Section III HIPCAR – Cybercrime/e-Crimes Section 29: Access Provider Based on Section 29, the liability of access providers (Section 29(1)) and router operators (Section 29(2)) is completely excluded as long as they comply with the three conditions defined in Section 29. As a consequence, the access provider is in general not responsible for criminal offences committed by its users. This full exclusion of liability does not release the provider from the obligation to prevent further offence if ordered by a court or administrative authority. Section 30: Hosting Provider The drafter took note that the identification of illegal content is a major challenge for the hosting provider. Especially for popular providers that store thousands of websites manual searches for illegal content would be impossible. As a result, the drafters decided to limit the liability of hosting providers. However, unlike the case of the access provider, the liability of the host provider is not generally excluded but only if certain conditions are fulfilled. Section 30(1)(a) is limiting the liability if the hosting provider expeditiously removes content after receiving an order from any public authority or court. Expeditiously does in general mean in less than 24 hours. Section 30(1)(b) defines that as long as the hosting provider has no actual knowledge about illegal activities or illegal content stored on his servers, he is not liable. The drafters found it important to point out that an assumption that illegal content could be stored on the servers is not considered equivalent to actually having knowledge of the issue. If information are brought to the attention of a provider they must be concrete and specific enough to enable him to identify the location of the illegal content. If the provider obtains concrete knowledge about illegal activities or illegal content he can only avoid liability if he informs a public authority about the potentially illegal content. Unlike the European Union E-Commerce directive, that established liability if the hosting provider does not remove illegal content after having information about its existence the drafters decided to leave the decision if content is illegal to competent pubic authorities. Countries may specify the competent authority such content needs to be reported to. Section 30 is not only applicable for the providers that limit their services to renting technical data storage infrastructure. Popular Internet Services like the auction platforms offer hosting services as well. Countries may decide to implement a hotline service where illegal content can be reported. As the removal of illegal content might depite the illegal nature of the content interfere with contractual obligation of the provider with regard to its customer. Therefore the drafters decided to implement a clarification in Section 30(3) that in those cases where an order was received pursuant to paragraph 1. Section 31: Caching Provider Section 31 limits the liability of caching provider. The term caching is in this context used to describe the storage of popular websites on local storage media in order to reduce the bandwidth and make the access to data more efficient – for example by implementing proxy servers. Within this scope a proxy server may service requests without contacting the specified server by retrieving content saved on local storage media from a previous request. The drafters recognised the economic importance of caching and decided to exclude the liability for automatic temporary storage if the provider complies with the conditions defined by Section 31. > Model Policy Guidelines & Legislative Text 45

Select target paragraph3