Computer Crime Proclamation
Proclamation No. 958/2016 (Federal Negarit Gazette, 22nd Year No. 83, 7 July 2016)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 7 July 2016.
A computer misuse rule binding public and private bodies.
As of 4 September 2026.
What it requires
- Do not secure access to the whole or any part of a computer system, computer data, or network without authorization or in excess of authorization, whether or not the system is publicly accessible.
- Do not intercept non-public computer data or a data-processing service without authorization.
- As a service provider, remove or disable access to illegal content data disseminated by a third party through your systems once you obtain actual knowledge of it or a notice from a competent authority.
If you get it wrong
Criminal exposureYes
Criminal exposure note
Illegal access carries simple imprisonment up to three years or a fine of Birr 30,000 to 50,000 for the base offence, rising through two tiers to rigorous imprisonment of five to ten years and a fine of 50,000 to 100,000 where the target is critical infrastructure (art. 3). Illegal interception carries rigorous imprisonment up to five years and a fine of 10,000 to 50,000 for the base offence, rising to ten to fifteen years and a fine of 100,000 to 200,000 against critical infrastructure (art. 4). A service provider's criminal liability under art. 16 is measured by reference to arts. 12 to 14 of the Proclamation. Where an offence under Part Three of the Proclamation is committed by a juridical person, art. 20(1) fixes the fine, notwithstanding the natural-person tiers above, at Birr 50,000 to 500,000, which is the highest fine figure the Proclamation states for any offender.
Penalty structure
Against a natural person, the highest fine on the Proclamation's tiered scale is Birr 100,000 to 200,000, alongside rigorous imprisonment of ten to fifteen years, for illegal interception committed against critical infrastructure (art. 4(2)(b)). The base illegal-access offence carries a fine of 30,000 to 50,000 (art. 3(1)), rising to 50,000 to 100,000 against critical infrastructure (art. 3(2)(b)); the base illegal-interception offence carries 10,000 to 50,000 (art. 4(1)). A service provider's failure to cooperate with an investigative obligation carries a fine up to 10,000, and intentionally hindering an investigation carries a fine up to 50,000 (art. 17). Where the offender is a juridical person, art. 20(1) fixes the fine at Birr 50,000 to 500,000 regardless of which Part Three offence was committed, which is the true statutory ceiling.
- Rule
- Fixed only
- As of
- 4 September 2026
- Currency
- ETB
- Fixed cap
- 500,000
Who enforces it
Enforcement body
Ministère public (ordinary criminal courts)
What it reaches
Obligation class
Access restriction, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 3 punishes intentionally securing access to the whole or any part of a computer system, computer data, or network, without authorization or in excess of authorization, with simple imprisonment up to three years or a fine of Birr 30,000 to 50,000, rising to rigorous imprisonment of three to five years and a fine of 30,000 to 50,000 where the target system is destined exclusively for a legal person, and five to ten years and a fine of 50,000 to 100,000 where the target is critical infrastructure.
Article 4 punishes intentionally intercepting non-public computer data or a data-processing service, with rigorous imprisonment up to five years and a fine of 10,000 to 50,000, rising in the same two tiers to five to ten years and a fine of 50,000 to 100,000 against a legal person's system, and ten to fifteen years and a fine of 100,000 to 200,000 against critical infrastructure.
Article 16 makes a service provider criminally liable for illegal content data that a third party disseminates through the provider's own computer systems, but only where the provider directly participated in disseminating or editing the content, or, on obtaining actual knowledge that the content is illegal or a notice from a competent administrative authority, failed to take measures to remove or disable access to it.
Article 17 punishes a person's failure to cooperate with an investigative obligation imposed under specified articles of the Proclamation with simple imprisonment up to one year or a fine up to Birr 10,000, and intentional hindrance of a computer-crime investigation with rigorous imprisonment up to five years and a fine up to Birr 50,000.
Where any offence under Part Three of the Proclamation is committed by a juridical person, Article 20 fixes the fine at Birr 50,000 to 500,000 regardless of which offence it was, which is the highest fine figure the Proclamation states for any offender. None of these provisions exempts a publicly accessible, unauthenticated page from the definition of unauthorized access.
When LexLint raises it
crawls_web