Law / Ethiopia

Computer Crime Proclamation, Duty to Report Computer Crime and Illegal Content

Computer Crime Proclamation No. 958/2016, art. 2(13), art. 2(19), art. 17, art. 27, art. 46

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 7 July 2016.

A vulnerability and incident reporting rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • This binds a service provider, defined as a person who provides technical data-processing or communication service or alternative infrastructure to users by means of a computer system, or a government organ; the trigger is knowledge, gained through the computer system you administer, that a crime under this Proclamation is being committed or that a third party is disseminating illegal content through it, which on this definition's own terms reaches an app or platform operator whose product is itself that computer system, not only a network, hosting, or telecommunications intermediary.
  • Immediately notify the Information Network Security Agency (now the Information Network Security Administration) and report the crime to the police, and take appropriate measures.
  • The Agency may issue a directive setting the form and procedure for this report; no such directive is confirmed as a separately published text in the primary sources located here.
  • No provision of this Proclamation states a separate penalty for failing this reporting duty. The Article 17 offense for failing to cooperate with an investigation lists five other, unrelated articles on data retention, real-time collection, data preservation orders, data-production orders, and search assistance, and does not include this one.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

No provision of the Computer Crime Proclamation attaches a criminal or administrative penalty to a service provider's or government organ's failure to comply with the Article 27 reporting duty specifically. The Article 17 failure-to-cooperate offense, punishable with simple imprisonment not exceeding one year or a fine not exceeding Birr 10,000, is expressly limited to a failure to comply with the obligations under articles 24(2), 25(6), 30(2), 31(2), or 32(4), a closed list that does not name article 27.

Who enforces it

Enforcement body

The Information Network Security Agency (now the Information Network Security Administration), which the report is made to, together with the police, to whom the crime must also be reported.

Settledness

This duty predates, and operates alongside, the Critical Infrastructure Cybersecurity Proclamation No. 1426/2026's narrower 48-hour cyber-incident reporting duty on a designated critical infrastructure owner; the two are filed as separate instruments because they bind overlapping but distinct classes of respondent, over different subject matter, on different clocks.

As of
19 September 2026
Open questions
  • Does the definition of "service provider" in article 2(13), a person who provides technical data-processing or communication service or alternative infrastructure to users by means of a computer system, reach an ordinary software or mobile-app developer whose own product is that computer system, or only a network, hosting, or telecommunications intermediary?
  • Has any directive the Agency issued under article 27(2) on the form and procedure of this report been published, and does it narrow or clarify which incidents or content trigger the duty?

What it reaches

Obligation class

Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A service provider is any person who provides technical data-processing or communication service or alternative infrastructure to users by means of a computer system.

Any service provider, or any government organ, that has knowledge that a crime under this Proclamation is being committed, or that a third party is disseminating illegal content data, through the computer system it administers, must immediately notify the Information Network Security Agency, now reconstituted as the Information Network Security Administration, report the crime to the police, and take appropriate measures. The Agency may issue a directive on the form and procedure of that report.

No provision of this Proclamation attaches a penalty specifically to a failure to comply with this reporting duty: the separate failure-to-cooperate offense in Article 17 lists five other, unrelated investigatory-assistance articles and does not name Article 27. The Proclamation entered into force on the date of its own publication in the Federal Negarit Gazette, Year 22, No. 83, on 7 July 2016, and no provision found here has repealed or amended Article 27 since.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product
  • handles_health_records
  • provides_financial_services
  • operates_essential_service
  • is_listed_company
  • provides_telecom_services

Read the law

Official Federal Negarit Gazette text, mirrored via the ILO's NATLEX database

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app