Section III HIPCAR – Cybercrime/e-Crimes During the discussion the working group decided to add certain qualifying circumstances to restrict the criminalisation that is reflective of the different assessments of the dangerous nature of the behaviour involved or of the need to use criminal law as a countermeasure within the region. This approach provides flexibility to the various states in determining their criminal policy in this area. Section 4: Illegal Access This provision criminalises the act of access. The protected legal interest is the integrity of the computer system. The need for criminalisation of such acts reflects the interests of operators or computer systems to run their systems in an undisturbed manner. The mere unauthorised intrusion and not only follow up crimes such as data interferences should therefore be criminalised as it my lead to impediments to legitimate users of systems and data and may generate high costs for reconstruction. The provision completes technical approaches to prevent such conduct (e.g. password protection measures) and enables law enforcement agencies to carry out investigations in such cases where offenders successfully manage to commit the offence. Access does not specify a certain means of communication, but is open-ended and facilitates further technical developments. It shall include all means of entering another computer system, including Internet attacks, as well as illegal access to wireless networks. Even unauthorised access to computers that are not connected to any network (e.g. by circumventing a password protection) are covered by the provision. Like all other offences established in this document Section 4 requires that the offender is carrying out the offences intentionally. Reckless acts are therefore not covered. Access to a computer system can only be prosecuted under Section 4, if it happens “without lawful excuse or justification”. This requires that the offender acts without authority (whether legislative, executive, administrative, judicial, contractual or consensual) and the conduct is otherwise not covered by established legal defences, excuses, justifications or relevant principles. Access to a system permitting free and open access by the public or access to a system with the authorisation of the owner or other rights-holder is as a consequently not criminalised. Network administrators and security companies that test the protection of computer systems in order to identify potential gaps in security measures do not commit a criminal act. The fact, that the victim of the crime proffered a password or similar access code to the offender, eg because the offender persuaded the victim to disclose a password or access code due to a successful social engineering approach, does not necessarily mean that the offender then acted legitimately when he accessed the computer system of the victim. Section 5: Illegal Remaining This provision criminalises the illegal remaining in a computer system. Similar to Section 4 the protected legal interest is the integrity of the computer system. The provision, that is in similar form neither contained in the Commonwealth Model Law nor Council of Europe Convention on Cybercrime is reflecting the fact, that the integrity of a computer system can not only be violated by entering a computer system without right but also by remaining in the computer system after the authorisation has expired. Such conduct cannot be covered by Section 4 as in such cases the offender did not illegally enter the system. Remaining requires that the offender still has access to the computer system. This can for example be the case if the offender remains logged on or continues to undertake operations. The fact that he has the theoretical possibility to log on to the computer system is not sufficient. Section 4 requires that the offender is carrying out the offences intentionally. Reckless acts are not covered by this section. Section 4 only criminalizes such acts that are committed “without lawful excuse or justification”. > Model Policy Guidelines & Legislative Text 33

Select target paragraph3