Law / Ethiopia

Personal Data Protection Proclamation

Proclamation No. 1321/2024 (Federal Negarit Gazette)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 24 July 2024.

A comprehensive regime rule binding public and private bodies.

As of 4 September 2026.

What it requires

  • Have a lawful basis for processing personal data before collecting, storing, or otherwise processing it, whether by automated means or in a filing system.
  • Register with the Ethiopian Communications Authority before processing personal data, and appoint a data protection officer where the Proclamation requires one.
  • Do not process sensitive personal data, including genetic or biometric data, unless a listed exception applies, such as the data subject's specific written consent.
  • Process a minor's personal data only with the consent or authorization of a parent, guardian, or tutor, or where necessary to the minor's vitally important interest, and never for marketing, profiling, or merging of profiles.
  • Give a data subject the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning them or significantly affects them.
  • Notify the Authority of a personal data breach within 72 hours of becoming aware of it, giving reasons for any delay.
  • Before transferring personal data to a third-party jurisdiction, confirm the jurisdiction ensures an appropriate level of protection, obtain the data subject's informed consent, or meet another condition the Proclamation lists.

If you get it wrong

Criminal exposureYes

Criminal exposure note

Processing personal data in contravention of the Proclamation, or failing to notify a personal data breach, is punished with imprisonment of one to three years or a fine of 60,000 to 100,000 Birr, or both (art. 64(1)). Violating a data subject's right to erasure, objection, restriction, or the right against automated decisions is punished with imprisonment of three to five years or a fine of 100,000 to 200,000 Birr, or both (art. 64(2)). Re-identifying de-identified data, selling personal data, or unlawfully transferring personal data outside Ethiopia is punished with imprisonment of five to ten years or a fine of 200,000 to 600,000 Birr, or both (art. 64(3)). Where the offence is committed by an institution, causes serious damage, or involves sensitive personal data or a minor's personal data, the fine rises to up to four percent of the offender's total worldwide turnover for the preceding financial year (art. 64(4)).

Penalty structure

Art. 60 empowers the Ethiopian Communications Authority to impose administrative penalties for processing in contravention of the Proclamation, and where the offence is committed by an institution, relates to sensitive data, or concerns a minor's personal data, the fine may reach four per cent of the offender's total worldwide turnover of the preceding financial year. Art. 64(4) sets the same four per cent ceiling as a criminal fine for the aggravated cases; the fixed criminal tiers below it run from 60,000 to 600,000 Birr (art. 64(1)-(3)). No fixed monetary cap is stated for the turnover-based fine.

Rule
Turnover pct only
As of
4 September 2026
Turnover percentage cap
4

Who enforces it

Enforcement body

Ethiopian Communications Authority (ECA)

What it reaches

Obligation class

Consent, Data subject rights, Breach notice, Transfer, Biometric, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A data controller or processor operating in Ethiopia must have a lawful basis before processing personal data, whether or not the processing is by automated means. Processing personal data requires registration with the Ethiopian Communications Authority, and a data controller or processor must appoint a data protection officer where the Proclamation requires one.

The processing of sensitive personal data, including genetic or biometric data, is prohibited unless a listed exception applies, such as the data subject's specific written consent. A minor's personal data may be processed only with the consent or authorization of a parent, guardian, or tutor, or where necessary to the minor's vitally important interest, and never for the purposes of marketing, profiling, or merging of profiles.

A data subject has the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning them or significantly affects them. A data controller must notify the Authority of a personal data breach within 72 hours of becoming aware of it.

A data controller or processor may transfer personal data to a third-party jurisdiction only where that jurisdiction ensures an appropriate level of protection, or another listed condition is met.

Violating the automated-decision right or another data subject right is punished with imprisonment of three to five years or a fine of 100,000 to 200,000 Birr, or both, and the fine rises to up to four percent of worldwide turnover where the offence involves an institution, sensitive personal data, or a minor's personal data.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • processes_voice
  • processes_biometrics
  • high_risk_decisions
  • serves_minors

Read the law

Personal Data Protection Proclamation No. 1321/2024, full English text (MetaAppz Ethiopian Federal Laws reference)

Back to the example  ·  Lint your app