Access Now #KeepItOn: Intelligence Source Guide
Access Now’s #KeepItOn coalition maintains the reference count of deliberate internet shutdowns worldwide, coding who ordered each one and what the government said it was for. It treats a shutdown as an accountable political act rather than a network outage.
Access Now’s #KeepItOn coalition maintains the reference count of deliberate internet shutdowns worldwide, coding who ordered each one and what the government said it was for. It treats a shutdown as an accountable political act rather than a network outage.
At a glance
| Source | Access Now #KeepItOn |
|---|---|
| Category | Conflict, Crime & Human Security › Transnational Repression & Digital Rights |
| Homepage | https://www.accessnow.org/ |
| Format | HTML |
| Access | Open — no account required |
| Disciplines | Open Source Intelligence, Social Media Intelligence |
| Mission domains | Transnational Repression |
Internet-shutdown & digital-repression tracking. — as catalogued in the platform’s own source registry.
Access Now is an international digital rights organisation. #KeepItOn is the coalition it convenes — hundreds of civil society organisations across most regions — and the Shutdown Tracker Optimization Project, usually abbreviated STOP, is the coalition's data effort. STOP records incidents in which a government or an actor at a government's direction deliberately disrupted internet or electronic communications for a population or an area. Each incident is coded by country and affected area, start and end date, the technical form of the disruption, the services or platforms affected, the telecommunications providers involved, the event that occasioned it, the justification the authorities gave, the coalition's assessment of the actual cause, and the sources relied on. The output is an annual report with a companion incident dataset published as a spreadsheet, plus continuous advocacy and rapid-response work around live events. What it is not is a measurement platform. STOP does not itself probe networks; it aggregates and adjudicates. The technical evidence comes from measurement projects, network telemetry published by large platforms, and local partners on the ground, and the coalition's contribution is the coding, the corroboration standard and the political attribution that raw measurement cannot supply.
Measurement tells you that traffic from an autonomous system fell to zero. It does not tell you that a minister ordered it, that the order cited an examinations schedule, that three named operators complied and one did not, or that the same province was cut for the same reason in each of the previous two years. STOP is where the network event becomes an accountable act with an actor, a stated rationale and a precedent. That is the analytical job nothing else in this catalogue does. For a country-risk analyst it converts connectivity into a governance indicator: a state that shuts down networks during elections has told you something about how it intends to manage the next one. For an investigator it provides a dated, sourced record that a specific disruption occurred, which is the predicate for everything from litigation to sanctions analysis to establishing why a witness could not communicate on a given day. For a security or continuity planner it is the base rate — the honest answer to whether connectivity in a given country during a given kind of event is a reasonable assumption. And because the coalition codes the stated justification separately from its own assessment of the cause, the dataset supports analysis of state narrative as well as state behaviour, which is a distinct and underused capability.
Who publishes it, and why that matters
Access Now is a non-profit funded by philanthropic foundations and democracy-support grants, and #KeepItOn is an advocacy coalition with an explicit normative position: shutdowns are a human rights violation and should stop. You should factor that into how you read the data rather than treating it as a reason to discount it. The advocacy purpose produces genuine strengths — sustained multi-year commitment to a dataset nobody would fund commercially, a large network of local partners who report incidents that no remote measurement would attribute correctly, and unusual transparency about counting rules. It also produces predictable pressures. An organisation whose case rests on the scale of the problem has an incentive toward inclusive counting, and the definition of a shutdown has broadened over the life of the project to encompass platform-level blocking and throttling alongside full blackouts. That broadening is documented and defensible, but it means year-on-year comparisons partly measure definitional drift. Funding dependence on democracy-support grants also means the project's continuity is exposed to shifts in donor policy. Read the methodology note in each annual release; it is where the counting rules are stated and where changes are disclosed.
Provenance is the first question to ask of any dataset and the one most often skipped. Who collects it, what their incentive is, whether they publish a methodology, and whether they correct the record when they get something wrong all bear directly on how much weight a finding drawn from it can carry.
What a record actually contains
The fields you will be working with, what each one means, and whether it is something you can pivot on. Read the meanings carefully — more analysis is wrecked by misreading a field than by failing to find one, and a field that looks like an observation is often an inference.
| Field | Type | What it means | Pivot value |
|---|---|---|---|
country |
string | State in which the disruption occurred. Coded per incident, so a country appears many times in a year, and the annual headline is a count of incidents rather than of countries. | Country risk profiles, cross-referencing against election calendars and conflict datasets. |
area_name |
string | The administrative areas or localities affected, as reported. Subnational shutdowns are the majority in several large countries and the granularity here determines whether you can localise the event at all. | Administrative geography, and correlation with conflict-event locations or protest reporting. |
start_date / end_date |
timestamp | First and last day of the disruption as established from reporting and measurement. End dates are frequently the weakest field: a partial restoration is hard to date and an open-ended shutdown may be coded at the point reporting stopped. | Timeline construction; duration analysis; alignment with political events. |
shutdown_extent |
enum | Whether the disruption was national or confined to specific regions. Distinguishing these is essential because their political logic and their humanitarian impact differ completely. | Separating regime-wide information control from localised counter-insurgency or protest suppression. |
shutdown_type |
enum | The technical form: full network blackout, mobile-internet-only shutdown, broadband disruption, service or platform blocking, or bandwidth throttling. Throttling is the hardest to detect and the most under-counted. | Matching against measurement evidence of the corresponding type, and assessing the sophistication of the controlling authority. |
affected_services |
array | Named platforms or protocols blocked where the disruption was service-based — typically messaging and social platforms. Absence of a service from the list does not mean it was reachable. | Platform transparency reports, measurement project test lists, circumvention-tool usage signals. |
telecom_providers |
array | Operators reported to have implemented the disruption. Partial compliance across operators in the same market is common and analytically significant. | Operator ownership, parent group, autonomous system numbers, and the corporate accountability question of which company complied. |
ordered_by |
string | The authority reported to have issued the instruction, where identifiable — a ministry, regulator, security agency or court. Frequently unknown, because orders are often verbal or unpublished. | Institutional accountability analysis, sanctions and export-control research, litigation targets. |
legal_method |
string | The legal instrument invoked, where one was, such as an emergency power, telecommunications act provision or public order statute. Records whether the state bothered to claim legality at all. | Comparative legal analysis; identifying which statutes are the operative shutdown authority in a jurisdiction. |
official_justification |
string | The reason the authorities gave publicly. Coded as stated, not as believed — examinations, public safety, misinformation, national security are the recurring categories. | State narrative analysis; comparing stated rationale against the coalition's assessed cause. |
actual_cause |
string | The coalition's assessment of what the shutdown was actually responding to, based on partner reporting and context. This is an analytical judgement and should be read as such. | Event correlation with elections, protests, conflict escalation, communal violence or examinations. |
event_trigger |
enum | The categorised occasion — election, protest, conflict, examination, communal violence, information control. The category that makes the dataset comparable across countries. | Cross-tabulation against election calendars and conflict-event datasets to build a predictive prior. |
information_source |
array | The reporting and measurement relied on for the incident, typically a mix of local media, partner organisations and technical measurement projects. | Provenance assessment; going back to the underlying measurement to establish the technical facts independently. |
certainty |
enum | Where recorded, the coalition's confidence that the incident occurred as coded. Incidents corroborated by measurement sit at a different evidentiary level from those resting on a single local report. | Quality gating; excluding weakly evidenced incidents from any quantitative claim you will have to defend. |
Coverage — and what is not in it
Global in ambition, with genuine reach into regions that technical measurement covers poorly, because the coalition's partner network reports incidents that remote probing would miss or misattribute. The series runs annually from the mid-2010s onward and grows each year both because shutdowns increased and because the coalition's detection capacity and definitional scope expanded. Coverage is strongest where a #KeepItOn member organisation is active and where independent media survive; it is weakest in the most closed states, where a shutdown may be complete, uncontested and consequently under-documented. Counting is by incident, not by country or by person affected, so a country that cuts one province forty times in a year produces a far larger number than a country that cuts the entire national network once — a distinction that headline comparisons routinely lose. Update rhythm is bimodal: the authoritative dataset is annual, published with the report early in the following year, while live incidents are documented through advocacy communications, coalition statements and social channels as they happen. For current awareness you are watching the coalition's public communications; for analysis you are working from the annual file. Historical incidents are occasionally revised as better information arrives, so the current release is authoritative over any copy you took previously.
Known blind spots
Absence of evidence here is not evidence of absence. These are the conditions under which Access Now #KeepItOn will not show you something that is nevertheless real:
- Throttling is systematically under-counted because it is hard to detect, hard to distinguish from congestion, and easy for an operator to deny. A country that degrades service instead of cutting it can produce an effective shutdown that barely registers in the incident count.
- The most closed states are the least well documented. Where no independent civil society organisation operates and no journalists report, a shutdown may be total and invisible, so the dataset's country ranking partly measures the presence of people willing and able to report.
- Definitional scope has broadened over the project's life to include platform blocking and throttling alongside full blackouts, which means multi-year trend lines conflate a real increase with an expansion in what is counted.
- Incident counting rewards fragmentation. Repeated short subnational cuts generate high counts while a single prolonged national blackout generates one, so incident totals are a poor proxy for either duration or population affected.
- End dates are weak. Partial restorations, region-by-region reconnection and shutdowns that quietly persist beyond media interest all produce duration figures that are approximate at best and sometimes materially wrong.
- Attribution of the ordering authority is frequently impossible because orders are verbal, unpublished or routed through a regulator that does not acknowledge them, so the ordering-authority field is empty in many of the incidents where accountability matters most.
- Non-state and infrastructure causes are outside scope by design. Cable cuts, power failures, conflict damage to infrastructure and commercial disputes can produce identical user experience and are not shutdowns in this dataset — but they are sometimes deliberate, and the boundary is genuinely difficult.
- The dataset records disruption, not effect. It does not measure how many people lost access, what they could not do, or what harm followed, and analyses that convert incident counts into impact estimates are supplying that step themselves.
- Current-awareness coverage is uneven between annual releases. A shutdown that occurs in a quiet news week in a country with few coalition partners may not surface publicly for weeks, so absence in real time carries little weight.
Write the blind spot into the product. A statement that something “was not observed in Access Now #KeepItOn” is defensible; a statement that it “did not happen” is not, and the difference is what survives cross-examination.
Access, licensing and what you may do with it
Access model: Open — no account required
The annual report and its companion incident data are published openly on the Access Now website with no account, key or negotiation required; the data has generally appeared as a downloadable spreadsheet alongside the narrative report, with the format and hosting varying between years. There is no API and you should not build a pipeline that assumes one. The practical approach is an annual manual retrieval of the report and dataset, archived with the release year and retrieval date, plus a separate monitoring arrangement for live incidents through the coalition's public communications. If your work depends on rapid awareness of shutdowns rather than on the annual record, the correct architecture is to consume measurement sources continuously for detection and use STOP for adjudicated, attributed history. Access Now also operates a digital security helpline for civil society and at-risk users; that is a support service for people in danger, not a research channel, and it should not be contacted for data enquiries.
Licence
The reports and data are published for public use by an organisation whose purpose is to see them used, and reuse with attribution is plainly within the spirit of the project. The specific licence terms have been stated differently across releases and hosting platforms, so check the notice on the file you actually download rather than assuming a Creative Commons grant carries across years. Attribution to Access Now and the #KeepItOn coalition is expected in any published use and is a matter of basic professional practice regardless of licence. Where you intend commercial redistribution — incorporating the incident data into a paid risk product, for example — write and ask; the answer is likely to be accommodating, and an advocacy organisation generally prefers its data circulated correctly to not circulated at all. Do not republish partner attributions or local source identities that the coalition has aggregated or anonymised for protection reasons.
Rate limits and fair use
No API, no quota, and no reason to make repeated automated requests. Retrieve the annual dataset once per release and archive it. If you monitor the organisation's public communications for live incidents, do so at a human cadence and identify yourself in your user agent; scraping an advocacy non-profit's site aggressively achieves nothing that a once-a-year download would not and consumes resources meant for people in danger.
Licensing changes, and it changes without warning. A dataset that was free for research this year may not be free for commercial or evidential use next year. Confirm the current terms before you build a dependency on it, and record the terms you relied on alongside the data — the licence in force at the time of collection is part of the provenance.
Collecting it
How Access Now #KeepItOn is actually pulled, in the order you would set it up. Prefer the bulk or export interface over per-item lookups wherever one exists: it is kinder to the publisher, faster for you, and gives a reproducible snapshot rather than a series of point-in-time answers you cannot reconstruct later.
| Method | Format | Cadence | Notes |
|---|---|---|---|
| Annual report and dataset retrieval | CSV | annually, on publication | The authoritative artefact. Download the report and the incident file together, archive both with the release year, and re-ingest fully rather than diffing, because prior-year incidents are sometimes revised. |
| Live incident monitoring | HTML | continuous | Watch the coalition's public statements and campaign pages for shutdowns in progress. Treat these as preliminary reporting to be reconciled against the annual dataset later. |
| Measurement corroboration pull | JSON | per incident | For any incident that matters to your work, retrieve the independent measurement evidence for the same window and store it alongside the STOP record. The coded incident is the political claim; the measurement is the technical fact. |
| Operator and ASN resolution | JSON | per incident | Resolve the named telecommunications providers to autonomous system numbers and corporate parents so that the incident attaches to network infrastructure rather than to a company name string. |
| Methodology note capture | HTML | annually | Archive the methodology section of each release. Counting rules and definitional scope have changed, and the old note is the only way to interpret an old count correctly. |
Ingesting it into the platform
Every step below is idempotent and cursor-based: interrupt one and it resumes from where it stopped rather than duplicating rows or losing progress. Collection is recorded per source, so a feed that quietly stops publishing shows up as a stale timestamp instead of silently thinning your coverage.
- Register the source with its cadence — Record #KeepItOn in sources.php as an annual bulk artefact with a separate live-monitoring channel, so that analysts see immediately that the authoritative data lags the events by months.
- Import the incident file — Use import.php for the annual spreadsheet rather than treating it as a polled feed in collect.php, and stamp every record with the release year so that revisions between releases are visible as versioned changes rather than silent overwrites.
- Separate stated justification from assessed cause — During ingest.php, keep the official justification and the coalition's assessed cause in distinct fields and never collapse them. The gap between them is one of the most analytically valuable things in the dataset.
- Resolve operators to network entities — Run resolve-asn-abuse.php over the named providers to attach autonomous system numbers and organisational records, so an incident links to asn-profile.php and org-profile.php rather than to a free-text company name.
- Normalise geography — Map country and area names onto the platform's administrative geography so that subnational incidents render correctly in country-dashboard.php and can be joined against conflict-event locations.
- Correlate against political calendars and conflict data — Use correlate.php to align incidents with election dates, protest reporting and conflict escalation, which is what turns a list of outages into a behavioural profile of a state.
- Build the country timeline — Push incidents into timeline.php per country, layered with the measurement evidence retrieved separately, so an analyst can see both the political record and the technical trace on one axis.
- Feed the country risk view — Expose shutdown frequency, extent and trigger mix into country-risk.php as governance indicators, with the caveat about incident-count semantics recorded on the indicator rather than in a footnote nobody reads.
Registered sources and their last-collected state are listed in sources.php, and the scheduled chain that keeps them current is in automation.php.
How it is wrong, and how to tell
Every dataset is wrong in characteristic ways. Knowing which ways is the difference between using a source and being used by one, and it is the part of source evaluation most often skipped because it is the part that takes work.
This is a well-run dataset by an organisation with an interest in the numbers, and both halves of that sentence matter. The corroboration standard is real: incidents are generally supported by a combination of technical measurement and local reporting, and the coalition's partner network gives it evidentiary reach into places where a purely technical detection approach would produce ambiguous results. The coding is consistent enough to support cross-country comparison within a release. Where the dataset is weakest is at the edges of its own definition — throttling, service degradation, partial restoration and the boundary between deliberate disruption and infrastructure failure — and at the edges of its detection capacity, which is a function of civil society presence rather than of state behaviour. The advocacy framing does not appear as fabrication; it appears as definitional generosity and as headline figures chosen for impact. The correct posture is to use the incident-level records, which are sourced and checkable, and to treat the aggregate figures as advocacy communication that you should recompute yourself under a definition you have chosen and can defend. Always retrieve the underlying measurement for any incident that carries weight in your product.
Characteristic false positives
- An infrastructure failure coded as a deliberate disruption. Cable cuts, power outages and conflict damage produce the same user-visible symptom, and in contested environments the distinction rests on reporting that may itself be contested.
- A commercially or technically caused platform outage read as state blocking. A global platform failure during a period of political tension is a classic confusion, and local reporting will describe it as blocking because that is the reasonable inference on the ground.
- Duration inflation from weak end dates. A shutdown coded as lasting weeks may have been substantially restored early, with only some regions or services still affected, which materially overstates both impact and severity.
- Duration deflation from lost visibility. Where reporting stops because the disruption itself prevented reporting, the incident is coded to the last observed day and the real duration is longer.
- Double counting of overlapping incidents. A national blackout that also involves specific platform blocking in some regions can be coded as one incident or several depending on the release's conventions, and totals are not always comparable across years as a result.
- Attribution of the ordering authority from press speculation. Where the field is populated on the basis of a single report naming a ministry, it carries the confidence of that report and no more, which is often not enough to support a corporate accountability or sanctions claim.
- Absence read as connectivity. A country with no incidents in a year may have had none, or may have no coalition partner reporting from it; the dataset cannot distinguish these and neither can you without independent measurement.
- Year-on-year comparisons across a definitional change. An increase driven by newly counting throttling or platform blocking looks identical in a chart to an increase in state behaviour, and the methodology note is the only place the difference is visible.
None of these make the source unusable. They make it a source that requires corroboration before an assertion built on it goes into a product, which is true of every source and admitted by few.
Ageing
Individual incident records are historical facts and do not decay, but three things around them do. The dataset itself is revised: incidents are added, corrected and occasionally reclassified between annual releases, so a copy taken last year is not merely incomplete but potentially wrong on specifics. The operator and network attributions age quickly, because telecommunications markets consolidate, licences transfer and autonomous system allocations change — a shutdown attributed to a company that no longer exists under that name will not resolve correctly two years later. And the analytical inference from the record ages fastest of all: a country's shutdown behaviour under one administration is a weak predictor under another, and the regulatory framework that made a shutdown lawful may have been amended in either direction. A stale usage looks like a risk assessment citing a shutdown pattern from a period that ended with a change of government, or an operator accountability claim resting on a corporate structure that has since been restructured. Re-download the current release rather than relying on your archived copy whenever a specific incident carries weight.
What this source feeds
A source is only worth what it lets you conclude. These are the disciplines that collect through it, the mission domains it serves and the data points it yields — every one is a tag, so you can follow any thread from here into the rest of the library.
Collected by these intelligence disciplines
Serves these mission domains
Yields these data points
How each sector uses Access Now #KeepItOn
The same dataset is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The records are shared — the constraints, thresholds and outputs are not.
🎖 Military and defence
For operations in or around a country with a shutdown record, this dataset is a planning input for communications assumptions and for understanding host-nation information control behaviour. The practical questions it answers are whether commercial connectivity can be relied upon during elections, protests or escalation, which regions have historically been cut, and how quickly service returned. It also indicates the state's technical reach — a government that can throttle selectively is exercising a more capable control apparatus than one that can only order a total blackout, and that distinction speaks to the relationship between the state and its operators. Treat the dataset as strategic context rather than tactical warning; it is annual, retrospective and built for advocacy, and any operational dependency on connectivity should be planned around measurement and redundancy rather than around a historical count.
🕵 National intelligence
The analytical value is as a governance and intent indicator. Shutdown behaviour is one of the more legible expressions of how a state understands its own legitimacy: the trigger mix tells you what the authorities fear, the legal method tells you whether they feel obliged to claim lawfulness, and the operator compliance pattern tells you how tightly the telecommunications sector is held. Because the coalition codes the stated justification separately from the assessed cause, the dataset directly supports narrative analysis — what a government says it is doing versus what it is doing — which is an unusual and useful property. Use it to build a prior on state behaviour during forthcoming political events, and pair it with measurement telemetry for the current picture. The caution is that the source is an advocacy coalition, and any product that carries its aggregate figures should say so and should recompute the numbers under your own definition.
👮 Law enforcement
Law enforcement and prosecutorial use is mostly evidentiary context rather than investigation. A documented shutdown establishes why communications records for a period are absent, why a witness could not report, or why a platform's logs show a discontinuity — all of which are otherwise easy to misread as evasion or as data loss. In transnational repression, corruption and organised crime cases, a shutdown coinciding with an event is frequently material context. The dataset is not itself evidence in the forensic sense: it is a coded secondary record, and where a shutdown matters to a case you should obtain the underlying measurement data and the operator records through proper process. Be alert to the reverse use as well — shutdowns are used to obscure state-perpetrated violence, and an incident coinciding with an alleged atrocity is a documented reason to look harder rather than a gap in the record.
🔍 Private investigation and corporate security
For corporate security, travel risk and continuity work, this is the base rate that tells you whether connectivity in a market is a safe assumption. It answers whether a country cuts networks during elections, whether the cuts are national or regional, and how long they last — which are the operational questions behind communications planning, duty of care and site continuity. It also supports supply-chain and counterparty questions: an operator that has repeatedly implemented shutdowns carries a human rights and reputational exposure that matters in due diligence on telecommunications and infrastructure investments. The limits are that the data is annual and retrospective, that incident counts do not translate into outage probability without work, and that the licence position for commercial deliverables should be checked rather than assumed.
📰 Journalism and OSINT media
For reporting on censorship, elections and protest, STOP supplies the documented record that turns 'the internet was down' into a sourced, dated, attributed claim with a stated official justification you can put to a government. The strongest journalism from this data is comparative and accountability-focused: which operators complied and which did not, which legal instruments are used, and how a state's stated reason has changed across successive shutdowns. Handle the aggregates with care — the headline annual figure is an incident count, not a measure of severity or population affected, and reporting it as 'the worst year ever' without that caveat is a mistake the data will not protect you from. Protect sources rigorously: local partners who report shutdowns are often at risk, and the dataset's aggregation is in part a protective measure that should not be reversed by your reporting.
🌍 NGO, humanitarian and human rights
This is a dataset built by and for the human rights community, and its most direct use is in documentation and advocacy: establishing a pattern of conduct for a UN submission, a litigation filing, a shareholder engagement with a telecommunications operator, or a sanctions designation argument. The trigger and legal-method fields are what make those arguments concrete rather than rhetorical. For operational NGOs, it is also a duty-of-care input — knowing that a region is routinely cut during specific events changes how field communications and check-in procedures are designed. Two obligations follow from using it. Reciprocate: if your organisation observes a shutdown, report it into the coalition, because the dataset's coverage is exactly the sum of people who do. And protect: never publish detail that would identify local reporters, and never let a documentation product become a map of who is watching in a given district.
🎓 University and research
The dataset supports research in internet governance, comparative authoritarianism, development economics and information control, and it is one of the few longitudinal records of a phenomenon that is otherwise studied episodically. Methodologically, the essential care is that the unit of analysis is a coded incident, the coding is done by an advocacy coalition with a stated position, the definition has broadened over time, and detection capacity correlates with civil society presence — all four of which are threats to any quantitative inference and all four of which are documented in the methodology notes. The strongest research designs treat STOP as one measurement of an underlying latent variable and triangulate it with independent network telemetry, which also allows the detection bias itself to be estimated. Cite the release year, archive the file, and read the methodology note for every year in your panel rather than assuming a stable definition.
Playbook: working Access Now #KeepItOn end to end
A repeatable sequence from first pull to finished product. Each phase states what you are trying to establish, not merely what to click — the objective is a defensible chain of reasoning, not a completed checklist.
Phase 1 — Fix the question: detection or accountability
Decide whether you need to know that a network is down now, or that a government cut it and why. Measurement platforms answer the first within minutes; STOP answers the second within months. Building a live monitoring capability on an annual advocacy dataset is the most common way this source is misused, and the failure is silent.
Phase 2 — Read the methodology note for every year you will use
Retrieve the methodology section of each annual release in your window and note the definition of a shutdown, the counting unit and any stated change. If you are building a multi-year series, this step determines whether your trend is measuring state behaviour or definitional drift, and there is no way to recover it later.
Phase 3 — Rebuild the counts under your own definition
Do not inherit the headline figure. Decide whether your analysis counts platform blocking, throttling and subnational incidents, then recompute from the incident records. State your definition wherever the number appears, because a reader comparing your figure to the published one will otherwise assume one of you is wrong.
Phase 4 — Corroborate every load-bearing incident with measurement
For any incident that will carry weight, pull the independent network measurement for the same country, window and networks, and store it with the record. The coded incident tells you what the coalition concluded; the measurement tells you what the network did. Where they disagree, the disagreement is the finding.
Phase 5 — Resolve operators to networks and owners
Convert the named telecommunications providers into autonomous system numbers, licence holders and corporate parents. This is what allows an incident to connect to infrastructure analysis, ownership research and corporate accountability work, and it is the step that turns a country-level fact into a specific one.
Phase 6 — Separate stated justification from assessed cause and analyse the gap
Tabulate what governments said against what the coalition assessed. Recurring mismatches — examinations cited during protests, misinformation cited during elections — are a reliable indicator of a state's information control doctrine and are far more interesting than the raw count.
Phase 7 — Correlate with the political calendar
Align incidents against elections, referendums, anniversaries, examination seasons and conflict escalation. Most shutdowns are not random and the pattern is usually legible within two or three cycles, which is what makes a forward-looking assessment possible at all.
Phase 8 — Characterise the technical capability on display
Distinguish blunt from selective control. A state that blocks a single platform on some operators has different technical means, and different relationships with its industry, than one that can only pull the national link. This is an infrastructure and procurement question as much as a political one, and it points at the equipment and vendors involved.
Phase 9 — Test the negative
Before concluding that a country does not cut its networks, check whether anyone is positioned to report from it. Cross-reference civil society presence, press freedom conditions and measurement coverage. A clean record in a closed state is not evidence of restraint and should never be presented as such.
Phase 10 — Build the country profile and forward assessment
Assemble incidents, measurement traces, operator attributions and political context into a per-country view in country-dashboard.php, then state a forward-looking judgement about the conditions under which connectivity is likely to be disrupted. Express it as conditions and confidence, not as a probability you cannot defend.
Phase 11 — Plan for the disruption you predicted
Where your organisation or its partners operate in an affected country, convert the assessment into a continuity and duty-of-care position: communications redundancy, check-in procedures that survive a blackout, and pre-agreed assumptions about what silence means. An assessment that does not change a procedure has not been operationalised.
Phase 12 — Report back and archive
Document findings in cases.php and reports.php with the release version and your definition recorded, archive the source file, and where your work observed an undocumented incident, report it to the coalition. The dataset's coverage is a collective product and consuming it without contributing degrades it for everyone.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
What to pair it with
No single source carries a finding. These are the datasets that corroborate, extend or contradict this one — and a source that contradicts is worth more than one that agrees, because it is the only thing that will tell you when you are wrong.
| Source | Relationship | What it adds |
|---|---|---|
| OONI | corroborates | Volunteer-run network measurement producing per-test evidence of website and app blocking, with an open data archive. The primary technical corroboration for service-based blocking incidents. |
| IODA | corroborates | Continuous macroscopic outage detection using routing, active probing and background traffic signals. The standard technical evidence for full network blackouts and their timing, at country and network granularity. |
| NetBlocks | corroborates | Rapid public reporting of connectivity disruptions, frequently the first public confirmation of a live shutdown and often cited as a source in the incident records. |
| Cloudflare Radar | corroborates | Traffic-level visibility from a large network operator, useful for confirming the timing and depth of a disruption independently of probe-based measurement. |
| Internet Society Pulse | corroborates | Aggregates shutdown and connectivity signals from multiple measurement sources into a single view, useful for triangulating whether independent methods agree on an event. |
| Freedom on the Net | extends | Annual country assessments of internet freedom covering the legal and regulatory apparatus behind shutdowns, which explains the legal-method field rather than merely recording it. |
| RIPE Atlas | corroborates | Distributed measurement network whose probes and measurement history can establish reachability from specific vantage points during a disruption window. |
| ACLED | extends | Political violence and protest event data, which supplies the ground events that shutdowns respond to and makes trigger analysis empirical rather than impressionistic. |
| OHCHR | extends | United Nations human rights reporting on internet shutdowns, providing the international legal framework against which the practice is assessed. |
Legal, ethical and operational constraints
Using this data is legally straightforward; the sensitivities are ethical and operational. The records concern state conduct rather than individuals, so data protection exposure is minimal, though incident sources and partner attributions can identify people who reported at risk to themselves and must not be re-published or re-identified. Attribution to Access Now and the coalition is expected and, where a licence is stated on the file, binding. The more consequential legal dimension is downstream: shutdown records are used in litigation, UN submissions, sanctions arguments and corporate accountability claims, and a coded incident from an advocacy dataset is a starting point for such a claim rather than proof of it. Where you intend to name a company or an official, obtain and cite the primary evidence — the measurement data, the regulatory order if it exists, the operator's own statements. Finally, be careful about the operational side: in some jurisdictions, publishing analysis that identifies who is measuring or reporting from within the country can place those people in danger, and that risk is not hypothetical in exactly the states that shut down their networks.
Operational security
Retrieving public reports from a digital rights organisation is a low-risk act in most places and a noteworthy one in a few. In states that treat contact with foreign human rights organisations as suspect, network-level observation of repeated access to Access Now's infrastructure — or of an organisation's staff doing so from inside the country — is a real exposure, and the sensible mitigation is to retrieve once, from infrastructure you are content to attribute, and work locally thereafter. If your work involves colleagues or partners inside an affected country, do not have them do the retrieval. Consider also what your outputs reveal: an analysis that maps shutdown reporting coverage is, read from the other direction, a map of civil society reporting capability, and that is precisely the thing a repressive authority would like to have. Aggregate, and do not publish the granular geography of who is watching.
Two rules that hold regardless of jurisdiction. Collection that is lawful is not automatically proportionate, and a dataset assembled for one purpose does not carry consent for another. Where the records concern identifiable people, the question is not only whether you may hold the data but whether holding it serves the purpose you are accountable for.
Is it earning its place?
Sources accumulate. Feeds get added during an incident and are never reviewed again, and a decade later the pipeline is carrying dead weight that nobody dares remove. These are the measures that show whether Access Now #KeepItOn is contributing anything, and they are worth baselining now so the answer is available later.
- Share of incidents in your working set corroborated by at least one independent technical measurement, tracked as the evidentiary floor of anything you publish.
- Number of live shutdowns your monitoring detected before they appeared in coalition communications, as the measure of whether your detection layer is doing real work or merely echoing.
- Proportion of incidents where you resolved the named operators to autonomous systems and corporate owners, which determines whether the data can support accountability analysis at all.
- Frequency with which your recomputed counts diverge from the published headline figures, as a running check that you have understood the counting rules rather than inherited them.
- Forward assessments issued before a political event that were subsequently borne out or falsified, scored honestly, because this is the only real test of whether the historical pattern has predictive value in a given country.
- Count of countries in your area of responsibility where you have verified that reporting capacity exists, so that a clean record can be distinguished from an unobserved one.
- Continuity procedures actually changed as a result of a shutdown assessment, as the measure of whether the analysis reached an operational decision or stopped at a briefing.
Beware of volume. Indicator counts rise easily and say almost nothing. Unique contribution — findings this source produced that no other source in your stack would have — is the measure that matters, and it is usually far lower than anyone expects.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- An incident count is not a severity measure. Forty one-day district cuts and one month-long national blackout are not comparable, and any ranking built on raw incident counts will mislead in a specific and predictable direction.
- Always ask who was in a position to report. The dataset's country coverage is a joint function of state behaviour and civil society presence, and confusing the two produces the reassuring conclusion that the most closed states are the least repressive.
- Keep the stated justification and the assessed cause in separate columns, and analyse the gap deliberately. Governments telegraph their doctrine in what they choose to claim, and that signal is lost the moment you collapse the two fields.
- Throttling deserves more attention than its record suggests. It is the sophisticated state's instrument precisely because it is deniable, under-measured and less politically costly than a blackout, so a low throttling count in a technically capable state is a detection failure rather than a finding.
- Resolve operators before you accuse them. A company name in a spreadsheet is not a corporate entity; licence structures, joint ventures and regional subsidiaries mean the entity that complied may not be the one your due diligence names.
- Distinguish deliberate disruption from infrastructure failure with evidence, not with plausibility. In conflict zones both are common, both look identical to users, and the difference is the entire legal significance of the event.
- Use measurement for detection and this dataset for meaning. Analysts who pick one and try to make it do both job either react late or react to noise, and neither failure is visible from inside the workflow.
- Treat the annual headline figure as a communication rather than a finding. Recompute under a definition you can defend and publish the definition next to the number, every time.
- Remember that a shutdown is often the context for something else. Atrocities, mass arrests and contested elections are frequently accompanied by information control, so an incident should raise your collection priority for the same window rather than close it.
Questions analysts actually ask
Can I use this to detect a shutdown in progress?
Not reliably. The authoritative dataset is annual and retrospective. For live detection use continuous network measurement, and use this source afterwards for attribution, justification and the political record. The coalition's public communications do cover live events, but coverage is uneven and depends on partner presence.
Why does the annual total keep rising?
Three reasons that the number itself cannot distinguish: more shutdowns are occurring, more of them are being detected as the coalition and measurement projects mature, and the definition of what counts has broadened over time. The methodology note in each release is where changes are disclosed, and reading it for every year in your panel is not optional.
Is a platform block the same as a shutdown?
In this dataset it is counted, and in political terms it is often equivalent in effect. But technically and analytically they are different acts requiring different capabilities, and mixing them in a single count obscures the more interesting question of what a state is actually able to do.
How do I tell a deliberate shutdown from a cable cut?
Rarely from a single source. Look for simultaneity across operators, timing that tracks a political event, selective survival of government or banking networks, and any regulatory instrument or operator statement. Where the evidence does not resolve it, say so rather than choosing the more interesting explanation.
Can I use this data in a commercial risk product?
Check the licence notice on the specific release you are using, and if it is unclear, write and ask. Access Now generally wants this data used, but the licence wording has varied and an advocacy organisation is entitled to know when its work is being resold.
What does it mean if a country has no incidents recorded?
Possibly that it does not shut down networks, and possibly that nobody is in a position to report from it. Verify that reporting capacity exists before treating a clean record as a finding, particularly in the most closed states, where a total shutdown may also be a totally undocumented one.
Is the coalition's assessment of the real cause reliable?
It is an analytical judgement by people with local sourcing and a stated normative position, and should be read as such. It is usually well grounded and occasionally the only assessment available. Where it matters to your conclusion, check it against the ground events independently and cite both.
Should my organisation report shutdowns to the coalition?
Yes, if you observe one and it is safe for the people involved. The dataset's coverage is exactly the sum of those who report, and consumers who never contribute are the reason the coverage gaps sit where they do. Coordinate through the coalition's published channels rather than publishing local sourcing yourself.
Does this cover shutdowns imposed by non-state actors?
Largely no. The scope is deliberate disruption by governments or at their direction. Armed groups controlling infrastructure, operator commercial decisions and conflict damage sit outside or at the boundary, which is a real gap in conflict environments where control of the network changes hands.
Standards, formats and interoperability
What this source speaks natively, and what it has to be translated into before a partner can consume it. Work that arrives in a recognised format is easier to defend, easier to hand over and easier to automate against:
- The project's own operational definition of an internet shutdown — an intentional disruption of internet or electronic communications rendering them inaccessible or unusable for a population or location — is the definitional anchor for the field and should be quoted rather than paraphrased.
- International human rights law, and in particular freedom of expression and assembly protections and the necessity and proportionality test, is the normative framework against which incidents are assessed.
- The UN Guiding Principles on Business and Human Rights are the framework under which operator compliance with shutdown orders is evaluated, which is why the telecommunications provider field exists at all.
- Autonomous system numbers and routing data are the technical layer this dataset attaches to; resolving operators to ASNs is what makes incidents interoperable with network intelligence.
- OONI's measurement data formats and IODA's outage signals are the de facto evidentiary standards for corroboration, and storing the corroborating measurement alongside the incident is the professional norm.
- ISO 3166 country and subdivision codes are required for joining incidents to administrative geography; the dataset uses names, and normalisation is an ingest responsibility.
- The platform exports shutdown incidents and derived country indicators in CSV, JSON and JSONL, and the associated network entities in STIX 2.1 and MISP where they carry infrastructure identifiers.
- No part of this record is model-generated in the platform: incidents are ingested as coded by the coalition, and any summary written by Copilot describes records that already exist rather than inventing them.
References
Primary documentation and authoritative references for this source. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- Access Now — Access Now. The organisation itself: reports, campaign material, the digital security helpline and the publication route for the annual shutdown data.
- #KeepItOn — Access Now. The coalition's campaign home, where the annual reports, methodology notes and incident data are published.
- OONI — Open Observatory of Network Interference — OONI. Open measurement data and analysis for website and application blocking. The corroboration layer for service-level censorship claims.
- NetBlocks — NetBlocks. Rapid public reporting on connectivity disruptions, frequently the first independent confirmation of a live event.
- Cloudflare Radar — Cloudflare. Traffic-level views of national and network connectivity from a major operator's vantage point, independent of probe-based measurement.
- Internet Society Pulse — Internet Society. Aggregated shutdown and connectivity signals across measurement sources, useful for checking whether independent methods agree.
- RIPE Atlas — RIPE NCC. Distributed active measurement network, valuable for establishing reachability from specific vantage points during a disruption.
- Freedom on the Net — Freedom House. Annual assessment of internet freedom including the legal and regulatory machinery that shutdown orders are issued under.
- Office of the United Nations High Commissioner for Human Rights — OHCHR. UN human rights reporting on internet shutdowns and the international law framework for assessing them.
- ACLED — Armed Conflict Location & Event Data Project. Protest and political violence event data, the empirical basis for analysing what shutdowns are responding to.
- Measurement Lab — M-Lab. Open network performance measurement data, useful for investigating throttling and degradation that fall short of a blackout.
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this source: it ingests the coalition's coded incidents as dated events, resolves the implementing operators to autonomous systems and corporate owners, keeps the state's stated justification separate from the assessed cause, and pairs each record with the independent network measurement that proves the disruption occurred.. Browse the full source catalogue, or follow any tag above into the rest of the library.