INSIGHT ETHIOPIA 1 MIN READ

Ethiopia | ICT Regulations & Cybersecurity

Published

Ethiopia’s new ICT regulations strengthen data protection, mainstream ISP licensing, and address rising cyberthreats, positioning the country at a pivotal moment in digital governance.

  • In July 2024, Ethiopia introduced the Personal Data Protection Proclamation (PDPP), requiring local storage of personal data and restricting international transfers unless explicit consent or equivalent protection exists. || Source: Strathmore University
    + Additionally, the PDPP grants data rights similar to the EU’s GDPR, allowing access, correction, and erasure. Notably, these rights extend 10 years posthumously, ensuring prolonged data protection.
  • Furthermore, in 2024, the Ethiopian Communications Authority required new ISP licensing fees, reaching 5 million birrs ($37,000 USD), with annual 1% gross revenue service charges and 500,000 birr ($780 USD) fees for data center operators. || Source: Addis Insight
  • Notably, Ethiopia ranked 2nd globally for cyberattacks in June 2024, surpassing Zimbabwe (3rd) and Kenya (9th), highlighting escalating cybersecurity risks despite stricter regulations. || Source: NCSI
  • To address these threats, INSA blocked 4,272 of 4,422 cyberattacks between July 2022 and March 2023, preventing an estimated $146.56 million in damages. || Source: INSA