Law / Sierra Leone

Cyber Security and Crime Act, 2021, unauthorised access

Cyber Security and Crime Act, 2021 (Act No. 7 of 2021), s. 33 (Unauthorised Access)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 15 November 2021.

A computer misuse rule binding public and private bodies.

As of 5 September 2026.

What it requires

  • Do not cause a computer system to perform a function to gain access to a computer system, program, or data without authorisation, including by exceeding the level of access a person entitled to grant it has consented to.
  • Reading a public, unauthenticated page without exceeding any consented scope of access has not itself been held to fall within this section's definition of unauthorised access.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

A fine of not less than Le 100,000,000 and not more than Le 250,000,000, or imprisonment of not less than 2 years and not exceeding 5 years, or both, on conviction; a corporation, partnership, or association faces a fine of not less than Le 500,000,000 and not exceeding Le 1,000,000,000 (s. 33(1)).

Penalty structure

Fine stated in the old Sierra Leonean Leone, the currency in circulation when this 2021 Act was passed (Sierra Leone redenominated to a new Leone in 2022). The same subsection also allows imprisonment of not less than 2 years and not exceeding 5 years instead of or in addition to the fine, and sets a separate, higher fixed range of Le 500,000,000 to Le 1,000,000,000 for a corporation, partnership, or association.

Rule
Fixed only
As of
5 September 2026
Minimum
100,000,000
Currency
SLL
Fixed cap
250,000,000

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 33(1) prohibits intentionally and without authorisation causing a computer system to perform a function with intent to secure access to the whole or a part of a computer system or to enable such access to be secured.

Section 33(3) defines unauthorised, for the purposes of this section, by reference to a person who has been authorised to access specific data and, without lawful excuse, causes the system to perform a function other than what was authorised, and section 33(4) confirms that the absence of authority includes a case where general authority exists but a specific type, nature, or method of access does not.

The Act's general interpretation section separately defines unauthorised access as access by a person who is either not entitled to access the computer system, program, or data at all, or who does not have or exceeds the level of authorisation consented to by the person entitled to grant it. Neither definition requires infringing a technical security measure to gain access, though both turn on there being a scope of consented access to exceed.

On conviction, an individual faces a fine of not less than Le 100,000,000 and not more than Le 250,000,000, or imprisonment of not less than 2 years and not exceeding 5 years, or both, and a corporation, partnership, or association faces a fine of not less than Le 500,000,000 and not exceeding Le 1,000,000,000.

When LexLint raises it

  • crawls_web
  • trains_models

Read the law

official gazetted Act text, Supplement to the Sierra Leone Gazette No. 71 of 25 November 2021, reproduced by SierraLII (Laws.Africa)

Back to the example  ·  Lint your app