{
 "jurisdiction_id": "GH",
 "jurisdiction": "Ghana",
 "url": "https://dataprotection.gi/jurisdictions/ghana/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 39,
  "sub_modules": 57,
  "source_register": 18
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ghana/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Omnibus statute in force since 2012 with an operational, currently-staffed regulator and an active registration regime; principal gap is the pending modernisation bill which has not yet displaced the current framework.",
   "claims": [
    {
     "statement": "The Ghanaian Data Protection Act provides for the Data Protection Commission ('DPC'), referred to as 'the Commission' in the Act, which oversees personal data protection matters in Ghana.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._ghana.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "As of early 2026, the Data Protection Commission (Ghana) is led by Dr Arnold Kavaarpuo (Executive Director/Commissioner), confirming the regulator is currently operational.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "Office of the Privacy Commissioner of Canada",
     "source_url": "https://www.priv.gc.ca/en/opc-news/speeches-and-statements/2026/js-dc_20260223_ai/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Data Protection Act, 2012 came into force on October 16, 2012, and provides the general data privacy framework for Ghana applicable to both public and private bodies.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/ghana",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Ghana is a signing member of the ECOWAS Supplementary Act A/SA.1/01/10 on Personal Data Protection and has signed and ratified the African Union Malabo Convention on Cyber Security and Personal Data Protection.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/ghana",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A Data Protection Bill (drafted 2024/2025) proposes a comprehensive successor legal framework for data protection in Ghana, including creation of an independent Data Protection Authority to replace the current Commission structure.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/ghana",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "One of the key areas of the Data Protection Act relates to assessable processing, under which the Minister of Communications is given power by executive instrument to specify actions which constitute assessable processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/ghana",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Ghanaian Act provides a similar potential for extraterritorial application as the GDPR, and is more detailed than the GDPR regarding what constitutes being established within the territory, defining 'foreign data subject' as data subject information regulated by a foreign jurisdiction's laws sent into Ghana for processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._ghana.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Act imposes obligations for ensuring adequate protection by data processors domiciled outside of Ghana under Article 30 and requires compliance with foreign jurisdiction legislation in the context of foreign data subjects' personal data under Article 18.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._ghana.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Data controllers are required to register with the Data Protection Commission (DPC) in the register of data controllers, a requirement that in some respects goes further than the GDPR's registration/notification regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/ghana",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DPC issued Registration Guidelines For Data Controllers and Data Processors in 2015 to operationalise the Data Processing Notification requirements found in Articles 27, 46, 50, 53, 55-57, 60-74 and 96 of the Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/ghana-data-processing-notification",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ghana/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Core lawful-basis and special-category concepts are present and comparable to GDPR, but anonymisation/pseudonymisation and consent granularity are materially less developed.",
   "claims": [
    {
     "statement": "The legal grounds provided for under the GDPR and the Ghanaian Act are broadly similar and include consent as well as other bases for lawful processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._ghana.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The GDPR and the Ghanaian Act define personal data and special categories or sensitive data in similar ways, though the Ghanaian Act does not explicitly refer to online identifiers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._ghana.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Ghanaian Act does not generally refer to anonymised data and does not explicitly define or refer to anonymisation and pseudonymisation beyond a brief reference to de-identified data, where Article 45(5) requires a data controller to destroy, delete or de-identify a record of personal data at expiry of the retention period.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._ghana.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ghana/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Objection/restriction rights are confirmed; erasure, portability and firm response-deadlines are weaker or unconfirmed in available secondary sources.",
   "claims": [
    {
     "statement": "The Ghanaian Act does not provide a specific right for erasure in the same manner as the GDPR; data subjects may, though, request certain remedies under the general framework.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._ghana.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Like the GDPR, the Ghanaian Act establishes a right to object to processing, as well as related provisions such as objecting to direct marketing and restricting processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._ghana.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The draft Data Protection Bill provides that a data controller shall facilitate the exercise of data subject rights, with a response period that may, with Commission approval, be extended by a period not exceeding two months.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance (hosting draft bill text)",
     "source_url": "https://www.dataguidance.com/sites/default/files/data_protection_bill_2024.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ghana/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Security, breach-notification and registration duties are confirmed and comparable to GDPR in principle but materially less detailed; DPIA and joint-controller mechanics are largely absent.",
   "claims": [
    {
     "statement": "Although the Ghanaian Act sets out provisions for the Commission to assess processing activities under Articles 57 and 77, it does not establish an equivalent concept to a data protection impact assessment.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._ghana.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under Section 58 of the Data Protection Act, controllers are listed as required to appoint a data protection supervisor, who must monitor compliance with the Act and register with the Commission.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://prod.iapp.org/media/pdf/resource_center/dpo_requirements_by_country.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Ghanaian Act establishes the concept of data protection supervisors, similar to GDPR data protection officers, but does not require their appointment, and is less explicit than the GDPR on DPO-related matters.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._ghana.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Ghanaian Act establishes registration (Data Processing Notification) requirements grounded in Articles 27, 46, 50, 53, 55, 56, 57, 60-74 and 96, which in some respects goes further than the GDPR's record-keeping requirements.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/ghana-data-processing-notification",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "There are parallels between the GDPR and the Ghanaian Act regarding definitions of data controllers and data processors, including requirements related to agreements or contracts between these parties.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._ghana.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "While the Ghanaian Act does not directly refer to data processing record-keeping obligations, its general security-of-processing obligations in Articles 28-30 may be interpreted as requiring certain organisational measures similar to GDPR requirements.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._ghana.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Like the GDPR, the Ghanaian Act requires technical and organisational measures including data breach notification obligations to both supervisory authorities and data subjects, with Article 31(2) requiring notification as soon as reasonably practicable after discovery of the breach, though the Act is generally less detailed than the GDPR on these matters.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._ghana.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Article 45(5) of the Data Protection Act requires that a data controller shall destroy or delete a record of personal data or de-identify the record at the expiry of the retention period.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._ghana.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ghana/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "A basic transfer-conditions regime exists via registration and processor obligations, but the modern adequacy/SCC/TIA toolkit found in GDPR-style regimes is absent.",
   "claims": [
    {
     "statement": "The Ghanaian Act imposes obligations for ensuring adequate protection by data processors domiciled outside of Ghana (Article 30), requires specifying where data may be transferred when registering processing with the DPC (Article 47), requires compliance with other jurisdictions' legislation in the context of foreign data subjects' personal data (Article 18), and establishes a general prohibition on selling data (Article 89).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._ghana.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "There are no data localisation provisions under the Ghanaian Data Protection Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._ghana.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "red",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ghana/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Only one sectoral overlay signal (telecoms, still a bill) was confirmed; all other sub-modules carry an explicit evidentiary gap rather than a substantive finding.",
   "claims": [
    {
     "statement": "The Electronic Communications Bill, 2025, aims to regulate electronic communications and broadcasting services with provisions on antitrust, cybersecurity, and data protection.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/ghana",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "red",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ghana/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Only direct-marketing objection and a general data-sale prohibition are confirmed; the remaining sub-modules carry explicit evidentiary gaps.",
   "claims": [
    {
     "statement": "The Data Protection Act establishes a general prohibition on selling data (Article 89).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._ghana.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Like the GDPR, the Ghanaian Act establishes a right to object to processing, as well as related provisions such as objecting to direct marketing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._ghana.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "red",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ghana/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Core algorithmic/biometric/surveillance governance sub-modules are unconfirmed under the current Act; only pending bills signal future coverage.",
   "claims": [
    {
     "statement": "The Emerging Technologies Bill, 2025, establishes an agency to regulate and promote ethical deployment of technologies like AI, blockchain, and IoT in Ghana.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/ghana",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Cybersecurity (Amendment) Bill, 2025 expands the Cyber Security Authority's powers, mandates compliance for critical information infrastructure owners, and enhances protection against cyber threats and online harassment of children.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/ghana",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ghana/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "A general children's-data protection exists but lacks GDPR-equivalent granularity on age verification, parental consent mechanics, or profiling bans; dependent-adult protections are unconfirmed.",
   "claims": [
    {
     "statement": "The GDPR's Article 8(1) age-of-consent mechanism for information society services offered to children has no equivalent provision in the Ghanaian Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._ghana.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Ghanaian Act provides a general prohibition and treats children's data similarly to other sensitive data, while the GDPR establishes more specific requirements in regard to consent, privacy notices, and information society services for minors.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._ghana.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ghana/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Core compensation/investigation powers and historical registration-enforcement are confirmed; specific penalty quanta, enforcement-activity index, funding/capacity and collective-redress mechanisms are unconfirmed gaps.",
   "claims": [
    {
     "statement": "The Data Protection Act prohibits the processing of information which would cause unwarranted damage or distress to an individual and provides that such an individual is entitled to compensation in case of damage or distress if the data controller contravenes the requirements of the Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/ghana",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Ghana Data Protection Commission has historically published lists of companies failing to register under the Data Protection Act, 2012, as a compliance-enforcement mechanism.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/ghanas-dpc-lists-companies-failing-to-register-under-data-protection-act-2012/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Data Protection Commission (Ghana) is led by an Executive Director/Commissioner and includes a Director of Regulatory & Compliance and a Head of Administration, as listed in a February 2026 international joint statement co-signed by global privacy regulators.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "Office of the Privacy Commissioner of Canada",
     "source_url": "https://www.priv.gc.ca/en/opc-news/speeches-and-statements/2026/js-dc_20260223_ai/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "An individual whose data is processed in a manner causing unwarranted damage or distress is entitled to compensation where a data controller contravenes the requirements of the Data Protection Act, providing a form of private redress.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/ghana",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Data Protection Bill, 2025, establishes a comprehensive legal framework for data protection in Ghana, including the creation of an independent Data Protection Authority, alongside a cluster of related pending bills covering emerging technologies, electronic transactions, electronic communications, misinformation, cybersecurity amendment, and data harmonisation.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/ghana",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "As of a February 2026 multilateral regulator joint statement on AI-generated imagery and privacy, the Data Protection Commission Ghana is confirmed as an active co-signatory regulator, evidencing continued operational capacity.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "Office of the Privacy Commissioner of Canada",
     "source_url": "https://www.priv.gc.ca/en/opc-news/speeches-and-statements/2026/js-dc_20260223_ai/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}