neutral’ in their text. They do not specifically list devices that might be considered as computer
systems or information systems. In most contexts, this approach is considered good practice, insofar
as it mitigates the risk of new technologies falling outside of legal provisions and the need for
continuous updating of legislation.81 Based on the core concept of processing computer data or
information, it is likely that provisions typically apply to devices such as mainframe and computer
servers, desktop personal computers, laptop computers, smartphones, tablet devices, and on-board
computers in transport and machinery, as well as multimedia devices such as printers, MP3 players,
digital cameras, and gaming machines.82 Under the concept of ‘processing computer data or
information,’ it is strongly arguable that any device, such as a wireless or fixed router, that connects
to the internet is also included. Storage devices such as hard disk drives, USB memory sticks or flash
cards may or may not strictly be part of the ‘computer system’ or ‘information system.’ But, where
they are not, they can still be relevant objects through separate legal provisions.
Only one international or regional instrument attempts a ‘lower technology’ limit on the
description of a computer system – stating that the term does not include an ‘automated typewriter or
typesetter, a portable hand held calculator, or other similar device.’83 As the world moves towards an ‘internet
of things’ and nano-computing, descriptions such as ‘computer system’ or ‘information system’ will
likely need to be interpreted as encompassing a greater range of devices.84 In principle, however, the
core concept of ‘automated processing of information’ would likely be sufficiently flexible to
include, for instance, a monitoring and control smart chip with NFC and IP connectivity, built into a
household appliance.
‘Computer data’ or ‘computer information’ is commonly described as a ‘representation of facts,
information or concepts that can be read, processed, or stored by a computer.’ Some approaches clarify that this
includes a computer program.85 Others are silent on the point. The difference between the
formulations ‘machine-readable’ and ‘can be read, processed or stored by a computer system (or
information system)’ is likely of a semantic nature only. In practice, computer data or information
likely includes data or information stored on physical storage media (such as hard disk drives, USB
memory sticks or flash cards), data or information stored in the memory of a computer system or
information system, data or information transmissions (whether wired, optical, or radio frequency),
and physical displays of data or information, such as in printout form or on a device screen.
While recognizing the use of different approaches to terminology, this Study makes use of
the terms ‘computer system’ and ‘computer data’, which it treats as equivalent to ‘information
system’ and ‘computer information.’
Categories of cybercrime
While the term ‘cybercrime’ is not amenable to a single description, the question arises
whether cybercrime objectives, features, or modus operandi can be identified in general terms, rather
than (or in addition to) by reference to a list of individual cybercrime acts. As noted above, one
81
82
83
84
85
See, for example, Explanatory Report to the Council of Europe Cybercrime Convention, ETS No. 185.
A Guidance Note of the Council of Europe Cybercrime Convention Committee (T-CY) also reaches the conclusion that the
definition of ‘computer system’ in Article 1(a) of the Council of Europe Cybercrime Convention covers developing forms of
technology that go beyond traditional mainframe or desktop computer systems, such as modern mobile phones, smart phones,
PDAs, tablets or similar. See Council of Europe. 2012. T-CY Guidance Note 1 on the notion of ‘computer system.’ T-CY (2012)
21, 14 November 2012.
COMESA Draft Model Bill, Part 1, Art. 1(b).
For a review of potential developments and regulatory challenges associated with the internet of things see European Union, 2009.
Communication from the Commission to the European Parliament, the Council, the European Economic and Social Committee
and the Committee of the Regions. Internet of Things – An Action Plan for Europe. COM (2009) 278 Final, 18 June 2009.
Council of Europe Cybercrime Convention, Art. 1(b).
14