LawyersForPeace.Online

a curated map of the law of peace in the cyber & information sphere

User Tools

Site Tools


law:soft:pall_mall

Pall Mall Process Code of Practice for States (2025)

As of 1 October 2026. Information only, not legal advice – see the disclaimer.

Full title The Pall Mall Process Code of Practice for States (commercial cyber intrusion capabilities)
Type Political commitment (non-binding code of practice)
Adopted by States participating in the Pall Mall Process, launched by France and the United Kingdom
Adopted Published on 4 April 2025 following the Paris conference of the Pall Mall Process (3–4 April 2025); updated list of supporting States 23 October 2025
Legal status Voluntary and non-binding; according to the October 2025 version, supported by 27 States
Official text UK Government – The Pall Mall Process Code of Practice for States
Subject area Cybersecurity, cybercrime and critical infrastructure; Use of force, intervention and cyber operations

Overview

The Pall Mall Process is an initiative of France and the United Kingdom on the proliferation and irresponsible use of commercial cyber intrusion capabilities, such as commercially available spyware and hacking services. The Code of Practice for States sets out commitments for State action in relation to the development, facilitation, purchase and use of such capabilities, structured around four pillars: accountability, precision, oversight and transparency. The text describes itself as a “voluntary and non-binding” code. A separate set of guidelines for industry has been the subject of a consultation (20 November 2025 – 16 January 2026).

Provisions relevant to the cyber and information sphere

  • Accountability – commitments regarding State conduct when developing, facilitating, purchasing or using commercial cyber intrusion capabilities.
  • Precision – commitments concerning the targeted and lawful use of such capabilities.
  • Oversight – commitments concerning domestic legal frameworks and oversight mechanisms.
  • Transparency – commitments concerning transparency towards the public and other States.

Application to cyber and information operations

The Code complements the UN framework of responsible State behaviour in the use of ICTs (ict_norms) by addressing the commercial market for intrusion capabilities. According to the October 2025 version, the supporting States are Austria, Belgium, Denmark, Estonia, Finland, France, Germany, Ghana, Greece, Hungary, Italy, Ireland, Japan, Kosovo, Latvia, Luxembourg, Moldova, the Netherlands, Poland, the Republic of Korea, Romania, Slovakia, Slovenia, Sweden, Switzerland, the United Kingdom and the United States.

Recent developments

  • 2025-04-04: Code of Practice for States published after the Paris conference (UK Government).
  • 2025-10-23: Belgium added as a supporting State (UK Government).
  • 2025-11-20 to 2026-01-16: UK and France consult on industry practices for commercial cyber intrusion capabilities (UK Government).

Sources

Change log

  • 2026-10-01: Entry created.
law/soft/pall_mall.txt · Last modified: by lfpo