Personal Data Protection and Privacy Act, 2025
gm-pdpp-2025 · Act
The Personal Data Protection and Privacy Act, 2025 (PDPPA) is The Gambia's first comprehensive personal data protection statute. The National Assembly passed the Act unanimously on 29 September 2025, and President Adama Barrow assented to it on 7 November 2025, making The Gambia one of the later West African states to enact standalone data protection legislation. The Act applies to the processing of personal data wholly or partly by automated means, and to non-automated processing where personal data forms part of a structured set accessible according to specific criteria. It has extra-territorial reach, applying to controllers and processors outside The Gambia where their processing relates to data subjects located in the country. A notable structural departure from the ECOWAS regional model is the absence of a prior notification or registration requirement. Controllers may commence processing without first registering with the supervisory authority, in line with the post-GDPR accountability model. Instead, the Act places emphasis on governance mechanisms: controllers must demonstrate compliance through records of processing, impact assessments, and appointment of data protection officers in specified circumstances. The Act codifies fundamental data protection principles, including lawful, fair and transparent processing; purpose limitation; data minimisation; accuracy; storage limitation; and integrity and confidentiality. It establishes a legal basis framework for processing, including consent, contractual necessity, legal obligation, vital interests, public task, and legitimate interests. Data subjects are granted rights of access, rectification, erasure, objection, restriction of processing, and data portability. Controllers must notify the Information Commission within 72 hours of becoming aware of a personal data breach, and must notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms. Rather than creating a new regulatory body, the Act designates the Information Commission, established under the Access to Information Act, 2021, as the supervisory authority. The Commission is granted powers to investigate complaints, conduct independent inquiries, enter and search premises with warrants, issue binding enforcement notices, and impose administrative fines. The maximum penalty for a legal entity is the greater of GMD 1,000,000 (approximately EUR 11,500) or 5% of the preceding year's gross income; aggravated offences, including unlawful sale of personal data, carry penalties of up to 10 years' imprisonment and fines of not less than GMD 10,000,000 for corporate offenders. Note: The precise commencement date and whether any transitional provisions apply are flagged for reviewer confirmation. No official gazette URL was confirmed at time of drafting; reviewer should locate the primary legislative text. Source language: English.
- Controllers may process personal data without prior registration with the Information Commission, consistent with a post-GDPR accountability model; lawfulness is demonstrated through governance measures rather than pre-clearance.
- Data subjects have rights of access, rectification, erasure, restriction, portability, and objection enforceable against controllers.
- Breach notification to the Information Commission is required within 72 hours of discovery; high-risk breaches must also be communicated to affected data subjects without undue delay.
- The Act applies extraterritorially to controllers and processors outside The Gambia where processing relates to individuals located in the country.
- Maximum administrative fine for a legal entity is GMD 1,000,000 or 5% of annual gross income, whichever is greater; aggravated offences carry fines of not less than GMD 10,000,000 and up to 10 years' imprisonment.
- Data Protection Officers must be appointed in specified circumstances.
- The Information Commission is the designated supervisory authority, combining its existing access-to-information mandate with data protection enforcement.
- Cross-border transfers are restricted and require adequate protection or appropriate safeguards.