activities. In South Africa, parliament passed the
Regulation of Interception of Communications
and Provisions of Communication-Related
Information Act 2002, which requires ISPs to
retain data from customers for an as-yet undetermined period of time and makes any Internet system that is unable to be monitored illegal. 89 In
addition, the Electronic Communications and
Transactions Act 2002 created a legion of cyber
inspectors whose job it is to, as Privacy
International describes, “inspect and confiscate
computers, determine whether individuals have
met the relevant registration provisions as well as
search the Internet for evidence of ‘criminal
actions.’” 90
Zimbabwe’s government, on the other hand,
has been fighting for years with its High Court for
wider powers to monitor and intercept e-mails.
As of publication, the court has successfully limited the legal ability of the government to perform
these tasks. 91 The raid, mentioned earlier, on a
cybercafé in 2005, however, shows that the government appears to be achieving its ends
despite these limitations. Furthermore, the government has recently stepped up its surveillance
of Internet activity by placing plain clothes agents
in cybercafés. 92
Nigeria has a relatively well developed
Internet security regulatory system in place
involving agencies such as the Nigerian
Cybercrime Working Group. 93 As mentioned earlier, Nigeria is currently considering the Computer
Security and Critical Information Infrastructure
Protection Bill 2005, which contains provisions to
combat cyberterrorism and to allow the government to request that ISPs hold information about
users without due process. 94 Additionally, the
Nigerian Communications Act 2003 contains
vaguely worded “information-gathering powers”
in the name of security. 95
Under the Telecommunications Act 2005 in
Ghana, ISPs can be instructed under court order
to intercept communications transmitted online
and gather all information they can about users. 96
In special cases, the president can grant authorization, avoiding the need to obtain a court
order. 97 Clauses 20–24 of the Computer and
Computer Related Crimes Act 2005 also delineate specific data retention and Internet communication interception rules for criminal investigations. 98
In addition to those countries that have
already adopted Internet security measures, a
handful of countries are formulating strategies to
address this issue. Malawi’s ICT4D policy, for
example, calls for the government to “formulate
and enforce laws and regulations that combat
cyber crimes; institute mechanisms and laws to
curb vandalism and theft of ICT infrastructure;
and enact a law to validate digital signatures on
documents in relation to the technology on the
market today.” 99 Botswana, as another example,
has acknowledged in its ICT Policy that it lacks
“comprehensive legislation in Botswana to deal
with data crimes, such as interceptions, modification, data theft, or trafficking in digital signatures or domain names” and has called for
further investigation into these topics. 100
As Internet usage develops in Africa, regulations to ensure increased Internet security will be
enacted to address cybercrime and the rights
and responsibilities of government investigators,
including such topics as investigation powers,
surveillance, and data retention laws. Even with
limited Internet penetration, a number of countries have already taken or are currently taking
significant steps to secure the Internet. The intrusiveness of these measures will likely vary by the
repressiveness of the government in question. If
South Africa’s relatively draconian policies are
any indication, however, these security measures
are likely to be highly invasive.
Copyright
Copyright protection is generally well established
in law in sub-Saharan Africa, covering materials
such as written works, music, and videos.
Exceptions for “fair use” are also commonplace.
Regional Overviews
219
Regulation of Interception of Communications
and Provisions of Communication-Related
Information Act 2002, which requires ISPs to
retain data from customers for an as-yet undetermined period of time and makes any Internet system that is unable to be monitored illegal. 89 In
addition, the Electronic Communications and
Transactions Act 2002 created a legion of cyber
inspectors whose job it is to, as Privacy
International describes, “inspect and confiscate
computers, determine whether individuals have
met the relevant registration provisions as well as
search the Internet for evidence of ‘criminal
actions.’” 90
Zimbabwe’s government, on the other hand,
has been fighting for years with its High Court for
wider powers to monitor and intercept e-mails.
As of publication, the court has successfully limited the legal ability of the government to perform
these tasks. 91 The raid, mentioned earlier, on a
cybercafé in 2005, however, shows that the government appears to be achieving its ends
despite these limitations. Furthermore, the government has recently stepped up its surveillance
of Internet activity by placing plain clothes agents
in cybercafés. 92
Nigeria has a relatively well developed
Internet security regulatory system in place
involving agencies such as the Nigerian
Cybercrime Working Group. 93 As mentioned earlier, Nigeria is currently considering the Computer
Security and Critical Information Infrastructure
Protection Bill 2005, which contains provisions to
combat cyberterrorism and to allow the government to request that ISPs hold information about
users without due process. 94 Additionally, the
Nigerian Communications Act 2003 contains
vaguely worded “information-gathering powers”
in the name of security. 95
Under the Telecommunications Act 2005 in
Ghana, ISPs can be instructed under court order
to intercept communications transmitted online
and gather all information they can about users. 96
In special cases, the president can grant authorization, avoiding the need to obtain a court
order. 97 Clauses 20–24 of the Computer and
Computer Related Crimes Act 2005 also delineate specific data retention and Internet communication interception rules for criminal investigations. 98
In addition to those countries that have
already adopted Internet security measures, a
handful of countries are formulating strategies to
address this issue. Malawi’s ICT4D policy, for
example, calls for the government to “formulate
and enforce laws and regulations that combat
cyber crimes; institute mechanisms and laws to
curb vandalism and theft of ICT infrastructure;
and enact a law to validate digital signatures on
documents in relation to the technology on the
market today.” 99 Botswana, as another example,
has acknowledged in its ICT Policy that it lacks
“comprehensive legislation in Botswana to deal
with data crimes, such as interceptions, modification, data theft, or trafficking in digital signatures or domain names” and has called for
further investigation into these topics. 100
As Internet usage develops in Africa, regulations to ensure increased Internet security will be
enacted to address cybercrime and the rights
and responsibilities of government investigators,
including such topics as investigation powers,
surveillance, and data retention laws. Even with
limited Internet penetration, a number of countries have already taken or are currently taking
significant steps to secure the Internet. The intrusiveness of these measures will likely vary by the
repressiveness of the government in question. If
South Africa’s relatively draconian policies are
any indication, however, these security measures
are likely to be highly invasive.
Copyright
Copyright protection is generally well established
in law in sub-Saharan Africa, covering materials
such as written works, music, and videos.
Exceptions for “fair use” are also commonplace.
Regional Overviews
219
