Cybersecurity Act, Duty to Report Cybersecurity Incident
Cybersecurity Act, 2020 (Act 1038), ss. 47(2) and 47(5)-(6), and Second Schedule item 47(6)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 29 December 2020.
A vulnerability and incident reporting rule binding public and private bodies.
As of 18 September 2026.
What it requires
- This binds the person in charge of any public or private institution in Ghana that detects a cybersecurity incident, not only the owner of a critical information infrastructure or a licensed cybersecurity service provider.
- Report a cybersecurity incident to the relevant Sectoral Computer Emergency Response Team, or to the National Computer Emergency Response Team where the institution has no Sectoral team, within twenty-four hours after the incident is detected.
- Where the institution is itself a cybersecurity service provider licensed by the Authority, also submit a periodic report on its operations, including any cybersecurity incident, within the period the Authority sets.
- Failing to report within the twenty-four-hour window is an administrative penalty of not less than two hundred and fifty penalty units and not more than five thousand penalty units, payable to the Cyber Security Authority.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Failing to report a cybersecurity incident under section 47(5) is enforced only as an administrative penalty under section 47(6) and the Second Schedule; no provision reviewed here makes that failure, standing alone, a criminal offence.
Who enforces it
Enforcement body
The Cyber Security Authority, established under section 2 of the Cybersecurity Act, 2020 (Act 1038).
Settledness
- As of
- 18 September 2026
- Open questions
- Does the twenty-four-hour clock in section 47(5) run from when the institution itself detects the incident, or from when the relevant Computer Emergency Response Team is told, given the Act does not define the moment of detection?
What it reaches
Obligation class
Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The person in charge of any institution, public or private, must report a cybersecurity incident to the relevant Sectoral Computer Emergency Response Team, or to the National Computer Emergency Response Team where no Sectoral team covers that institution, within twenty-four hours after the incident is detected.
A cybersecurity service provider licensed by the Cyber Security Authority carries a further duty to submit a periodic report on its own operations, including any cybersecurity incident, within a period the Authority determines. Failing to report within the twenty-four-hour window is an administrative penalty of not less than two hundred and fifty penalty units and not more than five thousand penalty units, payable to the Authority, rather than a criminal offence.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
Cybersecurity Act, 2020 (Act 1038), full text (Centre for Democracy and Development, csdsafrica.org)