GH

Ghana

West Africa

9Instruments
0Cases
3Regulators
65%Coverage
Overview

Ghana regulates personal data through the Data Protection Act, 2012 (Act 843), one of the earlier comprehensive statutes in anglophone West Africa, assented to on 10 May 2012 and in force from 16 October 2012. It applies to any person who collects, processes, holds, or uses personal data in Ghana, and extends to controllers established abroad that use equipment in Ghana (other than for transit). The Act establishes the Data Protection Commission, requires all controllers to register before processing, and maintains a public Data Protection Register. It articulates core principles (purpose limitation, adequacy, accuracy, retention limits, security), generally requires consent, and applies restricted grounds to special categories (health, race or ethnicity, political opinions, religious belief, biometrics, criminal records, sexual orientation). Data subjects have rights of access, rectification, prevention of harmful processing, prevention of direct marketing, objection to automated decision-making, and compensation for non-compliance. Cross-border transfers are restricted to countries with adequate protection or where conditions such as consent are met, and criminal penalties apply for serious breaches. Enforcement rests with the Data Protection Commission (DPC), Ghana's independent supervisory authority, empowered to register controllers, maintain the Register, investigate complaints, and enforce compliance. With an established in-force Act and an operational named regulator, Ghana has one of the more settled anglophone regimes in the region, though its 2012 registration-centred design predates the GDPR accountability generation.

Topic coverage
TopicInstrumentsCasesCoverage
Data Protection30
AI Governance10
Fintech40
Cybercrime10
Digital Rights30
Platform Liability00
Telecoms00

● Covered  ◐ Partially covered  ○ Not yet covered

Instruments
gh-const-privacy·Act

Constitution of the Republic of Ghana, 1992, Article 18(2) (Privacy of correspondence and communication)

GhanaDigital RightsData ProtectionIn Force
Verified

Enacted 28 Apr 1992

gh-rti-2019·Act

Right to Information Act, 2019 (Act 989)

GhanaDigital RightsIn Force
Verified

Enacted 21 May 2019

gh-cyber-2020·Act

Cybersecurity Act, 2020 (Act 1038)

GhanaCybercrimeData ProtectionDigital RightsIn Force
Verified

Enacted 29 Dec 2020

gh-pssact-2019·Act

Payment Systems and Services Act, 2019 (Act 987)

GhanaFintechIn Force
Verified

Enacted 13 May 2019

gh-agencybanking-2025·Guidance

Agency Banking Guideline (Ghana)

GhanaFintechIn Force
Verified

Enacted 1 Sept 2025

gh-emoney-2015·Guidance

Guidelines for E-Money Issuers in Ghana

GhanaFintechIn Force
Verified

Enacted 6 Jul 2015

gh-vaspact-2025·Act

Virtual Asset Service Providers Act, 2025 (Act 1154)

GhanaFintechIn Force
Verified

Enacted 30 Dec 2025

gh-ai-2023·Guidance

Ghana National Artificial Intelligence Strategy 2023 - 2033

GhanaAI GovernanceProposed
Verified

Enacted 1 Oct 2023

gh-dpa-2012·Act

Data Protection Act, 2012 (Act 843)

GhanaData ProtectionIn Force
Verified

Enacted 10 May 2012

Notable gaps

The 2012 Act lacks a fixed statutory 72-hour breach-notification rule, a general DPO mandate, and modern portability/restriction rights. ATLPF holds the primary Act but no implementing regulations or DPC guidance as separate instruments, and the registration model imposes recurring compliance steps.