Law / Ethiopia

Computer Crime Proclamation

Proclamation No. 958/2016 (Federal Negarit Gazette, 22nd Year No. 83, 7 July 2016)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 7 July 2016.

A computer misuse rule binding public and private bodies.

As of 4 September 2026.

What it requires

  • Do not secure access to the whole or any part of a computer system, computer data, or network without authorization or in excess of authorization, whether or not the system is publicly accessible.
  • Do not intercept non-public computer data or a data-processing service without authorization.
  • As a service provider, remove or disable access to illegal content data disseminated by a third party through your systems once you obtain actual knowledge of it or a notice from a competent authority.

If you get it wrong

Criminal exposureYes

Criminal exposure note

Illegal access carries simple imprisonment up to three years or a fine of Birr 30,000 to 50,000 for the base offence, rising through two tiers to rigorous imprisonment of five to ten years and a fine of 50,000 to 100,000 where the target is critical infrastructure (art. 3). Illegal interception carries rigorous imprisonment up to five years and a fine of 10,000 to 50,000 for the base offence, rising to ten to fifteen years and a fine of 100,000 to 200,000 against critical infrastructure (art. 4). A service provider's criminal liability under art. 16 is measured by reference to arts. 12 to 14 of the Proclamation. Where an offence under Part Three of the Proclamation is committed by a juridical person, art. 20(1) fixes the fine, notwithstanding the natural-person tiers above, at Birr 50,000 to 500,000, which is the highest fine figure the Proclamation states for any offender.

Penalty structure

Against a natural person, the highest fine on the Proclamation's tiered scale is Birr 100,000 to 200,000, alongside rigorous imprisonment of ten to fifteen years, for illegal interception committed against critical infrastructure (art. 4(2)(b)). The base illegal-access offence carries a fine of 30,000 to 50,000 (art. 3(1)), rising to 50,000 to 100,000 against critical infrastructure (art. 3(2)(b)); the base illegal-interception offence carries 10,000 to 50,000 (art. 4(1)). A service provider's failure to cooperate with an investigative obligation carries a fine up to 10,000, and intentionally hindering an investigation carries a fine up to 50,000 (art. 17). Where the offender is a juridical person, art. 20(1) fixes the fine at Birr 50,000 to 500,000 regardless of which Part Three offence was committed, which is the true statutory ceiling.

Rule
Fixed only
As of
4 September 2026
Currency
ETB
Fixed cap
500,000

Who enforces it

Enforcement body

Ministère public (ordinary criminal courts)

What it reaches

Obligation class

Access restriction, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 3 punishes intentionally securing access to the whole or any part of a computer system, computer data, or network, without authorization or in excess of authorization, with simple imprisonment up to three years or a fine of Birr 30,000 to 50,000, rising to rigorous imprisonment of three to five years and a fine of 30,000 to 50,000 where the target system is destined exclusively for a legal person, and five to ten years and a fine of 50,000 to 100,000 where the target is critical infrastructure.

Article 4 punishes intentionally intercepting non-public computer data or a data-processing service, with rigorous imprisonment up to five years and a fine of 10,000 to 50,000, rising in the same two tiers to five to ten years and a fine of 50,000 to 100,000 against a legal person's system, and ten to fifteen years and a fine of 100,000 to 200,000 against critical infrastructure.

Article 16 makes a service provider criminally liable for illegal content data that a third party disseminates through the provider's own computer systems, but only where the provider directly participated in disseminating or editing the content, or, on obtaining actual knowledge that the content is illegal or a notice from a competent administrative authority, failed to take measures to remove or disable access to it.

Article 17 punishes a person's failure to cooperate with an investigative obligation imposed under specified articles of the Proclamation with simple imprisonment up to one year or a fine up to Birr 10,000, and intentional hindrance of a computer-crime investigation with rigorous imprisonment up to five years and a fine up to Birr 50,000.

Where any offence under Part Three of the Proclamation is committed by a juridical person, Article 20 fixes the fine at Birr 50,000 to 500,000 regardless of which offence it was, which is the highest fine figure the Proclamation states for any offender. None of these provisions exempts a publicly accessible, unauthenticated page from the definition of unauthorized access.

When LexLint raises it

  • crawls_web

Read the law

Computer Crime Proclamation No. 958/2016, Federal Negarit Gazette, official gazetted text, ILO NATLEX

Back to the example  ·  Lint your app