Czech Republic Position paper on the application of international law in cyberspace 14. Therefore, assessed on a case-by-case approach and taking into account specific circumstances of the case, intervention in the internal or external affairs of the Czech Republic by cyber means may constitute a violation of the prohibition of intervention. Due Diligence 15. Due diligence stems from a general international law principle that States must ensure that territory and objects over which they enjoy sovereignty are not used to harm the rights of other States. Due diligence entails that “it is every State’s obligation not to allow knowingly its territory to be used for acts contrary to the rights of other States.”13 Thus, in the cyber domain, due diligence requires States to take all reasonable and feasible measures concerning activities in cyberspace falling under their jurisdiction in order to prevent, eliminate or mitigate potentially significant harm to legally protected interests of another State. 16. There exist, to this day, divergent views on the precise normative character, scope, and content of due diligence in cyberspace. In the opinion of the Czech Republic, due diligence, under the conditions stated below, may be considered an obligation in its own right. 17. Due diligence equally applies in cyberspace as concluded by the UN GGE in 2015.14 The Czech Republic is of the view that every State has an obligation to act against unlawful and harmful cyber activities emanating from or through its territory provided that it is aware of, or should reasonably be expected to be aware of, such activities. Due diligence applies in particular to activities of private individuals that violate the rights of other States, when harmful activities cannot be attributed to a particular State in accordance with the rules governing state responsibility or where only insufficient proof for such attribution exists. 18. The due diligence obligation is only triggered when the target State suffers serious adverse consequences. There is no universally accepted threshold of harm in international law and each case should be evaluated individually. The Czech Republic maintains that such harm does not need to be necessarily limited to physical damage to objects or physical injuries to persons by cyber means and could encompass other serious non-physical harm, resulting, for example, from the interference with or impairment of the use and operation of critical infrastructure. Such situations could also encompass, for example, malicious activities in cyberspace causing serious adverse consequences to medical and healthcare facilities in the Czech Republic.15 19. To ensure compliance with the due diligence obligation, States should take measures that may be reasonably expected, in the given context and circumstances, to act against harmful cyber activities that violate a right of another State. In procedural terms, due diligence might encompass a duty to inform and cooperate in the case of transboundary harm. At the same time, the means 13 Corfu Channel Case (United Kingdom v Albania); Merits, International Court of Justice (ICJ), 9 April 1949, Rep 4, p. 22. 14 See para. 13 (c) of the UN GGE 2015 Report. 15 See also The Oxford Statement on the International Law Protections Against Cyber Operations Targeting the Health Care Sector. Oxford Institute for Ethics, Law and Armed Conflict 6

Select target paragraph3