The Gambia's Information and Communications Act, 2009 (No. 2 of 2009, assented by the President on 29 May 2009) is the country's telecommunications sector statute, and it carries a genuine security-of-service duty distinct from its own privacy-of-communications and computer-misuse provisions.
Section 140(1) and (2) require an information and communications service provider, an operator or service provider licensed under the Act to provide a public telecommunications network, fixed or mobile telephony, or internet access, to take appropriate technical and organizational measures, jointly with other service providers where necessary, sufficient with regard to best practices and cost to afford a level of security appropriate to the risk its services present.
Section 140(3) to (6) layer a risk-notification duty on top of that safeguard: where a particular risk of a breach of security persists despite the measures taken, or an event reveals a previously unknown risk, the provider must inform its subscribers of the risk, of the protective measures and any available software or encryption technology, and, for a previously unknown risk, of the estimated cost involved, free of charge, without that notice discharging the provider's own obligation to restore the service's normal security level.
The adjacent section 139, requiring the same providers to take technical and organizational measures to block unauthorized interception, storage or monitoring of communications and any related traffic data, is a privacy-of-communications duty and is recorded under this jurisdiction's privacy topic rather than repeated here.
The Act sets no penalty specific to section 140; a violation falls to section 247's general offence for contravening or failing to comply with a provision of the Act, and The Gambia Public Utilities Regulatory Authority (PURA), the Act's designated Authority, may separately apply its own licence sanctions under section 44.
PURA has established a national Computer Security and Incident Response Team, gmCSIRT, to support cyber-awareness, training and incident coordination for government, parastatal and private critical information infrastructure holders, but gmCSIRT's own published material describes a capacity-building program rather than a binding reporting regulation, and no PURA-issued regulation, code of practice or minimum technical standard giving further content to section 140 is confirmed in the primary text.
Part III of the Act's Information Society Issues chapter, Computer Misuse and Cyber Crime (sections 163 to 173), criminalises unauthorized access, interception, modification and denial of access to a computer system and related conduct; because these offences bind the intruder rather than the operator or manufacturer, they belong to this corpus's scraping topic and are not recorded as a security-topic instrument here.
Part VIII of the same chapter regulates certification authorities issuing electronic certificates, and section 217 requires every certification authority to utilize a trustworthy system in performing its services, with section 218(2) requiring notice to affected persons, or action under its own certification practice statement, when an event materially and adversely affects that trustworthy system or the authority's own certificate; a certification-service-provider is a bound party this corpus's activity vocabulary does not yet express, so the duty is named here rather than filed as a coded instrument.
The Personal Data Protection and Privacy Act, 2025's own breach-notification duty to the Information Commission, and the security-of-processing obligations inside that comprehensive regime, are already recorded under this jurisdiction's privacy topic, as is the ECOWAS Supplementary Act A/SA.1/01/10 on Personal Data Protection (2010), which The Gambia has signed.
The Gambia Investment and Export Promotion Agency Act, 2015's Special Investment Certificate and Export Processing Zone License, researched for this jurisdiction's compute topic, condition eligibility on sector, investment size, employment and export share, and name no system or product security criterion.
No enacted Gambian law is confirmed in the primary text setting security requirements a software product or connected device must meet to be placed on the market, and no general reasonable-security or information-security-program statute reaches a business simply because it holds personal or other covered data outside the telecommunications sector section 140 governs.
Whether the Central Bank of The Gambia has issued a cybersecurity or information-technology risk directive binding a licensed bank or mobile-money operator is not confirmed in the primary text; the Bank's own site names Banking Supervision, Mobile Money and Fintech among its regulated areas and lists Guidelines and Directives among its regulatory instruments, but the documents themselves were not located.