Personal Data Protection Proclamation No. 1321/2024 (Ethiopia)
et-pdpp-2024 · Act
Ethiopia's Personal Data Protection Proclamation No. 1321/2024 is the country's first comprehensive personal data protection statute. It was adopted on 4 April 2024 and published in the Federal Negarit Gazette on 24 July 2024, bringing the framework into force. The Proclamation establishes data-processing principles, lawful bases for processing, and a structured set of data-subject rights, and creates an institutional supervisor for the regime. The law grants individuals the rights to access, rectify, erase, and restrict the processing of their personal data, and to object to direct marketing and to automated decision-making. Controllers and processors must observe core obligations around lawful, fair processing and appropriate technical and organisational security measures, and must notify personal data breaches. A defining and unusually strict feature is the data-localisation requirement: controllers and processors are required to store collected personal data on a server or data centre located in Ethiopia, a constraint that materially affects cross-border data flows and cloud arrangements. The Proclamation designates the Ethiopian Communications Authority (ECA) as the independent supervisory authority responsible for oversight and enforcement. Enforcement measures range from administrative fines to imprisonment for offences such as failure to notify a breach, inadequate implementation of technical and organisational measures, or processing personal data contrary to the Proclamation. This entry was created from a June 2026 verification search rather than from a pre-existing ATLPF research file; the precise detail of lawful bases, sensitive-data categories, cross-border transfer mechanisms (beyond localisation), and the penalty schedule should be confirmed against the official Negarit Gazette text. Locating and linking the primary text is a priority reviewer action. Source language: Amharic (with English commentary widely available).
- Ethiopia's first comprehensive data protection statute; adopted 4 April 2024 and in force on publication in the Federal Negarit Gazette on 24 July 2024.
- Data subjects have rights of access, rectification, erasure, restriction, and objection to direct marketing and automated decision-making.
- Imposes a strict data-localisation requirement: personal data must be stored on a server or data centre located in Ethiopia.
- Designates the Ethiopian Communications Authority (ECA) as the independent supervisory authority.
- Breach notification is mandatory; failure to notify is a sanctionable offence.
- Enforcement ranges from administrative fines to imprisonment for serious offences.
- Reviewer action: confirm provisions against the official Negarit Gazette text and add primary-source URL.