Addressing Online Harms Ahead of Rwanda’s 2026 UPR Review

By Patricia Ainembabazi |

As the world commemorates the 16 Days of Activism Against Gender-Based Violence (November 25 to December 10), global attention is drawn to the rising risks women and girls face in digital environments. These harms increasingly undermine political participation, public discourse, and the safety of women across Africa.

Accordingly, the Collaboration on International ICT Policy for East and Southern Africa (CIPESA) and the Association for Progressive Communications (APC) have stressed the urgent need to address technology-facilitated gender-based violence (TFGBV) in Rwanda in written and oral submissions to the Universal Periodic Review (UPR) 51st pre-session for Rwanda at the United Nations Human Council in Geneva. In a joint CIPESA–APC fact sheet on human rights, the two organisations highlighted critical gaps in legal protections, online safety, and digital inclusion in Rwanda.

The joint UPR report notes that TFGBV has become a major deterrent to Rwandan women’s participation online, affecting women in politics, journalism, activism, and advocacy. The 2024 online smear campaign against opposition figure Victoire Ingabire Umuhoza illustrates the gendered nature of digital disinformation and harassment. Such attacks rely on misogynistic narratives designed to humiliate, silence, and delegitimise women’s public engagement. This pattern is not only a violation of rights; it also reinforces structural inequalities and dissuades other women from engaging in civic or political life.

These concerns reflect global trends. UN Women has warned of the rapid escalation of deepfake pornography, a form of digitally manipulated sexualised content disproportionately deployed against women and girls. Deepfakes can cause severe psychological, reputational, and professional harm, often leaving survivors without effective avenues for redress. They are increasingly used to silence women, distort electoral participation, and discourage women from entering political leadership. Such harms undermine democratic processes, distort public debate, and entrench gender inequality.

Rwanda’s obligations under the Convention on the Elimination of All Forms of Discrimination Against Women (CEDAW) require the state to take comprehensive measures to eliminate discrimination (Articles 2 and 3) and ensure women’s full participation in political and public life (Article 7). However, as documented in the joint UPR report and fact sheet, gaps persist. The 2018 Cybercrime Law lacks survivor-centred provisions, and its broad definitions have on occasion been applied in ways that disadvantage victims.

Moreover, enforcement remains inconsistent, and the absence of specialised mechanisms for investigating and prosecuting online violence limits accountability. In this context, TFGBV is not merely a digital phenomenon; it is a direct barrier to fulfilling Rwanda’s CEDAW obligations and achieving SDGs 5 and 16.

The gender digital divide further compounds these harms. Internet penetration in Rwanda stands at 34.2%, with women representing just 38.2% of social media users. Structural inequalities, including device affordability, income disparities, and limited digital literacy, restrict women’s participation in digital spaces. These inequalities heighten vulnerability to online harm and restrict access to safety tools, reporting mechanisms, and digital rights resources. As the joint CIPESA–APC evidence indicates, without targeted investment in digital literacy, device access, and connectivity for women, Rwanda risks deepening existing socio-economic and civic inequalities.

During the UPR pre-session, CIPESA and APC presented a set of recommendations aimed at promoting rights-respecting digital governance. These included adopting survivor-centred TFGBV protections aligned with CEDAW, strengthening investigative and prosecutorial capacities to effectively respond to online harms, and compelling technology platforms to improve reporting, moderation, and accountability mechanisms. The submission also called for amending restrictive provisions in the Penal Code and Cybercrime Law, establishing independent oversight over surveillance operations, and addressing the gender digital divide through targeted digital literacy and affordability initiatives.

The 16 Days of Activism provide an important reminder that violence against women is evolving in both form and reach. Digital technologies have expanded the avenues through which women are targeted, often enabling harm that is faster, more pervasive, and harder to remedy. Ending violence against women, therefore, requires recognising online spaces as critical sites of protection.

Rwanda enters its fourth UPR cycle with a number of unaddressed commitments. During the 2021 review, the Rwandan government received 32 recommendations on freedom of expression and media freedom, including 24 urging reforms to restrictive speech provisions and 17 calling for enhanced protections for journalists and human rights defenders. Yet implementation has been limited. Provisions in Rwanda’s 2018 Penal Code and 2018 Cybercrime Law continue to criminalise “false information”, edited content, and criticism of public authorities, enabling arrests of journalists and discouraging dissenting expression.

These laws have contributed to widespread self-censorship, shrinking civic space, and undermining public participation in digital environments. At the same time, reports of intrusive surveillance, such as the documented use of Pegasus spyware targeting thousands of journalists, activists, and diaspora members, further erode trust and violate privacy rights. The absence of independent oversight in surveillance practices intensifies this concern.

The Country’s ongoing engagement with the UPR process and its upcoming review scheduled for January 21, 2026, offers a timely opportunity to address these challenges. During the pre-sessions 51 from 26 -27 November 2025 in Geneva, several permanent missions expressed eagerness to advance strong recommendations for Rwanda, and there is hope that these delegations will amplify our proposals during the formal review.

CIPESA and APC remain committed to supporting evidence-based reforms that strengthen digital rights protections across Africa. Rwanda’s review presents a defining moment for the government to adopt meaningful, future-focused reforms that uphold human rights, ensure accountability, and create a digital environment where all citizens, especially women, can participate safely, freely, and equally in shaping the country’s democratic and digital future.

#BeSafeByDesign: A Call To Platforms To Ensure Women’s Online Safety

By CIPESA Writer |

Across Eastern and Southern Africa, activists, journalists, and women human rights defenders (WHRDs) are leveraging online spaces to mobilise for justice, equality, and accountability.  However, the growth of online harms such as Technology-Facilitated Gender-Based Violence (TFGBV), disinformation, digital surveillance, and Artificial Intelligence (AI)-driven discrimination and attacks has outpaced the development of robust protections.

Notably, human rights defenders, journalists, and activists face unique and disproportionate digital security threats, including harassment, doxxing, and data breaches, that limit their participation and silence dissent.

It is against this background that the Collaboration on International ICT Policy for East and Southern Africa (CIPESA), in partnership with Irene M. Staehelin Foundation, is implementing a project aimed at combating online harms so as to advance digital rights. Through upskilling, advocacy, research, and movement building, the initiative addresses the growing threats in digital spaces, particularly affecting women journalists and human rights defenders.

The first of the upskilling engagements kicked off in Nairobi, Kenya, at the start of December 2025, with 25 women human rights defenders and activists in a three-day digital resilience skills share workshop hosted by CIPESA and the Digital Society Africa. Participants came from the Democratic Republic of Congo, Madagascar, Malawi, South Africa, Tanzania, Uganda, Zambia, and Zimbabwe. It coincides with the December 16 Days Of Activism campaign, which this year is themed “Unite to End Digital Violence against All Women and Girls”.

According to the United Nations Population Fund (UNFPA), TFGBV is “an act of violence perpetrated by one or more individuals that is committed, assisted, aggravated, and amplified in part or fully by the use of information and communication technologies or digital media against a person based on their gender.” It includes cyberstalking, doxing, non-consensual sharing of intimate images, cyberbullying, and other forms of online harassment.

Women in Sub-Saharan Africa are 32% less likely than men to use the internet, with the key impediments being literacy and digital skills, affordability, safety, and security. On top of this gender digital divide, more women than men face various forms of digital violence. Accordingly, the African Commission on Human and Peoples’ Rights (ACHPR) Resolution 522 of 2022 has underscored the urgent need for African states to address online violence against women and girls.

Women who advocate for gender equality, feminism, and sexual minority rights face higher levels of online violence. Indeed, women human rights defenders, journalists and politicians are the most affected by TFGBV, and many of them have withdrawn from the digital public sphere due to gendered disinformation, trolling, cyber harassment, and other forms of digital violence. The online trolling of women is growing exponentially and often takes the form of gendered and sexualised attacks and body shaming.

Several specific challenges must be considered when designing interventions to combat TFGBV. These challenges are shaped by legal, social, technological, and cultural factors, which affect both the prevalence of digital harms and violence and the ability to respond effectively. They include weak and inadequate legal frameworks; a lack of awareness about TFGBV among policymakers, law enforcement officers, and the general public; the gender digital divide; and normalised online abuse against women, with victims often blamed rather than supported.

Moreover, there is a shortage of comprehensive response mechanisms and support services for survivors of online harassment, such as digital security helplines, psychosocial support, and legal aid. On the other hand, there is limited regional and cross-sector collaboration between CSOs, government agencies, and the private sector (including tech companies).

A guiding strand for these efforts will be the #BeSafeByDesign campaign that highlights the necessity of safe platforms for women as well as the consequences when safety is missing. The #BeSafeByDesign obligation shifts the burden of responsibility of ensuring safety in online spaces away from women and places it on platforms where more efforts on risk assessments, accessible and stronger reporting pathways, proactive detection of abuse, and transparent accountability mechanisms are required. The initiative will also involve the practical upskilling of at-risk women in practical cybersecurity.

Advancing African-Centred AI is a Priority for Development in Africa

By Patricia Ainembabazi |

The Collaboration on International ICT Policy for East and Southern Africa (CIPESA) participated in the annual DataFest Africa event held on 30-31 October, 2025. Hosted by Pollicy, the event serves to celebrate data use in Africa by bringing together various stakeholders from diverse backgrounds, such as government, civil society, donors, academics, students, and private industry experts, under one roof and theme.  The event provided a timely platform to advance discussions on how Africa can harness AI and data-driven systems in ways that centre human rights, accountability, and social impact.

CIPESA featured in various sessions at the event, one of which was the launch of the ‘Made in Africa AI for Monitoring, Evaluation, Research and Learning (MERL)’ Landscape Study by the MERL Tech Initiative. At the session, CIPESA provided reflections on the role of AI in development across several humanitarian sectors in Africa.

CIPESA’s contributions complemented insights from the study that explored African approaches to AI in data-driven evidence systems and which emphasised responsive and inclusive design, contextual relevance, and ethical deployment. The Study resonated with insights from the CIPESA 2025 State of Internet Freedom in Africa report, which highlights the role of AI as  Africa navigates digital democracy.

According to the CIPESA report, AI technologies hold significant potential to improve civic engagement, extend access to public services, scale multilingual communication tools, and support fact-checking and content moderation. On the flip side, the MERL study also underscores the risks posed by AI systems that lack robust governance frameworks, including increased surveillance capacity, algorithmic bias, the spread of misinformation, and deepening digital exclusion. The aforementioned risks and challenges pose major concerns regarding readiness, accountability, and institutional capacity, given the nascent and fragmented legal and regulatory landscape for AI in the majority of African countries..

Sam Kuuku, Head of the GIZ-African Union AI Made in Africa Project, noted that it is important for countries and stakeholders to reflect on how well Africa can measure the impact of AI and evaluate the role and potential of AI use in improving livelihoods across the continent. He further reiterated the value of various European Union (EU) frameworks in providing useful guidance for African countries seeking to develop AI policies that promote both innovation and safety, to ensure that technological developments align with public interest, legal safeguards, and global standards.

The session was underscored by the need for African governments and stakeholders to benchmark global regulatory practices that are grounded in human rights principles for progressive adoption and deployment of AI.  CIPESA pointed out the EU AI Act of 2024, which offers a structured and risk-based model that categorises AI systems according to the level of potential harm and establishes controls for transparency, safety, and non-discrimination.

Key considerations for labour rights, economic justice, and the future of work were highlighted, particularly in relation to the growing role of African data annotators and platform workers within global AI supply chains. Investigations into outsourced data labelling, such as the case of Kenyan workers contracted by tech platforms to train AI models under precarious economic conditions, underlie the need for stronger labour protections and ethical AI sourcing practices. Through platforms such as DataFest Africa, there is a growing community dedicated towards shaping a forward-looking narrative in which AI is not only applied to solve African problems but is also developed, regulated, and critiqued by African actors. The pathway to an inclusive and rights-respecting digital future will rely on working collectively to embed accountability, transparency, and local expertise within emerging AI and data governance frameworks.

Safeguarding African Democracies Against AI-Driven Disinformation

ADRF Impact Series |

As Africa’s digital ecosystems expand, so too do the threats to its democratic spaces. From deepfakes to synthetic media and AI-generated misinformation, electoral processes are increasingly vulnerable to technologically sophisticated manipulation. Against this backdrop, THRAETS, a civic-tech pro-democracy organisation, implemented the Africa Digital Rights Fund (ADRF)-supported project, “Safeguarding African Elections – Mitigating the Risk of AI-Generated Mis/Disinformation to Preserve Democracy.”

The initiative aimed to build digital resilience by equipping citizens, media practitioners, and civic actors with the knowledge and tools to detect and counter disinformation with a focus on that driven by artificial intelligence (AI) during elections across Africa.

At the heart of the project was a multi-pronged strategy to create sustainable solutions, built around three core pillars: public awareness, civic-tech innovation, and community engagement.

The project resulted in innovative civic-tech tools, each of which has the potential to address a unique facets of AI misinformation. These tools include the  Spot the Fakes which is a gamified, interactive quiz that trains users to differentiate between authentic and manipulated content. Designed for accessibility, it became a key entry point for public digital literacy, particularly among youth. Additionally, the foundation for an open-source AI tracking hub was also developed. The “Expose the AI” portal will offer free educational resources to help citizens evaluate digital content and understand the mechanics of generative AI.

A third tool, called “Community Fakes” which is a dynamic crowdsourcing platform for cataloguing and analysing AI-altered media, combined human intelligence and machine learning. Its goal is to support journalists, researchers, and fact-checkers in documenting regional AI disinformation. The inclusion of an API enables external organisations to access verified datasets which is a unique contribution to the study of AI and misinformation in the Global South. However, THRAETS notes that the effectiveness of public-facing tools such as Spot the Fakes and Community Fakes is limited by the wider digital literacy gaps in Africa.

Meanwhile, to demonstrate how disinformation intersects with politics and public discourse, THRAETS documented case studies that contextualised digital manipulation in real time. A standout example is the “Ruto Lies: A Digital Chronicle of Public Discontent”, which analysed over 5,000 tweets related to Kenya’s #RejectTheFinanceBill protests of 2024. The project revealed patterns in coordinated online narratives and disinformation tactics, achieving more than 100,000 impressions. This initiative provided a data-driven foundation for understanding digital mobilisation, narrative distortion, and civic resistance in the age of algorithmic influence.

THRAETS went beyond these tools and embarked upon a capacity building drive through which journalists, technologists, and civic leaders were trained in open-source intelligence (OSINT), fact-checking, and digital security.

In October 2024, Thraets partnered with eLab Research to conduct an intensive online training program for 10 Tunisian journalists ahead of their national elections. The sessions focused on equipping the participants with tools to identify and counter-tactics used to sway public opinion, such as detecting cheap fakes and deepfakes. Journalists were provided with hands-on experience through an engaging fake content identification quiz/game. The training provided journalists with the tools to identify and combat these threats, and this helped them prepare for election coverage, but also equipped them to protect democratic processes and maintain public trust in the long run.

This training served as a framework for a training that would take place in August 2025 as part of the Democracy Fellowship, a program funded by USAID and implemented by the African Institute for Investigative Journalism (AIIJ). This training aimed to enhance media capacity to leverage OSINT tools in their reporting.

The THRAETS project enhanced regional collaboration and strengthened local investigative capacity to expose and counter AI-driven manipulation. This project demonstrates the vital role of civic-tech innovation that integrates participation and informed design. As numerous African countries navigate elections, initiatives like THRAETS provide a roadmap for how digital tools can safeguard truth, participation, and democracy.

Find the full project insights report here.

Commentary: Africa’s Endless Struggle for Internet Freedom Is Always in Motion, But Rarely Forward

By Jimmy Kainja |

In September 2025, the Collaboration on International ICT Policy for East and Southern Africa (CIPESA) hosted the 12th edition of the Forum on Internet Freedom in Africa (FIFAfrica) in Windhoek, Namibia. I have attended six of these Forums over the years, with my first being in 2017, when the event was held in Johannesburg, South Africa. I have also contributed to several editions of FIFAfrica’s flagship report, the State of Internet Freedom in Africa and thus through these activities, have been witness to CIPESA’s role in contributing to and shaping the continent’s digital policy conversations.

Each year, FIFAfrica provides a platform for governments, civil society, private sector actors, and researchers to reflect on emerging challenges and opportunities around digital rights and internet governance in Africa. Over time, the Forum has engaged with various themes which have mirrored global technological and policy shifts including internet shutdowns, data privacy and surveillance concerns, digital inclusion, disinformation and more recently, Artificial Intelligence (AI) and Digital Public Infrastructure (DPI). This adaptability demonstrates how FIFAfrica continues to engage with the evolving digital ecosystem and the continent’s responses to emerging digital and internet governance shifts. Yet, beneath this progress lies a paradox: Africa keeps moving on with the latest trends in internet freedom and internet governance concerns, but the foundational problems remain unresolved. 

When FIFAfrica began over a decade ago, Africa’s internet freedom challenges were clear and urgent: limited access, prohibitive data costs, state surveillance, weak legal protections, and rampant censorship. Governments often justified internet restrictions in the name of “national security” or “public order”. The term “fake news” soon emerged as another pretext for silencing critics and regulating online speech. Fast forward to 2025, and while the vocabulary of digital repression has evolved, the logic remains the same. Several African states continue to shut down internet access, particularly during times of public protest and elections, with Ethiopia, Sudan, Senegal, Uganda, and most recently Tanzania being prominent examples. Across the continent, privacy and data protection laws exist on paper but are inconsistently enforced or manipulated to align with political interests.

In essence, Africa has not yet achieved the baseline of internet freedom that would allow citizens to safely express themselves, access information, and participate fully in digital spaces. Instead, the continent’s policy agenda has become increasingly aspirational, focused on AI ethics, big data, and digital transformation, while the fundamental guarantees of access, security, and expression remain precarious.

Moving on Without Fixing the Old

The evolution of FIFAfrica’s agenda, from internet shutdowns to AI governance and digital identity, is both natural and necessary and might signal thought leadership, but it can also obscure the persistence of unresolved injustices. Take, for example, personal data and identity systems, which were popular topics of discussion at FIFAfrica. Across Africa, governments have introduced biometric ID programmes to modernise administration and improve service delivery. Yet, these systems are deeply entangled with long-standing concerns, surveillance, exclusion, and control, issues that FIFAfrica has grappled with since its inception. The technology has changed, but the regulatory dynamics have remained the same.

Similarly, AI ethics and data governance frameworks are now fashionable discussion points. However, how meaningful are these debates in countries where citizens still lack affordable, reliable internet access or where independent journalists risk arrest for their online commentary? Can we genuinely talk about algorithmic bias when freedom of expression itself is under threat? The danger, then, lies in what might be called “thematic displacement”, which is the tendency to move on to emerging global trends without consolidating progress on foundational freedoms. This displacement risks turning digital rights discourse into a treadmill: always in motion but not moving forward.

The persistence of old internet freedom problems is not accidental. It reflects deeper structural continuities in African digital governance and political economy. States continue to see the internet as both a tool of modernisation and a threat to political interests. Digital technologies are embraced for economic growth, service delivery, and image-building, but their democratic potential remains tightly controlled. This is especially true of authoritarian states. This duality produces a familiar pattern: governments invest in connectivity infrastructure while simultaneously tightening control over civic engagement and digital expression. Regulatory authorities are strengthened, but often in ways that expand state power rather than protect citizens’ rights. Surveillance capacities grow, but transparency and accountability shrink. The internet, once hailed as a space of liberation, increasingly mirrors the offline hierarchies of control, privilege, and exclusion.

In this sense, the continuity of control outweighs the rhetoric of freedom. The instruments may change, from content filtering to biometric registration and AI-enabled surveillance, but the underlying power relations remain largely intact.

Towards a More Grounded Internet Freedom Agenda

As FIFAfrica continues to play a role in convening a diverse spectrum of stakeholders with vested interests in a progressive internet freedom landscape in Africa, perhaps the most urgent task is to reconnect Africa’s digital policy discourse to its unresolved foundations. The continent does not need to reject new topics like AI or digital identity, but rather to approach them through the lens of continuity, recognising how they reproduce or intensify older struggles for rights, accountability, and inclusion. An agenda for the next decade of internet freedom in Africa must therefore balance innovation with introspection. It must ask: Who still lacks meaningful access to the internet, and why? How are digital laws being weaponised against journalists and citizens? Who benefits from datafication and AI, and who is being left out or surveilled? How can the African Union and sub-regional bodies ensure genuine enforcement of digital rights commitments?

Africa’s journey with internet freedom mirrors its broader democratic trajectory, marked by aspiration, innovation, and resilience, yet haunted by persistent constraints. The Forum has provided a vital mirror to this journey, reflecting both progress and contradiction. But as the themes evolve, one truth endures: Africa cannot truly move forward without resolving its unfinished struggles for internet freedom. Until access becomes equitable, laws become just, and expression becomes truly free, the continent’s digital future will remain suspended between promise and paradox.

About the author:

Jimmy Kainja is a Senior Lecturer at the University of Malawi and a PhD candidate at the Wits Centre for Journalism, University of the Witwatersrand. He researches media and communications policy, journalism, digital rights, freedom of expression, and the intersection of telecommunications, democracy, and development.