Disclaimer: This guide is for general technology and security readiness purposes only. It is not legal advice. Organisations should consult qualified legal counsel for formal interpretation of their legal obligations under the DPA 2025.
Why the DPA 2025 Matters
The Gambia's Data Protection and Privacy Act 2025 is now in force. Organisations that collect, store, use, or share personal data in The Gambia are now operating within a legal framework that establishes clear expectations for how that data is handled, protected, and governed.
This matters for every type of organisation — not just large banks or government institutions. Schools, clinics, NGOs, professional firms, and small businesses all handle personal data in the course of their work. Staff records, client information, patient files, student data, donor records — all of this falls within the scope of data protection obligations.
The DPA 2025 is now in force, and organisations should prepare to understand their obligations as data controllers and data processors. Those that cannot demonstrate appropriate technical and organisational security measures are exposed to regulatory attention and reputational risk.
Who Should Pay Attention
The DPA 2025 applies to any organisation that:
- Collects personal data about individuals — customers, clients, patients, students, staff, or beneficiaries
- Stores personal data on computers, servers, cloud systems, or paper records
- Uses or processes personal data to deliver services or conduct business
- Shares or transfers personal data to third parties or service providers
This covers a wide range of organisations operating in The Gambia — including financial institutions, healthcare providers, educational institutions, government agencies, NGOs, legal firms, hospitality businesses, and SMEs.
Data Controllers and Data Processors
Two key roles are established under data protection frameworks: the data controller and the data processor.
A data controller is an organisation that determines the purpose and means of processing personal data. Most organisations are data controllers — they decide what data to collect, how to store it, and what to do with it.
A data processor is an organisation that processes personal data on behalf of a data controller. Technology vendors, cloud service providers, payroll processors, and IT service providers may be data processors when they handle data belonging to their clients.
Both roles carry obligations. As an IT and cybersecurity service provider, MI Secure Tech Solutions may act as a data processor for client organisations. We take that responsibility seriously.
Common Types of Personal Data Organisations Handle
Personal data means any information relating to an identified or identifiable individual. Organisations commonly handle:
- Staff names, contact details, employment records, and payroll information
- Customer and client names, contact details, account information, and transaction records
- Patient names, contact details, health records, and appointment histories
- Student names, academic records, and family contact details
- Donor names, funding records, and beneficiary information
- Email correspondence containing personal information
- CCTV footage where individuals are identifiable
If your organisation holds any of these types of information, you are operating as a data controller and your data protection obligations apply.
Technology and Security Areas to Review
Data protection legislation requires organisations to implement appropriate technical and organisational security measures to protect personal data. Here are the key technology areas every organisation should review.
Access Controls
Only authorised staff should be able to access personal data. Review who has access to your systems, databases, and shared drives. Remove access for staff who no longer need it or who have left the organisation. Implement role-based access so each person only accesses what their role requires.
Authentication
Weak passwords and shared accounts are common causes of data breaches. Implement a strong password policy and enable multi-factor authentication (MFA) on all organisational email accounts, cloud systems, and platforms that process personal data.
Email Security
Email is both a primary communication channel and a primary attack vector. Implement spam filtering, anti-phishing controls, and safe links/safe attachments on your email platform. For Microsoft 365 or Google Workspace users, built-in security features should be actively configured — not left at default settings.
Data Storage and Encryption
Where sensitive personal data is stored — particularly health records, financial data, or staff information — encryption at rest should be considered. Cloud platforms such as Microsoft 365 and Google Workspace include encryption by default, but on-premises storage may require additional controls.
Backups and Data Recovery
Personal data must be protected from accidental loss, deletion, or destruction. Implement automated backups for all systems containing personal data, test your restore process regularly, and ensure backups are stored securely — including protection against ransomware through immutable or offline copies.
Incident Response Readiness
Data breach response is a specific area of concern under data protection frameworks. Organisations should have a documented process for identifying, containing, and reporting data incidents. This includes knowing who within your organisation is responsible for handling a breach and what steps to take in the event of a data loss or unauthorised access event.
Third-Party and Vendor Management
Any vendor or service provider that processes personal data on your behalf is acting as a data processor. Review your technology vendors — cloud storage providers, software platforms, IT support providers — to understand how they protect your data and what security assurances they provide.
Documentation and Records
Data protection compliance is partly about demonstrating what you have done. Organisations should maintain records of the types of personal data they hold, the purposes for which it is processed, how long data is retained, and what security measures are in place. This documentation may be reviewed by regulators.
Practical Readiness Checklist
Use this checklist as a starting point for your organisation's DPA 2025 readiness review:
- Identify all categories of personal data your organisation collects and processes
- Document the purposes for which each category of data is used
- Review and enforce access controls — who can access what, and why
- Enable MFA on all organisational accounts and cloud platforms
- Configure email security controls on Microsoft 365 or Google Workspace
- Implement automated, tested backups for all systems containing personal data
- Define a basic data breach response process — who to notify, what steps to follow
- Review third-party vendors — understand how they protect data they process on your behalf
- Establish a data retention policy — how long personal data is kept, and how it is securely deleted
- Train staff on data protection responsibilities and how to recognise and report incidents
How MI Secure Tech Solutions Can Help
MI Secure Tech Solutions provides managed IT and cybersecurity services designed to help organisations in The Gambia and West Africa build the technical and operational foundations that support responsible data handling.
We help organisations implement the technical controls described in this guide — including MFA configuration, email security, access management, backup and recovery, endpoint protection, and security documentation — as part of a structured managed service engagement.
We also offer free technology and security reviews for organisations that want to understand their current environment, identify gaps, and plan a practical path to improvement.
We do not provide legal advice or formal DPA 2025 compliance certification. For formal legal interpretation of your obligations under the Act, consult qualified legal counsel. Our role is to help you build the right technical environment to support your data protection responsibilities.