Cybersecurity Act, Cybersecurity Standards and Enforcement
Cybersecurity Act, 2020 (Act 1038), s. 59, and Second Schedule item 59(4)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 29 December 2020.
A security baseline statutes rule binding public and private bodies.
As of 18 September 2026.
What it requires
- This binds the public and private sectors generally in Ghana; the Act states no size or sector gate for this duty.
- Comply with the cybersecurity standards the Cyber Security Authority develops, establishes, adopts and publishes on its website, which by section 59(1) cover education and skills development, hardware and software engineering, governance and risk management, research and development, and any other area the Authority determines in line with international best practice.
- Breaching an adopted standard is an administrative penalty of not less than two hundred and fifty penalty units and not more than twenty-five thousand penalty units, payable to the Cyber Security Authority.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
A person who breaches a cybersecurity standard the Authority adopts under section 59 is liable only to an administrative penalty under section 59(4) and the Second Schedule; no provision reviewed here makes that breach, standing alone, a criminal offence.
Who enforces it
Enforcement body
The Cyber Security Authority, established under section 2 of the Cybersecurity Act, 2020 (Act 1038).
Settledness
- As of
- 18 September 2026
- Open questions
- Has the Cyber Security Authority published the hardware and software engineering standards section 59(1)(b) directs it to develop, and if so what do they require of a software developer operating in Ghana?
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Cyber Security Authority must develop, establish and adopt standards for cybersecurity covering education and skills development, hardware and software engineering, governance and risk management, research and development, and any other area it determines in line with international best practice. It must publish them on its website, and take the necessary measures to enforce them and monitor compliance by the public and private sectors.
A person who breaches an adopted standard is liable to an administrative penalty of not less than two hundred and fifty penalty units and not more than twenty-five thousand penalty units, payable to the Authority.
The Act names no size or sector gate for this duty and states no criminal penalty for a breach; the specific technical content of a standard the Authority adopts under this section, including whatever it requires of hardware and software engineering, is set outside the Act's own text and is not described here.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
Cybersecurity Act, 2020 (Act 1038), full text (Centre for Democracy and Development, csdsafrica.org)