Draft Law on Cybercrime and the Use of Social Media (Anteproyecto de Ley sobre ciberdelincuencia) (Equatorial Guinea)
gq-cyber-draft · Draft Bill
As at June 2026, Equatorial Guinea has no enacted standalone cybercrime statute. Cyber-related conduct is addressed through scattered provisions of the Penal Code and the Telecommunications Law, supplemented by Personal Data Protection Law No. 1/2016 of 22 July 2016. A dedicated cybercrime bill, which also governs the use of social media, has, however, been advancing through the legislature. In April 2024 the parliamentary panel reviewing the draft, chaired by the chamber's president Gaudencio Mohaba Messu, adopted the articles defining computer crimes and cybercrimes together with the associated penalties and fines, moving the country closer to enacting the law. The draft law defines and criminalises a broad set of offences. Computer-related crimes focus principally on the integrity of computer systems, unauthorised access to computer systems, programmes or data, and the illegal interception of communications. It also covers computer fraud and computer espionage aimed at unduly obtaining sensitive personal data or confidential public information, and breaching restricted or protected computer systems without authorisation. The cybercrime provisions extend to impersonation or takeover of another person's computer identity, the unauthorised disclosure of information stored on a computer or technological device, the unlawful use of personal data, the unauthorised transfer of public information classified as confidential, and conduct that violates computer systems or data or endangers the security and sovereignty of the State. Because the bill also regulates social-media use, it carries a content-governance dimension that has attracted free-expression commentary. Equatorial Guinea participates in regional and continental frameworks, including ECCAS and the African Union's cybersecurity initiatives associated with the Malabo Convention, which inform the design of the draft law. Until the bill is promulgated, enforcement of cyber-related offences continues to rely on the existing Penal Code and Telecommunications Law provisions. This record is provided for tracking purposes; no consolidated official text of the bill has been located, and the instrument should be re-checked for enactment status, final title, number and date.
- Status as at June 2026: no enacted standalone cybercrime law; pending draft bill advancing through the legislature (articles defining offences and penalties adopted by the parliamentary panel in April 2024)
- Draft criminalises offences against computer-system integrity: unauthorised access to systems, programmes or data, and illegal interception of communications
- Covers computer fraud and computer espionage to obtain sensitive personal data or confidential public information
- Covers identity takeover/impersonation, unauthorised disclosure of stored information, unlawful use of personal data, and unauthorised transfer of confidential public information
- Includes offences endangering State security/sovereignty and regulates the use of social media (content-governance dimension)
- Interim framework: Penal Code and Telecommunications Law provisions, alongside Data Protection Law No. 1/2016