Procedural Interoperability for Cross-Border Electronic Evidence under the United Nations Convention against Cybercrime
DOI:
https://doi.org/10.37420/j.mlr.2026.011Keywords:
Cross-border electronic evidence; International cooperation; Jurisdictional conflict; Procedural interoperability; Service providers; United Nations Convention against CybercrimeAbstract
Cross-border electronic evidence is governed by an overlapping set of global, regional, bilateral and domestic mechanisms, each relying on different jurisdictional connections, institutional channels and safeguards. This article asks whether the United Nations Convention against Cybercrime can reduce that fragmentation by supplying a common procedural layer. Using doctrinal analysis and functional comparison, it develops a lifecycle model covering request formation, preservation and acquisition, sovereign and rights-based review, and post-transfer governance. The article argues that the Convention does not allocate exclusive jurisdiction over data and should not be evaluated as a substitute for the Budapest Convention system, the European Union e-evidence package or the United States CLOUD Act. Its more plausible contribution is to connect legally heterogeneous systems through central authorities, a 24/7 network, expedited preservation, expedited disclosure of routing-related traffic data and differentiated cooperation for stored, traffic and content data. That contribution remains partial because conflict-of-law review, provider-facing procedures, notification, evidentiary integrity, retention, onward transfer and remedies are left substantially to domestic implementation. The Convention can therefore operate as a minimum global interoperability framework only if States coordinate the complete lifecycle of evidence requests and clarify how its State-mediated procedures interact with more specialized provider-oriented regimes. The article closes with implementation priorities across the evidence lifecycle and applies them to China, where treaty-based cooperation would have to be reconciled with approval requirements for foreign governmental requests, cybersecurity regulation and personal-information protection.