CO-CREATED LEGAL EDUCATION AND THE PREVENTIVE ARCHITECTURE OF EU CYBERCRIME GOVERNANCE
DOI:
https://doi.org/10.63456/jpslg-2-2-109Keywords:
EU Cybercrime Governance, preventive governance, legal Education Harmonisation, regulatory pluralism, co-creation, epistemic governance, Article 165 TFEU, NIS2 Directive, Directive 2013/40/EUAbstract
European Union cybercrime governance has achieved significant legislative and institutional sophistication through criminal law harmonisation, cybersecurity risk regulation, and transnational enforcement coordination. Nevertheless, prevailing regulatory and scholarly approaches remain disproportionately enforcement-centric, overlooking the epistemic infrastructures necessary for sustainable regulatory coherence and preventive compliance. This article identifies a critical lacuna in EU digital governance: the marginalisation of legal education as a structural regulatory instrument capable of enhancing cybercrime prevention, institutional resilience, and harmonised enforcement across Member States. Advancing an interdisciplinary analytical framework integrating preventive governance theory, regulatory pluralism scholarship, and co-creation governance models, the article argues that co-created legal education constitutes a novel form of preventive regulatory infrastructure within EU cybercrime governance. The study employs doctrinal analysis of EU cybercrime legal instruments, comparative evaluation of Member State educational governance across four analytically distinct jurisdictions, and normative regulatory modelling. Confronting the constitutional constraint of Article 165(4) TFEU — which expressly excludes legislative harmonisation of education — the article designs its normative model to operate through soft-law coordination, the Open Method of Coordination, and programmatic EU financing. It contributes original knowledge by reconceptualising legal education as a soft harmonisation mechanism that strengthens mutual trust, regulatory legitimacy, and interdisciplinary compliance ecosystems within multi-level digital governance. By proposing an institutionally grounded co-created legal education model, the study advances a preventive epistemic governance paradigm with transformative implications for EU cybersecurity policy, national regulatory capacity-building, and transnational cybercrime governance.
References
[1] Charter of Fundamental Rights of the European Union [2012] OJ C326/391. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A12012P%2FTXT
[2] Council Framework Decision 2002/584/JHA of 13 June 2002 on the European Arrest Warrant and the Surrender Procedures between Member States [2002] OJ L190/1. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32002F0584
[3] Council of Europe, Convention on Cybercrime (Budapest Convention) ETS 185 (Budapest, 23 November 2001). https://www.coe.int/en/web/conventions/full-list?module=treaty-detail&treatynum=185
[4] Council of Europe, Second Additional Protocol to the Budapest Convention on Cybercrime on Enhanced Co-operation and Disclosure of Electronic Evidence CETS 224 (Strasbourg, 12 May 2022). https://www.coe.int/en/web/conventions/full-list?module=treaty-detail&treatynum=224
[5] Directive 2013/40/EU of the European Parliament and of the Council of 12 August 2013 on Attacks against Information Systems [2013] OJ L218/8. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32013L0040
[6] Directive 2014/41/EU of the European Parliament and of the Council of 3 April 2014 on the European Investigation Order in Criminal Matters [2014] OJ L130/1. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32014L0041
[7] Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning Measures for a High Common Level of Security of Network and Information Systems Across the Union (NIS1 Directive) [2016] OJ L194/1. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016L1148
[8] Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on Measures for a High Common Level of Cybersecurity Across the Union (NIS2 Directive) [2022] OJ L333/80. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555
[9] European Commission, Evaluation of Directive 2013/40/EU COM(2018) 448 final. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52018DC0448
[10] European Commission, EU Cybersecurity Strategy for the Digital Decade JOIN(2020) 18 final. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52020JC0018
[11] European Commission, EU Security Union Strategy COM(2020) 605 final. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52020DC0605
[12] European Commission, Digital Education Action Plan 2021–2027 COM(2020) 624 final. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52020DC0624
[13] European Commission, ‘Shaping Europe’s Digital Future’ COM(2020) 67 final. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52020DC0067
[14] European Council, Presidency Conclusions, Tampere European Council 15–16 October 1999. https://www.europarl.europa.eu/summits/tam_en.htm
[15] Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the Protection of Natural Persons with Regard to the Processing of Personal Data and on the Free Movement of Such Data (GDPR) [2016] OJ L119/1. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
[16] Regulation (EU) 2016/794 of the European Parliament and of the Council of 11 May 2016 on the European Union Agency for Law Enforcement Cooperation (Europol Regulation) [2016] OJ L135/53. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0794
[17] Regulation (EU) 2018/1727 of the European Parliament and of the Council of 14 November 2018 on the European Union Agency for Criminal Justice Cooperation (Eurojust Regulation) [2018] OJ L295/138. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32018R1727
[18] Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA and on Information and Communications Technology Cybersecurity Certification (Cybersecurity Act) [2019] OJ L151/15. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32019R0881
[19] Regulation (EU) 2021/694 of the European Parliament and of the Council of 29 April 2021 establishing the Digital Europe Programme [2021] OJ L166/1. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021R0694
[20] Regulation (EU) 2021/695 of the European Parliament and of the Council of 28 April 2021 establishing the Framework Programme for Research and Innovation — Horizon Europe [2021] OJ L170/1. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021R0695
[21] Regulation (EU) 2021/1057 of the European Parliament and of the Council of 24 June 2021 establishing the European Social Fund Plus [2021] OJ L231/21. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021R1057
[22] Treaty on European Union [2012] OJ C326/13. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A12012M%2FTXT
[23] Treaty on the Functioning of the European Union [2012] OJ C326/47. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A12012E%2FTXT
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Elemegious Mugamba (Author)

This work is licensed under a Creative Commons Attribution 4.0 International License.

Licensing: Creative Commons Attribution 4.0 International License (CC BY 4.0)