Cybercrime Law in Europe (EU & Council of Europe)
Europe combines a foundational international treaty with EU-wide directives and regulations.
Key instruments
- Budapest Convention on Cybercrime (Council of Europe Treaty Series No. 185, opened for signature in Budapest on 23 November 2001) — the first international treaty on cybercrime, widely ratified beyond Europe. (A Council of Europe instrument, not an EU law, but foundational across the region.) Its Second Additional Protocol on enhanced co-operation and disclosure of electronic evidence was adopted on 17 November 2021 and opened for signature on 12 May 2022; EU member states were authorised to ratify it by Council Decision (EU) 2023/436. The authoritative treaty texts and the up-to-date list of parties are published by the Council of Europe Treaty Office.
- Directive 2013/40/EU of 12 August 2013 on attacks against information systems — harmonises criminal offences for illegal access, illegal system interference, illegal data interference and illegal interception, and for the tools used to commit them, across EU member states. It replaced Council Framework Decision 2005/222/JHA.
- GDPR (Regulation (EU) 2016/679) of 27 April 2016 — data protection, security of processing and personal-data breach notification.
- NIS2 Directive ((EU) 2022/2555) of 14 December 2022 — cybersecurity risk-management and incident-reporting obligations for essential and important entities. Member states had to transpose it by 17 October 2024 and apply the national measures from 18 October 2024; transposition has run late in a number of states, so check the national implementing law.
- Cyber Resilience Act (Regulation (EU) 2024/2847) of 23 October 2024 — horizontal cybersecurity requirements for products with digital elements. It applies in stages: the vulnerability-reporting obligation in Article 14 from 11 September 2026 and the Regulation generally from 11 December 2027.
- e-Evidence Regulation ((EU) 2023/1543) of 12 July 2023 — European Production and Preservation Orders, which let an authority in one member state require electronic evidence directly from a service provider in another. It has applied since 18 August 2026.
How it fits together
EU directives must be transposed into each member state’s national law, so the exact offences and penalties vary by country; EU regulations such as GDPR and the Cyber Resilience Act apply directly. Europol’s European Cybercrime Centre (EC3) and Eurojust coordinate cross-border investigations and prosecutions, and ENISA supports the NIS2 framework.
Plain-language overview, not legal advice. Read the current consolidated texts linked above, and the relevant national transposition, before relying on any of this.
Sources verified 9 August 2026 against EUR-Lex.