Ghana Data Protection Act 2012 (Act 843)
Evidence request list. 12 controls, 12 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Ghana DPA: 8 Data Protection Principles + Lawful Basis + Consent (Sec 17-24, Part Two)
Ghana DPA 2012 8 Data Protection Principles + lawful basis (Sec.17-24, Part Two). EIGHT PRINCIPLES: (1) ACCOUNTABILITY (Sec.17) - controller responsible for compliance; (2) LAWFULNESS OF PROCESSING (Sec.18) - lawful basis required including consent + contract + legal obligation + vital interests + public-interest + legitimate-interests; (3) SPECIFICATION OF PURPOSE (Sec.19) - specific + explicit + legitimate purpose; (4) COMPATIBILITY OF FURTHER PROCESSING (Sec.20) - compatible with original purpose only; (5) QUALITY OF DATA (Sec.21) - accurate + complete + up to date; (6) OPENNESS (Sec.22) - transparency notice + information about processing; (7) DATA SECURITY SAFEGUARDS (Sec.23) - appropriate technical + organisational measures; (8) DATA SUBJECT PARTICIPATION (Sec.24) - data subjects empowered to access + correct + control. CONSENT: must be freely given + specific + informed + verifiab
- Principles implementation evidence
- Lawful basis register
- Consent records + withdrawal
- Children consent verification
- Principles applied superficially
- Consent unclear or implied
- Children threshold confused with GDPR-13/16
Ghana DPA: Cross-Border Transfers, Breach Notification and Enforcement (Part Five)
Ghana DPA 2012 Part Five - Cross-Border + Breach + Enforcement. CROSS-BORDER TRANSFERS (Sec.47): personal data may be transferred outside Ghana only where: (a) ADEQUACY - destination country provides adequate level of protection (DPC determination); (b) APPROPRIATE SAFEGUARDS - binding corporate rules + standard contractual clauses + approved code of conduct + safeguards approved by DPC; (c) DEROGATIONS - explicit consent + contract necessity + public interest + legal claims + vital interests + Ministerial approval for sensitive transfers; (d) ECOWAS regional cooperation: data transfers within ECOWAS member states benefit from regional supplementary act. BREACH NOTIFICATION (Sec.55): controllers must notify DPC of personal data breach without undue delay; for material breaches with risk of harm to data subjects + notification to affected individuals required; documented incident records.
- Cross-border transfer mechanism + records
- Breach response procedure + DPC notification
- Penalty risk assessment
- Appeals procedure
- Transfers without adequacy/safeguards
- Breach notification slow
- Penalty risk underestimated
Ghana DPA: Data Controller + Processor Registration + Obligations (Part Four)
Ghana DPA 2012 Part Four - Registration + Controller/Processor Obligations. REGISTRATION (Sec.41-46): all data controllers + processors processing personal data in Ghana must REGISTER with DPC + complete REGISTRATION APPLICATION (Sec.42) including organizational details + categories of data + purposes + cross-border transfers + safeguards; the DPC may approve + reject + impose conditions; REGISTRATION FEE annual + scaled to organization size; REGISTRATION CERTIFICATE issued (Sec.43) + valid 2 years + renewable; PUBLIC REGISTER maintained by DPC accessible online. CONTROLLER OBLIGATIONS: lawful processing + 8 principles compliance + data subject rights enablement + security safeguards (technical + organisational) + breach notification + records of processing + cross-border transfer compliance + cooperation with DPC. PROCESSOR OBLIGATIONS: written contract with controller specifying scope
- DPC registration + renewal records
- RoPA + records-of-processing
- Processor agreement template
- DPC engagement records
- Registration lapsed
- RoPA missing
- Processor agreement weak
- DPC cooperation inconsistent
Ghana DPA: Data Subject Rights (Access, Rectification, Erasure, Objection, Portability) (Sec 30-38)
Ghana DPA 2012 Data Subject Rights (Sec.30-38). RIGHTS: (1) RIGHT TO INFORMATION (Sec.30) - clear privacy notice + collection-time information; (2) RIGHT OF ACCESS (Sec.32) - confirmation + copy of personal data + processing purposes + categories + recipients + retention + rights information; controller must respond within 40 DAYS (or shorter where required); (3) RIGHT TO RECTIFICATION (Sec.33) - correction of inaccurate or incomplete data; (4) RIGHT TO ERASURE (Sec.36) - deletion when data unlawful + obsolete + withdrawal of consent + objection sustained; (5) RIGHT TO OBJECT (Sec.34) - processing based on legitimate interests + direct marketing (absolute right) + research; (6) RIGHT TO DATA PORTABILITY (Sec.38, 2017 amendment) - structured + commonly used + machine-readable format + transmit to another controller; (7) AUTOMATED DECISION-MAKING (Sec.37, 2017 amendment) - protection from
- Rights request log + 40-day SLA
- ADM + portability implementation
- DPC complaint procedure
- Rights gaps
- 40-day SLA missed
- ADM + portability not implemented
Ghana DPA: Scope, DPC Establishment and Definitions (Part One)
Ghana DPA 2012 Part One. SCOPE (Sec.3): applies to (a) personal data of natural persons processed in Ghana or by Ghanaian-established controllers; (b) extraterritorial processing where data subjects are in Ghana or where the controller has presence in Ghana. ESTABLISHMENT OF DATA PROTECTION COMMISSION (Sec.1-15): the DPC is an INDEPENDENT statutory body with Director-General + Board (representing public + private + civil society) + Secretariat + offices in Accra + regional offices; FUNCTIONS include monitoring + enforcement + complaint-handling + registration of data controllers + investigations + audits + guidance + international cooperation + Ministerial advisory. DEFINITIONS (Sec.2): PERSONAL DATA = data relating to an identified or identifiable individual; CONTROLLER + PROCESSOR per pre-GDPR distinction; CONSENT = freely-given specific informed; SENSITIVE PERSONAL DATA = race + ethni
- DPC-applicability assessment
- DPC contact + cooperation procedure
- Definitions glossary + GDPR cross-map
- Scope misunderstood
- DPC engagement reactive
- Definitions not GDPR-aligned
Ghana DPA: Sectoral Coordination (Cybersecurity Act, ECOWAS, Malabo) and 2024-2025 Pipeline
Ghana DPA 2012 sectoral + regional + international coordination. GHANA CYBERSECURITY ACT 2020 (Act 1038, separately verified in corpus): cybersecurity-incident-personal-data overlap; cybersecurity breach affecting personal data triggers BOTH Ghana DPA Sec.55 breach notification (to DPC) AND Ghana CSA 24-hour incident reporting (to CSA Ghana); the two regulators (DPC + CSA Ghana) maintain MoUs for coordination. ELECTRONIC TRANSACTIONS ACT 2008 (Act 772): foundational e-commerce + electronic-records + electronic-signatures; complements Ghana DPA for online data. ECOWAS REGIONAL DATA PROTECTION COOPERATION: ECOWAS SUPPLEMENTARY ACT ON PERSONAL DATA PROTECTION 2010 + ECOWAS Court of Justice jurisdiction + regional data flows + harmonisation; Ghana actively participates. AFRICAN UNION MALABO CONVENTION 2014 (Convention on Cyber Security and Personal Data Protection): Ghana SIGNATORY but NOT Y
- Dual-reporting procedure (DPC + CSA)
- ECOWAS engagement
- Amendment + EU-adequacy tracking
- Dual reporting overlooked
- ECOWAS engagement absent
- Amendment pipeline not tracked
Ghana DPA 2012 sectoral coordination across Ghanaian sectors. BANKING + FINANCIAL: Bank of Ghana Cyber Risk Management Directive 2018 + 2021 + 2024 + Customer Data Protection in Banking Regulations + payment systems data + AML + Customer Due Diligence; DPC coordinates with BoG for banking-customer-data breaches + customer privacy notices. TELECOMMUNICATIONS: National Communications Authority (NCA) Code of Practice + Service Provider Licensing + Subscriber Data Protection + Lawful Intercept Regulations + Subscriber Registration + Mobile Money Customer Protection (significant in Ghana given mobile money penetration); DPC + NCA dual coordination. HEALTHCARE: Ministry of Health + National Health Insurance Authority + Ghana Health Service + Patient Rights regulations + electronic health records governance + clinical research data; sectoral guidance issued by DPC for healthcare. EDUCATION: Min
- Sectoral compliance per industry
- Multi-regulator engagement
- Public-sector data governance
- Sectoral coordination ad-hoc
- Multi-regulator engagement gaps
- Public-sector data governance weak
Ghana DPA 2012 crosswalk to international DP regimes. EU GDPR (Regulation (EU) 2016/679): Ghana DPA is conceptually similar but PREDATES GDPR (2012 vs 2018); 2017 amendments added data portability + automated decision-making (GDPR-influenced); 2024-2025 amendment pipeline aims further GDPR alignment + EU adequacy aspirations; key differences: 40-day vs 30-day response + EUR vs GHS penalties + 18 vs 13-16 children age + registration vs no-registration. EU LAW ENFORCEMENT DIRECTIVE 2016/680: separate Ghana criminal-investigation regime + Cybercrime Act + Criminal Code coordinates. COE CONVENTION 108 + 108+ (modernised 2018): Ghana NOT SIGNATORY but Act 843 conceptually aligned + ratification could support international cooperation + EU adequacy; Convention 108+ provides global DP framework + 55+ state parties. AU MALABO CONVENTION 2014: Ghana SIGNATORY + ratification pending; Convention en
- GDPR cross-map + amendment readiness
- Multi-regional cooperation engagement
- Sectoral integration
- GDPR alignment partial
- Multi-regional cooperation absent
- Sectoral integration siloed
Ghana DPA 2012 compliance program implementation roadmap. ORGANIZATIONAL ROLES: (a) DATA PROTECTION OFFICER (DPO, anticipated mandatory in 2024-2025 amendments per GDPR-alignment) - DPC liaison + program oversight + sensitive-data processing oversight; (b) DPC REGISTRATION OWNER - annual registration + renewal + DPC engagement; (c) DATA SUBJECT RIGHTS COORDINATOR - 40-day SLA + identity verification + appeals; (d) BREACH RESPONSE LEAD - DPC notification + dual-reporting with CSA Ghana + data subject notification; (e) CROSS-BORDER TRANSFER COMPLIANCE LEAD - adequacy + SCC/BCR + ECOWAS + Malabo + Convention 108+ tracking; (f) RECORDS MANAGER - RoPA + Sec.60 records + 7+ year retention; (g) SECTORAL COORDINATOR - Cyber Act + Banking + Telecommunications + sector regulators; (h) TRAINING COORDINATOR - awareness + role-specific training. OPERATIONAL CONTROLS: (a) DPC registration + renewal; (
- Role inventory + RACI
- Operational controls + metrics
- Sectoral + dual-regulator engagement
- Roles undefined
- Operational controls weak
- Sectoral coordination ad-hoc
Ghana DPA 2012 implementation status + 2024-2025 amendment pipeline. STATUS: Act 843 in force since 2012; 2017 minor amendments (data portability + ADM); DPC operational with registration + complaints + investigations; active enforcement of registration requirements + breach notifications + data subject rights; sectoral guidance issued for banking + telecommunications + healthcare. 2024-2025 AMENDMENT PIPELINE: comprehensive review underway by Ministry of Communications and Digitalisation + DPC + civil society + private sector consultations; KEY AMENDMENT TARGETS: (a) GDPR-alignment - response times + breach notification timelines + DSR + DPIA + DPO mandatory provisions; (b) AI/ML + automated decision-making strengthening + meaningful human review + bias + explainability; (c) cross-border data + EU adequacy decision pursuit + AfCFTA digital trade coordination; (d) administrative fines in
- Amendment tracking + readiness
- EU adequacy preparation
- AI/ML governance + amendment integration
- Multi-regional cooperation
- Amendment pipeline not tracked
- EU adequacy aspirations missed
- AI/ML governance gap
- Malabo not anticipated
Ghana DPA DPC enforcement status + case activity. DPC OPERATIONAL STATUS: established 2014 + operational since 2014 with growing capacity; Director-General + Board + ~100 staff + regional outreach offices + online complaint portal + registration database. ENFORCEMENT ACTIVITY (2014-2025): (a) thousands of data controller + processor REGISTRATIONS approved + thousands of annual renewals; (b) hundreds of COMPLAINTS investigated annually including employment + banking + telecommunications + healthcare + e-commerce + journalism; (c) BREACH NOTIFICATIONS received + investigations across financial + telecommunications + retail + government sectors; (d) ENFORCEMENT ACTIONS - GHS 1,000-50,000+ fines + warnings + corrective orders + occasional criminal referrals for unauthorised disclosure; (e) GUIDANCE PUBLICATIONS - sectoral codes of practice + guidance notes + privacy notice templates. CAPACIT
- DPC engagement + complaint records
- Enforcement risk assessment
- International cooperation engagement
- Amendment readiness plan
- DPC engagement reactive
- Enforcement risk underestimated
- International cooperation absent
- Amendment readiness gap
Ghana DPA: Sensitive Data, Children and Special Categories
Ghana DPA 2012 Sensitive Data + Children. SENSITIVE PERSONAL DATA (Sec.2): race + ethnic origin + political opinions + religious + philosophical beliefs + trade union membership + health + sex life + sexual orientation + criminal convictions; processing requires EXPLICIT CONSENT or specified statutory bases including employment + social security + medical purposes + vital interests + legal claims + manifestly-made-public + non-profit activities. CHILDREN (under 18): heightened protections; PARENTAL CONSENT required for processing personal data of children under 18 for online services + commercial activities + sensitive contexts; controllers must make reasonable verification efforts; child-friendly clear notices; PROHIBITION OF TARGETED ADVERTISING to children + profiling of children + behavioural surveillance of children. 2024-2025 amendment pipeline anticipated to: (a) better align with
- Sensitive data register + explicit consent
- Children consent verification
- Age verification mechanism
- Cyber-Act coordination
- Sensitive data processed without explicit consent
- Children consent verification absent
- Age threshold confused
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.