Section III HIPCAR – Cybercrime/e-Crimes (15) Remote Forensic Software One of the aspects that was intensively discussed during the negotiation of the legislative text was the conduct of sophisticated investigation procedures. The drafters took note of reports about the use of remote forensic software in national investigations. With regard to the definition of remote forensic software they decided to highlight the possible fields where such software could be used (keystroke logging and transmission of IP-addresses) but not limit the scope of such software to these functions. (16) Seize The seizure of evidence is a traditional investigation process. Taking into account that in addition to the seizure of hardware there are various ways in which evidence can be collected. The drafters decided to further elaborate on this definition by providing examples of activities that are considered to be part of the seizure of evidence. One example that was included in the definition is the authorization to activate the suspect’s computer system. The drafters found it worth mentioning that this is an essential requirement for sophisticated investigations. (17) Internet Service Provider In lieu of providing a single definition of Internet Service Provider the drafters decide to differentiate between the types of service providers. (18) Traffic Data The interception of traffic data is an important investigation process. The drafters decided to provide a set of criteria that clearly define and thereby limit the applicability of the provision to the relevant categories of data. (19) Things Things are object of seizure. While the interpretation of the term is left to national courts the drafters decided to provide a set of examples. (20) Utilise The definition of the term “utilise” is relevant for the use of remote forensic software. As a result of an intensive discussion during the working group session the drafters decided to clarify that not only the use of such software, but also preparatory acts are covered by the provision. PART II Introduction to Sections 4 – 15 The purpose of Sections 4-15 of the Legislative Text is to improve the means to prevent and investigate computer– and network-related crime by defining a common minimum standard of relevant offences based on best practice prevailing within the region as well as international standards. In this context the definition of standards by Sections 4-15 will help national lawmakers to discover possible gaps in domestic law and also form the basis for closer international cooperation that in general requires a similar degree of criminalisation as a consequence of the double criminality requirement. Sections 4-15 provide a definition of the minimum standards and therefore do not preclude more extensive criminalisation on the national level. 32 > Model Policy Guidelines & Legislative Text

Select target paragraph3