The AU’s cybercrime response: A positive start, but substantial challenges ahead
Summary
This policy brief by the Institute for Security Studies examines the African Union's (AU) adoption of the Convention on Cyber Security and Personal Data Protection. It argues that while the convention is a positive step, African states face significant hurdles in ratification and implementation due to capacity gaps, free speech concerns, and the global nature of cybercrime.
Key insights
- Africa is increasingly viewed as a 'cybercrime safe harbour' due to a combination of lower costs for Internet access, a rapidly expanding user base, and a lack of existing cybercrime laws across the continent.
- The AU adopted the Convention on Cyber Security and Personal Data Protection on 27 June 2014, which requires member states to criminalise attacks on computer systems, data breaches, content-related offences, and breaches of electronic message security.
- Critics argue that the AU convention imposes overly broad restrictions on free speech, specifically regarding the criminalisation of computerised content that is racist, xenophobic, or insults persons based on race, religion, or political opinion.
- Implementation of the convention is hindered by severe capacity shortfalls, including a lack of technical expertise to draft laws and deficiencies in the training of judges, prosecutors, and police regarding electronic evidence and computer-related crimes.
- The AU has tasked the New Partnership for Africa’s Development (NEPAD) with a capacity-building project to address gaps in the cybersecurity workforce and regulatory environments, though NEPAD may lack the necessary funding.
- The AU convention exists alongside various non-binding regional instruments from the EAC, COMESA, and SADC, as well as the binding Council of Europe Budapest convention, of which Mauritius is the only African state to have ratified.
- The author recommends that African states should not rely solely on the AU convention process but should also seek to ratify the Budapest convention and prioritize immediate domestic cybersecurity improvements to avoid becoming a global weak link.
Cite the original document
- APA
- Tamarkin, E. (2015). The AU’s cybercrime response: A positive start, but substantial challenges ahead. Institute for Security Studies. https://issafrica.s3.amazonaws.com/site/uploads/PolBrief73_cybercrime.pdf
- Chicago
- Tamarkin, Eric. The AU’s cybercrime response: A positive start, but substantial challenges ahead. Institute for Security Studies, 2015. https://issafrica.s3.amazonaws.com/site/uploads/PolBrief73_cybercrime.pdf.
- Wikipedia
- {{cite report |last1=Tamarkin |first1=Eric |title=The AU’s cybercrime response: A positive start, but substantial challenges ahead |publisher=Institute for Security Studies |date=January 2015 |url=https://issafrica.s3.amazonaws.com/site/uploads/PolBrief73_cybercrime.pdf |access-date=17 August 2026 |via=Climate Insights Directory}}
- BibTeX
- @techreport{tamarkin2015aus, author = {Tamarkin, Eric}, title = {{The AU’s cybercrime response: A positive start, but substantial challenges ahead}}, institution = {Institute for Security Studies}, year = {2015}, month = jan, url = {https://issafrica.s3.amazonaws.com/site/uploads/PolBrief73_cybercrime.pdf}, urldate = {2026-08-17}, note = {Indexed by Climate Insights Directory} }
Full text
Collected · Record updated