Law / Ghana

Cybersecurity Act, Cybersecurity Standards and Enforcement

Cybersecurity Act, 2020 (Act 1038), s. 59, and Second Schedule item 59(4)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 29 December 2020.

A security baseline statutes rule binding public and private bodies.

As of 18 September 2026.

What it requires

  • This binds the public and private sectors generally in Ghana; the Act states no size or sector gate for this duty.
  • Comply with the cybersecurity standards the Cyber Security Authority develops, establishes, adopts and publishes on its website, which by section 59(1) cover education and skills development, hardware and software engineering, governance and risk management, research and development, and any other area the Authority determines in line with international best practice.
  • Breaching an adopted standard is an administrative penalty of not less than two hundred and fifty penalty units and not more than twenty-five thousand penalty units, payable to the Cyber Security Authority.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

A person who breaches a cybersecurity standard the Authority adopts under section 59 is liable only to an administrative penalty under section 59(4) and the Second Schedule; no provision reviewed here makes that breach, standing alone, a criminal offence.

Who enforces it

Enforcement body

The Cyber Security Authority, established under section 2 of the Cybersecurity Act, 2020 (Act 1038).

Settledness

As of
18 September 2026
Open questions
Has the Cyber Security Authority published the hardware and software engineering standards section 59(1)(b) directs it to develop, and if so what do they require of a software developer operating in Ghana?

What it reaches

Obligation class

Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Cyber Security Authority must develop, establish and adopt standards for cybersecurity covering education and skills development, hardware and software engineering, governance and risk management, research and development, and any other area it determines in line with international best practice. It must publish them on its website, and take the necessary measures to enforce them and monitor compliance by the public and private sectors.

A person who breaches an adopted standard is liable to an administrative penalty of not less than two hundred and fifty penalty units and not more than twenty-five thousand penalty units, payable to the Authority.

The Act names no size or sector gate for this duty and states no criminal penalty for a breach; the specific technical content of a standard the Authority adopts under this section, including whatever it requires of hardware and software engineering, is set outside the Act's own text and is not described here.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Cybersecurity Act, 2020 (Act 1038), full text (Centre for Democracy and Development, csdsafrica.org)

Back to the example  ·  Lint your app