Overview
This Proclamation establishes a comprehensive legal framework to address computer crimes in Ethiopia, recognizing the vital role of ICT in national development while acknowledging vulnerabilities to cyber threats. The law criminalizes hacking, data damage, cyber fraud, and misuse of digital systems, with severe penalties—especially for attacks on critical infrastructure.
Purpose & Significance
This legislation aims to:
- Prevent, control, investigate, and prosecute computer crimes
- Facilitate collection of electronic evidence
- Protect computer systems, critical national infrastructure data, and networks from misuse and attacks.
- Safeguard individual rights in the digital environment
- Enable international cooperation on cybercrime
Key Definitions
The Proclamation defines:
- Computer crime: Offenses against computer systems/data, conventional crimes committed using computers, or illegal content disseminated through computer systems
- Computer/computer system: Software and microchip-based devices capable of data processing, storage, and communication
- Computer data: Content data, traffic data, programs, and subscriber information
- Critical infrastructure: Computer systems/networks where crimes would significantly impact public safety and national interests
- Interception: Real-time surveillance, recording, or monitoring of data processing services
Key words
Computer Crime, Cybersecurity, Computer System, Computer Data, Computer Network, Digital Evidence, Critical Infrastructure, Illegal Access (Hacking), Unauthorized Access, System Interference, Data Interference, Data Damage / Data Destruction, Network Disruption, Malware Distribution, Use of Hacking Tools, Data Alteration, Data Deletion, Data Suppression, Unauthorized Disclosure, Password / Access Code Sharing, Confidential Information Breach, Computer-related Fraud, Computer Forgery, Identity Misuse, Digital Deception, Critical Infrastructure Attack, Classified Data, National Security Risk
Criminal Offenses and Penalties
Crimes Against Computer Systems & Data
- Illegal Access (Hacking): Unauthorized access to computer systems/data is a crime. Includes accessing systems without permission or beyond authorization.
- Base penalty: Up to 3 years imprisonment + 30,000-50,000 Birr fine
- Against legal persons: 3-5 years + 30,000-50,000 Birr
- Against critical infrastructure: 5-10 years + 50,000-100,000 Birr
- Illegal Interception: Unauthorized interception of non-public data
- Base penalty: Up to 5 years + 10,000-50,000 Birr
- Enhanced penalties for legal persons and critical infrastructure
- Interference with Computer Systems: Hindering system functioning through data manipulation (Disrupting or damaging system operations (e.g., hacking, DDoS). Includes:
- Altering, deleting, or transmitting harmful data
- Interrupting normal system function
- 3-5 years imprisonment + up to 50,000 Birr
- Enhanced penalties up to 20 years for critical infrastructure cases
- Damage to Computer Data: Altering, deleting, or rendering data inaccessible
- Up to 3 years + 30,000 Birr
- Enhanced penalties for legal persons and critical infrastructure
Computer-Related Crimes
- Forgery: Falsifying data to harm others or gain undue advantage
- Fraud: Using misleading data or deception to cause harm
- Identity Theft: Producing/possessing electronic identity data without authorization
Content-Based Offenses
- Illegal Content Dissemination: Distributing prohibited content (child abuse, drugs, weapons, etc.)
- Cyber Harassment: Threatening, harassing, or defaming via computer systems
- Public Security Crimes: Disseminating content inciting violence or conflict
Other Offenses
- Computer Program Misuse: Producing/distributing tools for computer crimes
- Spam: Unsolicited commercial advertisements
- Service Provider Liability: Liability for illegal content if the provider fails to remove it
Investigative Powers & Procedures
Investigative Authorities
- Public prosecutors and police have joint investigative powers
- Information Network Security Agency provides technical support
- Specialized task forces can be organized for computer crime cases
Evidence Collection Powers
- Data Retention: Service providers must retain traffic data for one year
- Real-time Collection: Court-ordered interception/surveillance permitted with Attorney General approval
- Expedited Interception: Attorney General may authorize warrantless interception in urgent cases affecting critical infrastructure
- Search & Seizure: Court warrants allow physical/virtual searches, data seizure, copying, and recovery of deleted data
Due Process Protections
- Human and democratic rights guaranteed under the Constitution must be protected
- Irrelevant collected information must be destroyed
- Surveillance requires court warrants except in emergencies
- Attorney General must report warrantless actions within 48 hours
Detention Provisions
- Suspects can be arrested under Criminal Procedure Code provisions
- Remand period may not exceed four months
Evidentiary Rules
Admissibility
- Digital/electronic evidence collected under this Proclamation is admissible
- Evidence obtained by foreign law enforcement bodies (in accordance with Ethiopian law) is admissible
Authentication
- Electronic records from reliable systems are presumed original
- Burden of proof lies with the person producing electronic evidence
- Courts may consider the standard/manner of computer system functioning when assessing admissibility
Institutional Framework
Jurisdiction
- Federal High Court has first instance jurisdiction
- Jurisdictional provisions of the Criminal Code apply
International Cooperation
- Attorney General may cooperate with foreign authorities
- Information exchange, joint investigations, and extradition agreements are authorized
Enforcement Bodies
- National Executing Task Force: Comprising Federal Attorney General, Federal Police, and other relevant bodies
- Agency (INSA): Responsible for online investigation systems and technical support
- Public Prosecutors & Police: Responsible for enforcement and case follow-up
Sanctions
- Individuals: Imprisonment and fines (30,000-500,000+ Birr)
- Legal Persons: Fines of 50,000-500,000 Birr (or 5× specified fine amounts)
- Asset Forfeiture: Suspension, confiscation, or blockage of systems/data used in offenses
- Proceeds of Crime: Confiscation of assets acquired through computer crimes
Other Provisions
- Effective Date: July 7, 2016
- Repeals: Articles 706-711 of the Criminal Code and Article 5 of the Telecom Fraud Offense Proclamation No. 761/2012
- Regulatory Authority: Council of Ministers may issue regulations; INSA may issue directives
Leave a Reply
You must be logged in to post a comment.