission of IP-addresses) but not limit the scope of such software to these functions.
(16) Seize
The seizure of evidence is a traditional investigation process. Taking into account that in addition to the
seizure of hardware there are various ways in which evidence can be collected. The drafters decided to
further elaborate on this definition by providing examples of activities that are considered to be part of
the seizure of evidence. One example that was included in the definition is the authorization to activate
the suspect’s computer system. The drafters found it worth mentioning that this is an essential
requirement for sophisticated investigations.
(17) Internet Service Provider
In lieu of providing a single definition of Internet Service Provider the drafters decide to differentiate
between the types of service providers.
(18) Traffic Data
The interception of traffic data is an important investigation process. The drafters decided to provide a set
of criteria that clearly define and thereby limit the applicability of the provision to the relevant categories
of data.
(19) Things
Things are object of seizure. While the interpretation of the term is left to national courts the drafters
decided to provide a set of examples.
(20) Utilise
The definition of the term “utilise” is relevant for the use of remote forensic software. As a result of an
intensive discussion during the working group session the drafters decided to clarify that not only the use
of such software, but also preparatory acts are covered by the provision.
PART II
Introduction to Sections 4 – 15
The purpose of Sections 4-15 of the Legislative Text is to improve the means to prevent and investigate
computer– and network-related crime by defining a common minimum standard of relevant offences
based on best practice prevailing within the region as well as international standards. In this context the
definition of standards by Sections 4-15 will help national lawmakers to discover possible gaps in domestic
law and also form the basis for closer international cooperation that in general requires a similar degree
of criminalisation as a consequence of the double criminality requirement. Sections 4-15 provide a
definition of the minimum standards and therefore do not preclude more extensive criminalisation on the
national level.
32
> Model Policy Guidelines & Legislative Text