Milestones: 25 years of international co-operation powered by the Convention on Cybercrime (Budapest Convention)


In 1997, the Council of Europe decided that it was time to negotiate the first international treaty on cybercrime. On 23 November 2001, the Convention on Cybercrime was opened for signature in Budapest and since then 82 countries have become Parties.

The Budapest Convention has been a cornerstone for countries worldwide, offering a model framework that has guided the development of national legislation and institutional capacities aimed at effectively preventing and combating cybercrime.

We invite you to explore below the key milestones!
 

START HERE

 
2001

23 November 2001

Convention opens for signature

 
2003

28 January 2003

1st Additional Protocol on the criminalisation of acts of a racist and xenophobic nature

 
2001-2005

2001 – 2005

Albania, Croatia, Estonia, Hungary, Lithuania, North Macedonia, Romania, Slovenia, Bulgaria, Cyprus, Denmark join the Convention

 
2004

1 July 2004

Convention enters into force

 
2006-2010

2006– 2010

Armenia, Bosnia and Herzegovina, France, Netherlands, Norway, Ukraine, Finland, Iceland, Latvia, Italy, Slovakia, Germany, Moldova, Serbia, Azerbaijan, Montenegro, Portugal, Spain and the United States of America (in 2006), as the first non-member of the Council of Europe, join the Convention

 
2012

2012

The T-CY begins to carry out assessments of implementation and to adopt Guidance
Read more about assessments and Check the Guidance Notes

 
2013

2013

Guidance Notes on DDOS attacks, the provisions of the Budapest Convention covering botnets, identity theft and phishing in relation to fraud, new forms of malware and critical information infrastructure attacks.

 
2014

2014

Cybercrime Programme Office of the Council of Europe (C-PROC) in Bucharest becomes operational

 
2014

2014

T-CY "Transborder Group" (2012-2014)
Guidance Notes on transborder access to data and spam
Read the Guidance Notes

 
2011-2015

2011 – 2015

Switzerland, United Kingdom, Australia, Austria, Belgium, Georgia, Japan, Malta, Czech Republic, Dominican Republic, Luxembourg, Mauritius, Panama, Turkey, Canada, Poland, Sri Lanka join the Convention

 
2016

2016

Guidance Note on terrorism
Read the Guidance Notes

 
2017

2017

T-CY "Cloud Evidence Group" (2015-2017)
Guidance Note on production orders for subscriber information
Read the Guidance Notes

 
2019

2019

Guidance Note on election interference
Read the Guidance Notes

 
2016-2021

2016 - 2021

Andorra, Israel, Liechtenstein, Chile, Costa Rica, Greece, Monaco, Senegal, Tonga, Argentina, Cabo Verde, Morocco, Paraguay, Philippines, Ghana, Peru, San Marino, Colombia, Sweden join the Convention

 
2021

May 2021

Second Additional Protocol on enhanced cooperation and disclosure of electronic evidence – approved by the Cybercrime Convention Committee

 
2021

November 2021

Adoption of the 2nd Additional Protocol by the Council of Europe

 
2022

12 May 2022

Opening for signature of the Second Additional Protocol by the Council of Europe. 22 Parties sign the Second Additional Protocol at the opening for signature conference [Austria, Belgium, Bulgaria, Chile, Colombia, Estonia, Finland, Iceland, Italy, Japan, Lithuania, Luxembourg, Montenegro, Morocco, Netherlands, North Macedonia, Portugal, Romania, Serbia, Spain, Sweden and the United States of America]

 
2022-2026

2022 – 2026

Another 30 countries sign the Second Additional Protocol [Andorra, Costa Rica, Croatia, Moldova, Slovenia, Sri Lanka, Ukraine, the United Kingdom, Greece, France, Germany, the Dominican Republic, Argentina, Albania, Mauritius, Canada, Malta, Hungary, Cabo Verde, Ghana, Armenia, Georgia, Czechia, Sierra Leone, Paraguay, Peru, Latvia, Fiji, Norway, Bosnia and Herzegovina]

 
2022-2026

May 2022 – April 2026

Further countries join the Convention, bringing the number of Parties up to 81 [Brazil, Cameroon, Tunisia, Sierra Leone, Grenada, Benin, Fiji, Kiribati, Ecuador, Rwanda, Sao Tome and Principe, Vanuatu, New Zealand] and the number of countries have signed or been invited to accede to 16

 
2022

November 2022

New Guidance Note adopted by the T-CY - on Ransomware

 
2023

January 2023

20th anniversary of the First Additional Protocol to the Convention on Cybercrime and Iceland joining the First Protocol

 
2023

9 February 2023

Serbia becomes the first state to ratify the Second Additional Protocol to the Convention on Cybercrime

 
2023

August 2023

Japan becomes the second state to ratify the Second Additional Protocol

 
2024

August 2024

Application of the Budapest Convention was extended to Curaçao, This marks the first time that the Cybercrime Convention is extended by a Party to any other territory.

 
2025

January 2025

Application of the First Additional Protocol to the Convention on Cybercrime extended to Curaçao. This follows the application of the Budapest Convention having been extended to Curaçao in June 2024, marking the first time the Convention was extended by a Party to any other territory.

 
2025

June 2025

The T-CY adopts a new Guidance Note, on Spontaneous Information.

 
2026

5 February 2026

Hungary became the third state to ratify the Second Additional Protocol, after Serbia and Japan in 2023

 
2026

15 April 2026

Costa Rica becomes the fourth state to ratify the Second Additional Protocol, after Serbia, Japan and Hungary

To be continued...