CSL CSL International Cybersecurity Law 1 — Questions and Answers
Question 1: Which international treaty, opened for signature in 2001, is the primary multilateral agreement on cybercrime harmonization?
- UN Convention on Cybercrime
- Budapest Convention on Cybercrime (Correct answer)
- Tallinn Manual Framework
- G20 Digital Economy Agreement
Correct answer: Budapest Convention on Cybercrime
The Council of Europe's Budapest Convention is the first international treaty on cybercrime, establishing common criminal offenses and procedural tools across signatory nations.
Question 2: What mechanism does the EU's General Data Protection Regulation (GDPR) provide for lawfully transferring personal data to the United States?
- The EU-US Safe Harbor Framework (still in effect)
- Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework (Correct answer)
- GDPR Article 6 legitimate interests only
- UN data transfer protocols
Correct answer: Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework
Following the invalidation of Safe Harbor (Schrems I) and Privacy Shield (Schrems II), Standard Contractual Clauses and the 2023 EU-US Data Privacy Framework are the primary transfer mechanisms.
Question 3: Under GDPR, what is the maximum fine for the most serious violations of data protection obligations?
- €10 million or 2% of global annual turnover
- €20 million or 4% of global annual turnover (Correct answer)
- €50 million or 10% of global annual turnover
- Unlimited fines at member state discretion
Correct answer: €20 million or 4% of global annual turnover
GDPR Article 83(5) provides for fines up to €20 million or 4% of total worldwide annual turnover, whichever is higher, for the most serious violations.
Question 4: The Tallinn Manual, published by NATO's CCDCOE, addresses which aspect of international law as applied to cyberspace?
- International human rights law in cyber operations
- International law applicable to cyber warfare and state-sponsored attacks (Correct answer)
- EU cybersecurity regulatory standards
- Mutual legal assistance treaty (MLAT) procedures
Correct answer: International law applicable to cyber warfare and state-sponsored attacks
The Tallinn Manual analyzes how existing international law (jus ad bellum, jus in bello, state responsibility) applies to state-sponsored cyber operations.
Question 5: Which principle of international law determines which country's laws apply when a cyberattack originates in one country but causes harm in another?
- Sovereignty principle
- Territoriality principle
- Effects-based jurisdiction (Correct answer)
- Nationality principle
Correct answer: Effects-based jurisdiction
The effects-based (or objective territorial) principle allows states to assert jurisdiction over cyberattacks that cause substantial effects within their territory, regardless of the attacker's location.
Question 6: What is the primary legal challenge in attributing state responsibility for cyberattacks under international law?
- Cyberattacks never reach the threshold for state responsibility
- The requirement to prove that the state 'directed or controlled' the specific operation (Correct answer)
- International law does not recognize cyber operations as state acts
- MLAT treaties prevent attribution claims
Correct answer: The requirement to prove that the state 'directed or controlled' the specific operation
Under the ILC Articles on State Responsibility, holding a state responsible requires showing the state directed or controlled the private actors conducting the cyber operation (Article 8).
Which international treaty, opened for signature in 2001, is the primary multilateral agreement on cybercrime harmonization?