
Industries in Focus
Last updated:
8 min.
Based on the research work of Dr. iur. Dr. rer. pol. Fabian M. A. Teichmann
On December 24, 2024, the UN General Assembly adopted something historic: the first global convention against cybercrime. It is the first universal treaty under international law that defines crimes in and through cyberspace, creates cross-border investigative powers, and aims to facilitate worldwide judicial cooperation. For companies operating internationally, working with data, or using cloud services, this treaty has concrete practical consequences. Teichmann has analyzed the convention and its implications in detail (Teichmann, UN Convention against Cybercrime and Universal Human Rights Protection, Archiv des Völkerrechts 2026; ibid., UN Convention against Cybercrime and Universal Human Rights Protection, Jusletter, October 6, 2025).
What the convention regulates – and why it was created
The UN Cybercrime Convention is the first multilateral criminal law agreement in over two decades. It closes a gap that has existed for a long time: key states such as Russia, China, and India had never joined the Council of Europe's Budapest Convention of 2001. On Russia's initiative, a UN ad hoc committee was established in 2019. After tough negotiations, the committee reached an agreement in August 2024. The convention has been open for signature in Hanoi since the beginning of 2025 and will enter into force 90 days after the 40th ratification (Teichmann, Archiv des Völkerrechts 2026).
In terms of content, the treaty defines cybercrime, establishes cross-border investigative powers – such as requesting and securing electronic evidence across national borders – and sets up mechanisms for international legal assistance.
The positive side: Better prosecution of cybercriminals
One of the biggest practical problems in prosecuting cybercrime is the international network of the perpetrators: ransomware groups and phishing syndicates often operate from states that do not cooperate with the authorities of the victim countries. Law enforcement regularly leads nowhere. The UN Convention addresses precisely this point: it establishes a broader framework for cooperation – also with states that have remained aloof from the Budapest Convention. Theoretically, this means: more countries will cooperate, cross-border investigations will become easier, and the probability that perpetrators are actually held accountable will increase (Teichmann, Archiv des Völkerrechts 2026).
The problematic side: Surveillance and human rights
However, Teichmann's analysis also shows the dark sides. An unusual alliance of human rights organizations, the UN High Commissioner for Human Rights, and parts of the tech industry warns against far-reaching surveillance powers and a lack of binding rule-of-law protection mechanisms.
The core problem: The convention creates extensive extraterritorial investigative powers – such as cross-border data requests and surveillance – without sufficiently strong protection mechanisms for privacy. For companies, this means in concrete terms: authorities of various states could demand access to corporate data under the treaty – even to data stored in other countries. The protection standards offered, for example, by the GDPR in Europe could come under pressure as a result (Teichmann, Archiv des Völkerrechts 2026).
The fragmentation problem
With the UN Convention, two parallel regulatory frameworks will exist in the future: the Budapest Convention and the new UN Convention. Most Western states are likely to belong to both, while others will only join the UN Convention. This coexistence carries the risk of diverging standards. Teichmann formulates the overarching question with precision: Will digital space be governed by common fundamental principles in the future – or by a patchwork of national approaches? His finding is sober: The convention refers heavily to national law, thereby reflecting a fragmented normative landscape (Teichmann, Archiv des Völkerrechts 2026).
What this means in practice for companies
Companies should understand exactly where their data is stored and which jurisdictions they are potentially subject to as a result. The convention could facilitate access to data by foreign authorities – a factor to consider when choosing cloud providers and data center locations. GDPR compliance remains unaffected by this. Furthermore, the development of the convention should be monitored: Which states are joining, and how will the investigative powers be defined in practice?
Anyone who becomes a victim of a cyberattack should also be aware of the improved cooperation mechanisms. A criminal complaint under the convention could potentially lead to cross-border investigations that were previously impossible.
Conclusion: A double-edged sword
The UN Convention against Cybercrime is a political milestone – but not absolute progress. On the one hand, it improves international cooperation in the prosecution of cybercriminals. On the other hand, it creates far-reaching surveillance powers with insufficient human rights guarantees and deepens the fragmentation of international cyber law. For companies, it is neither a pure threat nor a pure opportunity – but rather both (Teichmann, Archiv des Völkerrechts 2026).
All source references refer to published scientific contributions by Dr. iur. Dr. rer. pol. Fabian M. A. Teichmann. The complete bibliography is documented in the list of publications (as of May 2026).
Related Posts



