GhanaIn ForceData Protection

Data Protection Act, 2012 (Act 843)

gh-dpa-2012 · Act

Verified entryReviewed by Ademola Adekunbi · 27 June 2026
Summary

The Data Protection Act, 2012 (Act 843) is Ghana's primary statute governing the collection, storage, use, and disclosure of personal data. Assented to on 10 May 2012 and brought into force on 16 October 2012, the Act regulates the activities of data controllers and processors in Ghana and protects individuals against the misuse of their personal information. The Act applies to any person who collects, processes, holds, or uses personal data in Ghana, and extends to data controllers established outside Ghana that use equipment within Ghana to process personal data, except for transit purposes. This extraterritorial hook captures foreign organisations that rely on locally situated infrastructure. The Act establishes the Data Protection Commission (DPC) as Ghana's independent regulatory body, mandated to ensure compliance with the Act, maintain the Data Protection Register, investigate complaints, and enforce the Act's provisions. All data controllers are required to register with the DPC before processing personal data. The Act articulates core data protection principles that all controllers must observe: personal data must be collected for a specific, explicitly defined, and lawful purpose that is related to the controller's functions; must be adequate, relevant, and not excessive relative to that purpose; must be accurate, complete, and kept up to date; must not be retained longer than necessary; and must be protected by appropriate security measures against loss, damage, and unauthorised access. Consent of the data subject is required as the primary basis for processing personal data. Special categories of sensitive data, including health information, racial or ethnic origin, political opinions, religious beliefs, biometric data, criminal records, and sexual orientation, may only be processed on specific, restricted grounds. Data subjects in Ghana are granted a set of rights: the right to access their personal data held by a data controller, the right to have inaccurate or incomplete data corrected, the right to prevent processing likely to cause unwarranted damage or distress, the right to prevent processing for direct marketing, the right to object to automated decision-making, and the right to claim compensation for damage suffered through a controller's non-compliance. Cross-border transfers of personal data are restricted to countries that provide an adequate level of data protection, or where specific conditions are satisfied, including the consent of the data subject. Criminal penalties, including fines and imprisonment, are available for data controllers found to be in serious breach of the Act's requirements.

Key provisions
  1. Establishes the Data Protection Commission (DPC) as Ghana's independent supervisory authority, empowered to register data controllers, receive complaints, investigate violations, and enforce compliance.
  2. Requires all data controllers to register with the DPC before processing personal data, with a publicly accessible Data Protection Register maintained by the Commission.
  3. Mandates that personal data be collected only for a specific, explicitly defined, and lawful purpose related to the controller's functions, and not processed incompatibly with that purpose.
  4. Requires prior consent from data subjects before processing their personal data, with heightened requirements for sensitive categories including health, biometric, racial or ethnic origin, and criminal records data.
  5. Grants data subjects rights of access, rectification, prevention of harmful processing, prevention of direct marketing, objection to automated decision-making, and compensation for non-compliance.
  6. Restricts cross-border transfers of personal data to countries with an adequate level of protection or where the data subject has given consent.
  7. Requires data controllers to implement appropriate technical and organisational security measures to protect personal data against loss, damage, and unauthorised access, use, or disclosure.
  8. Provides for criminal sanctions, including fines and imprisonment, for serious breaches of the Act's requirements by data controllers.
Entry history
Entry history
  1. 23 June 2026
    ATLPF Research Team (AI-assisted)
    Initial draft created from Ghana Data Protection Commission official website and NITA Ghana official Act text