Data Security & Breach Notification
Data Protection Act, 2012 — notification of unauthorised access to or acquisition of personal data
Ghana · October 16, 2012
Verify detailsLike South Africa's POPIA, Ghana sets no materiality threshold: where there are reasonable grounds to believe that personal data has been accessed or acquired by an unauthorised person, the controller must notify both the Data Protection Commission and the data subject, as soon as reasonably practicable after discovery, and the notice to the data subject must carry enough information for them to take protective measures. There is no risk-of-harm filter to apply first and no fixed hour count. Note how this interacts with the scope point in Ghana's comprehensive-law entry: the Act reaches a controller not established in Ghana that uses equipment or a Ghanaian processor for processing, so a foreign business relying on Ghanaian infrastructure can owe this duty without having a local entity. Marked 'check': the section text was taken from independent legal-reference sources and the Commission's own breach report form rather than read in the primary text.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.