Information and Communications Act, 2009, security of information and communications services (subscriber risk notification)
Information and Communications Act, 2009 (No. 2 of 2009), sec. 140(3)-(6)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 29 May 2009.
A vulnerability and incident reporting rule binding public and private bodies.
As of 19 September 2026.
What it requires
- This binds the same information and communications service provider bound by section 140(1) and (2)'s safeguards duty.
- Where a particular risk of a breach of the security of your services persists despite your safeguards, inform your subscribers of the risk and of the measures they may take to protect themselves.
- Identify in that notice any software or encryption technology available to the subscriber to protect the security of their communications.
- Where an event affecting or jeopardizing the security of your services occurs and reveals a previously unknown risk, promptly and free of charge inform the affected subscriber of the risk, the measures they may take, and the estimated cost involved.
- Notifying subscribers of a security risk does not excuse you from taking immediate measures to restore your service's normal security level.
If you get it wrong
Criminal exposureYes
Criminal exposure note
Contravening or failing to comply with a provision of the Act that carries no penalty of its own, including this duty, is an offence punishable by a fine of not less than fifty thousand Dalasis or imprisonment for a term not exceeding three years, or both, plus a further fine of five hundred Dalasis for every day a continuing offence persists.
Penalty structure
Section 140 carries no penalty of its own; a violation falls to section 247's general offence for contravening or failing to comply with a provision of the Act, a fine of not less than fifty thousand Dalasis or imprisonment for a term not exceeding three years, or both, for the underlying offence, with a further fine of five hundred Dalasis for every day a continuing violation persists.
- Rule
- Per violation only
- As of
- 19 September 2026
- Minimum
- 50,000
- Currency
- GMD
- Per violation unit
- Day
- Per violation amount
- 500
Over one month of continuous breach, GMD 15,220.
Who enforces it
Enforcement body
The Gambia Public Utilities Regulatory Authority (PURA), the Authority the Act designates to regulate the provision of information and communications services, may apply its own sanctions against a licensee's non-compliance with the Act, including a fine, a disclosure order, or advising the Minister to suspend or revoke the licence; a contravention with no penalty stated of its own draws the general offence under section 247.
Settledness
- As of
- 19 September 2026
- Open questions
- Does any Public Utilities Regulatory Authority directive, or the gmCSIRT's own protocols, require an information and communications service provider to report a security incident to a regulator or to gmCSIRT, in addition to the subscriber notice section 140(3) to (6) require?
What it reaches
Obligation class
Security, Breach notice
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Where a particular risk of a breach of the security of the services persists despite the technical and organizational measures taken under section 140(1) and (2), the service provider must inform the subscribers of the risk and of the measures they may take to enhance their level of protection. That information must also indicate any software and encryption technologies available for use by the end-users and subscribers to safeguard the security of their communications.
Where an event affecting or jeopardizing the security of the services occurs and a previously unknown risk of a breach of security appears as a result, the service provider must promptly inform the subscriber of the risk, free of charge, of the measures the subscriber may take to enhance the level of protection, and of the estimated costs involved.
Informing subscribers of a particular security risk does not discharge the service provider from the obligation to take appropriate and immediate measures to restore the normal security level of the service.
The Act sets no penalty specific to this duty, so a violation falls to the general offence under section 247 for contravening or failing to comply with a provision of the Act, a fine of not less than fifty thousand Dalasis or imprisonment for a term not exceeding three years, or both, with a further fine of five hundred Dalasis for every day a continuing offence persists.
When LexLint raises it
provides_telecom_services
Read the law
Official Act text, published by the Public Utilities Regulatory Authority (PURA)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.