Ghana
Ghana Data Privacy Laws: Data Protection Act 2012 (Act 843) Complete Guide (2026)
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 9 primary sources cited on this page. How we verify our legal content

Ghana regulates personal data under the Data Protection Act 2012 (Act 843), which requires every data controller to register with the Data Protection Commission before processing any personal data and establishes eight binding data protection principles enforceable through criminal sanctions including imprisonment of up to ten years.
Quick Answer: What Are Ghana's Data Privacy Laws?
Ghana's core data protection law is the Data Protection Act 2012 (Act 843). Enacted on 10 May 2012 and in force since 16 October 2012, it covers the full lifecycle of personal data processing by both public and private organizations operating in Ghana.
The Act is administered by the Data Protection Commission (DPC), an independent body with registration, monitoring, and enforcement powers. Before any processing begins, data controllers must register with the DPC. The law sets out eight binding data protection principles, a framework of data subject rights, a mandatory breach-notification duty, and a graduated penalty structure including criminal sanctions. It does not restrict sending personal data out of Ghana.
A replacement law, the Data Protection Bill 2025, has been drafted and publicly consulted. Parliament of Ghana's bills register listed no Data Protection Bill when checked on 10 September 2026, and the Minister for Communication described it in February 2026 as still under development. Until that bill is enacted, Act 843 remains the operative law.
For context on Ghana's recording and surveillance laws, see our guide to Ghana recording laws.
Constitutional Basis: Article 18(2) of the 1992 Constitution
Ghana's data protection regime has an express constitutional foundation. Article 18(2) of the 1992 Constitution provides that no person shall be subjected to interference with the privacy of their home, property, correspondence, or communication except in accordance with law and as may be necessary in a free and democratic society for public safety, the economic well-being of the country, the protection of health or morals, the prevention of disorder or crime, or the protection of the rights or freedoms of others.
Parliament enacted Act 843 to translate this constitutional guarantee into enforceable obligations for the digital age. The Act gives practical meaning to Article 18(2) by regulating how organizations collect, store, use, and disclose personal information. It creates the DPC as the enforcement body and provides individuals with rights and remedies when their privacy is violated.
Courts and commentators have consistently described Act 843 as the operational expression of the Article 18(2) right, meaning that a violation of Act 843 is, at its core, an infringement of a constitutionally protected right.
The Data Protection Act 2012 (Act 843): Core Provisions
Scope and Definitions
Act 843 applies to any data controller who processes personal data in Ghana, whether a government body, private company, non-profit, or individual. It covers both automated and manual processing.
Personal data means information about an identifiable individual. The definition is broad and includes obvious identifiers such as names, addresses, and identification numbers, but also opinions about the individual, correspondence sent by the individual, and biological samples. The Act does not require that the individual be directly named; indirect identification is sufficient.
Special personal data (sensitive data) receives a higher level of protection. It covers information about race or ethnic origin, political opinion, religious or other beliefs, trade union membership, physical or mental health or condition, sexual life, criminal offenses, and court proceedings. Section 37(1) prohibits processing this data unless the Act provides otherwise, and section 37(2) lifts the prohibition only where the processing is necessary or the data subject consents.
Eight Data Protection Principles
Every data controller in Ghana must comply with eight data protection principles. These principles apply throughout the data lifecycle and form the backbone of the compliance framework.
1. Accountability. The data controller is responsible for ensuring compliance with all measures that give effect to the data protection principles. Responsibility cannot be outsourced or delegated away from the organization.
2. Lawfulness of processing. Personal data must be processed lawfully and in a manner that does not infringe the privacy of the data subject. Processing that is technically legal but unreasonably intrusive can still violate this principle.
3. Specification of purpose. Data must be collected for a specific, explicitly defined, and lawful purpose related to the function or activity of the data controller. Controllers must identify that purpose before collection begins.
4. Compatibility of further processing. Any further processing of personal data must be compatible with the purpose for which it was originally collected. Using data collected for one purpose to serve a materially different purpose requires a fresh legal basis.
5. Quality of information. The data controller must take reasonably practicable steps to ensure personal data is complete, accurate, not misleading, and updated where necessary. Keeping stale or incorrect records is itself a compliance failure.
6. Openness. The data controller must take reasonably practicable steps to ensure the data subject is aware of what data is being collected, the controller's identity and contact details, the purposes of processing, and any third parties who may receive the data.
7. Security safeguards. The controller must secure the integrity and confidentiality of personal data through appropriate technical and organizational measures to prevent loss, damage, unauthorized destruction, or unlawful access. The measures required are proportionate to the sensitivity of the data and the risks involved.
8. Data subject participation. Data subjects have an active role in the framework. They may request confirmation of whether a controller holds data about them, obtain a description of that data, and request corrections.
Breach Notification Is Already Mandatory
This is the obligation Ghanaian compliance guides most often miss. Section 31 imposes a breach-notification duty today. It is not something the pending bill would introduce.
Where there are reasonable grounds to believe that a data subject's personal data has been accessed or acquired by an unauthorized person, the data controller, or a third party processing under the controller's authority, must notify both the Commission and the data subject. Section 31(2) sets the timing: as soon as reasonably practicable after the discovery.
Section 31(5) prescribes how the data subject is told, by registered mail, by email, by prominent placement on the controller's website, by publication in the media, or in any other manner the Commission directs. Sections 31(6) and 31(7) require enough information for the data subject to take protective measures, including the identity of the unauthorized person where the controller knows it.
Notification to the data subject is delayed only where the security agencies or the Commission tell the controller that notifying would impede a criminal investigation, under section 31(4). The controller must also take steps to restore the integrity of the information system under section 31(3).
No penalty is specified for section 31, so the section 95 general penalty applies: a fine of up to 5,000 penalty units or imprisonment of up to 10 years, or both.
Rights in Relation to Automated Decisions
Section 41 is headed "Rights in relation to automated decision-taking" and it is already in force. An individual may give written notice requiring that a decision which significantly affects them not be based solely on automated processing of their personal data.
Even without such a notice, section 41(2) requires the controller to tell the individual that the decision was taken on that basis, and entitles the individual to require reconsideration within twenty-one days. Section 41(3) requires a written response within twenty-one days, and section 41(5) lets the Commission order compliance.
Section 41(4) carves out decisions taken in the course of considering, entering into, or performing a contract with the data subject, and decisions authorized by an enactment. Separately, section 35(1)(d) requires the controller to inform the data subject of the logic or rationale behind a decision where the processing is the sole basis for a decision that significantly affects them, subject to the section 35(2) trade-secret exception.
Legal Bases for Processing

The primary legal basis for processing personal data under Act 843 is consent. Consent must be freely given, informed, and not obtained through fraud, coercion, or material misrepresentation. The data subject must understand the nature and extent of the processing before agreeing.
Section 20(1) sets out exactly five alternatives to consent. Processing may proceed without consent where the purpose is necessary for the purpose of a contract to which the data subject is a party; authorised or required by law; to protect a legitimate interest of the data subject; necessary for the proper performance of a statutory duty; or necessary to pursue the legitimate interest of the data controller or a third party to whom the data is supplied.
Two points are commonly misread here. Act 843's legitimate-interest ground carries no express balancing test against the rights of the data subject, unlike the GDPR formulation, so the Ghanaian version is drafted more broadly than practitioners often assume.
And national security is not a consent ground at all. Section 60 exempts processing for public order, public safety, public morality, national security, or the public interest from the Act entirely, on a certificate signed by the Minister. That is a different mechanism with different consequences: it removes the processing from the Act rather than supplying a lawful basis within it.
Data the subject has deliberately made public is likewise not a section 20 processing basis. It appears in section 21(2)(b), which is about when personal data may be collected indirectly rather than from the data subject.
Special personal data works differently. Section 37(1) starts from a prohibition: a person shall not process personal data relating to a child under parental control, or to the religious or philosophical beliefs, ethnic origin, race, trade union membership, political opinions, health, sexual life or criminal behaviour of an individual, unless the Act provides otherwise.
Section 37(2) supplies the two ways through. The processing is necessary, or the data subject consents to the processing. Act 843 never uses the GDPR's "explicit consent" standard, and the phrase does not appear anywhere in the Act, so ordinary consent is the test here.
Necessity is then defined in specific places. Section 37(3) treats processing as necessary where it is for the exercise or performance of a right or obligation imposed by law on an employer. Section 37(4) permits processing to protect the data subject's vital interests where consent is impossible, cannot reasonably be obtained, or has been unreasonably withheld. Section 37(6) presumes necessity for legal proceedings, obtaining legal advice, the establishment, exercise or defence of legal rights, the administration of justice, and medical purposes carried out by a health professional under a duty of confidentiality.
Section 37(5) covers the membership case: a non-profit body existing for political, philosophical, religious or trade union purposes may process this data about its members or regular contacts, provided it does not disclose the data to a third party without the data subject's consent. Section 37(8) adds a condition specific to race and ethnic origin, allowing that processing only where it is necessary for the identification and elimination of discriminatory practices and is carried out with appropriate safeguards.
Data the subject has made public is not an exception to section 37 either. Beyond section 21(2)(b) above, the idea appears in section 25(3)(b), on when further processing is compatible with the original purpose. Neither provision lifts the section 37 prohibition.
The Data Protection Commission (DPC)
Establishment and Mandate
The DPC was established by Act 843 as an independent body. Its statutory functions include maintaining the Register of Data Controllers, monitoring compliance with the Act across public and private sectors, investigating complaints from data subjects, conducting compliance audits, issuing guidance to data controllers, taking enforcement action including serving enforcement notices, and referring matters for criminal prosecution.
The Commission is led by a Board and an Executive Director. It is resourced to investigate breaches proactively, not merely in response to individual complaints.
Registration of Data Controllers
Mandatory pre-processing registration is the cornerstone of Ghana's compliance framework. Before processing any personal data, every data controller must apply to the DPC for registration. The application must include the name and address of the data controller, a description of the personal data to be processed, the purpose or purposes of processing, a description of the recipients to whom data may be disclosed, details of any proposed cross-border transfers, and the security measures in place.
The DPC registers the controller, issues a Certificate of Registration, and adds the organization to the public Data Protection Register. The public register allows individuals to verify which organizations are lawfully processing their data.
Registration is valid for two years and must be renewed. The DPC now requires comprehensive compliance gap analysis and assessment reports as part of the renewal process, making renewal more substantive than a simple administrative renewal.
Organizations may register online through the DPC's portal. The DPC also launched a DPC Privacy Seal in December 2025 -- a scannable QR certification that organizations can display to demonstrate verified compliance status to customers and regulators.
Enforcement Powers
When a data controller contravenes any of the data protection principles, the DPC may serve an enforcement notice requiring specified corrective steps within a defined timeframe. Failure to comply with an enforcement notice is itself a criminal offense.
The Commission may conduct inspections, require the production of documents and information, and investigate complaints. Where serious violations are found, the DPC can direct cessation of processing, impose conditions on future processing, and refer the matter for criminal prosecution.
Data Subject Rights
Right of Access
Data subjects have the right to request confirmation from any data controller as to whether personal data about them is held. If it is, the data subject is entitled to a description of that data, the purposes for which it is processed, and the categories of recipients who may receive it. Controllers must respond within a reasonable timeframe.
Right to Correction
Where personal data is inaccurate, incomplete, or misleading, the data subject may request correction. The data controller must take reasonable steps to correct the data without undue delay.
Right to Object
Section 20(2) gives a general right to object that is not conditioned on harm: unless otherwise provided by law, a data subject may object to the processing of personal data. Section 20(3) then requires that the person processing the data stop the processing.
A narrower route sits in section 39. An individual may give written notice requiring a controller to cease or not begin processing that causes or is likely to cause unwarranted damage or distress, and the controller must respond in writing within twenty-one days, either complying or giving reasons.
Direct marketing in Ghana is opt-in, not opt-out. Section 40(1) provides that a data controller shall not provide, use, obtain or procure information related to a data subject for the purposes of direct marketing without the prior written consent of the data subject. Section 40(2) separately entitles a data subject to require by written notice that the controller stop marketing processing, and section 40(3) lets the DPC order compliance.
Right to Compensation
A data subject who suffers damage as a result of a contravention of the Act has the right to claim compensation from the controller. This is enforceable through the civil courts. Unlike some modern frameworks, Act 843 does not establish a DPC-administered compensation scheme; claims are pursued as private civil actions.
Cross-Border Data Transfers
Act 843 Sets No Adequacy Test
Act 843 contains no cross-border transfer provision. Its arrangement of sections runs from 1 to 99 with no transfer or adequacy heading, no "adequate level of protection" test, and no DPC power to assess the laws of a receiving country. Guidance describing a Ghanaian adequacy regime is importing the UK and EU model into a statute that never adopted it.
Three real obligations govern data crossing Ghana's borders today.
Disclosure at registration. Section 47(1)(g) requires a registration application to state "the name or description of the country to which the applicant may transfer the data." That is a disclosure duty owed to the DPC, not a restriction on the transfer itself.
The principles travel with the data. The eight principles in section 17 and the security duties in sections 28 to 30 apply to the processing regardless of where it happens, so a controller stays answerable for data it sends abroad and for the processor that handles it.
Inbound foreign data. Section 18(2) runs in the opposite direction from an export rule. Where personal data originating in a foreign jurisdiction is sent to Ghana for processing, the controller or processor must ensure that data is processed in compliance with the data protection legislation of that foreign jurisdiction.
A Transfer Regime Is Proposed, Not Enacted
The draft Data Protection Bill 2025 would introduce cross-border transfer rules for the first time, as new sections 96 and 97.
Section 96(4) would permit a transfer only where the data subject has given written, free, explicit and informed consent after being told the risks involved, and one of a listed set of grounds applies, such as contractual necessity, the establishment or defence of legal claims, or the vital interests of the data subject. It would also require the Authority to authorise transfers involving large-scale data, following an assessment of safeguards such as contractual clauses or binding corporate rules.
Section 96(2) would impose mandatory localisation on a narrow set of categories: data critical to national defence, security and intelligence; national identity and civil registration data including voter databases; and children's data, biometric data, health records and genetic data. Section 97 would require Authority approval and data subject consent before special personal data leaves Ghana, and a Transfer Impact Assessment for large-scale, higher-risk processing.
None of this is law today. Until the bill is enacted, a Ghanaian controller planning an export needs accurate registration disclosure and ordinary compliance with the Act, not an adequacy assessment.
Penalties and Criminal Sanctions

Graduated Penalty Framework Under Act 843
Act 843 establishes a graduated criminal penalty structure. Severity escalates with the seriousness of the offense.
Processing without registration: A data controller who processes personal data without being registered is liable on summary conviction to a fine of not more than 250 penalty units or imprisonment of not more than two years, or both.
Failure to comply with an enforcement notice: A person who fails to comply with an enforcement notice from the DPC is liable to a fine of not more than 150 penalty units or imprisonment of not more than one year, or both.
Unlawful sale of personal data: Selling or offering to sell another person's personal data is a more serious offense, carrying a fine of not more than 2,500 penalty units or imprisonment of not more than five years, or both.
General offenses: For other offenses under the Act where no specific penalty is prescribed, section 95 sets a maximum of a fine of 5,000 penalty units or imprisonment of not more than 10 years, or both.
The custodial ceiling is among the highest in West Africa. The monetary ceiling is not. A penalty unit's cedi value is fixed by Schedule 1 to the Fines (Penalty Units) Act 2000 (Act 572), and the Attorney-General may amend that Schedule by legislative instrument. Section 2(2) caps the amendment: one penalty unit shall not exceed one third of the prevailing national daily minimum wage multiplied by thirty. The resulting figures are modest next to revenue-based regimes such as Nigeria's. Check the current penalty-unit value before converting any of these maximums into cedis.
Who Is Personally Liable
Act 843 has no offence-by-body-corporate provision. No section deems a director, manager, or secretary criminally liable for an offence committed by the company. The phrase "body corporate" appears in the Act only in the service-of-notices provisions and in the section 96 definitions.
The Act's offences are framed as applying to "a person," so an officer is exposed where that officer personally commits an offence under the Act, on ordinary criminal law principles. The one express exception runs the other way and is narrow: section 90(1)(c) makes a credit bureau liable for offences committed by the bureau and its officers.
Data protection is still a board-level concern in Ghana, because the section 17 accountability principle places responsibility for compliance on the controller and it cannot be delegated away. But the exposure route is corporate liability plus personal conduct, not an automatic deeming rule.
DPC Enforcement Year: 2026
For the first twelve years of Act 843's operation, the DPC focused primarily on education, public awareness, and building the registration infrastructure. That phase has now closed.
In late 2025, the DPC publicly announced that 2026 is a year of enforcement. Key developments include:
Nationwide enforcement began in January 2026. The DPC urged organizations to regularize compliance by 31 December 2025 or face formal sanctions. At the National Data Protection Conference 2026, held on 26 February 2026 at the Alisa Hotel in North Ridge, Accra, Communications Minister Samuel Nartey George told organizations that had not yet registered with the DPC to do so without delay, adding that "leadership should begin voluntarily, not after enforcement."
The DPC reported in early 2026 that its 2025 nationwide public awareness campaign had reached an estimated 25 million people, that more than 800 data protection officers had been trained, and that compliance audits had been conducted across key sectors with the data controller register expanded. The DPC Executive Director stated that unlawful data processing would now carry "real legal and reputational consequences." The theme "Your Data, Your Identity: Building Trust in Ghana's Digital Future" belongs to the National Data Protection Conference 2026, held in Accra on 26 February 2026.
The Pending Data Protection Bill 2025
Status and Overview
Ghana published a draft Data Protection Bill 2025 for public consultation in October and November 2025. The Ministry of Communication, Digital Technology and Innovations closed the consultation on 31 October 2025, with written submissions accepted through 28 November 2025. Parliament of Ghana's own bills register listed no Data Protection Bill when checked on 10 September 2026. At the National Data Protection Conference on 26 February 2026 the Minister described the bill as still being developed to address artificial intelligence, automated decision-making, and cross-border data flows, and announced a companion Emerging Technologies Bill and a Data Harmonisation initiative addressing fragmentation across financial services, telecommunications, and the public sector.
The bill would repeal and replace Act 843 in its entirety. Organizations should monitor its parliamentary progress closely, as many compliance obligations will shift significantly if it is enacted.
Structural Changes
The bill would rename the supervisory authority from the "Data Protection Commission" to the Data Protection Authority (DPA) and restructure leadership around a Director-General and Deputy Director-General. The bill explicitly guarantees the DPA's independence from ministerial direction on operational matters, unlike Act 843, which permitted ministerial policy directives.
Expanded Definitions
The bill broadens the definition of personal data to expressly include biometric data, location data, voice recordings, online identifiers (including IP addresses and cookies), and pseudonymized data. These categories were not enumerated in Act 843, creating legal uncertainty about their coverage that the bill would resolve.
New and Expanded Data Subject Rights
The bill introduces several rights not present in Act 843. The right to data portability would allow individuals to request their data in a structured, machine-readable format suitable for transfer to another controller. The right to erasure (the "right to be forgotten") would allow data subjects to request deletion of their personal data. Section 61(1) and 61(2) set the headline standard as erasure "without undue delay," and section 61(4)(f) puts an outer window of 30 days on the removal actions unless the controller justifies the complexity to the Authority. Section 61(3) extends the right beyond the controller's own systems to links, copies, websites and replications, "to the greatest extent possible."
Section 53 of the draft would broaden the treatment of automated decision-making, requiring technology-driven decisions affecting data subjects to be explainable, contestable, and subject to human oversight, and requiring bi-annual audits of systems used in critical sectors such as health, energy, finance, government services, and transport. It builds on protection Act 843 already gives rather than creating it: section 41 of the current Act already lets an individual object to a solely automated significant decision and require reconsideration within twenty-one days, and section 35(1)(d) already gives a right to the logic behind such a decision. The bill also introduces an explicit framework for children's data, requiring verifiable parental or guardian consent under section 68.
Mandatory Data Protection Officer
Act 843 section 58 makes a "data protection supervisor" optional: a data controller may appoint one. The bill replaces this with a certified Data Protection Officer (DPO).
Section 84(1) of the draft is unqualified: a data controller shall appoint a certified and qualified person to serve as a data protection officer. There is no size, revenue, or processing threshold anywhere in section 84, so the requirement would reach small and medium controllers exactly as it reaches large ones. Section 84(2) requires the officer to be trained and certified by the Authority, and section 84(8) sets an administrative penalty of not less than 2,000 and not more than 50,000 penalty units for failure to appoint.
72-Hour Breach Notification
Act 843 section 31 already requires notification of the Commission and the affected data subjects, but sets the timing as "as soon as reasonably practicable" rather than a fixed clock. The bill tightens an existing duty rather than creating a new one.
Sections 51(1) and 51(2) of the draft would require notification of the Authority and the data subject without undue delay, and in any case "immediately or within 72 hours" after discovery of the unauthorised access or acquisition. Section 51(9) would back this with an administrative penalty of not less than 2,000 and not more than 100,000 penalty units for missing the 72-hour window. This aligns with international standards including the EU General Data Protection Regulation.
Revised Cross-Border Transfer Rules
Act 843 imposes no transfer restriction and no adequacy test, so sections 96 and 97 of the bill would regulate cross-border transfers for the first time.
Section 96(1) sets a localization preference: a controller would make reasonable efforts to localise data, provided localisation does not impair its business or operations. Section 96(2) makes localisation compulsory for only three categories, namely data critical to national defence, security and intelligence; national identity and civil registration data including voter databases; and children's data, biometric data, health records and genetic data.
Authority involvement is triggered by category and by scale, not by a general high-risk test. Section 96(4)(c) would require the Authority to authorise a transfer involving large-scale data, following an assessment that adequate safeguards such as contractual clauses or binding corporate rules are in place. Section 97(1) would require Authority approval plus the consent of all affected data subjects before special personal data is processed outside Ghana. Section 97(4) would require a Transfer Impact Assessment where a controller processes large-scale data and the activity is likely to pose a real risk to the rights and freedoms of a data subject.
Higher Penalties
The bill introduces substantially higher maximum fines, on tiers that vary by offence. These are draft figures and may change before enactment.
Failure to register as a data controller: an administrative penalty of 2,000 to 100,000 penalty units (section 82).
Failure to notify a breach within 72 hours: 2,000 to 100,000 penalty units (section 51(9)).
Failure to appoint a data protection officer: 2,000 to 50,000 penalty units (section 84(8)).
Failure to comply with an enforcement notice: a fine of up to 10,000 penalty units or imprisonment of up to one year, or both (section 35(1)).
A knowingly false or reckless statement made in compliance with an information notice: a fine of up to 150,000 penalty units (section 35(2)).
Unlawful assessable processing: a fine of up to 150,000 penalty units or imprisonment of up to five years, or both (section 83(6)).
The bill's highest fine is therefore 150,000 penalty units, not 100,000. Its general penalty, for contraventions with no penalty specified, is an administrative penalty of 50,000 to 100,000 penalty units under section 94. Unlike GDPR, the bill does not adopt turnover-based fines, which commentators note may limit deterrence against large multinationals.
Recent Developments: 2024-2026
October 2024: Ghana's Cyber Security Authority adopted a National Cybersecurity Policy, establishing legal, technical, organizational, and capacity-building measures for cybersecurity that complement Act 843's data security obligations.
June 2024: The Minister for Communications and Digitalisation announced the government's intention to localize government data as a sovereignty and cost-reduction measure, prefiguring the localization provisions in the draft Bill 2025.
October-November 2025: Draft Data Protection Bill 2025 published for public consultation by the Ministry of Communication, Digital Technology and Innovations. Consultation closed 31 October 2025; written submissions accepted through 28 November 2025.
December 2025: The DPC launched the DPC Privacy Seal, a certification with a scannable QR code that organizations can display to demonstrate verified compliance with Act 843. Fee-based seal levels were introduced for different data sensitivity tiers.
January 2026: Nationwide DPC enforcement began. The DPC issued public notices warning that organizations that had not registered by 31 December 2025 would face formal regulatory action.
February 26, 2026: National Data Protection Conference 2026 at the Alisa Hotel, North Ridge, Accra. Communications Minister Samuel Nartey George said a new Data Protection Bill was being developed to address artificial intelligence, automated decision-making, and cross-border data flows, and called on organizations that had not registered with the DPC to do so without delay. A companion Emerging Technologies Bill was also announced to cover AI, advanced analytics, digital assets, and new digital platforms.
The Cybersecurity Act 2020 (Act 1038) Runs in Parallel
Personal-data compliance in Ghana is not only Act 843. The Cybersecurity Act 2020 (Act 1038) establishes the Cyber Security Authority, licenses cybersecurity service providers, and provides for the designation of critical information infrastructure. The CSA regulates cybersecurity; the DPC regulates personal data. A single incident can trigger both.
The clock that matters is far shorter than the one the draft data protection bill proposes. Section 39(1)(a) of Act 1038 requires the owner of a critical information infrastructure to report a cybersecurity incident within twenty-four hours after it is detected, to the relevant Sectoral Computer Emergency Response Team or, where the infrastructure does not belong to a sectoral team, to the National Computer Emergency Response Team.
Section 47(5) extends the same twenty-four-hour duty more broadly: a person in charge of an institution shall report a cybersecurity incident to the relevant sectoral or national CERT within not more than twenty-four hours after detection. Section 47(6) backs it with an administrative penalty of not less than 250 and not more than 5,000 penalty units.
For a Ghanaian bank, telco, or health provider, that means two reporting duties can run at the same time on the same incident: twenty-four hours to the CERT under Act 1038, and as soon as reasonably practicable to the DPC and to every affected data subject under Act 843 section 31. Meeting one does not discharge the other.
Compliance Guide for Businesses
Step 1: Register With the DPC Before Processing
Registration is non-negotiable and must come before any personal data processing begins. Section 53 prohibits an unregistered data controller from processing personal data at all.
Submit an application through the DPC's online portal, which the Commission links from dpc.gov.gh. Section 47(1) sets out the particulars the application must carry: the business name and address, a description of the personal data and the categories of people it concerns, whether special personal data is held, the purposes of processing, the recipients of any intended disclosure, the countries the applicant may transfer data to, the security measures, and any other information the Commission requires.
Registration is fee-bearing. Section 49(2) provides that the applicant shall pay the prescribed fee upon registration, and section 59 lets the Minister prescribe fees for registration, renewal, and public access to the Register. The DPC publishes its current fee schedule on dpc.gov.gh, so check it before budgeting.
Obtain and retain your Certificate of Registration. Registration is renewed every two years under section 50, and section 55 requires you to notify the Commission of changes to your registered particulars within fourteen days.
Step 2: Implement the Eight Principles in Practice
Conduct a data mapping exercise to document all personal data flows, then assess each processing activity against the eight principles. Practical steps include drafting clear privacy notices, establishing mechanisms for obtaining and recording valid consent, implementing technical security measures proportionate to data sensitivity, creating procedures for handling data subject access requests, and ensuring data accuracy standards are maintained.
Step 3: Appoint a Data Protection Supervisor
While Act 843 does not mandate a DPO in the way GDPR does, section 58 lets a controller appoint a certified data protection supervisor, and DPC guidance recommends it. Medium and large organizations should treat this as a substantive role, not a nominal designation. Under the pending bill, every data controller regardless of size would have to appoint an Authority-certified data protection officer, so planning the role and the certification now is worth doing.
Step 4: Document Where Data Goes, and Fix Direct Marketing
Act 843 does not require an adequacy assessment, because it imposes no transfer restriction. What it does require is that your registration application names the countries you may transfer data to, under section 47(1)(g), and that you tell the DPC within fourteen days when your registered particulars change, under section 55. Keep that destination list current as vendors and hosting arrangements change.
In the same pass, fix direct marketing. Section 40(1) requires prior written consent before personal data is used for direct marketing, so an opt-out list is not compliant in Ghana. Capture and record the consent before the campaign runs, and honour section 40(2) stop notices when they arrive.
Step 5: Prepare for the Data Protection Bill 2025
Organizations should begin gap analysis against the draft bill's new obligations now. Key areas include DPO appointment and certification planning, data portability request workflows, erasure request handling, and Transfer Impact Assessment processes for cross-border transfers.
Breach notification does not belong on that list, because it is not a future obligation. Act 843 section 31 already requires you to notify the DPC and every affected data subject as soon as reasonably practicable after you discover unauthorized access or acquisition, and Act 1038 already gives you twenty-four hours to report a cybersecurity incident to the relevant CERT. Both bind you today. The bill would only replace "as soon as reasonably practicable" with a 72-hour outer limit.
Step 6: Consider the DPC Privacy Seal
Applying for the DPC Privacy Seal, launched in December 2025, demonstrates verified compliance to customers, partners, and regulators. During the 2026 enforcement phase, seal-holding organizations may receive favorable treatment in DPC compliance monitoring. Fees apply based on data sensitivity tier.
Frequently Asked Questions
What is Ghana's main data protection law?
The Data Protection Act 2012 (Act 843) is Ghana's primary data protection legislation. Enacted on 10 May 2012 and in force since October 2012, it establishes the Data Protection Commission as the supervisory authority, requires mandatory registration of data controllers, sets eight data protection principles, and provides data subjects with rights to access, correction, and compensation.
Do organizations need to register before processing personal data in Ghana?
Yes. Act 843 requires all data controllers to register with the Data Protection Commission before processing personal data. Processing without registration is a criminal offense carrying a fine of up to 250 penalty units or imprisonment of up to two years, or both. Registration is valid for two years and must be renewed.
What is Ghana's constitutional basis for data protection?
Article 18(2) of Ghana's 1992 Constitution guarantees the right to privacy of home, property, correspondence, and communications. The Data Protection Act 2012 (Act 843) was enacted to operationalize that constitutional right for the digital age, translating it into enforceable obligations for organizations that process personal information.
What are the maximum penalties for data protection violations in Ghana?
Under Act 843, the maximum penalty for general offenses is a fine of 5,000 penalty units or imprisonment of up to 10 years, or both, under section 95. Specific offenses carry lower maximums: processing without registration (250 penalty units or 2 years, section 56), failure to comply with an enforcement or information notice (150 penalty units or 1 year, section 80), and unlawful sale of personal data (2,500 penalty units or 5 years, section 89). Act 843 contains no provision deeming directors or officers liable for an offence committed by the company; an officer is exposed where that officer personally commits an offence under the Act.
Can personal data be transferred outside Ghana?
Yes. Act 843 contains no cross-border transfer provision, no adequacy test, and no DPC power to assess a receiving country. The obligations that do apply are to name the countries you may transfer data to in your registration application under section 47(1)(g), and to keep meeting the Act's eight principles and security duties wherever the data is processed. Section 18(2) runs the other way, requiring personal data sent into Ghana from a foreign jurisdiction to be processed in compliance with that jurisdiction's law. A general transfer regime, with consent, listed grounds, Authority authorisation for large-scale transfers and limited mandatory localisation, is proposed in sections 96 and 97 of the draft Data Protection Bill 2025 and is not law today.
What is the Data Protection Bill 2025 and when will it take effect?
The Data Protection Bill 2025 is a comprehensive replacement for Act 843, drafted by the Ministry of Communication, Digital Technology and Innovations and publicly consulted in late 2025. It would introduce mandatory Data Protection Officers, 72-hour breach notification, data portability, a right to erasure, AI and emerging-technology oversight of automated decisions that builds on the existing section 41 right rather than creating it, a renamed Data Protection Authority, and substantially higher penalties. Parliament of Ghana's bills register listed no Data Protection Bill when checked on 10 September 2026.
What did Ghana declare about data protection enforcement in 2026?
Ghana's Data Protection Commission declared 2026 a year of active enforcement, ending a phase focused primarily on education and awareness. Nationwide enforcement began in January 2026, after a 31 December 2025 deadline for organizations to regularize their registration. At the National Data Protection Conference on 26 February 2026, the Communications Minister called on every organization that had not registered with the DPC to do so without delay, saying that leadership should begin voluntarily rather than after enforcement.
What are Ghana's data subject rights under Act 843?
Under Act 843, data subjects have the right to access their personal data held by a controller, request correction of inaccurate data, object to processing under section 20(2) so that the controller must stop, give written notice under section 39 to stop processing that causes unwarranted damage or distress, object under section 41 to decisions based solely on automated processing, and claim compensation through the civil courts for unlawful processing that causes damage. Direct marketing needs prior written consent under section 40(1), so a controller may not market first and wait for an opt-out.
Updates
Corrected the special personal data section to Act 843's actual section 37 rule, under which the prohibition lifts where the processing is necessary or the data subject consents, with the section 37(3) to 37(8) exceptions, removing an imported GDPR explicit-consent standard and a non-existent exception for data the subject has made public; restated the draft bill's cross-border rules to their real triggers in sections 96 and 97 and removed a clause implying current Ghanaian law lets controllers self-assess the adequacy of a receiving country; corrected the section 39 harm threshold to unwarranted damage or distress by removing a duplicate section that stated it as substantial damage; clarified that the DPC's enforcement tools under Act 843 are notices, audits and criminal referral rather than regulator-imposed fines; and fixed the description of how a penalty unit's cedi value is set under the Fines (Penalty Units) Act 2000.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Comprehensive refresh: added constitutional basis (Article 18(2)), detailed legal bases analysis, expanded data subject rights, a detailed DPC enforcement section covering the 2026 enforcement year declaration and the National Data Protection Conference, Data Protection Bill 2025 analysis (structure, new rights, DPO requirements, breach notification, cross-border transfer changes, higher penalties), 2024-2026 recent developments timeline, step-by-step compliance guide, and expanded FAQ.
Reviewed and approved by an editor
Original publication covering Act 843 core provisions, the Data Protection Commission, eight data protection principles, data subject rights, cross-border data questions, and penalties.
Sources and References
- Data Protection Act 2012 (Act 843), full text - Data Protection Commission Ghana(dpc.gov.gh).gov
- Data Protection Act 2012 - NCA Ghana(nca.org.gh).gov
- Compliance - Data Protection Commission Ghana(dpc.gov.gh).gov
- Data Protection Bill 2025 Draft - Data Protection Commission Ghana(dataprotection.org.gh).gov
- Data Protection Bill 2025 - Ministry of Communication Ghana(moc.gov.gh).gov
- Ghana to introduce Data Protection Bill to regulate AI - Ghana News Agency(gna.org.gh).gov
- Ghana Information Technologies Data Protection - US Trade.gov(trade.gov).gov
- Data Protection Laws in Ghana - DLA Piper(dlapiperdataprotection.com)
- Understanding the Data Protection Bill 2025 - Business and Financial Times Ghana(thebftonline.com)
- Comparative Analysis: Data Protection Bill 2025 vs Act 843 - Business and Financial Times Ghana(thebftonline.com)
- Cybersecurity Act 2020 (Act 1038), full text - Parliament of Ghana repository(repository.parliament.gh).gov
- Ghana Data Protection Act 2012 Entered Into Force - Digital Policy Alert(digitalpolicyalert.org)
- Keynote address, National Data Protection Conference 2026 - Ministry of Communication, Digital Technology and Innovations(moc.gov.gh).gov