Ghana
West Africa
Ghana regulates personal data through the Data Protection Act, 2012 (Act 843), one of the earlier comprehensive statutes in anglophone West Africa, assented to on 10 May 2012 and in force from 16 October 2012. It applies to any person who collects, processes, holds, or uses personal data in Ghana, and extends to controllers established abroad that use equipment in Ghana (other than for transit). The Act establishes the Data Protection Commission, requires all controllers to register before processing, and maintains a public Data Protection Register. It articulates core principles (purpose limitation, adequacy, accuracy, retention limits, security), generally requires consent, and applies restricted grounds to special categories (health, race or ethnicity, political opinions, religious belief, biometrics, criminal records, sexual orientation). Data subjects have rights of access, rectification, prevention of harmful processing, prevention of direct marketing, objection to automated decision-making, and compensation for non-compliance. Cross-border transfers are restricted to countries with adequate protection or where conditions such as consent are met, and criminal penalties apply for serious breaches. Enforcement rests with the Data Protection Commission (DPC), Ghana's independent supervisory authority, empowered to register controllers, maintain the Register, investigate complaints, and enforce compliance. With an established in-force Act and an operational named regulator, Ghana has one of the more settled anglophone regimes in the region, though its 2012 registration-centred design predates the GDPR accountability generation.
| Topic | Instruments | Cases | Coverage |
|---|---|---|---|
| Data Protection | 3 | 0 | ◐ |
| AI Governance | 1 | 0 | ◐ |
| Fintech | 4 | 0 | ◐ |
| Cybercrime | 1 | 0 | ◐ |
| Digital Rights | 3 | 0 | ◐ |
| Platform Liability | 0 | 0 | ○ |
| Telecoms | 0 | 0 | ○ |
● Covered ◐ Partially covered ○ Not yet covered
Constitution of the Republic of Ghana, 1992, Article 18(2) (Privacy of correspondence and communication)
Enacted 28 Apr 1992
Right to Information Act, 2019 (Act 989)
Enacted 21 May 2019
Cybersecurity Act, 2020 (Act 1038)
Enacted 29 Dec 2020
Payment Systems and Services Act, 2019 (Act 987)
Enacted 13 May 2019
Agency Banking Guideline (Ghana)
Enacted 1 Sept 2025
Guidelines for E-Money Issuers in Ghana
Enacted 6 Jul 2015
Virtual Asset Service Providers Act, 2025 (Act 1154)
Enacted 30 Dec 2025
Ghana National Artificial Intelligence Strategy 2023 - 2033
Enacted 1 Oct 2023
Data Protection Act, 2012 (Act 843)
Enacted 10 May 2012
The 2012 Act lacks a fixed statutory 72-hour breach-notification rule, a general DPO mandate, and modern portability/restriction rights. ATLPF holds the primary Act but no implementing regulations or DPC guidance as separate instruments, and the registration model imposes recurring compliance steps.