← Back to all research
CYBER LAW & DIGITAL RIGHTS · SEMESTER 1 · MA IT LAW

Survey of International Cybercrime Conventions and the Adequacy of Ghana's Legal Regime

Coursework written during my MA in Information Technology Law at the University of Ghana, 2025–2026. Presented as an academic working paper, not a peer-reviewed publication or current legal advice. Original language and arguments retained.

Introduction

Ghana’s cybercrime framework has developed through a constellation of statutes, most notably the Electronic Transactions Act, 2008 (Act 772)32, the Cybersecurity Act, 2020 (Act 1038)33, the Data Protection Act, 2012 (Act 843)34, and the Criminal Offences Act, 1960 (Act 29)35. This paper assesses these enactments vis-à-vis international instruments, particularly the Convention on Cybercrime (Budapest Convention),36 together with its First37 and Second38 Additional Protocols, the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention),39 and the United Nations Convention against Cybercrime (UN Convention).40 This paper further critically examines whether Ghana’s legal regime adequately addresses contemporary cyber threats such as racist and xenophobic online propaganda, large-scale digital intellectual property piracy, cyber espionage, aggravated attacks on critical information infrastructure, and cross-border access to electronic evidence.

Nature Of Cyber Offences

Cybercrime is divided into cyber-dependent offences, crimes directed against computer systems and data, and cyber-enabled offences, where technology is used as a tool to commit traditional crimes. The Budapest Convention defines a computer system as any device or interconnected devices capable of automatic data processing.41 This technological neutrality is essential as criminal harm is no longer confined to physical trespass or tangible property.

In Ghana, prevalent cyber threats include hacking, denial-of-service attacks, phishing, SIM box fraud, online banking fraud, identity theft, sextortion, online child sexual exploitation, and cyber-enabled money laundering.42 Ransomware attacks targeting financial institutions and public infrastructure have also emerged as material risks. Ransomware involves unauthorised encryption of data, followed by demands for payment, often in cryptocurrency, in exchange for access restoration. Distributed Denial-of-Service (DDoS) attacks overwhelm targeted systems with coordinated traffic to render services unavailable. Cyber espionage involves unauthorised access to state or strategic systems to obtain confidential governmental or security information.

These threats impact not only private victims but Ghana’s sovereign interests. Large-scale ransomware targeting financial institutions threatens systemic banking stability and investor confidence. Cyber espionage undermines national security and strategic autonomy. DDoS attacks against Critical Information Infrastructure risk disruption of energy, telecommunications, health, and electoral systems. Identity theft and data breaches erode personal privacy and economic security. The adequacy of Ghana’s legal regime must therefore be assessed not only in terms of compliance with treaties, but also its capacity to safeguard macroeconomic stability, democratic resilience, and the fundamental rights of data subjects.

Although Ghana’s legislation criminalises unauthorised access, interference, and related conduct,43 it does not categorise ransomware deployment, aggravated DDoS attacks against critical infrastructure, or cyber espionage as distinct offences. Instead, such conduct must be prosecuted under broader provisions concerning unlawful access, interference, fraud, or extortion.44

At the content layer, the non-consensual dissemination of intimate images and coordinated online hate speech present regulatory and human rights challenges. The First Additional Protocol to the Budapest Convention requires criminalisation of racist and xenophobic material disseminated through computer systems.45 Ghana has no technologically specific offence addressing racist or xenophobic online propaganda as such. While section 208 of Act 29 criminalises the publication of false news, and other provisions address offensive conduct,46 there is no explicit statutory offence targeting racist or xenophobic digital incitement. Constitutional protection of freedom of expression must also be considered.47

International Conventions

The Budapest Convention, adopted in 2001 under the auspices of the Council of Europe, remains the most comprehensive binding treaty on cybercrime.48 Its structure rests on three pillars: substantive offences, procedural investigative powers, and international cooperation. Articles 2–6 require criminalisation of illegal access, illegal interception, data interference, system interference, and misuse of devices.49 Articles 7–10 extend liability to computer-related forgery and fraud, child sexual abuse material, and copyright infringement.50 Article 15 mandates respect for human rights, including proportionality and safeguards for fundamental freedoms.51

Article 22 requires State Parties to exercise jurisdiction over offences against their systems, citizens abroad, or where extraterritorial effects manifest domestically.52 This ensures cross-border cybercrime falls within prosecutorial reach.

Articles 16–21 provide for expedited preservation of stored data, production orders, search and seizure of computer systems, and real-time collection of traffic data.53 Article 35 establishes a 24/7 network of contact points for immediate international cooperation.54

The First Additional Protocol requires criminalisation of racist and xenophobic acts committed through computer systems.55 The Second Additional Protocol modernises cooperation mechanisms via direct disclosure of subscriber information, emergency mutual assistance, joint investigative measures, and expedited cross-border data sharing with service providers.56 These reduce delays associated with traditional mutual legal assistance processes, particularly for volatile cloud-based electronic evidence.

The Malabo Convention, adopted by the African Union in 2014 and entering into force in 2023,57 integrates cybersecurity, data protection, and electronic commerce within a continental framework. It mandates criminalisation of offences affecting ICT system confidentiality, integrity, and availability, identity theft, child pornography, xenophobic material, and attacks against critical infrastructure.58 It also addresses personal data protection and e-commerce regulation, thereby situating cybersecurity within a broader governance architecture. However, unlike the Budapest Convention, it does not establish a standing operational cooperation mechanism such as a 24/7 contact network, and its implementation remains dependent on domestic legislative action by Member States.

The UN Convention, adopted by the General Assembly on 24 December 2024,59 seeks to establish a universal framework. It extends beyond the Budapest Convention by addressing serious crimes committed using ICT systems more broadly, incorporating provisions on corporate liability, asset recovery, money laundering, confiscation, technical assistance, and enhanced mutual legal assistance obligations.60 It also contains detailed provisions on capacity-building for developing states. Although not yet in force, it reflects an effort to universalise minimum standards and reduce fragmentation between regional regimes.

Ghana’s Legal Framework

Act 77261 creates offences of unauthorised access, unauthorised modification of data, interference with systems, possession of illegal devices, electronic fraud, and child pornography.62 These substantially replicate Articles 2–6 of the Budapest Convention.63

Act 2964 immediately follows Act 772 in analysis because it criminalises the substantive harms resulting from technological intrusion. Hacking under Act 772 may coexist with stealing, fraud, extortion, conspiracy, or forgery under Act 2965. This complementarity ensures that cyber intrusion does not escape liability merely because it is technologically mediated.

Act 103866 establishes a governance and regulatory framework beyond criminalisation. It creates the Cyber Security Authority, provides for licensing of cybersecurity service providers, imposes obligations on operators of Critical Information Infrastructure, mandates incident reporting, and empowers the Authority to issue directives and administrative sanctions.67 It therefore reflects a risk-regulation model rather than a purely penal model.

While Ghana’s Cybersecurity Act and related statutes provide enforcement powers, oversight mechanisms for interception, search, and seizure are not comprehensively codified. Comparative analysis with Article 15 of the Budapest Convention indicates a need for proportionality safeguards, judicial authorisation thresholds, and procedural review to balance investigative efficacy with constitutional rights, including privacy and expression.68

While Act 1038 strengthens institutional coordination and regulatory oversight, it does not expressly classify ransomware, cyber espionage, or aggravated DDoS attacks against critical infrastructure as distinct offences. Nor does it comprehensively codify corporate criminal liability for systemic cybersecurity failures, relying instead on general principles of attribution.

Act 843 criminalises unlawful processing and unauthorised disclosure of personal data.69 The Electronic Communications Act, 2008 (Act 775)70, the Economic and Organised Crime Office Act, 2010 (Act 804)71, and the Anti-Money Laundering Act, 2020 (Act 1044)72 reinforce enforcement capacity. Admissibility of electronic evidence is governed by the Evidence Act, 1975 (NRCD 323)73, which recognises documentary and computer-generated evidence subject to authentication.

Ghana acceded to the Budapest Convention on 3 December 2018, and it entered into force in Ghana on 1 April 2019.74 Ghana, therefore, participates in the Article 35 24/7 network.75 Ghana signed the Second Additional Protocol on 28 June 202376 but has not signed the First Additional Protocol. Without ratification, Ghana has no treaty obligation regarding the First Additional Protocol, and Second Additional Protocol cooperation mechanisms remain legally unavailable in practice.

Critical Examination Of The Legal Regimes

Measured against international instruments, Ghana’s legal framework demonstrates substantial compliance with core cyber-dependent offences. Illegal access, interference, misuse of devices, computer-related fraud, and child sexual exploitation are expressly criminalised77.

However, Ghana lacks a specific offence criminalising racist and xenophobic online propaganda comparable to the First Additional Protocol.78 Although constitutional protections for freedom of expression under Article 21 of the 1992 Constitution must be preserved, the absence of an offence addressing racist incitement creates a gap relative to international standards.

Although copyright infringement is regulated under the Copyright Act, 2005 (Act 690)79, Ghana’s cyber statutes do not integrate large-scale online piracy within the cybercrime legal framework as structured under Article 10 of the Budapest Convention.80 This separation may complicate transnational investigations where cybercrime and intellectual property violations overlap.

Ransomware is not defined as a distinct offence, and cyber espionage is not codified as an aggravated cyber-dependent crime. In circumstances involving attacks on energy grids, financial clearing systems, or electoral infrastructure, the absence of aggravated sentencing provisions may limit deterrence and symbolic denunciation of conduct threatening national sovereignty.

Procedurally, although Ghana participates in the Budapest 24/7 network81, its Mutual Legal Assistance Act, 2010 (Act 807) continues to rely on conventional diplomatic channels that may not satisfy the expedited preservation and direct cooperation mechanisms contemplated by Articles 16–21 of the Convention and elaborated under the Second Additional Protocol.82 Act 807 does not provide emergency disclosure orders directed at foreign service providers, nor does it codify rapid cross-border subscriber information requests. This may create delays in cases involving volatile cloud-stored evidence.

Practical enforcement is constrained by limited digital forensics infrastructure, shortages of trained investigators and prosecutors, and uneven awareness across agencies.83 These operational limitations hinder timely investigation and prosecution of cyber offences, particularly transnational attacks, affecting overall adequacy.

Corporate liability for systemic cybersecurity failures is not consolidated within a cybersecurity-specific statutory regime. Given the increasing reliance on private operators for critical digital infrastructure, clearer statutory articulation of institutional responsibility would enhance deterrence and align Ghana with emerging standards reflected in the UN Convention.84

These gaps affect both state interests and individual protection. Delays in cross-border cooperation risk impunity in transnational fraud cases affecting Ghanaian citizens. Insufficiently calibrated offences may undermine deterrence against infrastructure attacks. Absence of targeted hate-speech provisions leaves minority communities potentially vulnerable to coordinated online incitement. Adequacy must therefore be measured not only in terms of formal criminalisation but in terms of practical enforceability, deterrent capacity, and rights protection.

Recommendations

Ghana should harmonise Acts 1038 and 807 to incorporate expedited preservation orders, emergency disclosure mechanisms, and structured cooperation with foreign service providers consistent with Articles 16–21 of the Budapest Convention and the Second Additional Protocol.

Ghana should ratify the Second Additional Protocol to benefit from expedited cooperation mechanisms.

Ghana should consider ratifying the First Additional Protocol and defining racist and xenophobic incitement with precise intent thresholds and proportionality safeguards consistent with Article 21 of the 1992 Constitution.

Amendments to Act 772 could expressly incorporate ransomware deployment, aggravated DDoS attacks, and cyber espionage targeting state systems as distinct offences with enhanced penalties.

Statutory clarification of corporate criminal liability for systemic cybersecurity negligence would align Ghana’s framework with evolving international standards and reinforce accountability among critical digital infrastructure operators.

Finally, ratification of the Second Additional Protocol would modernise Ghana’s cross-border electronic evidence regime and strengthen interoperability with international partners.

Conclusion

Cybercrime presents a dynamic and transnational threat that tests the adaptability of domestic legal systems. Ghana’s legislative architecture, anchored in Act 772, Act 1038, Act 843, and Act 29, substantially criminalises core cyber-dependent and cyber-enabled offences and aligns in large measure with the principal substantive requirements of the Budapest Convention.

However, adequacy is not measured solely by substantive criminalisation. It also depends on coherence, procedural efficiency, institutional accountability, and international interoperability. In relation to racist and xenophobic online content, digital piracy integration, ransomware classification, cyber espionage codification, aggravated infrastructure attacks, corporate liability structuring, and expedited cross-border evidence access, Ghana’s cybercrime legal regime reveals identifiable gaps.

The way forward lies in calibrated harmonisation, refined statutory definitions, strengthened procedural cooperation, institutional accountability, integrated human rights safeguards, and alignment with international standards while protecting constitutional rights.

Source notes

  1. Electronic Transactions Act 2008 (Act 772).
  2. Cybersecurity Act 2020 (Act 1038).
  3. Data Protection Act 2012 (Act 843).
  4. Criminal Offences Act 1960 (Act 29).
  5. Council of Europe, Convention on Cybercrime (adopted 23 November 2001, entered into force 1 July 2004) ETS No 185.
  6. Council of Europe, First Additional Protocol to the Convention on Cybercrime, CETS No 189, 28 January 2003.
  7. Council of Europe, Second Additional Protocol to the Convention on Cybercrime (adopted 12 May 2022) CETS No 224.
  8. African Union, African Union Convention on Cyber Security and Personal Data Protection (adopted 27 June 2014, entered into force 8 June 2023).
  9. United Nations General Assembly, United Nations Convention against Cybercrime (adopted 24 December 2024) (not yet in force).
  10. Budapest Convention (n 5) art 1(a).
  11. Electronic Transactions Act 2008 (Act 772) ss 122–127, 136.
  12. ibid ss 122–125.
  13. Criminal Offences Act, 1960 (Act 29) ss 131, 151.
  14. First Additional Protocol (n 6) arts 3–6.
  15. Criminal Offences Act, 1960 (Act 29) s 208.
  16. Constitution of the Republic of Ghana 1992 art 21(1)(a).
  17. Budapest Convention (n 5).
  18. ibid, art 2-6
  19. ibid, art 7-10
  20. ibid, art 15
  21. ibid, art 22.
  22. ibid, arts 16–21.
  23. ibid, art 35
  24. First Additional Protocol (n 6) arts 3–6.
  25. Second Additional Protocol (n 7) art 6-12
  26. AU Convention (n 8)
  27. ibid, arts 25-31.
  28. UN Convention (n 9)
  29. ibid arts 5–14, 23–35.
  30. Electronic Transactions Act 2008 (Act 772)
  31. ibid, ss 122–138.
  32. Budapest Convention (n 5) arts 2–6.
  33. Offences Act 1960 (Act 29)
  34. Criminal Offences Act 1960 (Act 29) ss 131, 151.
  35. Cybersecurity Act 2020 (Act 1038)
  36. Cybersecurity Act 2020 (Act 1038) ss 2–4, 21–29, 35–43.
  37. Budapest Convention (n 5) art 15; Cybersecurity Act, 2020 (Act 1038), ss 10–12.
  38. Data Protection Act 2012 (Act 843) ss 26, 35, 56–60.
  39. Electronic Communications Act 2008 (Act 775) ss 76–80.
  40. Economic and Organised Crime Office Act 2010 (Act 804) ss 2–3.
  41. Anti-Money Laundering Act 2020 (Act 1044) ss 1–4, 92–98.
  42. Evidence Act 1975 (NRCD 323) ss 7, 129.
  43. Council of Europe Treaty Office, ‘Chart of signatures and ratifications of Treaty 185 – Convention on Cybercrime’ <https://www.coe.int/en/web/conventions/full-list;?module=treaties-full-list- signature&CodePays=GHA> accessed 21 February 2026.
  44. Budapest Convention (n 5)
  45. <https://www.csa.gov.gh/ghana-signs-council-of-europe-second-additional-protocol-to-the%20-convention-on-cybercrime> accessed 21 February 2026
  46. Electronic Transactions Act 2008 (Act 772); Budapest Convention (n 5) arts 2–6.
  47. First Additional Protocol (n 6) arts 3–6.
  48. Copyright Act 2005 (Act 690) ss 41–43.
  49. Budapest Convention (n 5) art 10.
  50. ibid, art 35.
  51. Mutual Legal Assistance Act 2010 (Act 807) ss 1–3, 13–18; Budapest Convention (n 5) arts 16–21; Second Additional Protocol (n 7) arts 6–12.
  52. Ghana Cyber Security Authority, Annual Report 2023 (Accra 2023) 12–18; Ministry of Communications, National Cybersecurity Strategy 2022–2026 22–25.
  53. UN Convention (n 9) arts 5–14, 23–35.
Explore more writing ↗