Ghana's cyber-resilience law sits in the Cybersecurity Act, 2020 (Act 1038), assented to on 29 December 2020, which establishes the Cyber Security Authority (the Authority) and gives it standards-setting, licensing and enforcement powers over private and public actors alike.
Section 47(5) places a general duty on the person in charge of any institution, public or private, with no size or sector gate, to report a cybersecurity incident to the relevant Sectoral or National Computer Emergency Response Team within twenty-four hours of its detection, backed by an administrative penalty under section 47(6); a licensed cybersecurity service provider carries a further periodic operations report under section 47(2).
Section 49 separately requires a person to hold an Authority-issued licence before providing a cybersecurity service, a term the First Schedule defines broadly enough to reach a vendor who designs, sells, imports, exports, installs, maintains, repairs or services a cybersecurity solution, so a company distributing security software for reward in Ghana needs the licence even if it performs none of the Schedule's other listed activities such as penetration testing or incident response.
Section 59 gives the Authority a broader standards mandate, to develop, adopt, publish and enforce cybersecurity standards covering education, hardware and software engineering, governance and risk management and research and development, against the public and private sectors generally, with an administrative penalty for breach; the specific content of an adopted standard is set by the Authority outside the Act's own text, so what a software engineering standard would require of a developer is not stated here.
A narrower duty runs to the owner of a computer system the Minister designates a critical information infrastructure under section 35: a twenty-four-hour incident report, an audit and a copy of the audit report to the Authority under section 39.
That designation is a government act directed at a named system rather than a status a business declares of itself, so it is recorded here rather than raised against a guess, the same treatment this profile gives Singapore's Cybersecurity Act critical information infrastructure owners and South Korea's Act on the Protection of Information and Communications Infrastructure.
Section 40's offence of securing or attempting to secure unauthorised access to a critical information infrastructure, and section 94's separate offence of unlawfully retrieving subscriber information or intercepting traffic or content data, both bind the intruder rather than the operator and stay with the scraping topic's existing Ghana row.
The Electronic Transactions Act, 2008 (Act 772) carries an older, narrower critical-database designation regime of its own (sections 55 to 62) and a licensing regime for a certifying agency issuing digital signatures (sections 28 to 45), whose procedures duty in section 45 binds only a person already licensed as a certifying agency; neither reaches a business by a size, sector or product test broader than that narrow licensed class, so neither is filed here.
The Data Protection Act, 2012 (Act 843) carries its own security measures and security-compromise notification duties at sections 28 to 31, addressed to a data controller and processor as such; that is Ghana's privacy row rather than repeated here, the same architecture as General Data Protection Regulation (GDPR) Article 32.
Whether the Bank of Ghana maintains a binding cybersecurity or technology-risk directive for banks and specialised deposit-taking institutions is not confirmed in the primary text read for this row; in any case a Bank of Ghana-regulated financial institution is a status this corpus's activity vocabulary cannot express, so such a directive would be deferred rather than flagged even once located.
Every fine in Act 1038 is denominated in penalty units under Ghana's general Fines (Penalty Units) Act framework rather than stated as a cedi amount on the face of the Act, and the current cedi value of one penalty unit is not confirmed in the primary text read for this row, so the amounts below are stated in penalty units rather than converted.