Canada's UN Cybercrime Convention Signing: What It Costs
Kate Robertson's Citizen Lab analysis of Canada's UN Cybercrime Convention signing and what the treaty's surveillance architecture means for OSINT and security practitioners.
Canada’s UN Cybercrime Convention Signing: What It Costs
Canada had spent years opposing the UN Convention against Cybercrime on human rights and overreach grounds. Then it signed anyway. Citizen Lab senior research associate Kate Robertson, speaking with law professor Michael Geist on the Law Bytes podcast, calls it unexpected — and the analysis she lays out in the accompanying Citizen Lab commentary has direct operational consequences for practitioners working across borders.
This is not a treaty-policy post. It is a threat-model update.
What the Convention Actually Is
The formal name is the United Nations Convention against Cybercrime: Strengthening International Cooperation for Combating Certain Crimes Committed by Means of Information and Communications Technologies Systems, adopted by the UN General Assembly in late 2024. The name is doing political work. Robertson’s more precise characterization: this is a cross-border surveillance and electronic evidence-sharing agreement dressed in cybercrime framing.
That reframe matters. “Cybercrime cooperation” sounds uncontroversial — of course states should coordinate against ransomware gangs. The actual mechanism is much broader: mutual legal assistance obligations, cross-border access to stored electronic data, and interoperability between the law enforcement systems of signatory states. Whether any given request fits the “cybercrime” label depends on how the requesting state defines the term — and the convention’s definition is deliberately elastic.
The gap between the political surface and the operational substrate is where practitioners should focus.
Why Elasticity Is the Threat
The convention’s cybercrime definition creates asymmetric risk across jurisdictions. States that already criminalize security research activities — unauthorized access statutes with no good-faith research exemption, possession-of-dual-use-tools statutes — become capable of generating evidence requests that travel through the convention’s mutual legal assistance channel into jurisdictions where the same activity is entirely lawful.
This is not a hypothetical dynamic. The Lauri Love case — a British national whose extradition to the United States for alleged computer intrusions was contested for years before UK courts blocked it — shows exactly how cross-border criminal cooperation frameworks reach into research-adjacent work under existing MLAT arrangements. The UN convention systematizes and scales that pattern to a much larger signatory base, including states with far more aggressive domestic definitions of computer crime than the US or UK.
For red teamers, vulnerability researchers, and OSINT practitioners: if you operate against infrastructure in future signatory states, your authorization documentation and methodology records are now a legal artifact, not just an operational formality.
The OSINT Dimension
Jurisdiction-Dependent Legality of Collection
Open-source collection routinely crosses national boundaries — social media platforms, government registries, domain registration records, public-forum leak indices. In most democratic jurisdictions, accessing publicly available information is not a crime. “Publicly available” is not, however, a universally shared legal concept.
Some signatory states treat data aggregation as unlawful surveillance regardless of the source. Others criminalize accessing systems without explicit authorization even where no authentication barrier exists — a definition that, applied broadly, would cover routine passive OSINT against misconfigured assets. If the convention creates an operable MLAT channel between states holding incompatible definitions of lawful collection, analysts who work across those jurisdictions acquire a new legal surface.
The exposure is sharpest for practitioners running threat intelligence on state-linked actors from authoritarian convention signatories. Retaliatory legal process from those states is not abstract — it is a tactic with documented prior use against researchers and journalists.
Access Now tracked the convention’s human rights provisions across its entire drafting history. Civil society groups raised consistent objections to language that could be turned against journalists, activists, and security researchers. Their textual analysis is the most granular public breakdown of the specific provisions at issue.
What This Does Not Break
Passive collection against infrastructure clearly within your operating jurisdiction is unaffected. Collection against clearly domestic targets under explicit authorization is unaffected. The exposure is concentrated at the intersection of cross-border collection, targets linked to states with expansive domestic cybercrime law, and collection techniques that lack explicit authorization documentation.
Defensive Security Implications
Defensive teams have a distinct but parallel problem. Incident response generates data — logs, forensic images, network captures, malware samples — that is operationally sensitive and may contain personal data. GDPR and PIPEDA provide some governance over personal data handling, but neither was designed to account for a multilateral cybercrime convention creating new legal pathways for foreign state access to incident artifacts.
A SOC operating in financial services or critical infrastructure, retaining six months of full packet capture, should know whether that data is now potentially reachable through a foreign government’s convention request. The answer depends on ratifying legislation that does not yet exist — but the architecture is committed, and the direction of travel is toward expanded access.
The Electronic Frontier Foundation’s international issues work covers the Budapest Convention — the Council of Europe instrument the UN convention partially mirrors and partially diverges from — and provides useful doctrinal context for how these access mechanisms function once implemented. The Budapest framework has been operational long enough to have a track record; it is the closest practical analogue.
Legal counsel involvement in IR planning is already considered standard. The convention adds a specific agenda item: pre-incident review of data retention policies for assets and personnel with international exposure.
Operational Steps
Not legal advice. Practitioners with specific jurisdictional exposure should consult qualified counsel.
1. Add legal process risk to your threat model. If your organization runs cross-border OSINT collection, red team operations, or vulnerability research touching infrastructure in future signatory states, foreign legal process is now a more plausible threat vector than it was a year ago. Document methodology. Retain authorization records. Know the legal basis for each collection technique.
2. Audit incident data retention with international exposure in scope. Work with legal and compliance to map which classes of IR data you hold, retention windows, and conditions under which third parties could compel disclosure. The convention is new impetus for a review that was probably overdue anyway.
3. Track ratification, not the signing. Signing is political signaling. Legal obligations attach at ratification, and scope is set by implementing legislation. Canada’s reversal from opposition to signature suggests political dynamics that may not fully resolve during ratification. Robertson’s commentary implies as much. Watch the implementing legislation — that is where the actual operational constraints will be written.
4. Engage during the ratification window. Security professionals carry technical credibility in legislative consultations that policy advocates do not. The period between signing and ratification is when community input has leverage. Robertson’s Citizen Lab analysis and the Access Now treaty-text breakdown provide technically grounded arguments you can bring into those conversations without building the case from scratch.
5. Build jurisdictional awareness into threat intelligence programs. Teams that have not previously tracked the legal environment of collection-source countries need to start. The convention makes the domestic cybercrime law of counterpart jurisdictions operationally relevant in ways it was not before.
Robertson’s contribution is not a general alarm — it is a structural diagnosis. The convention is presented as a law enforcement coordination tool; it functions as a general-purpose cross-border data access mechanism whose scope is bounded by how each signatory defines cybercrime domestically. Security researchers, OSINT practitioners, and defensive teams perform activities every day that fall within expansive versions of that definition.
The architecture is committed. Implementation and ratification are still in motion. That window is where updated threat modeling and policy engagement pay off.
Primary source: Kate Robertson, “Kate Robertson on the Risks That Lie Behind Canada’s Unexpected Signing of the UN Cybercrime Convention,” The Citizen Lab, January 2025. https://citizenlab.ca/kate-robertson-on-the-risks-that-lie-behind-canadas-unexpected-signing-of-the-un-cybercrime-convention/
Access Now, UN Cybercrime Convention analysis: https://www.accessnow.org/un-cybercrime-convention/
Electronic Frontier Foundation, International issues: https://www.eff.org/issues/international