UgandaIn ForceCybercrimeDigital Rights

The Computer Misuse Act, 2011 (Act No. 2 of 2011)

ug-cyber-2011 · Act

Verified entryReviewed by Ademola Adekunbi · 27 June 2026
Summary

The Computer Misuse Act, 2011 (Act No. 2 of 2011) is Uganda's principal statute on computer-related offences. It criminalises a core set of computer-integrity offences - unauthorised access (securing access to a computer or data without authority), unauthorised access with intent to commit a further offence, unauthorised modification of computer material, unauthorised use or interception of computer services, unauthorised disclosure of access codes and the unlawful disclosure of information accessed in confidence - together with electronic fraud. It also created a set of content and conduct offences: child pornography, cyber harassment, offensive communication (section 25), and cyber stalking. The Act provides for investigation and search-and-seizure, makes provision for the admissibility of electronic evidence, and addresses jurisdiction over acts committed in or affecting Uganda. The Act was significantly amended by the Computer Misuse (Amendment) Act, 2022 (assented to on 14 October 2022), which expanded the unauthorised-access offence and introduced new offences targeting the unauthorised recording or sharing of another person's information, the unauthorised sharing of information about children, the transmission of misleading or malicious information, and hate speech, and imposed restrictions (including bars from holding public office or leadership positions) on persons convicted under the Act. Both the original Act and the amendment have faced sustained constitutional challenge on freedom-of-expression grounds. In January 2023 the Constitutional Court, in Andrew Karamagi and Robert Shaka v Attorney General, struck down section 25 (offensive communication) as inconsistent with the right to free expression and for failing the constitutional requirement of legal certainty. The 2022 amendment has been the subject of further constitutional litigation, with reports of additional provisions being nullified by the courts. Enforcement is carried out by the Uganda Police Force, with the national computer emergency response function residing in the National Information Technology Authority - Uganda (NITA-U); prosecutions are conducted by the Directorate of Public Prosecutions. The Act remains in force as amended, subject to the provisions invalidated by the courts.

Key provisions
  1. Computer-integrity offences: unauthorised access, access with intent to commit a further offence, unauthorised modification, unauthorised use or interception of computer services and unauthorised disclosure of access codes
  2. Electronic fraud
  3. Content and conduct offences: child pornography, cyber harassment, offensive communication (s.25) and cyber stalking
  4. Investigation, search and seizure powers and admissibility of electronic evidence
  5. Amended by the Computer Misuse (Amendment) Act, 2022: new offences on unauthorised sharing of personal and children's information, misleading or malicious information and hate speech, plus disqualification of convicted persons from public office
  6. Section 25 (offensive communication) struck down as unconstitutional by the Constitutional Court in January 2023 (Karamagi and Shaka v AG); further 2022-amendment provisions subsequently challenged
  7. Enforced by the Uganda Police Force and prosecuted by the Directorate of Public Prosecutions; national CERT function under NITA-U
Cases citing this instrument
Related instruments
Entry history
Entry history
  1. 26 June 2026
    ATLPF Research Team (AI-assisted)
    Initial draft created from the Computer Misuse Act, 2011 (Act No. 2 of 2011) consolidated text as amended (ULII) and the Computer Misuse (Amendment) Act, 2022 (Parliament of Uganda); Constitutional Court ruling striking down s.25 (2023) per CIPESA, JURIST and ARTICLE 19 reporting.