Intotal Band’s Legends Night Has the Crowd. Who Gets the Royalties?




.      Image credit: Ecobank Zimbabwe Facebook page

By Dr Blessing Ivan Vava

I had chosen to stay out of the Intotal Band debate. But after Ecobank Legends Night Africa 2.0 at Alex Sports Club in Harare on Saturday, September 26, it's becoming difficult to stay quiet. These young musicians deserve credit for what they have built.

They have attracted Ecobank’s backing and taken Legends Night beyond Zimbabwe’s music to include artists such as Salif Keita and Yondo Sister. In an interview with Tafadzwa Zimoyo for the Sunday Mail, Keita said he had been following Intotal’s work and added: “I love the boys.”

Having talent and running a professional outfit are different things. Plenty of musicians can play familiar songs. Putting together a show of this ambition, finding sponsors and giving audiences a reason to return requires organisation. That is part of Intotal’s achievement.

The programme also included Tanga WekwaSando, Alick Macheso and Leonard Zhakata. This creates room for established musicians and younger performers to work together.

I support the concept. I also understand why musicians and their families want to know what they earn when those songs fill venues. The success of Legends Night makes that question more pressing.

Some of this music can find its way back into people’s lives through these shows. An am2k hears a song, asks who sang it first and looks for the recording. Someone older returns to an album they have not played for years. We still need figures to establish whether that interest has increased streams of the original recordings. The opportunity is there.

UB40 built much of its international appeal through interpretations of existing songs, alongside its original material. “Red Red Wine” was written and recorded by Neil Diamond before becoming one of UB40’s signature recordings. The band’s Labour of Love album showed how covers could reach fresh audiences and establish a band’s own identity.

The late country singer and songwriter Dolly Parton understood the financial value of a successful cover. Responding to people who associated “I Will Always Love You” with Whitney Houston, she joked: “That’s fine, she can have the credit, I just want my cash.” Houston’s recording reportedly earned Parton about US$10 million in songwriting royalties during the 1990s.

I would like Zimbabwean songwriters to have that confidence when someone performs their work. They need to know that permission has been obtained and that the money due to them will arrive.

Performing someone else’s song is lawful when the necessary permissions are in place, and their conditions are met. Recording a cover can also be lawful, although recording, distributing and uploading it involve additional rights. Permission for a concert does not automatically extend to every subsequent use of its recording.

The US$150 receipt mentioned in this debate was being cited as evidence that Intotal had a ZIMURA licence. Producer Clive “Mono” Mukundu had defended the band as licensed. In its September 9 statement, ZIMURA said the receipt related to a licence for one event on one day, not continuing permission for later shows. It also said it had received no royalties from the Ecobank Legends Night tours. ZIMURA’s account needs to be checked against the actual licences and payment records.

Online earnings are not automatic either. YouTube allows revenue sharing on eligible covers claimed by music publishers, but uploading a performance does not guarantee that all its proceeds reach the composer. The rights and payment arrangements still matter.

Before we can follow the money, though, we have to establish who owns what.

The musician whose voice we recognise may not own the original recording. A label may control the master recording, while the songwriter or publisher controls the composition. Ownership of the recording does not, by itself, give a company control over a band’s entirely live interpretation of the song.

That means looking again at the contracts behind Zimbabwe’s older recordings, and at how companies such as Gramma Records, Zimbabwe Music Corporation (ZMC) and Records and Tape Promotions (RTP) operated. Gramma recorded Leonard Dembo, System Tazvida and Biggie Tembo, the three musicians whose families have now spoken out, while ZMC recorded Oliver Mtukudzi, Leonard Zhakata and Lovemore Majaivana.

I have heard of musicians being recorded without paying for studio time. For a musician without money, an offer of studio time and distribution could be difficult to turn down. But being recorded without paying upfront was not necessarily a free service. Depending on the agreement, a company could recover its costs from royalties or obtain ownership of the recording. Payment disputes did not end there. In 2017, Alick Macheso sued Gramma Records for US$15,863 in royalties he alleged were unpaid between March 2009 and September 2014. We need the agreements to know what each musician retained.

Questions about recording costs and ownership also reach into the urban grooves years. In the early 2000s, producers such as Delani Makhalima and Take 5 (Tatenda Jenami), and labels such as Galaxy Records, gave young artists access to recording opportunities. In The Chamhembe Story, SoProfound’s documentary series on the era, Take 5 defends the financial arrangements, pointing to the studio, electricity and distribution costs. Artists brought their music and recorded without paying upfront. Makhalima has described how one act’s earnings paid for the next: “Roy and Royce’s money was used to finance Plaxedes, Plaxedes’ money was used to finance Shame and Nathan…” That model helped launch careers. But the agreements still matter: what costs could be recovered, how was income shared, and who owned the recordings?

In 2016, Leonard Zhakata questioned the proposed sale of Gramma Records, Zimbabwe Music Corporation and Ngaavongwe Records without consultation with musicians. He also complained about unpaid royalties.

Who controls those catalogues now, and for how long? Renewed interest in an old recording may bring in money without substantially improving a family’s circumstances. That interest alone will not change the terms under which those families are paid.

Solomon Linda’s story shows how far apart a song’s success and a family’s fortunes can be. His “Mbube” became the basis of “The Lion Sleeps Tonight”, which found international fame while his family struggled financially. A 2006 settlement secured payments for past uses, future royalties and recognition of Linda’s contribution, with a trust to administer his heirs’ interests. That outcome required legal action and negotiation.

Closer to home, Leonard Dembo’s son, Tendai, and the widows of Biggie Tembo and System Tazvida have also raised objections. Tazvida’s widow, Babra Mabuyaye, described struggling financially while others benefited from performances of her husband’s music.

Telling such families that the music keeps a legacy alive is hardly enough. They can appreciate its popularity and still ask why they are not benefiting.

ZIMURA must be transparent in its dealings and accountable to the musicians it represents. It should disclose what it collects, what it deducts, how royalties are allocated and when payments are made. Where money remains unpaid, musicians and their beneficiaries deserve clear explanations and a way to challenge errors. Collecting royalties carries a responsibility to account for every dollar.

That accountability must extend to how ZIMURA’s secretariat treats musicians. Questions about royalties deserve clear, respectful answers, not defensiveness or condescension. The secretariat should not behave like overzealous high school prefects: musicians are asking about their earnings, not seeking permission to leave the classroom. It serves the people whose rights it administers and must answer to them.

Labels and publishers must account for the income they handle too. Missing payments can also arise from incomplete records, unresolved estate documents or failures to license performances. Families still deserve to be told what has gone wrong and how it will be put right.

Britain’s PRS for Music matches concert setlists to registered works to allocate royalties. Australia and New Zealand’s APRA AMCOS requires performance reports that include covers, with promoters submitting setlists for promoter-organised events.

South Africa’s SAMRO publishes distribution schedules and provides an unclaimed-royalties search facility. Musicians should be able to find out when payment is expected and how to pursue money that has not reached them.

Intotal should now sit down with musicians and their families, explain its licensing arrangements and submit complete setlists. Recordings and uploads need separate clearance where required. Agreements with estates and collaborations with living legends could help more people benefit. The band should credit songwriters and direct listeners to authorised recordings. Covers are a legitimate business. The audience Intotal has built gives it a platform to introduce its own compositions and develop a catalogue from which it can earn in its own right.

This deserves a national conversation. The government and the National Arts Council of Zimbabwe (NACZ) should bring the parties together to clarify licensing responsibilities and identify where policy or legislation needs to change. NACZ and musicians’ associations could arrange practical copyright education in local languages and help artists and estates obtain legal advice.

Musicians need support to understand their contracts and keep ownership and beneficiary records current. Promoters, venues and bands should agree who obtains each licence before a show. Sponsors can require evidence of licensing and performance reporting as a condition of support.

I would rather see this debate lead to an open conversation than a lasting feud among musicians. The grievances need answers. Intotal has demonstrated what can be done with music that people still love.

Let the young musicians play, with the proper permissions. Let a new generation discover the songs. And make sure that celebrating our legends includes paying the people entitled to benefit from their work. Ends


Dr Blessing Ivan Vava is a Zimbabwean researcher, political analyst and civic leader with more than 15 years' experience in civil society and regional advocacy. He is Executive Director of the Southern Africa Coalition for Democracy and Accountability (SACDA) and previously wrote the Drumbeat column in The Standard. He holds a Doctor of Literature and Philosophy in Communication Studies from the University of Johannesburg, and his work examines democracy, governance, digital politics and Southern African affairs. He publishes The Thursday Briefing.


3

Mnangagwa’s Meeting with Google’s James Manyika Must Deliver for Zimbabwe


By Dr Blessing Ivan Vava

I was pleased to see reports of President Emmerson Mnangagwa’s meeting with Google executive James Manyika in New York on the sidelines of the 81st Session of the United Nations General Assembly. There is something satisfying about seeing a Zimbabwean who began his university education here help shape the future of technology. But I also wondered what would happen once the delegation returned home.

According to TechnoMag’s report, ICT, Postal and Courier Services Minister Tatenda Mavetera and Chief Secretary to the President and Cabinet Dr Martin Rushwaya also attended. The reports describe exploratory discussions about AI training, access to Google’s scholarship programmes and possible cooperation around a proposed technology park. They give no details of a concluded investment agreement or delivery timetable. Mnangagwa and the officials involved now have an opportunity to turn the conversation into something Zimbabweans can benefit from.

TechnoMag also reports that Zimbabwe’s National AI Strategy was launched in March this year, to help the country move towards a knowledge-based economy. That gives the Google discussions a policy framework to work within. The government should explain which parts of that strategy this cooperation could help put into practice.

I would like to see this engagement encourage a more serious commitment to technology and innovation in our own economy. Government needs to fund research, while banks and established businesses should look more closely at local technology enterprises. We cannot expect an overseas partner to carry ambitions we are unwilling to fund ourselves.

The potential extends well beyond the technology sector. A small manufacturer could avoid costly interruptions by using systems that detect equipment faults early. Timely information about crop disease could help a farmer protect a harvest. Better management of stock and deliveries can save a business money, leaving more to invest in its growth.

Zimbabwean developers and researchers could earn a living solving such problems. Some of their products might find customers elsewhere in the region, bringing in export income and supporting skilled employment at home. Getting a promising idea that far, however, takes money and time. Young firms need investors prepared to support development and testing before sales begin to cover the costs.

Manyika’s involvement also makes me think about the students following him through our universities today. A young researcher may have an idea she cannot test because her department lacks the computing resources. A university partnership could give her access to the computing resources and experienced collaborators she needs. That is the sort of opportunity I hope officials have in mind when they speak about cooperation.

We could also make better use of Zimbabwean expertise abroad. A software engineer based overseas could mentor a university team developing a product for local businesses, reviewing its work online over several months. A researcher could jointly supervise a postgraduate student and help arrange access to specialist facilities. People do not have to return permanently to contribute, but our universities need the resources and arrangements to sustain that collaboration.

Land has reportedly been secured for the proposed technology park. I would now want to hear from the researchers and businesses expected to use it. Dependable electricity and affordable internet will matter every day, as will equipment and competent management. The plans must explain how those services will be paid for once the buildings are occupied.

There is also the question of customers. Government could support local innovation through fair, transparent procurement that gives Zimbabwean companies a reasonable chance of competing for public contracts. A first serious contract, followed by payment on time, may do more for a young business than another entrepreneurship workshop.

A local authority, for instance, could commission a Zimbabwean company to develop a system through which residents track water faults, and the council records repairs. Starting with a small, paid pilot would allow both sides to establish whether it works before expanding it. The company would gain experience and a reference customer, while residents would have a way to see what happened to their reports.

In agriculture, a farmer in Gokwe could send a photograph of damaged maize leaves to a locally developed service that helps an extension officer identify the problem. Advice delivered in Shona or Ndebele, with an option to receive it through ordinary text messages, could make the service more useful. Its developers would need to work with farmers and agricultural specialists to test whether it gives reliable advice under local conditions.

My research on technology and development has made me attentive to what a partnership leaves behind. I would want our institutions to gain the expertise to maintain and adapt the systems they adopt. They also need to understand the continuing costs, the rules governing data use and their options if they decide to change providers. Those details will affect how much control they retain over their own work.

Having participated in the meeting, Mavetera should ensure that her ministry follows up on these discussions and brings universities and local technology companies into the process. The ministry should explain which proposals can proceed, who will carry them forward and when Zimbabweans can expect to benefit. Where scholarships or training opportunities become available, the application details should be public and easy to find. People should not need a connection in government to hear about them.

Mnangagwa should give that work sustained attention and ensure that the officials responsible have the resources to carry it through. I would be pleased to return to this story in a year and find that a student’s research had received support or a local developer had secured a contract through the engagement. That would give Zimbabweans a reason to remember the meeting long after the photograph has stopped circulating. ENDS

Dr Blessing Ivan Vava is a Zimbabwean researcher and civic leader whose work examines technology, power and development in Africa. He holds a doctorate in Communication Studies from the University of Johannesburg, where his research explored Chinese ICT investment in Zimbabwe. He writes The Thursday Briefing on democracy, digital sovereignty and technology governance.


The ThursdayBriefing: The Raw Material May Be Us: Africa, Health Data and the New Scramble for Digital Sovereignty

      A health worker uses a tablet during a patient consultation in Zimbabwe. As medical records move online, who controls the              information patients leave behind? Photo: Zimbabwe Ministry of Health and Child Care

By Dr Blessing Ivan Vava

Health data is deeply personal. It records illnesses I have suffered, medicines I take, tests I have undergone, my blood type and perhaps even my genetic characteristics. Increasingly, it can also reveal patterns from which algorithms make predictions about my health. In other words, my health data does not simply record what has happened to my body. It can be used to anticipate what might happen next.

Governments understand the value of such information, sometimes in extraordinary ways. In 2022, Paris Match reported that Vladimir Putin's security officers collected his urine and excrement during some foreign trips and carried it back to Russia, apparently to prevent foreign intelligence services from analysing his biological waste for clues about his health. The claim has never been officially confirmed, but the security logic behind it is revealing.

I remember similar talk in Harare when Chinese President Xi Jinping visited Zimbabwe in December 2015. Stories circulated that his delegation had brought his own toilet, and that his bodily waste would not be left behind. I cannot verify those claims, and they should be treated as the kind of security folklore that often surrounds powerful leaders. But viewed alongside what has since been reported about the extraordinary precautions states take to protect the biological traces of their leaders, the story no longer sounds quite as eccentric as it did then.

Other leaders take precautions against leaving biological traces abroad. Reporting on the elaborate preparations surrounding meetings between American and Chinese presidents, including Xi Jinping, has described measures intended to prevent inadvertent DNA leaks through objects used by leaders. After Kim Jong Un met Putin in Beijing in 2025, North Korean officials were filmed wiping his chair and table and removing his drinking glass. Kim has also been reported to travel with his own toilet.

There is a serious point beneath these unusual rituals. Powerful states understand that biological material is information. A drinking glass, a strand of hair, saliva, blood, urine or human waste can reveal things about a person they may never have intended to disclose.

If governments go to such lengths to protect the biological traces of one leader, what should African states make of agreements potentially involving health information and biological material belonging to millions of their citizens?

Hospitals across Africa are digitising patient records. Laboratories are producing genomic and pathogen data. Governments are building electronic health systems, while artificial intelligence is moving into diagnostics, epidemiology and pharmaceutical research. Information that once sat in a doctor's file is entering systems capable of storing, combining and analysing it at enormous scale.

So who ultimately controls Africa's health data?

When health assistance meets sovereignty

In 2026, several African governments pushed back against proposed bilateral health arrangements with the United States over provisions dealing with health data, biological specimens, privacy and sovereignty.

Zimbabwe declined to proceed with its proposed arrangement. Ghana rejected a proposed agreement after its authorities raised concerns about access to sensitive health information. Ghana's Data Protection Commission said the contemplated access went beyond ordinary health statistics and could extend to datasets, metadata, dashboards, reporting tools, data models and data dictionaries.

Namibia also rejected proposed arrangements involving health data and biological specimens. Zambia raised objections to data-sharing provisions during negotiations. Kenya took a different route: it signed an agreement, but its implementation faced a legal challenge over privacy, transparency, data protection and foreign access to sensitive health information.

This is not a rejection of international health cooperation. African health systems have benefited enormously from international partnerships, research collaboration and external financing. The dispute is about the terms on which that cooperation takes place.

For decades, debates about foreign assistance centred largely on money: who provides it, how much and under what conditions. In the digital age, data has entered that negotiation. An African country may receive millions of dollars in health assistance, but if an agreement also gives external actors access to valuable datasets, biological samples or analytical systems, we cannot measure the relationship only by what comes in. We must also account for what goes out.

A barrel of oil leaving an African port can be counted. Copper leaving Zambia can be weighed. Lithium leaving Zimbabwe can be valued. Millions of data points can cross borders almost invisibly. Unlike a mineral, they can be copied, combined and reused.

The raw material may be us

Africa knows this story in another form. For generations, the continent exported raw materials while much of the processing, technological development and value creation happened elsewhere. Copper left Zambia, gold left Ghana, diamonds left Zimbabwe and Botswana, oil left Nigeria and Angola.

Now some of the raw material sits inside African bodies, hospitals and databases: medical histories, genomic information, pathogen samples, disease-surveillance data and demographic patterns.

There are precedents worth remembering. In 2010, an international team sequenced the genomes of four elderly San men from Namibia alongside that of Archbishop Desmond Tutu and published the findings in Nature. The Working Group of Indigenous Minorities in Southern Africa later objected that San leadership had not been properly consulted and that the paper used language some San people considered offensive. Communities whose DNA had contributed to new scientific knowledge had little say in how it was subsequently used. Once sequenced, that genetic information could circulate indefinitely.

The Omicron episode exposed a different problem. In November 2021, Dr Sikhulile Moyo and colleagues at the Botswana-Harvard HIV Reference Laboratory detected an unusual pattern of mutations in COVID-19 samples and quickly shared their findings with the world. Within days, Botswana and South Africa faced travel restrictions imposed by some of the countries that had benefited from that scientific openness. Moyo's question at the time was pointed: “Is that how you reward science? By blacklisting countries?”

The data travelled faster than the solidarity.

None of this is an argument against sharing data. Modern medicine depends on scientific cooperation. The concern is what happens afterwards: who participates in the research, who owns the resulting intellectual property, what limits apply to secondary use and whether African institutions share fairly in the benefits.

Otherwise, an old economic relationship risks returning in digital form: Africa supplies the raw material, others develop the industries, and Africa later buys the finished product.

Only this time, the raw material may be us.

When health data feeds the machine

Large and diverse health datasets are becoming increasingly valuable to artificial intelligence. They can contribute to diagnostic systems, pharmaceutical research, epidemiological modelling and precision medicine. African patients could supply data used to develop valuable medical technologies that their hospitals may later be unable to afford or control.

Privacy is only one part of the problem. The larger issue is who has the computing power to turn African data into knowledge, who owns the algorithms and intellectual property produced from it, where those systems are hosted and where the value eventually settles.

Data centres belong in this conversation. Africa needs more of them, but governments do not need to build or own them all. Private investment can expand capacity, improve connectivity, develop technical skills and reduce dependence on offshore hosting.

A server located in Harare, Lusaka or Accra, however, does not automatically create sovereignty. A patient's medical record could be physically stored in Harare while the cloud architecture, software, encryption keys or administrative access remain controlled elsewhere.

Where a server sits is only part of the question; ownership can matter just as much. Legal authority, control of the software and encryption, and the ability of domestic regulators to enforce the rules are equally important. A country can host data within its borders while exercising remarkably little control over it.

Africa needs a mixed system: private investment, African technology companies, international firms operating under enforceable domestic laws, public-private partnerships and public infrastructure for particularly sensitive information.

Data cannot all be treated alike either. A supermarket's customer database is not equivalent to genomic information, medical records, passport databases, electoral systems or national-security information. Sensitive data requires stronger safeguards around hosting, encryption, access, onward transfer and cybersecurity.

Australia offered a live warning this week. Prime Minister Anthony Albanese revealed that an OpenAI agent had gained unauthorised access to the Medicare Statistics Reporting Service portal, a public-facing government site, while researching medical spending in June. OpenAI and the Australian government both stress that no patient records appear to have been reached  but that framing understates the problem. A government database is not meant to be entered without authority; whether the agent reached patient records is beside the point once it crossed that boundary. Who bears responsibility when an AI agent goes rogue, code pursuing a task it was set, then crossing a line nobody authorised? OpenAI took nearly three months to tell the government, and did so by email to a public inbox, raising questions about who was answerable for its agent’s conduct. If that question has no clear answer for a government like Australia’s, African governments negotiating health-data agreements should insist on one before they sign.

The lesson is not to isolate Africa technologically. It is to ensure that dependence does not become surrender of control.

Saying no is not enough

Rejecting unacceptable agreements is one thing. Building credible alternatives is another.

Zimbabwe, Ghana and Namibia can refuse arrangements they consider unacceptable. Zambia can demand different terms. Kenyan citizens can test an agreement through their courts. But refusal means little if countries lack secure cloud infrastructure, domestic data centres, interoperable health systems, research computing facilities and the expertise to run them.

Africa has to build that capacity: universities need to produce data scientists, cybersecurity specialists, health-informatics experts and cloud architects; African technology companies should be developing health systems; governments need reliable digital public infrastructure; and researchers need the computing capacity to work with African datasets instead of merely supplying them to better-resourced institutions elsewhere.

Africa cannot spend the next decade regulating algorithms developed elsewhere without developing the capacity to build some of its own, drawing on African languages, data and epidemiological realities.

Whereas, African ownership alone guarantees nothing. An African-owned database can still be abused. A surveillance system does not become benign because its servers happen to sit in Harare, Lusaka, Nairobi or Accra.

The patient cannot disappear behind claims of national sovereignty. Citizens need enforceable rights over how their information is collected, stored, accessed and reused. Health information must be protected from political surveillance, discrimination and uses unrelated to legitimate healthcare.

Sovereignty should protect the state from external dependence without giving the state unlimited power over its citizens.

Taken together, these cases reveal a geosociotechnopolitical problem: the San genome controversy, the Omicron experience, today's health agreements and the scramble to build African data centres may appear to be separate stories, but they are not. Each turns on the relationship between technology and power — who produces knowledge, where information travels, whose laws follow it, who owns the infrastructure through which it moves, and who is strong enough to set the terms.

Consent given today cannot become a blank cheque for uses nobody contemplated years later. Scientific openness, as the Omicron episode showed, also requires some expectation of reciprocity. And sovereignty on paper means little when governments lack the technical capacity to exercise it.

Africa's health-data question, then, reaches beyond privacy. It concerns the terms on which the continent enters an economy increasingly built on information extracted from human beings.

Africa does not need to retreat from international scientific cooperation. It needs to negotiate from a stronger position. Governments should know what information is leaving their countries, why it is being transferred, how long it will be retained, who can access it and which jurisdiction governs it. Limits on secondary use and onward transfer must be clear. Where African biological samples or datasets contribute to commercially valuable discoveries, benefit-sharing should be part of the agreement. Deals involving sensitive information belonging to millions of citizens deserve proper legal and public scrutiny.

There is also strength in negotiating together. Fifty-four states separately facing global technology companies, pharmaceutical corporations, cloud providers and powerful governments create an obvious imbalance. National sovereignty matters, but so does Africa's collective bargaining power. The African Union should help turn that collective bargaining power into common terms for health-data agreements.

The twentieth century taught Africa what happens when strategic resources leave the continent while processing, knowledge and value creation happen elsewhere. Data presents that old problem in a new form.

Health data deserves particular attention because it comes from us. It records our bodies, illnesses, vulnerabilities and communities. Increasingly, it can feed technologies capable of generating enormous scientific and economic value.

Africa should share health data where doing so saves lives and advances science. But sharing cannot be detached from the terms: the limits placed on its use, the institutions that gain access and whether the people and countries from which it comes participate in the knowledge and value eventually created.

Africa should neither become a digital fortress nor remain a digital mine. It needs the capacity to protect its citizens, negotiate fair partnerships, build infrastructure and turn African data into African knowledge and innovation.

Perhaps those strange precautions surrounding presidential biological traces contain a lesson after all. If powerful states worry that the DNA on a drinking glass, or even the bodily waste of one leader, could reveal strategically valuable information, African governments should think carefully about the value contained in the health information of more than a billion people.

The question is no longer whether that information has value. It is who controls it, what is built from it, and who benefits. Ends//

About the Author

Dr Blessing Ivan Vava is a researcher and civic leader working on democracy, technology and digital sovereignty in Africa. He holds a doctorate in Communication Studies from the University of Johannesburg, where his research examined Chinese ICT investment in Zimbabwe and the intersection of technology, geopolitics and power. He is the founder of the Southern Africa Coalition for Democracy and Accountability (SACDA) and writes The Thursday Briefing, a weekly commentary on politics, technology and governance in Africa.

Elections for Sale? The Angolan Playbook

An influence-for-hire operation in Angola offers a glimpse into how the battle for African elections is moving from the ballot box to the voter’s screen.


By Blessing Ivan Vava

For years, our conversations about the integrity of African elections have centred on the polling station. Could people register and vote freely? Could opposition parties campaign? Were ballot boxes secure? Was counting transparent? Increasingly, though, a large part of the election is happening somewhere you cannot walk into.

These questions still matter, but they no longer tell us the whole story.

A recent investigation by the University of Toronto’s Citizen Lab into BlackCore, an Israeli influence-for-hire company, gives us a glimpse of another electoral battleground.

Citizen Lab uncovered material referring to an “Angolan Government Campaign”, involving training in storytelling, copywriting, traffic management and social-media operations. Researchers found deceptive online personas, AI-generated profile pictures, coordinated amplification and a fabricated news outlet called Agita News. Content was introduced through apparently independent identities and pushed through online communities, with its reach monitored along the way.

There are limits to what has been established. Citizen Lab could not identify the Angolan personnel involved or independently confirm the identities of those who conducted the training. After examining BlackCore’s material and related online infrastructure, however, the researchers assessed it as highly likely that the programme happened as the company described.

With Angola heading towards elections in 2027, that deserves attention. But this is not only an Angolan story. It tells us something about how African elections are changing.

I saw some of this during Zambia’s 2026 elections. I spent considerable time in the country during the pre-election, election-day and post-election periods. The rallies and polling stations mattered, but much of the political contest was happening somewhere else: on people’s phones.

WhatsApp, Facebook and TikTok had become political arenas in their own right. Fake quotations, edited videos, anonymous pages and misleading claims circulated alongside genuine political debate. In one instance, a manipulated video purported to show opposition candidate Brian Mundubile saying he had evidence that the election would be rigged.

We have seen similar tactics elsewhere. Just before Nigeria’s 2023 election, a manipulated audio recording purported to capture opposition figures discussing plans to rig the vote. During South Africa’s 2024 election, AI-generated videos circulated in which Donald Trump appeared to endorse Jacob Zuma’s MKP Party and Joe Biden appeared to threaten sanctions if the ANC won.

Some of this material was not particularly sophisticated. It did not have to be.

What makes the BlackCore revelations more troubling is the organisation behind the messaging. This goes beyond someone creating a fake photograph or forwarding a misleading WhatsApp message. Citizen Lab found evidence of fake identities, an apparently independent news platform and coordinated efforts to spread material through online communities. Generative AI has made this kind of work easier and cheaper.

Political persuasion is nothing new. Governments have communication departments. Political parties employ strategists and candidates advertise. Citizens campaign for causes and politicians they support.

The difficulty comes when we cannot tell who is speaking to us.

We know how to treat a message carrying the logo of a political party. We can also recognise official government communication. It becomes harder when the same political message appears to come from an ordinary citizen, an independent commentator or a news organisation that is not what it claims to be.

This connects with something I have been writing about for some time: Africa’s digital sovereignty.

Much of that debate has focused on infrastructure, data centres, foreign technology companies and where our data eventually ends up. I have argued that these are political questions as much as technological ones. Elections bring another part of the problem into view. The issue is no longer only who controls our data or the infrastructure underneath our digital lives. It is also about the growing power to influence what reaches our screens in the first place.

That power is easy to underestimate. Most people scrolling through Facebook, TikTok or WhatsApp are not thinking about the systems behind what they are seeing. Yet a network of fake accounts can make an argument appear more popular than it is. Repetition can give a fabricated story the appearance of credibility. Algorithms then determine how far some of this material travels.

In an election, attention itself becomes part of the contest. Winning it can mean deciding which issue dominates the day, which allegation refuses to disappear and which political narrative follows voters around on their phones. That is why digital sovereignty must also concern itself with the conditions under which our attention is captured and political opinion is formed.

This creates a problem for election observation.

Our methods were largely developed for a different kind of election. We know how to observe voter registration, rallies, polling stations, counting centres and results forms. An observer can arrive at a polling station in the morning and confirm that the ballot box is empty.

It is much harder to observe everything that happened on the voter’s phone before they arrived there.

That does not mean every misleading post changes a vote, nor should we start blaming technology whenever an election produces a result we do not expect. Voters have agency. Misinformation is also much older than social media. South Africa’s experience showed that an old photograph with a false caption can sometimes do the job just as effectively as an AI-generated video.

What has changed is how quickly this material can be produced and spread, and how difficult it can be to know who is behind it.

Election observation will have to catch up. Observer missions and civil society organisations increasingly need people who understand digital platforms, coordinated networks, AI-generated material and online political advertising. Election management bodies will also have to engage platforms and independent researchers more seriously.

There is a danger here too. Governments can easily use the language of fighting “fake news” to restrict journalism, opposition politics and legitimate criticism. Protecting elections from manipulation cannot become an excuse for governments to decide what citizens are allowed to say or read.

That is why what happened in Angola should concern the rest of the continent.

The important lesson from BlackCore is not simply that false information exists online. We have known that for years. More disturbing is that the tools for creating the appearance of public opinion can now be packaged, outsourced, and sold.

That changes the electoral integrity conversation.

The ballot box still matters. But before a voter reaches it, another political contest may already have been taking place for weeks on the small screen in their hand.

If we watch the ballot but ignore that contest, we may increasingly be observing only half the election.ENDS


About the Author

Dr Blessing Vava is a Zimbabwean researcher, writer and democracy advocate working on elections, digital sovereignty and governance in Southern Africa. He holds a Doctor of Literature and Philosophy (DLitt et Phil) in Communication Studies from the University of Johannesburg. His research examines the intersection of technology, geopolitics and governance in Africa. He writes The ThursdayBriefing, a regular commentary on democracy, technology and politics.



The ThursdayBriefing: The Passport, the Database and the State: Who Controls Digital Zimbabwe?



17 September 2026 (Long Read-11 minutes read)

By Dr Blessing Vava

I recently arrived at Robert Gabriel Mugabe International Airport after a trip to Zambia. Like many other travellers, I went straight to the new self-service passport scanner. Within seconds, the system confirmed who I was.

It was an ordinary transaction, the kind we barely think about. We scan our passports, collect our luggage and leave. We rarely stop to wonder what happens behind the screen.

But this time, I did.

As I walked away, I found myself thinking about that scan: what exactly had the system just read about me, where had that information gone, and who ultimately controlled the infrastructure behind it?

Where did my data go?

What exactly did the system read from my e-passport? What information was retrieved or recorded in Zimbabwe's immigration systems, where is it stored, who secures it, who can access it, and who built the infrastructure through which it travels? Most importantly, does the Government of Zimbabwe possess effective technological control over the digital systems that increasingly know who we are?

These may sound like technical questions for computer scientists and immigration officials. They are not: they are questions of sovereignty.

The passport is no longer just a passport

For generations, the passport was primarily a physical document establishing nationality and identity. The e-passport changes that relationship: an embedded contactless chip digitally stores identity information under International Civil Aviation Organisation standards, including biometric and cryptographic mechanisms used to authenticate the document. Zimbabwe introduced its e-passport programme in January 2022. The benefits are obvious: passports are harder to forge, verification is faster, and border processing more efficient. As someone who travels regularly, I appreciate that convenience.

But convenience creates another reality. The passport has quietly evolved from a booklet we carry in our pockets into an interface with a much larger digital identity infrastructure. And once identity becomes data, we must start asking who controls it.

There is an important distinction. When my Zimbabwean passport was scanned, that did not necessarily mean my entire biometric record was transmitted somewhere. The chip contains information that can be read and authenticated under international standards. But what sits behind the scanner? What database confirms identity, what record is created when someone enters or leaves Zimbabwe, where is it stored, and who administers the systems?

One scan seems insignificant. Millions become a database, and a database becomes an asset.

The same questions arise with Zimbabwe's e-visa system. Applicants enter personal information, passport details and travel information online. The official platform says these details are confidential and stored in 'high-security systems.' Reassuring, yes, but where are those systems and backups, who operates the software, who has privileged administrator access, and who controls the encryption keys?

Who built Zimbabwe's digital identity architecture?

Zimbabwe did not develop every component of its e-passport ecosystem on its own. In 2021, Cabinet announced implementation of the e-passport production project under a Build, Own, Operate and Transfer agreement with the Lithuanian company Garsu Pasaulis. Semlex, a Belgian biometric-identification company, separately lists Zimbabwe's Ministry of Home Affairs among its government references for electronic and biometric passports, national identity cards, visas and civil records.

Foreign technological involvement is not unusual. Governments everywhere buy technology from companies based elsewhere, and Zimbabwe cannot manufacture every chip, server or line of code it needs. Nor does foreign involvement prove that anyone has a secret backdoor into Zimbabwe's databases; such a claim requires evidence. But absence of evidence of unauthorised access is not the same as demonstrating sovereign control.

The important question is whether Zimbabwe possesses the technical capacity to independently verify that nobody who should not have access actually does. That is the sovereignty test.

A server in Harare is not enough

Zimbabwe has invested in government data-centre infrastructure, including the National Data Centre commissioned in Harare in 2021. But the centre itself illustrates the complexity of digital sovereignty. It was completed with assistance from the Chinese government and Chinese firms Inspur Group and Sino-Zimbabwe; at its commissioning, President Emmerson Mnangagwa publicly thanked China for its strategic support and technical expertise in e-government. The government has also signalled plans to upgrade it to Tier 4 standards, announced by ICT minister Tatenda Mavetera at the Computer Society of Zimbabwe Summit in 2025.

There is nothing inherently problematic about that cooperation, and Chinese involvement does not establish that China has access to data stored at the centre. But it sharpens the question this article is asking. What does sovereignty mean when the infrastructure is physically national, while some of the technology, expertise or technical dependencies that helped create it originate elsewhere? Localising data is important; it is not the same thing as possessing the knowledge and capacity to control the systems that hold it.

Those investments matter, but they do not answer where critical passport, e-visa, immigration, national identity and civil-registration databases and backups are hosted, which companies maintain their software and security architecture, or who possesses privileged access.

The public does not need sensitive technical configurations published. But independent institutions must know the answers. Parliament should exercise oversight, the Data Protection Authority should know, and cleared Zimbabwean cybersecurity experts should be capable of auditing critical systems. Sovereignty cannot depend entirely on assurances from those operating the technology.

We often talk about data sovereignty as if the decisive question were simply where the server sits. Geography matters, but it is only the beginning. A database can sit in Harare while depending on software, security updates, expertise or remote administrators located elsewhere. The server may be ours while the knowledge required to operate it belongs to somebody else. That is dependency, and dependency becomes vulnerability when a state cannot independently understand, audit, repair or replace a critical system.

The real test is simple: if the foreign technology provider disappeared tomorrow, could Zimbabwe keep the system running? If not, we need to distinguish between possessing data and possessing sovereignty over data.

This question of dependency also touches a wider debate about what economist Yanis Varoufakis calls technofeudalism: a system in which those who own and control cloud infrastructure, platforms and algorithmic systems acquire extraordinary power over those who depend on them. His thesis is contested, and Zimbabwe's reliance on foreign technology should not simply be labelled technofeudalism. But the concept raises a useful question for African states: what happens when sovereignty remains formally national while some of the technological capabilities through which that sovereignty is exercised are controlled, maintained or understood elsewhere?

Europe is asking the same question

This is not uniquely a Zimbabwean anxiety. Germany's Schleswig-Holstein has been moving its public administration from Microsoft Office towards LibreOffice and developing a Linux-based workplace, explicitly linking the migration to digital sovereignty and reduced technological dependency.

France confronted a more sensitive version in April 2026 when its Health Data Hub selected French provider Scaleway as it transitions away from Microsoft's Azure cloud after concerns about sovereignty and foreign legal jurisdiction over health data. In June, the European Commission presented a Technological Sovereignty Package spanning semiconductors, cloud infrastructure, AI and open source, while its Cloud Sovereignty Framework assesses providers against criteria including strategic control, jurisdiction, data, technology and security.

These are wealthy states with sophisticated cybersecurity institutions and considerable bargaining power, yet they worry about technological dependency. If Europe is asking these questions about software and cloud infrastructure running its governments, why shouldn't Zimbabwe ask them about passports, biometrics, immigration and civil-registration systems?

The lesson is not that African governments should stop using foreign technology. That would be neither realistic nor desirable. What matters is whether they retain capacity, control and choice. Dependence can hide in ordinary arrangements: a ministry using foreign cloud infrastructure or a contractor maintaining a database local officials cannot independently repair. Such arrangements may be legitimate, but the sovereignty question remains: who controls the digital machinery of the state?

African governments should be able to use American, Chinese, European, Indian or other technology without permanent dependence on the provider. A sovereign state should know where critical data resides, who has administrator access, who controls encryption keys, whether systems can be audited and migrated, and whether its own engineers can keep them functioning. Digital sovereignty is partly the ability to walk away.

But changing suppliers is not the same thing as becoming sovereign. Replacing an American platform with a Chinese one, or a Chinese system with a European one, does not create African sovereignty. The objective is to expand Africa's capacity to choose through investment in cybersecurity, data centres, software engineering, open standards, research and indigenous AI, alongside regional standards and shared expertise through bodies such as SADC and the African Union.

The layers of sovereignty

So the question cannot stop at where data is stored. Legal control matters, but so do the infrastructure through which information moves, the software and encryption that govern it, the domestic expertise needed to operate or replace those systems, and increasingly the algorithms capable of turning vast datasets into classifications, predictions and knowledge.

These questions run into one another. Data moves through infrastructure and systems; algorithms can then turn it into knowledge. And knowledge, in the hands of states and powerful companies, is a form of power. That is why this discussion is much bigger than the passport.

Think again about the airport scan. One record of my return from Zambia tells you little; millions of travel records accumulated over years reveal patterns of movement. The same principle extends across identity, telecommunications, finance, health, civil-registration and tax systems: each serves a legitimate purpose, but together they describe a society in extraordinary detail.

AI and sophisticated algorithms can extract knowledge from such datasets at unprecedented scale. The strategic value of data increasingly lies not only in what one database contains, but in what can be learned when datasets are combined. Foreign-designed technology does not automatically mean foreign access, but governments must be able to identify, mitigate and independently audit the risks. Trust is not a cybersecurity architecture.

This is what I describe as geosociotechnopolitics: the interaction between geography, society, technology and political power. Zimbabwe's passport system illustrates it well. It forces us to ask several questions at once: where the data sits; whose identities and movements it represents; who designed, maintains and understands the systems; who has authority to access, transfer or combine the information; and what dependence means when the actors involved possess vastly unequal technological and computational power.

Seen through this lens, the e-passport is no longer merely a travel document. It is part of the infrastructure through which the Zimbabwean citizen increasingly becomes digitally legible.

Zimbabwe has laws. But does it have the capacity?

Zimbabwe is not operating in a legal vacuum. The Cyber and Data Protection Act designates POTRAZ as the Data Protection Authority, regulates personal information and places conditions on transfers of personal information outside Zimbabwe.

But legislation cannot secure a database by itself. A country also needs engineers, cybersecurity specialists, secure infrastructure, encryption, independent auditing, incident-response capability and strong institutional oversight. Legal sovereignty without technological capacity risks becoming sovereignty on paper.

What Zimbabwe should do now

Zimbabwe does not need to disconnect from the world. It needs strategic digital autonomy: the ability to benefit from foreign technology while retaining effective control over critical national systems.

A practical starting point is to identify Zimbabwe's critical sovereign data: passports and biometrics, national identity and civil registration, health, financial and tax information, telecommunications, electoral systems and national-security data.

Government should then conduct a sovereign-data and digital-infrastructure audit. For every critical system it should know where databases and backups are hosted, which companies and subcontractors are involved, who controls encryption keys and privileged access, whether remote administration is possible, what information crosses Zimbabwe's borders, and whether access is independently logged and audited.

Government procurement also needs a sovereignty test. The EU experience shows that providers can be assessed against sovereignty criteria. African governments can develop frameworks suited to their own conditions, nationally and eventually through SADC or the African Union. Critical public technologies need not all be African-made, but they must remain under meaningful African control.

Procurement contracts should also require genuine technology transfer and a credible exit strategy. Zimbabwean engineers should not merely operate somebody else's black box; they should understand the box. Open standards and open-source technologies should be considered where they improve transparency and independence, while vendor lock-in should be treated as a sovereignty risk.

Before signing a contract for critical national digital infrastructure, government should ask one deceptively simple question: if this company disappeared tomorrow, could Zimbabwe independently operate, secure, audit, repair and recover the system? If the answer is no, the problem is bigger than procurement. It is a sovereignty problem.

Who controls the digital Zimbabwean?

When I walked away from immigration at Robert Gabriel Mugabe International Airport, the passport scan had taken only seconds. But the questions stayed with me. We are rapidly digitising the state: passports, visas, borders, civil registries, health systems and financial services. Increasingly, the state encounters us as data. That changes the meaning of sovereignty.

Political independence gave African states authority over their territory and borders. Digital transformation introduces another frontier: who controls the digital representation of the people living within those borders?

There is also a distinctly Zimbabwean way of thinking about this question. In my doctoral work, I return to Nehanda as a symbol of self-determination and to the proposition that Zimbabwe's story is not finished until Nehanda is in it. That idea takes on a new meaning in the digital age. Political independence was ultimately about the right of a people to determine their own affairs. Digital sovereignty carries that unfinished question into another domain: can a society meaningfully determine its own future if the technological systems through which its citizens are identified, governed and increasingly understood remain beyond its effective control?

If Nehanda represented the struggle for political self-determination, the digital age asks what self-determination means when identity, borders and state power increasingly run through code. The question is not whether Zimbabwe should reject foreign technology. It is whether technological modernisation expands our capacity for self-determination or quietly creates new forms of dependence. Seen this way, digital sovereignty is not technological nationalism. It is the digital expression of an older struggle for agency.

Zimbabwe should continue modernising its immigration systems and welcome e-passports, efficient e-gates and digital public services. But technological convenience should never require intellectual complacency.

The next time I place my passport on a scanner, I want to know that behind that simple transaction Zimbabwe possesses the people, institutions, laws, infrastructure and technological knowledge necessary to control it. The most important question is no longer simply whether the technology works, but who ultimately possesses the power behind it.

Where does the data go? Who stores it? Who secures it? Who can access it? Who understands the system? And who possesses the ultimate power to say no?

In the twenty-first century, controlling our borders is no longer enough. 

We must also control the digital infrastructure through which those borders, and the people crossing them, are increasingly understood. ENDS

About the Author

Dr Blessing Vava is a Zimbabwean researcher and civic leader working on democracy, technology and governance in Africa. He holds a DLitt et Phil in Communication Studies from the University of Johannesburg, where his doctoral research produced geosociotechnopolitics, a framework linking geography, society, technology and political power.

He is the founding Executive Director of the Southern Africa Coalition for Democracy and Accountability (SACDA) and writes The Thursday Briefing, a weekly newsletter on politics, technology and sovereignty in Africa. Contact: blessingvava@gmail.com.