Section III
HIPCAR – Cybercrime/e-Crimes
During the discussion the working group decided to add certain qualifying circumstances to restrict the
criminalisation that is reflective of the different assessments of the dangerous nature of the behaviour
involved or of the need to use criminal law as a countermeasure within the region. This approach provides
flexibility to the various states in determining their criminal policy in this area.
Section 4: Illegal Access
This provision criminalises the act of access. The protected legal interest is the integrity of the computer
system. The need for criminalisation of such acts reflects the interests of operators or computer systems
to run their systems in an undisturbed manner. The mere unauthorised intrusion and not only follow up
crimes such as data interferences should therefore be criminalised as it my lead to impediments to
legitimate users of systems and data and may generate high costs for reconstruction. The provision
completes technical approaches to prevent such conduct (e.g. password protection measures) and
enables law enforcement agencies to carry out investigations in such cases where offenders successfully
manage to commit the offence.
Access does not specify a certain means of communication, but is open-ended and facilitates further
technical developments. It shall include all means of entering another computer system, including
Internet attacks, as well as illegal access to wireless networks. Even unauthorised access to computers
that are not connected to any network (e.g. by circumventing a password protection) are covered by the
provision. Like all other offences established in this document Section 4 requires that the offender is
carrying out the offences intentionally. Reckless acts are therefore not covered.
Access to a computer system can only be prosecuted under Section 4, if it happens “without lawful excuse
or justification”. This requires that the offender acts without authority (whether legislative, executive,
administrative, judicial, contractual or consensual) and the conduct is otherwise not covered by
established legal defences, excuses, justifications or relevant principles. Access to a system permitting
free and open access by the public or access to a system with the authorisation of the owner or other
rights-holder is as a consequently not criminalised. Network administrators and security companies that
test the protection of computer systems in order to identify potential gaps in security measures do not
commit a criminal act.
The fact, that the victim of the crime proffered a password or similar access code to the offender, eg
because the offender persuaded the victim to disclose a password or access code due to a successful
social engineering approach, does not necessarily mean that the offender then acted legitimately when
he accessed the computer system of the victim.
Section 5: Illegal Remaining
This provision criminalises the illegal remaining in a computer system. Similar to Section 4 the protected
legal interest is the integrity of the computer system. The provision, that is in similar form neither
contained in the Commonwealth Model Law nor Council of Europe Convention on Cybercrime is reflecting
the fact, that the integrity of a computer system can not only be violated by entering a computer system
without right but also by remaining in the computer system after the authorisation has expired. Such
conduct cannot be covered by Section 4 as in such cases the offender did not illegally enter the system.
Remaining requires that the offender still has access to the computer system. This can for example be the
case if the offender remains logged on or continues to undertake operations. The fact that he has the
theoretical possibility to log on to the computer system is not sufficient.
Section 4 requires that the offender is carrying out the offences intentionally. Reckless acts are not
covered by this section. Section 4 only criminalizes such acts that are committed “without lawful excuse
or justification”.
> Model Policy Guidelines & Legislative Text
33