CSA fines ORC, Purpleline GHC360,000 for violating cybersecurity law
The Cyber Security Authority (CSA) has imposed a combined fine of GH¢360,000 on the Office of the Registrar of Companies (ORC) and Purpleline Solutions Limited for breaches of the Cybersecurity Act, 2020 (Act 1038). The ORC was fined GHC240,000 after the Authority found it had failed to comply with directives requiring...

The Cyber Security Authority (CSA) has imposed a combined fine of GH¢360,000 on the Office of the Registrar of Companies (ORC) and Purpleline Solutions Limited for breaches of the Cybersecurity Act, 2020 (Act 1038).
The ORC was fined GHC240,000 after the Authority found it had failed to comply with directives requiring it to engage only licensed Cybersecurity Service Providers (CSPs).
According to the CSA, the ORC, a designated Critical Information Infrastructure (CII) institution, contracted Purpleline Solutions despite being directed to use a Tier 1 licensed cybersecurity provider.
The regulator said it had instructed the ORC on 15 June 2026 to strengthen the security of its critical systems and requested details of its cybersecurity providers, proposed Security Operations Centre and Public Procurement Authority approvals.
Despite the directive, the authority said the ORC proceeded to engage Purpleline, which did not hold the required licence.
The CSA said the ORC committed two separate breaches of its directives and was fined 10,000 penalty units for each offence, amounting to GHC240,000. The office has also been directed to comply with the outstanding directives within one month.
Purpleline Solutions was separately fined GHC120,000 after the authority determined that it had provided regulated cybersecurity services without first obtaining the required licence.
Although the company applied for a licence on 15 July 2026, the CSA said the application was submitted only after it had established that Purpleline had already begun providing the services.
The authority stressed that applying for a licence does not authorise a company to operate and warned public institutions to verify the licensing status of cybersecurity service providers before awarding contracts.