Key points
- The revised Bill gets the architecture of a modern ICT regulator largely right: licensing is risk-based, decisions must be reasoned and published, and government hosting is opened to competition.
- Its weaknesses are reach beyond public ICT and high-risk services, two conflicting enforcement regimes, data protection promises that are not binding duties, and oversight bodies that depend on the Ministry.
- Ten priority amendments, each explained with suggested wording, would fix them.
- One correction is urgent: as drafted, section 107(6) could end every ICT-related licence issued by any public body six months after commencement.
ACTPOL supports the Bill’s aim of a modern, risk-based regulator for Ghana’s ICT sector and digital state. This commentary reviews every part of the revised draft of September 2026 and proposes specific amendments, with suggested wording, to keep the Authority’s reach within its purpose and its powers within the Constitution.
Summary
The revised Bill gets the architecture of a modern ICT regulator largely right, and ten amendments would fix its main weaknesses. Licensing is risk-based, decisions must be reasoned and published, search and seizure need warrants, and government hosting is opened to competition. The weaknesses are four: reach beyond public ICT and high-risk services, two conflicting enforcement regimes, data protection promises that are not binding duties, and oversight bodies that depend on the Ministry.
The ten amendments below matter most. Each is explained, with suggested wording, in the section on that part of the Bill.
| # | Provision | Amendment | Why it matters |
|---|---|---|---|
| 1 | s 46(9) to (11) | Delete the duty on every private-sector ICT professional to join a recognised body, or confine it to prescribed critical functions on designated critical ICT infrastructure. | “ICT professional” is undefined for the private sector, and the duty works as licensing of the technology workforce, contrary to s 35(3) and s 46(8). |
| 2 | ss 94(1)(c), 94(2), 96, 97, 103(7) | Treat licence breaches as administrative matters under s 99, remove minimum prison terms, and align s 97(a) with s 76(3). | The same conduct can draw a warning or a criminal conviction, at the enforcer’s choice. |
| 3 | s 100(5), s 106 | Define “critical data” or delete the offence of hosting it without a licence. | An undefined term carries up to seven years’ imprisonment, against article 19(11) of the Constitution. |
| 4 | ss 101(3), 72(4), 72(6), 40(2)(a) | Delete “or the public interest” as a ground for acting without a hearing, for urgent action and for reusing shared information, and replace it as a refusal ground with defined criteria. | The phrase swallows the safeguards these sections set out. |
| 5 | ss 41(3)(h), 43(1)(g) | Stop suspension or non-renewal of a licence merely because an offence is under investigation. | A sanction should follow a finding, not a suspicion. |
| 6 | ss 5(6), 5(7), 52, 53 | Make data protection impact assessments binding for identity, data exchange and shared platforms before technical clearance, and add privacy by design, minimisation, purpose limitation and access logging to the National Digital Architecture. | Integration is where the privacy risk in digital government concentrates. |
| 7 | ss 68, 73(6) to (9) | Let one incident notification through the single window satisfy the Authority, the Cyber Security Authority and the Data Protection Commission, on timelines they set jointly. | One incident should mean one report. |
| 8 | s 6(1)(h) | Replace the National Security Council’s Board seat with the consultation already provided in ss 32(1) and 37(3). | Security input belongs in consultation, not in commercial licensing decisions. |
| 9 | ss 87 to 90 | Move the Tribunal’s registry, staff, budget and rules away from the Ministry. | The Tribunal reviews an Authority that takes its policy directions from the same Minister. |
| 10 | ss 31 to 34, 106 | Use one defined term for the government operator, separate it from the Authority, and publish the designated systems by category. | The Bill contemplates the regulator holding an interest in the operator it regulates. |
One further correction is urgent. As drafted, s 107(6) could end every ICT-related licence issued by any public body, including other regulators, six months after commencement (see the transition section).
Scope and approach
This commentary reviews the revised National Information Technology Authority Bill, 2026, in the draft of September 2026. ACTPOL was invited, through OAKS Legal, to share its views on it.
- The draft: 69 pages, 108 sections and a Schedule. Section numbers in this commentary refer to that draft.
- What it does: it establishes a National Information Technology Authority (s 1), transfers to it the assets, staff and contracts of the National Information Technology Agency (s 107), and repeals the National Information Technology Agency Act, 2008 (Act 771) (s 108).
- Method: for each part we set out what it does, what works and what should change, with suggested wording where a change is practical. Penalties are given in penalty units, as the Bill states them.
- Constitutional tests: we refer to articles 18(2) (privacy), 19(11) (offences must be defined in written law) and 23 (administrative justice) of the 1992 Constitution.
- Limit: the Bill relies on an “Electronic Transactions Act, 2026 (Act …)” that has not been enacted. Provisions that depend on it (ss 3(1)(p), (r), (s), (v), (y) and (bb), 3(2)(c), 101(1) and 106(2)) cannot be fully assessed until its text is known.
Object, functions and powers (ss 1 to 5)
The Authority’s object and functions are wider than the tools the Bill gives it, and should be tied to public ICT and high-risk services. Section 5, by contrast, is a strong charter of regulatory principles and should be kept.
What these sections do. Section 2 makes the object to “regulate, coordinate, promote and develop” information technology, IT infrastructure and digital services in Ghana. Section 3(1) then lists some 36 functions: licensing, standards, technical clearance, certification, complaints, investigations, competition, advice to the Minister, and internal governance. Section 5 sets the principles, links the Bill to six other Acts and forbids the Authority to usurp other regulators’ mandates.
What works
- s 5(1) and (5) require regulation that is transparent, accountable, proportionate, technology-neutral and consistent with natural justice.
- s 5(3) and (8) to (10) preserve the mandates of the Data Protection Commission, the Cyber Security Authority, the National Communications Authority and the Public Procurement Authority.
- s 5(4) binds the Authority to respect constitutional rights, including privacy and administrative justice.
What should change
| Provision | Issue | Suggested change |
|---|---|---|
| s 2, s 3(1)(b) | “Regulate IT infrastructure, IT products and IT service providers” reaches the whole private market, beyond the risk-based limits of ss 35 and 36. | Tie regulatory functions to licensable ICT services, public ICT and matters expressly assigned by this Act. |
| s 3(1)(k), (n) | The Authority may “regulate the use of emerging technologies” and set safeguards for “the responsible and secure use of technology in the country”, with no framework for either. | “advise the Minister on, and support through the regulatory sandbox under section 60, the use of emerging technologies, and regulate that use only as provided in this Act or another enactment”. |
| s 3(1)(o), (bb) | The Authority would “determine complaints” on anti-competitive and price-fixing practices, with an unnamed “appropriate public institution”. | Limit the role to referral and technical advice: “refer to the competent competition authority, with technical advice, a complaint of anti-competitive, price-fixing or unfair trade practices by a licence holder”. |
| s 3(1)(w) | Users may complain when a licence holder fails them, but no procedure or time limit exists in the Act. | Add a duty to acknowledge a complaint within 10 working days and decide it within 60 days, with detail left to regulations under s 105(1)(b). |
| s 3(1)(cc) to (hh) | Formulating strategy, propriety, efficiency and corporate governance are Board duties, not external functions. | Move them to s 7. |
| s 3(1) | Two paragraphs are lettered (c). | Renumber. |
| s 5(2) | Cites the Electronic Transactions Act, 2008 (Act 772), while s 3 cites an Electronic Transactions Act, 2026. | Cite one Act, consistently. |
| s 5(6) | Data Protection Commission requirements apply only to processing “on a significant scale”, which is undefined. | Add: “processing on a significant scale includes processing of sensitive personal data, systematic monitoring and large-scale processing as specified by the Data Protection Commission”. |
Governance: the Board, policy directives and independence (ss 6 to 16)
The governance provisions contain real safeguards, but a regulator that licenses and sanctions private firms needs a Board with an independent majority and no security-service seat. The limit on ministerial directives in s 15(2) is a model worth keeping.
What these sections do. The Board has 10 members (s 6(1)): a chairperson and an expert nominated by the President, directors from the Ministries of Communication and Finance, the Director-General, a nominee of a recognised ICT professional body, a lawyer, a representative of the National Security Council and two others. At least three must be women (s 6(2)). The President appoints all of them under article 70 of the Constitution (s 6(3)) for four years, renewable once (s 9(1)).
What works
- Members may be removed only for stated cause, after written notice and a chance to respond (s 9(5) to (7)).
- Conflicts must be disclosed, conflicted members stand aside, and undisclosed conflicts end membership (ss 11 and 12).
- Technical, Audit and Risk Committees are mandatory (s 13(4)).
- The Minister may give written policy directives but not “instruct the Authority on specific technical or operational matters” (s 15), and directives received must be reported annually (s 29(2)(g)).
What should change
| Provision | Issue | Suggested change |
|---|---|---|
| s 6(1)(h) | A National Security Council representative would sit on decisions about ordinary commercial licences, with access to applicants’ ownership and financial information. | Delete. Route security questions through the consultation already required by ss 32(1) and 37(3). |
| s 6(1), (3) | Six of 10 members are officials or presidential nominees, and the President appoints the rest. | Fill paragraphs (f), (g) and (i) through a public call for nominations and a published shortlist, and give independent members a majority. |
| s 6(5) | Appointees must meet “qualification requirements prescribed under this Act or Regulations”, but the Act prescribes none. | State the requirements in the Act, or oblige the Minister to prescribe them before the first appointments. |
| s 9(6)(h) | Removal for “any other sufficient cause recognised by law” reopens a closed list. | Delete paragraph (h). |
| s 9(8) | The Minister alone decides whether a member’s inability to act creates a vacancy. | The Board should report the facts to the President, who decides after hearing the member. |
| s 10(3) | A quorum of seven out of 10 can fail when two members are absent and one is conflicted out under s 11. | “The quorum for a meeting of the Board is a majority of the members.” |
| s 15 | Directives are reported only once a year. | Publish each directive on the Authority’s website within 14 days of receipt. |
Leadership and administration (ss 17 to 22)
The Bill promises a “transparent and merit-based” appointment of the Director-General but does not say what that means, and it leaves the length of the leaders’ terms open. Both gaps are easy to close.
What these sections do. The President appoints the Director-General and one Deputy under article 195 of the Constitution (s 17(1)). The Director-General serves “not more than four years”, renewable once, and needs at least 10 years’ relevant experience; the Deputy needs seven (s 17(3) to (5)). The President also appoints the Board Secretary, on the Board’s recommendation (s 19), and all other staff (s 20).
What works
- Clear minimum qualifications, including proven competence in regulation or digital transformation (s 17(4) and (5)).
- Removal only for stated cause, with written notice and a chance to respond (s 17(6)).
- An Internal Audit Unit reporting every three months (s 22).
What should change
| Provision | Issue | Suggested change |
|---|---|---|
| s 17(2) | The “transparent and merit-based process” is not described. | “The Board shall advertise the vacancy, assess candidates against published criteria and submit a shortlist of not more than three to the President.” |
| s 17(3) | “Not more than four years” allows short, renewable appointments that weaken independence. The Deputy’s term is not stated at all. | Fix both terms at four years, renewable once. |
| s 17(6) | Stated cause is not defined for the leadership, unlike s 9(6) for the Board. | Apply s 9(6)(a) to (g) to the Director-General and Deputy. |
| ss 19 and 20 | Presidential appointment of the Board Secretary and every member of staff is slow and centralised for a technical regulator. | Keep presidential appointment for the Director-General and Deputy, and provide for the Board to appoint the Secretary and staff under approved schemes of service, to the extent article 195 of the Constitution permits. |
Finance, fees and financial transparency (ss 23 to 30)
The financial provisions are among the Bill’s best: fees must track the cost of regulation, revenue-based levies need Parliament, and accounts, fees and contracts are published. Three gaps remain: donations from regulated firms, an audit timetable that cannot work, and an empty Schedule.
What these sections do. The Authority is funded by fees, parliamentary appropriations, donations and grants, and investment income (s 23(1)). Surpluses go to the Consolidated Fund unless the Minister for Finance allows them to be kept (s 25(2)). Accounts are audited by the Auditor-General and published (s 28), and an annual report goes to Parliament through the Minister (s 29).
What works
- Every fee, levy or regulatory contribution must be “proportionate to the cost of regulation and the risk profile of the regulated activity” (s 23(2)).
- A fee calculated on gross revenue needs an Act, or regulations approved by Parliament after consultation and an impact assessment (s 23(3)).
- Fees collected and their use (s 23(4)), procurement awards and contract values (s 25(4)) and audited statements with the management response (s 28(5)) must all be published.
- The annual report must list licences, penalties, clearances, appeals and directives received (s 29(2)).
What should change
| Provision | Issue | Suggested change |
|---|---|---|
| s 23(1)(c) | A regulator funded partly by donations and grants could receive them from the firms it licenses. | “The Authority shall not accept a donation or grant from a licence holder, an applicant for a licence or an affiliate of either, and shall publish every donation and grant received.” |
| s 23(2), s 36(2) | Fee schedules are reported after the event, and s 36(2) does not require fees to be published with licence terms. | Publish every fee in the Gazette and on the website before it takes effect. |
| s 25(2) | Fee surpluses can be retained or swept away at the Finance Minister’s discretion. | Apply a surplus from fees to reduce the next year’s fees, consistent with s 23(2). |
| s 28(2), (3) | The Board has six months after the year end to submit accounts, and the Auditor-General must finish the audit within the same six months. | “The Board shall submit the accounts … within three months after the end of the financial year.” |
| s 29(3) | The annual report must follow “the form and content set out in the Schedule”, but the Schedule is empty. | Complete the Schedule before passage. |
Government digital infrastructure (ss 31 to 34)
These sections open government hosting and shared services to competition, and they should survive intact. What they need is one consistent name for the government operator, a clear separation between that operator and the regulator, and transparency about which systems are reserved to it.
What these sections do. Public institutions must buy e-government infrastructure, cloud hosting, shared services and enterprise platforms competitively (s 31(2)). A government-owned operator may be reserved only systems the Minister designates as sovereign, classified or critical, in writing and with reasons, after consulting the National Security Council and relevant regulators (ss 31(3) and 32). Contracts need measurable service levels and exit terms (s 33), and the operator is audited independently (s 34).
What works
- No exclusivity for the government operator over non-classified public ICT, and no preference except on objective grounds (s 31(4) and (5)).
- Designations must state reasons, cannot be used to exclude competition for ordinary services, and are reviewed at least every three years (s 32(2) to (4)).
- Every contract must cover security, interoperability, data portability, business continuity, disaster recovery, accessibility, incident notification, confidentiality and exit management (s 33(2)).
- Audit reports, service performance and complaints about the operator are published (s 34(5)).
What should change
| Provision | Issue | Suggested change |
|---|---|---|
| ss 31 to 34, s 106 | The sections speak of a “government-owned operator”; s 106 defines a “Government ICT Infrastructure Operator” as “a company licensed by the Authority”, a term the Bill never uses. | Use one defined term throughout. |
| s 31(3), (4) | Subsection (3) says the operator “may provide services only for” designated systems; subsection (4) assumes it competes for other services. | “A government-owned operator may be assigned without competition only a system designated under section 32, and may compete for other public ICT services on equal terms.” |
| s 34(4) | The Authority may not audit the operator “where the Authority has a governance, financial or operational interest” in it, which assumes it may hold one. | “The Authority shall not hold a governance, financial or operational interest in an operator it regulates.” If s 107 transfers operating assets or contracts to the Authority, require their transfer to a separate operator within 12 months. |
| s 32 | Designations are not published, and a provider excluded by one has no route to challenge it. | Publish designated systems by category (not technical detail), report them to Parliament annually, and allow review by the Tribunal. |
| s 33(2) | Contracts must cover confidentiality but not data protection as such. | Add compliance with the Data Protection Act, 2012 (Act 843), and the return and deletion of data at exit. |
Licensing (ss 35 to 45)
The licensing chapter is the Bill’s strongest part: it licenses only services that carry material risk, sets decision deadlines and approves applications by default when the Authority is silent. Its weaknesses are undefined tests, grounds for sanction that reach beyond the Act, and the risk that one data centre needs several licences.
What these sections do. A “licensable ICT service” is one prescribed under s 36 that “presents material risk” to public or critical infrastructure, government services, cloud hosting, data centres or digital trust services (s 35(2)). The Authority sorts such services into notification, registration, class licence and specific licence tiers (s 35(4)). Section 36 names six principal licences: public or commercial ICT infrastructure, cloud hosting, software as a service (“where the service is a high-risk or public ICT service”), government digital services partnership, national digital platform operator and data centre operator.
What works
- Internal ICT use, in-house development, freelance work and low-risk start-ups below a threshold are outside licensing (s 35(3)), and regulations cannot bring them in (s 36(5), s 105(3)).
- Providing an unlicensed service is an administrative breach only after written notice. Criminal liability is confined to fraud, evading a prohibition order, endangering critical infrastructure and serious risk to public safety or security (s 35(5), (6)).
- A new principal licence category needs an amendment to the Act (s 36(4)).
- Deadlines: acknowledgement in 10 days; decisions in 30 days for notification or registration, 45 for a class licence and 90 for a specific high-risk licence; silence means approval unless the Authority gives written reasons for an extension of up to 60 days (s 39).
- Foreign ownership alone is not a ground for refusal (s 37(4)); refusals must be reasoned and state the right of appeal (s 40(3)).
- Suspension and revocation need notice, reasons and a chance to remedy, and revocation is possible only after a suspension that was not remedied (ss 43 and 45).
What should change
| Provision | Issue | Suggested change |
|---|---|---|
| s 36(1)(a), (c) | “Commercial ICT infrastructure” and “high-risk” software services have no criteria in the Act. | State in the Act the criteria for each category, for example services to public institutions, designated critical infrastructure, or large-scale processing of sensitive personal data. |
| ss 36 and 68 | One facility may need an Authority licence and, depending on what it does, registration with the Data Protection Commission, obligations to the Cyber Security Authority and a National Communications Authority licence. | “Where a service requires authorisation from more than one regulator, the applicant may make one application through the single-window mechanism under section 68, and the regulators shall decide within the period in section 39.” |
| s 37(3) | “Data sovereignty” triggers consultation but is undefined, and could become a localisation requirement by practice. | Define it, or delete it and rely on national security and critical infrastructure. |
| s 37(4) | Foreign ownership may justify refusal on “any other ground prescribed by law”. | Delete those words, leaving the listed grounds. |
| s 40(2)(a) | A licence may be refused as “against the public interest”, which is undefined. | Delete “the public interest” and rely on the specific grounds that follow it. |
| ss 41(3)(h), 43(1)(g) | A licence may be refused renewal or suspended because an offence “is being investigated”. | Delete, or allow suspension only as an interim measure under s 101(3) to (5), confirmed by the Tribunal. |
| ss 41(3)(i), 43(1)(h) | Unpaid sums owed to “another public institution”, including taxes, can cost a firm its ICT licence. | Limit the ground to sums due to the Authority under this Act, or a judgment debt to another public body. |
| ss 41(3)(c), 43(1)(b) | Not using a licence “for the intended purpose one year after issuance” penalises slow build-outs. | Allow a written extension where the licence holder shows reasonable progress. |
| ss 41(3)(f), 43(1)(e) | Risk to public health, safety or security is a suspension ground without the safeguards of s 48. | Route these cases through s 48 and s 101(5), with Tribunal or court confirmation. |
| s 44(2) | A remedied licence may take 60 days to be restored. | “within 14 days after the Authority confirms that the breach has been remedied”. |
| s 41(1) | A licence lasts “the period specified in the licence”, with no minimum. | Publish a standard term for each category under s 36(2), and require reasons for any shorter term. |
Certification of ICT professionals and the register (ss 46 and 47)
Certifying the people who run public ICT is reasonable, and the Bill does it with fair procedure. Extending a membership duty to every ICT professional in the private sector is not, and it is the single change we most recommend.
What these sections do. No one may be appointed, or continue to serve, as a public ICT professional unless certified by the Authority or holding a certification it recognises (s 46(1)). Section 46(9) then requires every ICT professional “employed, engaged or practising in a private institution” to maintain membership of a professional body recognised by the Authority and to comply with standards the Authority prescribes. Section 46(11) bars private institutions from letting anyone perform “critical ICT functions” without that membership. Section 47 creates a public register of licences, certifications, penalties and enforcement actions.
What works
- Certifications from private bodies, universities and international certifiers can be recognised (s 46(3)).
- Suspension or withdrawal of a certification needs notice, reasons and a hearing (s 46(6)).
- Serving public ICT professionals are provisionally recognised for 24 months (s 107(11)).
- Published enforcement decisions carry brief reasons and the right of appeal, and exclude personal and confidential data (s 47(4), (5)).
Why s 46(9) to (11) should go. The Bill defines only public ICT professionals; the private-sector “ICT professional” is undefined. Read literally, every developer, systems administrator and IT support worker in a private firm must join an approved body and follow the Authority’s standards. That is licensing of a profession by another name. It contradicts the exemption for freelance work and start-ups in s 35(3) and the assurance in s 46(8) that private professionals need no certification unless they perform public ICT functions. It would also burden start-ups and independent developers, whose innovation the Bill elsewhere aims to support (s 59(4)).
What should change
| Provision | Issue | Suggested change |
|---|---|---|
| s 46(9) to (12) | A membership duty on the whole private ICT workforce, with no definition of who is covered. | Delete. If a duty is needed, substitute: “An operator of critical ICT infrastructure shall ensure that a person who performs a critical ICT function prescribed by Regulations holds a certification recognised under subsection (3).” |
| s 106 | “Public ICT professional” is defined twice, differently: the first covers contractors’ staff and is limited to functions that “materially affect” public ICT; the second covers any ICT function in a public institution. | Keep one definition. The first, materiality-based version is the better one. |
| s 57(4) | The Authority may suspend or revoke certification without the notice and hearing required by s 46(6). | Make s 57(4) subject to s 46(6). |
| s 46(1), (2) | Certification of serving public officers has cost and capacity implications that the Bill does not address. | Require the Authority to publish the certification criteria, fees and routes for recognising existing qualifications within six months of commencement. |
| s 47(2) | The register is updated only every six months. | “The Authority shall enter a decision in the register within seven days after it is made.” |
Closure of facilities and change of control (ss 48 and 49)
The closure power is well bounded, with court or Tribunal review of any emergency closure within seven days. The merger power should leave market concentration to the competition authority, so that one transaction does not face two competition reviews.
What these sections do. The Authority may close or suspend a facility used for a licensable service only for serious and imminent risk to people, security, critical infrastructure, essential public services or the environment, or after persistent failure to remedy a material breach (s 48(1)). Normally it must give 15 days’ notice with reasons (s 48(2)). A licensed provider of a high-risk service or critical infrastructure needs prior approval for a change of control, merger or transfer of regulated assets that materially affects the service (s 49(1)).
What works
- An interim closure, suspension or seizure must be reviewed by the Tribunal or a court within seven days (s 48(4)).
- The Authority must protect data integrity, confidentiality, business continuity and third parties’ rights when it closes a facility (s 48(5)).
- Merger decisions are due in 60 days, extendable once by 30, with approval by default when the Authority is silent (s 49(3), (4)).
- A transaction made without approval is voidable “only to the extent necessary” to protect the service or the public (s 49(5)).
What should change
| Provision | Issue | Suggested change |
|---|---|---|
| s 48(6) | “The Authority shall guidelines” is missing its verb, and the guidelines need not exist before the power is used. | “The Authority shall, before exercising a power under this section, issue and publish guidelines on its exercise.” |
| s 48(5) | Closing a data centre or cloud platform affects every customer hosted on it, including public institutions. | Require notice to affected customers and a continuity plan agreed with any public institution whose service depends on the facility. |
| s 49(2), (6) | The Authority assesses “market concentration” while the competition authority keeps its own jurisdiction, so one transaction may face two competition reviews. | Limit the Authority’s review to continuity, security, interoperability and consumer protection, and require it to share its findings with the competition authority. |
| s 49(1) | “High-risk ICT service” is not defined. | Define it in s 106 by reference to the licence categories and criteria in s 36. |
Standards, technical clearance and public ICT governance (ss 50 to 61)
The public-sector tools are well designed: technical clearance has objective thresholds and deadlines, the project registry is advisory, and the sandbox cannot switch off data protection. Two things need to change: enforceable standards should stop at licensable services and public ICT, and fining public institutions should give way to accountability to Parliament.
What these sections do. The Authority sets performance standards and product specifications (ss 50, 51, 58). Public institutions need technical clearance before a major ICT procurement or deployment (s 52), register every ICT project (s 54), give first consideration to designated shared services (s 55) and face audits and improvement plans (s 56). The Authority also maintains a National Digital Architecture (s 53), runs a regulatory sandbox (s 60) and sets accessibility standards (s 61).
What works
- Clearance thresholds are set by regulations after consultation and an impact assessment, using objective criteria such as contract value, data sensitivity and cyber risk (s 52(3)).
- Clearance is due in 45 days, is granted by default for non-critical projects, and must list the other approvals still needed (s 52(4), (5), (7)).
- Registry review is advisory and cannot delay procurement unless the project needs clearance (s 54(4)).
- An institution may opt out of a shared service that does not meet its needs, with reasons kept for audit (s 55(4), (5)).
- Sandbox participants remain bound by data protection, cybersecurity, consumer protection and anti-money-laundering law unless the competent authority exempts them (s 60(5)), and another regulator’s rules can be relaxed only by that regulator (s 60(6)).
- A licence or accreditation can be required only for a licensable service (s 58(5)).
What should change
| Provision | Issue | Suggested change |
|---|---|---|
| ss 50, 51, 58(1) | Performance standards and specifications are enforceable across “the ICT sector”, beyond the risk-based limits of licensing. | Make standards binding only for licensable services and public ICT. For the rest of the market, the Authority should issue guidance. |
| s 51 | Product specifications may overlap with type approval by the National Communications Authority and standards of the Ghana Standards Authority. | Require specifications to be set jointly with those bodies where they overlap. |
| s 52 | Clearance does not depend on a data protection impact assessment. | Make an assessment reviewed by the Data Protection Commission a condition of clearance for projects that process personal data at scale (see the data protection section). |
| s 53 | The Architecture sets standards for data exchange and authentication but carries no privacy safeguards, and need not be published. | Add privacy by design, data minimisation, purpose limitation and auditable access logs to s 53(2), and require publication. |
| s 56(3) | A public institution that fails an improvement plan pays the Authority 5,000 to 10,000 penalty units, moving public money between public bodies and giving the Authority an income from its own findings. | Replace the penalty with a published report of non-compliance to Parliament and the Auditor-General, and accountability of the institution’s accounting officer. |
| s 60(4) | “The Authority shall guidelines” is missing its verb. | “The Authority shall issue guidelines …” |
| s 60(9) | Only an annual summary of the sandbox is published. | Publish each admission, the relief granted and its duration when the decision is made. |
| s 61(2) | Accessibility standards are to be “based on international best practices”, with no baseline or deadline. | Name a baseline for public websites and apps, such as the World Wide Web Consortium’s Web Content Accessibility Guidelines at level AA, set a compliance date, and make accessibility a clearance criterion. |
Industry Forum, consultation and impact assessment (ss 62 and 63)
Section 63 is a model notice-and-comment regime and should be kept whole. The Industry Forum needs more structure to be useful, and urgent instruments made without consultation should lapse unless re-made properly.
What these sections do. An Industry Forum gives the ICT sector a consultative platform whose recommendations go to the Authority (s 62). Before issuing any binding instrument of general application, the Authority must publish a draft, allow at least 30 days for comment, and publish the final text with a summary of comments and its response (s 63(5) to (7)). Instruments are reviewed every three or five years, and the Minister must tell Parliament which review recommendations were accepted (s 63(1) to (4)).
What works
- Consultation, a published response to comments and an impact assessment covering privacy and innovation effects (s 63(7), (8); s 106 “regulatory impact assessment”).
- Parliament sees the Minister’s response to each review within 12 months (s 63(4)).
- Urgent action without consultation requires published reasons and consultation within 90 days afterwards (s 63(10)).
What should change
| Provision | Issue | Suggested change |
|---|---|---|
| s 62(4) | The Authority alone decides the Forum’s membership, frequency, venue and agenda. | Set open membership criteria covering licensees, users, civil society and academia, and require published minutes. |
| s 62(7) | Recommendations are only “considered”. | Require a written response from the Authority within 60 days. |
| s 63(9), (10) | An urgent instrument stays in force indefinitely after the 90-day consultation. | “An instrument issued under subsection (9) lapses after 180 days unless re-issued in accordance with subsections (5) to (8).” |
| s 105(2) | Only regulations creating a new licence obligation, fee, penalty, clearance threshold or certification requirement must be consulted on. | Apply s 63(5) to (8) to all regulations under s 105. |
Regulatory coordination (ss 64 to 72)
The coordination framework is the Bill’s most original contribution, and it answers a real problem: digital services cross the mandates of several regulators. It needs deadlines to work in practice, a neutral chair, and firmer protection for the independent regulators when disputes reach Ministers.
What these sections do. Each digital service has a lead regulator and co-regulators (s 65). The Data Protection Commission leads on personal data, the Cyber Security Authority on cybersecurity, the National Communications Authority on spectrum and networks, and the Authority on public ICT architecture and interoperability (s 65(6)). The Authority keeps a published Regulatory Clarity Matrix of who regulates what (s 67), runs a single window for applications (s 68) and chairs a Regulatory Coordination Committee of 10 named bodies and any others it invites (s 71). Disputes go to consultation, then the Committee, then Ministers (s 72).
What works
- Other regulators are “independent peer regulators” (s 69(1)), and nothing in these sections makes the Authority superior to them (s 72(7)).
- The Matrix is a coordination tool only, and an enactment prevails over it (s 67(5), (6)).
- No one should have to give the same information to several regulators where it can lawfully be shared (s 68(6)).
- Joint guidelines must state each regulator’s legal basis (s 70(5)).
What should change
| Provision | Issue | Suggested change |
|---|---|---|
| s 67(4) | The Matrix must be updated every two years, but no date is set for the first one. | “The Authority shall publish the first Regulatory Clarity Matrix within 12 months after the commencement of this Act.” |
| s 68(3), (5) | Referrals between regulators wait for a “prescribed period”, so the single window can stall until regulations are made. | Set a default of 21 days in the Act, and make the s 39 deadlines run for the whole joint application. |
| s 71(3) | The Director-General always chairs a committee of peer regulators. | Rotate the chair annually among the member bodies, with the Authority providing the secretariat. |
| s 72(3) | Unresolved disputes go to Ministers for “policy coordination”. | State that ministerial coordination is advisory and cannot direct a regulator in a matter within its statutory mandate, and that disputes over the Data Protection Commission’s mandate are excluded. |
| s 72(4) | Urgent action is allowed to protect “the public interest”, besides specific harms. | Delete “or the public interest”. |
| s 72(6) | Shared information may be reused for a new purpose to protect “the public interest”. | Delete “or the public interest”, and require a record of each reuse, open to the Data Protection Commission. |
| s 66(6) | “National data integration” is a cross-cutting service, but it is not defined. | Define it, and name the Data Protection Commission as a co-regulator of every such service. |
Reporting and incident notification (s 73)
Incident reporting to the Authority is sensible for public infrastructure, but as drafted it adds a third reporting line alongside the Cyber Security Authority and the Data Protection Commission. Routine reporting should also scale with the licence tier.
What this section does. Every licensed provider files an annual report within 90 days of its year end, may be asked for an unaudited compliance summary within 30 days, and must answer requests about its conduct, practices and management (s 73(1) to (4)). Providers and public institutions must notify “significant ICT incidents” affecting public infrastructure, public digital services, interoperability or government hosting, in a manner and period to be prescribed (s 73(6), (7)). The Authority coordinates with the Cyber Security Authority on cyber incidents and with the Data Protection Commission on personal data breaches (s 73(8), (9)).
What works
- Public institutions, not only private providers, must report incidents (s 73(6)).
- Reports are confidential except for regulatory coordination, safety, enforcement or where the law requires disclosure (s 73(10)).
- A provider that followed recognised cybersecurity standards is not sanctioned merely because an incident occurred (s 100(8)).
What should change
| Provision | Issue | Suggested change |
|---|---|---|
| s 73(6) to (9) | One incident may have to be reported three times, to three regulators, on three timelines. | “A notification made through the single-window mechanism under section 68 satisfies the duty to notify the Authority, the Cyber Security Authority and the Data Protection Commission, on timelines prescribed jointly by them.” |
| s 106 | A “significant ICT incident” includes anything that “is likely to disrupt” data integrity or availability, which could capture routine outages. | Prescribe thresholds, such as duration, number of users or services affected, before the duty takes effect. |
| s 73(1) to (3) | Annual reports and a 30-day compliance summary apply to every licence holder, including those at the notification tier. | Scale reporting to the tier in s 35(4), and limit the 30-day summary to specific high-risk licences. |
| s 73(4) | Requests about the “conduct, practices and management” of a business have no stated limit. | Limit requests to information reasonably required for a function under this Act, stated in writing with reasons and a reasonable time to respond. |
| s 73(10) | Incident data is confidential, so the public learns nothing about the resilience of public services. | Publish anonymised annual incident statistics in the annual report. |
Inspection and enforcement (ss 74 to 79)
The search and seizure safeguards in s 75 are strong: a warrant for anything forcible, court confirmation of urgent seizures within 48 hours, and limits on access to personal data. Several other powers in these sections sit outside those safeguards and should be brought within them.
What these sections do. Inspectors, authorised in writing by the Director-General, may enter premises at a reasonable time where there is reason to believe a contravention is occurring (ss 74, 75(1)). Forced entry, search, seizure and copying of protected information need a court warrant (s 75(3)). The Authority can demand documents, summon witnesses, restrain licence holders, order compensation, issue warnings and cease-and-desist orders, and audit ICT infrastructure (ss 77 to 79).
What works
- A seizure without a warrant must be confirmed by a court within 48 hours, or the items returned at once (s 75(4) to (6)).
- Inspectors give an inventory of anything seized and report within 48 hours (s 75(7), (11)).
- A first failure to provide information, without fraud or threats, is met with a compliance notice, not prosecution (s 76(3)).
- Forfeiture needs a court’s validation and protects third parties’ rights (ss 78(b), 79(3)).
- The Authority must consult any other regulator affected before acting, or notify it within 48 hours after urgent action (s 79(5), (6)).
What should change
| Provision | Issue | Suggested change |
|---|---|---|
| s 75(1) | Entry is allowed wherever a contravention is suspected, including a home used for work. | “An inspector shall not enter a dwelling except with the consent of the occupier or under a warrant.” |
| s 75(8) | Personal data may be accessed where a warrant authorises it “or” where it is “necessary for the specific investigation”, so the second limb can bypass the first. | Require a warrant for access to personal data, and a record of each access available to the Data Protection Commission. |
| s 77(1)(c) | The power to require a witness to attend has no procedure. | Require a written summons with reasonable notice, the right to be accompanied by a lawyer, and protection against self-incrimination. |
| s 77(1)(d) | Restraining a licence holder from doing business is suspension without the notice and hearing required by s 43. | Make the power subject to s 43, or to s 101(3) to (5) in an emergency. |
| s 77(1)(e) | Compensation orders are valuable for users but have no stated procedure. | Require a hearing of both sides and written reasons, and publish the orders. |
| s 78(e) | The Authority may “take any other action necessary to ensure compliance”. | Delete. Enforcement powers should be listed. |
| s 79(1) | Audits of “commercial ICT infrastructure” are not limited to licence holders or to cases with grounds. | Limit audits to licence holders and public ICT, on reasonable grounds stated in writing. |
Dispute resolution and the Tribunal (ss 80 to 93)
A specialist appeal Tribunal is the right design for a technical regulator, and its judicial appointments process is sound. Its administration, budget and rules, however, all run through the same Minister who directs the Authority, and the Bill leaves out stays, decision deadlines and a forum for users’ complaints.
What these sections do. Disputes between ICT service providers go first to negotiation, then to a Dispute Resolution Committee that must decide within 30 days (ss 80 to 83). Its decisions, and the Authority’s, can be appealed within 21 days to a three-member National Information Technology Tribunal, which must convene within 30 days (ss 85, 91). Tribunal decisions have the effect of High Court judgments and can be appealed to the Court of Appeal on points of law (ss 92, 93).
What works
- The Tribunal’s chairperson is a retired Superior Court Justice or a lawyer with 15 years’ relevant experience, appointed after consulting the Attorney-General and the Judicial Council (s 86(1), (2)).
- The Tribunal is declared independent of the Authority, the Board and the Minister (s 86(4)), and must publish its decisions (s 86(5)).
- The Tribunal may become the single appeal body for related digital economy laws, avoiding inconsistent decisions (s 86(6)).
What should change
| Provision | Issue | Suggested change |
|---|---|---|
| ss 87 to 90 | The Minister appoints the Registrar and staff, approves the budget, sets allowances and makes the rules of procedure. The same Minister directs the Authority whose decisions the Tribunal reviews (s 15). | Place the registry and staff under the Judicial Service, fund the Tribunal through its own budget line approved by Parliament, and have the rules made on the Judicial Council’s advice. |
| ss 91, 92 | An appeal does not say whether the Authority’s decision is suspended in the meantime. | “An appeal does not suspend the decision, but the Tribunal may stay it on application. A revocation of a licence is stayed until the appeal is decided unless the Tribunal orders otherwise.” |
| s 91(3) | The Tribunal must convene within 30 days but has no deadline to decide. | Require a decision within 60 days after the hearing ends. |
| s 86(1) | Three members may not cope if the Tribunal also hears appeals under other laws (s 86(6)). | Allow additional members to be appointed and the Tribunal to sit in panels of three. |
| ss 80 to 82 | The Dispute Resolution Committee is formed and staffed by the Authority’s own Board, and may hear disputes involving an operator in which the Authority has an interest. | Bar Authority staff from membership and require publication of the Committee’s decisions. |
| s 3(1)(w), s 81 | The Committee hears only disputes between providers, so users who complain under s 3(1)(w) have no hearing body. | Extend the Committee’s jurisdiction to unresolved user complaints, with appeal to the Tribunal. |
Offences and penalties (ss 94 to 100)
The penalty provisions need the most work. They run two enforcement regimes side by side, impose minimum sentences, punish false information in three different ways, and create offences from undefined terms.
The offences as drafted (fines in penalty units; “or both” means a fine and imprisonment together)
| Section | Conduct | Penalty |
|---|---|---|
| s 76(4) | Wilfully obstructing an inspector | 1,000 to 5,000 units, or up to 2 years, or both |
| s 94(1)(a) | Unlawfully destroying, damaging or interfering with ICT equipment or facilities | 2,000 to 5,000 units, or 6 months to 2 years, or both |
| s 94(1)(b) | False information or fraudulent documents “related to ICT transactions” | As s 94(1)(a) |
| s 94(1)(c) | Failing or neglecting to comply with licence terms and conditions | As s 94(1)(a) |
| s 94(1)(d), (e) | Bribing an officer; fronting to acquire a licence | As s 94(1)(a) |
| s 95 | Embezzling or diverting funds of the Authority or the Republic under this Act | 5,000 to 10,000 units, or 5 to 20 years, or both |
| s 96 | Obstructing or circumventing technical clearance | 1,000 to 2,000 units, or 6 months to 2 years, or both |
| s 97 | Refusing information to a compliance inspector, delaying access, or concealing documents | 2,000 to 5,000 units, or 12 months to 2 years, or both |
| s 100(1) | False declaration in a licence application; destroying a register | Up to 500 units, or up to 2 years, or both |
| s 100(2) | Intentionally or recklessly causing a cybersecurity breach or system failure in licensed, critical or public ICT | Up to 5,000 units, or up to 5 years, or both |
| s 100(3) | “Fraudulent ICT practices” using regulated infrastructure | Up to 5,000 units, or up to 10 years, or both |
| s 100(5) | Intentionally hosting “critical data” without a licence | Up to 5,000 units, or up to 7 years, or both |
| s 100(7) | Knowingly submitting a false report | A fine of 5,000 units, or up to 5 years, or both |
| s 103(7) | Victimising a whistleblower | 1,000 to 5,000 units, or 6 months to 2 years, or both |
Administrative penalties under s 99 are graded: up to 2,000 units for a minor breach, 10,000 for a significant breach and 50,000 for a serious, repeated, intentional or systemic breach causing material harm.
What works
- The graded administrative scale in s 99, with proportionality factors that include turnover, harm, cooperation and voluntary disclosure (s 99(5)).
- Directors and managers are liable only if they took part in or recklessly permitted the offence, with a due diligence defence, and shareholders are not liable as such (s 98).
- No sanction for a cybersecurity incident where the provider followed recognised standards and took reasonable steps (s 100(8)).
What should change
- One regime for licence breaches. Failing to comply with a licence condition is a crime under s 94(1)(c) and an administrative breach under s 99, so the same conduct can draw a warning or a conviction. Delete s 94(1)(c) and leave licence breaches to s 99.
- One rule for refusing information. A first failure to provide information draws a compliance notice under s 76(3) and an administrative penalty under s 99(1), yet s 97(a) makes refusal a crime carrying at least 12 months if imprisonment is chosen. Restrict s 97 to deliberate concealment, alteration or destruction of documents.
- No minimum sentences. Sections 94(2), 95, 96, 97 and 103(7) set minimum fines and minimum prison terms. Keep the maximums and let courts judge proportion.
- One false-information offence. False information is punished under s 94(1)(b) with at least 2,000 units, under s 100(1) with at most 500 units, and under s 100(7) with a fixed 5,000 units. Replace the three with one offence of knowingly or recklessly giving false or misleading information to the Authority, with a single graded penalty.
- Define every offence. “Critical data” (s 100(5)) and “fraudulent ICT practices” (s 100(3)) are undefined, yet carry up to seven and 10 years. Article 19(11) of the Constitution requires an offence to be “defined” in written law. Define “critical data” by reference to critical information infrastructure designated under the Cybersecurity Act, 2020 (Act 1038), and delete s 100(3), since fraud is already an offence under general criminal law.
- Add a mental element. Sections 94(1)(a) and 96 carry prison terms with no requirement of intent. Insert “knowingly” or “intentionally”.
- Avoid double criminalisation. Section 100(2) may duplicate computer-misuse offences in existing legislation. Either delete it or provide that a person is not charged under this Act and another enactment for the same conduct.
- Publish penalty guidance. Define “minor”, “significant” and “serious” breaches in regulations and publish how penalties are calculated before s 99 is used.
- No permanent bans. Section 100(9) allows “permanent revocation”. Let a person reapply after five years if they show the causes have been addressed.
Procedure, integrity and regulations (ss 101 to 105)
Section 101 gives everyone affected by an adverse decision notice, reasons and a hearing, in line with article 23 of the Constitution. Its emergency exception is too wide, some of its duties bind only the Board, and the regulation-making list needs guardrails on local content.
What these sections do. Before refusing, suspending or revoking a licence, imposing a penalty, closing premises or seizing equipment, the Authority must give notice, state reasons, hear the person and decide in writing (s 101(2)). Immediate action is allowed to prevent serious and imminent harm, with reasons within 48 hours, a hearing within seven days and Tribunal or court confirmation of closures within seven days (s 101(3) to (5)). Board interests go on a public register, senior staff face a one-year cooling-off period, and whistleblowers are protected (ss 102, 103). The Minister makes regulations on 33 listed subjects (s 105).
What works
- A full statutory hearing duty before any adverse action (s 101(2)).
- Emergency action is followed quickly by reasons, a hearing and review (s 101(4), (5)).
- A public register of the interests of Board members, the Director-General, inspectors and consultants (s 102(1), (3)).
- A code of conduct within a year, confidential reporting and protection under the Whistleblower Act, 2006 (Act 720) (s 103).
- Regulations that create a new obligation, fee, penalty, clearance threshold or certification need consultation, an impact assessment and parliamentary scrutiny, and cannot widen licensing (s 105(2), (3)).
What should change
| Provision | Issue | Suggested change |
|---|---|---|
| s 101(3) | Immediate action without a hearing is allowed to protect “the public interest”, besides specific harms, which swallows the rule in s 101(2). | Delete “or the public interest”. |
| s 101(1), (6) to (8) | These duties bind “the Board”, but most decisions will be taken by the Director-General or officers. | Replace “the Board” with “the Authority” throughout s 101. |
| s 101(8), s 91(1) | A request for internal review does not stop the 21-day appeal period running. | “Where review is sought within 14 days, the period for appeal runs from the date of the review decision.” |
| s 102(4), (5) | Inspecting and copying the register of interests costs a fee. | Make the online register free, with charges only for printed copies at cost. |
| s 102(6) | The cooling-off period is one year, and the Board may waive it. | Extend it to two years for the Board, the Director-General and the Deputy, and publish every waiver. |
| s 104(1) | The Authority “may” publish notices and directives on its website. | “shall publish every notice and directive on its website”. |
| s 105(1)(h) | Rules on “Ghanaian content and Ghanaian participation” may conflict with s 37(4) and with Ghana’s trade commitments. | Require any such rules to be consistent with s 37(4) and with Ghana’s international trade obligations, and justified by an impact assessment. |
| s 105(1)(o) | The Minister may prescribe “anti-competition rules in the ICT sector”. | Leave competition rules to the competition authority, with the Authority advising. |
Definitions, transition, repeal and the Schedule (ss 106 to 108)
The transitional provisions protect staff and give new licensees fair time, but s 107(6), read literally, would end every ICT-related licence issued by any public body six months after commencement. That needs urgent correction. The definitions also need a clean-up.
The transition problem. Section 107(6) provides that “a licence, permit or certificate issued by the Ministry or any other public body for matters related to ICT” remains valid for only six months, “unless revoked earlier by the Authority”. That wording could reach licences issued by the National Communications Authority, the Cyber Security Authority or the Bank of Ghana, and would let the Authority revoke them, contrary to s 5(3). It also conflicts with s 107(9), which gives newly licensable services 12 months from the relevant regulations, and s 107(12), which keeps existing authorisations valid “during the applicable transition period”.
What works in the transition
- Staff move to the Authority on terms “not less favourable in aggregate”, and any skills assessment follows labour law and fair procedure (s 107(2) to (4)).
- Services that become licensable get 12 months from the relevant regulations, and start-ups and low-risk providers can have another 12 (s 107(9), (10)).
- Serving public ICT professionals are provisionally recognised for 24 months (s 107(11)).
What should change
| Provision | Issue | Suggested change |
|---|---|---|
| s 107(6), (7) | Could end licences issued by other regulators, and lets the Authority revoke them. | “A licence, permit or certificate issued under the repealed Act, or by the Ministry for a matter now regulated under this Act, remains valid until the end of the period in subsection (9), unless suspended or revoked in accordance with this Act. Nothing in this section affects an authorisation issued by another regulator.” |
| s 107(12) | “The applicable transition period” is not defined. | Refer expressly to the period in s 107(9) and (10). |
| s 106 | Eight terms are defined but never used: adaptive regulation, principles-oriented regulation, risk-based approach, cloud computing, national digital identity services, Digital Economy Act, Government ICT Infrastructure Operator and internet protocol address (used only inside another definition). | Delete them, or use them. |
| s 106 | Key terms are used but not defined: critical data, data sovereignty, high-risk ICT service, ICT professional, government-owned operator, national data integration, commercial ICT infrastructure, digital trust services, fraudulent ICT practices and processing on a significant scale. | Define each, or remove the provisions that depend on it. |
| s 106 | “Public ICT professional” is defined twice, differently. | Keep one definition (see ss 46 and 47). |
| s 106 | “Technology-neutral” is defined, but s 5(1)(a) uses “technology neutrality”. | Align the terms. |
| Schedule | It is headed “Form and Content of Annual Report” and “Regulatory Clarity Matrix” but contains neither. | Complete the annual report form required by s 29(3). The Matrix belongs on the website under s 67, not in the Schedule. |
| s 108 | The repeal of Act 771 is sound, and actions under it are saved. | No change. |
Data protection across the Bill
The Bill respects the Data Protection Commission’s mandate throughout, but it treats privacy as something to coordinate rather than something to build in. The Authority will design the systems that connect government data: identity integration platforms, API gateways and data exchange (s 66(2)). Its own rules for those systems should carry binding safeguards.
What the Bill already does
- It is to be read with the Data Protection Act, 2012 (Act 843) and must not derogate from the Commission’s functions (s 5(2), (3)).
- The Commission leads on personal data, privacy and data controllers’ obligations (ss 65(6)(c), 69(4)).
- Personal data is excluded from the Bill’s main publication duties (ss 25(4), 28(5), 34(5), 47(5), 86(5), 102(3)).
- Sandbox participants stay bound by data protection law (s 60(5)), and inspectors are limited in their access to personal data (s 75(8)).
- Personal data breaches reported to the Authority are coordinated with the Commission (s 73(9)).
Where it falls short
- Impact assessments appear only as guidelines to be issued with the Commission (s 5(7)), and the Commission’s requirements apply only to processing “on a significant scale”, which is undefined (s 5(6)).
- The National Digital Architecture must set standards for data exchange and authentication, but carries no duty of minimisation, purpose limitation or access logging (s 53).
- The Minister, not the Commission, may prescribe impact assessment requirements for public ICT (s 105(1)(v)).
- Shared information may be reused for a new purpose in “the public interest” (s 72(6)), and inspectors may access personal data where “necessary” without a warrant (s 75(8)).
- “Data sovereignty”, undefined, can shape licensing decisions (s 37(3)).
Article 18(2) of the Constitution permits interference with privacy of communication only “in accordance with law” and where “necessary in a free and democratic society”. Systems built to that standard should have the safeguards in their design rules, not only in coordination arrangements.
Recommended amendments
- Binding impact assessments. Replace s 5(6) and (7) with: “Before technical clearance under section 52 of a project that involves digital identity, data exchange between public institutions, a shared platform or large-scale processing of personal data, the public institution shall carry out a data protection impact assessment in the form required by the Data Protection Commission, obtain the Commission’s comments, and publish a summary in the ICT Project Registry.”
- Privacy in the Architecture. Add to s 53(2): privacy by design and by default; data minimisation and purpose limitation for every data exchange; and a log of each access to personal data through shared platforms, available to the Commission.
- The Commission sets assessment rules. Amend s 105(1)(v) so that impact assessment requirements are prescribed on the recommendation of the Data Protection Commission.
- The Commission as co-regulator. Name the Commission as a co-regulator of identity integration platforms, API gateways and national data integration in ss 65 and 66.
- Close the exceptions. Delete “the public interest” from s 72(6), and require a warrant for inspectors’ access to personal data under s 75(8).
- Define or drop “data sovereignty” in s 37(3), so that it cannot become a data localisation rule by practice.
What the Bill means in practice
If passed as drafted, the Bill would change day-to-day obligations most for public institutions and for cloud, data centre and software providers. The table sets out, for each group, what changes and what it can do now.
| Group | What changes | What to do now |
|---|---|---|
| Public institutions (ministries, departments, agencies, assemblies and state-owned entities) | Technical clearance before major ICT projects (s 52); every project registered within 30 days (s 54); competitive procurement for hosting and shared services (s 31); contracts with service levels and exit terms (s 33); incident reporting (s 73(6)); audits and improvement plans (s 56); certified ICT staff within 24 months (ss 46, 107(11)). | List current and planned ICT projects; check hosting contracts for data portability and exit terms; plan staff certification; set up an incident reporting route. |
| Cloud, data centre and software providers | Likely licensable under s 36, with ownership, technical and financial disclosure (s 37(2)), annual reports within 90 days (s 73), incident reporting, approval of changes of control (s 49) and audits (s 79). Government hosting opens to competition (s 31). | Map services against the s 36 categories; prepare ownership and capacity documents; take part in consultation on the thresholds and fees, which will be set by regulations. |
| Start-ups, freelancers and small firms | Exempt from licensing below thresholds to be prescribed (s 35(3)); access to the sandbox (s 60); up to 12 extra months to comply (s 107(10)). As drafted, every private ICT professional must join a recognised body (s 46(9)). | Press in consultation for clear, generous thresholds and for deletion of s 46(9) to (11). |
| ICT professionals | Public ICT professionals need certification from the Authority or a recognised body (s 46(1)). As drafted, private-sector professionals need membership of a recognised body (s 46(9)). | Professional bodies should prepare to seek recognition under s 46(3). |
| Other regulators | Seats on the Regulatory Coordination Committee (s 71); memoranda of understanding, a single window and a published Regulatory Clarity Matrix (ss 64 to 68). | Agree lead-regulator arrangements and a single incident notification route before commencement. |
| Staff of the National Information Technology Agency | Transfer on terms not less favourable in aggregate, and a skills assessment within 12 months under fair procedure (s 107(2) to (4)). | Seek clarity on the assessment criteria and redeployment options. |
| Citizens and service users | A right to complain when a licence holder fails them (s 3(1)(w)), possible compensation orders (s 77(1)(e)), accessibility standards (s 61) and published enforcement decisions (s 47). | Watch for the complaints procedure in regulations; ACTPOL recommends putting its time limits in the Act. |
Implementation: what the Bill requires to be made
The Bill depends on more than 20 regulations, guidelines, frameworks and registers, but sets deadlines for only three of them. Licensing, incident reporting and the single window cannot work until their instruments exist, so the Act should fix the order in which they are made.
| Instrument | Section | Made by | Deadline in the Bill |
|---|---|---|---|
| Tribunal rules of procedure | s 90(1) | Minister, by legislative instrument | 90 days after commencement |
| Skills assessment of transferred staff | s 107(3) | Authority | 12 months after commencement |
| Code of conduct | s 103(1) | Board | One year after commencement |
| Licence sub-categories, thresholds and conditions | ss 36(3), 105(1)(a) | Minister, by regulations | None. Services that become licensable have 12 months from these regulations (s 107(9)) |
| Published terms, thresholds and timelines for each licence | s 36(2) | Authority | None |
| Fees | ss 38(2), 105(1)(q) | Minister, by regulations | None |
| Technical clearance thresholds | s 52(3) | Minister, by regulations | None |
| Incident notification requirements and timelines | ss 73(7), 105(1)(w) | Minister, by regulations | None |
| Regulatory Clarity Matrix | s 67 | Authority, with regulators | None for the first; updates every two years |
| Classification guidelines for digital services | s 66(7) | Authority, with regulators | None |
| Single-window mechanism | s 68 | Authority, with regulators | None |
| Data protection impact assessment guidelines | s 5(7) | Authority, with the Data Protection Commission | None |
| Certification criteria and procedure | s 46(2) | Authority | None; serving staff provisionally recognised for 24 months |
| National Digital Architecture | s 53 | Authority | None |
| ICT Project Registry | s 54 | Authority | None |
| Model service-level standards | s 33(4) | Authority (optional) | None |
| Sandbox framework and guidelines | s 60(1), (4) | Authority | None; annual report on its operation |
| Guidelines on closure powers | s 48(6) | Authority | None |
| Dispute Resolution Committee rules | s 82 | Board | None |
| National ICT accessibility standards | s 61(2) | Authority | None |
| Board qualification requirements | s 6(5) | The Act or regulations | None |
Recommendations
- Publish a roadmap. Require the Authority to publish, within three months of commencement, a timetable for every instrument in this table, and to report progress in each annual report.
- Sequence licensing. Provide that no licensing obligation takes effect until the licence regulations, fees, the single window, the first Regulatory Clarity Matrix and the incident notification rules are all in force.
- Set dates for the essentials. Give the Matrix, the licence regulations and the impact assessment guidelines each a deadline of 12 months after commencement.
Drafting corrections
These technical errors should be corrected before passage, because a law this detailed will be read closely by courts and litigants.
| Section | Error | Correction |
|---|---|---|
| s 3(1) | Two paragraphs are lettered (c). | Renumber the paragraphs. |
| ss 3, 101(1), 106(2) and s 5(2) | Most references are to an “Electronic Transactions Act, 2026 (Act …)”, not yet enacted; s 5(2) cites the Electronic Transactions Act, 2008 (Act 772). | Cite one Act consistently, and tie commencement to the 2026 Act if it is relied on. |
| ss 48(6), 60(4) | “The Authority shall guidelines” has no verb. | “The Authority shall issue guidelines”. |
| s 106 | “Public ICT professional” is defined twice, in different terms. | Keep one definition. |
| s 106 | Eight defined terms are never used. | Delete them, or use them. |
| s 106, s 5(1)(a) | “Technology-neutral” is defined; “technology neutrality” is used. | Align the terms. |
| ss 31 to 34, s 106 | “Government-owned operator” is used; “Government ICT Infrastructure Operator” is defined. | Use one term. |
| s 31(3), (4) | Subsection (3) confines the operator to designated systems; subsection (4) assumes it competes for others. | Reconcile as proposed under ss 31 to 34. |
| s 28(2), (3) | The Board and the Auditor-General both have six months from the year end. | Board submits within three months. |
| s 29(3), Schedule | The Schedule referred to is empty. | Complete it. |
| s 101(1), (6) to (8) | Duties bind “the Board”, not “the Authority”. | Replace with “the Authority”. |
| s 107(12) | “The applicable transition period” is undefined. | Refer to s 107(9) and (10). |
| ss 10, 18, 30, 80, 91, 104, 108 | Marginal headings listed in the arrangement of sections are missing from the text. | Restore them. |
| s 105 | The opening paragraph is not numbered (1), although subsections (2) and (3) follow. | Number it subsection (1). |
Sources
- National Information Technology Authority Bill, 2026, revised draft of September 2026 (69 pages), shared with ACTPOL through OAKS Legal. All section references are to this draft.
- Constitution of the Republic of Ghana, 1992, articles 18(2), 19(11) and 23, checked on 25 September 2026.
- Other Acts are cited as the Bill cites them: the Data Protection Act, 2012 (Act 843), the Cybersecurity Act, 2020 (Act 1038), the Electronic Transactions Act, 2008 (Act 772), the National Communications Authority Act, 2008 (Act 769), the Public Procurement Act, 2003 (Act 663), the Public Financial Management Act, 2016 (Act 921), the Whistleblower Act, 2006 (Act 720) and the National Information Technology Agency Act, 2008 (Act 771).