Home/Publications/Peer-Reviewed Article
KKTC'de Bilişim Sistemine veya Bilişim Verisine Hukuka Aykırı Erişim (Yetkisiz Erişim) Suçu
Yavuz Erdoğan, “KKTC'de Bilişim Sistemine veya Bilişim Verisine Hukuka Aykırı Erişim (Yetkisiz Erişim) Suçu”, Legal Hukuk Dergisi, 2021.
IT Law and Cybercrime Criminal Law
Translated summary; the work itself was published in Turkish.
This article examines, within the framework of criminal-law dogmatics, the offence of "unlawful access to an information system or informatics data (unauthorised access)" regulated in Article 4 of the Cybercrime Law of the Turkish Republic of Northern Cyprus (TRNC), which entered into force in 2020. The author likens the TRNC's regulation of cybercrime in a special statute to countries of the Anglo-Saxon legal tradition such as England and the United States, but argues that the statute's content contains serious deficiencies and errors.
The Statute's Basic Concepts and Their Critique
The study opens with a critical treatment of the definitions on which the statute rests.
- The definition of "information system": the author emphasises that this definition is the most fundamental problem. It permits any device capable merely of processing data — a kitchen oven, say, or a calculator — to count as an information system, needlessly widening the scope of cybercrime and complicating the fight against it. For a system to qualify, it should possess the capacities of processing, storing and transferring data.
- Other concepts: the statute is criticised for defining "data" and "informatics data" separately without need, while giving no place at all to the concept of "personal data" and its protection — vital to modern law.
Elements of the Offence of Unauthorised Access
The article analyses the offence on the basis of classical offence theory:
- The act (access): the offence's basic act is "access". The statutory definition requires "gaining the ability of use by connecting, by any means, to an electronic communications network". The author argues this is narrow and erroneous, since it leaves outside the offence such cases as intrusion into a computer not connected to any network.
- Offender and victim: anyone may be offender or victim. The author draws attention to the fact that, unlike Turkish law, TRNC law allows legal persons to be offenders.
- Subject-matter: an information system or informatics data.
- Mental element: the offence must be committed "intentionally"; negligent commission is not punished.
- Unlawfulness: the phrase "unlawfully" in the text shows that the offender must act in the consciousness that the act is unlawful — thereby preventing acts such as visiting a publicly accessible site from counting as offences.
- Attempt and participation: as a peculiarity of TRNC criminal law, both the "attempt" and the act of "assisting" are expressly punished, in the same article, together with the basic form of the offence.
Sanction and Conclusion
The sanction is a fine of up to ten times the monthly minimum wage, or imprisonment of up to three years, or both. The author observes that so wide a range of penalty may impair the principle of proportionality.
In conclusion, the author holds that enacting a special cybercrime statute was the right step, but that the law was passed in haste and without regard to the existing criticisms. The statute needs fundamental amendment: above all the rewriting of the definition of "information system", the addition of the concept of "personal data", and the alignment of its penal sanctions with the principle of proportionality.