Data Protection Act
Data Protection Act, 2012 (Act 843)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force.
A comprehensive regime rule binding public and private bodies.
As of 4 September 2026.
What it requires
- Have a lawful basis for processing personal data, and register with the Data Protection Commission before processing begins.
- Do not process special personal data, including a person's DNA, ethnic origin, political opinion, religious belief, or sexual life, unless a listed exception applies, such as the data subject's consent.
- Give a data subject the right to demand that a decision significantly affecting them is not based solely on automated processing of their personal data, and to require reconsideration of such a decision within twenty-one days of notice.
- Notify the Data Protection Commission and the affected data subject of unauthorized access to or acquisition of personal data as soon as reasonably practicable after discovering it.
- When registering as a data controller, disclose the countries to which personal data may be transferred.
If you get it wrong
Criminal exposureYes
Criminal exposure note
Where a person commits an offence under the Act for which no penalty is specified, the general penalty is a fine of not more than five thousand penalty units or imprisonment of not more than ten years, or both (s. 95). Selling or offering to sell personal data carries a fine of not more than two thousand five hundred penalty units or imprisonment of not more than five years, or both (s. 89). Purchasing, obtaining, or unlawfully disclosing personal data, failing to register as a data controller, or continuing assessable processing without the Commission's clearance, each carry a fine of not more than two hundred and fifty penalty units or imprisonment of not more than two years, or both (ss. 88, 56, 57(6)).
Penalty structure
Section 95 (General penalty) sets the residual ceiling for any offence under the Act with no penalty otherwise specified: a fine of not more than five thousand penalty units or imprisonment of not more than ten years, or both. Named offences carry lower fixed tiers, for example two thousand five hundred penalty units for prohibited sale of personal data (s. 89), and two hundred fifty penalty units for prohibited purchase, obtaining, or disclosure of personal data (s. 88) or failure to register as a data controller (s. 56). One penalty unit equals twelve Ghana cedis under the Fines (Penalty Units) Act, 2000 (Act 572), as recorded by the Ghana Revenue Authority, making the general-penalty fine sixty thousand Ghana cedis.
- Rule
- Fixed only
- As of
- 4 September 2026
- Currency
- GHS
- Fixed cap
- 5,000
Who enforces it
Enforcement body
Data Protection Commission
What it reaches
Obligation class
Consent, Data subject rights, Breach notice, Biometric, Governance, Disclosure
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Data Protection Act, 2012 (Act 843) is administered by the Data Protection Commission, an independent statutory body it establishes. A data controller or processor established in Ghana, or using equipment or a processor in Ghana, must have a lawful basis before processing personal data. It must also register with the Data Protection Commission before processing begins. The Act binds the Republic itself, treating each government department as a data controller.
Processing special personal data, including an individual's DNA, ethnic origin, political opinion, religious belief, or sexual life, is prohibited unless a listed exception applies, such as the data subject's consent or a legal obligation on an employer. A data subject may require that a decision significantly affecting them is not based solely on automated processing of their personal data.
The data subject may also require reconsideration of such a decision within twenty-one days of being notified of it. A data controller must notify the Commission and the affected data subject of unauthorized access to or acquisition of personal data as soon as reasonably practicable after discovering it. The Act imposes no adequacy test or other substantive condition on transferring personal data outside Ghana.
An applicant for registration as a data controller must, however, disclose the countries to which it may transfer the data it holds. The Act was gazetted on 18 May 2012. Its commencement was left to a date the Minister specifies by notice in the Gazette. The Act came into force in October 2012.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachprocesses_biometricshigh_risk_decisionsserves_minorsprocesses_voice