Rights
No comprehensive data protection statute; sectoral rules and a cybersecurity act apply
Sierra Leone has not enacted a general data protection law. Personal data is addressed indirectly through the Cybersecurity and Cybercrime Act 2021, the constitutional privacy guarantee, and sectoral banking and telecommunications rules, so there is no data protection authority or general lawful-basis requirement.
Key rules
- Jurisdiction β No dedicated authority; High Court under s.28 for constitutional privacy claims; sector regulators for their licensees.
Governing law
- Cybersecurity and Cybercrime Act, 2021 β Criminal offences and investigatory powers; not a data protection framework.
- Constitution of Sierra Leone, 1991 (s.22 β Privacy of home and correspondence.)
In practice
The atlas records the absence of a general regime as the material fact. The Cybersecurity and Cybercrime Act 2021 criminalises unauthorised access, interception and data interference and creates investigatory powers, but it is a criminal statute rather than a data protection framework: it does not establish processing principles, data subject rights or a supervisory authority. Section 22 of the Constitution protects the privacy of home and property and correspondence, enforceable under s.28. The Bank of Sierra Leone imposes customer confidentiality duties on financial institutions, and NATCOM regulates telecommunications operators including some subscriber data obligations. Drafting of a comprehensive data protection bill has been reported in successive digital strategy documents but no Act is in force, so cross-border transfer restrictions and breach notification duties of the GDPR type do not apply.