Ghana DPA 2012
Market regime · Data Protection Act, 2012 (Act 843, Ghana)
Republic of Ghana
Ghana
2012; a modernising redraft is in progress
Data Protection Commission (Ghana)
You process personal data in Ghana or of Ghanaian data subjects
Curated, versioned & cross-mapped
The obligation, plainly.
Ghana's Act 843 was among Africa's earliest comprehensive data-protection laws: controllers register with the Data Protection Commission, process under the Act's principles, honour data-subject rights, secure personal data under section 28, and notify the Commission of security breaches under section 31.
A modernising redraft has been in motion to bring the 2012 text up to the GDPR-era baseline; the curated framework tracks the Act as it stands and will version to the new law when it passes, the overlay model doing exactly what it exists for.
Where programmes are tested.
DPC registration
Controllers registered with the Commission and renewed on schedule; the certificate is asked for in diligence.
Principles and rights
Lawful, fair processing under the Act's principles, with access and correction rights answered.
Section 28 security
Appropriate, demonstrable security measures for personal data.
Section 31 breach notice
Security compromises notified to the Commission and affected subjects.
Curated once, evidenced continuously.
- Act 843 is curated beside the ECOWAS Supplementary Act it descends from and cross-mapped to the shared privacy control set, with a v2 ready path for the redraft.
- Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
- Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
- Every attestation carries maker/checker, and every action lands in an append-only audit trail.
Ghana DPA 2012, asked plainly.
The questions compliance teams actually ask before an adoption decision or an audit.
Who must register with Ghana's Data Protection Commission?
Data controllers processing personal data in Ghana, registration is the Act's entry obligation and renewable every two years. Operating unregistered is an offence, and counterparties increasingly check the register during onboarding.
What does section 31 require after a breach?
Notification to the Commission and communication to affected data subjects where a security compromise occurs, as soon as reasonably practicable. The Act predates the 72-hour convention, but the practical discipline is the same: detect, assess, notify, and evidence each step.
Is Ghana's data-protection law changing?
A modernising redraft has been in progress to align Act 843 with the GDPR-era baseline, clearer lawful bases, stronger rights and penalties. We track the current Act today and will curate the successor as a new version the moment it is enacted, so adopters inherit the change deliberately.
How does Act 843 relate to the ECOWAS Supplementary Act?
Ghana's Act transposes the regional baseline ECOWAS set in 2010, which is why the two are curated side by side: the Supplementary Act explains the floor, the national Act carries the enforceable obligations.
Where it connects.
The full catalogCompliance you can prove.
Walk into your next audit ready.
Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.
The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.