Impact of ICT on Cybercrime Risks
Impact of ICT on Cybercrime Risks
age saw that of printing. This contemporary revolution is notably linked to the
the very structure of the internet and the virtual space it generates, cyberspace1The latter is
commonly defined as a set of digitized data constituting a universe
information and communication, linked to the global interconnection of computers, more
precisely defined as 'a set of commercial networks, public networks, networks
private, teaching networks, service networks, that operate on a global scale2.
The informational space now adds to the terrestrial, maritime, and aerial spaces.
where protection and security naturally fall within the scope of skills
sovereign powers of the State.
The digital age now ignores all boundaries. It allows access to culture and to
knowledge facilitates exchanges between people. It makes the establishment possible
of an online economy and brings the citizen closer to their administration. The technologies
digitals are carriers of innovation and growth, while they can
to help or accelerate the development of emerging countries.
The development of ICT and the popularization of the Internet have caused upheavals.
major, both in terms of communication on a global scale and in terms of law
applicable. We see new modes of communication emerging, revolutionized by this
possibility of constantly connecting the whole world, and particularly new modes
of exchanges, such as online commerce or electronic commerce. It is now
possible to complete a transaction thousands of kilometers away from it
interlocutor and with a simple click.
But a certain pessimist tempers this idealistic approach. Thus, any activity
humane bearer of economic, social, and cultural progress that is its social purpose,
also generate new fragilities and vulnerabilities conducive to threats or risks,
because they sharpen the imagination of criminals.
Indeed, the use of ICT is accompanied by various risks and threats. For example, the
medication contains an active substance that has therapeutic effects on your
organism. Undesirable effects can also occur with any treatment. It is there to
treat but if it is misused, it can be dangerous. The growing use of ICT has
also trained challenges in cybersecurity, online threats and the necessity
to protect the data. ICT can pose risks and threats to the
people and organizations.
ICT has facilitated the emergence of new forms of crime, such as
cybercrime, drug trafficking, human trafficking, and terrorism3. These
criminal activities are often difficult to detect and prosecute, as they use
new forms and new means of communication.
1
Pr. HADID Noufyele and Mr. MERBOUHI Samir, Consequences of the use of ICT on economic crime and
Financial in Algeria, University of Algiers 3, New Economy Review
2
United Nations Convention on the Fight Against the Use of Information and Communication Technologies for
criminal fins
Budapest Convention on Cybercrime
3
Cybercrime is now a reality. It is all the more dangerous because it
penetrates within families, where ordinary delinquency had not had access until now.
In 1972, Dean Jean CARBONNIER already stated that "the evolution of customs and
techniques give rise to new forms of delinquency4Indeed, most
great technological discoveries have almost always led, alongside progress
economic benefits they provide to humanity, negative consequences among which is
in a good position the emergence of new forms of crime. The internet is not exempt from
this sociological law of development.5
According to Army General Marc WATIN-AUGOUARD, "when development
the economy was limited to the agricultural primary sector, insecurity was reduced to violations
against people. The secondary sector has seen the emergence of goods production
manufactured and thus of thefts, destruction, degradation. The development of sectors
"tertiary services inspired the so-called smart crimes" 6With the emergence of a
quaternary sector of the economy, where information has become a source of wealth,
cybercrime. It blurs the boundaries between states, bringing the victim closer to their
aggressor but keeps the offender away from his judge.
4
Information and communication technologies and their impact on the economy, OECD, page 7
5
Dr. Kamel REZGUI, Cybersecurity Law, Master's in ICT Law, International University
Tunis, 2022
6
Wikipedia, cyber attack
7
GASSIN (R.), "The criminal law of computer science", DS., [1986], Chron p. 35.
8
CSIS, Center for Strategic and International Studies
9
Dr. Sami SOUDANI, Introduction to Computer Security, Master's in ICT Law, International University
from Tunis, 2022
infractions. The examination of these definitions allows us to identify the major concepts and to use
these definitions coherently within the framework of a national strategy to combat
cybercrime...............
An example of this method is Decree-Law No. 2022-54 of September 13, 2022.
related to the fight against offenses related to information systems and
communication that introduces provisions on cybercrime. This text of law
{"système d’information":"information system","données informatiques":"computer data"}
communication system, communication service provider, traffic flow or
access data, IT support, program, the erasure of computer data.
After defining these key terms, the Law lists the main offenses considered
as falling within the scope of cybercrime: the violation of integrity of
information systems and data and their confidentiality, the offenses committed against
the help of information systems or computer data. This approach is very
similar to that adopted by the Council of Europe's Convention on Cybercrime
(Budapest Convention).
Cybercrime can be defined as any illegal action aimed at perpetrating
criminal offenses on or by means of a computer system interconnected to a network
telecommunications. It targets either specific offenses related to the interest for which the
information and communication technologies are the very object of the offense, that is to say, some
common law offenses for which the internet is the means of developing
pre-existing infractions.
A piece of data is a factual and raw piece of information, without context. In certain situations,
this corresponds to each information communicated voluntarily by a person. This
are, for example, demographic data (age, gender, place of residence...). The data
can also correspond to all results of searches, analyses, and other information
held by an organization. The data therefore corresponds to everything that is collected by
an organization. Either through its own means or during exchanges with clients, patients,
partners, ... as soon as they have given their agreement. The data is necessary
only when they can be exploited, confronted, analyzed, and lead to a
result. Without the work of confrontation and analysis, the data is often of little value.
useful; (reference)
10
[Link]
11
[Link]
12
htps://[Link]/fr-fr/topics/cyber-athank you
13
htps://[Link]/2018/07/04/les-10-types-de-cyberataques-les-plus-courants/
14
htps://[Link]/fr-fr/topics/cyber-athanks
In addition to cybercrime, cyberattacks can also be associated with war.
cybernetics or cyberterrorism, like hacktivists. The motivations can vary,
In other words. And within these motivations, we find three main categories:
criminal, political and personal. Pirates motivated by criminal motives seek
a financial gain through money theft, data theft, or disruption of activities.
even, people motivated by personal grievances, like long-time employees or
current dissatisfied individuals will seize money, data, or a simple chance to interrupt the
system of a company. However, they mainly seek to take revenge. The hackers
whose socio-political motivations seek to draw attention to their causes. In
consequently, they ensure that their attacks known to the public - this is called
also hacktivism. Among the other motivations for cyber attacks, espionage can be mentioned.
industrial (with the aim of gaining an unfair advantage over competitors) and the challenge
intellectual.15
Criminal organizations, state actors, and individuals launch
cyberattacks against companies. One of the ways to classify the risks of cyberattack
consist of distinguishing external threats from internal threats. External cyber threats
including: organized criminals or criminal groups, professional pirates, such as
state-sponsored actors, amateur hackers, including hacktivists.
internal threats come from users who have legitimate and authorized access to the
company assets and deliberately or accidentally abuse them; in particular: the
negligent employees regarding security policies and procedures, current employees
former dissatisfied ones, business partners, clients, contractors or
suppliers with access to the system16.
Cyberattacks occur when organizations, actors on behalf of
of a state or private individuals want to seize one or more things, such as:
the company's financial data, customer lists, financial data
regarding clients, customer databases, including information
personally identifiable information (PII), email addresses, and identification documents
for login sessions, all intellectual property, such as trade secrets
or product designs, access to IT infrastructure, services
computer science, to accept financial payments, personal data, the
possibility to infiltrate government departments and government agencies17.
In today's connected digital environment, cybercriminals use tools
sophisticated to launch cyberattacks against companies. Their attack targets
includes personal computers, computer networks, infrastructure
computer science and computer systems18. The common types of cyberattacks are the
following:19
15
Tenth United Nations Congress, in Vienna, under the title 'the prevention of crime and the treatment of
"delinquents", [10 – 17 April 2000], available at (accessed on 12/11/2004).
16
H. ALTERMAN et A. BLOCH : La Fraude Informatique (Paris, Gaz. Palais), [3 sep. 1988] p. 530
17
Derived from the English 'Cyberspace', a contraction of the words 'Cybernetics' and 'Space', this term has been
introduced for the first time by the American author William Gibson in his science fiction novel "
Neuromancer, published in 1984.
18
LEBERT (M-F.), « De l'imprimé à Internet », thèse Paris, éd. 00h00, [1999].
19
CARBONNIER (J.), « Sociologie juridique », éd. A. Colin, [1972], éd. PUF, coll. Thémis, Paris, [1978],
Refondue coll. Quadrige, [1994] and [2004].
Backdoor Trojans: a Trojan creates a backdoor
vulnerable in the system the victim, allowing the hacker to gain control of it
distance and almost total. Frequently used to connect a group of computers of
victims, in a bot network or Zombie network, hackers can take advantage of
of the Trojan horse for other cybercrimes.
Cross-Site Scripting (XSS) attack: cross-site scripting attacks insert code
malicious in a legitimate website or application script in order to obtain
user information, often using third-party web resources. The
pirates frequently use JavaScript for XSS attacks, but Microsoft
VCScript, ActiveX, and Adobe Flash can also be used.
Denial of service (DoS) attack and distributed denial of service (DDoS) attack
flood the resources of a system, overwhelming them and preventing responses to
service requests, which reduces the operational capacity of the system, the
rendering it unavailable for legitimate users. Often, this type of attack sets up
another attack.
Tunneling of domain name systems (DNS): cybercriminals use
DNS tunneling, a transactional protocol, for exchanging data
applications, such as silent mode data extraction or establishing
from a communication channel with an unknown server, similar to the exchange of
command and control (C&C) as an example.
Malware: This is malicious software that can compromise systems.
inoperable infected. Most variants of malware destroy the
data by deleting or erasing the essential files for operation of the
operating system.
Phishing: The scam through phishing attempts to steal identifiers or
sensitive user data such as credit card numbers. In this case,
Fraudsters send users emails or SMS designed to look like
to come from a legitimate source code, using fake hyperlinks.
Ransomware: ransomware is a sophisticated malware that takes advantage
the weaknesses of the system, using enhanced encryption to retain the
data or the system functionality held hostage. Cybercriminals use
ransomware to demand a payment in exchange for the release of the system. A
A recent development with ransomware is the addition of extortion tactics.
SQL Injection: Attacks using Structured Query Language injection
SQL) integrate malicious code into vulnerable applications, producing
final results of database queries and executing commands or
similar actions that the user did not request.
Zero-day exploit: Zero-day attacks take advantage of unknown vulnerabilities of
hardware and software. These vulnerabilities can exist for days, months
or years before developers became aware of these vulnerabilities.
Man-in-the-middle (MitM) attacks: in this type of attack, a hacker
computing intercepts communication between two parties to steal or modify
information.
Password attacks: password attacks use various methods,
such as brute force or dictionary attacks, to guess or decrypt the
passwords and gain unauthorized access to computer systems.
Ping of Death Attack: Ping of Death attacks involve sending packets of
oversized data to a computer, causing it to crash or become unresponsive.
In case of success, cyberattacks can harm businesses. They can
cause a valuable unavailability, manipulations or data losses, and
loss of money through ransom. Additionally, downtime can lead to
major service interruptions and financial losses. For example:
DoS, DDoS, and malware attacks can cause crashes of
system or server.
DNS tunneling or SQL injection attacks have the ability to modify,
delete, insert, or steal data within a system.
Phishing attacks and zero-day exploits allow hackers
to enter a system to cause damage or steal valuable items
information.
Phishing attacks and zero-day exploits enable hackers
to enter a system to cause damage or steal valuable things
information.
Ransomware attacks can disable a system until
The company pays a ransom to the hacker.
For example, Darkside, a ransomware gang, attacked Colonial Pipeline, a
large American network of refined product pipelines, on April 29, 2021. Through
of a virtual private network (VPN) and a compromised password (external link to [Link]),
this pipeline cyberattack breached the company's networks and disrupted the
pipeline operations. Indeed, DarkSide has shut down the pipeline that transports 45% of the gas, from
diesel and aviation fuel that is shipped to the east coast of the United States. Quickly after
the pipeline blockage, the company received a ransom demand of nearly 5 million
dollars in cryptocurrency Bitcoin, eventually paid by the CEO of Colonial Pipeline
external to [Link]). Following this mishap, Colonial Pipeline hired a company to
third-party cybersecurity and informed federal agencies and U.S. authorities20.
Cybersecurity measures, such as firewalls, antivirus software, and encryption,
can help protect against cyberattacks. It is important to stay informed about the
latest threats and to follow best practices in cybersecurity in order to
minimize the risk of a cyber attack.
The United Nations adopted a convention to combat the use of ICT for purposes
criminals21.
The fight against data piracy is an important issue for states, which have taken measures to
national cybersecurity strategies to address it. These national strategies
aim to protect citizens and businesses from cyberattacks and to reduce
threat, the impact and victimization of cybercrime. They include measures
to strengthen the security of information systems, raise users' awareness of the risks
related to cybersecurity, and to combat data hacking. States are also working
in collaboration with international organizations such as INTERPOL to combat
WATIN-AUGOUARD (M.), Preface of the book "Cybercrime Global Challenge", VII.
20
The Decree-Law No. 2023-17 of March 11, 2023, regarding cybersecurity establishes as a principle
the obligation to submit to the mandatory periodic audit applicable to public bodies
and not public except for the networks of the ministries of defense and interior that follow
22
:
Public telecommunications network operators and suppliers of
telecommunications and internet services,
-Les entreprises dont les réseaux informatiques sont interconnectés à travers des
telecommunication networks
The providers of hosting and cloud computing services.
Companies that process personal data through automated means
their users in the context of providing their services through networks
telecommunications.
Critical digital infrastructure
The periodic audit procedure is scheduled for each year and organized by articles 7 to
9 of Decree-Law No. 2023-17 of March 11, 2023, relating to cybersecurity.
1.2. The measure of information
The Decree-Law No. 2023-17 of March 11, 2023, requires all public or private organizations to inform
the ANC from any attack, intrusion or disturbance of their system or network.
1.3. The security measure
Decree-Law No. 2023-17 of March 11, 2023, requires all public or private organizations to
comply with the security measures established by the ANC.
1.4. The granting of the secure label measure
The Decree-Law No. 2023-17 of March 11, 2023, assigns the ANC the responsibility of awarding the 'secured' label.
22
Article 6 of Decree-Law No. 2023-17 of March 11, 2023, relating to cybersecurity
the expiration of the validity period in case of modification of technical characteristics
or the occurrence of technological change that introduces vulnerabilities to the software or
electronic equipment.
The procedures and conditions for granting the "secured" label and its withdrawal will be determined by
Decree of the Minister in charge of the Communications Technology portfolio.
A national register of software and electronic equipment that have obtained the label "
"secured" will be published by the ANC and updated regularly.
Under this decree, the structures that manage important digital infrastructures
Vital entities are required to use software and equipment that have the 'secure' label, to have their
main hosting center and a backup center with a provider of
cloud computing services that have obtained the label, and comply with the measures and the
necessary procedures to ensure business continuity and protect databases
sensitive information whose compromise could affect national security in case of a crisis
cybernetics, according to a procedure manual approved by decree at the proposal of
Minister in charge of Communication Technologies.
The ANC will also be responsible for granting, renewing, and withdrawing the label "Supplier of
government cloud computing services (G-cloud)" and the label "Supplier of
National cloud computing services (N-cloud) to service providers
housing after consultation with the ministers of national defense and the interior.
The ANC is also required to develop and implement the national response plan.
to the cyber emergency services in collaboration with the response centers
sectoral cyber emergencies public and private, set up the modalities
techniques necessary for the early detection of incidents and attacks
cybernetics that threaten the cyber space, set up and exploit the
reporting channels for incidents and cyber attacks, reduce the
repercussions of incidents and cyber attacks and ensure the continuity of
the activity and the quick recovery of their effects, or also to alert the institutions, the
administrations and individuals, strengthen information systems, manage the
incidents, organize and coordinate efforts to address weaknesses,
study, analyze them and anticipate appropriate solutions.
Paragraph 2. Decree No. 2008-2639 of July 21, 2008, setting the conditions and procedures
import and marketing of means or services of encryption through
telecommunication networks
The importation and marketing of other encryption means not provided for
in this list are subject to the authorization of the ANCE based on the certificate
of approval.
The encryption methods imported by companies on a temporary basis to meet their needs
personal needs are not subject to authorization and technical approval.
-La liste de ces entreprises est établie et actualisée par l ’ANCE
2.2. Approval measurement
The approval of encryption means, except for encryption means imported by
temporary companies to meet their own needs, of which a list is
published by the ANCE is carried out with the authorization of the ANCE by certificate of approval
and the establishment of a publicly accessible list of approved means25.
The ANCE checks the following elements in the approval:
The technical rules in the field of use of encryption means
The malfunctioning of the encryption method and public networks
telecommunications
The security of data related to users.
2.3. The control measure
Decree No. 2008-2639 of July 21, 2008 allocates to the ministers of national defense and
within the following prerogatives:
23
Article 4 of Decree No. 2008-2639 of July 21, 2008, setting the conditions and procedures
importation and marketing of means or services of encryption through the
telecommunications networks
article 1
24
article 3
25
Ability to consult all documents related to equipment and systems
electronic devices that allow encrypting data or examining said equipment and
systems
Intervene with any person holding these equipment or systems
Obligation for these individuals to deliver these equipment or systems to the
first request and to comply with the measures
The government decree n°2020-48 of January 23, 2020, has subjected the import and the
commercialization of terminal equipment and radiocommunication equipment manufactured in
Tunisia or imported connected or not to a public network, or intended for public use at
the exception of terminal telecommunications equipment and equipment
radio frequencies used by the Ministry of National Defense and the Ministry of the Interior
to approval regimes, compliance control, and technical inspection.
3.1. The equipment certification measurement
The granting by the CERT of a renewable homologation certificate by type, brand and
model.
The approval is granted based on criteria/requirements established by the CERT/Single Window.
given certain imperatives:
The protection of public telecommunications networks against any damage
The electromagnetic compatibility specific to the terminal equipment
The electronic security of the terminal equipment
The effects of non-ionizing rays
The rules for the use and exploitation of the radio frequency spectrum
The malfunctioning of the terminal equipment with public networks
telecommunications
The safety of users and personnel operating the equipment
The safety of users and operating personnel
Paragraph 4. Law No. 2000-83 of August 9, 2000, concerning exchanges and commerce
electronic
One of the essential aspects of cybersecurity is the security of exchanges in the
cyberspace.
This law regulates the legal framework for certification service providers.
electronics.
Access to supplier activities of certification services:
The certification service provider is a natural or legal person of
Tunisian nationality responsible for issuing, delivering, and preserving
electronic certificates
Carries out its activities with the authorization of the ANCE and a specifications document.
The legal obligations of the supplier
Obligation to ensure the reliability and confidentiality of the means of issuance and of the
conservation and management of certificates
Obligation to maintain a register of electronic certificates
Obligation to ensure the confidentiality of certificate data and data
personal and related
Paragraph 5. Decree No. 2008-3026 of September 15, 2008, setting the conditions
General operating conditions of public telecommunications networks and networks
access
Paragraph 5. Decree No. 2014-4773 of December 26, 2014, setting the conditions and
procedures for granting authorization for internet service provider activity
This decree has subjected the activity of providing internet services to the authorization regime granted by
decision of the Minister responsible for telecommunications and after the opinion of the Minister of the Interior,
the National Telecommunications Authority and the advisory commission created in
the occurrence.
make available to the ministry in charge of telecommunications and the National Instance of
Telecommunications all information relating to technical order issues,
operational, financial and accounting in accordance with the terms set by the authority,
submit for approval to the National Telecommunications Authority the contract model
service to be concluded with clients,
to be able to meet the needs of national defense and public security and safety
in accordance with the legislation and regulations in force, - provide the competent authorities
the means necessary for the execution of its functions, and in this context, the supplier of
Internet services must comply with the instructions of judicial, military, and security authorities.
national, - respect the conventions and international treaties ratified by Tunisia. inform the
Publish the general conditions of offers and services, publish the rates for the supply of each.
service category. Internet service providers are required before marketing
of the service, to present a notice advertising the rates according to the following conditions: - a
A copy of the notice is sent to the national telecommunications authority at least fifteen
(15) days before the marketing of any new offer being considered - a copy of the notice
The definitive advertising is made available to the public electronically for free consultation.
and in all the areas of the relevant services
5.2. The obligations of the service provider towards the clients
provide access to Internet services to all applicants using technical solutions the
more effective, - to provide subscribers with clear information regarding the subject and the
access methods to the service and support them in case of request,
Provide a response service to subscribers' questions and requests and their follow-up through a
permanent focal point. Take the necessary measures to ensure the quality of the services that it
provide subscribers and respect their rights resulting from the service contract concluded with them, to
this effect he is required to take the necessary measures to:
ensure the neutrality of its services, confidentiality, and integrity of the data transmitted in
the framework of the services provided in accordance with the applicable legislation and regulations
ensure the protection, security, and confidentiality of personal data they hold
you process or record at the subscriber identification unit in accordance with the legislation and
regulations in force
the non-disclosure to third parties of the data transmitted or held, relating to subscribers and
notably those that are nominative, and this without the consent of the concerned subscriber subject to the
prescriptions required by national defense and public security and the prerogatives of the authority
judicial and by the legislation in force
guarantee the right of any subscriber not to appear in any nominative database of
supplier except for those related to billing, - guarantee the right of every subscriber to
to oppose the use of his invoicing data for prospecting purposes
commercial
guarantee the right of any subscriber to rectify the personal data concerning them or to
to complete them, clarify them, update them, or delete them
define the secure navigation service for children on the Internet and provide for it in the
service contracts as a service of choice that depends on the client's will - give to the
subscribers the ability to change their choice regarding the secure browsing service of
children on the Internet and this through simple and instant mechanisms.
ensure the continuity of services, according to the nature of the contracts to be concluded with its subscribers, and
ensuring the continuous operation of the equipment and computer programs used
and to take the necessary measures to maintain the level of service quality indicators
Internet provided by the standards in force at the national and international level.
Paragraph 6. Decree No. 2014-412 of January 16, 2014, setting the conditions and the
procedures for granting authorization for the exercise of the activity of operator of a
virtual telecommunications network
To obtain permission to operate as a virtual network operator
Telecommunications in Tunisia, the following conditions and procedures must be fulfilled:
6.1. Conditions:
The person representing the virtual operator must be of Tunisian nationality and hold a
higher education diploma or equivalent
The activity of virtual telecommunications network operator is subject to authorization from
Minister responsible for telecommunications
6.2. Procedures:
The operation of a virtual telecommunications network is subject to prior authorization.
of the minister in charge of telecommunications.
To obtain permission, the interested parties must submit a request to the Ministry.
communication technologies.
The request must include a description of the technical and financial means available.
applicant's disposition, as well as a business plan.
The Ministry of Communication Technologies will review the request and may
request additional information or documents.
If the request is approved, the ministry will issue a permit to the applicant.
6.3. The obligations of the virtual operator
The responsibilities of a virtual telecommunications network operator in Tunisia
may include the following elements:
Provide telecommunications services to customers using the physical network
from an authorized operator, such as Tunisie Telecom
Ensure that the services provided are of high quality and meet the needs of
clients
To comply with the regulations and laws governing the telecommunications sector.
in Tunisia, including obtaining the necessary permits and licenses
Contribute to the development of the telecommunications sector in Tunisia by
investing in infrastructure and promoting the use of ICT
Participate in initiatives aimed at improving the country's competitiveness and encouraging
investments
Cooperate with other operators in the sector, as in the case of portability.
mobile numbers, made effective among all operators in Tunisia in 2017
Ensure the security and confidentiality of customer data and comply with the regulations
data protection
It is important to note that the specific responsibilities of a virtual operator
may vary depending on the terms of its authorization and the regulations in
in force at that moment.
Paragraph 7. Law No. 2005-51 of June 27, 2005, relating to electronic fund transfers
It should be noted that in Tunisia, all monetary flows must, except in special cases, obtain
the approval of the Central Bank of Tunisia (BCT)
the issuer must provide the public with a document free of charge that includes the
contractual conditions for the use of the electronic transfer instrument.
The law on electronic funds transfers states that the sender must verify the identity
of the beneficiary and check the electronic transfer instrument before carrying out the operation.
Tunisian banks are required to identify and verify the identity of clients.
occasional and, where applicable, final beneficiaries
For international transfers through money transfer agencies, the applicant must provide
identification documents and comply with legal obligations
It is possible that some banks have their own specific procedures for verification.
the identity of the beneficiaries before electronic fund transfers.
Paragraph 8. Law No. 94-36 of February 24, 1994, concerning literary property and
artistic as modified by law n°2009-33 of June 23, 2009
Law No. 94-36 of February 24, 1994 regulates the protection of works protected by law.
author coming from digitization and networks against threats.
The protection of works takes place at three levels:
Legal protection by copyright
Protection technique through access control mechanisms, usage, and traceability
Legal protection of technical measures against their circumvention
L'INNORPI plays the role of regulator in the area of technical protection measures of
works.
The different titles of industrial property are:
The invention patent: The patent can be filed in Arabic, French, or English.
with the INNORPI. The invention must comply with patentability rules, namely
novelty, inventive activity and industrial application, but the INNORPI does not verify
not these conditions. Patents are granted at the risk and peril of the applicants, it
It is advisable to conduct a prior search for prior art to avoid any
legal insecurity. The patent is valid for twenty years from the filing date of the
request. Tunisia joined the Patent Cooperation Treaty in 2001.
(PCT). A foreign applicant can therefore extend the protection of their title in Tunisia.
through an international patent (twelve-month priority period from the first)
deposit). However, Tunisia applies the principle of international exhaustion: the
exclusive right does not extend to the importation of the product into Tunisian territory
patented after this product was lawfully put on the market
any country (by the patent holder or with their consent). From
Plus, since a 2017 agreement between the Tunisian government and the European Office.
European patents can be validated in Tunisia.
The brand: To be registered with INNORPI, the brand must be
distinctive, lawful and available. It is possible to conduct a prior art search.
based on TMView. INNORPI can provide this service upon request,
for a fee. The registered trademark is protected for ten years, renewable.
indefinitely. The Madrid Protocol is applicable in Tunisia and allows for the extension
of rights from or to Tunisia (six-month priority period starting from
first deposit.
The design and model: Since INNORPI does not conduct a substantive examination, it is solely up to the...
ensuring compliance with the validity conditions of novelty and the
specific character. The protection cannot exceed fifteen years. The Hague system
allows the extension of titles from or to Tunisia (six-month priority period).
Geographical indications: Tunisia has been a member of the arrangement since 1973.
Lisbon concerning the protection of origin designations and their registration
international. This is supplemented by geographical indications as well as indications
of origin (law n°99-57 of June 28, 1999). A national development plan of
craftsmanship 2017-2021 was launched, with the objectives of creating jobs,
rehabilitation of artisanal establishments and the increase of the contribution of
sector in GDP at 6%.
Note: The country also has legislation on collective trademarks and, for the
environmental protection, from a Tunisian Ecolabel.
Tunisia has been a member of WIPO since 1975 and has ratified the Berne Convention for the
protection of literary and artistic works. The author as well as performing artists or
performers enjoy moral and property rights. The Tunisian Office for the Protection of
copyrights and neighboring rights (OTDAV), an establishment under the supervision of the Ministry of
culture, sets the financial and material conditions for the exploitation of works, and manages the
perception and distribution of royalties. Protection is granted to the work simply by the fact
since its creation. Nevertheless, OTDAV provides creators with a deposit service
works, which allows us to date their creation.
Paragraph 9. Organic Law No. 2004-63 of July 27, 2004, concerning the protection of
personal data
9.1. The obligations of the data controller
Organic law no. 2004 - 63 has placed the responsibility for data processing on the data controller.
personal a set of legal obligations:
9.1.1. The obligation of purpose
The purpose limitation requirement implies that processing involves:
Document compliance
We will address in this section the legislative aspect of the breach of information systems and
data. With the development and generalization of computer systems in
In all sectors of society, the judicial system has had to adapt to new offenses.
and offenses and implement measures to address these phenomena. Thus, here are the
main laws on the subject without claiming to be exhaustive:
The decree-law No. 2023-17 of March 11, 2023 establishes sanctions for the following offenses:
1.1. Administrative sanctions
The minister in charge of communication technologies may, based on a motivated report from
the Agency, to downgrade the entities mentioned in Article 6 of this decree-law, and classified
at the first and second levels, and in the following cases:
The non-implementation of the mandatory and periodic security audit of the systems
information.
The failure to submit a protected electronic copy of the audit report to the Agency
within the deadline mentioned in Article 8 of this decree-law.
The non-implementation of the recommendations from the audit report or their partial implementation.
within a period not exceeding one year.
Failure to comply with the emergency measures prescribed by the national contact point for
the response to cyber emergencies or emergency response centers
cybernetics following the occurrence of an incident or a cyber attack.
-does not result from failures within the deadline mentioned in article 17 of this decree-
law.
The failure to create a cyber emergency response center or the non-
membership in cyber emergency response centers.
The non-compliance with the framework mentioned in Article 14 of this decree-law.
Several sanctions are also provided for in this decree in case of infringement; a
a fine of fifty thousand (50,000) dinars to one hundred thousand (100,000) dinars for the organizations
mentioned in Article 6 of this decree-law, and classified at the third level, and this
in the following cases:
The non-fulfillment of the mandatory and periodic security audit of the systems
of information.
The non-execution of the recommendations of the audit report or their execution
split within a period not exceeding one year.
The non-compliance with the emergency measures prescribed by the point of contact
national for the response to cyber emergencies or response centers
to the cybernetics emergency following the occurrence of an incident or a
cybernetic attack.
The non-compliance does not fall within the failures mentioned within the timeframe stated in Article 17 of this document.
decree-law.
The non-establishment of a cyber emergency response center or the non
membership in cyber emergency response centers.
Paragraph 2. Decree No. 2008-2639 of July 21, 2008, setting out the conditions and procedures
importing and marketing means or services of encryption through
telecommunication networks
- In case of a blatant failure to comply with the provisions of this decree, the minister in charge
telecommunications can pronounce the immediate suspension of the authorization, and the
regularization of the situation of the concerned offender within a period not exceeding
two months from the date of suspension.
- Encryption methods of all categories can be seized provisionally, without
compensation, by decision of the Minister of National Defense and the Minister of the Interior and
of local development if it turns out that the use of these means disrupts defense
national and public security, and from the minister of communication technologies if
it turns out that the use of these means disrupts the security of networks
telecommunications.
Paragraph 3. Law No. 2000-83 of August 9, 2000, concerning trade and commerce
electronics
The law creates sanctions for the following offenses:
The certification service provider is punished under Article 254 of the Penal Code.
electronics and its agents who disclose, incite or participate in disclosing information
which are entrusted to them in the course of their activities, except for those of which
the publication or communication is authorized by the certificate holder in writing or by
electronic means or in the cases provided for by the legislation in force.
Without prejudice to the rights of victims to compensation, the minister responsible for commerce may carry out
transactions regarding the offenses provided for in Article 49 of this law and which are
observed in accordance with the provisions of this law.
Without prejudice to the rights of victims to compensation, the minister responsible for the oversight of the agency
The national electronic certification can carry out transactions concerning offenses.
provided for in Article 45 of this law, and which are established in accordance with the provisions of the
present law.
Without prejudice to the rights of others, the terms and procedures for the transactions are those provided for.
by the texts in force governing economic control, notably law no. 91-64 of July 29
1991 regarding competition and prices, along with the texts that have supplemented and amended it.
Paragraph 4. Decree No. 2014-4773 of December 26, 2014, setting the conditions and the
procedures for granting authorization for internet service provider activity
In the event of a serious failure or blatant breach of the provisions of this decree,
the Minister of Telecommunications, based on a report established by the National Authority
of Telecommunications, may pronounce the immediate suspension of the activity and summon
the internet service provider to present its observations related to the facts that it
are charged before the commission that establishes a motivated report with the regulation of the
operator's situation within a period not exceeding one month from the date of the
date of the suspension According to the provisions of Section 2 of Chapter 6 of the Code
telecommunications of penal sanctions, consisting either of fines or of
private penalties of freedom or both sanctions cumulatively whoever installs
You operate a public telecommunications network without having obtained the license and any
person who provides telecommunications services to the public without having obtained
the authorization or continues to provide the services after the withdrawal of said authorization.
The provisions of the Penal Code and the penalties provided for in its Article 253 apply to
Anyone who discloses, incites, or participates in the disclosure of the content of communications and
exchanges transmitted through telecommunications networks.
The Internet service provider may be subject to the criminal penalties provided for in the
legislations governing the press, literary and artistic property, competition and prices,
consumer protection and personal data protection in all cases
where it results from practices inherent to its activity an infringement of the provisions and rules
prescribed in these legislations.
Paragraph 5. Decree No. 2014-412 of January 16, 2014, setting the conditions and the
procedures for granting authorization to operate as an operator of a
virtual telecommunications network
This decree establishes administrative sanctions for the following offenses:
In the event of a serious failure or a blatant breach of the provisions of this decree,
the minister responsible for telecommunications, based on a report prepared by the authority
national telecommunications authority can pronounce the immediate suspension of activity and
summon the operator of the virtual telecommunications network to present its
observations related to the facts inflicted upon him before the commission that establishes a
motivated report regarding the resolution of the operator's situation within a period not exceeding
not a month from the date of the suspension.
The authorization is automatically withdrawn from the virtual network operator
telecommunications in the following cases: the dissolution or bankruptcy of the legal entity,
and the termination of the contract with public telecommunications network operators.
Paragraph 6. Law No. 2005-51 of June 27, 2005, on electronic funds transfer
This law establishes criminal sanctions for the following offenses:
Is punishable by ten years of imprisonment and a fine of ten thousand dinars anyone who:
-forge an electronic funds transfer instrument,
use a funds transfer electronic instrument with full knowledge
falsified
- knowingly accepted a transfer by the use of an instrument of
falsified electronic funds transfer.
Shall be punished with three years of imprisonment and a fine of three thousand dinars, anyone who
uses an electronic funds transfer instrument without the consent of its holder.
Paragraph 7. Law No. 94-36 of February 24, 1994, relating to literary property and
artistic as amended by law no. 2009-33 of June 23, 2009
This law aims to preserve the rights of creators. The provision of illegal means of implementation
the disposition of the public of protected works or objects is punished. Publishers and distributors of
Software dedicated to or used for this purpose is now liable for the offense of infringement.
Fines
Imprisonment
Paragraph 9. Telecommunications Code
The aforementioned code suppresses a number of behaviors during the use of
telecommunications in its chapter 6. This repression is provided for in articles 81, 82, 83,
84, 85, 86, 87.
Article 89 of the code under review provides for a special procedure for offenses in
communication matter. Thus, at the end of the aforementioned article, "the offenses
in telecommunications matters provided for in article 81 give rise to a procedure of
transaction. The Minister in charge of telecommunications can negotiate with the offender and
to impose a transaction fine.
Paragraph 10. Decree-Law No. 2022-54 of September 13, 2022, concerning the fight against
infractions related to information and communication systems
We will quickly develop their roles and the actions they can take.
Also, she manages thetunCERTthe assistance and support center for security matters
Computer Emergency Response Team
This center offers the necessary assistance free of charge to both citizens
to professionals regarding all issues related to security
information systems and ensures the availability of appropriate resources,
capable of ensuring the protection of the national cyberspace. It also aims to
inform and raise awareness in the national community about security threats and
to guide her on ways to protect herself.
The National Instance for the Protection of Personal Data (INPDP) in Tunisia
is responsible for ensuring compliance with the provisions of the law relating to the protection of
données en metant en œuvre les moyens nécessaires à l'exercice de son mandat, tels que
procedural manuals, training sessions, and awareness campaigns
She is also responsible for granting permits, receiving declarations and
handling complaints related to the protection of personal data
The INPDP has legal personality and enjoys financial autonomy.
Its main missions are as follows:
Grant the permissions
Receive the declarations
Handle complaints related to the protection of personal data
Ensure compliance with the provisions of the law related to data protection.
Implement the necessary means for the exercise of its mandate, such as
procedure manuals, training programs, and awareness campaigns
Develop training and awareness tools for data protection
destination for health professionals or the press for example
The Council of Europe offers its legislative expertise to support the alignment of
new legislative provisions in line with international and European standards
data protection matter, particularly the Convention for the
Protection of individuals in regard to the automated processing of personal data
Personnel (Convention 108) and its Additional Protocol (CETS 181) ratified by Tunisia in
July 2017
Paragraph 2. on an international level
The countries of the world quickly understood that to be effective, the fight against cybercrime
should be global. Thus, several bodies have been created, among others:
2.1. INTERPOL
International police (INTERPOL): created on September 7, 1923, with the aim of promoting cooperation
international police. It is an international criminal police organization (ICPO) that has the purpose of
headquarters in the city of Lyon in France;
2.2. Cybersud
The Council of Europe has a project called CyberSud, which aims to improve cooperation.
international in the fight against cybercrime in the southern Mediterranean region.
the project includes workshops on international cooperation in the field of cybercrime for
the judges and the prosecutors, and Tunisia is one of the beneficiary countries
2.3. UNODC
The United Nations Office on Drugs and Crime (UNODC) has provided Tunisia with
equipment and forensic software to help combat cybercrime. UNODC works with
national and international partners in Tunisia
It has been noted that, under Tunisian law, cyber offenses are punishable by a penalty.
imprisonment and a fine. Consequently, the following jurisdictions remain competent. A
to know: the court of first instance, the court of appeal, and the court of cassation.
Any offense opens the way for a public action aimed at enforcing penalties and, if
Damage has been caused, leading to a civil action for the repair of this damage. Thus, the public action
is the work of the prosecutor and the investigating judge.
The public prosecutor, the investigating judge, or the judicial police officers
authorized in writing, are empowered to order:
To provide them with the computer data stored in a system or medium
informatics or those related to telecommunications traffic or to their
users, or other data that could help reveal the truth.
To input a system of information in whole or in part or a medium
information, including stored data that may help reveal the truth. If the
data entry of the information system proves to be unnecessary or impossible to carry out, the
data related to the offense as well as those allowing their reading and their
understanding will be copied onto a computer medium to ensure
the authenticity and integrity of their content.
To collect or record in real time the data related to traffic
telecommunications through the use of appropriate technical means.
In cases where the necessity of the investigation requires it, the public prosecutor or the judge
of instruction may resort to the interception of communications of suspects, under a
written and reasoned decision. In the same cases, based on the reasoned report of the police officer
judiciary authorized to ascertain the offenses, the interception of communications of suspects
may also take place, and this, by virtue of a written and reasoned decision of the prosecutor of
the Republic or the investigating judge.
Paragraph 2. Cooperation with technical agencies
They are also authorized to access directly or with the assistance of experts any system.
IT support and conduct an investigation in order to obtain the stored data.
can help to reveal the truth.
The competent services of the Ministry of National Defense and the Ministry of the Interior
ensuring the operation of data entry, its location and the access process to the systems
of information, to data, to stored information, to software and to all these supports
related to the two ministries, each according to its area of expertise.
The interception of communications includes the obtaining of access data, eavesdropping, or
access to their content, their reproduction, their recording using means
techniques appropriés et en recourant, en cas de besoin, aux structures compétentes,
each according to the type of service provided.
Part 2: the limits of the Tunisian legal framework on cybercrime in the face of protection
data
The fight against cybercrime, a form of delinquency that ignores borders, demands
necessarily an international cooperation. The European content is at the forefront in this
fight and benefit from the action of the Council of Europe and the European Union whose cooperation
Police and judicial matters are becoming increasingly integrated.
possibility of invoking the exception of lack of reciprocity and any other plea of inadmissibility.
The principle of sovereignty indeed allows states to evade their obligation to
cooperation, especially when there may be some tensions between them. The second limit
is related to the difficulties associated with the scope of the letter of request. The execution of the
The letter rogatory depends on the national legislation of the state receiving the request.
letter rogatory being executed in accordance with the usual procedural rules and
from the requesting State and not from the State of origin. Bilateral treaties, when they
existing, can limit the object and scope of the letters rogatory. Some treaties
limit the commission rogatory to the hearing of witnesses or the production of documents to
conviction or judicial documents. Other investigative measures can be
subordinate to particular conditions. Thus, it is generally difficult to obtain
positive responses from certain states such as Russia, China, or Israel that show themselves
sometimes reluctant to share data stored with their service providers
Internet. It was also reported to the reporters that the Swiss police services
rarely wished to cooperate and directed their French colleagues towards this
Judicial procedure. The American judicial authorities would not be very
allies in the field of international judicial cooperation, while the GAFAM are
American companies. Moreover, during the signing of the convention on the
cybercrime of the Council of Europe, in 2001 (see below), many states have issued
reserves concerning requests for the execution of letters rogatory, if the condition of
double jeopardy was not fulfilled. Indeed, the letter of request assumes
also a double incrimination, namely the incrimination of the offense in both
Concerned states. However, many cybercrimes are currently excluded from any
incrimination in many States, thus rendering the letter rogatory ineffective
In many cases. This difference in the applicable national rules can
compromise the investigation of transnational offenses, which allows for the
cybercriminals continue to escape justice. This difficulty can be found in the
fight against online money laundering. The standards of the Financial Action Task Force
(GAFI) define the terms of international cooperation and provide for reciprocity in
information exchanges. However, according to Tracfin, the quality of working relationships varies.
much depending on the willingness for cooperation of its foreign interlocutors: exchanges
are very good in Europe, good with the countries of Central and South America and those of
Golf countries, who have adopted a cooperative approach, but they are less so with China and
even the United States, especially since the financial intelligence services of these
the latter would have much more limited investigation powers, which diminishes the interest
the transmitted information.
Section 2: Difficulties related to the complexity of procedures
- Bureaucratic burden
- Difficulty of gathering evidence + definition of the responsible party
Decree-Law No. 2022 - 54 does not transpose the provisions related to the preservation of
data from the Budapest Convention on Cybercrime (articles 16, 17, 29, and 30).
In terms of interceptions relating to content, articles 54 to 56 of organic law no.
2015-26 of August 7, 2015 relating to the fight against terrorism and repression of
money laundering allows, 'when the necessity of the investigation requires it,' to 'resort to
at the interception of communications of the defendants," which includes "the data of
flow, listening, or access to their content, their reproduction, their recording,
control of the public prosecutor or the examining judge (art. 54).
Finally, the encryption does not meet the requirements of decree n°2001-2727 of the 20
November 2001 is prohibited by article 9 ofTelecommunications CodetonsArticle 87 of this
same code repressing notably the use and detention with a view to their distribution
free or costly access methods. The liability of access providers is not
not specifically regulated, and Article 87 of the Telecommunications Code not requiring
no fraudulent intent, the possible liability of access providers for having
transported illegal means of cryptology, based on these articles, remains in question
(en matère civile, par applicaton des artcles 82 et 83 du Code des obligatons et des
contracts (COC), access providers do not seem to be able to be held responsible
that if they can technically act, know that they must act and do not act).
information for at least two years and potentially more, by joint order of
criminal proceedings.
electronics). It is generally accepted that the analysis of this type of data can
allow for precise conclusions about the individuals involved, such as the
daily movements and others, the activities undertaken, the social relationships of these
Section 2: risks related to the infringement of freedom of expression