Personal Data Protection Proclamation, cross-border transfer and data sovereignty
Proclamation No. 1321/2024, arts. 18-22 (cross-border transfer and data sovereignty)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 24 July 2024.
A cross border transfer rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Before transferring personal data to a third-party jurisdiction, confirm the jurisdiction ensures an appropriate level of protection, obtain the data subject's informed consent, or meet another condition the Proclamation lists.
- Store personal data collected or obtained in Ethiopia on a server or data center located in Ethiopia, and keep any category of critical personal data the Authority prescribes on a server or data center there.
- Get the Authority's prior approval before any cross-border transfer of sensitive personal data.
- Assess the level of protection in the destination jurisdiction before the transfer, weighing the nature of the data, the purpose and duration of the processing, the countries of origin and final destination, and the rules of law and security measures in force there.
- Be ready to demonstrate to the Authority the effectiveness of your security safeguards and the existence of compelling legitimate interests for a transfer, and abide by any prohibition, suspension or condition it imposes on one.
What it reaches
Obligation class
Transfer, Access restriction
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 18 permits the transfer of personal data to a third-party jurisdiction only subject to the Proclamation and only where that jurisdiction ensures appropriate levels of protection.
Article 19 requires that level to be assessed before the transfer in the light of all the circumstances, with particular regard to the nature of the data, the purpose and duration of the processing, the countries of origin and final destination, and the rules of law, professional rules and security measures in force in the third-party jurisdiction; where protection is absent the Authority may still authorize a limited form of transfer, provided the data subject's rights are not violated, the data subject consents and those aspects of the data the Authority deems appropriate are severed or reduced, and otherwise the transfer is prohibited.
Article 20 lets a data controller or data processor transfer personal data where it has proved appropriate protection to the Authority and the Authority has so determined, where the data subject has given explicit consent after being informed of the possible risks, where the transfer is necessary in one of the listed senses, or where the transfer is made from a register intended by law to inform the public.
Article 21 lets the Authority require a transferor to demonstrate the effectiveness of its security safeguards and the existence of compelling legitimate interests, and lets it prohibit, suspend or condition the transfer to protect data subjects.
Article 22 requires every data controller and data processor to store personal data collected or obtained locally on a server or data center located in Ethiopia, lets the Authority prescribe categories of critical personal data that may be processed only on a server or data center in Ethiopia, and makes cross-border transfer of sensitive personal data subject to the Authority's prior approval.
Article 70 enters the Proclamation into force on the date of its publication in the Negarit Gazeta, and it was signed at Addis Abeba on the 24th day of July 2024, so these provisions bind today.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometrics
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.