WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Africa

Ghana Privacy & Data Protection Laws

Every regime below can apply to a business handling Ghana residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

October 16, 2012
Data Protection Act, 2012
Ghana DPA (Act 843)
Verify details

One of West Africa's earliest data-protection statutes. It applies to a data controller established in Ghana where the data is processed in Ghana, and to a controller not established in Ghana that uses equipment or a data processor located in Ghana for processing other than mere transit — an equipment-based test rather than a targeting test, so the trigger below is modeled on established presence only, and a foreign controller relying on Ghanaian infrastructure or a Ghanaian processor should check the second limb specifically. The defining operational duty is registration: data controllers must register with the Data Protection Commission and renew periodically, and processing without registration is itself an offence. A controller not established in Ghana but caught by the equipment limb must nominate a Ghana-based representative.

Act 843 of 2012, ss. 45-46 (application)Read regulation →

Cross-Border Data Transfer · 1

Verify details

Personal data may be sent to a foreign country only where that country provides an adequate level of protection for data subjects' rights and freedoms, and the Data Protection Commission is the body that assesses adequacy — weighing the nature of the data, the purpose and duration of the proposed processing, the countries of origin and destination, the laws and professional rules in force in the receiving country, and whether any supervisory or judicial remedy is actually available to data subjects there. Ghana publishes no standing adequacy list, so the assessment is the exporter's to make and document, and it interacts with the Act's registration regime: the processing a controller registers with the Commission includes where data may be transferred. Marked 'check': the section numbering could not be pinned down against the primary text, and the adequacy factors above come from independent legal-reference summaries of the Act rather than a direct reading.

Act 843 of 2012Read regulation →

Data Security & Breach Notification · 1

Like South Africa's POPIA, Ghana sets no materiality threshold: where there are reasonable grounds to believe that personal data has been accessed or acquired by an unauthorised person, the controller must notify both the Data Protection Commission and the data subject, as soon as reasonably practicable after discovery, and the notice to the data subject must carry enough information for them to take protective measures. There is no risk-of-harm filter to apply first and no fixed hour count. Note how this interacts with the scope point in Ghana's comprehensive-law entry: the Act reaches a controller not established in Ghana that uses equipment or a Ghanaian processor for processing, so a foreign business relying on Ghanaian infrastructure can owe this duty without having a local entity. Marked 'check': the section text was taken from independent legal-reference sources and the Commission's own breach report form rather than read in the primary text.

Act 843 of 2012, s. 31Read regulation →

Other Africa jurisdictions