Ethiopia Personal Data Protection Proclamation (No. 1321/2024)
Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Ethiopia PDPP - Controllers, Processors and Registration
Sets the registration regime with the Authority: registration (Art.33); power to refuse registration (Art.34); effects of registration (Art.35); duty to notify change (Art.36); removal from register (Art.37); cancellation of registration (Art.38); access by the public (Art.39).
- Authority-registration certificate
- Change-notification procedure
- Public-access information per Art.39
- Operating as a controller without Authority registration
- Material changes not notified
Ethiopia PDPP - Cross Border Transfer
Sets the principle of data transfer (Art.18), the required level of protection in third parties (Art.19), conditions for cross-border transfer (Art.20), safeguards prior to cross-border transfer (Art.21) and data sovereignty considerations (Art.22).
- Transfer-impact assessment
- Safeguards prior to transfer (contractual/certification)
- Data-sovereignty justification where applicable
- Transferring without an Art.19 protection-level assessment or Art.21 safeguards
Sets the duration for which personal data protection applies, including continuation of obligations after the relevant processing has ended where required for the purposes specified.
- Post-processing obligations documented (e.g. retention for legal-defence, audit)
- Treating obligations as ending strictly at end of processing without legal-basis review
Ethiopia PDPP - Data Protection Officer and Accountability
Art.40 designation of a Data Protection Officer (DPO); Art.41 duties of the DPO, including advising the controller/processor, monitoring compliance, training, and cooperating with the Authority.
- DPO designation and reporting line
- DPO duties documented and resourced
- No designated DPO where required by Art.40
- DPO without sufficient independence to discharge Art.41 duties
The controller is responsible for and must be able to demonstrate compliance with the Proclamation, including by documenting processing decisions and the measures implemented.
- Accountability record (decisions, basis, safeguards) per processing activity
- No demonstrable accountability record
Ethiopia PDPP - Data Quality and Security
Art.12 fairness and transparency; Art.13 purpose limitation; Art.14 accuracy; Art.15 storage limitation - personal data shall be kept for no longer than is necessary for the purposes for which it is processed.
- Documented purposes per processing activity
- Accuracy/validation controls
- Retention schedule with deletion evidence
- Open-ended retention
- Inaccurate records left uncorrected
Art.16 integrity and confidentiality (the data must be protected against unauthorised or unlawful processing and against accidental loss, destruction or damage). Art.17 sets the security obligation requiring appropriate technical and organisational measures.
- Technical and organisational measures matched to risk
- Confidentiality undertakings for staff and processors
- No documented security programme proportionate to processing risk
Ethiopia PDPP - Data Subject Rights
Art.24 right to be informed; Art.25 right of access; Art.26 exceptions to the right of access (national security, criminal investigation, etc.); Art.27 right to rectification; Art.28 right to erasure ('right to be forgotten').
- Subject access request procedure with response timelines
- Documented Art.26 exceptions per refusal
- Rectification and erasure logs
- No documented procedure for rights handling
- Blanket Art.26 refusals without case-by-case test
Art.29 right to object; Art.30 restriction of processing; Art.31 automated individual decision-making with the right to obtain human intervention and contest the decision; Art.32 right to data portability.
- Objection/restriction handling procedure
- Automated-decision register and human-intervention path
- Data portability format support
- No human-intervention path on solely automated decisions producing legal/similarly significant effects
Ethiopia PDPP - Final Provisions
Art.65 reference rules in conflict of laws; Art.66 duty to cooperate with the Authority; Art.67 non-applicable existing laws displaced by this Proclamation; Art.68 transitory provisions; Art.69 power to issue Regulations and Directives; Art.70 effective date (date of publication in the Federal Negarit Gazette).
- Cooperation evidence with the Authority per Art.66
- Awareness of Directives/Regulations issued under Art.69
- Reliance on Authority guidance lacks tracking of Directives/Regulations
Ethiopia PDPP - General Provisions
Art.1 cites the Act as the Personal Data Protection Proclamation No. 1321/2024. Art.2 sets the definitions. Art.3 sets the scope of application of the Proclamation to processing of personal data of natural persons in Ethiopia, including data controllers and processors operating in Ethiopia or processing the data of natural persons in Ethiopia.
- Mapping of in-scope processing per the Art.3 territorial/material scope
- Use of the Act's defined terms in policies
- Treating Ethiopia operations as out-of-scope where data of persons in Ethiopia is processed
Art.4 sets the powers and functions of the Ministry; Art.5 establishes the personal data protection Authority and its powers and functions including registration of controllers, enforcement and supervision.
- Awareness of the Authority's registration/supervision powers and Ministry's competences
- Engaging only Ministry channels where Authority handles registration/supervision
Ethiopia PDPP - Monitoring, Sanctions and Offences
Art.55 the Authority's enforcement orders; Art.56 power to obtain information; Art.57 monitoring activities; Art.58 complaints by data subjects to the Authority.
- Cooperation records with Authority orders and information requests
- Complaint-handling procedure linked to the Authority
- Non-cooperation with Authority information requests
Art.59 principles for imposing administrative fines; Art.60 administrative sanctions; Art.61 administrative complaints; Art.62 decisions on administrative complaints.
- Awareness of administrative fine scales and aggravating/mitigating factors
- Internal admin-complaint escalation procedure
- No tracking of Authority administrative decisions affecting the controller
Art.63 the burden of proof in proceedings (with specific allocation rules); Art.64 criminal offences and sanctions, including for unlawful processing of sensitive personal data and obstruction of the Authority.
- Documentation supporting demonstrability under Art.63
- Awareness of Art.64 criminal-offence categories
- Unlawful sensitive-data processing risks Art.64 criminal liability
Ethiopia PDPP - Principles of Processing
Sets the core principles of processing: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.
- Documented principles applied per processing activity
- Accountability records demonstrating principle adherence
- Processing without an articulated principles framework
Processing is lawful only where one of the listed legal bases applies (e.g. consent, contract, legal obligation, vital interests, public interest, legitimate interests, with corresponding tests).
- Documented lawful basis per processing activity
- No documented lawful basis
- Defaulting to consent for processing that fits another basis better
Sets the conditions for valid consent: freely given, specific, informed, unambiguous, and capable of being withdrawn easily; specific protections for consent given by minors and for re-purposing.
- Consent records (purpose, scope, withdrawal capability)
- Mechanisms for parental/guardian consent for minors
- Bundled or coerced consent
- No easy withdrawal
Ethiopia PDPP - Research Exceptions
Art.53 the principle for scientific and historical research processing; Art.54 exceptions to research (with appropriate safeguards such as pseudonymisation, restrictions on disclosure, and ethics review).
- Research-purpose documentation
- Pseudonymisation and disclosure restrictions for research datasets
- Ethics review where required
- Identifiable research datasets where pseudonymisation is feasible
Ethiopia PDPP - Security, Breach and DPIA
Art.42 technical and organisational measures; Art.43 notification to the Authority of a personal data breach; Art.44 communication to the data subject of breaches likely to result in a high risk to rights and freedoms; Art.45 prior security check for higher-risk processing.
- Incident response plan with Authority-notification and data-subject-communication paths
- Records of breach notifications and communications
- Prior security check records where required
- No breach notification path to the Authority
- No prior security check for higher-risk processing
Art.46 records of processing operations; Art.47 Data Protection Impact Assessment for high-risk processing; Art.48 prior authorisation and consultation with the Authority for residual high risks.
- Records of processing activities (ROPA)
- DPIAs for high-risk processing
- Prior-consultation records with the Authority
- No DPIA for high-risk processing
- Skipping prior consultation where residual risk is high
Art.49 data protection by design and by default; Art.50 duty to destroy personal data at end of retention; Art.51 joint data controllers' joint and several responsibilities and transparency to data subjects.
- DPbD/DPbDef evidence at system design time
- Secure-destruction records at end of retention
- Joint-controller arrangements documented (Art.51)
- DPbD treated as documentation only
- Indefinite retention
- Joint-controller responsibilities undefined
Ethiopia PDPP - Sensitive Data and Minors
Strengthens protections for the processing of personal data of minors, requiring parental/guardian consent and additional safeguards proportionate to the risks to the rights of the minor.
- Parental/guardian consent records
- Risk-proportionate safeguards for minors
- Processing minor PD without verified parental/guardian consent
Prohibits processing of sensitive personal data (health, biometric, genetic, sexual life, racial/ethnic, religious/political, criminal etc.) except where specified conditions apply, and provides for further categories of sensitive data to be designated by the Authority.
- Sensitive-data inventory and lawful condition per processing
- Designations by the Authority of further sensitive categories
- Processing sensitive PD without a documented Art.9 condition
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.