Data Protection Act, notification of security compromises
Data Protection Act, 2012 (Act 843), s. 31 (notification of security compromises)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force.
A breach notification rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Notify the Data Protection Commission and the affected data subject as soon as reasonably practicable after you have reasonable grounds to believe personal data has been accessed or acquired by an unauthorised person.
- Take steps to restore the integrity of the information system after unauthorised access or acquisition of personal data, and delay notifying the data subject only where the Commission or a security agency says notification would impede a criminal investigation.
- Give the data subject enough information in the notification to take protective measures against the consequences of the breach, including the identity of the unauthorised person if known, and communicate it by registered mail, electronic mail, the website, media publication, or another manner the Commission directs.
What it reaches
Obligation class
Breach notice
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 31(1) requires a data controller, or a third party processing data under its authority, to notify the Data Protection Commission and the affected data subject where there are reasonable grounds to believe personal data has been accessed or acquired by an unauthorised person. Section 31(2) requires that notification to be made as soon as reasonably practicable after discovery of the unauthorised access or acquisition.
Section 31(3) requires the data controller to take steps to restore the integrity of the information system. Section 31(4) lets the data controller delay notifying the data subject where a security agency or the Commission says notification would impede a criminal investigation.
Section 31(5) lets the notification to a data subject be made by registered mail, electronic mail, prominent placement on the responsible party's website, publication in the media, or another manner the Commission directs. Section 31(6) and (7) require the notification to give the data subject enough information to take protective measures, including the identity of the unauthorised person if it is known to the data controller.
Section 31(8) lets the Commission direct the data controller to publicise the compromise where publicity would protect an affected data subject.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometrics
Read the law
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived May 23, 2026. Publisher's page: https://nita.gov.gh/wp-content/uploads/2017/12/Data-Protection-Act-2012-Act-843.pdfEvery line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.