Ghana DPA 2012

West Africa's pioneer data-protection act: registration, principles and security duties under the DPC.

Market regime · Data Protection Act, 2012 (Act 843, Ghana)

Issued by

Republic of Ghana

Region

Ghana

Effective

2012; a modernising redraft is in progress

Oversight

Data Protection Commission (Ghana)

Applies when

You process personal data in Ghana or of Ghanaian data subjects

In the catalog

Curated, versioned & cross-mapped

The obligation, plainly.

Ghana's Act 843 was among Africa's earliest comprehensive data-protection laws: controllers register with the Data Protection Commission, process under the Act's principles, honour data-subject rights, secure personal data under section 28, and notify the Commission of security breaches under section 31.

A modernising redraft has been in motion to bring the 2012 text up to the GDPR-era baseline; the curated framework tracks the Act as it stands and will version to the new law when it passes, the overlay model doing exactly what it exists for.

Where programmes are tested.

01

DPC registration

Controllers registered with the Commission and renewed on schedule; the certificate is asked for in diligence.

02

Principles and rights

Lawful, fair processing under the Act's principles, with access and correction rights answered.

03

Section 28 security

Appropriate, demonstrable security measures for personal data.

04

Section 31 breach notice

Security compromises notified to the Commission and affected subjects.

Curated once, evidenced continuously.

  • Act 843 is curated beside the ECOWAS Supplementary Act it descends from and cross-mapped to the shared privacy control set, with a v2 ready path for the redraft.
  • Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
  • Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
  • Every attestation carries maker/checker, and every action lands in an append-only audit trail.

Ghana DPA 2012, asked plainly.

The questions compliance teams actually ask before an adoption decision or an audit.

Who must register with Ghana's Data Protection Commission?

Data controllers processing personal data in Ghana, registration is the Act's entry obligation and renewable every two years. Operating unregistered is an offence, and counterparties increasingly check the register during onboarding.

What does section 31 require after a breach?

Notification to the Commission and communication to affected data subjects where a security compromise occurs, as soon as reasonably practicable. The Act predates the 72-hour convention, but the practical discipline is the same: detect, assess, notify, and evidence each step.

Is Ghana's data-protection law changing?

A modernising redraft has been in progress to align Act 843 with the GDPR-era baseline, clearer lawful bases, stronger rights and penalties. We track the current Act today and will curate the successor as a new version the moment it is enacted, so adopters inherit the change deliberately.

How does Act 843 relate to the ECOWAS Supplementary Act?

Ghana's Act transposes the regional baseline ECOWAS set in 2010, which is why the two are curated side by side: the Supplementary Act explains the floor, the national Act carries the enforceable obligations.

Compliance you can prove.
Walk into your next audit ready.

Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.

The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.