Law / Ghana

Data Protection Act, notification of security compromises

Data Protection Act, 2012 (Act 843), s. 31 (notification of security compromises)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force.

A breach notification rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Notify the Data Protection Commission and the affected data subject as soon as reasonably practicable after you have reasonable grounds to believe personal data has been accessed or acquired by an unauthorised person.
  • Take steps to restore the integrity of the information system after unauthorised access or acquisition of personal data, and delay notifying the data subject only where the Commission or a security agency says notification would impede a criminal investigation.
  • Give the data subject enough information in the notification to take protective measures against the consequences of the breach, including the identity of the unauthorised person if known, and communicate it by registered mail, electronic mail, the website, media publication, or another manner the Commission directs.

What it reaches

Obligation class

Breach notice

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 31(1) requires a data controller, or a third party processing data under its authority, to notify the Data Protection Commission and the affected data subject where there are reasonable grounds to believe personal data has been accessed or acquired by an unauthorised person. Section 31(2) requires that notification to be made as soon as reasonably practicable after discovery of the unauthorised access or acquisition.

Section 31(3) requires the data controller to take steps to restore the integrity of the information system. Section 31(4) lets the data controller delay notifying the data subject where a security agency or the Commission says notification would impede a criminal investigation.

Section 31(5) lets the notification to a data subject be made by registered mail, electronic mail, prominent placement on the responsible party's website, publication in the media, or another manner the Commission directs. Section 31(6) and (7) require the notification to give the data subject enough information to take protective measures, including the identity of the unauthorised person if it is known to the data controller.

Section 31(8) lets the Commission direct the data controller to publicise the compromise where publicity would protect an affected data subject.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics

Read the law

Data Protection Act, 2012 (Act 843), full gazetted text (National Information Technology Agency, Internet Archive copy)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived May 23, 2026. Publisher's page: https://nita.gov.gh/wp-content/uploads/2017/12/Data-Protection-Act-2012-Act-843.pdf

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app