EthiopiaIn ForceCybercrimeDigital Rights

Computer Crime Proclamation No. 958/2016

et-cyber-2016 · Act

Verified entryReviewed by Ademola Adekunbi · 27 June 2026
Summary

The Computer Crime Proclamation No. 958/2016 is Ethiopia's principal cybercrime statute. It was adopted by the House of Peoples' Representatives and entered into force on 7 July 2016 on publication in the Federal Negarit Gazette, replacing the narrower computer-crime provisions previously contained in the 2004 Criminal Code. The Proclamation groups offences into several categories. Crimes against computer systems and computer data cover illegal access, illegal interception, and interference with computer data or systems (including causing damage, deletion, alteration or denial of service). Computer-related crimes cover computer-related fraud and forgery and the dissemination or use of access codes and devices designed to commit offences. Content-related crimes cover the production, dissemination and possession of child pornography, the dissemination through a computer system of material inciting or threatening public security or that is defamatory, and the sending of spam. The Proclamation also provides for aggravated penalties (for example where critical infrastructure is targeted) and for the criminal liability of service providers who fail to act against illegal content of which they are aware. On the procedural side, Part Three (preventive and investigative measures) empowers the public prosecutor and police to investigate, requires service providers to retain traffic data and subscriber information for up to one year and to cooperate with investigations, and allows interception and real-time collection of data and warrant-based sudden searches and digital forensic investigation; the Information Network Security Agency (INSA) provides technical support, conducts digital forensics, and may take protective measures over computer systems and critical infrastructure. Part Four governs evidentiary and procedural matters, including the admissibility of digital evidence, and Part Five designates the institutions responsible for following up computer-crime cases - principally the public prosecutor, the police and INSA. The Proclamation has been criticised by civil-society organisations for the breadth of its content-related offences and surveillance powers and their implications for privacy and freedom of expression.

Key provisions
  1. Crimes against computer systems and data: illegal access, illegal interception and data/system interference (incl. damage and denial of service)
  2. Computer-related fraud and forgery and misuse of access codes/devices
  3. Content offences: child pornography, dissemination of inciting or defamatory content via a computer system, and spam
  4. Aggravated penalties (e.g. attacks on critical infrastructure) and criminal liability of service providers
  5. Service-provider duties to retain traffic data and subscriber information (up to one year) and to cooperate with investigations
  6. Investigative powers: interception, real-time data collection and warrant-based sudden searches and digital forensics
  7. INSA provides technical support and digital forensics; public prosecutor and police investigate and prosecute (Parts Three to Five)
Related instruments
Entry history
Entry history
  1. 26 June 2026
    ATLPF Research Team (AI-assisted)
    Digital Rights sweep (Brief 3, East Africa): cross-referenced Article 32(5) (court-ordered blocking/inaccessibility of computer data or systems) as the provision most often cited, and contested by ARTICLE 19, Internews and CIPESA, as a legal basis for Ethiopia's internet shutdowns; full shutdown-basis treatment recorded in the new Communications Service Proclamation No. 1148/2019 entry (et-comms-2019), now linked. Digital Rights topic already present; existing content preserved.