Digital Rights

Switched off: surveillance powers, internet shutdowns, and the law behind them in Africa

By Ademola Adekunbi·Published 27 June 2026
South AfricaRwandaZimbabweUgandaNigeriaNamibiaBotswanaEgyptTunisiaTanzaniaKenyaCameroonEthiopiaBeninSierra LeoneSenegalSudanZambiaCabo VerdeComorosGabon

The most important thing the Digital Rights sweep surfaced is not that African states restrict communications, it is how they do it. Across the jurisdictions surveyed, the legal authority used to intercept communications, block platforms, or switch off the internet is rarely contained in a law written for that purpose. It is far more often borrowed: drawn from general telecommunications-licensing and emergency powers, from broadly worded offences buried inside cybercrime statutes, or from constitutional limitation clauses originally drafted to qualify privacy and expression rights for other ends. A handful of countries do have a dedicated, named interception statute, and those are examined below. But the dominant pattern is one of indirection, restriction exercised through instruments whose principal subject is something else, and frequently with oversight that is procedural in form rather than substantive in effect. In several of the most consequential episodes, the research could identify no clear legal basis at all. This guide reports what the records document, names the instruments, and states plainly where the law is weak or absent. It does not attribute motive; it describes what the law says and what was found to have happened.

Surveillance and interception: the dedicated instruments

A minority of jurisdictions regulate interception through a statute built specifically for that task. South Africa's Regulation of Interception of Communications and Provision of Communication-related Information Act 70 of 2002 za-rica-2002 is the clearest documented example. RICA imposes a general prohibition on intercepting any communication except as the Act authorises, and routes all interception and metadata directions through a single "designated judge", a retired judge appointed by the Minister, on secret, ex parte application. On paper this is judicial authorisation. In practice the Constitutional Court found it constitutionally inadequate. In AmaBhungane Centre for Investigative Journalism v Minister of Justice (2021), the Court declared RICA unconstitutional for failing to provide post-surveillance notification, for insufficient guarantees of the designated judge's independence, for the absence of special procedures where the subject is a journalist or lawyer, for inadequate data-handling rules, and for providing no lawful basis for bulk interception (which it declared unlawful). RICA remains in force pending remediation, but it should not be described as a model of strong oversight: as designed, it failed the constitutional standard.

The other dedicated statutes share RICA's architecture, interception centres, provider-side capability mandates, warrant requirements, but most provide weaker oversight than RICA's flawed judicial model. Rwanda's Law N° 60/2013 regulating the interception of communications rw-interception-2013 confines interception to named security organs but vests authorisation not in a judge but in a National Prosecutor designated by the Minister of Justice, with verbal warrants permitted in urgent cases. The record states directly that this prosecutorial model is weaker than a judicial-warrant system and that there is no general notification requirement and no express protection for journalists or lawyers. Zimbabwe's Interception of Communications Act [Chapter 11:20] (2007) zw-digitalrights-ica-2007 goes further still: warrants are issued by the responsible Minister, not a court, and the record characterises the protections for journalistic sources and privilege as thin. Uganda's Regulation of Interception of Communications Act, 2010 ug-interception-2010 does require a warrant from a designated High Court judge and establishes a national Monitoring Centre, but the record notes there is no independent surveillance commissioner and that Amnesty International and Ugandan civil-society groups criticise the breadth of the grounds and the absence of robust notification and transparency mechanisms.

Nigeria's Lawful Interception of Communications Regulations 2019 ng-lic-2019 sit at the stronger end of this group: interception generally requires a warrant from a Federal High Court judge, is framed as a last resort, and is subject to annual reporting to the Attorney-General. Even here, oversight runs through the warrant-issuing court and the executive rather than an independent interception commissioner, and express protection for confidential communications is limited. Namibia's Communications Act, 2009 na-digitalrights-communications-2009 builds interception into Part 6: interception centres, a SIM-registration regime expressly designed to make customers' communications interceptable (s.73), and implementing rules contemplating five-year retention of all traffic data. The record notes oversight is "widely regarded as weak" and that Namibia still has no enacted data-protection law to constrain use of the collected data. Botswana's Criminal Procedure and Evidence (Controlled Investigations) Act, 2022 bw-digitalrights-controlledinvestigations-2022 is the one case where civil-society pressure measurably improved a draft: the original Bill permitted up to 14 days of warrantless interception on the say-so of an investigatory-authority head; after objections from the CPJ, MISA and the APC, the enacted version added a privacy clause and generally requires a warrant. The standing interception-capability mandate, however, remains. The honest reading across this group is that a dedicated statute does not, by itself, deliver meaningful oversight; in most of these jurisdictions authorisation is executive or prosecutorial, notification is absent, and provider-side interception capability is compulsory.

Surveillance and interception: where it hides inside other laws

The more revealing pattern is the migration of surveillance, interception, and content-restriction powers into cybercrime statutes, laws whose stated purpose is to criminalise hacking and fraud, but which carry, in their procedural chapters, the real machinery of state access to communications. This is exactly the structure the Digital Rights sweep was built to surface, by updating existing cybercrime entries to expose their digital-rights dimension.

Egypt's Anti-Cyber and Information Technology Crimes Law No. 175 of 2018 eg-cyber-2018 is the most complete example. Alongside conventional offences, it imposes 180-day data-retention duties on providers and empowers investigative authorities to order the blocking of websites deemed to threaten national security or the national economy, and to conduct surveillance, search and seizure, a website-blocking power located inside a crime statute rather than a media or telecoms law. Tunisia's Decree-Law No. 2022-54 tn-cyber-2022 pairs a notorious "false news" offence (Article 24, up to five years' imprisonment) with a surveillance framework: Article 6 mandates retention of identity, traffic and metadata for a reported minimum of two years, and the authorities may, on judicial order, seize devices, track individuals, and intercept communications. The record documents its use against journalists, lawyers and critics.

The same embedding appears across common-law Africa. Tanzania's Cybercrimes Act, 2015 tz-cyber-2015 confers search-and-seizure, expedited preservation, real-time traffic collection, and content interception powers, several of which may be exercised on a police officer's own authority without prior judicial order, combined with the section 16 false-information offence used against journalists and ordinary users. Kenya's Computer Misuse and Cybercrimes Act, 2018 ke-cyber-2018 provides real-time traffic and content interception under judicial authorisation, but its contested content offences (false publication, cyber-harassment) were significant enough that 26 sections were suspended pending a constitutional challenge before being upheld in 2020. Nigeria's Cybercrimes Act, 2015 ng-cyber-2015 carries interception under warrant and two-year data retention, and its section 24 cyberstalking offence was litigated and criticised on free-expression grounds until its partial amendment in 2024. Uganda's Computer Misuse Act, 2011 ug-cyber-2011 illustrates the judicial limit on this drafting style: its section 25 "offensive communication" offence was struck down as unconstitutional in Karamagi and Shaka v Attorney General (2023) for failing the requirement of legal certainty. Cameroon's Law No. 2010/012 on cybersecurity and cybercrime cm-cyber-2010 requires operators to retain connection and traffic data for ten years and disclose it on request, among the longest retention mandates on file, within a statute principally about cybercrime. South Africa's Cybercrimes Act 19 of 2020 za-cyber-2020, Ethiopia's Computer Crime Proclamation No. 958/2016 et-cyber-2016, Benin's Digital Code bj-digital-code-2018, Togo's cybersecurity law tg-cyber-2018, and Sierra Leone's Cyber Security and Crime Act, 2021 sl-cyber-2021 all follow the pattern: interception and preservation powers in the procedural chapters, content offences in the substantive ones. Sierra Leone's section 44 cyber-harassment provision has been applied to journalism and social-media posts. The common thread is that the surveillance capability is real and operative, while the label on the statute points elsewhere.

Internet shutdowns and the law that is actually cited

Shutdowns are where the gap between law and practice is widest, and where the central finding of this guide is most starkly documented: in the recorded episodes, the legal basis is contested, borrowed, or simply absent.

Ethiopia is the clearest case of absence. The Communications Service Proclamation No. 1148/2019 et-comms-2019 recognises users' right to access communications services "except as provided by law," but the record states plainly that Ethiopian law contains no clear, express statutory authority empowering the government to order shutdowns. Ethiopia has nonetheless imposed repeated, sometimes prolonged disruptions since 2015, during protests, national exams, and the Tigray conflict. The asserted bases form a contested patchwork: Article 32(5) of the Computer Crime Proclamation et-cyber-2016 (court-ordered blocking of data or systems), the broad mandate of the Information Network Security Agency, the national-security limitation clauses in the Constitution et-const-privacy and sector laws, and state-of-emergency proclamations. The record's conclusion is that none squarely authorises a general shutdown, and that shutdowns have been ordered administratively, without published instruments or judicial authorisation. That absence is itself the finding: a sustained, repeated restriction of access operating outside any identifiable legal authority.

Cameroon's 2017 - 2018 shutdowns in the Anglophone North-West and South-West regions were, per the record cm-const-privacy, "ordered administratively rather than under any dedicated statutory shutdown power" and challenged in court without lasting success, again, restriction without a clear legal grounding.

Where a basis was cited, courts have twice found it defective. In Zimbabwe, the January 2019 shutdown during fuel-protest unrest was purportedly ordered by the Minister of State for National Security under the Interception of Communications Act zw-digitalrights-ica-2007; the High Court in Harare held the Minister had no authority because the Act is administered by the President, establishing that a Cabinet Minister may not order the interruption of internet services. In Zambia, the August 2021 election-day blocking of WhatsApp, Facebook, Twitter and Messenger was attributed to ZICTA under the Information and Communication Technologies Act, 2009 zm-digitalrights-ictact-2009; in Chapter One Foundation v ZICTA the High Court stayed the order and later entered a consent judgment recording that ZICTA's powers do not extend to arbitrary access interruption and requiring reasons for any disruption within 36 hours. In both cases the cited authority was held not to support what was done.

West Africa supplies the most significant precedent and several documented gaps. Togo's September 2017 protest shutdowns were held unlawful by the ECOWAS Community Court of Justice in Amnesty International Togo and others v Togolese Republic (25 June 2020) tg-cyber-2018, the first ECOWAS ruling that internet shutdowns violate freedom of expression, and the record notes the 2017 shutdowns were ordered "without a clearly disclosed digital-rights-specific legal basis." (This finding is drawn from the Togo cybercrime instrument record; the ECOWAS judgment is described there but is not itself a separate entry in the Cases database.) Senegal restricted mobile internet and social media during unrest in March 2021 and June/July 2023, and on 4 February 2024 the Ministry of Communication ordered a shutdown citing the "dissemination of hateful and subversive messages" after the presidential election was postponed; the record states these measures were imposed "without a clear statutory basis" sn-digitalrights-penalcode-2021. Sierra Leone's 10 August 2022 protest-related disruption "had no clearly disclosed statutory basis," accompanied by an official notice warning of long prison terms for sharing destabilising information online sl-cyber-2021. Sudan recorded extended shutdowns, including a weeks-long 2019 disruption, in direct tension with the express constitutional right of internet access discussed below sd-const-internet. Uganda added a fiscal variant: the 2018 Over-the-Top "social media tax" ug-ott-2018, a daily levy on access to some 60 platforms, which the record characterises as a tax operating as an access barrier before its 2021 replacement. Taken together, the recorded shutdown episodes are defined less by contested law than by the recurring absence of any clearly disclosed legal basis.

What the constitutional layer adds

Almost every jurisdiction has a constitutional privacy or expression clause, but most are general, protecting "correspondence" or "communication" without naming the digital sphere. A smaller group cleared the topic's inclusion bar because their constitutional text is genuinely digital-specific, and these are the more interesting entries. Ethiopia's 1995 Constitution et-const-privacy expressly protects the inviolability of communications "by means of post, telephone, telecommunications and electronic devices", unusually explicit language, yet its practical force is qualified by the country's shutdown record and by constitutional interpretation running through the politically constituted House of the Federation rather than an independent court. Cabo Verde's Article 45 cv-const-digitalrights enshrines a constitutional right of data protection and habeas data over computerised processing, mirrored in statute and matched by no documented shutdown practice, protection that appears real in both theory and practice. The Comoros' Article 27 km-const-privacy extends confidentiality expressly to "individual computer data," though the record notes weak independent oversight in practice. Gabon's 2024 Constitution ga-const-privacy makes the secrecy of "electronic, telephone and telematic communications" inviolable, even as the 2026 social-media ordinance creates content-removal and platform-audit powers engaging the same interests. Tunisia's 2022 Constitution tn-const-networkaccess guarantees that the State "endeavours to ensure" access to communication networks, but only as a best-efforts aim, and undercut within weeks by Decree-Law 2022-54. Sudan's 2019 Constitutional Charter sd-const-internet is the boldest, expressly guaranteeing "the right to access the internet", a guarantee the record describes as gravely compromised by shutdowns and by constitutional disruption since 2021. The pattern is that digital-specific constitutional text exists, but its practical value tracks the strength of independent enforcement, which is high in Cabo Verde and thin almost everywhere else.

Closing

The combined picture is genuinely uneven. A few jurisdictions, Cabo Verde most clearly, pair digital-specific constitutional protection with functioning oversight. Most do not. The dominant reality the sweep documented is restriction by indirection: interception conducted under prosecutorial or ministerial authorisation rather than independent judicial control; surveillance, retention and blocking powers carried inside cybercrime statutes whose titles point elsewhere; and, in the shutdown context, restriction frequently imposed with no clearly identified legal basis at all. Where the basis was named, courts in Zimbabwe and Zambia and the ECOWAS Court for Togo found it wanting, evidence that litigation can constrain the practice, but only after the fact. The recurring finding of an absent legal basis is not a research gap; it is the substantive result. A shutdown ordered without a published instrument or judicial authorisation is not a documentation failure on the part of the analyst, it is a rule-of-law failure on the part of the state, and it is reported here as such. The protections exist on paper in most of these jurisdictions; what varies, sharply, is whether anything compels the state to observe them. That is the state of digital rights the records describe: not uniformly authoritarian, not adequately safeguarded, but indirect, weakly checked, and in several documented cases not clearly grounded in law at all.

This guide was produced by Ademola Adekunbi and reviewed by the ATLPF research team. It reflects the state of the law as at 27 June 2026. Notify us of an error or update (opens in new tab).

Related guides

Topic guide

How Africa actually regulates digital finance: a comparative guide to fintech law

NigeriaKenyaGhanaTanzaniaUgandaRwandaZimbabweZambiaSouth AfricaMoroccoEgyptAlgeriaMauritiusEthiopiaNamibiaMalawiMadagascarBotswanaLiberiaSudanMozambiqueSouth SudanComorosDjiboutiGambiaGuineaMauritaniaBeninCôte d'IvoireGuinea-BissauNigerSenegalCameroonCongo (Republic)Equatorial GuineaGabonCentral African Republic

Ademola Adekunbi · June 2026

If you set out to find "the fintech law" of an African country, you will usually fail, not because the activity is unregulated, but because there is rarely a single statute to find. Across the ATLPF L

Read →
Topic guide

One law, many jobs: how African cybercrime statutes carry data protection, fintech, and digital rights obligations

MalawiCameroonBeninCongo (DRC)NigeriaEgyptDjiboutiSouth AfricaSudanZimbabweGuineaKenyaTanzaniaUgandaGhanaRwandaAngola

Ademola Adekunbi · June 2026

A meaningful number of African countries do not have a separate data protection act, a separate cybercrime act, a separate fintechfraud regime, and a separate digitalrights statute sitting side by sid

Read →
Topic guide

Data protection law across Africa: a comparative overview

AlgeriaAngolaBeninBotswanaBurundiCabo VerdeCameroonCentral African RepublicComorosCongo (DRC)Congo (Republic)Côte d'IvoireDjiboutiEgyptEquatorial GuineaEritreaEswatiniEthiopiaGabonGambiaGuineaGuinea-BissauKenyaLesothoLiberiaLibyaMadagascarMalawiMauritaniaMauritiusMoroccoMozambiqueNamibiaNigerNigeriaRwandaSenegalSierra LeoneSouth AfricaSouth SudanSudanTanzaniaTunisiaUgandaZambiaZimbabwe

Ademola Adekunbi · June 2026

The oldest comprehensive data protection statute tracked in this Library was enacted in January 2001, in Cabo Verde cvdp2001. The most recent, The Gambia's Personal Data Protection and Privacy Act gmp

Read →
Topic guide

How African data protection authorities are actually enforcing the law

NigeriaKenyaSouth AfricaGhanaRwandaEgypt

Ademola Adekunbi · June 2026

A data protection law is only as real as its enforcement. Across Africa the past decade has produced a wave of new statutes, comprehensive frameworks modelled, to varying degrees, on the GDPR, but the

Read →