FIFAfrica26 Agenda Reveals Africa’s Tech Ecosystem is Keeping in Tandem With Global Strides

By FIFAfrica |

The Forum on Internet Freedom in Africa (FIFAfrica) has evolved in tandem with the prevailing concerns related to the internet in Africa. At its inception in 2014, discourse centred around who is connected and how to access information. While this remains pertinent today, Africa’s digital ecosystem has become far more complex.

This year, the Forum is hosted by the Collaboration on International ICT Policy in East and Southern Africa (CIPESA) in partnership with Mauritius-based Halley Movement Coalition. The keynote speech will be delivered by the Minister of Information Technology, Communication and Innovation of Mauritius.

FIFAfrica has become one of the continent’s most important convening spaces for shaping debate on digital rights, internet governance, and civic freedoms. Its continued relevance lies in its ability to remain closely attuned to the changing realities of Africa’s digital landscape, since its inception in 2014.

Within Africa’s digital rights ecosystem, the Forum serves the strategic function of connecting research, advocacy, policymaking, movement building, and public interest engagement in one forum. FIFAfrica is particularly significant because it places African digital rights interests within wider global conversations on technology governance, including for the Internet Government Forum (IGF), the World Summit on the Information Society (WSIS), and numerous others. At a time when decisions on Artificial Intelligence (AI), digital public infrastructure, content moderation, cross-border data governance, and online freedoms are increasingly shaped through international processes, FIFAfrica positions African stakeholders to contribute evidence and shape narratives in ways that are rooted in the continent’s own political, economic, and social contexts.

The four-day Forum kicks off with two days of 18 pre-events, followed by two days of the main programme which features 41 stand-out sessions, with participants from across Africa and beyond. The Forum has eight thematic areas covering digital democracy and civic participation, data governance and sovereignty, AI and emerging technologies, platform accountability, digital inclusion, digital economy and trade, movement building, and digital security and safety.

The agenda is built out of a selection of submissions received from more than 450 proposals received via a public call for sessions and travel support. The diversity of sessions submitted and selected is a reflection of the multiplicity of issues that the African tech ecosystem needs to address, many of which cannot be addressed in isolation. Questions about human rights and democracy increasingly intersect with technology and information. Meanwhile, data governance is tied to economic interests, while AI raises questions about exploitation, information integrity, access to information, and discrimination.

There will be strategic engagement between regulators, parliamentarians and the judiciary from across Africa on the Malabo Convention in a session hosted by Mzalendo Trust in partnership with CIPESA and the African Parliamentary Network on Internet Governance (APNIG). Further sessions engaging National Human Rights Institutions (NHRIs) on human rights and technology will be hosted by the Danish Human Rights Institute in partnership with CIPESA and the International Commission of Jurists (ICJ). The Forum will also serve as the host of the pre-launch of the Copenhagen Principles for the Protection of Human Rights in the Digital Age.

Meanwhile, AI remains a focus area of discussion due to its intersection with data protection, worker rights, access to information, information integrity, and democracy. Entities including Digital Action, the Global Center on AI Governance, the Electronic Frontier Foundation (EFF), the African Internet Rights Alliance (AIRA), the Digital Rights Alliance of Africa (DRAA), BBC Media Action, UNESCO, Article 19, Lighthouse Reports, Africa Uncensored, the Office of the United Nations High Commissioner for Refugees, and the Oversight Board will explore these concerns, including through the lens of child online safety, migration, media regulation, digital markets, and digital democracy. 

Further sessions entail discussions on the state of data governance, civic space, strategic litigation, technology and human rights, digital identity, DPI, gender and civic participation as part of broader debates on data, power and emerging technologies. Speakers will be drawn from entities such as Oxfam, Pan African Lawyers Union (PALU), and the Digital Impact Alliance (DIAL).

Platform accountability is also a key area of interest, including how it can be humanised, while sessions on corporate power and the push-back against internet shutdowns will involve speakers from Nguvu Collective, Lumate, and the Oversight Lab. Long-term FIFAfrica partner, Access Now, will host a session marking a decade of the #KeepItOn campaign. Internet shutdowns remain key violations of freedom of expression and access to information on the continent and also have significant economic and infrastructural consequences.

For years, platform regulation has often been framed around content moderation and how platforms should respond to harmful content. However, various FIFAfrica26 sessions are extending the debate into how platforms collect and use data, how they design recommendation and advertising systems, how they assess risk, how they respond to government demands, how they conduct due diligence, and what remedies they provide to people harmed by their systems. This is particularly important in Africa, where the global scale of technology companies is vastly greater than the capacity of national regulators and courts to scrutinise them. Entities such as CIPESA, GIZ, the Oversight Board, and EFF will host sessions challenging these narratives.

Sessions at the Forum will also reflect on shrinking civic space online and offline across the continent, including learnings from the cancellation of Rightscon and the rise in authoritarian practices across the continent. These will be candidly addressed by Access Now, RightsCon, and Amnesty International.

Practical sessions also form part of the agenda, with Masakhane, International Research & Exchanges Board (IREX) and the Human Rights Foundation (HRF) each hosting skills workshops on Safety By Design for African tech ecosystems, AI and languages, as well as Bitcoin as a tool for human rights activism and civil society respectively.

FIFAfrica26 continues in its path of inclusion and will entail language interpretation and adherence to a code of conduct that encourages active participation and contribution online and offline.

CIPESA Weighs in on Kenya’s Draft Guidance Notes on AI and Emerging Technologies

By Raylenne Kambua |

The Collaboration on International ICT Policy for East and Southern Africa (CIPESA) submitted comments on two draft Guidance Notes that Kenya’s Office of the Data Protection Commissioner (ODPC) opened for public participation: one on Artificial Intelligence (AI), and another on Emerging Technologies.

The draft Notes provide guidance to entities on how to make sure their AI systems and emerging technologies comply with the Data Protection Act, 2019. While this is a positive step toward the responsible adoption and deployment of AI and emerging technologies, CIPESA highlights gaps the ODPC should address to ensure these technologies are governed in a rights-respecting, transparent, and accountable manner.

CIPESA’s Comments on the Draft Guidance Note on AI

A first set of concerns relates to how the AI Note fits with other legal frameworks. The Note cites only national laws, yet AI in Kenya operates within a wider regional and international framework, which risks regulatory inconsistency. Continental frameworks such as the AU Continental AI strategy, the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention) and the AU Data Policy Framework offer guidance on AI development and harmonised data governance.

The Note requires entities to conduct adequacy assessments before transferring AI-processed personal data across borders. Although intended to protect privacy, this requirement could trigger blanket data localisation and impede cross-border AI inference and cloud computing capabilities. CIPESA recommends aligning these assessments with the AU Data Policy Framework and the African Continental Free Trade Area (AfCFTA) Protocol on Digital Trade to balance privacy safeguards with Africa’s digital trade ambitions.

As AI is increasingly deployed as an assistive technology, it risks excluding persons with disabilities when training data and biometric information are developed without their input. CIPESA observes that the Note omits Article 54 of the Constitution of Kenya, which protects persons with disabilities. Incorporating this provision would align the guidance with other standards, which set a benchmark for how regulation can protect groups that AI systems often overlook.

Furthermore, the draft Note lacks cross-references to the ODPC’s 2025 Guidance Note for Processing Children’s Data, and the Children Act, 2022, which enforces online protection and the best-interest principle for minors. This shortcoming creates disharmony among related efforts on children’s protection.

The submission points to the 2025 High Court judgment against Worldcoin, which found that iris data from hundreds of thousands of Kenyans was processed without a Data Protection Impact Assessment (DPIA). The Note’s biometric provisions prohibit only real-time surveillance without legal authority. This leaves retrospective analysis of stored facial or iris images unregulated, even though it carries equivalent privacy risks. CIPESA advocates mandatory pre-deployment registration with the ODPC and submission of DPIAs before any biometric data processing begins.

As generative AI spreads, so do its risks, such as hallucination. CIPESA recommends implementing verifiable content records and labelling requirements, such as watermarking or equivalent disclosure, for synthetic media used in decisions affecting individuals. This aligns with constitutional consumer rights under Article 46 and supports digital trust in continental trade involving automated electronic services covered by the AfCFTA Digital Trade Protocol.

The AI shaping Kenyans’ daily consumption centres around algorithmic feeds rather than enterprise chatbots. CIPESA argues that if AI laws regulate only technical enterprise tools while ignoring social media algorithms and content curation systems, they risk missing the AI that mostly shapes consumers’ public discourse. Global and local platforms that process Kenyan users’ data must also be subject to algorithmic governance and regular audits.

CIPESA also notes that the Note’s high-risk AI table omits information systems deployed in political and electoral environments. This is despite political opinion being classified as sensitive personal data under major data protection laws, and the AI Bill, 2026 addressing synthetic political content. CIPESA recommends adding categories for AI in political communication, voter micro-targeting, and synthetic political media ahead of the 2027 general election.

Other recommendations concern who the rules protect and who they hold to account. Kenya’s data annotators, content moderators, and reinforcement learning from human feedback (RLHF) workers help train both local and foreign AI models. However, the Note’s obligations focus entirely on end-user rights. CIPESA calls for extending data protection rights to this workforce, including protections over performance and monitoring data collected about them.

The Note requires entities to register with the ODPC as data controllers or processors before deploying any AI system that processes personal data. However, it does not address the separate Commissioner-maintained public register of high-risk AI models that is proposed under the AI Bill, 2026. CIPESA recommends clarifying how registration functions will be divided between the ODPC and the prospective AI Commissioner.

Regarding Digital Public Infrastructure such as interoperable digital identity systems, the Social Health Authority’s premium assessments, and the Kenya Revenue Authority’s automated eTIMS processes, CIPESA advises mandatory pre-deployment DPIAs, equity assessments before deployment, publicly disclosed methodologies, and human review guarantees.

Finally, AI governance is incomplete if it regulates companies but leaves government and security agencies outside meaningful oversight and accountability. CIPESA warns that without accountability for state use of AI in public services and surveillance, critical systems remain unmonitored. Citizens should be able to challenge public sector AI decisions just as they can challenge those of private entities.

CIPESA’s Comments on the Draft Guidance Note on Emerging Technologies

CIPESA also submitted comments on the Draft Guidance Note on Emerging Technologies. On cloud computing, it cautions that restricting systems tied to “the strategic interests of the state” risks becoming a de facto data localisation rule. CIPESA recommends confining data localisation to cases where a specific statutory requirement applies, in line with the AfCFTA Digital Trade Protocol and the AU Data Policy Framework’s emphasis on responsible intra-African data flows.

The submission advocates a complete prohibition on real-time remote biometric identification and indiscriminate mass surveillance in public spaces. It warns against using biometric categorisation to infer sensitive traits, alongside AI-based emotion recognition in schools and workplaces. Law enforcement remote biometric identification must require legal authorisation, judicial warrant, and independent oversight.

To strengthen impact assessments, CIPESA suggests publishing executive summaries of all DPIAs, excluding trade secrets, on a public High-Risk Technology Register before deployment. This would improve transparency and accountability and build public trust in high-risk emerging technology deployments.

Concerning automated decisions, CIPESA recommends meaningful human review by a reviewer with real authority to overturn or modify the outcome, not a rubber stamp. This should apply specifically to decisions on employment, credit, insurance, healthcare, social protection, immigration, and policing. To reduce the compliance burden, CIPESA recommends simplified registration and DPIA templates.

Building on CIPESA’s Wider Work on Kenya’s AI Governance

The two submissions follow CIPESA’s August 2026 submission on the Draft Kenya AI and Other Emerging Technologies Policy, which raised similar concerns about institutional independence and biometric safeguards at the policy level. They also draw on the Navigating the Implications of AI on Digital Democracy in Kenya report and its regional companion. The AI Guidance Note’s argument on algorithmic feeds echoes Kenya Doesn’t Have an AI Regulation Gap, It Has an Accountability Gap and Who Holds Digital Power Accountable? Lessons from Platform Governance in Africa.

Read CIPESA’s full comments on the Draft Guidance Notes on AI here and on Emerging Technologies here.

It’s Almost Time For FIFAfrica26! Discover the Agenda. Meet the Speakers

By FIFAfrica |

This time next week, FIFAfrica26 will be underway in Mauritius!

The conversations we have been planning, the ideas we have been shaping, and the connections we have been looking forward to will finally shift into actions, debates, and new learning!

Across four days, FIFAfrica26 will bring together conversations on digital democracy and civic participation, AI and emerging technologies, data governance and sovereignty, platform accountability, digital inclusion, digital economy and trade, movement building, and digital security and safety.

Here is what you can look forward to:

  • Two days of engaging pre-event sessions (Be sure to sign up, as spaces are limited!)
  • Two days of an action-packed main event agenda, with in-depth sessions featuring speakers from across Africa and beyond. Be sure to explore the Agenda and meet the Speakers!
  • A Digital Rights Fun Run – come ready with your running shoes!
  • A Digital Reality Walk through Paths, Traps and Safe Passages.
  • An exhibition where you can discover new work, explore resources and meet the people behind some of the amazing digital rights work happening across the continent.

FIFAfrica is a unique opportunity to discover new work and organisations, exchange ideas and insights, make connections, and encounter conversations that expand how you think about the digital rights ecosystem. There will be plenty of opportunities to connect, contribute and make FIFAfrica26 your own.

Visit the FIFAfrica website for more information.

FIFAfrica26 is calling! How Will You Answer?

By FIFAfrica |

Accept the call and come ready to “Be The Experience”!

At the upcoming Forum on Internet Freedom in Africa 2026 (FIFAfrica26), be ready to do lots of the following:

  • Connect and meet people beyond your usual networks.
  • Question by bringing the difficult questions.
  • Learn by stepping into conversations beyond your usual area of work
  • Contribute through sharing your experience, ideas and perspective
  • Collaborate and find people you can build with
  • Experience and make the Forum your own!

As you enjoy the weekend, take a little time to think about what you are bringing to FIFAfrica26, what you hope to take away, and the conversations you want to be part of.

We look forward to engaging with you more next week as we get closer to the Forum.

Until then, get ready to Accept the Call and #BeTheExperience!

If you haven’t yet registered for FIFAfrica26, you can still do so here.

Uganda’s Digital Economy: Rights Trends, Regulatory Gaps and Policy Responses

By Doreen Elizabeth Namuyanja |

Uganda’s digital economy is expanding rapidly across finance, transport, agriculture, commerce, healthcare and public-service delivery. However, this growth is outpacing the legal, regulatory and institutional safeguards needed to address emerging concerns around personal and biometric data, artificial intelligence, platform work, digital exclusion and internet shutdowns.

Drawing on a 2025 survey, two commentaries and a policy submission by CIPESA, this policy brief examines Uganda’s evolving digital business landscape, business data practices, the future of work and the impact of internet disruptions. It highlights the gaps between technological advancement and effective governance and proposes actions for government, businesses, private sector associations and civil society to build an inclusive, resilient, and rights-respecting digital economy.

The brief finds that Uganda has established important legal protections, including the Data Protection and Privacy Act of 2019. The principal challenge, however, is implementation, enforcement, and the ability of regulatory and institutional frameworks to adapt to rapidly evolving technologies and business models. Businesses frequently collect personal and biometric data without sufficiently explaining how it will be used, stored, shared, or deleted. Meaningful consent, data security, and effective retention and deletion practices also remain inconsistent, particularly among businesses with limited compliance capacity.

These gaps have consequences beyond privacy and individual rights. Weak data governance can undermine trust in digital services, while inadequate safeguards for platform workers and persistent digital exclusion can limit who benefits from the digital economy. Internet shutdowns pose a broader threat, disrupting digital financial services, e-commerce, public services and other activities that increasingly depend on reliable connectivity.

The brief calls for coordinated action by government, businesses, private sector associations and civil society to:

Businesses

  • Strengthen data governance and informed consent: implement collection and processing frameworks built on explicit, freely given consent, backed by clear, accessible privacy notices.
  • Improve data security and lifecycle management: adopt encryption, regular security audits, and clear retention, deletion and minimisation policies.
  • Build organisational compliance capacity: appoint and train Data Protection Officers, embed privacy-by-design into product development, and run regular staff training on data protection, cybersecurity and phishing risks.
  • Strengthen digital resilience: develop business continuity plans for internet disruptions, and collaborate with civil society and legal actors to promote an open, secure and reliable internet.

Government of Uganda

  • Strengthen enforcement of the data protection framework by adequately resourcing the Personal Data Protection Office (PDPO) and other regulators to conduct audits, investigate violations, and impose proportionate sanctions.
  • Modernise the legal and policy framework to address biometric data, AI and platform work, aligned with constitutional and international human rights standards, and issue practical, sector-specific guidance to help businesses, particularly SMEs, comply.
  • Promote digital inclusion and public awareness through sustained education campaigns, including in local languages, and continued investment in affordable infrastructure and digital skills.
  • Safeguard the digital economy against internet disruptions by developing clear legal safeguards against shutdowns and ensuring any restrictions comply with constitutional and international human rights obligations.

Private Sector Associations

  • Build members’ capacity through regular training on data protection, cybersecurity, AI governance and business continuity planning.
  • Promote industry standards and peer learning by developing model policies and compliance toolkits for consistent implementation across member organisations.
  • Support risk management by encouraging periodic risk assessments among members and facilitating the sharing of lessons learned and mitigation strategies.

Civil Society Organisations

  • Strengthen multi-stakeholder collaboration among government, businesses, academia and technical experts on data protection, AI governance and digital rights.
  • Promote public awareness and digital rights literacy through accessible educational materials and community outreach.
  • Undertake research and evidence-based advocacy on biometric data governance, AI, platform work and internet shutdowns, including documenting their social, economic and human rights impacts, to support stronger legal frameworks and strategic litigation.
  • Support business compliance and resilience by developing practical guidance, templates and capacity-building support on responsible data governance.

Read the full brief here.