Personal Data Protection Proclamation, enforcement, sanctions and offences
Proclamation No. 1321/2024, arts. 55-64 (enforcement, administrative sanctions and offences)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 24 July 2024.
An enforcement supervision rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Comply with an enforcement order the Authority serves within the period it specifies, which is never less than twenty-one days, then tell the data subject concerned and, where compliance materially modifies the data, anyone it was disclosed to in the twelve months before the order was served.
- Furnish the Authority with information it requests, in a form that can be taken away and is intelligible and retrievable, and cooperate with it in discharging its powers and functions.
- Expect a data subject to be able to complain to the Authority in writing, and be ready to carry the burden of proving that an exemption applies wherever you refuse a data subject's request.
- Expect administrative penalties for processing in contravention of the Proclamation, reaching four per cent of total worldwide turnover of the preceding financial year where the offender is an institution or the offence concerns sensitive data or a minor's personal data, and criminal liability under article 64 on top of them.
If you get it wrong
Criminal exposureYes
Criminal exposure note
Processing personal data in contravention of the Proclamation, or failing to notify a personal data breach, is punished with imprisonment of one to three years or a fine of 60,000 to 100,000 Birr, or both (art. 64(1)). Violating a data subject's right to erasure, objection, restriction, or the right against automated decisions is punished with imprisonment of three to five years or a fine of 100,000 to 200,000 Birr, or both (art. 64(2)). Re-identifying de-identified data, selling personal data, or unlawfully transferring personal data outside Ethiopia is punished with imprisonment of five to ten years or a fine of 200,000 to 600,000 Birr, or both (art. 64(3)). Where the offence is committed by an institution, causes serious damage, or involves sensitive personal data or a minor's personal data, the fine rises to up to four percent of the offender's total worldwide turnover for the preceding financial year (art. 64(4)).
Penalty structure
Art. 60 empowers the Ethiopian Communications Authority to impose administrative penalties for processing in contravention of the Proclamation, and where the offence is committed by an institution, relates to sensitive data, or concerns a minor's personal data, the fine may reach four per cent of the offender's total worldwide turnover of the preceding financial year. Art. 64(4) sets the same four per cent ceiling as a criminal fine for the aggravated cases; the fixed criminal tiers below it run from 60,000 to 600,000 Birr (art. 64(1)-(3)). No fixed monetary cap is stated for the turnover-based fine.
- Rule
- Turnover pct only
- As of
- 4 September 2026
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
Ethiopian Communications Authority (ECA)
What it reaches
Obligation class
Governance, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 55 lets the Ethiopian Communications Authority serve an enforcement order on a data controller or data processor that has contravened, is contravening or is about to contravene the Proclamation, specifying the provision at issue, the measures to be taken, a period of not less than twenty-one days in which to take them, and the right of appeal; on complying, the recipient must tell the data subject concerned and, where compliance materially modifies the data, anyone the data were disclosed to in the twelve months before the order.
Article 56 lets the Authority request information from anyone, in a form that can be taken away and is intelligible and retrievable, and article 57 lets its monitoring arise from its own staff's work or from information and complaints.
Article 58 gives a data subject the right to complain in writing to the Authority, requires the Authority to investigate unless the complaint is not made in good faith and to give its decision in writing within twenty-one days, and allows an appeal to the Federal High Court within sixty days.
Article 59 requires administrative fines to be effective, proportional and dissuasive and lists the factors that set them, and article 60 gives the Authority power to impose administrative penalties for processing in contravention of the Proclamation, rising to a fine of up to four per cent of total worldwide turnover of the preceding financial year where the offence was committed by an institution, in relation to sensitive data, or against a minor's personal data, with any gain made going to the government.
Article 63 puts the burden of proving an exemption on the data controller that refused a data subject's request.
Article 64 sets the criminal tiers: one to three years' simple imprisonment or 60,000 to 100,000 Birr for failing to notify a personal data breach, failing to implement technical and organizational measures, or processing in contravention of the Proclamation; three to five years or 100,000 to 200,000 Birr for denying a data subject's rights of erasure, objection, restriction or protection against automated decisions; five to ten years or 200,000 to 600,000 Birr for re-identifying de-identified data, selling personal data or transferring it out of Ethiopia unlawfully; and the same four per cent of worldwide turnover where the offence involves an institution, serious damage, sensitive personal data or a minor's personal data.
Article 70 enters the Proclamation into force on the date of its publication in the Negarit Gazeta, and it was signed at Addis Abeba on the 24th day of July 2024, so these provisions bind today.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbothigh_risk_decisionsis_listed_company
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.