Information and Communications Act, 2009, Computer Misuse and Cyber Crime part
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 29 May 2009.
A computer misuse rule binding public and private bodies.
As of 4 September 2026.
What it requires
- Do not cause a computer system to perform any function to secure access to a program or data without the right or permission of the person who controls that system.
- Do not intercept, or cause to be intercepted, any function of or data within a computer system without the consent of both the sender and the intended recipient of the data, or a statutory power to do so.
- Do not modify data held in a computer system, or degrade, interrupt, or deny access to a computer system, without lawful authority or excuse.
- Do not manufacture, sell, import, distribute, or possess a device or data designed or adapted primarily to commit an offence under this Part.
- Do not disclose a password or access code to a computer system or data for a wrongful purpose.
If you get it wrong
Criminal exposureYes
Criminal exposure note
Unauthorised access to computer data (s. 163), access with intent to commit a further offence (s. 164), unauthorised access to and interception of a computer service (s. 165), unauthorised modification of computer material (s. 166), damaging or denying access to a computer system (s. 167), unlawful possession of devices and data (s. 168), and unauthorised disclosure of a password (s. 169) each carry, for an individual, a fine of 200,000 Dalasis or imprisonment for a term not exceeding five years, or both; a body corporate faces a fine of not less than 500,000 Dalasis. Where an offence under s. 166 impairs the operation of the computer system or suppresses or modifies data held in it, a further fine of 500,000 Dalasis applies.
Penalty structure
The 200,000 Dalasi figure is the individual offender's fixed ceiling (alongside up to five years' imprisonment) common to ss. 163-169. A body corporate instead faces a floor rather than a ceiling, a fine of not less than 500,000 Dalasis, which this single fixed_only shape cannot also express; see criminal_exposure_note for the corporate figure and the s. 166 aggravated further fine.
- Rule
- Fixed only
- As of
- 4 September 2026
- Currency
- GMD
- Fixed cap
- 200,000
What it reaches
Obligation class
Access restriction
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A person who causes a computer system to perform a function knowing that the access is unauthorised commits an offence, unless the person has a right to control the operation or use of the computer system and exercises that right.
Securing access to a computer system for the purpose of obtaining a computer service, or intercepting any function of or data within a computer system, is also an offence unless both the sender and intended recipient of the data have given consent or the actor is exercising a statutory power.
Causing an unauthorised modification of data held in a computer system, or, without lawful authority or excuse, degrading, interrupting, or denying access to a computer system or the data held in it, are each separate offences.
Manufacturing, selling, importing, distributing, or possessing a device or data designed or adapted primarily to commit any of these offences is itself an offence, as is knowingly disclosing a password or access code for wrongful gain, an unlawful purpose, or knowing it is likely to cause prejudice. It is immaterial to any of these offences whether the access or interception was directed at a particular program or data, or at any program or data at all.
When LexLint raises it
crawls_web
Read the law
Information and Communications Act
2009, official consolidated text as republished by the Public Utilities Regulatory Authority (PURA), The Gambia's telecommunications regulator