Give Them an Inch, They’ll Take a Terabyte How States May Interpret Tallinn Manual 2.0’s International Human Rights Law Chapter

Essay - Volume 95 - Issue 7

The development of norms for [S]tate conduct in cyberspace does not require a reinvention of customary international law, nor does it render existing international norms obsolete. Long-standing international norms guiding [S]tate behavior—in times of peace and conflict—also apply in cyberspace.[1]


The recent publication of Tallinn Manual 2.0 on the International Law Applicable to Cyber Operations, the “follow-on initiative [expanding Tallinn Manual 1.0’s] scope to include the public international law governing cyber operations during peacetime,”[2] is a truly remarkable accomplishment in both cyber and international law. Unquestionably, it is the most comprehensive work ever written to describe how international law regulates cyber activities that take place below the use-of-force threshold. As this Article underscores, the significance of the Manual’s publication is further enhanced by its Chapter seeking to “articulate[] Rules indicating the scope of application and content of international human rights law [(IHRL)] bearing on cyber activities.”[3]

An international group of “scholars and practitioners with expertise in the legal regimes implicated by peacetime cyber activities”[4] (International Group of Experts) authored the Manual (Tallinn 2.0) between 2013 and 2016 over the course of a series of formal meetings and workshops held in Tallinn, Estonia.[5] Like the Manual itself, it is inevitable that the Manual’s IHRL Chapter will be studied and debated endlessly. Less concerned with this overall debate than with the need for practitioners to understand specific assertions made within the human rights Chapter, this Article closely examines certain key terms in the text to ascertain their impact on daily cyber activities at the State (national) level. A granular view of the IHRL Chapter reveals these key terms to be often vague and ill-defined, resulting in definitional gaps capable of being used by States to undermine IHRL progress over time.

After background discussion laying the foundation for IHRL and identifying the actual human rights contemplated by the International Group of Experts in the IHRL Chapter (Part II), this Article identifies several important yet undefined terms and concepts throughout the work. Part III centers on perhaps the most significant example of an undefined concept, “countering terrorism,”[6] which the Experts state without further explanation to be a “legitimate purpose” allowing States to monitor online communications without violating the right to privacy.[7] While the International Group of Experts offers checks on possible abuse, this section demonstrates the challenges of constraining a State intent on using the “countering terrorism” exception to swallow the rule requiring States to respect and protect international human rights.[8] Even key terms such as the word “terrorism” are nebulous to the reader and exemplify the ambiguity on which a State may rely to limit human rights.[9]

Part IV analogizes the gaps in 2.0 to a similarly critical, unforeseen gap in Tallinn 1.0 (above the use-of-force-threshold activities) to illustrate how both manuals similarly act as a general framework for application of international law to cyber activities while leaving specifics to be filled in by State practice. Although the International Group of Experts is not optimistic there will be more than a paucity of State practice[10] available due to secrecy challenges, and provides another vague term suggesting “effective measures”[11] will be allowed, this Article suggests there are examples of unclassified, ongoing State practices that both help define the vague “effective measures” term and indicate the ability to overcome the secrecy challenge in this area. Unclassified U.S. cyber programs designed to gather intelligence, map networks, and prepare for military operations against an adversary in the cyber realm are described here in an effort to illustrate the (perhaps) overstated secrecy concerns.[12] Finally, mindful that “[m]any commentators assert customary international law as they would like it to be, rather than as it actually is,”[13] this Article does not suggest any particular State practice has risen to the level of customary international law in these areas. Nevertheless, the aspects of State practice described infra amplify our understanding of what the IHRL Chapter seeks to achieve with its admirable efforts to codify online rights “in accordance with international human rights law.”[14]

I. Background

The United Nations Charter lays the foundation for international human rights law. While primarily a jus ad bellum instrument, the purposes and principles of the charter recognize the need for human rights and “for fundamental freedoms for all without distinction as to race, sex, language, or religion.”[15] This statement ensures the protection of persons as individuals “rather than as subjects of sovereign States” and imposes certain legal requirements on State actors.[16] Composed of both treaty[17] and customary obligations, this body of international law, as noted throughout the Tallinn Manual 2.0 IHRL Chapter, applies in cyberspace.[18]

While no definitive list of human rights in cyberspace exists,[19] certain rights are especially relevant in the cyber context. The International Group of Experts provides a nonexhaustive list of particularly important human rights applicable in cyberspace, including freedom of expression, freedom of opinion, due process, and perhaps most importantly, privacy.[20] Rule 35 of the IHRL Chapter notes the central importance of privacy in cyberspace but also cautions that the precise scope of the right is unsettled.[21] Further, the International Group of Experts acknowledges the view that the right to privacy has “not yet crystallized into a customary norm.”[22] Yet, despite these caveats, a reading of the Manual makes clear that an individual’s right to privacy in cyberspace, similar to other international human rights,[23] is to be respected and protected by State actors.[24]

Furthermore, although certain fundamental human rights are considered nonderogable,[25] such as the prohibition on slavery, the prohibition on torture, and the right to recognition as a person before the law,[26] the International Group of Experts notes that privacy “is not an absolute right and may be subject to limitations, as discussed in Rule 37.”[27] Thus, Rule 37—“[t]he obligations to respect and protect international human rights, with the exception of absolute rights, remain subject to certain limitations that are necessary to achieve a legitimate purpose, nondiscriminatory, and authorized by law”—offers a methodology for limiting the international human right of privacy in cyberspace.[28]

As a final background matter for purposes of this Article, the International Group of Experts outlines the effect of secrecy as a barrier to understanding State practice in cyberspace, arguing that “State cyber practice is mostly classified and publicly available expressions of opinio juris are sparse, [making it] difficult to definitively identify any cyber-specific customary international law.”[29] While this statement accurately captures aspects of the contemporary environment, specific State practice in cyberspace is increasingly available to the public[30] and, in time, can ripen into customary international law. Though not yet at the level of customary international law, certain State practice in cyberspace, and a discussion of its relevance, are key subjects to which this Article returns below.

II. Is Countering Terrorism a Legitimate Reason to Violate the Right to Privacy in Cyberspace?

Importantly, Rule 37 of the IHRL Chapter states that the “obligations to respect and protect international human rights, with the exception of absolute rights, remain subject to certain limitations.”[31] Recognizing the sensitivity of placing limitations on international human rights, Rule 37’s commentary expounds on the limitation criteria and their applicability.[32] While the International Group of Experts discusses the need to ground any limitation in international law[33] and for these measures to be nondiscriminatory,[34] the greatest ambiguity in the applicability of Rule 37 surrounds the meaning of “legitimate purpose.” In an effort to establish parameters for whether a limitation serves a legitimate purpose, the International Group of Experts offers in the commentary a nonexhaustive list of legitimate purposes, including: “protection of rights and reputations of others, national security, public order, public health, [and] morals.[35] To provide even a greater understanding of the term, the commentary gives an example: “For instance, countering terrorism is a legitimate purpose that allows States to monitor particular online communications without thereby violating the right to privacy.”[36]

Despite the admirable attempt of the International Group of Experts to define a “legitimate purpose,” the term remains overly broad. The commentary’s countering-terrorism example most starkly illustrates this point. Currently, there is no universally accepted definition of “terrorism,”[37] and the parameters of the term remain contentiously debated.[38] As a result, there is a myriad of national and regional definitions for “terrorism.”[39] The closest the international community has come to an understanding of the concept is in United Nations Security Council Resolution 1566, which forbids:

criminal acts, including against civilians, committed with the intent to cause death or serious bodily injury, or taking of hostages, with the purpose to provoke a state of terror in the general public or in a group of persons or particular persons, intimidate a population or compel a government or an international organization to do or to abstain from doing any act . . . .[40]

The resolution, however, is unhelpful as it is nonbinding and lacks authority in international law.[41] Further, its offered definition of “terrorism” is sufficiently vague to allow for individual State interpretations. “Terrorism,” therefore, can encompass a wide range of activities and, in its nebulous conception, is highly susceptible to States’ infringement on individuals’ right of privacy in cyberspace.

Similarly, the broad concept of “countering terrorism” is too expansive to be a “legitimate purpose.” “Counterterrorism,” like “counterinsurgency,”[42] is a far-reaching strategic term that is expansively applied to a variety of circumstances. Described by the United States as “activities and operations . . . taken to neutralize terrorists, their organizations, and networks in order to render them incapable of using violence to instill fear and coerce governments or societies to achieve their goals,” the concept is intentionally broad to allow for a variety of responses.[43] Countering terrorism, in other words, is whatever a State does to “disrupt, isolate, and dismantle terrorist organizations.”[44] Admittedly, States are obligated to comply with international human rights law when implementing their counterterrorism measures.[45] However, this obligation lacks specificity and allows wide latitude to States in determining how to “counter terrorism,” including, if necessary, monitoring online personal communications.

Declaring that “countering terrorism” is a “legitimate purpose” for infringing upon the right to privacy in cyberspace is both vague and problematic. Equally troubling is the use of other broad and amorphous terms such as “national security,” “public order,” or “public health” to describe a “legitimate purpose.”[46] By leaving the description of a “legitimate purpose” vague, Rule 37 gives State actors discretion, increasing the risk of overzealous limitations on international human rights in the cyber context. To its credit, the International Group of Experts does not ignore this problem and addresses this concern by emphasizing in the commentary that “[a] restriction on cyber activities that might otherwise be protected by international human rights law must be ‘necessary.’”[47] However, this language is of questionable impact as the commentary immediately follows with the statement “although States enjoy a margin of appreciation in this regard.”[48]

The International Group of Experts also raises the principle of proportionality, as it applies to limiting international human rights, as a check on overuse of Rule 37.[49] The idea of proportionality is extensively used throughout international law;[50] thus, it is helpful for the commentary to note expressly “that the need for any State interference with human rights in order to meet a legitimate State objective be assessed against the severity of the infringement on human rights.”[51] The commentary goes on to state that the restriction must be the least intrusive means available to achieve the stated objective.[52] While disagreeing as to whether the proportionality principle is customary, the Experts note in the commentary that a majority “accepted a condition of proportionality.”[53] In so doing, they agreed that “necessity alone does not suffice to justify limiting obligations” as it would be “incongruent with the object and purpose of limitations on international human rights law to permit a restriction that is necessary, but disproportionate to the State’s interest in question.”[54] Yet, again, after outlining this seeming restraint, the commentary goes on to note that State actors “enjoy a margin of appreciation” when applying the least-restrictive-means proportionality requirement.[55]

Rule 37 and its commentary consistently defer to States. This deference allows the State to determine unilaterally whether a limitation on an international human right in cyberspace is necessary to achieve a legitimate purpose and, if so, how to effectuate any limitations in a proportional manner. The vague and broad terminology used to describe a “legitimate purpose” further empowers the State to limit human rights in the cyber context if it so chooses. The Experts’ use of generalities, including but not limited to the term “countering terrorism,” and the deference shown to States throughout Rule 37, therefore leaves open the question of what exactly restrains a State from limiting international human rights in cyberspace.

III. Do Not Worry . . . State Practice Will Begin to Fill the Gaps

The uncertainty in Rule 37 is not surprising, as a granular analysis of such an ambitious and unprecedented project as the Manual will invariably reveal some gaps. This is similar to Tallinn 1.0,[56] which, in its attempt “to explain how the existing law of armed conflict generally regulate[d] cyber warfare,” left certain specifics unaddressed.[57] For example, Tallinn 1.0’s Rule 27 states that “[i]n an international armed conflict, inhabitants of unoccupied territory who engage in cyber operations as part of a levée en masse enjoy combatant immunity and prisoner of war status.”[58] Yet this attempt “to reconcile the [traditional] concept of levée en masse[59] with the ‘cyber conflicts between nations and ad hoc assemblages’” is simply impractical.[60] While there are a number of problems with the idea of a cyber levée en masse,[61] the most obvious is the traditional criteria that those participating in a spontaneous uprising carry arms openly.[62] The requirement to “carry[] arms openly” is of utmost importance in a levée en masse as these movements are done in emergency circumstances, leaving no time for organization or for participants to use distinctive signs.[63] With no other form of recognition, carrying a weapon becomes the “only distinguishing characteristic between a protected civilian and a combatant, and, therefore, who can be lawfully attacked.”[64] Further, there is no question as to what “carrying arms openly” means for those participating in a levée en masse. The referred-to arms are clearly traditional weapons like rifles, hand grenades, and pistols.[65]

“Recognizing both the realities of a levée en masse and the criticality of protecting civilians, the law of armed conflict [thus] places singular emphasis on the essential need for those choosing to participate in a spontaneous uprising” to openly carry these conventional armaments.[66] Yet, in a cyber levée en masse the “weapon” used is a computer. While it is possible for a computer to be considered a “weapon,”[67] simple possession “cannot be interpreted to be indicative of combatant activity.”[68] The Tallinn 1.0 International Group of Experts recognized this reality by noting, “even if [computers] qualify as weapons, the requirement to carry arms openly has little application in the cyber context.”[69] A detailed law of armed conflict (LOAC) analysis reveals key challenges related to this area: namely, the impossibility of distinguishing participants in a cyber levée en masse and, subsequently, the inability of participating individuals to comply with the required LOAC principle of distinction.[70]

The Tallinn 1.0 International Group of Experts understood the difficulties with the concept of a cyber levée en masse and even “highlight[ed] various unanswered and troubling questions in the commentary to Rule 27.”[71] The Experts were also aware that a general application of the existing LOAC to cyber warfare does not always work[72] and future legal developments are necessary to address the nuanced issues generated by the novelties of cyber warfare.[73] Yet, due to “the relative infancy of cyber operations and paucity of state practice,”[74] the Tallinn 1.0 International Group of Experts only addressed the “law currently governing cyber conflict.”[75] Avoiding theoretical debates,[76] Tallinn 1.0 thus provided a general regulatory framework capable of allowing the LOAC to evolve, as necessary, to address the unanticipated complexities that emerge in cyberspace.[77]

Similar to Tallinn 1.0, Tallinn 2.0’s IHRL Chapter acts as a broad foundational document that intentionally leaves room for further legal developments. As noted in Part III, the International Group of Experts occasionally refers to terms without adding specificity to their meaning. For example, the commentary to Rule 36 states:

The Internet has been used for terrorist purposes, such as recruitment for, incitement of, and the financing of terrorism. The International Group of Experts agreed that “States have both a right and a duty to take effective measures to counter the destructive impact of terrorism on human rights,” even though some measures taken by the State may affect human rights such as the freedom of expression and the right of privacy. Any such measures must comply with Rule 37.[78]

Like the term “legitimate purpose” in the commentary to Rule 37, the Rule 36 language leaves open a critical question—namely, what constitutes “effective measures” States have a right and duty to undertake in this context? Moreover, what is an effective measure that rises to the level of a legitimate purpose for limiting the international human right of privacy in the cyber context?[79]

The United States has begun to answer this question by publicly advertising the measures it employs to “counter terrorism” in cyberspace. The United States requires “[i]nformation-related capabilities such as . . . cyberspace operations . . . [to] be applied to [counterterrorism] operations as a means to influence extremists, their supporters, and the mainstream populace.”[80] These cyber operations, nested within the United States’ counterterrorism efforts, are “composed of the military, intelligence, and ordinary business operations of [the Department of Defense] in and through cyberspace.”[81]

While this broad definition of cyberspace operations may not be tremendously helpful, Joint Publication 3-12(R), an unclassified military document titled “Cyberspace Operations,” provides some clarity. The document notes that “successful execution of [cyberspace operations] requires the integrated and synchronized employment of offensive, defensive, and DODIN operations, underpinned by effective and timely operational preparation of the environment [(OPE)].”[82] It goes on to state that categorization of a cyberspace operation is dependent upon the intent behind the mission.[83] However, “these missions . . . require the employment of various capabilities to create specific effects,” and therefore the document discusses a number of particular actions in cyberspace.[84]

In so doing, it becomes possible to determine what type of cyber activities are considered part of “cyberspace operations” and subsequently are included as cyberspace measures in United States counterterrorism operations. Cyberspace Intelligence, Surveillance, and Reconnaissance (C-ISR), which gathers intelligence to support a future offensive or defensive cyber operation[85] and maps adversary cyberspace to support military planning,[86] is one example of a listed activity. Additionally, cyberspace operational preparation of the environment (C-OPE), which “consists of the non-intelligence enabling activities conducted to plan and prepare for potential follow-on military operations,”[87] is also a described cyber action.

Some of the described actions, such as “cyberspace attack,”[88] clearly cross the use-of-force threshold and would not be regulated by the international law contemplated in Tallinn 2.0.[89] However, C-ISR and C-OPE most likely fall below the use-of-force line as, by definition, they do not cause damage, injury, or even severe nonphysical consequences.[90] Instead, these cyber activities focus on intelligence gathering and planning for future military operations, both of which are peacetime activities. As a result, it becomes possible to start determining what cyber measures below the use of force the United States employs to counter terrorism.

Understanding what cyber activities below the use-of-force threshold the United States employs in its counterterrorism efforts thus helps to define the term “effective measure” as undertaken in the Rule 36 context. More importantly, it evinces State practice and begins to represent the legal developments necessary to fill in the gaps left open by Tallinn 2.0’s IHRL Chapter. Of course, the United States’ practice is a singular example of one nation’s behavior and is clearly not a customary norm. Yet it is an important representation of how State practice can provide the specificity currently missing in Tallinn 2.0 while simultaneously illustrating how the international law regulating cyber operations is likely to develop in the future.

IV. Conclusion

Similar to Tallinn 1.0, Tallinn 2.0 is an unprecedented attempt to codify international law, albeit below the use-of-force threshold, in cyber operations.[91] It is an objective restatement of the lex lata, versus a reflection of lex ferenda,[92] for the same reason Tallinn 1.0 only analyzed current international law: namely, to avoid making questionable predictions about how the law should develop.[93] Instead, the International Group of Experts behind Tallinn 2.0, and specifically its International Human Rights Law Chapter, created a foundational document with room for international law to develop and fill gaps as needed.[94] This “gap filler” will come in the form of either a treaty or by States’ “engaging in practices out of a sense of legal obligation (opinio juris) that, combined with similar practice by other [S]tates, eventually crystallizes into customary international law.”[95] With the accelerating pace of change in cyberspace[96] and the glacial speed at which conventional law develops,[97] new international law will likely come through State practice.

Although certain terms in the IHRL Chapter generally—and in Rules 36 and 37, specifically—are problematic, both the IHRL Chapter and the Tallinn Manual 2.0 represent a tremendously useful starting point for assessing the challenging intersection of multiple areas of the law. Quickly filling definitional gaps is essential to amplifying the Chapter and determining what legitimate reasons may exist to violate rights, such as privacy, in cyberspace. Moreover, understanding timely, relevant activities not triggering the law of armed conflict but nevertheless of the type contemplated throughout Tallinn 2.0, such as the United States’ C-ISR and C-OPE efforts, serve as tremendous indicators of State practice in this area.

Finally, it must be stated that the above nuanced criticism is not a broad condemnation of the Group of Experts’ efforts in any regard. To the contrary, it is only because of their excellent and unprecedented work that we are able to spot the definitional gaps and begin to fill them with evidence of State practice. All of it, and especially the IHRL Chapter, represents a tremendous contribution to the law.

