#
Omnibus statute in force since 2012 with an operational, currently-staffed regulator and an active registration regime; principal gap is the pending modernisation bill which has not yet displaced the current framework.
Sub-modules (5)
Regulator And AuthorityGreen
The Data Protection Commission ('the Commission' in the Act) oversees personal data protection matters in Ghana; its current Executive Director/Commissioner is confirmed via a 2026 multilateral regulator joint statement.
Claims: CLM-GH-1a2b3c4d, CLM-GH-9f8e7d6c
Act And InstrumentsAmber
Primary instrument is the Data Protection Act, 2012; Ghana is also bound by the ECOWAS Supplementary Act on Personal Data Protection and has signed/ratified the AU Malabo Convention; a Data Protection Bill (2024/2025) proposes a successor Data Protection Authority.
Claims: CLM-GH-2b3c4d5e, CLM-GH-3c4d5e6f, CLM-GH-4d5e6f7a
Material ScopeGreen
The Act provides the general data privacy framework for Ghana and is applicable to both public and private bodies, covering assessable processing designated by executive instrument.
Claims: CLM-GH-5e6f7a8b
Territorial ScopeAmber
The Act provides for extraterritorial-type application via the 'foreign data subject' concept and obligations on processors domiciled outside Ghana, though it is less explicit than GDPR Art. 3 on establishment tests.
Claims: CLM-GH-6f7a8b9c, CLM-GH-7a8b9c0d
Regulator Registration And FilingGreen
Data controllers and processors are required to register with the DPC in the register of data controllers under Registration Guidelines published in 2015; historical enforcement has included public listing of non-compliant entities.
Claims: CLM-GH-8b9c0d1e, CLM-GH-0d1e2f3a
Sources and claims (10)
- ConfirmedOneTrust DataGuidance — The Ghanaian Data Protection Act provides for the Data Protection Commission ('DPC'), referred to as 'the Commission' in the Act, which oversees personal data protection matters in Ghana.
- ProbableOffice of the Privacy Commissioner of Canada — As of early 2026, the Data Protection Commission (Ghana) is led by Dr Arnold Kavaarpuo (Executive Director/Commissioner), confirming the regulator is currently operational.
- ConfirmedOneTrust DataGuidance — The Data Protection Act, 2012 came into force on October 16, 2012, and provides the general data privacy framework for Ghana applicable to both public and private bodies.
- ConfirmedOneTrust DataGuidance — Ghana is a signing member of the ECOWAS Supplementary Act A/SA.1/01/10 on Personal Data Protection and has signed and ratified the African Union Malabo Convention on Cyber Security and Personal Data Protection.
- ProbableOneTrust DataGuidance — A Data Protection Bill (drafted 2024/2025) proposes a comprehensive successor legal framework for data protection in Ghana, including creation of an independent Data Protection Authority to replace the current Commission structure.
- ConfirmedOneTrust DataGuidance — One of the key areas of the Data Protection Act relates to assessable processing, under which the Minister of Communications is given power by executive instrument to specify actions which constitute assessable processing.
- ConfirmedOneTrust DataGuidance — The Ghanaian Act provides a similar potential for extraterritorial application as the GDPR, and is more detailed than the GDPR regarding what constitutes being established within the territory, defining 'foreign data subject' as data subject information regulated by a foreign jurisdiction's laws sent into Ghana for processing.
- ConfirmedOneTrust DataGuidance — The Act imposes obligations for ensuring adequate protection by data processors domiciled outside of Ghana under Article 30 and requires compliance with foreign jurisdiction legislation in the context of foreign data subjects' personal data under Article 18.
- ConfirmedOneTrust DataGuidance — Data controllers are required to register with the Data Protection Commission (DPC) in the register of data controllers, a requirement that in some respects goes further than the GDPR's registration/notification regime.
- ConfirmedOneTrust DataGuidance — The DPC issued Registration Guidelines For Data Controllers and Data Processors in 2015 to operationalise the Data Processing Notification requirements found in Articles 27, 46, 50, 53, 55-57, 60-74 and 96 of the Act.