Questions and Answers: The ICC Office of the Prosecutor's Policy on Cyber-Enabled Crimes under the Rome Statute

Image
cover-eng
1. What is the main content of the Policy?

This Policy sets out how the Office of the Prosecutor (OTP) can apply its existing mandate to investigate and prosecute crimes under the Rome Statute, including when they are committed or facilitated through cyber means. It reflects the growing reality that digital technologies may increasingly be used to enable serious crimes — for instance, to plan or coordinate attacks, incite violence, or manipulate evidence.

2. Why did the OTP develop the Policy? And why now?

The growing use of cyberspace is already transforming the way that international crimes may be committed, and this is likely to continue. The digital sphere or digital ecosystem or cyberspace can now be used to plan, facilitate, or even directly commit acts that may amount to genocide, crimes against humanity, war crimes, or offences against the administration of justice at the ICC. The Policy sets out the Office’s interpretation of how the Rome Statute applies to cyber-enabled conduct, and provides principles and guidance for identifying, investigating, and prosecuting such crimes within the Court’s jurisdiction.
The OTP’s Policy—which is the first to address the implications of new technology in this way—comes as part of a much broader series of expert initiatives and other measures addressing the misuse of cyberspace and its implications for international law more generally. Critically, these measures all affirm that cyberspace is not a ‘law free zone’. This important principle applies no less to international criminal law.

3. What are the key objectives of the Policy?

Among other objectives, the Policy seeks to:

  • Affirm the OTP’s commitment to investigating and prosecuting cyber-enabled crimes under the Rome Statute on an equal basis with crimes committed by other means;
  • Demonstrate that the Rome Statute remains relevant in the context of technological change;
  • Contribute to the development of international law on conduct in cyberspace which amounts to or facilitates core international crimes;
  • Strengthen institutional expertise and training within the OTP;
  • Encourage and support national efforts to address such crimes;
  • Enhance cooperation with civil society, corporations, and other non-State actors.
4. What does the term “cyber-enabled crimes” mean in this context?

By “cyber-enabled crimes”, the OTP Policy refers to two categories of conduct:

  1. The use of cyber means to commit one or more crimes under the Rome Statute (for example, directing attacks on civilian infrastructure using digital tools); and
  2. The use of means to facilitate such crimes, irrespective whether they are carried out by cyber means or otherwise (for example, online incitement to violence or use of digital platforms to coordinate or facilitate attacks).
    Importantly, many of the same practical considerations discussed in the Policy are also relevant even when proving crimes which are only committed and facilitated physically. In other words, the Policy is potentially relevant for the OTP’s work addressing all crimes within the jurisdiction of the ICC, however they may be carried out.
5. Does the ICC have jurisdiction over all cybercrimes? Is the ICC expanding its jurisdiction?

No. The ICC’s jurisdiction does not extend to ‘ordinary’ cybercrimes (prohibited under national laws) such as hacking, fraud, or identity theft, unless those acts form part of or facilitate crimes already defined in the Rome Statute.
The ICC’s work is thus limited to the most serious crimes of international concern — genocide, crimes against humanity, war crimes, and the crime of aggression. The ICC also has jurisdiction over offences against its own administration of justice.
Nothing in the OTP’s Policy expands the ICC’s jurisdiction, which is determined by the Rome Statute—an international treaty.

6. How will this Policy affect ongoing or future investigations?

The Policy will guide the OTP’s next steps in integrating cyber elements into its investigations where relevant. It will help the OTP as it continues to improve its ability to identify, preserve, collect, and analyse digital evidence. It also ensures that Rome Statute crimes facilitated or committed through cyber means are recognised and investigated on an equal basis with other forms of conduct. As with all its investigations, the OTP will continue to be guided by a variety of factors including the gravity of the alleged conduct.

7. What types of international crimes could be “cyber-enabled”?

As the Policy explains, in principle, the crimes in the Rome Statute are ‘technology neutral’. This means that, provided the elements of the crimes are satisfied, the particular means which may be used by the suspect do not matter. This is important because it helps ensure that the Rome Statute remains relevant even as the world changes and develops.

Consequently, all five types of crime in the Rome Statute can be committed through cyber means. Examples include:

  • Genocide, which is characterised by the perpetrator’s intention to destroy a protected group in whole or in part—relevant conduct might include cyber-attacks on services essential to human life, resulting in the deaths of members of a protected group, or online statements which directly and publicly call for the killing of members of that group;
  • Crimes against humanity, which are characterised by a widespread or systematic attack against a civilian population, not necessarily in armed conflict—relevant conduct might include killing on a mass scale by means of a cyber-attack, or the use of advanced technologies as part of a campaign to severely deprive persons of internationally recognised human rights because of their ethnicity, in connection with other crimes;
  • War crimes, which are characterised by the existence of an armed conflict—relevant conduct might include the use of certain types of malware causing prohibited effects on a variety of both military and civilian computer systems, without distinction, or the use of the internet to publish humiliating images of persons in captivity such as prisoners of war;
  • Aggression, which is characterised by the prohibited use of force by one State against another State, carried out by a person in a leadership position and amounting to a manifest violation of the United Nations Charter—relevant conduct might include a cyber-attack by the armed forces of one State against the armed forces of another State, causing numerous deaths;
  • Offences against the administration of justice at the ICC—relevant conduct might include tampering with evidence by intentionally deleting certain data, witness intimidation by a campaign of online harassment, or leaking confidential information through cyber channels.

Furthermore, since in principle any form of conduct may facilitate the Rome Statute crimes above, provided it is legally sufficient and carried out with the necessary intent and knowledge, this necessarily also includes conduct in cyberspace.

8. Are there already examples of cyber-enabled crimes investigated or prosecuted under the Rome Statute?

There are currently no publicly known cases before the ICC focusing specifically on cyber-enabled crimes. Moreover, since the focus of OTP investigations is determined significantly by the gravity of alleged crimes, and OTP investigations are often confidential until proceedings are well advanced, it is not possible to say when the first case focused on cyber-enabled crimes might be seen at the ICC. However, these practical considerations do not mean that the issue is not important. To the contrary, the existence of the Policy marks the OTP’s public recognition that conduct in cyberspace may increasingly play a role in the commission or facilitation of Rome Statute crimes, as well as in proving them.

9. How will the OTP ensure it has the necessary expertise to address cyber-enabled crimes?

The OTP already has a dedicated Cyber Unit, as well as other staff members with relevant skills and expertise. However, the Policy commits the Office to further developing its capabilities and practices in this area. This includes:

  • Recruiting and training staff with additional digital, forensic, and technical expertise;
  • Strengthening cooperation with specialised national and international agencies;
  • Building partnerships with academia, civil society, and the private sector;
  • Further enhancing internal procedures for handling digital evidence securely and effectively.
10. How will the OTP cooperate with national authorities on these issues?

The OTP seeks to cooperate with national authorities where feasible and appropriate, including by participating in joint investigations in suitable circumstances and providing expertise and direct support to national authorities in response to requests for assistance. The OTP’s cooperation is always consistent with its independent mandate and its responsibilities under the Rome Statute. While the transnational nature of conduct in cyberspace may make effective cooperation especially, the OTP’s approach is the same as it is for all investigations, as explained in its Policy on Complementarity and Cooperation.

If circumstances arise where both the ICC and a State are exercising jurisdiction over the same case, this will be resolved in accordance with the principle of complementarity in the Rome Statute. Where genuine and effective national proceedings are underway, the ICC will defer to the State’s exercise of jurisdiction.

11. How does this Policy relate to broader international efforts on cybercrime?

While the ICC’s jurisdiction does not extend to ‘ordinary’ cybercrimes under national laws, such conduct may in certain cases nevertheless intersect with crimes under the Rome Statute. As such, the OTP’s investigations in this area may likewise intersect with broader national and international efforts to counter harmful uses of cyberspace. 

By clarifying its own approach, the OTP aims to contribute to the development of international best practices and jurisprudence in this field, complementing rather than duplicating other initiatives. No less important, by recognising the intersections between its own work and that of States, the OTP also seeks to learn from cutting-edge national techniques.

12. Does the Policy create new legal obligations or expand the Rome Statute?

No. The Policy does not amend or expand the Rome Statute. It interprets and applies the Statute in light of technological developments. The Office is not seeking new powers; it is clarifying how existing ones apply to cyber-related conduct.

13. How was this Policy developed?

The Policy was developed through an extensive process, including written input and discussions with staff, States Parties, legal and technical experts, civil society including representatives of the private sector, and academia. The Policy was further edited and revised on the basis of a public consultation.

14. How will the OTP protect sensitive digital data and privacy in these investigations?

The OTP adheres to strict data protection, confidentiality, and chain-of-custody standards for all forms of evidence, including digital material.

The Policy reinforces these principles, emphasising responsible handling of data, respect for privacy, and the security of digital information collected during investigations.

15. Why is the launch of this Policy significant for the Assembly of States Parties?

The ASP brings together States Parties and observers to discuss the implementation of the Rome Statute. Launching the Policy at this forum underscores the OTP’s commitment to innovation, partnership, and accountability in a rapidly changing world. It also invites States to consider how national systems can better address cyber-enabled crimes that may amount to international crimes.

16. What message does this Policy send to victims and affected communities?

The Policy sends a clear message that the Office will seek to ensure the full and effective use of the provisions of the Rome Statute regardless of the means which perpetrators use to commit international crimes. Whether crimes are carried out through physical violence or digital tools, the OTP will adapt its methods to ensure accountability and protection for victims, within the framework and the confines of the Statute.

17. How does this Policy relate to threats or attacks directed against the ICC, including cyber-interference targeting the Court and its officials?

The Policy strengthens the OTP’s capacity to detect, document, and, where appropriate, investigate conduct that amounts to an interference with the administration of justice at the Court — including where such interference is carried out by the use of cyberspace.

The ICC has in recent years seen various attempts to exert pressure on the institution and its proceedings, including cyber-attacks. Since the OTP has primary responsibility for investigating offences against the administration of justice at the ICC, these further underscore why the OTP must be equipped to respond to conduct in cyberspace aimed at undermining the ICC’s independent judicial mandate.

This Policy helps the Office further ensure that such conduct — whether through traditional or digital means — can be properly assessed and, when within the Court’s jurisdiction, investigated and prosecuted. 

cyber policy_FAQs_web eng.jpg