Law / Gambia

Information and Communications Act, 2009, security of information and communications services (subscriber risk notification)

Information and Communications Act, 2009 (No. 2 of 2009), sec. 140(3)-(6)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 29 May 2009.

A vulnerability and incident reporting rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • This binds the same information and communications service provider bound by section 140(1) and (2)'s safeguards duty.
  • Where a particular risk of a breach of the security of your services persists despite your safeguards, inform your subscribers of the risk and of the measures they may take to protect themselves.
  • Identify in that notice any software or encryption technology available to the subscriber to protect the security of their communications.
  • Where an event affecting or jeopardizing the security of your services occurs and reveals a previously unknown risk, promptly and free of charge inform the affected subscriber of the risk, the measures they may take, and the estimated cost involved.
  • Notifying subscribers of a security risk does not excuse you from taking immediate measures to restore your service's normal security level.

If you get it wrong

Criminal exposureYes

Criminal exposure note

Contravening or failing to comply with a provision of the Act that carries no penalty of its own, including this duty, is an offence punishable by a fine of not less than fifty thousand Dalasis or imprisonment for a term not exceeding three years, or both, plus a further fine of five hundred Dalasis for every day a continuing offence persists.

Penalty structure

Section 140 carries no penalty of its own; a violation falls to section 247's general offence for contravening or failing to comply with a provision of the Act, a fine of not less than fifty thousand Dalasis or imprisonment for a term not exceeding three years, or both, for the underlying offence, with a further fine of five hundred Dalasis for every day a continuing violation persists.

Rule
Per violation only
As of
19 September 2026
Minimum
50,000
Currency
GMD
Per violation unit
Day
Per violation amount
500

Over one month of continuous breach, GMD 15,220.

Who enforces it

Enforcement body

The Gambia Public Utilities Regulatory Authority (PURA), the Authority the Act designates to regulate the provision of information and communications services, may apply its own sanctions against a licensee's non-compliance with the Act, including a fine, a disclosure order, or advising the Minister to suspend or revoke the licence; a contravention with no penalty stated of its own draws the general offence under section 247.

Settledness

As of
19 September 2026
Open questions
Does any Public Utilities Regulatory Authority directive, or the gmCSIRT's own protocols, require an information and communications service provider to report a security incident to a regulator or to gmCSIRT, in addition to the subscriber notice section 140(3) to (6) require?

What it reaches

Obligation class

Security, Breach notice

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Where a particular risk of a breach of the security of the services persists despite the technical and organizational measures taken under section 140(1) and (2), the service provider must inform the subscribers of the risk and of the measures they may take to enhance their level of protection. That information must also indicate any software and encryption technologies available for use by the end-users and subscribers to safeguard the security of their communications.

Where an event affecting or jeopardizing the security of the services occurs and a previously unknown risk of a breach of security appears as a result, the service provider must promptly inform the subscriber of the risk, free of charge, of the measures the subscriber may take to enhance the level of protection, and of the estimated costs involved.

Informing subscribers of a particular security risk does not discharge the service provider from the obligation to take appropriate and immediate measures to restore the normal security level of the service.

The Act sets no penalty specific to this duty, so a violation falls to the general offence under section 247 for contravening or failing to comply with a provision of the Act, a fine of not less than fifty thousand Dalasis or imprisonment for a term not exceeding three years, or both, with a further fine of five hundred Dalasis for every day a continuing offence persists.

When LexLint raises it

  • provides_telecom_services

Read the law

Official Act text, published by the Public Utilities Regulatory Authority (PURA)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app