Law / Sierra Leone

Sierra Leone

3 of 7 named instruments researched to a stage, across two of the six areas of law we track: 3 in force. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law none researched
  3. Scraping law 1
  4. Cybersecurity law 2
  5. Age gating law none researched
  6. News aggregation law none researched

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Scraping law1 instrument, 1 in force

Research summary (252 words)

Sierra Leone has no scraping-specific statute, so general law governs each dimension separately.

The Cyber Security and Crime Act, 2021 criminalises causing a computer system to perform a function, intentionally and without authorisation, with intent to secure access to a computer system, and defines unauthorised access as either having no entitlement to access at all or exceeding the level of authorisation the person entitled to grant it has consented to, without requiring that a technical security measure be defeated; no reported case has tested whether reading a public, unauthenticated page falls within that definition.

No Sierra Leonean decision addresses the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

The Copyright Act, 2011 (Act No. 8 of 2011) is Sierra Leone's general copyright statute, but its fair-dealing, quotation, and text-and-data-mining provisions could not be confirmed from primary text: both located electronic copies of the Act (WIPO Lex and a legislative archive mirror) extract as corrupted, unreadable text because of a font-encoding fault in the underlying PDF, so no finding is made on Sierra Leone's copyright or database-right posture toward scraping.

Sierra Leone has no comprehensive data-protection statute, so scraping personal data from a public Sierra Leonean website is not subject to a general lawful-basis or purpose-limitation duty; a Data Protection and Right to Access Information Bill remained pending before Parliament as of April 2026.

No Sierra Leonean statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, or assigns legal weight to a robots.txt directive or an AI-training-specific rule.

Computer misuse

Cyber Security and Crime Act, 2021, unauthorised access

Cyber Security and Crime Act, 2021 (Act No. 7 of 2021), s. 33 (Unauthorised Access)official gazetted Act text, Supplement to the Sierra Leone Gazette No. 71 of 25 November 2021, reproduced by SierraLII (Laws.Africa)

In force since 15 November 2021. Binds public and private bodies.

What this law does

Section 33(1) prohibits intentionally and without authorisation causing a computer system to perform a function with intent to secure access to the whole or a part of a computer system or to enable such access to be secured.

Section 33(3) defines unauthorised, for the purposes of this section, by reference to a person who has been authorised to access specific data and, without lawful excuse, causes the system to perform a function other than what was authorised, and section 33(4) confirms that the absence of authority includes a case where general authority exists but a specific type, nature, or method of access does not.

The Act's general interpretation section separately defines unauthorised access as access by a person who is either not entitled to access the computer system, program, or data at all, or who does not have or exceeds the level of authorisation consented to by the person entitled to grant it. Neither definition requires infringing a technical security measure to gain access, though both turn on there being a scope of consented access to exceed.

On conviction, an individual faces a fine of not less than Le 100,000,000 and not more than Le 250,000,000, or imprisonment of not less than 2 years and not exceeding 5 years, or both, and a corporation, partnership, or association faces a fine of not less than Le 500,000,000 and not exceeding Le 1,000,000,000.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (284 words)

Sierra Leone's Cyber Security and Crime Act, 2021 (Act No. 7 of 2021), the same statute already documented in this jurisdiction's scraping-topic file for its unauthorised-access offence, also carries two operator-facing security duties.

Section 53 requires any person or institution operating a computer system or network, public or private, to report a disruptive attack or intrusion to the National Computer Security Incidence Response Team within 7 days, with its own offence and penalty for failing to do so.

Sections 7 and 8 let the President, on the Minister's recommendation, designate specific computer systems, data, or traffic data as Critical National Information Infrastructure and impose minimum security standards and an audit and inspection regime on whatever is designated, though the Act states no penalty for an operator's non-compliance with that regime and no public list of any system actually designated under it was located.

No instrument found here sets security requirements a software product or connected device must meet before being placed on the Sierra Leonean market, and no general reasonable-security baseline statute reaches a business simply because it holds covered information; the Electronic Transactions Act, 2018 duty to disclose security procedures to a consumer, documented in this jurisdiction's privacy-topic file, is a transparency duty rather than a security standard.

A Bank of Sierra Leone cybersecurity or IT-risk directive for licensed financial institutions and a National Communications Authority network-security regulation for licensed telecommunications operators may exist but could not be located with the tools available to this research.

Sierra Leone has no comprehensive data-protection statute or breach-notification duty; that absence, and the unconfirmed domestic status of the ECOWAS Supplementary Act on Personal Data Protection, is recorded in this jurisdiction's privacy-topic file rather than repeated here.

Sector security regimes

Cyber Security and Crime Act, 2021, Critical National Information Infrastructure

Cyber Security and Crime Act, 2021 (Act No. 7 of 2021), ss. 7-8 (Critical National Information Infrastructure)official gazetted Act text, Supplement to the Sierra Leone Gazette No. 71 of 25 November 2021, reproduced by SierraLII (Laws.Africa)

In force since 15 November 2021. Binds public and private bodies.

What this law does

Section 7(1) lets the Minister, in consultation with the National Cybersecurity Advisory Council, recommend that the President designate specific computer systems, computer data, or traffic data, or a combination of them, as Critical National Information Infrastructure by an Order published in the Gazette.

The Act's interpretation section defines Critical National Information Infrastructure as computer systems necessary for the continuous delivery of essential services Sierra Leone relies on, whose loss or compromise would have a debilitating impact including on services directly related to communications infrastructure, banking and financial services, public utilities, public transportation, or public-key infrastructure.

Under section 7(2), a Presidential Order made under section 7(1) must prescribe minimum standards, guidelines, rules, or procedures including requiring critical information systems to be secured by default and to log system and user activity for accurate and efficient audits.

Section 8 lets a Presidential Order made under section 7(1) require the National Computer Security Incidence Response Team to audit and inspect any Critical National Information Infrastructure at any time to ensure compliance with the Act. Section 2 establishes that body as the National Computer Security Incidence Response Coordination Centre, headed by the National Cyber Security Coordinator.

What it requires

Vulnerability and incident reporting

Cyber Security and Crime Act, 2021, Reporting of Cyber Security Incidents

Cyber Security and Crime Act, 2021 (Act No. 7 of 2021), s. 53 (Reporting Cyber Threats)official gazetted Act text, Supplement to the Sierra Leone Gazette No. 71 of 25 November 2021, reproduced by SierraLII (Laws.Africa)

In force since 15 November 2021. Binds public and private bodies.

What this law does

Section 53(1) requires a person or institution that operates a computer system or network, whether public or private, to immediately inform the National Computer Security Incidence Response Team of an attack, intrusion, or other disruption liable to hinder the functioning of another computer system or network. Under section 53(2), the Team may propose isolating an affected computer system or network pending resolution of the issue.

Section 53(3) separately makes it an offence to intentionally or without reasonable excuse fail to report such an incident to the Team within 7 days of its occurrence, distinct from any liability for the underlying disruption itself.

On conviction an individual faces a fine of not less than Le 10,000,000 and not more than Le 30,000,000, or imprisonment of not less than 1 year and not exceeding 3 years, or both, and a corporation, partnership, or association faces a fine of not less than Le 50,000,000 and not exceeding Le 100,000,000.

What it requires

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.