As of 1 October 2026. Information only, not legal advice – see the disclaimer.
| Full title | Council of Europe Convention on Cybercrime (Budapest Convention, ETS No. 185) and its Second Additional Protocol (CETS No. 224) |
|---|---|
| Type | Treaty (with additional protocols) |
| Adopted by | Council of Europe (open also to non-member States) |
| Adopted | Opened for signature on 23 November 2001 (Convention); 12 May 2022 (Second Additional Protocol) |
| Legal status | Convention in force since 1 July 2004; 83 Parties since the accession of Seychelles on 17 September 2026 (Council of Europe); binding on Parties. Second Additional Protocol not in force: it requires five ratifications; the Council of Europe reported four (Serbia, Japan, Hungary, Costa Rica) as of 30 June 2026 |
| Official text | Council of Europe – Budapest Convention · Council of Europe – Second Additional Protocol |
| Subject area | Cybersecurity, cybercrime and critical infrastructure |
The Budapest Convention is a treaty on criminal law and criminal procedure concerning offences committed through computer systems. It requires Parties to criminalise certain conduct (offences against the confidentiality, integrity and availability of computer data and systems, computer-related forgery and fraud, content-related offences and copyright infringements), to provide procedural powers for investigations involving electronic evidence, and to cooperate internationally. The First Additional Protocol (ETS No. 189, 2003) concerns the criminalisation of acts of a racist and xenophobic nature committed through computer systems. The Second Additional Protocol provides for enhanced cooperation and disclosure of electronic evidence. The Convention is referred to in debates on cybercrime cooperation and in comparison with the UN Convention against Cybercrime.
The Convention addresses criminal conduct by individuals and does not regulate the conduct of States as such. The Cybercrime Convention Committee (T-CY) monitors its implementation and adopts guidance notes, including on the application of the Convention's offences to attacks on critical infrastructure and to election interference: the Guidance Note on critical information infrastructure attacks (T-CY(2013)11, adopted June 2013) and the Guidance Note on election interference by malicious cyber activities (T-CY(2019)4, adopted July 2019).