EXECUTIVE SUMMARY inspired by: (i) the Council of Europe or the European Union, (ii) the Commonwealth of Independent States or the Shanghai Cooperation Organization, (iii) intergovernmental African organizations, (iv) the League of Arab States, and (v) the United Nations. A significant amount of cross-fertilization exists between all instruments, including, in particular, concepts and approaches developed in the Council of Europe Convention on Cybercrime. Analysis of the articles of 19 multilateral instruments relevant to cybercrime shows common core provisions, but also significant divergence in substantive areas addressed. Globally, 82 countries have signed and/or ratified a binding cybercrime instrument.1 In addition to formal membership and implementation, multilateral cybercrime instruments have influenced national laws indirectly, through use as a model by non-States parties, or via the influence of legislation of States parties on other countries. Membership of a multilateral cybercrime instrument corresponds with the perception of increased sufficiency of national criminal and procedural law, indicating that current multilateral provisions in these areas are generally considered effective. For the more than 40 countries that provided information, the Council of Europe Convention on Cybercrime is the most used multilateral instrument for the development of cybercrime legislation. Altogether, multilateral instruments from other ‘clusters’ were used in around half as many countries. Overall, one-third of responding countries report that their legislation is highly, or very highly, harmonized with countries viewed as important for the purposes of international cooperation. This varies regionally, however, with higher degrees of harmonization reported within the Americas and Europe. This may be due to the use, in some regions, of multilateral instruments, which are inherently designed to play a role in harmonization. Fragmentation at the international level, and diversity of national laws, in terms of cybercrime acts criminalized, jurisdictional bases, and mechanisms of cooperation, may correlate with the existence of multiple cybercrime instruments with different thematic and geographic scope. Both instruments and regions presently reflect divergences derived from underlying legal and constitutional differences, including differing conceptions of rights and privacy. Criminalization Information on cybercrime criminal laws was gathered through the study questionnaire, as well as by primary source analysis of available legislation collected by the Secretariat.2 The study 1 2 One or more of: The Council of Europe Convention on Cybercrime, the League of Arab States Convention on Combating Information Technology Offences, the Commonwealth of Independent States Agreement on Cooperation in Combating Offences related to Computer Information, or the Shanghai Cooperation Organization Agreement in the Field of International Information Security. Primary source legislation was analyzed for 97 Member States, including 56 that responded to the questionnaire, with regional distribution as follows: Africa (15), Americas (22), Asia (24), Europe (30), and Oceania (6). xix

Select target paragraph3