Section III HIPCAR – Cybercrime/e-Crimes Section 6: Illegal Interception This provision aims to equate the protection of electronic transfers with the protection of voice conversations against illegal tapping and/or recording that currently already exists in most legal systems. The offence in general applies to all forms of electronic data transfer (e.g. telephone, fax, file transfer or e-mail). The applicability of Section 3 is limited to the interception of transmissions realised by technical measures. Interception related to electronic data can be defined as any act of acquiring data during a transfer process. Interception related to electronic data can be defined as any act of acquiring data during a transfer process. This can be done by listening to, monitoring or surveillance of the content of communications. This provision only applies to the interception of transmissions therefore access to stored information is not considered as an interception of a transmission. The term “transmission” covers all data transfers, whether by telephone, fax, e-mail or file transfer. The offence established under Section 6 applies only to non-public transmissions. A transmission is “nonpublic”, if the transmission process is confidential. The vital element to differentiate between public and non-public transmissions is not the nature of the data transmitted, but the nature of the transmission process itself. Even the interception of publicly available information can be considered criminal, if the parties involved in the transfer intend to keep the content of their communications secret. Use of public networks does not exclude “non-public” communications. The inclusion of electromagnetic emissions within the legislative text ensures that a comprehensive approach is undertaken, especially as older computers generate electromagnetic emissions during their operation. Such emissions that are not covered by the term data within the legislative text needed to be specifically criminalised. Section6 requires that the offender carries out or perpetrates the offences intentionally and without lawful excuse or justification. This is not the case if the interception takes place on the basis of instructions or with the authorisation of the participants of the transmission or it is a lawful interception on the basis of criminal law provisions. Section 7: Illegal Data Interference Section 7 aims to fill existing gaps in some national criminal laws as well as provide computer data and computer programmes with protections similar to those enjoyed by tangible objects against the intentional infliction of damage. The terms damaging and deterioration mean any act related to the negative alteration of the integrity of data and software. To a certain degree these terms contain an essential overlap. “Deleting” covers such acts where information is removed from storage media and is considered comparable to the destruction of a tangible object. Dropping a file to the virtual trash bin does not remove the file from the hard disk and is therefore not considered an act of deletion but can be covered by the term denial of access. Altering data covers the modification of existing data, without necessarily lowering the serviceability of the data. This act is especially covering the installation of malicious software like spyware, viruses or adware on the victim’s computer even if they do not operate afterwards. The term “Rendering meaningless” covers all acts of interference with data that makes it unprocessable with regard to its intended use. This act requires that the data was useful or effective before such interference. “Obstructing, interrupting and interfering with the lawful use or any person in the lawful use” covers any action that negatively influences a lawful data processing process. The application of the provision is especially discussed with regard to Denial-of-Service attacks. During the attack the data provided on the 34 > Model Policy Guidelines & Legislative Text

Select target paragraph3