When a cybercriminal in Mumbai hacks into a server in London to steal data stored in New York, which country has the right to prosecute? This question sits at the heart of one of the most complex challenges in modern law enforcement. The borderless nature of cyberspace has forced nations to rethink traditional concepts of jurisdiction, leading to the creation of the world’s first international treaty on cybercrime.

Table of Contents

What is the Budapest Convention on Cybercrime?

The Convention on Cybercrime, commonly known as the Budapest Convention, is the first binding international treaty designed to address internet and computer crime. Adopted by the Council of Europe on November 8, 2001, it was opened for signature in Budapest on November 23, 2001, and entered into force on July 1, 2004.

The Convention was developed through collaboration between Council of Europe member states and observer states including Canada, Japan, the Philippines, South Africa, and the United States. As of August 2025, 81 states have ratified the convention, making it the most widely adopted international framework for combating cybercrime.

Core objectives of the Convention

The Budapest Convention pursues three interconnected goals that form the backbone of international cybercrime cooperation.

Harmonizing national laws

The Convention requires member states to criminalize specific cyber-related offenses in their domestic legislation. These include illegal access, data interference, system interference, computer-related fraud, and distribution of child abuse material. By establishing common definitions and standards, the treaty ensures that a cybercrime prosecuted in Germany is also recognized as criminal conduct in Argentina or Japan.

Establishing investigative procedures

The Convention mandates that countries adopt specific procedural powers to investigate cybercrimes effectively. These include mechanisms for expedited preservation of stored data, production orders for electronic evidence, search and seizure of computer data, and real-time collection of traffic data. The treaty also requires adequate protection of human rights and incorporation of the principle of proportionality in applying these investigative powers.

Facilitating international cooperation

Perhaps most critically, the Convention establishes frameworks for rapid cross-border cooperation. It functions as a mutual legal assistance treaty when countries involved in a request do not have an existing agreement. The treaty also established a 24/7 network of contact points to ensure immediate assistance in urgent cases.

Jurisdiction provisions under the Convention

Article 22 of the Budapest Convention addresses the fundamental question of jurisdiction over cybercrimes. The Convention requires each member state to establish jurisdiction over offenses when certain conditions are met.

Territorial jurisdiction

States must establish jurisdiction when the offense is committed within their territory. This includes crimes committed on board ships flying their flag or aircraft registered under their laws. This territorial principle remains the primary basis for prosecution, reflecting traditional concepts of sovereignty.

Nationality jurisdiction

The Convention also requires states to establish jurisdiction based on the nationality of the offender. Article 22 mandates state parties to provide for territorial and nationality-based jurisdiction, meaning a state can prosecute its own nationals for cybercrimes committed abroad, provided the offense is punishable where it occurred or was committed outside any territorial jurisdiction.

Alternative jurisdiction principle

The Convention incorporates the principle of “extradite or prosecute.” When an alleged offender is present in a state’s territory and that state refuses to extradite based solely on nationality, the state must submit the case to its competent authorities for prosecution. This ensures accountability even when extradition is not possible.

Consultation in concurrent jurisdiction cases

Recognizing that multiple states may claim jurisdiction over a single cybercrime, the Convention provides that when this occurs, the parties involved shall consult to determine the most appropriate jurisdiction for prosecution. This prevents conflicts and ensures efficient use of resources.

International cooperation mechanisms

The Convention goes beyond establishing jurisdiction to create practical mechanisms for cooperation between law enforcement agencies across borders.

Expedited preservation of data

One state can request another to quickly preserve computer data stored within its territory while formal mutual legal assistance requests are prepared. This addresses the critical problem of volatile electronic evidence that can be deleted or lost within hours.

Trans-border access to stored data

Article 32 of the Convention allows states to access publicly available data regardless of location and to access data in another country with lawful consent of the person authorized to disclose it. This provision constitutes an exception to the principle of territoriality and has been particularly important for cloud computing investigations.

The 24/7 network

Each member state must designate a contact point available around the clock to provide immediate assistance. These contact points facilitate technical advice, data preservation, evidence collection, and locating suspects across borders.

Evolution and additional protocols

The Convention has evolved to address emerging challenges in cyberspace.

The First Additional Protocol, which entered into force on March 1, 2006, requires states to criminalize dissemination of racist and xenophobic material through computer systems, along with threats and insults motivated by racism or xenophobia.

A Second Additional Protocol was adopted to address challenges posed by cloud computing and the need for enhanced cooperation in obtaining electronic evidence. The protocol was designed to address the disconnect between territorial jurisdiction of states and the ways data moves across borders, recognizing that more than half of criminal investigations now involve cross-border requests for electronic evidence.

Global impact and reach

The Convention has influenced cybercrime legislation far beyond its member states. The Budapest Convention reinforced a process of legislative reform worldwide, serving as a guideline to at least 120 states that have carried out or are undertaking cybercrime law reforms. This widespread adoption has facilitated a minimum level of harmonization in cybercrime legislation around the world.

Beyond Europe, countries from diverse regions have joined the Convention. Non-Council of Europe states that have ratified include Argentina, Australia, Brazil, Canada, Chile, Colombia, Ghana, Israel, Japan, Kenya, Mexico, Nigeria, South Korea, Sri Lanka, and the United States, among many others.

Challenges and criticisms

Despite its success, the Convention faces ongoing debates and challenges.

Data sovereignty concerns

Some nations, including Russia and China, have opposed the Convention on grounds of national sovereignty. They argue that provisions allowing trans-border access to data infringe on state sovereignty and have proposed alternative frameworks through the United Nations.

Human rights considerations

Critics have raised concerns about potential impacts on privacy and civil liberties. While the Convention requires adequate protection of human rights and the principle of proportionality, implementation varies across member states, leading to concerns about surveillance and data protection.

Technical and practical limitations

The Convention was drafted before the explosive growth of cloud computing and social media. While additional protocols have addressed some gaps, the rapid pace of technological change continues to create challenges for the treaty’s application.

India’s position on the Budapest Convention

India has notably remained outside the Budapest Convention framework, despite significant cybercrime challenges. India declined to adopt the Convention citing concerns about participation in its negotiation, though the country has been reconsidering its position since 2018 due to increasing cybercrime.

According to the Intelligence Bureau, data sharing with foreign law enforcement agencies raises concerns about national sovereignty. Despite these reservations, India’s Information Technology Act of 2000 and its 2008 amendments brought Indian legislation broadly in line with Budapest Convention standards, demonstrating the treaty’s influence even on non-member states.

India has instead supported a United Nations convention on cybercrime that was officially adopted in December 2024, reflecting the ongoing global debate about how best to govern cyberspace and combat international cybercrime.

The future of international cybercrime jurisdiction

The Budapest Convention represents a milestone in international criminal law, demonstrating that nations can cooperate effectively on complex jurisdictional issues in the digital age. Its framework of territorial and nationality-based jurisdiction, combined with practical cooperation mechanisms, has provided a workable model for addressing crimes that transcend borders.

However, as technology evolves and cyber threats grow more sophisticated, the Convention continues to adapt through additional protocols and guidance notes from the Cybercrime Convention Committee. The success of future international efforts in combating cybercrime will depend on balancing effective law enforcement with protection of fundamental rights, respecting sovereignty while enabling necessary cooperation, and bridging diverse approaches between nations with different governance models.

What do you think? Should countries prioritize data sovereignty or international cooperation when dealing with cybercrime? How can jurisdictional frameworks keep pace with rapidly evolving technology while protecting individual rights?

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

We are sorry that this post was not useful for you!

Let us improve this post!

Tell us how we can improve this post?

References
  1. https://www.coe.int/en/web/cybercrime/the-budapest-convention
  2. https://en.wikipedia.org/wiki/Budapest_Convention_on_Cybercrime
  3. https://eur-lex.europa.eu/EN/legal-content/summary/convention-on-cybercrime.html
  4. https://www.crossborderdataforum.org/budapest-convention-what-is-it-and-how-is-it-being-updated/
  5. https://www.tandfonline.com/doi/full/10.1080/13600869.2022.2061888
  6. https://rm.coe.int/1680081561
  7. https://www.eurojust.europa.eu/sites/default/files/assets/trans-border-access-to-stored-computer-data-under-article-32-of-the-budapest-convention-on-cybercrime-and-extraterritorial-powers-23-01-2024.pdf
  8. https://rm.coe.int/16802fa3e0
  9. https://www.drishtiias.com/daily-news-analysis/convention-on-global-cybercrime
  10. https://cis-india.org/internet-governance/blog/budapest-convention-and-the-information-technology-act
  11. https://jsis.washington.edu/news/cybersecurity-profile-2025-india/

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

Regulation of Cyberspace

1 Domestic Laws- Backgrounder

  1. Challenges to Laws
  2. Information Technology Act 2000
  3. Critiques of the I.T. Act
  4. Proposed Amendments to the I.T. Act

2 Information Technology Act โ€“ Part-I

  1. Statement of Objects and Reasons
  2. Application of the Act โ€“ The Extra-Territorial Effect
  3. Digital Signatures
  4. E-governance

3 Information Technology Act โ€“ Part-II

  1. Adjudication (Chapter IX)
  2. Penalties and Offences (Chapter IX & XI)
  3. Network Service Provider Liability (Chapter XII)
  4. Amendments to Certain Statutes

4 International Treaties, Conventions and Protocols Concerning Cyberspace

  1. United Nations Commission on International Trade Law
  2. World Summit on Information Society
  3. United Nations Commission on Trade and Development
  4. Council of Europe
  5. World Trade Organization
  6. World Intellectual Property Organization

5 Guidelines Issued by Various Ministries

  1. Broadband Policy 2004
  2. .IN Internet Domain Name โ€“ Policy Framework
  3. Draft Policy Guidelines on Web-site Development Hosting and Maintenance
  4. New Telecom Policy 1999 (NTP 1999)
  5. Information Technology Security Guidelines
  6. SEBI Guidelines on Internet-based Trading and Services
  7. Guidelines for Setting up of International Gateways for Internet

6 Introduction to Computer Wrongs

  1. Computer Wrongs
  2. Classification of Computer Crimes
  3. Technology-neutral and Technology-based Laws
  4. Regulation Versus Freedom on the Internet
  5. Information Technology Act 2000
  6. Convention on Cyber Crime โ€“ Council of Europe

7 Conventional Crimes Through Computer

  1. Cyber Defamation
  2. Digital Forgery
  3. Cyber Pornography
  4. Cyber Stalking/Harassment
  5. Online Gambling
  6. Online Sale of Illegal Articles

8 Crimes and Torts Committed on a Computer Network and Relating to Electronic Mail

  1. Hacking/Unauthorized Access
  2. Denial of Service
  3. Crimes Relating to Electronic Mail: E-mail Spamming/E-mail Bombing
  4. Crimes Relating to Electronic Mail: E-mail Spoofing

9 Crimes Relating to Data Alteration/Destruction

  1. Internet Fraud and Financial Crimes
  2. Virus Worms Trojan Horses and Logic Bombs
  3. Theft of Internet Hours
  4. Salami Attacks
  5. Data Diddling
  6. Steganography

10 Issues of Jurisdiction and Applicable Law in Cyberspace

  1. Jurisdiction in Cyberspace
  2. Theories of Jurisdiction in Criminal Cases
  3. General Jurisdiction in Computer Crimes
  4. Application of โ€˜Effectsโ€™ Doctrine in Computer Crimes
  5. Convention on Cyber Crime โ€“ Council of Europe
  6. Applicable Law in Computer Crimes

11 Enforcement Issues in Cyberspace

  1. Prevention
  2. Detection of Crime
  3. Use of Cyber Forensics
  4. On-going Efforts in India

12 Online Dispute Resolution

  1. Internet Fraud and Financial Crimes
  2. Theories of Jurisdiction in Criminal Cases
  3. Prevention
  4. Online Dispute Resolution (ODR)