Cyber Confidence-Building Measures

CBM 6: Legislation to facilitate co-operation

Organization for Security and Co-operation in Europe

OSCEWidely implemented2013

Measure

CBM 6 (2013): Participating States are encouraged to have in place modern and effective national legislation to facilitate on a voluntary basis bilateral co-operation and effective, time-sensitive information exchange between competent authorities, including law enforcement agencies, of the participating States in order to counter terrorist or criminal use of ICTs. The OSCE participating States agree that the OSCE shall not duplicate the efforts of existing law enforcement channels.

Background: Transnational cooperation is essential for detection, investigation, and prosecution enabling timely information sharing, coordinated responses, and the harmonization of legal frameworks to combat cybercrime. This CBM encourages OSCE participating states to adopt national legislation that enables timely and voluntary cooperation between law enforcement and other relevant authorities in combating the criminal or terrorist use of ICTs. The goal is to strengthen cross-border cooperation by having clear and trusted legal pathways in place while avoiding duplication of existing mechanisms - thus, it describes steps to consider by states at the national level. Measures may include streamlining legal frameworks for data sharing, harmonizing procedures for digital evidence exchange, and designating national contact points for urgent cybercrime-related cooperation.

Practice: This CBM is widely implemented, as the vast majority of OSCE participating states have legal frameworks in place to support cross-border cooperation against the criminal or terrorist use of ICTs. A key example is the Budapest Convention on Cybercrime, which entered into force in 2004 and has since been signed and/or ratified by 85% of OSCE states. The Convention establishes a legal basis for international cooperation through timely information sharing, mutual legal assistance, and expedited access to stored and traffic data. Beyond this, all OSCE states are members of Interpol, while EU member states additionally participate in Europol; many non-EU OSCE members have formal cooperation agreements with Europol (covering another 85% of the OSCE, though Russia is currently suspended). Since both organizations prioritize coordinated information exchange, such memberships further illustrate how legal and institutional mechanisms for cooperation exist across the region. More recently, in December 2024, the United Nations Convention against Cybercrime was adopted, though it has not yet entered into force. Collectively, these instruments underscore the shared commitment to international cooperation and the establishment of processes to counter terrorist or criminal use of ICTs.

The annual C-PROC overview further highlights that legislative reform in this area is a global, ongoing process. By December 2024, 95% of UN member states had reformed or were in the process of reforming legislation on cybercrime and electronic evidence. Taking a closer look at the regions with participating states within the OSCE; Europe was at 100%, the Americas at 97%, and Asia at 90%. It is important to stress, however, that such efforts are not undertaken for the purpose of implementing this CBM. Rather, the CBM serves as an affirmation of these broader goals and provides a dedicated platform for dialogue. Each IWG meeting includes a standing agenda item for national updates, including legislative developments. In addition, the OSCE conducts capacity-building activities that strengthen implementation, such as workshops linked to CBM 2 and CBM 4, as well as its “Regional Capacity-Building Project on Combating Cybercrime in Central Asia.” This multi-year project, launched in 2020 with support from Germany, the US, and others, targets states that are neither signatories to the Budapest Convention nor members of Europol (Kazakhstan, Kyrgyzstan, Tajikistan, Turkmenistan, and Uzbekistan). Its activities focus on four pillars: strengthening training institutions, developing digital forensic capacity, enhancing regional cooperation, and raising awareness among policymakers and the public - all while embedding human rights considerations. A dedicated training guide on integrating human rights into daily criminal justice practice was also released. By mid-2024, nearly 600 police officers and prosecutors from the region had received OSCE training, while law enforcement institutions were equipped with IT systems and educational materials to support cybercrime education. The project has also fostered new professional networks and partnerships, building on earlier workshops that addressed capacity gaps in the region. Ultimately, effective international cooperation in combating cybercrime depends not only on legal frameworks but also on the capacity of states to put them into practice.

Key Implementation Activities and Resources

  • Participating states exchange information on national legislative developments and legal frameworks that facilitate international cooperation against cybercrime and the criminal use of ICTs.

  • International legal frameworks implicitly support the implementation, more explicitly OSCE cybercrime capacity-building projects, specialised training programmes, digital forensics support, and regional cooperation initiatives drive implementation forward.