Legal:Wikimedia Foundation Country and Territory Protection List
Please note that in the event of any differences in meaning or interpretation between the original English version of this content and a translation, the original English version takes precedence. |
Transparency is a cornerstone of the Wikimedia movement — as such, we care a lot about what data we release and how we release it. In line with our Data Publication Guidelines, our goal is to provide accurate information about our projects without exacerbating the privacy and other safety risks that our communities may face for contributing to our projects.
The Country and Territory Protection List Policy aims to enhance the Wikimedia Foundation's ability to publish information and protect contributors' personal information, while preserving everyone's ability to contribute safely to our projects online, consistent with the Foundation's commitment to upholding Wikimedians' rights to privacy as laid out in its Human Rights Policy. Publishing exact values of high-level, seemingly anonymous statistics exposes contributors to data re-identification or reconstruction risks. To that end, this update of the Country and Territory Protection List Policy takes into account the ability of differential privacy to statistically mask individual contributors and contributions. This update will allow for more flexibility and nuance without compromising the safety of our communities, and will thus allow us to release more data and better meet communities' needs.
Process
The list is maintained by the Global Advocacy team of the Wikimedia Foundation. The team relies on the judgments of respected international human rights NGOs to assess potential risk to Wikimedia users. Every year, Reporters Without Borders produces an annual score for hundreds of countries and territories (based on a review of political, economic, legislative, social, and security factors) that signifies journalistic safety in each place. Similarly, Freedom House produces an annual internet freedom score for nearly 80 countries and territories (based on a questionnaire that evaluates obstacles to access, limits on content, and violations of user rights).
These signals are highly-credible and dynamic, with updates every year provided by panels of subject matter experts. Relying on this independent data allows our own models to iterate and provides every person with access to sensitive data with a built-in set of guidelines around risk minimization. They also give the Wikimedia Foundation a sense of the relative risk of government or other parties' actions against Wikimedia community members for their on-platform behaviors (e.g. editing and reading). Where possible, we average the two scores together and subtract them from 100 to get a composite risk score, where 0 is the least likely and 100 is the most likely to take action against community members for on-platform behavior.[1]
Based on the composite score, we then sort each country or territory into one of four categories:
- 0 to 60 — lower risk: These countries and territories are at lower risk of action being taken against Wikimedia community members for on-platform activities. The Wikimedia Foundation can publish aggregated data about them as long as it is in line with the minimum thresholds set out in the Data Publication Guidelines.
- 60 to 67.5 — medium risk: These countries and territories are at medium risk of action being taken against Wikimedia community members for on-platform activities. The Wikimedia Foundation can publish aggregated data about them only using differential privacy such that any consumer of the data will be (in the worst case) at most 5% more certain about a data subject's presence or absence in the dataset.[2]
- 67.5 to 75 — higher risk: These countries and territories are at higher risk of action being taken against Wikimedia community members for on-platform activities. The Wikimedia Foundation can publish aggregated data about them only using differential privacy such that any consumer of the data will be (in the worst case) at most 2.5% more certain about a data subject's presence or absence in the dataset.[3]
- 75 to 100 — not published: These countries and territories are at the highest risk of action being taken against Wikimedia community members for on-platform activities. For reasons of user and editor safety, the Wikimedia Foundation does not publish aggregated data about them.
Our privacy and human rights experts may manually assign risk categories to countries and territories not sufficiently covered by the independent scores. Additionally, they may occasionally reassign a country or territory manually if there are important factors not incorporated into the independent scores (for instance, Wikimedia-specific factors or developments that occurred after the scores were assigned). In both cases, the country or territory's risk score is manually set to the minimum of the category's score range.
Country and territory protection list designations
In 2026, the country and territory protection list is as follows:
Medium risk
There are eight countries and territories deemed medium risk of action being taken against community members for on-platform activities: Bangladesh, Bhutan, Cambodia, Ethiopia, Honduras, Iraq, Kazakhstan, Laos, and Rwanda.
Higher risk
There are thirteen countries and territories deemed higher risk of action being taken against community members for on-platform activities: Azerbaijan, Bahrain, Djibouti, Egypt, Nicaragua, Pakistan, Palestine, Sudan, Tajikistan, Türkiye, United Arab Emirates, Uzbekistan, and Yemen.
Not published
There are sixteen countries and territories deemed highest risk of action being taken against community members for on-platform activities, and that are, as a result, too risky to publish data about: Afghanistan, Belarus, China, Cuba, Eritrea, Hong Kong, Iran, Macao, Myanmar, North Korea, Russia, Saudi Arabia, Syria, Turkmenistan, Vietnam, and Venezuela.
Full country and territory list
The data below is in the process of being updated as of 20 January 2026.
| Country and territory protection list (full list) | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Usage
The list can be accessed programmatically (for a data pipeline or a data analysis, for example) in two ways:
- The
canonical_data.countriestable in the Data Lake. - The source file hosted on GitLab. The data dictionary is available in the same repository.