0% found this document useful (0 votes)
16 views44 pages

Impact of ICT on Cybercrime Risks

The 21st century has seen a digital revolution comparable to the advent of printing, characterized by the rise of cyberspace and the internet, which facilitates global communication and economic transactions. However, this digital age also introduces significant risks, including cybercrime and cybersecurity challenges, as criminal activities evolve alongside technological advancements. The lack of a universally accepted definition of cybercrime complicates legal responses, highlighting the need for coherent national strategies to combat these emerging threats.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
16 views44 pages

Impact of ICT on Cybercrime Risks

The 21st century has seen a digital revolution comparable to the advent of printing, characterized by the rise of cyberspace and the internet, which facilitates global communication and economic transactions. However, this digital age also introduces significant risks, including cybercrime and cybersecurity challenges, as criminal activities evolve alongside technological advancements. The lack of a universally accepted definition of cybercrime complicates legal responses, highlighting the need for coherent national strategies to combat these emerging threats.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

The 21st century has experienced a revolution in digital technologies like the end of the Middle Ages.

age saw that of printing. This contemporary revolution is notably linked to the
the very structure of the internet and the virtual space it generates, cyberspace1The latter is
commonly defined as a set of digitized data constituting a universe
information and communication, linked to the global interconnection of computers, more
precisely defined as 'a set of commercial networks, public networks, networks
private, teaching networks, service networks, that operate on a global scale2.
The informational space now adds to the terrestrial, maritime, and aerial spaces.
where protection and security naturally fall within the scope of skills
sovereign powers of the State.

The digital age now ignores all boundaries. It allows access to culture and to
knowledge facilitates exchanges between people. It makes the establishment possible
of an online economy and brings the citizen closer to their administration. The technologies
digitals are carriers of innovation and growth, while they can
to help or accelerate the development of emerging countries.

The development of ICT and the popularization of the Internet have caused upheavals.
major, both in terms of communication on a global scale and in terms of law
applicable. We see new modes of communication emerging, revolutionized by this
possibility of constantly connecting the whole world, and particularly new modes
of exchanges, such as online commerce or electronic commerce. It is now
possible to complete a transaction thousands of kilometers away from it
interlocutor and with a simple click.
But a certain pessimist tempers this idealistic approach. Thus, any activity
humane bearer of economic, social, and cultural progress that is its social purpose,
also generate new fragilities and vulnerabilities conducive to threats or risks,
because they sharpen the imagination of criminals.

Indeed, the use of ICT is accompanied by various risks and threats. For example, the
medication contains an active substance that has therapeutic effects on your
organism. Undesirable effects can also occur with any treatment. It is there to
treat but if it is misused, it can be dangerous. The growing use of ICT has
also trained challenges in cybersecurity, online threats and the necessity
to protect the data. ICT can pose risks and threats to the
people and organizations.
ICT has facilitated the emergence of new forms of crime, such as
cybercrime, drug trafficking, human trafficking, and terrorism3. These
criminal activities are often difficult to detect and prosecute, as they use
new forms and new means of communication.

1
Pr. HADID Noufyele and Mr. MERBOUHI Samir, Consequences of the use of ICT on economic crime and
Financial in Algeria, University of Algiers 3, New Economy Review
2
United Nations Convention on the Fight Against the Use of Information and Communication Technologies for
criminal fins
Budapest Convention on Cybercrime
3
Cybercrime is now a reality. It is all the more dangerous because it
penetrates within families, where ordinary delinquency had not had access until now.
In 1972, Dean Jean CARBONNIER already stated that "the evolution of customs and
techniques give rise to new forms of delinquency4Indeed, most
great technological discoveries have almost always led, alongside progress
economic benefits they provide to humanity, negative consequences among which is
in a good position the emergence of new forms of crime. The internet is not exempt from
this sociological law of development.5
According to Army General Marc WATIN-AUGOUARD, "when development
the economy was limited to the agricultural primary sector, insecurity was reduced to violations
against people. The secondary sector has seen the emergence of goods production
manufactured and thus of thefts, destruction, degradation. The development of sectors
"tertiary services inspired the so-called smart crimes" 6With the emergence of a
quaternary sector of the economy, where information has become a source of wealth,
cybercrime. It blurs the boundaries between states, bringing the victim closer to their
aggressor but keeps the offender away from his judge.

Cybercrime, not being rigorously defined, leads to excesses.


terminological. Thus, Messrs. Alterman and Bloch retain as a definition of the offense.
computer science, the definition of cybercrime proposed by experts from the Organization
for the Organisation for Economic Co-operation and Development (OECD), namely "everything
illegal, unethical or unauthorized behavior, concerning a treatment
data and/or data transmission automation7.
According to the U.N., 'cybercrime' should encompass 'any illegal behavior that involves'
intervene in electronic operations aimed at the security of computer systems and
data they process," and in a broader sense, "any illegal act committed at
means of a system or a computer network or in relation to a system
computer science8This definition uses the term illegal behavior to refer to the
cybercrime. However, a behavior may be considered illegal in one state and
legal in the other.
However, the term cybercrime remains difficult to conceptualize, as it does not
the object of no legal or regulatory definition9; at the very least, is it not the subject of
from a universal definition by the states, each having tried to grasp this notion
according to its own criteria..................

There is no commonly accepted definition of cybercrime. The method ...


the most common approach is to define the key terms used in cyber surveys

4
Information and communication technologies and their impact on the economy, OECD, page 7
5
Dr. Kamel REZGUI, Cybersecurity Law, Master's in ICT Law, International University
Tunis, 2022
6
Wikipedia, cyber attack
7
GASSIN (R.), "The criminal law of computer science", DS., [1986], Chron p. 35.
8
CSIS, Center for Strategic and International Studies
9
Dr. Sami SOUDANI, Introduction to Computer Security, Master's in ICT Law, International University
from Tunis, 2022
infractions. The examination of these definitions allows us to identify the major concepts and to use
these definitions coherently within the framework of a national strategy to combat
cybercrime...............
An example of this method is Decree-Law No. 2022-54 of September 13, 2022.
related to the fight against offenses related to information systems and
communication that introduces provisions on cybercrime. This text of law
{"système d’information":"information system","données informatiques":"computer data"}
communication system, communication service provider, traffic flow or
access data, IT support, program, the erasure of computer data.
After defining these key terms, the Law lists the main offenses considered
as falling within the scope of cybercrime: the violation of integrity of
information systems and data and their confidentiality, the offenses committed against
the help of information systems or computer data. This approach is very
similar to that adopted by the Council of Europe's Convention on Cybercrime
(Budapest Convention).
Cybercrime can be defined as any illegal action aimed at perpetrating
criminal offenses on or by means of a computer system interconnected to a network
telecommunications. It targets either specific offenses related to the interest for which the
information and communication technologies are the very object of the offense, that is to say, some
common law offenses for which the internet is the means of developing
pre-existing infractions.

As such, in the activities of each organization, a significant amount is used.


data. Data protection has become a major issue for individuals and
organizations facing cybercrime. Data is a gold mine for the
organizations, but their value is too often underestimated. Personal data is the
fuel of the digital age (Isabelle Falque-Pierrotin, President of the CNIL).

A piece of data is a factual and raw piece of information, without context. In certain situations,
this corresponds to each information communicated voluntarily by a person. This
are, for example, demographic data (age, gender, place of residence...). The data
can also correspond to all results of searches, analyses, and other information
held by an organization. The data therefore corresponds to everything that is collected by
an organization. Either through its own means or during exchanges with clients, patients,
partners, ... as soon as they have given their agreement. The data is necessary
only when they can be exploited, confronted, analyzed, and lead to a
result. Without the work of confrontation and analysis, the data is often of little value.
useful; (reference)

To do this, the Budapest Convention has defined data types.............


The expression 'computer data' refers to any representation of facts, information or
of concepts in a form suitable for computer processing, including a
program aimed at ensuring that a computer system executes a function
"traffic data" refers to all data related to a communication that is passing
by a computer system, produced by it as an element of the chain of
communication, indicating the origin, the destination, the route, the time, the date, the size and the
duration of the communication or the type of underlying service.

Computer data refers to any representation of facts, information or


concepts in a format suitable for processing by a computer system, including a
program that allows a computer system to perform a function.10

Application users provide companies with access to large amounts


considerable amounts of data, which are often personal data and whose
uses are always more varied. The data collected can be used not
only to personalize the experience, but also to generate productivity gains
and quality at scale, through a controlled experiment. The data
personal information can be obtained in various ways: voluntarily provided by the
users (for example, when they register to be able to use an online service),
observed (for example, by recording the browsing history on the Internet, the data
of localization, etc.), or inferred (for example, from an analysis of online activities). The
the ability to collect useful data increases with the number of connected devices to
the Internet, cloud computing, the Internet of Things, and advanced robotics.
All kinds of companies use user data, as it allows them to
to adapt their offerings to the clientele. The administrations are making progress in making available
of public resources readable by machines, particularly data. This is what we
called 'open data policy', 'open administration', or even 'democracy
open." As increasingly large amounts of potentially
tools are collected, it is necessary to develop increasingly advanced techniques
sophisticated to be able to collect, process appropriately, and analyze these11
Thus, the internet proves to be an opportune place for the development of crimes and offenses.
relevant to classic crime, but also cybercrime. Indeed, the internet has not
only favored the perpetration of classic criminal acts, it modernized this
crime and gave rise to new offenses. And the sharp increase in
acts committed and the financial harm they cause, testify to the particular interest that
arouses the internet network among criminals12Statistically, cybercrime has generated
a loss estimated at '600 billion dollars in 2019, or about 1% of global GDP13.
A cyberattack is any type of offensive action targeting computer systems,
infrastructures or networks, even personal computers, use various methods
to steal, modify, or destroy data or computer systems.14

10
[Link]
11
[Link]
12
htps://[Link]/fr-fr/topics/cyber-athank you
13
htps://[Link]/2018/07/04/les-10-types-de-cyberataques-les-plus-courants/
14
htps://[Link]/fr-fr/topics/cyber-athanks
In addition to cybercrime, cyberattacks can also be associated with war.
cybernetics or cyberterrorism, like hacktivists. The motivations can vary,
In other words. And within these motivations, we find three main categories:
criminal, political and personal. Pirates motivated by criminal motives seek
a financial gain through money theft, data theft, or disruption of activities.
even, people motivated by personal grievances, like long-time employees or
current dissatisfied individuals will seize money, data, or a simple chance to interrupt the
system of a company. However, they mainly seek to take revenge. The hackers
whose socio-political motivations seek to draw attention to their causes. In
consequently, they ensure that their attacks known to the public - this is called
also hacktivism. Among the other motivations for cyber attacks, espionage can be mentioned.
industrial (with the aim of gaining an unfair advantage over competitors) and the challenge
intellectual.15
Criminal organizations, state actors, and individuals launch
cyberattacks against companies. One of the ways to classify the risks of cyberattack
consist of distinguishing external threats from internal threats. External cyber threats
including: organized criminals or criminal groups, professional pirates, such as
state-sponsored actors, amateur hackers, including hacktivists.
internal threats come from users who have legitimate and authorized access to the
company assets and deliberately or accidentally abuse them; in particular: the
negligent employees regarding security policies and procedures, current employees
former dissatisfied ones, business partners, clients, contractors or
suppliers with access to the system16.
Cyberattacks occur when organizations, actors on behalf of
of a state or private individuals want to seize one or more things, such as:
the company's financial data, customer lists, financial data
regarding clients, customer databases, including information
personally identifiable information (PII), email addresses, and identification documents
for login sessions, all intellectual property, such as trade secrets
or product designs, access to IT infrastructure, services
computer science, to accept financial payments, personal data, the
possibility to infiltrate government departments and government agencies17.
In today's connected digital environment, cybercriminals use tools
sophisticated to launch cyberattacks against companies. Their attack targets
includes personal computers, computer networks, infrastructure
computer science and computer systems18. The common types of cyberattacks are the
following:19
15
Tenth United Nations Congress, in Vienna, under the title 'the prevention of crime and the treatment of
"delinquents", [10 – 17 April 2000], available at (accessed on 12/11/2004).
16
H. ALTERMAN et A. BLOCH : La Fraude Informatique (Paris, Gaz. Palais), [3 sep. 1988] p. 530
17
Derived from the English 'Cyberspace', a contraction of the words 'Cybernetics' and 'Space', this term has been
introduced for the first time by the American author William Gibson in his science fiction novel "
Neuromancer, published in 1984.
18
LEBERT (M-F.), « De l'imprimé à Internet », thèse Paris, éd. 00h00, [1999].
19
CARBONNIER (J.), « Sociologie juridique », éd. A. Colin, [1972], éd. PUF, coll. Thémis, Paris, [1978],
Refondue coll. Quadrige, [1994] and [2004].
Backdoor Trojans: a Trojan creates a backdoor
vulnerable in the system the victim, allowing the hacker to gain control of it
distance and almost total. Frequently used to connect a group of computers of
victims, in a bot network or Zombie network, hackers can take advantage of
of the Trojan horse for other cybercrimes.
Cross-Site Scripting (XSS) attack: cross-site scripting attacks insert code
malicious in a legitimate website or application script in order to obtain
user information, often using third-party web resources. The
pirates frequently use JavaScript for XSS attacks, but Microsoft
VCScript, ActiveX, and Adobe Flash can also be used.
Denial of service (DoS) attack and distributed denial of service (DDoS) attack
flood the resources of a system, overwhelming them and preventing responses to
service requests, which reduces the operational capacity of the system, the
rendering it unavailable for legitimate users. Often, this type of attack sets up
another attack.
Tunneling of domain name systems (DNS): cybercriminals use
DNS tunneling, a transactional protocol, for exchanging data
applications, such as silent mode data extraction or establishing
from a communication channel with an unknown server, similar to the exchange of
command and control (C&C) as an example.
Malware: This is malicious software that can compromise systems.
inoperable infected. Most variants of malware destroy the
data by deleting or erasing the essential files for operation of the
operating system.
Phishing: The scam through phishing attempts to steal identifiers or
sensitive user data such as credit card numbers. In this case,
Fraudsters send users emails or SMS designed to look like
to come from a legitimate source code, using fake hyperlinks.
Ransomware: ransomware is a sophisticated malware that takes advantage
the weaknesses of the system, using enhanced encryption to retain the
data or the system functionality held hostage. Cybercriminals use
ransomware to demand a payment in exchange for the release of the system. A
A recent development with ransomware is the addition of extortion tactics.
SQL Injection: Attacks using Structured Query Language injection
SQL) integrate malicious code into vulnerable applications, producing
final results of database queries and executing commands or
similar actions that the user did not request.
Zero-day exploit: Zero-day attacks take advantage of unknown vulnerabilities of
hardware and software. These vulnerabilities can exist for days, months
or years before developers became aware of these vulnerabilities.
Man-in-the-middle (MitM) attacks: in this type of attack, a hacker
computing intercepts communication between two parties to steal or modify
information.
Password attacks: password attacks use various methods,
such as brute force or dictionary attacks, to guess or decrypt the
passwords and gain unauthorized access to computer systems.
Ping of Death Attack: Ping of Death attacks involve sending packets of
oversized data to a computer, causing it to crash or become unresponsive.
In case of success, cyberattacks can harm businesses. They can
cause a valuable unavailability, manipulations or data losses, and
loss of money through ransom. Additionally, downtime can lead to
major service interruptions and financial losses. For example:
DoS, DDoS, and malware attacks can cause crashes of
system or server.
DNS tunneling or SQL injection attacks have the ability to modify,
delete, insert, or steal data within a system.
Phishing attacks and zero-day exploits allow hackers
to enter a system to cause damage or steal valuable items
information.
Phishing attacks and zero-day exploits enable hackers
to enter a system to cause damage or steal valuable things
information.
Ransomware attacks can disable a system until
The company pays a ransom to the hacker.
For example, Darkside, a ransomware gang, attacked Colonial Pipeline, a
large American network of refined product pipelines, on April 29, 2021. Through
of a virtual private network (VPN) and a compromised password (external link to [Link]),
this pipeline cyberattack breached the company's networks and disrupted the
pipeline operations. Indeed, DarkSide has shut down the pipeline that transports 45% of the gas, from
diesel and aviation fuel that is shipped to the east coast of the United States. Quickly after
the pipeline blockage, the company received a ransom demand of nearly 5 million
dollars in cryptocurrency Bitcoin, eventually paid by the CEO of Colonial Pipeline
external to [Link]). Following this mishap, Colonial Pipeline hired a company to
third-party cybersecurity and informed federal agencies and U.S. authorities20.
Cybersecurity measures, such as firewalls, antivirus software, and encryption,
can help protect against cyberattacks. It is important to stay informed about the
latest threats and to follow best practices in cybersecurity in order to
minimize the risk of a cyber attack.
The United Nations adopted a convention to combat the use of ICT for purposes
criminals21.
The fight against data piracy is an important issue for states, which have taken measures to
national cybersecurity strategies to address it. These national strategies
aim to protect citizens and businesses from cyberattacks and to reduce
threat, the impact and victimization of cybercrime. They include measures
to strengthen the security of information systems, raise users' awareness of the risks
related to cybersecurity, and to combat data hacking. States are also working
in collaboration with international organizations such as INTERPOL to combat
WATIN-AUGOUARD (M.), Preface of the book "Cybercrime Global Challenge", VII.
20

CHAWKI (M.), "Essay on the Notion of Cybercrime", IEHEI, [2006], p. 6.


21
against cybercrime on a global [Link], on the other hand, has a strategy of
Cybersecurity 2020 - 2025. This strategy aims to direct and manage the national cyberspace.
identifying the parties involved and supporting coordination among them. It also aims to
prevent cyber threats and improve the country's resilience against these threats by
strengthening national capacities, raising awareness and protecting
vital information infrastructures. To achieve these objectives, the strategy focuses on 5 axes
key elements, including the establishment of sectoral cybersecurity strategies,
the improvement of the legal and regulatory framework, the strengthening of skills, the
promotion of cybersecurity culture as well as mastering the standards and
technologies related to digital security.
In response to these national strategies to combat cybercrime and with the aim of building
a logical reasoning around our research topic raises the question of knowing whether
To what extent does the legal framework for combating cybercrime in Tunisia respond to the...
challenges of data protection? To address this issue, we will look at
to what extent does this legal framework effectively address the fight against piracy of
data (I) before studying its weaknesses (II).
First part. State of Tunisian legislation on cybercrime in the face of
data protection.
In this section, Tunisian legislation will be presented in relation to its reactions against the
cybercrime affecting data. Thus, we will expose the legal measures and
regulations on cybercrime in relation to data protection (Chapter I) and the
regulatory, control, and enforcement agencies involved in the fight against the
cybercrimes (chapter II).

Chapter I. Legal and regulatory measures on cybercrime in the face of


data protection
The legal and regulatory measures on cybercrime in the face of protection of
data in Tunisian law directly leads us to reflect on preventive measures
and the repressive measures.

Section I. preventive measures


In this section, we will address the legislative aspect of attacks on information systems and
data. With the development and generalization of computer systems in
In all sectors of society, the judicial system had to adapt to new offenses.
and offenses and implement measures to address these phenomena. Thus, here are the
main laws on the subject without claiming to be exhaustive:
Law No. 99-89 of August 2, 1999 amending and supplementing certain provisions of the code
penal, in particular in its articles 199 bis and 199 ter
Chapter 6 of the telecommunications code
Chapter 7 of the law on exchanges and electronic commerce
Law on Electronic Funds Transfer
Law on the fight against cyber terrorism and money laundering ...
The European Convention on Cybercrime of November 23, 2001, convention
African Cybersecurity, Arab Convention ......
However, the Tunisian legislator, in the interest of modernizing cybercrime, has
promulgated Decree-Law No. 2022-54 of September 13, 2022, concerning the fight against
infractions related to information and communication systems that contain
penal provisions aimed at the protection of information systems and data. In
In principle, only the law creates offenses and determines the penalties applicable to them.
virtue of the principle 'No crime, no punishment without law'.

Paragraph 1. Decree-law No. 2023-17 of March 11, 2023, relating to cybersecurity

1.1. The measure of mandatory audit

The Decree-Law No. 2023-17 of March 11, 2023, regarding cybersecurity establishes as a principle
the obligation to submit to the mandatory periodic audit applicable to public bodies
and not public except for the networks of the ministries of defense and interior that follow
22
:
Public telecommunications network operators and suppliers of
telecommunications and internet services,
-Les entreprises dont les réseaux informatiques sont interconnectés à travers des
telecommunication networks
The providers of hosting and cloud computing services.
Companies that process personal data through automated means
their users in the context of providing their services through networks
telecommunications.
Critical digital infrastructure

The periodic audit procedure is scheduled for each year and organized by articles 7 to
9 of Decree-Law No. 2023-17 of March 11, 2023, relating to cybersecurity.
1.2. The measure of information
The Decree-Law No. 2023-17 of March 11, 2023, requires all public or private organizations to inform
the ANC from any attack, intrusion or disturbance of their system or network.
1.3. The security measure
Decree-Law No. 2023-17 of March 11, 2023, requires all public or private organizations to
comply with the security measures established by the ANC.
1.4. The granting of the secure label measure

The Decree-Law No. 2023-17 of March 11, 2023, assigns the ANC the responsibility of awarding the 'secured' label.

to each software or electronic equipment at the request of the developer or


the importer. This label, optional, is renewed every three years, and can be withdrawn before

22
Article 6 of Decree-Law No. 2023-17 of March 11, 2023, relating to cybersecurity
the expiration of the validity period in case of modification of technical characteristics
or the occurrence of technological change that introduces vulnerabilities to the software or
electronic equipment.

The procedures and conditions for granting the "secured" label and its withdrawal will be determined by
Decree of the Minister in charge of the Communications Technology portfolio.

A national register of software and electronic equipment that have obtained the label "
"secured" will be published by the ANC and updated regularly.

Under this decree, the structures that manage important digital infrastructures
Vital entities are required to use software and equipment that have the 'secure' label, to have their
main hosting center and a backup center with a provider of
cloud computing services that have obtained the label, and comply with the measures and the
necessary procedures to ensure business continuity and protect databases
sensitive information whose compromise could affect national security in case of a crisis
cybernetics, according to a procedure manual approved by decree at the proposal of
Minister in charge of Communication Technologies.

The ANC will also be responsible for granting, renewing, and withdrawing the label "Supplier of
government cloud computing services (G-cloud)" and the label "Supplier of
National cloud computing services (N-cloud) to service providers
housing after consultation with the ministers of national defense and the interior.

The label 'Government Cloud Services Provider (G-cloud)' and the


Label 'National Cloud Service Provider (N-cloud)' is renewed
annually, according to the same decree.

The ANC is also required to develop and implement the national response plan.
to the cyber emergency services in collaboration with the response centers
sectoral cyber emergencies public and private, set up the modalities
techniques necessary for the early detection of incidents and attacks
cybernetics that threaten the cyber space, set up and exploit the
reporting channels for incidents and cyber attacks, reduce the
repercussions of incidents and cyber attacks and ensure the continuity of
the activity and the quick recovery of their effects, or also to alert the institutions, the
administrations and individuals, strengthen information systems, manage the
incidents, organize and coordinate efforts to address weaknesses,
study, analyze them and anticipate appropriate solutions.
Paragraph 2. Decree No. 2008-2639 of July 21, 2008, setting the conditions and procedures
import and marketing of means or services of encryption through
telecommunication networks

Le décret n° 2008-2639 du 21 juillet 2008 soumet l’exercice de certaines activités de cryptage


through telecommunications networks under authorization regime except for encryption
operated by the ministries of sovereignty and diplomatic and consular missions23.
2.1. Measurement of import and marketing
The importation and marketing of commonly used encryption means approved by
the ANCE24:
They are not subject to the authorization of the ANCE.
Establishment by ANCE of an updated list of these approved means
accessible to the public

The importation and marketing of other encryption means not provided for
in this list are subject to the authorization of the ANCE based on the certificate
of approval.
The encryption methods imported by companies on a temporary basis to meet their needs
personal needs are not subject to authorization and technical approval.
-La liste de ces entreprises est établie et actualisée par l ’ANCE
2.2. Approval measurement
The approval of encryption means, except for encryption means imported by
temporary companies to meet their own needs, of which a list is
published by the ANCE is carried out with the authorization of the ANCE by certificate of approval
and the establishment of a publicly accessible list of approved means25.
The ANCE checks the following elements in the approval:
The technical rules in the field of use of encryption means
The malfunctioning of the encryption method and public networks
telecommunications
The security of data related to users.
2.3. The control measure
Decree No. 2008-2639 of July 21, 2008 allocates to the ministers of national defense and
within the following prerogatives:

23
Article 4 of Decree No. 2008-2639 of July 21, 2008, setting the conditions and procedures
importation and marketing of means or services of encryption through the
telecommunications networks
article 1
24

article 3
25
Ability to consult all documents related to equipment and systems
electronic devices that allow encrypting data or examining said equipment and
systems
Intervene with any person holding these equipment or systems
Obligation for these individuals to deliver these equipment or systems to the
first request and to comply with the measures

Paragraph 3. Government decree n° 2020-48 of January 23, 2020, relating to


import and marketing approval procedures for equipment
telecommunication terminals and radio equipment

The government decree n°2020-48 of January 23, 2020, has subjected the import and the
commercialization of terminal equipment and radiocommunication equipment manufactured in
Tunisia or imported connected or not to a public network, or intended for public use at
the exception of terminal telecommunications equipment and equipment
radio frequencies used by the Ministry of National Defense and the Ministry of the Interior
to approval regimes, compliance control, and technical inspection.
3.1. The equipment certification measurement
The granting by the CERT of a renewable homologation certificate by type, brand and
model.
The approval is granted based on criteria/requirements established by the CERT/Single Window.
given certain imperatives:
The protection of public telecommunications networks against any damage
The electromagnetic compatibility specific to the terminal equipment
The electronic security of the terminal equipment
The effects of non-ionizing rays
The rules for the use and exploitation of the radio frequency spectrum
The malfunctioning of the terminal equipment with public networks
telecommunications
The safety of users and personnel operating the equipment
The safety of users and operating personnel

Any modification to the approved equipment requires a new request for


the certification of the equipment.

3.2. The control measure of compliance


Government decree n°2020-48 of January 23, 2020, has subjected terminal equipment
and those radioelectrical items imported for personal needs, or those imported for
temporary; those imported as part of the execution of public procurement contracts for the
accounts of telecommunications operators or public structures and enterprises for
their use; the prototypes of the terminal equipment of telecommunications and
radio equipment imported by individuals, legal entities, or startups,
in development; spare parts for terminal equipment of
telecommunications and certified radio equipment; the equipment
telecommunication terminals and imported radio equipment
in the context of the seller's warranty regime to the conformity control regime.
The verification criteria are as follows:
Technical requirements for interoperability with public networks
Rules for the use of radio frequencies
Only the following devices are allowed to be imported by individuals for
their own need:
GSM Terminal, Simple telephone station, DECT telephone station or
{"CORDLESS":"CORDLESS","Télécopieur":"Fax machine","Récepteur TV-SAT":"TV-SAT receiver","Convertisseur TV-SAT":"TV-SAT converter","Antenne":"Antenna"}

parabolic for TV-SAT and modem...


3.3. Technical control measures
Government decree no. 2020-48 of January 23, 2020, has subjected the equipment
radioelectrics under a technical control regime with the ANF.
The ANF has the following responsibilities:

The control of the technical conditions of radio equipment and the


protection of the use of radio frequencies
The ANF has the power of approval/authorization regarding radio equipment on
:
The activities of manufacturing, importing, installing, and operating equipment
using frequencies
Any transfer, modification or destruction of this equipment
The ANF and the ministers of the interior and defense provide their opinion on the minister's decree.
in charge of telecommunications setting the maximum power and the range limit of
radio devices.
Low-power and short-range radio equipment is not subject to
with the authorization of the minister responsible for telecommunications.

Paragraph 4. Law No. 2000-83 of August 9, 2000, concerning exchanges and commerce
electronic
One of the essential aspects of cybersecurity is the security of exchanges in the
cyberspace.
This law regulates the legal framework for certification service providers.
electronics.
Access to supplier activities of certification services:
The certification service provider is a natural or legal person of
Tunisian nationality responsible for issuing, delivering, and preserving
electronic certificates
Carries out its activities with the authorization of the ANCE and a specifications document.
The legal obligations of the supplier
Obligation to ensure the reliability and confidentiality of the means of issuance and of the
conservation and management of certificates
Obligation to maintain a register of electronic certificates
Obligation to ensure the confidentiality of certificate data and data
personal and related

Paragraph 5. Decree No. 2008-3026 of September 15, 2008, setting the conditions
General operating conditions of public telecommunications networks and networks
access

This decree provides information on the obligations of public network operators.


telecommunications to provide their services under the best economic conditions. It
also inform about the conditions for the installation and operation of these networks.
This decree also states that public telecommunications networks and networks
access must be exploited under fair competition conditions, in accordance with the
legality. Public telecommunications network operators are required to render
their services under the best economic conditions.
The operators take the necessary measures to ensure the neutrality of their services.
regarding the content of the messages transmitted over its network and the confidentiality of
correspondences.
The operator takes the necessary measures to ensure protection, integrity, and
privacy of personal data that it holds, processes, or records on the
subscriber identification module

Paragraph 5. Decree No. 2014-4773 of December 26, 2014, setting the conditions and
procedures for granting authorization for internet service provider activity

This decree has subjected the activity of providing internet services to the authorization regime granted by
decision of the Minister responsible for telecommunications and after the opinion of the Minister of the Interior,
the National Telecommunications Authority and the advisory commission created in
the occurrence.

5.1. The obligations of the service provider towards the State

make available to the ministry in charge of telecommunications and the National Instance of
Telecommunications all information relating to technical order issues,
operational, financial and accounting in accordance with the terms set by the authority,
submit for approval to the National Telecommunications Authority the contract model
service to be concluded with clients,

to be able to meet the needs of national defense and public security and safety
in accordance with the legislation and regulations in force, - provide the competent authorities
the means necessary for the execution of its functions, and in this context, the supplier of
Internet services must comply with the instructions of judicial, military, and security authorities.
national, - respect the conventions and international treaties ratified by Tunisia. inform the
Publish the general conditions of offers and services, publish the rates for the supply of each.
service category. Internet service providers are required before marketing
of the service, to present a notice advertising the rates according to the following conditions: - a
A copy of the notice is sent to the national telecommunications authority at least fifteen
(15) days before the marketing of any new offer being considered - a copy of the notice
The definitive advertising is made available to the public electronically for free consultation.
and in all the areas of the relevant services
5.2. The obligations of the service provider towards the clients

provide access to Internet services to all applicants using technical solutions the
more effective, - to provide subscribers with clear information regarding the subject and the
access methods to the service and support them in case of request,

Provide a response service to subscribers' questions and requests and their follow-up through a
permanent focal point. Take the necessary measures to ensure the quality of the services that it
provide subscribers and respect their rights resulting from the service contract concluded with them, to
this effect he is required to take the necessary measures to:

ensure the neutrality of its services, confidentiality, and integrity of the data transmitted in
the framework of the services provided in accordance with the applicable legislation and regulations

ensure the protection, security, and confidentiality of personal data they hold
you process or record at the subscriber identification unit in accordance with the legislation and
regulations in force
the non-disclosure to third parties of the data transmitted or held, relating to subscribers and
notably those that are nominative, and this without the consent of the concerned subscriber subject to the
prescriptions required by national defense and public security and the prerogatives of the authority
judicial and by the legislation in force

guarantee the right of any subscriber not to appear in any nominative database of
supplier except for those related to billing, - guarantee the right of every subscriber to
to oppose the use of his invoicing data for prospecting purposes
commercial

guarantee the right of any subscriber to rectify the personal data concerning them or to
to complete them, clarify them, update them, or delete them

to respect its obligations related to confidentiality and neutrality in the context


of its contractual relations with service marketing companies - to provide a service
support and information on the nature of services to be offered to its subscribers while ensuring the
protection of their personal data across the Internet network - adopt the
solutions and mechanisms that ensure a secure navigation service
children on the internet

define the secure navigation service for children on the Internet and provide for it in the
service contracts as a service of choice that depends on the client's will - give to the
subscribers the ability to change their choice regarding the secure browsing service of
children on the Internet and this through simple and instant mechanisms.
ensure the continuity of services, according to the nature of the contracts to be concluded with its subscribers, and
ensuring the continuous operation of the equipment and computer programs used
and to take the necessary measures to maintain the level of service quality indicators
Internet provided by the standards in force at the national and international level.

Paragraph 6. Decree No. 2014-412 of January 16, 2014, setting the conditions and the
procedures for granting authorization for the exercise of the activity of operator of a
virtual telecommunications network
To obtain permission to operate as a virtual network operator
Telecommunications in Tunisia, the following conditions and procedures must be fulfilled:
6.1. Conditions:
The person representing the virtual operator must be of Tunisian nationality and hold a
higher education diploma or equivalent
The activity of virtual telecommunications network operator is subject to authorization from
Minister responsible for telecommunications

6.2. Procedures:
The operation of a virtual telecommunications network is subject to prior authorization.
of the minister in charge of telecommunications.

To obtain permission, the interested parties must submit a request to the Ministry.
communication technologies.
The request must include a description of the technical and financial means available.
applicant's disposition, as well as a business plan.
The Ministry of Communication Technologies will review the request and may
request additional information or documents.
If the request is approved, the ministry will issue a permit to the applicant.
6.3. The obligations of the virtual operator
The responsibilities of a virtual telecommunications network operator in Tunisia
may include the following elements:
Provide telecommunications services to customers using the physical network
from an authorized operator, such as Tunisie Telecom
Ensure that the services provided are of high quality and meet the needs of
clients
To comply with the regulations and laws governing the telecommunications sector.
in Tunisia, including obtaining the necessary permits and licenses
Contribute to the development of the telecommunications sector in Tunisia by
investing in infrastructure and promoting the use of ICT
Participate in initiatives aimed at improving the country's competitiveness and encouraging
investments
Cooperate with other operators in the sector, as in the case of portability.
mobile numbers, made effective among all operators in Tunisia in 2017
Ensure the security and confidentiality of customer data and comply with the regulations
data protection
It is important to note that the specific responsibilities of a virtual operator
may vary depending on the terms of its authorization and the regulations in
in force at that moment.
Paragraph 7. Law No. 2005-51 of June 27, 2005, relating to electronic fund transfers
It should be noted that in Tunisia, all monetary flows must, except in special cases, obtain
the approval of the Central Bank of Tunisia (BCT)
the issuer must provide the public with a document free of charge that includes the
contractual conditions for the use of the electronic transfer instrument.
The law on electronic funds transfers states that the sender must verify the identity
of the beneficiary and check the electronic transfer instrument before carrying out the operation.
Tunisian banks are required to identify and verify the identity of clients.
occasional and, where applicable, final beneficiaries
For international transfers through money transfer agencies, the applicant must provide
identification documents and comply with legal obligations
It is possible that some banks have their own specific procedures for verification.
the identity of the beneficiaries before electronic fund transfers.
Paragraph 8. Law No. 94-36 of February 24, 1994, concerning literary property and
artistic as modified by law n°2009-33 of June 23, 2009
Law No. 94-36 of February 24, 1994 regulates the protection of works protected by law.
author coming from digitization and networks against threats.
The protection of works takes place at three levels:
Legal protection by copyright
Protection technique through access control mechanisms, usage, and traceability
Legal protection of technical measures against their circumvention
L'INNORPI plays the role of regulator in the area of technical protection measures of
works.
The different titles of industrial property are:
The invention patent: The patent can be filed in Arabic, French, or English.
with the INNORPI. The invention must comply with patentability rules, namely
novelty, inventive activity and industrial application, but the INNORPI does not verify
not these conditions. Patents are granted at the risk and peril of the applicants, it
It is advisable to conduct a prior search for prior art to avoid any
legal insecurity. The patent is valid for twenty years from the filing date of the
request. Tunisia joined the Patent Cooperation Treaty in 2001.
(PCT). A foreign applicant can therefore extend the protection of their title in Tunisia.
through an international patent (twelve-month priority period from the first)
deposit). However, Tunisia applies the principle of international exhaustion: the
exclusive right does not extend to the importation of the product into Tunisian territory
patented after this product was lawfully put on the market
any country (by the patent holder or with their consent). From
Plus, since a 2017 agreement between the Tunisian government and the European Office.
European patents can be validated in Tunisia.
The brand: To be registered with INNORPI, the brand must be
distinctive, lawful and available. It is possible to conduct a prior art search.
based on TMView. INNORPI can provide this service upon request,
for a fee. The registered trademark is protected for ten years, renewable.
indefinitely. The Madrid Protocol is applicable in Tunisia and allows for the extension
of rights from or to Tunisia (six-month priority period starting from
first deposit.
The design and model: Since INNORPI does not conduct a substantive examination, it is solely up to the...
ensuring compliance with the validity conditions of novelty and the
specific character. The protection cannot exceed fifteen years. The Hague system
allows the extension of titles from or to Tunisia (six-month priority period).
Geographical indications: Tunisia has been a member of the arrangement since 1973.
Lisbon concerning the protection of origin designations and their registration
international. This is supplemented by geographical indications as well as indications
of origin (law n°99-57 of June 28, 1999). A national development plan of
craftsmanship 2017-2021 was launched, with the objectives of creating jobs,
rehabilitation of artisanal establishments and the increase of the contribution of
sector in GDP at 6%.
Note: The country also has legislation on collective trademarks and, for the
environmental protection, from a Tunisian Ecolabel.
Tunisia has been a member of WIPO since 1975 and has ratified the Berne Convention for the
protection of literary and artistic works. The author as well as performing artists or
performers enjoy moral and property rights. The Tunisian Office for the Protection of
copyrights and neighboring rights (OTDAV), an establishment under the supervision of the Ministry of
culture, sets the financial and material conditions for the exploitation of works, and manages the
perception and distribution of royalties. Protection is granted to the work simply by the fact
since its creation. Nevertheless, OTDAV provides creators with a deposit service
works, which allows us to date their creation.
Paragraph 9. Organic Law No. 2004-63 of July 27, 2004, concerning the protection of
personal data
9.1. The obligations of the data controller
Organic law no. 2004 - 63 has placed the responsibility for data processing on the data controller.
personal a set of legal obligations:
9.1.1. The obligation of purpose
The purpose limitation requirement implies that processing involves:

The prior determination of the purposes of the processing


The treatments must be necessary given the stated purposes.
Prohibition of exceeding the purposes of the processing displayed for other reasons.
declared
Principle of proportionality between the content and the quality of the data processed and the
treatment objectives
The law provides for exceptions:
consent of the person; the processing is necessary to preserve an interest
vital for the person; the treatment is carried out for scientific purposes
9.1.2. The obligation of data security and confidentiality
Security is designed with evolving best practices in mind.
This obligation requires the implementation of preventive and corrective material measures and solutions.
and software.
It is a result obligation.

The Obligation of Security according to the GDPR (art 32)

obligation to implement technical measures and


appropriate organizational measures to ensure a level of
security adapted to the risk
The use of the following techniques: pseudonymization,
data encryption; the means to ensure the
confidentiality, integrity, availability, and resilience of
systems and processing services; a procedure aimed at
to test, analyze and regularly evaluate the effectiveness of
technical and organizational measures to ensure security
of the treatment.
Given several parameters such as: the state of
knowledge, implementation costs and the nature of the
scope, context, and purposes of the processing

9.1.3. The obligation to update processed data


Obligation to update the data.
Obligation to correct them in case of error.
Obligation to delete them at the request of the person concerned and in certain cases
provided by law.
The update occurs even in the absence of a request from the person concerned.

9.1.4. The obligation to notify


The GDPR provides for a notification obligation to the authority.
of monitoring DP violations (art 33)
Obligation to notify these violations as soon as possible and if
possible within 72 hours
Obligation to document everything related to the violation and
the measures taken
Obligation to inform the affected person of the violation if
it is likely to pose a high risk to rights and
freedoms of a natural person except in cases cited by
Article 34 especially if it has already taken corrective measures or in cases
disproportionate efforts...
9.2. The rights of the data subject

The organic law recognizes individuals who are subject to


of data processing certain rights. This concerns
essentially from:
Prior consent for processing
Right of access
Right of opposition
9.2.1. Prior consent for processing
Consent must accompany the entire process of
treatment: it is not only interested in the collection phase
data.
The person who consented to the processing may withdraw at
any time.
The Necessity of a new consent for processing
who has surpassed the form or purpose of the treatment already
was granted.
Consent must be prior to processing, explicit and by
write.
The law provides for exceptions: treatments in the interest
manifesto of the person; impossibility of contact or if the
contact requires disproportionate efforts...
9.2.2. the right of access
The person concerned has the right to access the data.
personal data processed in order to become aware of it,
take a copy, correct them, update them,
modify, or delete them.
It is a public order right. A right recognized to the person.
concerned, to her heirs and to her guardian.
It is a right that is exercised freely. It is exercised by a
written request with a response time of 1 month.
The law provides for exceptions: the processing is carried out for
purposes of scientific research; the treatments of certain
public figures; the reason for the limitation is related to the protection of
the person concerned or third parties
9.2.3. Right to object
The person concerned has the right to object to the processing,
communication or data transfer.
It is a conditional right: for valid, legitimate reasons and
serious under the control of the Instance.
The right of opposition has a suspensive effect.
The law provides for exceptions: the right to object does not apply.
when the processing is required by law or contract.
9.2.4. Right to data portability: art 20 GDPR
The person concerned has:
Right to receive the DPs concerning them in a structured format,
commonly used and machine-readable.
Right to transfer this data to another controller
treatment
Right to obtain that the DP be transmitted directly from a
responsible for processing to another, when this is
technically possible
These rights do not apply to the processing necessary for the performance
of a public interest mission or relating to the exercise of authority
public.

9.2.5. Right to be forgotten (to erasure): art 17 GDPR


The person concerned has the right to request the deletion of the DP in
the best deadlines.
The GDPR requires the data controller to delete the personal data in the
best deadlines in cases where: the DP are no longer necessary; withdrawal
of consent; exercise of the right of opposition.
This right does not apply if the processing is necessary for: the exercise
the right to freedom of expression and information; respect for
legal obligation; for archival purposes in the public interest, for purposes
for scientific or historical research or for statistical purposes...
The notification to each recipient of the DP of any correction or any
deletion of personal data completed.
9.3. Compliance

The implementation of GDPR compliance involves 6 steps.


steps (CNIL FR):
Appoint a pilot to govern the DPs: the delegate
for the protection of the DP

–Map the treatments of DPs


Identify the actions to be taken as a priority in the
conformity
Manage risks through the implementation of
the impact analysis related to protection of
data
-Organize internal processes: review the documents
contractual and internal procedures (GTC/GTU,
information blocks, notification of vulnerabilities
security, right of access...)...

Document compliance

Section 2. Repressive measures

We will address in this section the legislative aspect of the breach of information systems and
data. With the development and generalization of computer systems in
In all sectors of society, the judicial system has had to adapt to new offenses.
and offenses and implement measures to address these phenomena. Thus, here are the
main laws on the subject without claiming to be exhaustive:

Paragraph 1. Decree-Law No. 2023-17 of March 11, 2023, relating to cybersecurity

The decree-law No. 2023-17 of March 11, 2023 establishes sanctions for the following offenses:
1.1. Administrative sanctions
The minister in charge of communication technologies may, based on a motivated report from
the Agency, to downgrade the entities mentioned in Article 6 of this decree-law, and classified
at the first and second levels, and in the following cases:
The non-implementation of the mandatory and periodic security audit of the systems
information.
The failure to submit a protected electronic copy of the audit report to the Agency
within the deadline mentioned in Article 8 of this decree-law.
The non-implementation of the recommendations from the audit report or their partial implementation.
within a period not exceeding one year.
Failure to comply with the emergency measures prescribed by the national contact point for
the response to cyber emergencies or emergency response centers
cybernetics following the occurrence of an incident or a cyber attack.
-does not result from failures within the deadline mentioned in article 17 of this decree-
law.
The failure to create a cyber emergency response center or the non-
membership in cyber emergency response centers.
The non-compliance with the framework mentioned in Article 14 of this decree-law.

1.2. Financial sanctions

Several sanctions are also provided for in this decree in case of infringement; a
a fine of fifty thousand (50,000) dinars to one hundred thousand (100,000) dinars for the organizations

mentioned in Article 6 of this decree-law, and classified at the third level, and this
in the following cases:
The non-fulfillment of the mandatory and periodic security audit of the systems
of information.
The non-execution of the recommendations of the audit report or their execution
split within a period not exceeding one year.
The non-compliance with the emergency measures prescribed by the point of contact
national for the response to cyber emergencies or response centers
to the cybernetics emergency following the occurrence of an incident or a
cybernetic attack.
The non-compliance does not fall within the failures mentioned within the timeframe stated in Article 17 of this document.

decree-law.
The non-establishment of a cyber emergency response center or the non
membership in cyber emergency response centers.

Paragraph 2. Decree No. 2008-2639 of July 21, 2008, setting out the conditions and procedures
importing and marketing means or services of encryption through
telecommunication networks

The decree creates administrative sanctions for the following offenses:

- In case of a blatant failure to comply with the provisions of this decree, the minister in charge

telecommunications can pronounce the immediate suspension of the authorization, and the
regularization of the situation of the concerned offender within a period not exceeding
two months from the date of suspension.
- Encryption methods of all categories can be seized provisionally, without
compensation, by decision of the Minister of National Defense and the Minister of the Interior and
of local development if it turns out that the use of these means disrupts defense
national and public security, and from the minister of communication technologies if
it turns out that the use of these means disrupts the security of networks
telecommunications.

Paragraph 3. Law No. 2000-83 of August 9, 2000, concerning trade and commerce
electronics
The law creates sanctions for the following offenses:

3.1. Administrative sanctions


The authorization is revoked from the electronic certification service provider and its
activity is suspended if it has failed to meet its obligations set forth by this law or its texts
of application. The national agency for electronic certification withdraws the authorization after
audition of the concerned supplier.
3.2. Criminal sanctions
Any provider of certification services is punishable by a fine of 1,000 to 10,000 dinars.
electronics that did not comply with the provisions of the specifications set out in Article 12 of
the present law.
Anyone who engages in the activity of providing electronic certification services without
having obtained a prior authorization in accordance with article 11 of this law is punished
from a imprisonment of two months to three years and a fine of 1,000 to 10,000 dinars or
of one of these two penalties.
It is punishable by imprisonment of six months to two years and a fine of 1,000 to 10,000.
dinars or of one of these two penalties who willfully made false statements to
provider of electronic certification services as well as any party to which it has
asked to trust his signature.
It is punishable by imprisonment for six months to two years and a fine of 1,000 to 10,000.
dinars or one of these two penalties for anyone who illegitimately uses the elements of
personal encryption relating to the signature of others.
- Law No. 200-83 of August 9, 2000, concerning exchanges and electronic commerce 10 All
person violating the provisions of articles 25, 27, 29, of the second paragraph of
Article 31 of Article 34 and the first paragraph of Article 35 of this law is punished.
a fine of 500 to 5000 dinars.
Without prejudice to the provisions of the penal code, anyone who has abused the weakness or
l'ignorance d'une personne pour lui faire souscrire, dans le cadre d'une vente électronique, des
cash or credit commitments in any form will be punished by a
fine of 1000 to 20,000 dinars, when the circumstances show that this person was not
unable to appreciate the scope of the commitments she was making or to detect the tricks or
artifices deployed to convince her to subscribe or appear to show that she has been subjected to
a constraint.
Any person who contravenes the provisions of Articles 38 and 39 shall be punished by a fine.
from 1,000 to 10,000 dinars.

The certification service provider is punished under Article 254 of the Penal Code.
electronics and its agents who disclose, incite or participate in disclosing information
which are entrusted to them in the course of their activities, except for those of which
the publication or communication is authorized by the certificate holder in writing or by
electronic means or in the cases provided for by the legislation in force.
Without prejudice to the rights of victims to compensation, the minister responsible for commerce may carry out
transactions regarding the offenses provided for in Article 49 of this law and which are
observed in accordance with the provisions of this law.
Without prejudice to the rights of victims to compensation, the minister responsible for the oversight of the agency
The national electronic certification can carry out transactions concerning offenses.
provided for in Article 45 of this law, and which are established in accordance with the provisions of the
present law.
Without prejudice to the rights of others, the terms and procedures for the transactions are those provided for.
by the texts in force governing economic control, notably law no. 91-64 of July 29
1991 regarding competition and prices, along with the texts that have supplemented and amended it.

Paragraph 4. Decree No. 2014-4773 of December 26, 2014, setting the conditions and the
procedures for granting authorization for internet service provider activity

In the event of a serious failure or blatant breach of the provisions of this decree,
the Minister of Telecommunications, based on a report established by the National Authority
of Telecommunications, may pronounce the immediate suspension of the activity and summon
the internet service provider to present its observations related to the facts that it
are charged before the commission that establishes a motivated report with the regulation of the
operator's situation within a period not exceeding one month from the date of the
date of the suspension According to the provisions of Section 2 of Chapter 6 of the Code
telecommunications of penal sanctions, consisting either of fines or of
private penalties of freedom or both sanctions cumulatively whoever installs
You operate a public telecommunications network without having obtained the license and any
person who provides telecommunications services to the public without having obtained
the authorization or continues to provide the services after the withdrawal of said authorization.
The provisions of the Penal Code and the penalties provided for in its Article 253 apply to
Anyone who discloses, incites, or participates in the disclosure of the content of communications and
exchanges transmitted through telecommunications networks.
The Internet service provider may be subject to the criminal penalties provided for in the
legislations governing the press, literary and artistic property, competition and prices,
consumer protection and personal data protection in all cases
where it results from practices inherent to its activity an infringement of the provisions and rules
prescribed in these legislations.

Paragraph 5. Decree No. 2014-412 of January 16, 2014, setting the conditions and the
procedures for granting authorization to operate as an operator of a
virtual telecommunications network
This decree establishes administrative sanctions for the following offenses:
In the event of a serious failure or a blatant breach of the provisions of this decree,
the minister responsible for telecommunications, based on a report prepared by the authority
national telecommunications authority can pronounce the immediate suspension of activity and
summon the operator of the virtual telecommunications network to present its
observations related to the facts inflicted upon him before the commission that establishes a
motivated report regarding the resolution of the operator's situation within a period not exceeding
not a month from the date of the suspension.
The authorization is automatically withdrawn from the virtual network operator
telecommunications in the following cases: the dissolution or bankruptcy of the legal entity,
and the termination of the contract with public telecommunications network operators.
Paragraph 6. Law No. 2005-51 of June 27, 2005, on electronic funds transfer
This law establishes criminal sanctions for the following offenses:
Is punishable by ten years of imprisonment and a fine of ten thousand dinars anyone who:
-forge an electronic funds transfer instrument,
use a funds transfer electronic instrument with full knowledge
falsified
- knowingly accepted a transfer by the use of an instrument of
falsified electronic funds transfer.
Shall be punished with three years of imprisonment and a fine of three thousand dinars, anyone who
uses an electronic funds transfer instrument without the consent of its holder.
Paragraph 7. Law No. 94-36 of February 24, 1994, relating to literary property and
artistic as amended by law no. 2009-33 of June 23, 2009
This law aims to preserve the rights of creators. The provision of illegal means of implementation
the disposition of the public of protected works or objects is punished. Publishers and distributors of
Software dedicated to or used for this purpose is now liable for the offense of infringement.

Despite a well-established legal framework, Tunisia is a favorable market for


counterfeiting: a limited purchasing power of the local population, a very informal market
important, a tourist destination, vulnerable borders. The fields of luxury, of
sports articles and textiles are heavily affected by counterfeiting, most often imported,
but other sectors such as automotive spare parts, cosmetics, products
electric vehicles are also strongly affected and pose great dangers for
uninformed consumers. Like its neighbors, Tunisia also experiences.
great difficulties in the face of the importance of piracy in the artistic fields
IT.
The owner of a prior trademark (or the beneficiary of an exclusive exploitation right)
can oppose the registration of a trademark within two months following its
publication. The opposition system is based on conciliation, and the majority of disputes are
settled with INNORPI through an amicable agreement.
The Customs Code gives customs services investigative powers and
quite a broad finding regarding counterfeiting. They can, on their own initiative,
suspend the customs clearance of goods and proceed with seizures. The owner of a
registered trademark can claim from customs (requirement of serious grounds) the
suspension of customs clearance for the import of goods allegedly infringing.
Customs services note that the goods indeed correspond to those
indicated in the request, they proceed to the retention of these goods. They transmit
then all the information at their disposal to the rights holder, who has a
a deadline of ten days to initiate legal action.
Counterfeiting engages the civil and criminal liability of its author. The president of
a court, seized in summary proceedings, can prohibit under penalty the continuation of infringing acts (or
supposed as such). It can also make the continuation of these acts contingent on the establishment of
guarantees allowing for the compensation of the brand owner. If the judgment recognizes
that the counterfeit goods will be ordered for destruction by the court, or their
exclusion from the commercial circuit (provided that it does not infringe on the rights of the holder
from the brand). The simple offense of counterfeiting is punishable by a fine of 5,000 to 50,000 dinars.
for a patent, and from 10,000 to 50,000 dinars for a trademark [between 1,500 and 15,000 euros].
In the case of a repeat offence, a prison sentence of one to six months may be imposed in addition to
the fine that is doubled. Furthermore, an action for unfair competition can be
attempted by the trademark holder if they prove that there are facts distinct from the infringement
they caused harm (especially in cases where the trademark has not been registered in
Tunisia). Alternative dispute resolution: Tunisian legislation on
industrial property provides that the provisions relating to counterfeiting and its penalties
does not hinder recourse to arbitration. Such recourse is governed by the Code of
the arbitration.
Within the Ministry of Commerce, the Directorate General of Competition and Investigations
Economic measures include, among others, the fight against counterfeiting and the enforcement of standards.
It can trigger investigations that sometimes lead to sanctions. The Ministry of
commerce oversees the National Council for the Fight Against Counterfeiting, a
public-private partnership for consulting purposes. In addition to its awareness-raising duties and
cooperation, he is mainly responsible for giving his opinion on national programs
anti-counterfeiting efforts, and to coordinate the different actors.
Paragraph 8. Organic Law No. 2004-63 of July 27, 2004, concerning the protection of
personal data
This law provides for penalties in case of violations of its following provisions:
Administrative sanctions:
Withdrawal or suspension of the authorization
Prohibition of treatment
Criminal sanctions:

Fines
Imprisonment
Paragraph 9. Telecommunications Code
The aforementioned code suppresses a number of behaviors during the use of
telecommunications in its chapter 6. This repression is provided for in articles 81, 82, 83,
84, 85, 86, 87.
Article 89 of the code under review provides for a special procedure for offenses in
communication matter. Thus, at the end of the aforementioned article, "the offenses
in telecommunications matters provided for in article 81 give rise to a procedure of
transaction. The Minister in charge of telecommunications can negotiate with the offender and
to impose a transaction fine.
Paragraph 10. Decree-Law No. 2022-54 of September 13, 2022, concerning the fight against
infractions related to information and communication systems

Decree-Law No. 2022-54 provides for the following offenses:


Violation of the integrity of information systems and data and their
confidentiality (articles 16 - 21);
Computer fraud (article 22);
Information forgery (article 23);
Rumors and false news (Article 24), which is not provided for by the Convention of
Budapest
Illegal access to protected content (Article 25);
Exploitation of children (Article 26);
Repression of the failure to comply with the obligations of electronic evidence collection
(articles 27-31);
Criminal liability of legal entities and their leaders (Article 32).

Damage caused to computer systems in the context of a terrorist project


Article 14 of Organic Law No. 2015-26 of August 7, 2015, relating to the fight against
terrorism and the repression of money laundering.
Disclosure of the content of communications and electronic exchanges (article
85 of the Telecommunications Code.
Infractions related to intellectual property and related rights
(particularly articles 50 to 55 of law No. 94-36 of February 24, 1994 relating to the
literary and artistic property, three other laws adopted in 2001 regulating the
protection of trademarks, trade marks, and service marks; the protection of
designs and industrial models; and the protection of configuration schematics
integrated circuits).
Paragraph 11. Penal Code
This is law no. 99-89 of August 2, 1999, amending certain provisions of the penal code.
notably in its articles 199 bis 199 ter. Indeed, this law punishes only partially
the offenses provided for by the Budapest Convention.
Thus, this law incriminates four types of offenses, namely:
The offense of unauthorized access and fraudulent maintenance in a computer system
The offense of introducing data into a computer system
The offense of computer forgery

Chapter 2: The regulatory, control, and enforcement bodies involved in the


fight against cyber crimes
In this chapter, we will present the main technical agencies existing within the framework of the fight.
against cybercrimes affecting data (section I) and the competent jurisdictions for their suppression
(section2).

Section 1. The technical agencies

Paragraph I. At the national level

Cybercrime is recognized by many experts as the new form of


21st century crime.
th
Therefore, to control it, Tunisia has set up new bodies.
of struggle. Here are a few examples:

We will quickly develop their roles and the actions they can take.

1.1. The national cybersecurity agency

The national cybersecurity agency conducts a general control of the systems


informatics and networks pertaining to various public and private organizations. It is
responsible for the following tasks (Article 5 of Decree-Law No. 2023-17 of March 11, 2023, relating to
cybersecurity
):
Develop and update governance and security policies and mechanisms.
of national cyber space and make it available to the sectors and
concerned organizations.
Monitor the implementation of action plans for the security of cyberspace
national regarding:
Proactive measures to prevent deliberate and accidental threats on
the national cyber space.
Preventive measures to protect against cyber risks.
The mechanisms for the instant detection and reporting of incidents and of
cyber attacks.
The urgent response in case of emergencies to deal with cyber attacks and
mitigate their impacts.
The rapid recovery following the effects of incidents and cyberattacks to ensure
the continuity of the activity.
The investigation and digital inquiry to diagnose incidents and determine
the responsibilities related to cybersecurity.
Develop and monitor the implementation of development programs
skills in the field of cybersecurity through:
Participation in the development of academic and professional programs
specialized in the field of cybersecurity.
The validation of training programs in the field of cybersecurity and
their publication on the official website of the Agency.
The organization of specialized training sessions in the field of
cybersecurity.
Develop and publish reference frameworks, models, and guides related to cybersecurity
to which public and private organizations must adhere.
Develop national cybersecurity measurement indicators and publish them.
dashboards periodically.
Conduct periodic communication and awareness campaigns in the
field of cybersecurity, especially during cyber crises.
Ensure technological monitoring and follow developments in the field of the
cybersecurity
International cooperation and coordination with foreign structures
competent officials in accordance with the agreements concluded for this purpose at the scale
bilateral, regional and international.

Also, she manages thetunCERTthe assistance and support center for security matters
Computer Emergency Response Team
This center offers the necessary assistance free of charge to both citizens
to professionals regarding all issues related to security
information systems and ensures the availability of appropriate resources,
capable of ensuring the protection of the national cyberspace. It also aims to
inform and raise awareness in the national community about security threats and
to guide her on ways to protect herself.

[Link] Technical Agency for Telecommunications


The Technical Agency for Telecommunicationstonsalso has broad [Link] no
2013-4506 of November 6, 2013, related to its creation provides in particular:

Art. 2 - The technical agency for telecommunications provides technical support to


judicial investigations into crimes of information systems and the
communication, it is tasked with the following missions:
The reception and processing of investigation and crime observation orders
information and communication systems derived from the judiciary
in accordance with the current legislation.
The coordination with the different public network operators
telecommunications and access network operators and all suppliers of
concerned telecommunications services, in all that falls under its missions
in accordance with the legislation in force.
The exploitation of national telecommunications traffic control systems
in accordance with the respect of international treaties related to human rights and
legislative frameworks related to the protection of personal data.
Article 6 - A monitoring committee is created within the technical telecommunications agency.
who ensures the proper operation of national traffic control systems
telecommunications in the context of the protection of personal data and freedoms
public, it is tasked with the following:
the reception and technical qualification the orders of investigation and observation
crimes of information and communication systems arising from power
judicial in accordance with the legislation in force,
the transfer of investigation and observation orders to specific services of
the agency or order their referral to the relevant structures with an obligation to
motivation
the monitoring of the technical execution of investigation and observation orders
to arrange the transfer of the results of the investigation and verification orders to
concerned structures in accordance with the legislation in force in the matter of
confidentiality and protection of personal data
the transfer of annual reports on the handling of investigation orders and
observation of crimes in information and communication systems, at
advice regarding the legislative power.

Paragraph [Link] Na AgencytCrown of Heaventfigton Electronics


There also existsthe Na AgencytCrown of Heaventfikaton Electronics(TUNTRUST), created by
Law No. 2000-83 of August 9, 2000and whose missions are as follows:
The signature and encryption of electronic messages.
The security of transactions and electronic exchanges.
The provision of keys for Virtual Private Networks (VPNs).
The homologation of encryption systems.
The security of transactions conducted by companies.
Risk analysis for a company.
Timestamping services.
Paragraph 4. The National Telecommunications Authority

The National Telecommunications Authority (INT) is an administrative authority.


independent in Tunisia that was created to regulate the telecommunications sector
Here are the main missions and actions of the INT:
Manage the national numbering and addressing plan to ensure coverage of
user needs
Carry out observation and control measures to ensure the quality of services
telecommunications offered to users
Launch calls for tenders for the acquisition of computer equipment
Protect consumers' rights and sanitize the telecommunications market
Receive consumer complaints and address them.
Regulate the relationships between telecommunications operators and installers
In summary, the INT is tasked with regulating the telecommunications sector in Tunisia.
ensure the quality of services offered to users, to protect the rights of
consumers and to clean up the market.
Paragraph 5. The national authority for the protection of personal data

The National Instance for the Protection of Personal Data (INPDP) in Tunisia
is responsible for ensuring compliance with the provisions of the law relating to the protection of
données en metant en œuvre les moyens nécessaires à l'exercice de son mandat, tels que
procedural manuals, training sessions, and awareness campaigns
She is also responsible for granting permits, receiving declarations and
handling complaints related to the protection of personal data
The INPDP has legal personality and enjoys financial autonomy.
Its main missions are as follows:
Grant the permissions
Receive the declarations
Handle complaints related to the protection of personal data
Ensure compliance with the provisions of the law related to data protection.
Implement the necessary means for the exercise of its mandate, such as
procedure manuals, training programs, and awareness campaigns
Develop training and awareness tools for data protection
destination for health professionals or the press for example
The Council of Europe offers its legislative expertise to support the alignment of
new legislative provisions in line with international and European standards
data protection matter, particularly the Convention for the
Protection of individuals in regard to the automated processing of personal data
Personnel (Convention 108) and its Additional Protocol (CETS 181) ratified by Tunisia in
July 2017
Paragraph 2. on an international level
The countries of the world quickly understood that to be effective, the fight against cybercrime
should be global. Thus, several bodies have been created, among others:
2.1. INTERPOL
International police (INTERPOL): created on September 7, 1923, with the aim of promoting cooperation
international police. It is an international criminal police organization (ICPO) that has the purpose of
headquarters in the city of Lyon in France;

2.2. Cybersud

The Council of Europe has a project called CyberSud, which aims to improve cooperation.
international in the fight against cybercrime in the southern Mediterranean region.
the project includes workshops on international cooperation in the field of cybercrime for
the judges and the prosecutors, and Tunisia is one of the beneficiary countries

2.3. UNODC

The United Nations Office on Drugs and Crime (UNODC) has provided Tunisia with
equipment and forensic software to help combat cybercrime. UNODC works with
national and international partners in Tunisia

Section 2. the jurisdictions

It has been noted that, under Tunisian law, cyber offenses are punishable by a penalty.
imprisonment and a fine. Consequently, the following jurisdictions remain competent. A
to know: the court of first instance, the court of appeal, and the court of cassation.

Any offense opens the way for a public action aimed at enforcing penalties and, if
Damage has been caused, leading to a civil action for the repair of this damage. Thus, the public action
is the work of the prosecutor and the investigating judge.

Paragraph 1. The prosecutor and the investigating judge

The public prosecutor, the investigating judge, or the judicial police officers
authorized in writing, are empowered to order:
To provide them with the computer data stored in a system or medium
informatics or those related to telecommunications traffic or to their
users, or other data that could help reveal the truth.
To input a system of information in whole or in part or a medium
information, including stored data that may help reveal the truth. If the
data entry of the information system proves to be unnecessary or impossible to carry out, the
data related to the offense as well as those allowing their reading and their
understanding will be copied onto a computer medium to ensure
the authenticity and integrity of their content.
To collect or record in real time the data related to traffic
telecommunications through the use of appropriate technical means.
In cases where the necessity of the investigation requires it, the public prosecutor or the judge
of instruction may resort to the interception of communications of suspects, under a
written and reasoned decision. In the same cases, based on the reasoned report of the police officer
judiciary authorized to ascertain the offenses, the interception of communications of suspects
may also take place, and this, by virtue of a written and reasoned decision of the prosecutor of
the Republic or the investigating judge.
Paragraph 2. Cooperation with technical agencies
They are also authorized to access directly or with the assistance of experts any system.
IT support and conduct an investigation in order to obtain the stored data.
can help to reveal the truth.
The competent services of the Ministry of National Defense and the Ministry of the Interior
ensuring the operation of data entry, its location and the access process to the systems
of information, to data, to stored information, to software and to all these supports
related to the two ministries, each according to its area of expertise.
The interception of communications includes the obtaining of access data, eavesdropping, or
access to their content, their reproduction, their recording using means
techniques appropriés et en recourant, en cas de besoin, aux structures compétentes,
each according to the type of service provided.
Part 2: the limits of the Tunisian legal framework on cybercrime in the face of protection
data

Chapter 1: The difficulties related to an effective implementation of the regulation on the


cybercrime in Tunisia

Secton 1 : Difficultés liées à la naturetransfrontalière des cybercrimes

The fight against cybercrime, a form of delinquency that ignores borders, demands
necessarily an international cooperation. The European content is at the forefront in this
fight and benefit from the action of the Council of Europe and the European Union whose cooperation
Police and judicial matters are becoming increasingly integrated.

Paragraph 1. Cybercrime is not a simple crime - it is cross-border - dimension


international
The principle of territoriality of criminal law gives jurisdiction to the repressive judge as soon as
that an offense is committed on national territory, regardless of the nationality of the
authors or victims 1, even if case law accepts the jurisdiction of the courts
French when the offense committed abroad had its effects in France. Also,
when an investigation is opened in France, it is generally because the victims come forward
find. The authors themselves may also be found there, as this case has shown.
in which two 21-year-old young French people sent millions of messages
Electronic blackmailers using intimate video (sextortion) have been arrested in France.
December 2019, after 28,000 people reported this scam, and more than 2,000
one of them filed a complaint. Likewise, the effects of a conviction decision are
limited to the territory of the State where it was rendered. As a result, a conviction judgment
Foreign judgments are generally not enforceable in France. However, cybercrime is,
Essence, an international phenomenon: Internet allows us to quickly achieve quantity.
of offenses in several states. Cyberspace is by nature free from all borders.
states, especially since cybercriminals tend to commit their offenses
in countries where the legislation is embryonic, even nonexistent. Thus, many of
cybercriminals are located abroad, particularly in Eastern Europe – 'Hackerville' is
the nickname given by the American press to the Romanian city of Ramnicu Vâlcea which, according to
it would be the world capital of online theft and where the FBI sent a team to assist
the local police - in the former Soviet space, as well as in Africa. The general director
For example, Tracfin explained that call centers located abroad could
organizing scams taking the form of supposedly very fake investments
profitable, in products such as forests, rare earths or diamonds, in
encouraging victims to register on websites located in the Middle East, in Israel,
in Eastern Europe, even in the United Kingdom. The same applies to sexual offenses.
against minors on the Internet, which often involves individuals, the victims in
particularly, being not only outside the national territory but also outside the
European territory, in Asia in general. This situation constitutes an obstacle to treatment.
of these matters. Thus, both investigative and judicial services may encounter
national borders and the principle of sovereignty as long as the concerned States do not
want, or cannot, cooperate loyally. There are also areas of lawlessness,
conducive to the proliferation of illegal activities of all kinds, including in the
cyberspace. For example, cybercriminals have settled in Crimea since the annexation.
illegal annexation of this Ukrainian territory by Russia in 2014. They are thus sheltered from any
judicial cooperation procedure: Ukraine no longer has authority over this territory, and it is
diplomatquement inenvisageable d’émetre une demande à la Russie… L’une des difficultés
In the fight against cybercrime, this form of global delinquency poses a challenge.
the classical rules of legislative competence based largely on sovereignty
and: states are free in the organization of their repressive system so that
that a multitude of national criminal laws coexist, which poses a problem in case
of offenses concerning multiple states at once. The international nature of offenses
Cybercriminals are often a source of difficulties in determining jurisdiction.
territorially competent to judge the case. The judicial treatment of the
cybercrime regularly calls for cross-border investigations. These are
made all the more complex as information must sometimes be solicited
with foreign operators or whose activities are located in foreign territory, such as
that the GAFAM1, whose headquarters are located in the United States, as well as among the hosts
important based in Switzerland. In total, cybercriminals often seem elusive. They
ne le sont cependant pas toujours, y compris les plus importants d’entre eux. Ainsi, le 23
Last January, two investigating judges from the financial division of the Paris judicial court have
obtenu de la Grèce l ’extraditon du Russe Alexander Vinnik, un grand délinquant du
dark web, also sought after by the United States and Russia. Upon his arrival in France, he
was placed under investigation for aggravated money laundering, criminal association, and hacking
organized crime in information technology. He is suspected of money laundering on the
Bitcoin exchange platform BTC-e, of which he is the founder, which would have been the most
large 'money laundering' hub of the planet, with losses amounting to billions
dollars. Russia has requested his extradition to France.
Paragraph 2. Lack of international cooperation and assistance
In the face of the limitations of classic international cooperation, the Council of Europe has established
establish an innovative convention whose universal scope inspires legislation and
practices beyond the Old Continent. In this overall framework, it is essential that
The European Union continues to work closely with the United Kingdom to fight
against cybercrime.
2.1. Lack of international cooperation
The Budapest Convention, "one of the most beautiful successes of the Council of Europe" Security
digital space is negotiated in a global context marked by interests and
divergent objects. If Europe positions itself in favor of an open Internet, it is not
necessarily the case for some of its partners. The negotiations of agreements
international digital matters are made more complex by this factor
geopolitics. That is why they generally lead to texts of scope
general, whose geographical scope is only regional; this is the case, for example,
from the Malabo convention on the fight against cybercrime, which concerns Africa.
The European Union, for its part, has an increasingly broad regulation on
matter of cybercrime and cybersecurity (see below), but not a comprehensive treaty. It is
why they support the convention on cybercrime of November 23, 2001, known as
Budapest convention, established within the framework of the Council of Europe, the only treaty with scope
universal on this subject. Its main objective is to pursue a criminal policy.
a community destined to protect society from crime in cyberspace, notably
by the adoption of appropriate legislation and the improvement of cooperation
international. However, some states contest the universal nature of the convention on
Budapest. Thus, at the initiative of Russia, the UN General Assembly on December 27
2019, adopted a resolution aimed at establishing a United Nations convention on
fight against cybercrime. The European Union and its member states had then
opposed to this text, believing that the current international legal framework was sufficient and
that it was appropriate to focus the efforts of the international community on development
national legislations and capacity building. Since the adoption of this
resolution, the Union and its member states coordinate to prevent the new
negotiation process for a United Nations convention does not call into question
the necessary balance between strengthening the resources dedicated to the fight against
cybercrime and respect for fundamental rights and the rule of law, which prevails
currently under the Budapest Convention. The Budapest Convention is
open to all countries, beyond the 47 member states of the Council of Europe - the
Russia neither signed nor ratified it, unlike Turkey. Moreover, it counts on...
currently 65 States parties, including the United States, and about a hundred countries would be inspired by
their provisions in their national legislation. Two member states of the European Union
only signed it without ratifying it: Sweden and Ireland. This convention, without giving
of the definition of cybercrime, addresses this phenomenon from two angles: that of the law
penal, targeting offenses that must be integrated into national legislation of
States parties, and that of international cooperation – "to the fullest extent possible
possible » stpule article 23 –, by facilitating extradition between state parties and assistance
judicial penal, for example through exchanges of digital evidence located in these
States. Its scope of application concerns attacks on information systems and
data, payment fraud and online offenses against minors. The
the Budapest convention was qualified by one of the people interviewed by the
rapporteurs of "one of the greatest successes of the Council of Europe". This instrument has in
demonstrated its effectiveness: it allows for the harmonization of support tools such as the
data computer conservation, very useful for investigators to obtain
evidence, the order to produce, the search and seizure of computer data
stored or the cross-border access to stored data, with consent or
when they are accessible to the public. This text allows for 'freezing crime scenes
"digital" and thus provides the possibility to trace back to the authors of the offenses.
informatics. For example, it constitutes the foundation of the database related to
international letters rogatory initiated by the French authorities. The United States, the
Canada, Australia, the United Kingdom, Germany, or even the Netherlands, as well as France,
counted among the most involved State Parties in the implementation of the convention
from Budapest. The convention also established a '24/7 network', that is to say a point of
contact available 24 hours a day, 7 days a week, designated by each State party
to ensure immediate assistance to conduct investigations regarding the
criminal offenses related to systems and data processing, or to collect
electronic evidence of a criminal offense. The French point of contact is
The Central Office for the Fight Against Technology-Related Crime
communication (OCLCTIC), division of the sub-directorate for the fight against cybercrime
within the central directorate of the judicial police of the Ministry of the Interior. The committee
of the convention on cybercrime, which represents the contracting states, aims to
facilitate the use and effective implementation of the convention, the exchange of information and
the examination of any future amendment to the legislation. It publishes reports and notes
information on any subject related to the convention, particularly on interpretation
the provisions of the convention in light of the technical developments that have occurred, which
allows for a flexible adaptation of the application of the convention. It also publishes
Forms for the concrete use of the agreement on data retention
example. Furthermore, the Budapest Convention gives rise to programs of
cooperation in favor of the least developed States parties, in Africa, in the Maghreb or in
Asia-Pacific. The training actions, particularly the GLACY + program, implemented in
work jointly with the European Union, is conducted and coordinated by the
Cybercrime Program Office (C-PROC), established by the Committee of Ministers
of the Council of Europe in 2013, located in Bucharest. The Budapest Convention has been in effect since
September 2017, the subject of important negotiations aimed at equipping it with a second
additional protocol 1. Its objective is to modernize and complete the convention
on several aspects: a more effective legal assistance (simplified regime for the
requests for assistance, injunctions to produce international, direct cooperation between
judicial authorities for requests for assistance, investigations, and investigation teams
municipalities, audio/video hearings of witnesses, victims and experts, procedures
urgent for assistance requests); direct cooperation with suppliers of
services in other jurisdictions regarding requests for information
on the subscribers, requests for conservation and urgent requests; a broader framework
clearer and stronger guarantees regarding existing practices in terms of access
cross-border data, and guarantees, particularly regarding the conditions related to the
data protection. The European Commission has been mandated since June 2019 to
participate in these negotiations on behalf of the European Union and its Member States. The
Negotiations often lead to debates and raise questions about the
territorial sovereignty in cyberspace. They are expected to end by the end of 2020,
but will likely be extended, due both to the health crisis and the length of
discussions. The second additional protocol, after its adoption, will need to be approved.
by the Parliamentary Assembly of the Council of Europe and then ratified by all the States
parts.
The fight against cybercrime has been taking place since 2007 and every 12 to 18 months,
the organization of an international event, known as the Octopus conference.
The last edition of the conference was held in Strasbourg from November 20 to 22, 2019.
in the context of the French Presidency of the Committee of Ministers of the Council of Europe,
with an agenda focusing in particular on evidence in cyberspace, exploitation
and online child sexual abuse, the challenges of data protection and
criminal justice, cooperation in the field of cybercrime and cybersecurity or even
fake news and electoral interference. The Octopus conferences bring together ministers,
representatives of international and non-governmental organizations,
universities, associations, private companies, particularly the GAFAM, or even
representatives of national data protection authorities, such as the CNIL
French, or about 250 people. They allow for discussions on the latest
let's evolve, cyber violence for example, and to 'test' the reactions of the actors of
cyberspace.
2.2. Lack of international cooperation
All the criminal mutual legal assistance treaties, which are numerous, can
to contribute to combating cybercrime as long as the offense in question falls under
the "cyber" space. This is the case, for example, of the Paris treaty of December 1998 between the
France and the United States. Nevertheless, this bilateral framework has, by definition, a scope
restricted. The letter rogatory is the preferred procedural tool for judicial assistance.
allowing to pursue transnational offenses such as cybercrimes.
Consistent, for a judge, to entrust any judicial authority belonging to another State to
mission to carry out in its name measures of instruction or other judicial acts,
it relates to any act of instruction, the hearing of witnesses, searches and seizures or
again the arrest of the suspects. It thus theoretically allows to overcome the difficulties
related to the borders. However, the letter rogatory is a cumbersome procedure to handle and
presenting long response times; it is therefore a slow tool compared to speed
of the execution of computer offenses and the volatility of digital evidence. It
has two main limitations. The first relates to the subordination of the commission
request for the existence of bilateral or multilateral agreements between states. Although the sending
a request is not, in principle, subject to the existence of an agreement
bilateral between the requesting state and the requested state, the existence of this often conditions
the acceptance and cooperation of the States. In the absence of such a convention, the applicant
is never sure of a positive response. The admissibility of the commission request
The request for assistance is subject to the assessment of the competent authority of the requested State, which will have the

possibility of invoking the exception of lack of reciprocity and any other plea of inadmissibility.
The principle of sovereignty indeed allows states to evade their obligation to
cooperation, especially when there may be some tensions between them. The second limit
is related to the difficulties associated with the scope of the letter of request. The execution of the
The letter rogatory depends on the national legislation of the state receiving the request.
letter rogatory being executed in accordance with the usual procedural rules and
from the requesting State and not from the State of origin. Bilateral treaties, when they
existing, can limit the object and scope of the letters rogatory. Some treaties
limit the commission rogatory to the hearing of witnesses or the production of documents to
conviction or judicial documents. Other investigative measures can be
subordinate to particular conditions. Thus, it is generally difficult to obtain
positive responses from certain states such as Russia, China, or Israel that show themselves
sometimes reluctant to share data stored with their service providers
Internet. It was also reported to the reporters that the Swiss police services
rarely wished to cooperate and directed their French colleagues towards this
Judicial procedure. The American judicial authorities would not be very
allies in the field of international judicial cooperation, while the GAFAM are
American companies. Moreover, during the signing of the convention on the
cybercrime of the Council of Europe, in 2001 (see below), many states have issued
reserves concerning requests for the execution of letters rogatory, if the condition of
double jeopardy was not fulfilled. Indeed, the letter of request assumes
also a double incrimination, namely the incrimination of the offense in both
Concerned states. However, many cybercrimes are currently excluded from any
incrimination in many States, thus rendering the letter rogatory ineffective
In many cases. This difference in the applicable national rules can
compromise the investigation of transnational offenses, which allows for the
cybercriminals continue to escape justice. This difficulty can be found in the
fight against online money laundering. The standards of the Financial Action Task Force
(GAFI) define the terms of international cooperation and provide for reciprocity in
information exchanges. However, according to Tracfin, the quality of working relationships varies.
much depending on the willingness for cooperation of its foreign interlocutors: exchanges
are very good in Europe, good with the countries of Central and South America and those of
Golf countries, who have adopted a cooperative approach, but they are less so with China and
even the United States, especially since the financial intelligence services of these
the latter would have much more limited investigation powers, which diminishes the interest
the transmitted information.
Section 2: Difficulties related to the complexity of procedures

- Bureaucratic burden
- Difficulty of gathering evidence + definition of the responsible party

The main obstacle faced by judges and investigators lies in the


difficulty accessing digital evidence. The collection of digital evidence depends on the
data retention period by each host, which does not comply with any standard
community, but also of the guarantee that the investigators can provide that the evidence does not
has not been forged. As Myriam Quémener 1 pointed out, public prosecutor near the court
from the Paris call, "criminal matter strengthens the requirements on investigators who will have to
being able to demonstrate its origin and authenticity to lawyers and magistrates. Respect
the procedure for accessing digital evidence is of fundamental importance because it
allows to demonstrate the integrity of electronic data and explain how
they were obtained in accordance with the rights of the parties. Negotiations are
currently ongoing at the level of the European Union, as part of the 'e- package
evidence, in order to harmonize the rules applicable at the European level (see below).
The issue of access to digital evidence goes beyond the scope of the fight against the
cybercrime: in cases of a certain complexity, whatever its nature, the
Investigators often have the first reflex to exploit telephone data.
mobile, video surveillance, or to consult IT experts, which indicates
the necessity of securing this data.
b) The question of the responsibility of hosts The reporters focused their
investigations on the fight against cybercrime by the judicial authority and by the
investigator services. They have not studied the question of the responsibility of hosting providers, which
remains today under debate. Two recent developments highlight the complexity of this
subject. First, the censorship by the Constitutional Council of the proposed law presented
by Deputy Laetta Avia, on which the Senate had issued multiple warnings. This text
aimed to impose the withdrawal within an extremely short timeframe of certain
illegal content. He would have forced certain online platform operators, under penalty of
penal sanction, to withdraw or render inaccessible, within a period of twenty-four hours,
illegal content due to their hateful or sexual nature, based on a simple
report by a user. He would also have imposed on hosts or 1 Cete
The citation is taken from the written contribution that Ms. Quémener sent to the
reporters. - 34 - to the editors of an online communication service to withdraw, in a
a one-hour deadline, content of a terrorist or child pornography nature reported by
the administrative authority. The failure to comply with these obligations would have been subject to severe penalties.
criminal sanction. Seized by more than sixty senators, including the rapporteur Sophie Joissains,
The Constitutional Council estimated, in its decision n° 2020-801 DC of June 18, 2020, that these
dispositions disproportionately infringed upon freedom of expression and
communication and that they should therefore be declared contrary to the Constitution. They
would have granted considerable power to the administration to decide on the contents to
retreat and impose a strong constraint on the operators who would have been tempted to retreat
all content reported to protect against criminal prosecution, taking into account the
difficulty in conducting a genuine examination of the litigious content within the short timeframe that
they were released. Furthermore, the Court of Auditors published a report in February 2020 on
the fight against counterfeits in which it suggests strengthening obligations
legal frameworks for online trading platforms in order to better combat trade
of counterfeiting. The Court of Auditors estimates that "digital platforms are
relative passives in the fight against counterfeiting as they are only
intermediaries without a particular vigilance obligation. This limited liability regime
results from the e-commerce directive 2000/31/EC which exempts platforms from the
general control of the content they host. It is only in case of inaction that
Following a notification that the intermediary may, where applicable, see their liability
engaged. Without going so far as to impose on the platforms (search engines, social networks
social networks, marketplaces) a general duty of prior surveillance of the entirety of
content, products, and services they reference, the Court suggests defining new
enhanced vigilance obligations, which would require them to verify the identity of
sellers and to communicate this information to consumers, to monitor the flows
allowing to identify the steps of the distribution chain and to set up a
procédure de notficaton des contenus contrefaisants, avec un délai de retrait homogène et
rapid. Given the large number of infractions observed in the cyber universe, it is
likely a better regulation of the Internet by its main actors, in a
a framework defined by the States or, better, by the European Union, will prove necessary to
complete the efforts of the police and justice.
- Various organizations involved + fragmentation of skills

Investigations as well as search, seizure, and extradition are governed by the


General provisions of the code of criminal procedure, applicable to all offenses.
Decree-Law 2022-54 introduces the following procedural powers:
Obligation of conservation (article 6), which is not provided for in the Convention
Budapest
Establishment of violations and the execution of interception and access orders
(articles 8 - 11);
Interception of communications (Article 10);
Collection of electronic evidence (articles 12-15).

Decree-Law No. 2022 - 54 does not transpose the provisions related to the preservation of
data from the Budapest Convention on Cybercrime (articles 16, 17, 29, and 30).
In terms of interceptions relating to content, articles 54 to 56 of organic law no.
2015-26 of August 7, 2015 relating to the fight against terrorism and repression of
money laundering allows, 'when the necessity of the investigation requires it,' to 'resort to
at the interception of communications of the defendants," which includes "the data of
flow, listening, or access to their content, their reproduction, their recording,
control of the public prosecutor or the examining judge (art. 54).
Finally, the encryption does not meet the requirements of decree n°2001-2727 of the 20
November 2001 is prohibited by article 9 ofTelecommunications CodetonsArticle 87 of this
same code repressing notably the use and detention with a view to their distribution
free or costly access methods. The liability of access providers is not
not specifically regulated, and Article 87 of the Telecommunications Code not requiring
no fraudulent intent, the possible liability of access providers for having
transported illegal means of cryptology, based on these articles, remains in question
(en matère civile, par applicaton des artcles 82 et 83 du Code des obligatons et des
contracts (COC), access providers do not seem to be able to be held responsible
that if they can technically act, know that they must act and do not act).

Many offenses provided for by the Decree-Law are already sanctioned in


other legal texts. The crimes mentioned in the Decree law such as the
diffamation, the distribution of images of child sexual abuse and hate speech are
already sanctified in other legal texts, namely the Penal Code, Decree Law No.
115 d e 2011 relating to freedom of the press, of printing and publishing as follows
Law Decree No. 115 of 2011) or the Telecommunications Code, with various penalties
applicable to what corresponds effectively to the same offenses. This is not
complies with the principle of legal certainty and increases the possibility of an application

Chapter 12: The Risks of Violating Rights and Individual Freedoms

Secton 1 : Risques liées à la collecte, à la conservaton, à l’accès et à l’intercepton des données


personal.

Article 6 of the decree law compels telecommunications service providers to

to generally and systematically preserve the data stored in a system

information for at least two years and potentially more, by joint order of

ministers of national Defense, Interior, Justice as well as the ministry in charge

telecommunications. The individuals whose data is kept are not

obliged to be, even indirectly, in a situation likely to give rise to

criminal proceedings.

The data that must be stored includes data on identity

the user, traffic, and location data (metadata of communications

electronics). It is generally accepted that the analysis of this type of data can

allow for precise conclusions about the individuals involved, such as the

daily lifestyle habits, the permanent or temporary places of residence, the

daily movements and others, the activities undertaken, the social relationships of these
Section 2: risks related to the infringement of freedom of expression

You might also like