
Ghana Office of Registrar Fined GH¢240k for Unlicensed Cybersecurity
Summary
- The Office of the Registrar of Companies (ORC) has been fined GH¢240,000 for engaging an unlicensed cybersecurity provider.
- The Cybersecurity Authority (CSA) found that the ORC had failed to comply with two directives requiring it to engage only licensed Cybersecurity Service Providers (CSPs).
- Purpleline Solutions Limited was also sanctioned and fined GH¢120,000 for providing cybersecurity services without a license.
- The CSA has warned institutions against engaging unlicensed cybersecurity service providers while cautioning companies against providing regulated cybersecurity services without the appropriate licence.
What Happened
Entities are required to obtain the requisite license before commencing the provision of regulated cybersecurity services
The Office of the Registrar of Companies (ORC) has been fined GH¢240,000 for engaging an unlicensed cybersecurity provider. The Cybersecurity Authority (CSA) found that the ORC had failed to comply with two directives requiring it to engage only licensed Cybersecurity Service Providers (CSPs). Despite being directed to do so on June 15, 2026, the ORC proceeded to engage Purpleline Solutions Limited, which was not licensed by the CSA. This breach of Ghana's cybersecurity requirements has resulted in significant penalties for both the ORC and Purpleline Solutions Limited.
Legal Context
The Cybersecurity Act 2020 (Act 1038) sets out clear guidelines for entities operating in the cybersecurity sector. Section 92 of the Act requires Critical Information Infrastructure institutions to engage only licensed CSPs. The CSA has warned that engaging unlicensed providers can have serious consequences, including fines and penalties. In this case, the ORC was fined 10,000 penalty units for each instance of non-compliance, amounting to GH¢240,000.
Why It Matters
The sanctions imposed on the ORC and Purpleline Solutions Limited serve as a reminder of the importance of cybersecurity compliance. The CSA has emphasized that entities cannot engage unlicensed providers and expect them to regularize their status. This case highlights the need for organizations to verify the licensing status and appropriate licence tier of cybersecurity service providers before awarding contracts or allowing them to operate. Lawyers advising clients on cybersecurity compliance should take note of this development, as it underscores the risks associated with non-compliance.
Practical Implications
Lawyers advising clients on cybersecurity compliance should take note that the Cybersecurity Authority has warned institutions against engaging unlicensed providers, and that an application for a license does not authorise a company to operate as a Cybersecurity Service Provider.
Source
How does this affect you?
Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.
Wansom is AI and can make mistakes.
