The post Mozambique’s Internet Shutdown Case: African Courts Draw a Line on Executive Power appeared first on Collaboration on International ICT Policy for East and Southern Africa (CIPESA).
]]>In July 2026, Mozambique’s Constitutional Council ruled that before a government can justify an internet shutdown, it must first have lawful authority to order one. The ruling signifies that before governments restrict connectivity, they must be able to show not only that the power to do so was lawfully created, but that it was exercised by a legally authorised authority.
The ruling comes against a wider pattern across the continent, where governments have used internet shutdowns to silence dissent and restrict fundamental rights.
The Constitutional Council declared 18 provisions of the Telecommunications Traffic Control Regulation (Decree No. 48/2025) unconstitutional, following a petition from the Center for Democracy and Human Rights. These provisions granted the telecommunications regulator, the National Communications Institute of Mozambique (INCM), broad powers to control telecommunications traffic, collect user data, intervene in operators’ networks using its own technology without their consent, and monitor communications on stated grounds including protecting state security and mitigating fraud.
The Council’s ruling was not about a recently imposed internet shutdown. Instead, it examined provisions of the regulation that gave the authorities powers to monitor communications, collect data, suspend telecommunications services and intervene in networks. The question was whether those powers could be created through regulation without a sufficient basis in legislation enacted by Parliament. The Council found that they could not, holding that the executive had effectively assumed the role of Parliament in defining the essential content of fundamental rights.
The Council described this as “organic unconstitutionality” and held that powers capable of restricting fundamental rights could not be created through executive regulation alone, but required parliamentary legislation that complies with constitutional and human rights protections.
| In the Constitutional Council’s words, the provisions “substituted the Government for the Assembly of the Republic’s legislature in defining the essential content of fundamental rights”, contrary to Article 178 of the Constitution. |
The Mozambique ruling also helps clarify three contentious questions emerging in shutdown litigation across the continent. What law permits the restriction, and who is authorised to order it? Which rights does it affect, including freedom of expression and access to information? And even where a legal power exists, is the restriction genuinely necessary and proportionate to the stated aim?
A Regional Pattern of Unlawful Interference
Mozambique’s ruling mirrors a broader African legal front against arbitrary internet shutdowns. Across the continent, governments have used shutdowns to restrict political opposition, communication, mobilisation, assembly, association and protest, in some cases without a sufficient legal basis.
In January 2019, the High Court of Zimbabwe ruled that the state security minister had no legal authority under the Interception of Communications Act to order an internet shutdown or issue an intercept directive to mobile network operators. The shutdown was ordered amid nationwide protests against rising fuel prices, but was later restored.
In Togo, the ECOWAS Community Court of Justice found that Togo’s three-day internet shutdown during the 2017 protests violated freedom of expression under Article 9 of the African Charter because it lacked authorisation under national law. The Court also ordered compensation to the applicants for the violation of their right to freedom of expression. The judgment affirmed that access to the internet enables people to exercise rights that are already protected, particularly freedom of expression and access to information.
In Nigeria, the court reached a similar conclusion, finding that the government’s seven-month suspension of Twitter violated freedom of expression, access to information, and media freedom. It described access to the platform as “a derivative right that is complementary to the enjoyment of the right to freedom of expression.”
The case of Association des Blogueurs de Guinée (ABLOGUI) and three others against Guinea shows that a legal basis alone is not enough. In that case, the ECOWAS Court found that restrictions on internet and social media access between October and December 2020 violated the applicants’ rights to information and freedom of expression. The case reinforces the rule that a government must show not only that a restriction is authorised by law, but also that it serves a legitimate aim and is necessary and proportionate.
In Senegal, the shutdowns imposed during the 2023 unrest violated freedom of expression and access to information for both applicants. The court also upheld Ndiaga Gueye’s individual claim that the shutdown violated his right to work as an IT consultant. The case illustrates that shutdowns can disrupt far more than speech. They can cut people off from work and other essential digital services, while disrupting journalism, education, payments and access to health information.
Strengthening Preventive Safeguards
Courts are not the only institutions shaping this debate. For years, the African Commission on Human and Peoples’ Rights (ACHPR) has set continental standards on open internet access. The Commission’s resolutions and declarations do not carry the same legal force as court judgments. Still, they provide important guidance on how African states should protect freedom of expression, access to information, and access to the internet.
Its 2019 Declaration of Principles on Freedom of Expression and Access to Information in Africa, Principle 38(2), provides that states “shall not engage in or condone any disruption of access to the internet and other digital technologies for segments of the public or an entire population.”
In March 2024, the Commission went further in Resolution 580, calling on states to ensure open and secure internet access before, during, and after elections, and to refrain from ordering shutdowns or disrupting digital communication platforms during the electoral process.
Conclusion
Despite judicial victories, the threat remains pervasive, and litigation alone is insufficient when judgments arrive years after the harm. In 2025, the #KeepItOn coalition recorded 30 shutdowns across 15 African countries.
There must be independent oversight, public transparency, and effective ways for people affected by an unlawful restriction to challenge it and seek redress. Telecommunications operators should also be protected from being forced to carry out unlawful orders. Only then can we ensure that the digital rights of millions are protected from the arbitrary exercise of power.
Mozambique’s ruling affirms that digital rights are not subject to executive whim. Governments must respect the rule of law, ensuring that restrictions on connectivity that limit fundamental rights are grounded in parliamentary legislation and subject to rigorous constitutional safeguards.
The post Mozambique’s Internet Shutdown Case: African Courts Draw a Line on Executive Power appeared first on Collaboration on International ICT Policy for East and Southern Africa (CIPESA).
]]>The post Uganda’s Digital Economy: Rights Trends, Regulatory Gaps and Policy Responses appeared first on Collaboration on International ICT Policy for East and Southern Africa (CIPESA).
]]>Uganda’s digital economy is expanding rapidly across finance, transport, agriculture, commerce, healthcare and public-service delivery. However, this growth is outpacing the legal, regulatory and institutional safeguards needed to address emerging concerns around personal and biometric data, artificial intelligence, platform work, digital exclusion and internet shutdowns.
Drawing on a 2025 survey, two commentaries and a policy submission by CIPESA, this policy brief examines Uganda’s evolving digital business landscape, business data practices, the future of work and the impact of internet disruptions. It highlights the gaps between technological advancement and effective governance and proposes actions for government, businesses, private sector associations and civil society to build an inclusive, resilient, and rights-respecting digital economy.
The brief finds that Uganda has established important legal protections, including the Data Protection and Privacy Act of 2019. The principal challenge, however, is implementation, enforcement, and the ability of regulatory and institutional frameworks to adapt to rapidly evolving technologies and business models. Businesses frequently collect personal and biometric data without sufficiently explaining how it will be used, stored, shared, or deleted. Meaningful consent, data security, and effective retention and deletion practices also remain inconsistent, particularly among businesses with limited compliance capacity.
These gaps have consequences beyond privacy and individual rights. Weak data governance can undermine trust in digital services, while inadequate safeguards for platform workers and persistent digital exclusion can limit who benefits from the digital economy. Internet shutdowns pose a broader threat, disrupting digital financial services, e-commerce, public services and other activities that increasingly depend on reliable connectivity.
The brief calls for coordinated action by government, businesses, private sector associations and civil society to:
Businesses
Government of Uganda
Private Sector Associations
Civil Society Organisations
Read the full brief here.
The post Uganda’s Digital Economy: Rights Trends, Regulatory Gaps and Policy Responses appeared first on Collaboration on International ICT Policy for East and Southern Africa (CIPESA).
]]>The post FIFAfrica26 Is One Month Away – It’s Time to Connect! appeared first on Collaboration on International ICT Policy for East and Southern Africa (CIPESA).
]]>In just one month, the Forum on Internet Freedom in Africa 2026 (FIFAfrica26) will convene in Mauritius from September 28 to October 1, 2026, bringing together hundreds of participants from across Africa and beyond for critical conversations on digital rights, inclusion, governance, and the future of the continent’s digital landscape. Now is the time to begin engaging with the vibrant community that makes FIFAfrica such a powerful space for exchange and collaboration.
Participants (in-person and remote) can already look forward to a rich agenda shaped by the digital rights community which reflects the pressing issues at the heart of Africa’s digital rights landscape. The Forum will spotlight themes including digital democracy and civic participation, data governance and sovereignty, artificial intelligence and emerging technologies, platform accountability, digital inclusion, digital economy and trade, movement building, and digital security and safety.
And the conversation does not have to wait until you arrive in Mauritius! You can start connecting and engaging with fellow participants and the wider community now by following @cipesaug and sharing your anticipation, insights, and reflections ahead of the Forum. Use #FIFAfrica26 and #InternetFreedomAfrica to join and amplify the conversations shaping a more open, inclusive, and secure digital future for the continent. Be sure to also join the engaging networks and communities within the event app too. You can start your own too!
As you prepare to attend or participate remotely, we encourage you to take a moment to read the FIFAfrica26 Code of Conduct. The Forum is built on dignity, respect, inclusion, and constructive engagement. The Code of Conduct applies to all Forum spaces including sessions, social events, and online platforms and is intended to ensure that every participant can engage free from intimidation, discrimination, harassment, or hostility. All attendees are expected to uphold these standards throughout the event.
For those traveling, be sure to review the official Travel Note and plan accordingly. FIFAfrica26 will be hosted at the InterContinental Resort, Mauritius in Balaclava.
We look forward to welcoming you online or in person at FIFAfrica26.
The post FIFAfrica26 Is One Month Away – It’s Time to Connect! appeared first on Collaboration on International ICT Policy for East and Southern Africa (CIPESA).
]]>The post CIPESA and UNESCO Partner on Project to Strengthen Climate Change Information Integrity in Africa appeared first on Collaboration on International ICT Policy for East and Southern Africa (CIPESA).
]]>The Collaboration on International ICT Policy for East and Southern Africa (CIPESA), in partnership with UNESCO, is launching a new project to address the growing challenge of climate change disinformation and strengthen information integrity in the public sphere.
At a time when false and misleading narratives are weakening public trust and distorting public understanding of the climate crisis, the initiative will support fact-based public discourse and strengthen the ability of journalists and civil society actors to engage with climate issues using credible information.
Reliable climate information is essential to informed public debate and effective climate action. Yet journalists, content creators, and Civil Society Organisations (CSOs) working on climate and environmental issues often lack the resources and skills needed to verify information, identify disinformation and effectively communicate accurate findings to the public.
CIPESA’s research has documented some of these challenges. Journalists and activists working on climate-related issues, including environment, land and extractives, face significant information gaps and have to navigate disinformation and misinformation campaigns, often with limited avenues to independently verify information.
The initiative recognises that public communication relies on facts and the ability of credible voices to deliver information. The project is supported by the UNESCO-led Global Initiative for Information Integrity on Climate Change, which was established to investigate, expose, and dismantle disinformation related to climate change.
The project will respond to these challenges by combining research, capacity building, and public communication. Research will map how climate disinformation spreads across African digital ecosystems, who drives it, and what tactics they use. Findings will inform a Fact-checking Masterclass at the upcoming 2026 Forum on Internet Freedom in Africa, an online training for journalists and civil society actors, and a communications campaign aimed at strengthening public awareness of climate disinformation and promoting credible sources of information.
This approach builds on the Declaration on Information Integrity on Climate Change, which commits its signatories to protect information integrity on climate change at international, national, and local levels. It also reflects the broader United Nations Global Principles for Information Integrity, which envision “an information ecosystem that delivers choice, freedom, privacy and safety for all,” and support those working to share facts in the public interest.
Reporting on climate change in Africa is increasingly taking place in a difficult information environment. Journalists, activists and human rights defenders covering environmental, land and extractives issues face surveillance, censorship, online harassment and coordinated disinformation campaigns. CIPESA’s research has documented these risks, as well as the limited digital security resources available to many of those doing this work.
The project will focus on Uganda and Ethiopia, both of which are experiencing a rise in misleading narratives related to climate change in their digital ecosystems. These narratives frequently revolve around issues such as deforestation, dam and water system developments, droughts, landslides, oil and gas exploration.
The project’s research will also track the information environment, including the public positions and communications of African governments ahead of the 31st Session of the Conference of Parties (COP31) scheduled for November 2026 in Ankara, Türkiye. The conference brings together nearly 200 nations under the United Nations Framework Convention on Climate Change (UNFCCC) to negotiate climate action, set emission-reduction targets, and coordinate policies to limit global warming.
Looking further ahead, Ethiopia’s hosting of the 32nd session of the (COP32) in 2027, will bring the global climate conversation back to Africa for the fifth time after Kenya (2006), South Africa (2011), Morocco (2016), and Egypt (2022). This makes the CIPESA-UNESCO partnership particularly timely. As technology increasingly shapes how people access, interpret and contest information about the environment, there is a growing need to understand the evolving relationship between digital platforms, climate narratives, and the integrity of public debate.
The post CIPESA and UNESCO Partner on Project to Strengthen Climate Change Information Integrity in Africa appeared first on Collaboration on International ICT Policy for East and Southern Africa (CIPESA).
]]>The post CIPESA Urges Kenya to Align and Strengthen Its Draft AI Policy appeared first on Collaboration on International ICT Policy for East and Southern Africa (CIPESA).
]]>In August 2026, the Collaboration on International ICT Policy for East and Southern Africa (CIPESA) submitted a detailed set of recommendations to the Committee on the Draft Kenya Artificial Intelligence (AI) and Other Emerging Technologies Policy, 2026. The submission calls for closer alignment of Kenya’s policy with regional and international AI frameworks, alongside stronger protections for fundamental human rights.
The submission emphasises the need for Kenya to strike a balance between its aspirations for AI governance and strong safeguards that protect human rights, people, and democratic values. Without these, the nation risks developing systems that are innovative but exclusive, unfair, and harmful.
CIPESA argues that since Kenya is simultaneously advancing multiple AI-related processes, including a national AI strategy, a proposed AI Bill, and this draft AI policy, there is a need to align and harmonise the different proposed frameworks to ensure coherence and mitigate the risks of duplication and contradictory provisions.
For example, under section 3.5.1, the Policy commits the government to develop a dedicated AI and other Emerging Technologies Governance Act to provide the legal framework for its governance in Kenya, including the establishment, powers, and functions of the Council, without acknowledging that a similar Bill is already before the Senate.
Kenya’s policy direction is influenced by constitutional obligations as well as wider regional and international commitments that underscore the importance of human rights, accountability, transparency, and inclusiveness. According to CIPESA’s submission, Kenya should incorporate these principles into legally binding policy measures rather than just mentioning them.
The submission further encourages collaboration within the East African region and across the African continent, pointing to the value of shared standards, combined knowledge, and coordinated advocacy in strengthening governance outcomes.
CIPESA’s Navigating the Implications of AI in Kenya report also highlights that AI is reshaping digital participation, information access, and democracy in Kenya. In the absence of explicit protections and clear safeguards, AI systems can perpetuate discrimination, facilitate surveillance, violate people’s right to privacy, restrict freedom of expression, and undermine livelihoods. A rights-based approach that includes mandatory human rights impact assessments will ensure that potential harms are identified and mitigated before systems are deployed.
While the draft policy outlines institutional structures and governance ambitions, CIPESA argues that effective oversight will depend on institutional independence, clear powers, and meaningful accountability. The submission raises concerns about the proposed AI Council’s institutional independence and recommends giving it explicit authority to audit, obtain information, enforce compliance, and report directly to Parliament.
In automated systems, decision-making processes are often opaque and distributed across multiple actors. CIPESA therefore recommends clearly defining responsibilities and liability so that individuals harmed by AI systems have effective redress mechanisms.
Effective AI governance requires technical expertise, resources, and coordination across multiple agencies, yet many institutions in Kenya remain under-resourced. Therefore, proposed governance frameworks should be realistic about the state’s ability to implement and enforce stronger oversight mechanisms by investing in institutional capacity and talent retention.
According to CIPESA’s research, AI content moderation on major platforms is built largely for the Global North, with low-resource African languages. Many AI systems deployed in African contexts are trained on datasets that do not reflect local realities, leading to biased outcomes with direct implications for fairness, inclusion, and accuracy. This necessitates strong local data ecosystems and locally relevant content moderation systems and languages.
Kenya’s 2025 High Court ruling on the Worldcoin iris-scanning project affirmed the need for stronger data protection measures and integration with AI-specific legislation. According to CIPESA, incorporating pre-deployment oversight would transform AI governance from a reactive to a proactive model, particularly regarding sensitive biometric data.
AI systems are resource-intensive, consuming a lot of energy and requiring large amounts of water for data centre cooling. They also emit carbon and ultimately contribute to electronic waste. The submission recommends environmentally sustainable approaches, including independent third-party verification of environmental disclosures and publication of verified information in the public Registry.
The African Union AI Strategy identifies disinformation as a distinct risk. AI can influence public discourse by deciding which information is promoted, suppressed, or amplified. Disinformation, manipulation, targeted harassment, technology-facilitated gender-based violence (TFGBV), and AI-generated deepfakes can create particular risks in civic and democratic spaces, with disproportionate effects on women and other vulnerable groups. CIPESA proposes explicit recognition of these threats, implementation of gender impact assessments for high-risk systems, and stronger oversight of AI use in elections, political advertising, and content moderation.
Another recommendation is the inclusion of civil society representation at the steering committee, which is the top decision-making level. This is to ensure meaningful participation and alignment with the African Union AI Strategy and the UNESCO Recommendation on the Ethics of AI, which call for inclusive, multi-stakeholder involvement in AI governance, especially where major decisions are made.
Inclusion and public participation also require accessible language and processes that enable broader public engagement with what are often complex and technical issues, through investments in digital literacy and public awareness.
The submission further underscores the importance of labour rights and the often invisible workforce behind AI systems, many of whom work in unfavourable conditions. By highlighting the need for fair labour standards, protections, and recognition of data work, CIPESA also recommends including the workforce that sustains AI ecosystems in high-level policy discussions.
Explainability and transparency are essential to accountable AI governance. For people to trust AI systems, they need to understand how AI-driven decisions are made and contest results they believe to be unfair. To prevent AI systems from being treated as black boxes beyond public scrutiny, there must be clear documentation, disclosure standards, and rights to explanation. This builds accountability and trust, especially in high-risk sectors like public services, healthcare, and finance.
Finally, CIPESA highlights the necessity of continuous policy review and adaptation, emphasising that governance frameworks must remain adaptable and responsive as AI technologies evolve quickly. This includes establishing mechanisms for periodic review, stakeholder feedback, and iterative policy development to ensure that regulations remain relevant and effective over time.
CIPESA’s recommendations provide a mechanism to close the gap between ambition and accountability as Kenya works to finalise its AI policy. The decisions made at this point will influence not only the development, deployment, and application of AI but also the distribution of its benefits and risks.
Key recommendations from CIPESA:
Read the full submission here: CIPESA Submission on Kenya’s Draft AI and Emerging Technologies Policy.
The post CIPESA Urges Kenya to Align and Strengthen Its Draft AI Policy appeared first on Collaboration on International ICT Policy for East and Southern Africa (CIPESA).
]]>The post Civil Society and the Fight for Big Tech Accountability in Africa appeared first on Collaboration on International ICT Policy for East and Southern Africa (CIPESA).
]]>As digital platforms become central to how Africans communicate, access information, conduct business, and participate in public life, the question of who holds these companies accountable has become increasingly urgent.
Technology companies exercise considerable influence over personal data, online visibility, advertising markets, content moderation, and, increasingly, artificial intelligence systems. Yet CIPESA’s work on platform governance shows that having laws and regulations does not always translate into effective oversight of multinational technology companies.
These concerns were at the centre of the Big Tech Accountability Summit on July 30, 2026, where CIPESA’s Policy and Advocacy Officer, Patricia Ainembabazi, spoke on the panel “How Civil Society and Public Interest Litigation Drive Big Tech Data Protection Accountability in Africa.”
The discussions focused on the role civil society can play in triggering enforcement, the barriers to holding multinational companies accountable across borders, and the institutional reforms and policies needed to strengthen accountability. A key point from the discussion was that adopting data protection laws and establishing regulators does not automatically guarantee enforcement.
Across Africa, many regulators operate with limited financial resources, insufficient specialised personnel, fragmented mandates, and varying levels of institutional independence. They are nevertheless expected to oversee companies with substantial financial, technical, and legal capacity. Much of the evidence required to establish violations, including information about algorithms, data flows, and internal risk assessments, also remains under the control of the companies themselves.
This imbalance means that civil society can play an important role. As Patricia Ainembabazi noted, civil society organisations document harms, aggregate the experiences of affected users, undertake legal and technical research, file regulatory complaints, support strategic litigation, and sustain public scrutiny.
Similar concerns regarding tech accountability had been raised earlier on July 7, 2026, during the Humanising Big Tech Accountability webinar, where panelists argued that holding platforms accountable requires concerted efforts and a multistakeholder approach, including through storytelling and narrative building.
Uganda’s data protection case against Google LLC illustrates the importance of citizen-led accountability. The complaint was brought by four Ugandan data subjects, while CIPESA subsequently documented and amplified its wider significance. CIPESA highlighted how the case transformed an abstract privacy right into a concrete enforcement action against one of the world’s largest technology companies. The case also demonstrated the importance of testing the application of national data protection obligations to multinational companies operating across borders.
From western Africa, Nigeria offers another important example. A joint investigation by the Federal Competition and Consumer Protection Commission and the Nigeria Data Protection Commission resulted in a USD 220 million penalty against Meta and WhatsApp, which was subsequently upheld by the Competition and Consumer Protection Tribunal. The case demonstrates that African regulators can build credible enforcement actions against multinational platforms. It also raises the broader question of whether such penalties ultimately lead to lasting compliance and changes in corporate behaviour.
CIPESA’s recent analysis, Who Holds Digital Power Accountable? Lessons from Platform Governance in Africa further show that countries are experimenting with different approaches to regulating platform power. South Africa’s Media and Digital Platforms Market Inquiry examined the influence of dominant platforms on local journalism and secured commitments from several major companies. Uganda’s prolonged restriction on Facebook presents a contrasting experience, where the social and economic costs were borne by users and businesses without clearly producing greater accountability from the platform.
These examples show that the ability of individual African countries to influence global technology companies depends not only on having laws but also on regulatory capacity, market size, and political leverage.
The challenge extends beyond data protection. CIPESA has documented how weaknesses in platform governance affect freedom of expression, access to information, civic participation, and gender equality. Inadequate local language content moderation, technology-facilitated gender-based violence (TFGBV), and rapidly spreading disinformation demonstrate how failures in platform accountability translate directly into harms for African users. Effective platform governance, therefore, needs to address not only content moderation but also pay attention to data governance, competition, algorithmic transparency, market concentration, and access to effective remedies.
For civil society and regulators, one of the major challenges is regulatory fragmentation. A technology company may collect data in one country, process or store it in another, and make key decisions elsewhere. Different national laws, procedures, and institutional capacities can allow companies to challenge jurisdiction or respond selectively across markets. Regulators and civil society organisations may also lack the resources to undertake sophisticated technical audits or sustain lengthy litigation.
As such, CIPESA has called for a shift beyond isolated national enforcement towards the domestication of the African Union-backed cross-border enforcement mechanism, bringing together data protection, competition, consumer protection, and communications regulators.
While regional approaches begin to emerge, the COMESA Competition Commission’s investigation into Meta across its member states illustrates the potential for collective oversight of platform power. CIPESA’s research similarly argues that no African country can effectively address systemic platform power in isolation and calls for stronger institutions, deeper regulatory cooperation, rights-respecting regulation, and greater transparency from technology companies.
Ultimately, civil society must be integral to this accountability architecture, not merely consulted after decisions have been taken, but as a source of complaints, research, community evidence, and independent oversight. Stronger Big Tech accountability in Africa will also depend on regulators that have the resources and independence to act, accessible remedies for affected users, coordinated regional enforcement, and sustained public interest advocacy.
During the Humanising Tech Accountability webinar, CIPESA emphasised the need for civil society actors to proactively engage in research and advocacy that centers and amplifies the impact of unchecked big tech companies’ practices on people’s lives. It is only when people understand the impact of practices and manifestations such as TFGBV or the spread of disinformation on their fundamental human rights, such as freedom of expression, access to information, civic participation, and gender equality, that they will aggressively demand platform reforms and accountability.
Through our research, policy engagement, and advocacy on data governance, privacy, platform governance, and digital rights, CIPESA continues to contribute to building an African digital ecosystem in which technological power is matched by meaningful accountability.
The post Civil Society and the Fight for Big Tech Accountability in Africa appeared first on Collaboration on International ICT Policy for East and Southern Africa (CIPESA).
]]>The post Uganda and Zimbabwe’s Fourth-Cycle UPRs Must Turn Digital Progress into Stronger Rights Protections appeared first on Collaboration on International ICT Policy for East and Southern Africa (CIPESA).
]]>As Uganda and Zimbabwe prepare for their fourth-cycle Universal Periodic Reviews (UPRs) at the United Nations Human Rights Council, stakeholder submissions by the Collaboration on International ICT Policy for East and Southern Africa (CIPESA) and partners on the two countries reveal a common challenge: digital infrastructure and legislation are advancing, but the protection of human rights online is not keeping pace.
Both countries have made notable progress since their previous UPR reviews in January 2022, including advances in digital infrastructure, regulatory frameworks, and access to digital services. Uganda has expanded its communications infrastructure and digital public services, strengthened aspects of data protection enforcement, and registered important court decisions annulling provisions of the Computer Misuse (Amendment) Act, 2022, and criminal defamation offences.
Zimbabwe has expanded internet and broadband subscriptions, licensed satellite internet services, adopted regulations to support the Freedom of Information Act, 2020, and introduced a data protection framework through the Cyber and Data Protection Act, 2021.
However, these developments have not consistently translated into safe, affordable, and rights-respecting participation online. For instance, freedom of expression remains under pressure in both countries. Journalists, activists, opposition actors, artists, comedians, human rights defenders, and social media users continue to face arrest, prosecution, intimidation, and harassment over their expression.
While Uganda’s court decisions have provided important protections, broadly framed communication offences and online media licensing requirements continue to create uncertainty and encourage self-censorship. In Zimbabwe, offences relating to false information, cyberbullying, incitement, insulting the President, sovereignty, and national interest threaten journalism, political debate, satire, whistleblowing, and human rights advocacy.
The joint submission on Uganda by CIPESA, the Association for Progressive Communications (APC), and Women of Uganda Network (UWOGNET) underlines the growing relationship between internet access and democratic participation. A similar dynamic is seen in the joint submission on Zimbabwe by Zimbabwe Lawyers for Human Rights (ZLHR), the University of Birmingham, Pan African Lawyers Union (PALU), the Digital Rights Alliance Africa (DRAA), and CIPESA.
During Uganda’s January 2026 general elections, the government imposed an internet shutdown lasting almost five days, disrupting communication, access to information, economic activity, digital financial services, and participation in public affairs. It marked the third consecutive election cycle in which the country disrupted digital communications, following similar measures in 2016 and 2021.
Zimbabwe experienced network degradation during its 2023 elections. Although internet connectivity has expanded in both countries, these network disruptions demonstrate the need for safeguards against shutdowns, throttling, and other forms of communication interference during elections and periods of political contestation.
Affordability and inequality also remain obstacles in both countries. While Uganda recorded 47.1 million active mobile subscriptions and 18.5 million active internet subscriptions by December 2025, taxes on data, airtime, devices, and digital services continue to make connectivity unaffordable to a large number of Ugandans.
In Zimbabwe, high data and device costs, unreliable electricity, rural infrastructure gaps, limited digital literacy, and inaccessible services prevent many people from fully participating online. Across both countries, women, rural communities, students, older persons, low-income households, and persons with disabilities face disproportionate barriers to affording and using digital technologies.
Privacy and surveillance are equally pressing challenges. Uganda’s expanding use of biometric identification, iris scans, closed-circuit television systems, digital number plates, and electoral technologies requires stronger safeguards, transparency, and independent oversight. Proposed social media monitoring tools raise additional concerns regarding privacy, freedom of expression, and accountability. The Personal Data Protection Office also needs adequate institutional capacity to effectively enforce the law.
In Zimbabwe, the designation of the Postal and Telecommunications Regulatory Authority of Zimbabwe as the Data Protection Authority raises concerns about institutional independence. Broad national security exemptions and limited judicial oversight of surveillance powers also expose individuals to possible violations of privacy.
Another shared concern is technology-facilitated gender-based violence. Women journalists, politicians, activists, and human rights defenders face cyberstalking, doxing, impersonation, sexualised disinformation, threats, coordinated harassment, and the non-consensual sharing of intimate images. Artificial intelligence is increasing these risks by enabling sexual deepfakes and other manipulated content intended to discredit women and exclude them from public life.
The fourth-cycle reviews should result in clear and measurable commitments. Accordingly, Uganda and Zimbabwe should:
The UPR provides both governments with an opportunity to show that digital transformation and human rights protection are mutually reinforcing. Progress must be measured not only through infrastructure, subscription numbers, and legislation, but by whether people can communicate, organise, access information, and participate online freely, safely, and without discrimination.
For the full reports as submitted, click here for Uganda and here for Zimbabwe.
The post Uganda and Zimbabwe’s Fourth-Cycle UPRs Must Turn Digital Progress into Stronger Rights Protections appeared first on Collaboration on International ICT Policy for East and Southern Africa (CIPESA).
]]>The post Rethinking Africa’s Approach to the Politics of AI Governance and Regulation appeared first on Collaboration on International ICT Policy for East and Southern Africa (CIPESA).
]]>The past few years have witnessed a growing urgency for frameworks that regulate and harness the development and implementation of new and emerging technologies, especially Generative Artificial Intelligence (Gen AI).
At the international and regional level, the United Nations (UN) and the African Union (AU) have established norms through resolutions, strategies and guidelines to affirm the relationship between technology and human rights, and provide benchmarks for Member States developing rights-respecting AI governance and regulatory frameworks.
In March 2024, the UN adopted a landmark resolution on the promotion of “safe, secure and trustworthy” artificial intelligence (AI) systems that also benefit sustainable development. The resolution also calls upon Member States and other stakeholders “to refrain from or cease the use of artificial intelligence systems that are impossible to operate in compliance with international human rights law or that pose undue risks to the enjoyment of human rights.”
The 2024 resolution reaffirmed that “the same rights that people have offline must also be protected online, including throughout the life cycle of artificial intelligence systems.” It called upon member states to ensure that national AI governance and regulatory frameworks “promote safe, secure and trustworthy artificial intelligence systems” that are inclusive and benefit everyone in an equal manner.
In August 2025, the UN adopted resolution 79/325, establishing the Independent International Scientific Panel on AI and Global Dialogue on AI Governance. It aims to provide a platform to discuss international cooperation, share best practices and lessons learned, and to facilitate open, transparent and inclusive discussions on AI governance. However, a year earlier, in July 2024, the AU adopted the Continental AI Strategy, which emphasises the development of robust governance regimes for AI founded on ethical principles, democratic values, human rights, and the rule of law, in line with the AU Agenda 2063.
Both the UN resolutions on AI and the AU continental strategy came on the backdrop of other AI-related policy guidelines such as Center for AI and Digital Policy’s 2018 Universal Guidelines for AI, the Organization for Economic Cooperation and Development (OECD) 2019 AI Principles / G20 AI Guidelines, the United Nations Education Scientific and Cultural Organization (UNESCO’s) 2021 Recommendation on the Ethics of AI, and the European Union Commission’s (EUC) 2024 European Union AI Act.
Many African countries have been actively developing AI-related laws, policies, and strategies. Rwanda was the first to adopt a national AI policy in 2019, followed by Ghana’s National Artificial Intelligence Strategy in October 2022, Egypt’s National Artificial Intelligence Strategy in January 2025, and Kenya’s own strategy in May 2025. Benin, Côte d’Ivoire, Ethiopia, Mauritius, Nigeria, Tunisia, Zambia, and Zimbabwe are among others that have developed AI policies or strategies. Others, such as Burkina Faso, Guinea, Lesotho, Mali, Namibia, and Uganda, are still at different stages in developing their AI policies or strategies.
A case of history repeating itself?
While all these have been welcome developments in the governance and regulation of AI, studies show that the adoption of international and regional human rights instruments and national laws, policies and strategies is often just the first step in a long process. If not well managed, it often results in provisions that are, although of a progressive nature, are hard to implement and fail to address local needs and realities.
This is because the process of drafting these laws and strategies in many developing contexts is often devoid of meaningful multistakeholder consultations and engagement. Moreover, there has also been a tendency to adopt and replicate models from the global North, whose texts, while progressive, have faced strong resistance from Member States as they sometimes do not align with local contexts and cultural norms.
For example, many African countries, including Algeria, Ethiopia, Cameroon, Kenya, Mauritius, Namibia, Rwanda, South Africa, and Uganda, expressed strong reservations about certain provisions contained in the Protocol to the African Charter on Human and People’s Rights on the Rights of Women in Africa (Maputo Protocol).
Additionally, most of these models are state-centric and grounded in frameworks that create a distinct binary between duty-bearers and rights-holders, but do not articulate how and what each party needs to do to ensure meaningful implementation of the initiatives.
While the state-centric and rights-based approaches may seem attractive, in practice, their relevance in advancing digital rights is often undermined, especially when the prescribed provisions and action points do not align with the country’s current social, economic and political realities. Indeed, cases abound in which initial promises have fizzled over time due to the political leadership’s inaction (and sometimes unwillingness) to fully adopt and implement the resolutions or strategies.
For example, it took almost nine years for the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention) to enter into force on June 8, 2023, after its adoption in 2014. Indeed, more countries (40) have enacted data protection laws as compared to those that have ratified (16), highlighting a disconnect between national legal reforms and their commitment to continental frameworks. Similarly, the AU Protocol to the African Charter on Human and Peoples’ Rights on the Rights of Persons with Disabilities in Africa, adopted on January 30, 2018, took six years to enter into force, after the 15th ratification was achieved.
More critically, however, the lack of political will often reflect in the absence of clearly defined funding mechanisms for the implementation of these policies and strategies. As a result, even well-designed and progressive frameworks face implementation challenges due to structural flaws and insufficient funding.
For example, while Africa has scored highly in enacting Data Protection laws, which have become central to ongoing AI governance frameworks, one issue affecting their effective implementation is the lack of clear funding mechanisms for the regulatory bodies responsible for oversight and implementation. Other challenges include weak governance structures that deny these oversight bodies financial, decisional and operational independence and place them under the supervision of political appointees rather than parliament.
Designing for Failure?
Apart from Kenya, most African countries that have developed or are in the process of developing an AI strategy or policy do not provide for budgetary allocations or estimates for the implementation of their AI strategies, laws or policies. Countries such as Rwanda provide for a project-level funding framework, while others, such as Egypt and Mauritius, rely on programmatic budgets to fund the implementation of their strategies.
Even then, while implementation of Kenya’s National Artificial Intelligence Strategy (2025–2030) was costed at KSh 152 billion over a period of five years, a review of Kenya’s 2026/27 national budget shows no dedicated funding allocation for the strategy. Instead, the Sh8.6 billion allocated to the ICT sector mainly targets the expansion of broadband access, the strengthening of digital skills, and the digitisation of government services.
Additionally, in countries such as Ethiopia and Rwanda, while the policies provide for the establishment of an implementation body, several functions have been split across different ministries, departments and agencies (MDAs), which, in practice, would pose a significant challenge to meaningful execution.
For example, Rwanda’s AI policy mandates the Responsible AI office under the Ministry of ICT and Innovation to be responsible for effective tech implementation. It also positions the Rwanda Utilities Regulatory Authority (RURA) as the technical regulator responsible for developing ethical AI guidelines and principles, and the National Cyber Security Authority (NCSA) to oversee data protection compliance relevant to AI systems.
In Ethiopia, the policy designates the Ethiopian Artificial Intelligence Institute (EAII) as the national coordinating body responsible for implementation, standards development, and capacity building, and the Ministry of Innovation and Technology is responsible for providing policy oversight. Other sectoral agencies, such as the Ethiopian Communications Authority (ECA), the Ministry of Health, and the National Bank, have mandates over telecommunications and data matters, health-sector-related AI, and financial AI, respectively.
While a multisectoral approach to policy and strategic implementation can improve cohesiveness and legitimacy, the approach is prone to risks such as divergent priorities, internal conflicts, power struggles, and regulatory fragmentation, which are likely to affect how the policies and strategies are executed.
Implications for the Future of AI Governance and Regulation
In many African countries, the development of AI governance and regulatory structures is still in its infancy and presents a unique opportunity for Africans to shape their own destiny on how AI should be developed and deployed in ways that respond to and respect local needs and contexts.
Enactment of AI-specific Laws
In many countries, governments are relying on existing laws, such as data protection, communications, and cyber-related legislation, alongside the AI policies and strategies being developed. Given the evolving nature of AI, countries need to work towards enacting AI-specific laws that clearly define and contextualise AI.
Empowering the Oversight Bodies
As currently structured, many of the existing and proposed oversight bodies are either not yet operational or lack a clear mandate and sufficient resources for effective oversight. Additionally, many of them are situated within fragmented regulatory environments with overlapping responsibilities, which results in uncoordinated implementation. It is important, therefore, that the mandate of the oversight bodies and resources are clearly defined and guaranteed to ensure independence and eliminate the possibility of political interference.
Meaningful Stakeholder Participation
Having empowered stakeholders who are meaningfully engaged and participate in the development processes for policies, laws and strategies is critical to ensuring that the resulting instruments address real needs, are people-centred and implementable, and have government buy-in, as reflected in the government’s funded priorities.
Adopting a Human Rights-Centred Approach
A 2025 study by CIPESA shows that in many countries, the adoption of a human rights-centred approach to AI governance remains aspirational due to gaps in implementation, technical capacity, and stakeholder engagement in policy development and implementation. It is important, therefore, that current efforts prioritise safeguarding fundamental human rights and freedoms, enhancing human capabilities over replacement, and ensuring meaningful human control, transparency, fairness, and inclusivity in AI systems.
The post Rethinking Africa’s Approach to the Politics of AI Governance and Regulation appeared first on Collaboration on International ICT Policy for East and Southern Africa (CIPESA).
]]>The post Shaping the Agenda for the Forum on Internet Freedom in Africa 2026 (FIFAfrica26): Thank You for Your Proposals appeared first on Collaboration on International ICT Policy for East and Southern Africa (CIPESA).
]]>The organisers of the upcoming Forum on Internet Freedom in Africa 2026 (FIFAfrica26) extend sincere appreciation to everyone who submitted a session proposal or travel support application in response to the recent Call.
We received over 450 submissions, reflecting a rich diversity of interests spanning the current digital rights landscape in Africa and their intersections with global dynamics. The submissions collectively reflected the pressing issues shaping digital rights, online freedoms, and internet governance across the continent while also highlighting the vibrant community working to advance internet freedom in Africa.
Successful Applicants
Successful applicants have been notified directly. We are excited to confirm that their sessions and contributions will form the core of the Forum’s agenda. We look forward to working closely with them to shape the programme and to bringing their insightful proposals to life during the Forum.
For Those Not Selected
If you have not received a success notification, please know that this does not reflect a lack of value in your submission. The volume of high-quality proposals far exceeded the available session slots, and difficult decisions had to be made. We remain grateful for your engagement and encourage you to stay connected with the Forum as there will be future opportunities to contribute.
Next Steps in the Process
Plan Your Travel to Mauritius
The Forum will be hosted at the InterContinental Resort, Fort Coastal Road, MU, Balaclava 21306, Mauritius. All participants, those receiving travel support from CIPESA and other partners as well as independent participants, should refer to the FIFAfrica26 travel note and plan accordingly.
Thank you once again for your time, expertise, and commitment to building a free, open, and inclusive internet in Africa. We look forward to engaging with you online or in person at FIFAfrica26.
The post Shaping the Agenda for the Forum on Internet Freedom in Africa 2026 (FIFAfrica26): Thank You for Your Proposals appeared first on Collaboration on International ICT Policy for East and Southern Africa (CIPESA).
]]>The post Who Holds Digital Power Accountable? Lessons from Platform Governance in Africa appeared first on Collaboration on International ICT Policy for East and Southern Africa (CIPESA).
]]>Digital platforms have become central to how millions of Africans access news, organise politically, run businesses, and participate in public life. Yet the companies that operate these platforms make far-reaching decisions about what people see online, whose voices are amplified, and how public debate unfolds, often with limited accountability to the communities they affect.
As platforms increasingly rely on artificial intelligence and automated systems to recommend, rank, and moderate content, questions about transparency, oversight, and responsibility have become more urgent.
Governments across Africa are beginning to answer the question of who governs the platforms in different ways. CIPESA’s latest policy brief, Platform Governance in Africa: Emerging Models and Policy Priorities, examines how Nigeria, South Africa, and Uganda have confronted platform power, what their experiences reveal about the limits of national regulation, and why regional cooperation is becoming increasingly important.
Three Countries, Three Approaches
Nigeria has shown that African regulators can build credible cases and prevail in court. Following a joint investigation by the Federal Competition and Consumer Protection Commission and the Nigeria Data Protection Commission, Meta was found to have appropriated Nigerian users’ data without consent, abused its dominant market position, and treated Nigerian consumers less favourably than users elsewhere. In July 2024, regulators imposed a USD 220 million fine, which was later upheld on appeal.
Yet the case also illustrates the limits of enforcement. When the payment deadline expired in June 2025, neither Meta nor the regulator had publicly confirmed whether the fine had been paid. Nigeria demonstrated that regulators can win legal battles. Whether those victories translate into lasting changes in platform behaviour remains an open question.
South Africa has taken a different approach. Rather than relying primarily on financial penalties, the Competition Commission’s Media and Digital Platforms Market Inquiry sought to address how dominant platforms affect the sustainability of local journalism. The inquiry secured binding commitments from Google, Meta, TikTok, and Microsoft, including a ZAR 688 million (USD 41.6 million) media support package from Google. It represents one of Africa’s most ambitious efforts to address platform power through competition oversight, although its long-term impact will depend on sustained political commitment and regulatory capacity.
Uganda’s experience offers a different lesson. A government-ordered restriction on Facebook, imposed in January 2021 after Meta removed accounts linked to government-affiliated influence operations, has now lasted more than five years. The costs have largely been borne by Ugandan users and businesses, highlighting the wider social and economic consequences of unresolved disputes between governments and global platforms.
The Limits of Acting Alone
These cases highlight a central challenge of platform governance in Africa: legal authority does not always translate into practical leverage over global technology companies. Also, it is apparent that market size matters. Nigeria and South Africa, as two of Africa’s largest digital markets, secured stronger responses from platforms than Uganda did. Most African economies are considerably smaller than Meta’s annual profits, limiting the pressure individual governments can exert on multinational companies.
This reality is driving growing interest in regional approaches. The ongoing investigation by the Common Market for Eastern and Southern Africa (COMESA) Competition Commission into Meta’s practices across 21 member states reflects a shift towards collective oversight of platform power. By acting together, governments have greater potential to address competition, data governance, and digital market concerns than they do individually.
Why Platform Governance Matters
Platform governance is often discussed in terms of regulation and competition, yet users ultimately experience its consequences. During the conflict in Ethiopia’s Tigray region, platforms struggled to moderate harmful content in Tigrinya and Amharic. In one widely documented case, Facebook posts targeting university professor Meareg Amare remained online for days after being reported and were removed only after he had been killed.
Across Africa, women journalists, politicians, and activists continue to face technology-facilitated gender-based violence that platform governance systems have struggled to address effectively. These failures can discourage participation in public life and narrow the diversity of voices represented online.
Meanwhile, coordinated disinformation campaigns continue to spread faster than moderation and fact-checking systems can respond. A 2025 analysis in Kenya documented a coordinated campaign that generated more than 150,000 views in less than two weeks, illustrating how quickly harmful narratives can circulate before effective interventions are possible.
What Needs to Change
The policy brief argues that platform governance in Africa must extend beyond content moderation to broader questions of accountability, competition, data governance, and algorithmic transparency. Addressing these challenges will require governments to pursue rights-respecting regulation, regulators to strengthen oversight of platform systems, regional bodies to deepen cooperation, and platforms to provide greater transparency about how automated systems shape online experiences.
Platform governance in Africa is no longer only about removing harmful content. It is about who controls the infrastructure of public communication, on what terms, and with what accountability to the people who depend on it.
The experiences of Nigeria, South Africa, and Uganda show that African governments are increasingly willing to confront platform power. They also demonstrate that no African country can do so effectively in isolation. Building a more accountable digital future will require stronger institutions, deeper regional cooperation, and platforms that are genuinely responsive to the societies they serve.
To explore the evidence, country case studies, and policy recommendations in greater detail, read CIPESA’s full policy brief, Platform Governance in Africa: Emerging Models and Policy Priorities.
The post Who Holds Digital Power Accountable? Lessons from Platform Governance in Africa appeared first on Collaboration on International ICT Policy for East and Southern Africa (CIPESA).
]]>