Personal Data Protection and Privacy Act, 2025
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
Commencement not set.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Establish one of the Act's seven lawful bases before processing personal data, whether you are established in The Gambia or process the data of individuals in the country from outside it.
- Collect personal data only for explicit and legitimate purposes, keep it adequate and relevant to those purposes, keep it accurate and up to date, and process it securely.
- Carry out a compatibility assessment before putting personal data to a new purpose, weighing the relationship between the purposes, the context of collection, the nature of the data, the consequences for the data subject and the safeguards in place.
- Use only a processor that provides sufficient guarantees of compliance, govern the engagement by a contract setting out the subject matter, duration, nature and purpose of the processing, and do not engage a sub-processor without the controller's prior written authorisation.
- Where you determine the purposes and means of processing jointly with another controller, specify each party's compliance responsibilities.
- Design your technical and organisational measures to implement the data protection principles, and ensure that by default only the personal data necessary for each specific purpose is processed.
- Maintain a written record of your processing activities, as a controller and as a processor alike.
- Carry out a data protection impact assessment before high-risk processing such as profiling or large-scale surveillance.
- Designate a data protection officer if you are a public authority, or if you engage in large-scale monitoring or large-scale processing of sensitive data.
What it reaches
Obligation class
Consent, Security, DPIA, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Act applies to the processing of personal data by both automated and non-automated means where the data forms part of a filing system, and it asserts extraterritorial jurisdiction over a controller outside The Gambia whose processing relates to individuals within the country. Purely personal or household activities and anonymous data are carved out of that scope.
Personal data must be processed fairly, transparently and lawfully, collected only for explicit and legitimate purposes, kept adequate and relevant to the purpose, kept accurate and up to date, and processed securely so that its integrity and confidentiality are maintained.
The Act establishes seven lawful bases for processing: consent, contract performance, legal obligation, vital interests, public task, legitimate interest, and processing for archiving, public interest, scientific or historical research or statistical purposes under appropriate safeguards.
Secondary use of personal data for a new purpose is permitted only after a compatibility assessment weighing the relationship between the purposes, the context of collection, the nature of the data, the consequences for the data subject and the safeguards in place. Joint controllers must clearly specify their respective compliance responsibilities.
A controller may use only a processor that provides sufficient guarantees of compliance, the relationship must be governed by a contract setting out the subject matter, duration, nature and purpose of the processing, and a processor may not engage a sub-processor without the controller's prior written authorisation.
Technical and organisational measures must be designed to implement the data protection principles and to ensure that, by default, only the personal data necessary for each specific purpose is processed. Both controllers and processors must maintain a written record of processing activities.
A prior data protection impact assessment is required for high-risk processing such as profiling or large-scale surveillance, and designation of a data protection officer is mandatory for public authorities and for organisations engaged in large-scale monitoring or processing of sensitive data. The Gambia has enacted the Personal Data Protection and Privacy Act, 2025.
The Information Commission and the Ministry of Information conducted community sensitisation sessions on the newly enacted Act in November 2025. The review records the Act as enacted and names no date on which it comes into operation, so the day its duties begin to bind is not established.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachprocesses_voiceprocesses_biometrics
Read the law
Tech Hive Advisory Africa's published legal review of the Personal Data Protection and Privacy Act, 2025
the Act's own gazetted text is not reproduced there
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.