Law / Gambia

Gambia

10 of 12 named instruments researched to a stage, across four of the six areas of law we track: 4 in force and 6 enacted but not yet in force. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 1
  4. Cybersecurity law 2
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 enacted but not yet in force

Research summary (218 words)

The Gambia's National Assembly passed the Personal Data Protection and Privacy Bill, 2025 during its Third Ordinary Session on 29 September 2025, the country's first comprehensive statute for the processing of personal data, and Tech Hive Advisory Africa's December 2025 legal review describes it as already enacted. The Act designates the Information Commission, the body the Access to Information Act, 2021 established, as its regulatory authority rather than creating a new one.

The Gambia had earlier published a non-binding Data Protection and Privacy Policy and Strategy in 2019, setting out the case for such legislation without itself creating any duty. The government-reported country factsheet on dataprotection.africa records that The Gambia has signed the ECOWAS Supplementary Act on Personal Data Protection (2010), though that instrument's own content is not described here.

The Information and Communications Act, 2009 separately requires an information and communications service provider to take technical and organisational measures to block unauthorized interception, storage, or monitoring of communications it carries, and requires a person who sends unsolicited commercial communications to give the recipient the option to unsubscribe and, on request, the identifying particulars of the source that supplied the recipient's personal information; both are sectoral duties on telecommunications and electronic-commerce actors that predate and sit alongside the 2025 Act rather than a comprehensive regime of their own.

Breach notification

Personal Data Protection and Privacy Act, 2025, personal data breach notification

Personal Data Protection and Privacy Act, 2025, breach notificationTech Hive Advisory Africa's published legal review of the Personal Data Protection and Privacy Act, 2025

Commencement not set. Binds public and private bodies.

What this law does

The Act sets a strict timeline for reporting breaches. A controller must notify the Information Commission within 72 hours of becoming aware of a breach. A controller must also notify affected data subjects without undue delay if there is a high risk to their rights. Concealment of a security breach is a criminal offence carrying a potential two-year prison term. The Gambia has enacted the Personal Data Protection and Privacy Act, 2025.

The Information Commission and the Ministry of Information conducted community sensitisation sessions on the newly enacted Act in November 2025. The review records the Act as enacted and names no date on which it comes into operation, so the day its duties begin to bind is not established.

What it requires

Comprehensive regime

Personal Data Protection and Privacy Act, 2025

Personal Data Protection and Privacy Act, 2025, scope, principles, lawful basis and the obligations of controllers and processorsTech Hive Advisory Africa's published legal review of the Personal Data Protection and Privacy Act, 2025

Commencement not set. Binds public and private bodies.

What this law does

The Act applies to the processing of personal data by both automated and non-automated means where the data forms part of a filing system, and it asserts extraterritorial jurisdiction over a controller outside The Gambia whose processing relates to individuals within the country. Purely personal or household activities and anonymous data are carved out of that scope.

Personal data must be processed fairly, transparently and lawfully, collected only for explicit and legitimate purposes, kept adequate and relevant to the purpose, kept accurate and up to date, and processed securely so that its integrity and confidentiality are maintained.

The Act establishes seven lawful bases for processing: consent, contract performance, legal obligation, vital interests, public task, legitimate interest, and processing for archiving, public interest, scientific or historical research or statistical purposes under appropriate safeguards.

Secondary use of personal data for a new purpose is permitted only after a compatibility assessment weighing the relationship between the purposes, the context of collection, the nature of the data, the consequences for the data subject and the safeguards in place. Joint controllers must clearly specify their respective compliance responsibilities.

A controller may use only a processor that provides sufficient guarantees of compliance, the relationship must be governed by a contract setting out the subject matter, duration, nature and purpose of the processing, and a processor may not engage a sub-processor without the controller's prior written authorisation.

Technical and organisational measures must be designed to implement the data protection principles and to ensure that, by default, only the personal data necessary for each specific purpose is processed. Both controllers and processors must maintain a written record of processing activities.

A prior data protection impact assessment is required for high-risk processing such as profiling or large-scale surveillance, and designation of a data protection officer is mandatory for public authorities and for organisations engaged in large-scale monitoring or processing of sensitive data. The Gambia has enacted the Personal Data Protection and Privacy Act, 2025.

The Information Commission and the Ministry of Information conducted community sensitisation sessions on the newly enacted Act in November 2025. The review records the Act as enacted and names no date on which it comes into operation, so the day its duties begin to bind is not established.

What it requires

Cross border transfer

Personal Data Protection and Privacy Act, 2025, transfer of personal data outside The Gambia

Personal Data Protection and Privacy Act, 2025, transfer of personal data outside The GambiaTech Hive Advisory Africa's published legal review of the Personal Data Protection and Privacy Act, 2025

Commencement not set. Binds public and private bodies.

What this law does

The Act regulates the transfer of personal data to countries or international organisations outside The Gambia so that the level of protection it guarantees is not undermined.

The primary mechanism for transfer is adequacy, where the receiving country or international organisation has a law that provides an appropriate level of protection, and in the absence of such a law transfers may proceed based on appropriate safeguards established through ad hoc or standardised instruments adopted by the Information Commission.

The controller is responsible for assessing whether an appropriate level of protection exists, taking into account the nature of the data, the purpose of the transfer, and the recipient country's legal regime. The controller or processor must document the assessment of the appropriate safeguards or criteria that justify the transfer, and the Commission has a supervisory role in assessing whether the transfer criteria are met.

The Gambia has enacted the Personal Data Protection and Privacy Act, 2025. The Information Commission and the Ministry of Information conducted community sensitisation sessions on the newly enacted Act in November 2025. The review records the Act as enacted and names no date on which it comes into operation, so the day its duties begin to bind is not established.

What it requires

Data subject rights

Personal Data Protection and Privacy Act, 2025, rights of the data subject

Personal Data Protection and Privacy Act, 2025, rights of the data subjectTech Hive Advisory Africa's published legal review of the Personal Data Protection and Privacy Act, 2025

Commencement not set. Binds public and private bodies.

What this law does

A controller must provide a data subject with comprehensive details of its identity, the purposes of the processing, the recipients of the data and the legal basis for the processing, at the time of collection or within a reasonable period where the data was obtained indirectly. A data subject may request confirmation of whether their personal data is being processed and obtain a copy of that data free of charge, along with specific details about the processing activities.

A data subject may demand the correction of inaccurate or incomplete personal data, which obliges the controller to update its records without undue delay. A data subject may request deletion of personal data that is no longer necessary for the original purpose, where consent is withdrawn, or where the processing is unlawful.

A data subject may require processing to be restricted in specific circumstances, such as where the accuracy of the data is contested, so that the data is stored but not further processed until the issue is resolved. A data subject may object to processing at any time based on their particular circumstances, and has an absolute right to object to processing for direct marketing purposes, which the controller must cease immediately upon request.

A data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or significantly affects them. The Gambia has enacted the Personal Data Protection and Privacy Act, 2025. The Information Commission and the Ministry of Information conducted community sensitisation sessions on the newly enacted Act in November 2025.

The review records the Act as enacted and names no date on which it comes into operation, so the day its duties begin to bind is not established.

What it requires

Enforcement supervision

Personal Data Protection and Privacy Act, 2025, the Information Commission, offences and penalties

Personal Data Protection and Privacy Act, 2025, offences, penalties and the Information CommissionTech Hive Advisory Africa's published legal review of the Personal Data Protection and Privacy Act, 2025

Commencement not set. Binds public and private bodies.

What this law does

Rather than creating a new agency from scratch, the Act designates the Information Commission, established under the Access to Information Act, 2021, as the regulatory authority. The Commission is granted independence and extensive powers, including the authority to investigate complaints and conduct separate inquiries, to enter and search premises with warrants, to impose administrative sanctions and monetary fines, and to issue binding enforcement notices.

Its administrative sanctions include corrective warnings, enforcement notices, bans on processing, and financial penalties calculated by the Commission. Unlawful processing of data for financial gain or to cause harm attracts a prison term of up to three years or a fine of not less than 500,000 Dalasis. The sale of personal data carries a penalty of up to five years imprisonment for individuals, while corporate bodies face fines of not less than 1,000,000 Dalasis or 5% of their gross income.

Aggravated offences, such as unlawfully selling data, can result in imprisonment of up to 10 years and fines of not less than 10,000,000 Dalasis for corporations. Obstruction of the Commission's investigation carries up to seven years of imprisonment.

A data subject has the right to lodge complaints and the right to compensation for material or non-material damage suffered as a result of an infringement of the Act, and may authorise a non-profit organisation to lodge complaints or pursue judicial remedies on their behalf. The Gambia has enacted the Personal Data Protection and Privacy Act, 2025. The Information Commission and the Ministry of Information conducted community sensitisation sessions on the newly enacted Act in November 2025.

The review records the Act as enacted and names no date on which it comes into operation, so the day its duties begin to bind is not established.

What it requires

Sensitive categories

Personal Data Protection and Privacy Act, 2025, sensitive personal data and children's data

Personal Data Protection and Privacy Act, 2025, sensitive personal data and children's dataTech Hive Advisory Africa's published legal review of the Personal Data Protection and Privacy Act, 2025

Commencement not set. Binds public and private bodies.

What this law does

The Act imposes a stricter regime for the processing of sensitive personal data, which includes genetic and biometric data and data revealing racial origin, political opinions or health status. Processing such data is generally prohibited unless the controller identifies a lawful basis and also satisfies one of the specific conditions the Act sets out.

Those conditions include explicit consent, obligations in the field of employment and social security, vital interests where the subject is physically incapable of consenting, and reasons of substantial public interest such as public health or national security. A child is a person under the age of 18, and a controller processing a child's data must prioritise the child's best interests and privacy.

Specific safeguards are required for marketing or profiling directed at children, the lawful processing of a child's data generally requires parental or guardian consent, and all information directed at children must be in clear, plain language that they can easily understand. The Gambia has enacted the Personal Data Protection and Privacy Act, 2025. The Information Commission and the Ministry of Information conducted community sensitisation sessions on the newly enacted Act in November 2025.

The review records the Act as enacted and names no date on which it comes into operation, so the day its duties begin to bind is not established.

What it requires

Scraping law1 instrument, 1 in force

Research summary (204 words)

The Gambia's Information and Communications Act, 2009 (No. 2 of 2009) carries a dedicated Computer Misuse and Cyber Crime part reaching unauthorised access to computer data, unauthorised access to and interception of a computer service, unauthorised modification of computer material, damaging or denying access to a computer system, unlawful possession of hacking devices or data, and unauthorised disclosure of a password, each a criminal offence rather than a civil wrong.

The Gambia has no located terms-of-service enforceability doctrine, database right, text-and-data-mining exception, or robots.txt-specific rule; the Copyright Act, 2004's general reproduction and quotation exceptions are a copyright question rather than a computer-misuse one, and a personal-data duty reaching data collected from public sources attaches to the data itself, under the Personal Data Protection and Privacy Act, 2025, rather than to the collection method.

A Cybercrime Bill, 2023 that would add procedural powers, including compelled decryption and interception assistance, and international-cooperation provisions to this regime was tabled at the National Assembly for a first and second reading in March 2024 and referred to the Assembly's Select Committee on ICT and Education, which was still holding consultations per a Ministry retreat reported on 14 May 2024; whether it has since been enacted is not established here.

Computer misuse

Information and Communications Act, 2009, Computer Misuse and Cyber Crime part

Information and Communications Act, 2009 (No. 2 of 2009), Chapter III, Part III (Computer Misuse and Cyber Crime, ss. 163-169)Information and Communications Act

In force since 29 May 2009. Binds public and private bodies.

What this law does

A person who causes a computer system to perform a function knowing that the access is unauthorised commits an offence, unless the person has a right to control the operation or use of the computer system and exercises that right.

Securing access to a computer system for the purpose of obtaining a computer service, or intercepting any function of or data within a computer system, is also an offence unless both the sender and intended recipient of the data have given consent or the actor is exercising a statutory power.

Causing an unauthorised modification of data held in a computer system, or, without lawful authority or excuse, degrading, interrupting, or denying access to a computer system or the data held in it, are each separate offences.

Manufacturing, selling, importing, distributing, or possessing a device or data designed or adapted primarily to commit any of these offences is itself an offence, as is knowingly disclosing a password or access code for wrongful gain, an unlawful purpose, or knowing it is likely to cause prejudice. It is immaterial to any of these offences whether the access or interception was directed at a particular program or data, or at any program or data at all.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (703 words)

The Gambia's Information and Communications Act, 2009 (No. 2 of 2009, assented by the President on 29 May 2009) is the country's telecommunications sector statute, and it carries a genuine security-of-service duty distinct from its own privacy-of-communications and computer-misuse provisions.

Section 140(1) and (2) require an information and communications service provider, an operator or service provider licensed under the Act to provide a public telecommunications network, fixed or mobile telephony, or internet access, to take appropriate technical and organizational measures, jointly with other service providers where necessary, sufficient with regard to best practices and cost to afford a level of security appropriate to the risk its services present.

Section 140(3) to (6) layer a risk-notification duty on top of that safeguard: where a particular risk of a breach of security persists despite the measures taken, or an event reveals a previously unknown risk, the provider must inform its subscribers of the risk, of the protective measures and any available software or encryption technology, and, for a previously unknown risk, of the estimated cost involved, free of charge, without that notice discharging the provider's own obligation to restore the service's normal security level.

The adjacent section 139, requiring the same providers to take technical and organizational measures to block unauthorized interception, storage or monitoring of communications and any related traffic data, is a privacy-of-communications duty and is recorded under this jurisdiction's privacy topic rather than repeated here.

The Act sets no penalty specific to section 140; a violation falls to section 247's general offence for contravening or failing to comply with a provision of the Act, and The Gambia Public Utilities Regulatory Authority (PURA), the Act's designated Authority, may separately apply its own licence sanctions under section 44.

PURA has established a national Computer Security and Incident Response Team, gmCSIRT, to support cyber-awareness, training and incident coordination for government, parastatal and private critical information infrastructure holders, but gmCSIRT's own published material describes a capacity-building program rather than a binding reporting regulation, and no PURA-issued regulation, code of practice or minimum technical standard giving further content to section 140 is confirmed in the primary text.

Part III of the Act's Information Society Issues chapter, Computer Misuse and Cyber Crime (sections 163 to 173), criminalises unauthorized access, interception, modification and denial of access to a computer system and related conduct; because these offences bind the intruder rather than the operator or manufacturer, they belong to this corpus's scraping topic and are not recorded as a security-topic instrument here.

Part VIII of the same chapter regulates certification authorities issuing electronic certificates, and section 217 requires every certification authority to utilize a trustworthy system in performing its services, with section 218(2) requiring notice to affected persons, or action under its own certification practice statement, when an event materially and adversely affects that trustworthy system or the authority's own certificate; a certification-service-provider is a bound party this corpus's activity vocabulary does not yet express, so the duty is named here rather than filed as a coded instrument.

The Personal Data Protection and Privacy Act, 2025's own breach-notification duty to the Information Commission, and the security-of-processing obligations inside that comprehensive regime, are already recorded under this jurisdiction's privacy topic, as is the ECOWAS Supplementary Act A/SA.1/01/10 on Personal Data Protection (2010), which The Gambia has signed.

The Gambia Investment and Export Promotion Agency Act, 2015's Special Investment Certificate and Export Processing Zone License, researched for this jurisdiction's compute topic, condition eligibility on sector, investment size, employment and export share, and name no system or product security criterion.

No enacted Gambian law is confirmed in the primary text setting security requirements a software product or connected device must meet to be placed on the market, and no general reasonable-security or information-security-program statute reaches a business simply because it holds personal or other covered data outside the telecommunications sector section 140 governs.

Whether the Central Bank of The Gambia has issued a cybersecurity or information-technology risk directive binding a licensed bank or mobile-money operator is not confirmed in the primary text; the Bank's own site names Banking Supervision, Mobile Money and Fintech among its regulated areas and lists Guidelines and Directives among its regulatory instruments, but the documents themselves were not located.

Sector security regimes

Information and Communications Act, 2009, security of information and communications services (safeguards duty)

Information and Communications Act, 2009 (No. 2 of 2009), sec. 140(1)-(2)Official Act text, published by the Public Utilities Regulatory Authority (PURA)

In force since 29 May 2009. Binds public and private bodies.

What this law does

Every information and communications service provider must take appropriate technical and organizational measures, jointly with other service providers where necessary, in order to safeguard the security of its services. Those measures must be sufficient, with regard to best practices and the cost of the proposed measures, to afford a level of security appropriate to the risk presented in connection with the services provided.

The Gambia Public Utilities Regulatory Authority is the Authority the Act designates to regulate the provision of information and communications services in The Gambia. The Authority may enforce a licensee's compliance with the terms and conditions of its activities under the Act, including by imposing a fine, ordering disclosure of information, or advising the Minister to suspend or revoke the licence.

A person who contravenes or fails to comply with a provision of the Act for which no other penalty is specified is liable on conviction to a fine of not less than fifty thousand Dalasis or to imprisonment for a term not exceeding three years, or to both, and, in the case of a continuing offence, to a further fine of five hundred Dalasis for every day the offence continues.

What it requires

Vulnerability and incident reporting

Information and Communications Act, 2009, security of information and communications services (subscriber risk notification)

Information and Communications Act, 2009 (No. 2 of 2009), sec. 140(3)-(6)Official Act text, published by the Public Utilities Regulatory Authority (PURA)

In force since 29 May 2009. Binds public and private bodies.

What this law does

Where a particular risk of a breach of the security of the services persists despite the technical and organizational measures taken under section 140(1) and (2), the service provider must inform the subscribers of the risk and of the measures they may take to enhance their level of protection. That information must also indicate any software and encryption technologies available for use by the end-users and subscribers to safeguard the security of their communications.

Where an event affecting or jeopardizing the security of the services occurs and a previously unknown risk of a breach of security appears as a result, the service provider must promptly inform the subscriber of the risk, free of charge, of the measures the subscriber may take to enhance the level of protection, and of the estimated costs involved.

Informing subscribers of a particular security risk does not discharge the service provider from the obligation to take appropriate and immediate measures to restore the normal security level of the service.

The Act sets no penalty specific to this duty, so a violation falls to the general offence under section 247 for contravening or failing to comply with a provision of the Act, a fine of not less than fifty thousand Dalasis or imprisonment for a term not exceeding three years, or both, with a further fine of five hundred Dalasis for every day a continuing offence persists.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (174 words)

The Gambia has no press-publisher neighbouring right, no compelled platform-to-publisher bargaining code, no recognized hot-news misappropriation doctrine distinct from ordinary copyright law, and no machine-readable text-and-data-mining opt-out mechanism; each of those is a sourced absence rather than an unresolved question, and no Gambian court decision on hyperlinking or framed display is reported either.

The relevant instrument is the Copyright Act, 2004, whose section 29 permits the reproduction, in the form of quotation, of a short part of a published work without the authorisation of the author or other owner of copyright, provided the reproduction is compatible with fair practice and does not exceed the extent justified by the purpose. Section 29 names no permitted purposes and no news or press-summary use.

An indication of the source and the name of the author or other owner of copyright, where that name appears in the work quoted, must accompany the quotation. Whether this exception reaches a systematic aggregator's reproduction of headlines and snippets, as opposed to an ordinary quotation, is not established in the Act's text.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.