Digital Rights: Concerning trends in INCLO jurisdictions
Takeaways from digital rights experts and enthusiasts gathered for our 2026 annual meeting.
By Timilehin Ojo, Surveillance and Digital Rights Programme Manager
As the need for digital rights advocacy continues to grow, with human rights norms that were once assumed to be broadly accepted now becoming contested, and governments around the world increasingly willing to restrict civic participation for different reasons, it was urgent for digital rights experts and enthusiasts to gather under the INCLO umbrella in April 2026.
The gathering brought together digital rights experts from 13 jurisdictions spanning different legal systems, political contexts, and geographies, including lawyers, advocates, technologists, and researchers. These people work in very different environments, but confront, with remarkable consistency, the same threats.
Continued coordinated attack against encryption
Governments across multiple jurisdictions are pushing for legislation that would require encryption backdoors, mechanisms that give state actors access to encrypted communications. The justifications are familiar and not novel, ranging from child safety, counter-terrorism, and serious crime prevention. The framing is designed to be difficult to argue against, especially in public debate with less skilled members of the public as the judge.
But civil society has been consistent and clear that there is no such thing as a backdoor that only the “right” people can walk through. Weakening encryption weakens it for everyone, for activists, for journalists, for survivors of domestic abuse, for ordinary people whose data flows through systems they will never see. This is not a technical objection. It is a fundamental rights issue.
We also identified that civil society’s ability to challenge encryption backdoors, whether in legislative consultations, regulatory submissions, courtrooms, or public advocacy, depends on a consolidated, evidence-based counter-narrative.
Jurisdiction-by-jurisdiction analysis of backdoor policy proposals exists. But it remains scattered and difficult to deploy at the speed these debates demand. Building that shared foundation is one of our most pressing tasks.
Surveillance technologies are being deployed in the dark
Similar challenges arise in relation to surveillance technologies, where transparency and accountability remain equally elusive.
Across jurisdiction after jurisdiction, police and government agencies are acquiring and using surveillance tools, facial recognition systems, biometric identification, autonomous technologies, networked law enforcement infrastructure, with little transparency and almost no meaningful oversight.
Part of what makes this so difficult to resist is that it is, at its core, a knowledge problem. You cannot challenge what you cannot see. Many civil society organizations do not have a clear picture of which technologies are being procured or deployed in their own countries. And even where that information can be extracted, through access to information requests, procurement disclosures, or litigation, the technical complexity of these systems makes rights-based analysis genuinely difficult without specialised expertise.
International human rights law provides a foundation. But general principles alone may not be sufficient. What is needed are specific, enforceable standards tied to specific technologies that can anchor legal challenges, inform regulatory engagement, and give civil society a common reference point across jurisdictions. Our project, Eyes on the Watchers: Challenging the Rise of Police Facial Recognition is a useful reference on how to address this concern.
AI in policing demands urgent scrutiny
Particular attention was given to the growing use of artificial intelligence in policing. Specifically, within the broader surveillance landscape, artificial intelligence tools deployed for predictive policing and analytics require particular and urgent attention. These systems are already shaping decisions about who is stopped, who is flagged, or who is treated as a risk. Sadly, these systems are shaping decisions often in ways that are opaque, poorly regulated, and that embed and amplify existing patterns of discrimination.
The challenge is layered. Understanding these systems requires technical knowledge that most civil society organizations do not ordinarily possess and is expensive to outsource. Challenging these systems requires legal strategy, communications capacity, and cross-jurisdictional coordination as the issues are highly aligned across board. More concerning is that the pace of procurement and deployment is consistently outrunning the development of any meaningful accountability framework.
This is one of the sharpest edges of the gap between the speed of technological change and the pace of rights protection. The consequences of that gap are not abstract. They are felt by the communities most exposed to these systems, who are also, typically, the communities least positioned to challenge them.
Age verification: child safety or surveillance by another name?
Age verification mandates, that is, laws requiring platforms to verify users’ ages before granting access to certain content, are being introduced across multiple jurisdictions. While they are already being enforced in some jurisdictions, there are legislative proposals already before parliament, in some others there are explicit intentions or interest in introducing such mechanisms. They arrive, almost universally, under the banner of protecting children online.
No serious civil society actor dismisses the importance of child safety. But the policy proposals on the table raise questions that cannot be set aside. These include data collection, questions regarding the processing of such data, the risks of breaches, misuse, government access including repurposing of such data, the safeguards of the data and effect of breach.
These are not hypothetical concerns. They are the predictable structural consequences of poorly designed legislation. And when the same child safety framing is deployed, as it consistently is, to justify both age verification mandates and encryption backdoors, it is worth asking seriously what work that framing is doing, and in whose interests.
What is our response?
What connected every issue we discussed was a shared structural challenge that civil society organizations are too often responding to these threats in isolation, without shared evidence, without common methodologies, without coordinated positions. That fragmentation weakens our collective voice at precisely the moment when coordination matters most.
The threats to digital rights are not isolated incidents. They accumulate, in legislation passed without adequate scrutiny, in technologies deployed without transparency or oversight, in harms experienced by people who never consented to any of it. There is an immediate need to respond to these concerns. It requires joint resistance, evidence bases, enforceable standards, technical capacity, and sustained cross-jurisdictional collaboration.
That is what we are committed to building.









