Skip to content

Evidence request lists

Ethiopia Personal Data Protection Proclamation (No. 1321/2024)

Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Ethiopia PDPP - Controllers, Processors and Registration

ETH-PDPP-Art.33-39
Controller registration regime

Sets the registration regime with the Authority: registration (Art.33); power to refuse registration (Art.34); effects of registration (Art.35); duty to notify change (Art.36); removal from register (Art.37); cancellation of registration (Art.38); access by the public (Art.39).

Artefacts an auditor will ask for
  • Authority-registration certificate
  • Change-notification procedure
  • Public-access information per Art.39
Where this commonly fails
  • Operating as a controller without Authority registration
  • Material changes not notified

Ethiopia PDPP - Cross Border Transfer

ETH-PDPP-Art.18-22
Cross-border transfer and data sovereignty

Sets the principle of data transfer (Art.18), the required level of protection in third parties (Art.19), conditions for cross-border transfer (Art.20), safeguards prior to cross-border transfer (Art.21) and data sovereignty considerations (Art.22).

Artefacts an auditor will ask for
  • Transfer-impact assessment
  • Safeguards prior to transfer (contractual/certification)
  • Data-sovereignty justification where applicable
Where this commonly fails
  • Transferring without an Art.19 protection-level assessment or Art.21 safeguards
ETH-PDPP-Art.23
Duration of personal data protection

Sets the duration for which personal data protection applies, including continuation of obligations after the relevant processing has ended where required for the purposes specified.

Artefacts an auditor will ask for
  • Post-processing obligations documented (e.g. retention for legal-defence, audit)
Where this commonly fails
  • Treating obligations as ending strictly at end of processing without legal-basis review

Ethiopia PDPP - Data Protection Officer and Accountability

ETH-PDPP-Art.40-41
Data Protection Officer

Art.40 designation of a Data Protection Officer (DPO); Art.41 duties of the DPO, including advising the controller/processor, monitoring compliance, training, and cooperating with the Authority.

Artefacts an auditor will ask for
  • DPO designation and reporting line
  • DPO duties documented and resourced
Where this commonly fails
  • No designated DPO where required by Art.40
  • DPO without sufficient independence to discharge Art.41 duties
ETH-PDPP-Art.52
Accountability of the controller

The controller is responsible for and must be able to demonstrate compliance with the Proclamation, including by documenting processing decisions and the measures implemented.

Artefacts an auditor will ask for
  • Accountability record (decisions, basis, safeguards) per processing activity
Where this commonly fails
  • No demonstrable accountability record

Ethiopia PDPP - Data Quality and Security

ETH-PDPP-Art.12-15
Fairness/transparency, purpose limitation, accuracy, storage limitation

Art.12 fairness and transparency; Art.13 purpose limitation; Art.14 accuracy; Art.15 storage limitation - personal data shall be kept for no longer than is necessary for the purposes for which it is processed.

Artefacts an auditor will ask for
  • Documented purposes per processing activity
  • Accuracy/validation controls
  • Retention schedule with deletion evidence
Where this commonly fails
  • Open-ended retention
  • Inaccurate records left uncorrected
ETH-PDPP-Art.16-17
Integrity and confidentiality; Security

Art.16 integrity and confidentiality (the data must be protected against unauthorised or unlawful processing and against accidental loss, destruction or damage). Art.17 sets the security obligation requiring appropriate technical and organisational measures.

Artefacts an auditor will ask for
  • Technical and organisational measures matched to risk
  • Confidentiality undertakings for staff and processors
Where this commonly fails
  • No documented security programme proportionate to processing risk

Ethiopia PDPP - Data Subject Rights

ETH-PDPP-Art.24-28
Right to be informed, access, rectification and erasure

Art.24 right to be informed; Art.25 right of access; Art.26 exceptions to the right of access (national security, criminal investigation, etc.); Art.27 right to rectification; Art.28 right to erasure ('right to be forgotten').

Artefacts an auditor will ask for
  • Subject access request procedure with response timelines
  • Documented Art.26 exceptions per refusal
  • Rectification and erasure logs
Where this commonly fails
  • No documented procedure for rights handling
  • Blanket Art.26 refusals without case-by-case test
ETH-PDPP-Art.29-32
Right to object, restriction, automated decision-making, portability

Art.29 right to object; Art.30 restriction of processing; Art.31 automated individual decision-making with the right to obtain human intervention and contest the decision; Art.32 right to data portability.

Artefacts an auditor will ask for
  • Objection/restriction handling procedure
  • Automated-decision register and human-intervention path
  • Data portability format support
Where this commonly fails
  • No human-intervention path on solely automated decisions producing legal/similarly significant effects

Ethiopia PDPP - Final Provisions

ETH-PDPP-Art.65-70
Reference, cooperation duties, non-applicable laws, transitory and final provisions

Art.65 reference rules in conflict of laws; Art.66 duty to cooperate with the Authority; Art.67 non-applicable existing laws displaced by this Proclamation; Art.68 transitory provisions; Art.69 power to issue Regulations and Directives; Art.70 effective date (date of publication in the Federal Negarit Gazette).

Artefacts an auditor will ask for
  • Cooperation evidence with the Authority per Art.66
  • Awareness of Directives/Regulations issued under Art.69
Where this commonly fails
  • Reliance on Authority guidance lacks tracking of Directives/Regulations

Ethiopia PDPP - General Provisions

ETH-PDPP-Art.1-3
Short Title, Definitions and Scope

Art.1 cites the Act as the Personal Data Protection Proclamation No. 1321/2024. Art.2 sets the definitions. Art.3 sets the scope of application of the Proclamation to processing of personal data of natural persons in Ethiopia, including data controllers and processors operating in Ethiopia or processing the data of natural persons in Ethiopia.

Artefacts an auditor will ask for
  • Mapping of in-scope processing per the Art.3 territorial/material scope
  • Use of the Act's defined terms in policies
Where this commonly fails
  • Treating Ethiopia operations as out-of-scope where data of persons in Ethiopia is processed
ETH-PDPP-Art.4-5
Powers and functions of the Ministry and the Authority

Art.4 sets the powers and functions of the Ministry; Art.5 establishes the personal data protection Authority and its powers and functions including registration of controllers, enforcement and supervision.

Artefacts an auditor will ask for
  • Awareness of the Authority's registration/supervision powers and Ministry's competences
Where this commonly fails
  • Engaging only Ministry channels where Authority handles registration/supervision

Ethiopia PDPP - Monitoring, Sanctions and Offences

ETH-PDPP-Art.55-58
Enforcement orders, monitoring and complaints

Art.55 the Authority's enforcement orders; Art.56 power to obtain information; Art.57 monitoring activities; Art.58 complaints by data subjects to the Authority.

Artefacts an auditor will ask for
  • Cooperation records with Authority orders and information requests
  • Complaint-handling procedure linked to the Authority
Where this commonly fails
  • Non-cooperation with Authority information requests
ETH-PDPP-Art.59-62
Administrative fines, sanctions and complaints

Art.59 principles for imposing administrative fines; Art.60 administrative sanctions; Art.61 administrative complaints; Art.62 decisions on administrative complaints.

Artefacts an auditor will ask for
  • Awareness of administrative fine scales and aggravating/mitigating factors
  • Internal admin-complaint escalation procedure
Where this commonly fails
  • No tracking of Authority administrative decisions affecting the controller
ETH-PDPP-Art.63-64
Burden of proof and criminal offences

Art.63 the burden of proof in proceedings (with specific allocation rules); Art.64 criminal offences and sanctions, including for unlawful processing of sensitive personal data and obstruction of the Authority.

Artefacts an auditor will ask for
  • Documentation supporting demonstrability under Art.63
  • Awareness of Art.64 criminal-offence categories
Where this commonly fails
  • Unlawful sensitive-data processing risks Art.64 criminal liability

Ethiopia PDPP - Principles of Processing

ETH-PDPP-Art.6
Principles of personal data processing

Sets the core principles of processing: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.

Artefacts an auditor will ask for
  • Documented principles applied per processing activity
  • Accountability records demonstrating principle adherence
Where this commonly fails
  • Processing without an articulated principles framework
ETH-PDPP-Art.7
Lawfulness of processing

Processing is lawful only where one of the listed legal bases applies (e.g. consent, contract, legal obligation, vital interests, public interest, legitimate interests, with corresponding tests).

Artefacts an auditor will ask for
  • Documented lawful basis per processing activity
Where this commonly fails
  • No documented lawful basis
  • Defaulting to consent for processing that fits another basis better
ETH-PDPP-Art.8
Conditions for consent

Sets the conditions for valid consent: freely given, specific, informed, unambiguous, and capable of being withdrawn easily; specific protections for consent given by minors and for re-purposing.

Artefacts an auditor will ask for
  • Consent records (purpose, scope, withdrawal capability)
  • Mechanisms for parental/guardian consent for minors
Where this commonly fails
  • Bundled or coerced consent
  • No easy withdrawal

Ethiopia PDPP - Research Exceptions

ETH-PDPP-Art.53-54
Research and exceptions to research

Art.53 the principle for scientific and historical research processing; Art.54 exceptions to research (with appropriate safeguards such as pseudonymisation, restrictions on disclosure, and ethics review).

Artefacts an auditor will ask for
  • Research-purpose documentation
  • Pseudonymisation and disclosure restrictions for research datasets
  • Ethics review where required
Where this commonly fails
  • Identifiable research datasets where pseudonymisation is feasible

Ethiopia PDPP - Security, Breach and DPIA

ETH-PDPP-Art.42-45
Security measures, breach notification and prior security check

Art.42 technical and organisational measures; Art.43 notification to the Authority of a personal data breach; Art.44 communication to the data subject of breaches likely to result in a high risk to rights and freedoms; Art.45 prior security check for higher-risk processing.

Artefacts an auditor will ask for
  • Incident response plan with Authority-notification and data-subject-communication paths
  • Records of breach notifications and communications
  • Prior security check records where required
Where this commonly fails
  • No breach notification path to the Authority
  • No prior security check for higher-risk processing
ETH-PDPP-Art.46-48
Records of processing, DPIA and prior authorisation/consultation

Art.46 records of processing operations; Art.47 Data Protection Impact Assessment for high-risk processing; Art.48 prior authorisation and consultation with the Authority for residual high risks.

Artefacts an auditor will ask for
  • Records of processing activities (ROPA)
  • DPIAs for high-risk processing
  • Prior-consultation records with the Authority
Where this commonly fails
  • No DPIA for high-risk processing
  • Skipping prior consultation where residual risk is high
ETH-PDPP-Art.49-51
Data protection by design and by default; duty to destroy; joint controllers

Art.49 data protection by design and by default; Art.50 duty to destroy personal data at end of retention; Art.51 joint data controllers' joint and several responsibilities and transparency to data subjects.

Artefacts an auditor will ask for
  • DPbD/DPbDef evidence at system design time
  • Secure-destruction records at end of retention
  • Joint-controller arrangements documented (Art.51)
Where this commonly fails
  • DPbD treated as documentation only
  • Indefinite retention
  • Joint-controller responsibilities undefined

Ethiopia PDPP - Sensitive Data and Minors

ETH-PDPP-Art.11
Processing of personal data of a minor

Strengthens protections for the processing of personal data of minors, requiring parental/guardian consent and additional safeguards proportionate to the risks to the rights of the minor.

Artefacts an auditor will ask for
  • Parental/guardian consent records
  • Risk-proportionate safeguards for minors
Where this commonly fails
  • Processing minor PD without verified parental/guardian consent
ETH-PDPP-Art.9-10
Processing of sensitive personal data and further categories

Prohibits processing of sensitive personal data (health, biometric, genetic, sexual life, racial/ethnic, religious/political, criminal etc.) except where specified conditions apply, and provides for further categories of sensitive data to be designated by the Authority.

Artefacts an auditor will ask for
  • Sensitive-data inventory and lawful condition per processing
  • Designations by the Authority of further sensitive categories
Where this commonly fails
  • Processing sensitive PD without a documented Art.9 condition
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.