Law / Ethiopia

Ethiopia

12 of 13 named instruments researched to a stage, across four of the six areas of law we track: 10 in force and 2 enacted but not yet in force. As of 19 September 2026.

When they take effect12 of 12 carry a date. Earlier is before 2015.
Before 2015: 2 instruments (2 in force) earlier 2015: 0 instruments 2016: 2 instruments (2 in force) 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 6 instruments (6 in force) 2025: 0 instruments ’25 2026: 0 instruments 2027: 2 instruments (2 enacted but not yet in force) ’27 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law 3
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (272 words)

Ethiopia's comprehensive personal-data statute is the Personal Data Protection Proclamation No. 1321/2024, in force under its own Article 70 since its publication in the Federal Negarit Gazette, and signed at Addis Ababa on 24 July 2024.

It applies to processing personal data by automated means, or held in a filing system, by a data controller or processor established in Ethiopia or using equipment there, covering public and private bodies alike; its exhaustive scope exceptions (an individual's personal or household activity, and need-to-know exchange between government agencies) carry no carve-out for publicly available personal data.

Sensitive personal data, including genetic or biometric data, is presumptively prohibited absent a listed exception such as the data subject's specific written consent, and a minor's data may be processed only with a parent's, guardian's, or tutor's consent or where necessary to the minor's vitally important interest, never for marketing, profiling, or merging of profiles.

A data subject has the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or significantly affects them; a controller or processor must register with the Ethiopian Communications Authority (ECA), the Proclamation's designated supervisory authority, notify the Authority of a personal data breach within 72 hours, and secure an appropriate-protection determination or another listed condition before transferring personal data outside Ethiopia.

Violating the automated-decision right or another data-subject right carries imprisonment of three to five years or a fine of 100,000 to 200,000 Ethiopian Birr, or both, rising to a fine of up to four percent of worldwide turnover where the offence involves an institution, sensitive personal data, or a minor's personal data.

Breach notification

Personal Data Protection Proclamation, personal data breach notification

Proclamation No. 1321/2024, arts. 43-44 (personal data breach notification)Personal Data Protection Proclamation No. 1321/2024, full English text (MetaAppz Ethiopian Federal Laws reference)

In force since 24 July 2024. Binds public and private bodies.

What this law does

Article 43(1) requires a data controller, where there is a personal data breach, to notify the breach to the Authority within 72 hours after having become aware of it, and article 43(2) requires a notification made outside that period to be accompanied by reasons for the delay. Article 43(3) requires a data processor to notify the data controller without undue delay after becoming aware of a personal data breach.

Article 43(4) fixes what the notification to the Authority must contain: the nature of the breach including, where possible, the categories and approximate number of data subjects and of personal data records concerned, the name and contact details of the data protection officer or other contact point, the likely consequences, and the measures taken or proposed to address the breach and mitigate its adverse effects, with information supplied in phases without undue further delay where it cannot all be given at once.

Article 43(6) requires the data controller to document every personal data breach, its facts, effects and remedial action, so that the Authority can assess compliance.

Article 44(1) requires the controller to communicate the personal data breach to the data subject within 72 hours after having become aware of it, in clear language and with the article 43(4) information on contact point, consequences and measures, and article 44(3) excuses that communication only where the affected data were protected by measures such as encryption that render them unintelligible, where subsequent measures have made the high risk no longer likely to materialize, or where direct communication would involve disproportionate effort and a public communication of equal effect has been made; article 44(4) lets the Authority require the communication anyway.

Article 70 enters the Proclamation into force on the date of its publication in the Negarit Gazeta, and it was signed at Addis Abeba on the 24th day of July 2024, so these provisions bind today.

What it requires

Comprehensive regime

Personal Data Protection Proclamation

Proclamation No. 1321/2024 (Federal Negarit Gazette), arts. 1-3, 6-8, 12-17, 33-42 and 45-52Personal Data Protection Proclamation No. 1321/2024, full English text (MetaAppz Ethiopian Federal Laws reference)

In force since 24 July 2024. Binds public and private bodies.

What this law does

Article 3 applies the Proclamation to processing personal data wholly or partly by automated means, and to other processing where the data form part of a filing system, by a data controller or data processor established in Ethiopia or using equipment in Ethiopia and represented there; it reaches private and public institutions of the federal and regional governments alike, and its exceptions are exhaustive, covering only an individual's purely personal or household activity, need-to-know exchange between government agencies, restricted application, and data merely transiting Ethiopia.

Article 7 bars processing unless one of the listed conditions is met, beginning with the data subject's consent and running through contractual necessity, a legal obligation, vital interests, a public health crisis or national emergency, and legitimate interests that the data subject's fundamental rights do not override.

Article 8 requires consent to be free, informed, specific and clear, to be requested separately from other terms rather than bundled with them, and to be withdrawable at any time, with the burden of proving consent on the data controller.

Articles 12 to 15 carry the fairness, transparency, purpose-limitation, accuracy and storage-limitation principles, and articles 16 and 17 require appropriate technical and organizational measures against unauthorized or unlawful processing and against accidental loss, destruction or damage, including pseudonymization and encryption, the ability to restore access after a physical or technical incident, and regular testing of those measures.

Article 33 makes registration with the Authority a precondition of processing personal data, articles 34 to 39 govern refusal, effects, change, removal and cancellation of that registration, and article 40 requires a data protection officer where processing is carried out by a government body, where core activities require regular and systematic monitoring of data subjects on a large scale, or where core activities involve large-scale processing of sensitive personal data.

Article 46 requires a record, including logs, of all processing operations, article 47 requires a data protection impact assessment before processing that may risk data subjects' rights and freedoms, article 48 requires prior authorization from or consultation with the Authority in the cases it lists, article 49 requires data protection by design and by default, and article 50 requires personal data to be destroyed as soon as is reasonably practicable once the purpose for storing it has lapsed, in a manner that prevents reconstruction.

Article 70 enters the Proclamation into force on the date of its publication in the Negarit Gazeta, and it was signed at Addis Abeba on the 24th day of July 2024, so these provisions bind today.

What it requires

Cross border transfer

Personal Data Protection Proclamation, cross-border transfer and data sovereignty

Proclamation No. 1321/2024, arts. 18-22 (cross-border transfer and data sovereignty)Personal Data Protection Proclamation No. 1321/2024, full English text (MetaAppz Ethiopian Federal Laws reference)

In force since 24 July 2024. Binds public and private bodies.

What this law does

Article 18 permits the transfer of personal data to a third-party jurisdiction only subject to the Proclamation and only where that jurisdiction ensures appropriate levels of protection.

Article 19 requires that level to be assessed before the transfer in the light of all the circumstances, with particular regard to the nature of the data, the purpose and duration of the processing, the countries of origin and final destination, and the rules of law, professional rules and security measures in force in the third-party jurisdiction; where protection is absent the Authority may still authorize a limited form of transfer, provided the data subject's rights are not violated, the data subject consents and those aspects of the data the Authority deems appropriate are severed or reduced, and otherwise the transfer is prohibited.

Article 20 lets a data controller or data processor transfer personal data where it has proved appropriate protection to the Authority and the Authority has so determined, where the data subject has given explicit consent after being informed of the possible risks, where the transfer is necessary in one of the listed senses, or where the transfer is made from a register intended by law to inform the public.

Article 21 lets the Authority require a transferor to demonstrate the effectiveness of its security safeguards and the existence of compelling legitimate interests, and lets it prohibit, suspend or condition the transfer to protect data subjects.

Article 22 requires every data controller and data processor to store personal data collected or obtained locally on a server or data center located in Ethiopia, lets the Authority prescribe categories of critical personal data that may be processed only on a server or data center in Ethiopia, and makes cross-border transfer of sensitive personal data subject to the Authority's prior approval.

Article 70 enters the Proclamation into force on the date of its publication in the Negarit Gazeta, and it was signed at Addis Abeba on the 24th day of July 2024, so these provisions bind today.

What it requires

Data subject rights

Personal Data Protection Proclamation, rights of data subjects

Proclamation No. 1321/2024, arts. 24-32 (rights of data subjects)Personal Data Protection Proclamation No. 1321/2024, full English text (MetaAppz Ethiopian Federal Laws reference)

In force since 24 July 2024. Binds public and private bodies.

What this law does

Article 24 gives a data subject the right to be told the controller's and any representative's name and contact details, the data protection officer's contact details, the purposes and lawful basis of the processing, the recipients, any transfer to a third-party jurisdiction, the retention periods, the rights available including withdrawal of consent and complaint to the Authority, the existence of automated decision-making including profiling, and the categories of personal data processed; where the data were not obtained from the data subject the categories obtained and their source are added, and the information is due when the data are obtained, or otherwise within a reasonable period and at the latest within one month, or by the first communication or first disclosure if either comes sooner.

Article 25 gives a right of access, at reasonable intervals, free of charge and without excessive delay, to confirmation of processing, the data in an intelligible form, their origin, the storage period and the article 24 transparency information, in electronic or hard copy at the data subject's preference, and article 26 lists the narrow grounds on which access may be refused, each refusal to be given in writing with detailed reasons.

Article 27 gives a right to rectification and requires the controller to pass a correction on to anyone the data were disclosed to in the year before the request, article 28 gives a right to erasure on the listed grounds, article 29 gives a right to object, including an unqualified stop to direct marketing and the profiling related to it, article 30 gives a right to restriction of processing, and article 32 gives a right to data portability in a structured, commonly used and machine-readable format, free of charge and without excessive delay.

Article 31 gives every data subject the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or significantly affects them, to obtain human intervention and to express their views, and bars any automated evaluation of personal aspects from being based on sensitive personal data.

Article 70 enters the Proclamation into force on the date of its publication in the Negarit Gazeta, and it was signed at Addis Abeba on the 24th day of July 2024, so these provisions bind today.

What it requires

Enforcement supervision

Personal Data Protection Proclamation, enforcement, sanctions and offences

Proclamation No. 1321/2024, arts. 55-64 (enforcement, administrative sanctions and offences)Personal Data Protection Proclamation No. 1321/2024, full English text (MetaAppz Ethiopian Federal Laws reference)

In force since 24 July 2024. Binds public and private bodies.

What this law does

Article 55 lets the Ethiopian Communications Authority serve an enforcement order on a data controller or data processor that has contravened, is contravening or is about to contravene the Proclamation, specifying the provision at issue, the measures to be taken, a period of not less than twenty-one days in which to take them, and the right of appeal; on complying, the recipient must tell the data subject concerned and, where compliance materially modifies the data, anyone the data were disclosed to in the twelve months before the order.

Article 56 lets the Authority request information from anyone, in a form that can be taken away and is intelligible and retrievable, and article 57 lets its monitoring arise from its own staff's work or from information and complaints.

Article 58 gives a data subject the right to complain in writing to the Authority, requires the Authority to investigate unless the complaint is not made in good faith and to give its decision in writing within twenty-one days, and allows an appeal to the Federal High Court within sixty days.

Article 59 requires administrative fines to be effective, proportional and dissuasive and lists the factors that set them, and article 60 gives the Authority power to impose administrative penalties for processing in contravention of the Proclamation, rising to a fine of up to four per cent of total worldwide turnover of the preceding financial year where the offence was committed by an institution, in relation to sensitive data, or against a minor's personal data, with any gain made going to the government.

Article 63 puts the burden of proving an exemption on the data controller that refused a data subject's request.

Article 64 sets the criminal tiers: one to three years' simple imprisonment or 60,000 to 100,000 Birr for failing to notify a personal data breach, failing to implement technical and organizational measures, or processing in contravention of the Proclamation; three to five years or 100,000 to 200,000 Birr for denying a data subject's rights of erasure, objection, restriction or protection against automated decisions; five to ten years or 200,000 to 600,000 Birr for re-identifying de-identified data, selling personal data or transferring it out of Ethiopia unlawfully; and the same four per cent of worldwide turnover where the offence involves an institution, serious damage, sensitive personal data or a minor's personal data.

Article 70 enters the Proclamation into force on the date of its publication in the Negarit Gazeta, and it was signed at Addis Abeba on the 24th day of July 2024, so these provisions bind today.

What it requires

Sensitive categories

Personal Data Protection Proclamation, sensitive personal data and minors

Proclamation No. 1321/2024, arts. 9-11 (sensitive personal data and minors)Personal Data Protection Proclamation No. 1321/2024, full English text (MetaAppz Ethiopian Federal Laws reference)

In force since 24 July 2024. Binds public and private bodies.

What this law does

Article 9(1) prohibits the processing of sensitive personal data outright, and article 9(2) permits it only in the listed cases: the data subject's written consent, specific to the purpose and given before the processing, unless a law bars the data subject from lifting the prohibition; protecting the life or health of the data subject or another person where the data subject cannot express consent; the lawful non-commercial objectives of public organizations; medical treatment carried out by a medical treatment institution; and the protection of lawful rights and interests in court or other public proceedings, or processing by a not-for-profit body with a political, philosophical, religious or trade union aim that relates solely to its members and is not disclosed outside it without consent.

Article 9(3) bars processing sensitive personal data in respect of race or ethnic origin unless it ensures justice and equality on those grounds and carries appropriate safeguards, and article 9(4) permits the listed cases only where appropriate technical and security safeguards are in place. Article 10 lets a Regulation add further categories of sensitive personal data.

Article 11 requires a minor's personal data to be processed in a manner that protects and advances the minor's rights and best interests, with the burden of proof on the data controller, and makes that processing lawful only where consent is given or authorized by the minor's parent, guardian or tutor, or where the processing is necessary to the minor's vitally important interest; the data controller must make reasonable efforts to verify the data subject's age and that the consent came from a parent or guardian, taking available technology into account, and processing a minor's personal data for marketing, profiling or merging of profiles is not allowed at all.

Article 70 enters the Proclamation into force on the date of its publication in the Negarit Gazeta, and it was signed at Addis Abeba on the 24th day of July 2024, so these provisions bind today.

What it requires

Scraping law2 instruments, 2 in force

Research summary (343 words)

Ethiopia's computer-misuse authority is the Computer Crime Proclamation No. 958/2016, which punishes securing access to the whole or any part of a computer system, computer data, or network without authorization or in excess of authorization, whether or not the target is a public or a private system; no Ethiopian court decision or statutory carve-out reads a public, unauthenticated page as outside that offence.

The same Proclamation makes a service provider criminally liable for illegal content data disseminated by a third party through its own systems only where the provider was directly involved in disseminating or editing the content, or failed to remove or disable access to it after obtaining actual knowledge or a notice from a competent authority; that duty binds a hosting or access provider, not a general web crawler that only collects data from public pages it does not own.

No statute or reported case addresses terms-of-service enforceability, or whether login or acceptance of terms changes the legal picture; this is unsettled rather than a specific regime.

Copyright protects a database only as a compilation, never through a separate sui generis right: the Copyright and Neighbouring Rights Protection Proclamation No. 410/2004 protects a collection of works such as an encyclopedia, anthology, or database, whether in machine-readable or other form, only where the collection is original by reason of the selection or arrangement of its contents, and its personal-reproduction exception expressly does not extend to reproducing the whole or a substantial part of a database in digital form.

The Personal Data Protection Proclamation No. 1321/2024 reaches scraped public personal data: it defines personal data broadly as any information relating to an identified or identifiable natural person, and its exhaustive list of scope exceptions (personal or household activity, and inter-agency government exchange) carries no carve-out for publicly available personal data, so a scrape of a public page that captures personal data still needs a lawful basis under that Proclamation.

No specific unfair-competition or misappropriation doctrine addresses scraping, and no case law or regulatory statement gives robots.txt legal weight or addresses AI-training-specific access rules.

Computer misuse

Computer Crime Proclamation

Proclamation No. 958/2016 (Federal Negarit Gazette, 22nd Year No. 83, 7 July 2016)Computer Crime Proclamation No. 958/2016, Federal Negarit Gazette, official gazetted text, ILO NATLEX

In force since 7 July 2016. Binds public and private bodies.

What this law does

Article 3 punishes intentionally securing access to the whole or any part of a computer system, computer data, or network, without authorization or in excess of authorization, with simple imprisonment up to three years or a fine of Birr 30,000 to 50,000, rising to rigorous imprisonment of three to five years and a fine of 30,000 to 50,000 where the target system is destined exclusively for a legal person, and five to ten years and a fine of 50,000 to 100,000 where the target is critical infrastructure.

Article 4 punishes intentionally intercepting non-public computer data or a data-processing service, with rigorous imprisonment up to five years and a fine of 10,000 to 50,000, rising in the same two tiers to five to ten years and a fine of 50,000 to 100,000 against a legal person's system, and ten to fifteen years and a fine of 100,000 to 200,000 against critical infrastructure.

Article 16 makes a service provider criminally liable for illegal content data that a third party disseminates through the provider's own computer systems, but only where the provider directly participated in disseminating or editing the content, or, on obtaining actual knowledge that the content is illegal or a notice from a competent administrative authority, failed to take measures to remove or disable access to it.

Article 17 punishes a person's failure to cooperate with an investigative obligation imposed under specified articles of the Proclamation with simple imprisonment up to one year or a fine up to Birr 10,000, and intentional hindrance of a computer-crime investigation with rigorous imprisonment up to five years and a fine up to Birr 50,000.

Where any offence under Part Three of the Proclamation is committed by a juridical person, Article 20 fixes the fine at Birr 50,000 to 500,000 regardless of which offence it was, which is the highest fine figure the Proclamation states for any offender. None of these provisions exempts a publicly accessible, unauthenticated page from the definition of unauthorized access.

What it requires

Database right

Copyright and Neighbouring Rights Protection Proclamation, Database Protection

Proclamation No. 410/2004, arts. 4(6)(b), 9(2)(c) (Database Protection)Copyright and Neighbouring Rights Protection Proclamation No. 410/2004, Federal Negarit Gazeta, official gazetted text

In force since 19 July 2004. Binds private bodies.

What this law does

The Copyright and Neighbouring Rights Protection Proclamation No. 410/2004 defines a database as an aggregate of information, articles, or numerical data or diagrams that is systematically constructed so that it can be searched for with the aid of a computer. A collection of works such as an encyclopedia, anthology, or database, whether in machine-readable or other form, is protected as a work only where the collection is original by reason of the selection or arrangement of its contents.

Ethiopia has no separate sui generis database right. The Proclamation's exception permitting a single-copy personal reproduction of a published work does not extend to reproducing the whole or a substantial part of a database in digital form. Reproducing or communicating a protected work without authorization, outside the Proclamation's exceptions, is punishable under its criminal-sanctions article.

What it requires

Cybersecurity law3 instruments, 1 in force, 2 enacted but not yet in force

Research summary (799 words)

Ethiopia's private-sector security posture rests on two currently enacted instruments plus one duty-to-report provision inside its computer-crime statute, with several adjacent regimes named here but not filed as instruments because their bound party is a status this profile's declared activities cannot express, or because they fall outside this topic's four registered families.

The Critical Infrastructure Cybersecurity Proclamation No. 1426/2026, published in the Federal Negarit Gazette (Year 32, No. 41) on 21 July 2026 and entering into force, under its own Article 28, one year later on 21 July 2027, lets the Information Network Security Administration designate, by Directive, specific institutions within twelve named sectors (information technology and communication, finance, security and safety, transport, education, health, water and energy, government services, disaster management, agriculture, trade, and industry) as critical infrastructure, and imposes eighteen obligations on each designated owner: building a national-framework-aligned cybersecurity program, classifying and protecting critical assets, conducting regular risk assessments, holding current cyber-audit and cybersecurity-inspection-and-evaluation certificates, employing certified cybersecurity professionals, securing the technology supply chain, obtaining security clearance before integrating a new or upgraded information and communication technology system, establishing a center to monitor, report on, and respond to cyberattacks, and notifying the National Computer Emergency Response Center of a cyber incident within 48 hours.

An owner may delegate these duties to a licensed cybersecurity service provider unless the Administration has designated the infrastructure as non-delegable on national-security grounds.

Breach of these duties carries administrative fines set article by article from 300,000 up to 2,000,000 Birr, doubled in some bands for a repeat violation and halved for a negligent one, and separately exposes an officer, employee, manager, or owner who intentionally commits the underlying failure to imprisonment of up to one year, rising to seven to ten years where the failure damages the infrastructure's service or harms national security, public health, life, or the environment.

The Proclamation's own text, and the Information Network Security Administration's public statements, both describe the twelve months after publication as a grace period for institutional readiness, and no designation Directive naming specific covered institutions is confirmed in the primary text, so which institutions are bound today, as distinct from which sectors could eventually be reached, is not yet settled.

Separately, and predating the Critical Infrastructure Proclamation, Article 27 of the Computer Crime Proclamation No. 958/2016, in force since its own publication on 7 July 2016, requires any service provider, meaning a person who provides technical data-processing or communication service or alternative infrastructure to users by means of a computer system, or any government organ, that becomes aware that a crime under that Proclamation is being committed, or that a third party is disseminating illegal content, through the computer system it administers, to notify the Information Network Security Agency (now the Administration) immediately and report the crime to the police; no provision of that Proclamation attaches a penalty to breach of this particular duty.

Part Four of the 2026 Proclamation (arts. 16 to 21) separately licenses and regulates persons who sell cybersecurity products or services, a narrow licensed-vendor status this profile's declared activities do not identify, so it is named here rather than filed.

The Information Technology Products Security Clearance and Control Proclamation No. 1310/2023, also administered by the Administration, is a national-security import, export, and use control and permit regime for technology products the Administration and the National Intelligence and Security Service designate as prohibited or restricted; it does not set a security-by-design or vulnerability-handling standard a product must meet to reach the market generally, so it does not fit any of this topic's four registered law families and is named here without being filed.

The Critical Mass Cyber Security Requirement Standard, version 2.0, issued by the Administration under Article 13 of the Council of Ministers Regulation No. 320/2014 that executes the Administration's own establishment proclamation, states in its own text that it is mandatory for Ethiopia's federal and regional governments and for unspecified 'key private organizations'; the primary text does not define which private organizations meet that description, so its private-sector reach is not filed here either.

Whether the National Bank of Ethiopia has issued its own binding cybersecurity or information-technology risk directive for licensed banks is not confirmed in the primary text: the National Bank's own directives listing serves only a JavaScript shell to the crawler on both the compliant and the browser tier.

No separate, general-application baseline security statute reaching an ordinary, undesignated business was located, so that research dimension is a researched absence outside the designated-critical-infrastructure and computer-crime duties above.

This jurisdiction's own privacy row, the Personal Data Protection Proclamation No. 1321/2024, in force since 24 July 2024, carries the breach-notification duty a data controller owes the Ethiopian Communications Authority within 72 hours; that duty, and the Proclamation's own security-of-processing article, are researched there and are not restated here.

Sector security regimes

Critical Infrastructure Cybersecurity Proclamation, Critical Infrastructure Owner Obligations

Critical Infrastructure Cybersecurity Proclamation No. 1426/2026 art. 3, art. 4, art. 5, art. 7, art. 8, art. 22(1)(a), art. 22(1)(d)-(f), art. 22(2)-(3), art. 22(5), art. 25(1)(a), art. 25(1)(c)-(d), art. 25(2)-(4), art. 28Official Federal Negarit Gazette text, hosted on the Information Network Security Administration's own document portal

In force in 301 days, effective 21 July 2027. Binds public and private bodies.

What this law does

The Information Network Security Administration may designate a critical infrastructure owner under Article 5. A designated owner sits in one of twelve named sectors, including information technology and communication, finance, transport, education, health, water and energy, government services, disaster management, agriculture, trade, and industry.

A designated owner must formulate and implement its own cybersecurity program based on the Administration's mandatory national cybersecurity frameworks. A designated owner must hold a current cyber-audit certificate and a cybersecurity inspection-and-evaluation certificate that the Administration issues. A designated owner must ensure the security of the supply chain of the technology products it uses.

A designated owner must obtain the Administration's security clearance before integrating a new or upgraded information and communication technology system. A designated owner must establish and manage a center responsible for monitoring, reporting, and responding to cyberattacks. An owner may perform these obligations itself or delegate them to a person providing cybersecurity services licensed under this Proclamation.

The Administration may identify infrastructure whose cybersecurity service may not be delegated on national-security grounds.

Not implementing a mandatory framework in time is fined from 500,000 to 1,000,000 Birr, not cooperating with a periodic audit is fined from 1,500,000 to 2,000,000 Birr, and not correcting an audit or inspection finding in time, or using an information and communication technology system that has not undergone the required inspection and evaluation, is each fined from 800,000 to 1,000,000 Birr, with a negligent violation of any of these fined at no more than half the stated amount, a first violation causing no damage resolved with a written warning instead, and a repeat violation fined at triple the stated maximum.

A critical infrastructure officer, employee, manager, or owner who intentionally commits the underlying failure is separately liable to imprisonment of up to one year, a term that rises to rigorous imprisonment of seven to ten years, or three to five years if committed negligently, where the failure damages the infrastructure's service or harms national security, national interest, public health, life, or the environment.

The Proclamation was published in the Federal Negarit Gazette, Year 32, No. 41, on 21 July 2026. Under its own Article 28, it enters into force one year later, on 21 July 2027.

What it requires

Vulnerability and incident reporting

Computer Crime Proclamation, Duty to Report Computer Crime and Illegal Content

Computer Crime Proclamation No. 958/2016, art. 2(13), art. 2(19), art. 17, art. 27, art. 46Official Federal Negarit Gazette text, mirrored via the ILO's NATLEX database

In force since 7 July 2016. Binds public and private bodies.

What this law does

A service provider is any person who provides technical data-processing or communication service or alternative infrastructure to users by means of a computer system.

Any service provider, or any government organ, that has knowledge that a crime under this Proclamation is being committed, or that a third party is disseminating illegal content data, through the computer system it administers, must immediately notify the Information Network Security Agency, now reconstituted as the Information Network Security Administration, report the crime to the police, and take appropriate measures. The Agency may issue a directive on the form and procedure of that report.

No provision of this Proclamation attaches a penalty specifically to a failure to comply with this reporting duty: the separate failure-to-cooperate offense in Article 17 lists five other, unrelated investigatory-assistance articles and does not name Article 27. The Proclamation entered into force on the date of its own publication in the Federal Negarit Gazette, Year 22, No. 83, on 7 July 2016, and no provision found here has repealed or amended Article 27 since.

What it requires

Critical Infrastructure Cybersecurity Proclamation, Cyber Incident Reporting to National CERT

Critical Infrastructure Cybersecurity Proclamation No. 1426/2026 art. 7(14), art. 9(2), art. 22(1)(b)-(c), art. 22(2)-(3), art. 22(5), art. 25(1)(b), art. 25(2)-(4), art. 28Official Federal Negarit Gazette text, hosted on the Information Network Security Administration's own document portal

In force in 301 days, effective 21 July 2027. Binds public and private bodies.

What this law does

The Information Network Security Administration may designate a critical infrastructure owner under Article 5. A designated owner sits in one of twelve named sectors, including information technology and communication, finance, security and safety, and health. A designated owner must notify the National Computer Emergency Response Center of a cyber incident within 48 hours of becoming aware of it, and must implement the mandatory recommendations or directions the Center provides.

A designated owner must also give the Center the information it requests and cooperate with its activities when it is responding to a cyberattack. Failing the 48-hour notification or corrective-action duty is fined from 1,500,000 to 2,000,000 Birr.

Failing to cooperate with the Center's response activities is fined from 300,000 to 500,000 Birr, with a negligent violation of either fined at no more than half the stated amount, a first violation causing no damage resolved with a written warning instead, and a repeat violation fined at triple the stated maximum.

A critical infrastructure officer, employee, manager, or owner who intentionally commits either failure is separately liable to imprisonment of up to one year, a term that rises to rigorous imprisonment of seven to ten years, or three to five years if committed negligently, where the failure interrupts or damages the infrastructure's service or harms national security, national interest, public health, life, or the environment.

The Proclamation was published in the Federal Negarit Gazette, Year 32, No. 41, on 21 July 2026. Under its own Article 28, it enters into force one year later, on 21 July 2027.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (214 words)

Ethiopia has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the general copyright framework of the Copyright and Neighbouring Rights Protection Proclamation No. 410/2004 is the only law reaching an aggregator's reproduction of news content.

Its quotation article permits reproducing or quoting a published work without the copyright owner's authorization, provided the quotation is compatible with fair practice, does not exceed the extent justified by its purpose, and, where the source names an author, names the source and the author; the article carries no headline-length or short-extract cap and no restriction to the press industry, and no reported Ethiopian decision applies it to a systematic news aggregator as opposed to an individual quoting a published work.

Neighbouring rights under the Proclamation protect only performers, producers of sound recordings, and broadcasting organizations, not print or online news publishers, so there is no publisher-side neighbouring right of the kind the European Union's Digital Single Market Directive Article 15 creates.

No statute or case law addresses whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer, and no hot-news or misappropriation doctrine distinct from ordinary copyright law exists. The Proclamation predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists.

Snippet reproduction

Copyright and Neighbouring Rights Protection Proclamation, Quotation Exception

Proclamation No. 410/2004, art. 10 (Quotation)Copyright and Neighbouring Rights Protection Proclamation No. 410/2004, Federal Negarit Gazeta, official gazetted text

In force since 19 July 2004. Binds private bodies.

What this law does

Article 10 of the Copyright and Neighbouring Rights Protection Proclamation No. 410/2004 provides that the owner of copyright cannot forbid the reproduction or quotation of a published work. The quotation must be compatible with fair practice and must not exceed the extent justified by the purpose. Where the quotation is taken from a source that carries the author's name, the quotation must name both the source and the author.

Neighbouring rights under the same Proclamation protect only performers, producers of sound recordings, and broadcasting organizations, so a print or online news publisher holds no neighbouring right distinct from its ordinary copyright in the articles it publishes. No provision addresses hyperlinking, framing, or inline display, and no reported case law applies art. 10 to a systematic aggregator rather than an individual quoting a published work.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.