World Watch/Ghana/Cybersecurity

Cybersecurity · Ghana

Cybersecurity - Ghana

Comprehensive lawCybersecurity Act, 2020 (Act 1038), administered by the Cyber Security Authority (CSA)

Ghana enacted a standalone, comprehensive cybersecurity law — the Cybersecurity Act, 2020 (Act 1038) — which established the Cyber Security Authority (CSA) as the primary regulator, mandated protection of Critical Information Infrastructure (CII) across 13 designated sectors, and imposed incident-reporting and licensing obligations. The Data Protection Act, 2012 (Act 843) runs in parallel, requiring breach notification to the Data Protection Commission. A Cybersecurity (Amendment) Bill, 2025 was published for public consultation in October 2025 and, as of May 2026, has not yet been enacted by Parliament.

Cybersecurity Act 1038 (2020)

Enacted 29 December 2020, the Act is Ghana's primary cybersecurity statute. It creates the Cyber Security Authority, regulates cybersecurity service providers and practitioners, and provides the legal basis for protecting Critical Information Infrastructure.

Critical Information Infrastructure (CII)

The Minister designated 13 sectors as CII by Gazette Notice No. 132 on 23 September 2021, followed by the launch of the CII Protection Directive on 1 October 2021. CII owners must register systems with the CSA, conduct periodic security audits, and report incidents.

Incident Reporting (24-hour duty)

Act 1038 requires owners of designated CII systems to report cybersecurity incidents to CERT-GH within 24 hours of detection. A dedicated online incident reporting portal is operated by the CSA.

Licensing & Accreditation

Cybersecurity service providers must obtain a licence from the CSA; individual practitioners must be accredited. Cybersecurity products and technology solutions also require CSA certification before deployment.

Data Protection Act 843 (2012) — parallel breach-notification

The Data Protection Act, 2012 (Act 843) requires data controllers to notify the Data Protection Commission and affected individuals as soon as reasonably practicable following a personal-data security breach, complementing the CSA incident-reporting regime.

Cybersecurity Amendment Bill 2025 (pending)

A draft Cybersecurity (Amendment) Bill, 2025 was published by the CSA for public consultation (extended to 14 November 2025). It proposes expanded CSA investigative and enforcement powers, stricter penalties, and explicit parallel breach-notification to the Data Protection Commission. As of May 2026, it has not been passed by Parliament.

Machine-assisted translation · verified 5/24/2026 · orientation, not legal advice. English version →