Data Protection Act, rights of data subjects
Data Protection Act, 2012 (Act 843), ss. 32-36 and 39-44 (rights of data subjects)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force.
A data subject rights rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Give a data subject the right to demand that a decision significantly affecting them is not based solely on automated processing of their personal data, and notify them as soon as reasonably practicable when such a decision is taken without a prior notice.
- Reconsider an automated decision within twenty one days of a data subject's written request, and tell them in writing what steps you will take to comply.
- Cease or refrain from processing personal data within twenty one days of a data subject's written notice that the processing causes or is likely to cause them unwarranted damage or distress, or give them your reasons for not complying.
- Do not provide, use, obtain, or procure a data subject's personal data for direct marketing without their prior written consent, and stop on their written request at any time.
- Answer a data subject's request to confirm whether you hold personal data about them, describe it, and correct it, promptly and in any event within forty days of receiving the request.
- Correct or delete personal data on a data subject's request where it is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or unlawfully obtained, and tell every person the data was disclosed to of the correction.
- Comply with a Commission order to rectify, block, erase, or destroy personal data found to be inaccurate on a data subject's complaint.
What it reaches
Obligation class
Data subject rights, Consent, Disclosure
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 35 gives a data subject the right to be told the personal data a data controller holds about them, the purpose of processing, the recipients, and the source of the data, communicated in an intelligible form. Section 35(10) requires a data controller to comply with an access request promptly and in any event within forty days of receiving it.
Section 33 gives a data subject the right to have inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or unlawfully obtained personal data corrected or deleted, and requires the data controller to tell every person the data was disclosed to of the correction. Section 39 lets an individual require a data controller to cease or not begin processing personal data that causes or is likely to cause them unwarranted damage or distress.
Section 40 bars a data controller from using a data subject's personal data for direct marketing without their prior written consent, and lets the data subject object to direct marketing at any time. Section 41 gives a data subject the right to demand that a decision significantly affecting them is not based solely on automated processing of their personal data.
Despite the absence of a prior notice, section 41(2) entitles the data subject to require reconsideration of such a decision within twenty-one days after receipt of the notification from the data controller. Section 42 gives a data subject the right to require the rectification, blocking, erasure, or destruction of exempt manual data that is inaccurate or incomplete.
Section 44 lets the Commission order a data controller to rectify, block, erase, or destroy personal data on a data subject's complaint that it is inaccurate. Section 36 applies these rights to a credit bureau acting as a data controller, letting a data subject limit an information request to their financial standing and history for the twelve months before the request.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsgenerates_content
Read the law
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived May 23, 2026. Publisher's page: https://nita.gov.gh/wp-content/uploads/2017/12/Data-Protection-Act-2012-Act-843.pdfEvery line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.