Several international initiatives on cybercrime raise concerns for Internet freedom. One is the Council of Europe (COE) treaty on computer crime. Another major issue concerns legal mandates on ISPs to retain data about their customers’ Internet usage. CDT here collects various materials on these and other initiatives.
Council of Europe Treaty
The Council of Europe has adopted a “Convention on Cybercrime,” the first international treaty to address criminal law and procedural aspects of various types of criminal behavior directed against computer systems, networks or data.
The Convention was approved by the COE in November 2001. Thereupon it was opened for signature by member states of the COE and other countries invited by the COE to adopt it. As a treaty, the convention has no binding legal force in any country until it is ratified by the national government. The treaty entered into force on January 7, 2004, after five states ratified it. The US, as a participant in the drafting of the treaty, was invited to ratify the treaty and did so in August 2006.
The Convention requires countries that ratify it to adopt similar criminal laws on hacking, infringements of copyright, computer-related fraud, and child pornography. It also contains provisions on investigative powers and procedures, such as the search of computer networks and interception of communications, and requires cross-border law enforcement cooperation in searches and seizures and extradition. It has been supplemented by an additional protocol making any publication of racist and xenophobic propaganda via computer networks a criminal offence.
One of the most contentious issues is whether governments should require communications service providers to retain traffic data or transactional records on all communications.
Eleven member States of the Council of Europe signed the Racism Protocol to the Convention on Cybercrime, on January 28, 2003. The Protocol was adopted by the Committee of Ministers of the Council of Europe on 7 November 2002.
British Public Oppose Secret Surveillance Powers and Want Strong Protections for Encrypted Communications
CDT released nationally representative polling data revealing that a the British public are broadly concerned about the security, privacy, and free speech consequences of allowing law enforcement to access encrypted communications.
Responding to the EU-US Negotiations on Reciprocal Data Exchanges for Border Procedures
CDT Europe, together with 29 other civil society organisations and academics, sent an open joint letter to the Council of the EU regarding the worrying direction taken by the European Commission in the EU-US border negotiations with the U.S. government.
Open Joint Letter on a Public Reassessment of the EU-US Adequacy Decision
On 29 June, the US Supreme Court ruled that US President Trump can remove the leaders of independent agencies and commissions, overturning nearly 90 years of precedent limiting executive power. This decision raises serious questions about one of the key safeguards underpinning the EU-US Data Privacy Framework adopted in 2023: independent supervision.
Return of Mass Scanning of Private Communications through Undemocratic Procedure
CDT Europe responds to the European Parliament's vote to revive the interim derogation from the ePrivacy Directive, commonly known as “Chat Control 1.0”, which provides the legal basis for the voluntary, indiscriminate scanning of private communications for known and new Child Sexual Abuse Material (CSAM), and for the solicitation of children.