Skip to content

Evidence request lists

Ghana Data Protection Act 2012 (Act 843)

Evidence request list. 12 controls, 12 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Ghana DPA: 8 Data Protection Principles + Lawful Basis + Consent (Sec 17-24, Part Two)

GhDPA-8Principles-Lawful-Consent
8 Data Protection Principles + Lawful Basis + Consent (Sec 17-24, Part Two)

Ghana DPA 2012 8 Data Protection Principles + lawful basis (Sec.17-24, Part Two). EIGHT PRINCIPLES: (1) ACCOUNTABILITY (Sec.17) - controller responsible for compliance; (2) LAWFULNESS OF PROCESSING (Sec.18) - lawful basis required including consent + contract + legal obligation + vital interests + public-interest + legitimate-interests; (3) SPECIFICATION OF PURPOSE (Sec.19) - specific + explicit + legitimate purpose; (4) COMPATIBILITY OF FURTHER PROCESSING (Sec.20) - compatible with original purpose only; (5) QUALITY OF DATA (Sec.21) - accurate + complete + up to date; (6) OPENNESS (Sec.22) - transparency notice + information about processing; (7) DATA SECURITY SAFEGUARDS (Sec.23) - appropriate technical + organisational measures; (8) DATA SUBJECT PARTICIPATION (Sec.24) - data subjects empowered to access + correct + control. CONSENT: must be freely given + specific + informed + verifiab

Artefacts an auditor will ask for
  • Principles implementation evidence
  • Lawful basis register
  • Consent records + withdrawal
  • Children consent verification
Where this commonly fails
  • Principles applied superficially
  • Consent unclear or implied
  • Children threshold confused with GDPR-13/16

Ghana DPA: Cross-Border Transfers, Breach Notification and Enforcement (Part Five)

GhDPA-CrossBorder-Breach-Enforcement
Cross-Border Transfers, Breach Notification, Enforcement and Penalties (Part Five)

Ghana DPA 2012 Part Five - Cross-Border + Breach + Enforcement. CROSS-BORDER TRANSFERS (Sec.47): personal data may be transferred outside Ghana only where: (a) ADEQUACY - destination country provides adequate level of protection (DPC determination); (b) APPROPRIATE SAFEGUARDS - binding corporate rules + standard contractual clauses + approved code of conduct + safeguards approved by DPC; (c) DEROGATIONS - explicit consent + contract necessity + public interest + legal claims + vital interests + Ministerial approval for sensitive transfers; (d) ECOWAS regional cooperation: data transfers within ECOWAS member states benefit from regional supplementary act. BREACH NOTIFICATION (Sec.55): controllers must notify DPC of personal data breach without undue delay; for material breaches with risk of harm to data subjects + notification to affected individuals required; documented incident records.

Artefacts an auditor will ask for
  • Cross-border transfer mechanism + records
  • Breach response procedure + DPC notification
  • Penalty risk assessment
  • Appeals procedure
Where this commonly fails
  • Transfers without adequacy/safeguards
  • Breach notification slow
  • Penalty risk underestimated

Ghana DPA: Data Controller + Processor Registration + Obligations (Part Four)

GhDPA-Registration-Controller-Processor
Data Controller + Processor Registration and Obligations (Part Four)

Ghana DPA 2012 Part Four - Registration + Controller/Processor Obligations. REGISTRATION (Sec.41-46): all data controllers + processors processing personal data in Ghana must REGISTER with DPC + complete REGISTRATION APPLICATION (Sec.42) including organizational details + categories of data + purposes + cross-border transfers + safeguards; the DPC may approve + reject + impose conditions; REGISTRATION FEE annual + scaled to organization size; REGISTRATION CERTIFICATE issued (Sec.43) + valid 2 years + renewable; PUBLIC REGISTER maintained by DPC accessible online. CONTROLLER OBLIGATIONS: lawful processing + 8 principles compliance + data subject rights enablement + security safeguards (technical + organisational) + breach notification + records of processing + cross-border transfer compliance + cooperation with DPC. PROCESSOR OBLIGATIONS: written contract with controller specifying scope

Artefacts an auditor will ask for
  • DPC registration + renewal records
  • RoPA + records-of-processing
  • Processor agreement template
  • DPC engagement records
Where this commonly fails
  • Registration lapsed
  • RoPA missing
  • Processor agreement weak
  • DPC cooperation inconsistent

Ghana DPA: Data Subject Rights (Access, Rectification, Erasure, Objection, Portability) (Sec 30-38)

GhDPA-DataSubjectRights
Data Subject Rights (Access, Rectification, Erasure, Objection, Portability) (Sec 30-38)

Ghana DPA 2012 Data Subject Rights (Sec.30-38). RIGHTS: (1) RIGHT TO INFORMATION (Sec.30) - clear privacy notice + collection-time information; (2) RIGHT OF ACCESS (Sec.32) - confirmation + copy of personal data + processing purposes + categories + recipients + retention + rights information; controller must respond within 40 DAYS (or shorter where required); (3) RIGHT TO RECTIFICATION (Sec.33) - correction of inaccurate or incomplete data; (4) RIGHT TO ERASURE (Sec.36) - deletion when data unlawful + obsolete + withdrawal of consent + objection sustained; (5) RIGHT TO OBJECT (Sec.34) - processing based on legitimate interests + direct marketing (absolute right) + research; (6) RIGHT TO DATA PORTABILITY (Sec.38, 2017 amendment) - structured + commonly used + machine-readable format + transmit to another controller; (7) AUTOMATED DECISION-MAKING (Sec.37, 2017 amendment) - protection from

Artefacts an auditor will ask for
  • Rights request log + 40-day SLA
  • ADM + portability implementation
  • DPC complaint procedure
Where this commonly fails
  • Rights gaps
  • 40-day SLA missed
  • ADM + portability not implemented

Ghana DPA: Scope, DPC Establishment and Definitions (Part One)

GhDPA-Scope-DPC-Defs
Scope, DPC Establishment and Definitions (Part One, Sec 1-15)

Ghana DPA 2012 Part One. SCOPE (Sec.3): applies to (a) personal data of natural persons processed in Ghana or by Ghanaian-established controllers; (b) extraterritorial processing where data subjects are in Ghana or where the controller has presence in Ghana. ESTABLISHMENT OF DATA PROTECTION COMMISSION (Sec.1-15): the DPC is an INDEPENDENT statutory body with Director-General + Board (representing public + private + civil society) + Secretariat + offices in Accra + regional offices; FUNCTIONS include monitoring + enforcement + complaint-handling + registration of data controllers + investigations + audits + guidance + international cooperation + Ministerial advisory. DEFINITIONS (Sec.2): PERSONAL DATA = data relating to an identified or identifiable individual; CONTROLLER + PROCESSOR per pre-GDPR distinction; CONSENT = freely-given specific informed; SENSITIVE PERSONAL DATA = race + ethni

Artefacts an auditor will ask for
  • DPC-applicability assessment
  • DPC contact + cooperation procedure
  • Definitions glossary + GDPR cross-map
Where this commonly fails
  • Scope misunderstood
  • DPC engagement reactive
  • Definitions not GDPR-aligned

Ghana DPA: Sectoral Coordination (Cybersecurity Act, ECOWAS, Malabo) and 2024-2025 Pipeline

GhDPA-Coord-Cyber-ECOWAS-Malabo-Status
Sectoral Coordination + ECOWAS + Malabo + 2024-2025 Pipeline + Status

Ghana DPA 2012 sectoral + regional + international coordination. GHANA CYBERSECURITY ACT 2020 (Act 1038, separately verified in corpus): cybersecurity-incident-personal-data overlap; cybersecurity breach affecting personal data triggers BOTH Ghana DPA Sec.55 breach notification (to DPC) AND Ghana CSA 24-hour incident reporting (to CSA Ghana); the two regulators (DPC + CSA Ghana) maintain MoUs for coordination. ELECTRONIC TRANSACTIONS ACT 2008 (Act 772): foundational e-commerce + electronic-records + electronic-signatures; complements Ghana DPA for online data. ECOWAS REGIONAL DATA PROTECTION COOPERATION: ECOWAS SUPPLEMENTARY ACT ON PERSONAL DATA PROTECTION 2010 + ECOWAS Court of Justice jurisdiction + regional data flows + harmonisation; Ghana actively participates. AFRICAN UNION MALABO CONVENTION 2014 (Convention on Cyber Security and Personal Data Protection): Ghana SIGNATORY but NOT Y

Artefacts an auditor will ask for
  • Dual-reporting procedure (DPC + CSA)
  • ECOWAS engagement
  • Amendment + EU-adequacy tracking
Where this commonly fails
  • Dual reporting overlooked
  • ECOWAS engagement absent
  • Amendment pipeline not tracked
GhDPA-Coord-Sectoral-Bank-Tel-Health
Sectoral Coordination - Banking, Telecommunications, Healthcare, Education + Public Sector

Ghana DPA 2012 sectoral coordination across Ghanaian sectors. BANKING + FINANCIAL: Bank of Ghana Cyber Risk Management Directive 2018 + 2021 + 2024 + Customer Data Protection in Banking Regulations + payment systems data + AML + Customer Due Diligence; DPC coordinates with BoG for banking-customer-data breaches + customer privacy notices. TELECOMMUNICATIONS: National Communications Authority (NCA) Code of Practice + Service Provider Licensing + Subscriber Data Protection + Lawful Intercept Regulations + Subscriber Registration + Mobile Money Customer Protection (significant in Ghana given mobile money penetration); DPC + NCA dual coordination. HEALTHCARE: Ministry of Health + National Health Insurance Authority + Ghana Health Service + Patient Rights regulations + electronic health records governance + clinical research data; sectoral guidance issued by DPC for healthcare. EDUCATION: Min

Artefacts an auditor will ask for
  • Sectoral compliance per industry
  • Multi-regulator engagement
  • Public-sector data governance
Where this commonly fails
  • Sectoral coordination ad-hoc
  • Multi-regulator engagement gaps
  • Public-sector data governance weak
GhDPA-Crosswalk-GDPR-CoE108-Sectoral
Crosswalk to GDPR, Council of Europe Convention 108+, AU Malabo Convention and Industry Frameworks

Ghana DPA 2012 crosswalk to international DP regimes. EU GDPR (Regulation (EU) 2016/679): Ghana DPA is conceptually similar but PREDATES GDPR (2012 vs 2018); 2017 amendments added data portability + automated decision-making (GDPR-influenced); 2024-2025 amendment pipeline aims further GDPR alignment + EU adequacy aspirations; key differences: 40-day vs 30-day response + EUR vs GHS penalties + 18 vs 13-16 children age + registration vs no-registration. EU LAW ENFORCEMENT DIRECTIVE 2016/680: separate Ghana criminal-investigation regime + Cybercrime Act + Criminal Code coordinates. COE CONVENTION 108 + 108+ (modernised 2018): Ghana NOT SIGNATORY but Act 843 conceptually aligned + ratification could support international cooperation + EU adequacy; Convention 108+ provides global DP framework + 55+ state parties. AU MALABO CONVENTION 2014: Ghana SIGNATORY + ratification pending; Convention en

Artefacts an auditor will ask for
  • GDPR cross-map + amendment readiness
  • Multi-regional cooperation engagement
  • Sectoral integration
Where this commonly fails
  • GDPR alignment partial
  • Multi-regional cooperation absent
  • Sectoral integration siloed
GhDPA-Implementation-Roadmap
Implementation Roadmap - Organizational Roles, Tooling and Metrics

Ghana DPA 2012 compliance program implementation roadmap. ORGANIZATIONAL ROLES: (a) DATA PROTECTION OFFICER (DPO, anticipated mandatory in 2024-2025 amendments per GDPR-alignment) - DPC liaison + program oversight + sensitive-data processing oversight; (b) DPC REGISTRATION OWNER - annual registration + renewal + DPC engagement; (c) DATA SUBJECT RIGHTS COORDINATOR - 40-day SLA + identity verification + appeals; (d) BREACH RESPONSE LEAD - DPC notification + dual-reporting with CSA Ghana + data subject notification; (e) CROSS-BORDER TRANSFER COMPLIANCE LEAD - adequacy + SCC/BCR + ECOWAS + Malabo + Convention 108+ tracking; (f) RECORDS MANAGER - RoPA + Sec.60 records + 7+ year retention; (g) SECTORAL COORDINATOR - Cyber Act + Banking + Telecommunications + sector regulators; (h) TRAINING COORDINATOR - awareness + role-specific training. OPERATIONAL CONTROLS: (a) DPC registration + renewal; (

Artefacts an auditor will ask for
  • Role inventory + RACI
  • Operational controls + metrics
  • Sectoral + dual-regulator engagement
Where this commonly fails
  • Roles undefined
  • Operational controls weak
  • Sectoral coordination ad-hoc
GhDPA-Status-2024-2025-Amendment-AI
Implementation Status, 2024-2025 Amendment Pipeline, AI/ML and EU Adequacy Aspirations

Ghana DPA 2012 implementation status + 2024-2025 amendment pipeline. STATUS: Act 843 in force since 2012; 2017 minor amendments (data portability + ADM); DPC operational with registration + complaints + investigations; active enforcement of registration requirements + breach notifications + data subject rights; sectoral guidance issued for banking + telecommunications + healthcare. 2024-2025 AMENDMENT PIPELINE: comprehensive review underway by Ministry of Communications and Digitalisation + DPC + civil society + private sector consultations; KEY AMENDMENT TARGETS: (a) GDPR-alignment - response times + breach notification timelines + DSR + DPIA + DPO mandatory provisions; (b) AI/ML + automated decision-making strengthening + meaningful human review + bias + explainability; (c) cross-border data + EU adequacy decision pursuit + AfCFTA digital trade coordination; (d) administrative fines in

Artefacts an auditor will ask for
  • Amendment tracking + readiness
  • EU adequacy preparation
  • AI/ML governance + amendment integration
  • Multi-regional cooperation
Where this commonly fails
  • Amendment pipeline not tracked
  • EU adequacy aspirations missed
  • AI/ML governance gap
  • Malabo not anticipated
GhDPA-Status-DPC-Enforcement
DPC Enforcement Status, Case Activity and Capacity-Building 2024-2025

Ghana DPA DPC enforcement status + case activity. DPC OPERATIONAL STATUS: established 2014 + operational since 2014 with growing capacity; Director-General + Board + ~100 staff + regional outreach offices + online complaint portal + registration database. ENFORCEMENT ACTIVITY (2014-2025): (a) thousands of data controller + processor REGISTRATIONS approved + thousands of annual renewals; (b) hundreds of COMPLAINTS investigated annually including employment + banking + telecommunications + healthcare + e-commerce + journalism; (c) BREACH NOTIFICATIONS received + investigations across financial + telecommunications + retail + government sectors; (d) ENFORCEMENT ACTIONS - GHS 1,000-50,000+ fines + warnings + corrective orders + occasional criminal referrals for unauthorised disclosure; (e) GUIDANCE PUBLICATIONS - sectoral codes of practice + guidance notes + privacy notice templates. CAPACIT

Artefacts an auditor will ask for
  • DPC engagement + complaint records
  • Enforcement risk assessment
  • International cooperation engagement
  • Amendment readiness plan
Where this commonly fails
  • DPC engagement reactive
  • Enforcement risk underestimated
  • International cooperation absent
  • Amendment readiness gap

Ghana DPA: Sensitive Data, Children and Special Categories

GhDPA-SensitiveData-Children
Sensitive Personal Data and Children's Data (Sec 5 + 35)

Ghana DPA 2012 Sensitive Data + Children. SENSITIVE PERSONAL DATA (Sec.2): race + ethnic origin + political opinions + religious + philosophical beliefs + trade union membership + health + sex life + sexual orientation + criminal convictions; processing requires EXPLICIT CONSENT or specified statutory bases including employment + social security + medical purposes + vital interests + legal claims + manifestly-made-public + non-profit activities. CHILDREN (under 18): heightened protections; PARENTAL CONSENT required for processing personal data of children under 18 for online services + commercial activities + sensitive contexts; controllers must make reasonable verification efforts; child-friendly clear notices; PROHIBITION OF TARGETED ADVERTISING to children + profiling of children + behavioural surveillance of children. 2024-2025 amendment pipeline anticipated to: (a) better align with

Artefacts an auditor will ask for
  • Sensitive data register + explicit consent
  • Children consent verification
  • Age verification mechanism
  • Cyber-Act coordination
Where this commonly fails
  • Sensitive data processed without explicit consent
  • Children consent verification absent
  • Age threshold confused
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.