#
Omnibus statute in force since 2012 with an operational, currently-staffed regulator and an active registration regime; principal gap is the pending modernisation bill which has not yet displaced the current framework.
Sub-modules (5)
Regulator And AuthorityGreen
The Data Protection Commission ('the Commission' in the Act) oversees personal data protection matters in Ghana; its current Executive Director/Commissioner is confirmed via a 2026 multilateral regulator joint statement.
Claims (2):
- The Ghanaian Data Protection Act provides for the Data Protection Commission ('DPC'), referred to as 'the Commission' in the Act, which oversees personal data protection matters in Ghana.
- As of early 2026, the Data Protection Commission (Ghana) is led by Dr Arnold Kavaarpuo (Executive Director/Commissioner), confirming the regulator is currently operational.
Act And InstrumentsAmber
Primary instrument is the Data Protection Act, 2012; Ghana is also bound by the ECOWAS Supplementary Act on Personal Data Protection and has signed/ratified the AU Malabo Convention; a Data Protection Bill (2024/2025) proposes a successor Data Protection Authority.
Claims (3):
- The Data Protection Act, 2012 came into force on October 16, 2012, and provides the general data privacy framework for Ghana applicable to both public and private bodies.
- Ghana is a signing member of the ECOWAS Supplementary Act A/SA.1/01/10 on Personal Data Protection and has signed and ratified the African Union Malabo Convention on Cyber Security and Personal Data Protection.
- A Data Protection Bill (drafted 2024/2025) proposes a comprehensive successor legal framework for data protection in Ghana, including creation of an independent Data Protection Authority to replace the current Commission structure.
Material ScopeGreen
The Act provides the general data privacy framework for Ghana and is applicable to both public and private bodies, covering assessable processing designated by executive instrument.
Claims (1):
- One of the key areas of the Data Protection Act relates to assessable processing, under which the Minister of Communications is given power by executive instrument to specify actions which constitute assessable processing.
Territorial ScopeAmber
The Act provides for extraterritorial-type application via the 'foreign data subject' concept and obligations on processors domiciled outside Ghana, though it is less explicit than GDPR Art. 3 on establishment tests.
Claims (2):
- The Ghanaian Act provides a similar potential for extraterritorial application as the GDPR, and is more detailed than the GDPR regarding what constitutes being established within the territory, defining 'foreign data subject' as data subject information regulated by a foreign jurisdiction's laws sent into Ghana for processing.
- The Act imposes obligations for ensuring adequate protection by data processors domiciled outside of Ghana under Article 30 and requires compliance with foreign jurisdiction legislation in the context of foreign data subjects' personal data under Article 18.
Regulator Registration And FilingGreen
Data controllers and processors are required to register with the DPC in the register of data controllers under Registration Guidelines published in 2015; historical enforcement has included public listing of non-compliant entities.
Claims (2):
- Data controllers are required to register with the Data Protection Commission (DPC) in the register of data controllers, a requirement that in some respects goes further than the GDPR's registration/notification regime.
- The DPC issued Registration Guidelines For Data Controllers and Data Processors in 2015 to operationalise the Data Processing Notification requirements found in Articles 27, 46, 50, 53, 55-57, 60-74 and 96 of the Act.
Key findings (3)
- — source on file
- — source on file
- — source on file
Sources and claims (10)
- ProbableOneTrust DataGuidance — The Ghanaian Data Protection Act provides for the Data Protection Commission ('DPC'), referred to as 'the Commission' in the Act, which oversees personal data protection matters in Ghana.observed
- ProbableOffice of the Privacy Commissioner of Canada — As of early 2026, the Data Protection Commission (Ghana) is led by Dr Arnold Kavaarpuo (Executive Director/Commissioner), confirming the regulator is currently operational.observed
- ProbableOneTrust DataGuidance — The Data Protection Act, 2012 came into force on October 16, 2012, and provides the general data privacy framework for Ghana applicable to both public and private bodies.observed
- ProbableOneTrust DataGuidance — Ghana is a signing member of the ECOWAS Supplementary Act A/SA.1/01/10 on Personal Data Protection and has signed and ratified the African Union Malabo Convention on Cyber Security and Personal Data Protection.observed
- ProbableOneTrust DataGuidance — A Data Protection Bill (drafted 2024/2025) proposes a comprehensive successor legal framework for data protection in Ghana, including creation of an independent Data Protection Authority to replace the current Commission structure.observed
- ProbableOneTrust DataGuidance — One of the key areas of the Data Protection Act relates to assessable processing, under which the Minister of Communications is given power by executive instrument to specify actions which constitute assessable processing.observed
- ProbableOneTrust DataGuidance — The Ghanaian Act provides a similar potential for extraterritorial application as the GDPR, and is more detailed than the GDPR regarding what constitutes being established within the territory, defining 'foreign data subject' as data subject information regulated by a foreign jurisdiction's laws sent into Ghana for processing.observed
- ProbableOneTrust DataGuidance — The Act imposes obligations for ensuring adequate protection by data processors domiciled outside of Ghana under Article 30 and requires compliance with foreign jurisdiction legislation in the context of foreign data subjects' personal data under Article 18.observed
- ProbableOneTrust DataGuidance — Data controllers are required to register with the Data Protection Commission (DPC) in the register of data controllers, a requirement that in some respects goes further than the GDPR's registration/notification regime.observed
- ProbableOneTrust DataGuidance — The DPC issued Registration Guidelines For Data Controllers and Data Processors in 2015 to operationalise the Data Processing Notification requirements found in Articles 27, 46, 50, 53, 55-57, 60-74 and 96 of the Act.observed