Law / Ghana

Ghana

5 of 8 named instruments researched to a stage, across three of the six areas of law we track: 5 in force. As of 4 September 2026.

  1. AI law none researched
  2. Privacy law 1
  3. Scraping law 3
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law1 instrument, 1 in force

Research summary (199 words)

Ghana's comprehensive personal-data statute is the Data Protection Act, 2012 (Act 843), which binds the Republic and every private data controller or processor established in Ghana, or using equipment or a processor in Ghana, and is enforced by the Data Protection Commission.

Processing special personal data, including an individual's DNA, health, ethnic origin, religious belief, political opinion, or sexual life, is prohibited unless a listed exception applies, and a data subject has a right to demand that a decision significantly affecting them is not based solely on automated processing.

A data controller must notify both the Commission and the data subject of unauthorized access to personal data as soon as reasonably practicable, and the Act sets no adequacy test or other substantive condition on transferring personal data outside Ghana, though a registering data controller must disclose the countries to which it may transfer data.

The Ministry of Communication, Digital Technology and Innovations announced in March 2026 that a new Data Protection Bill and a separate Emerging Technologies Bill are being developed to address artificial intelligence, automated decision-making, and cross-border data flows, and to provide structured oversight of AI systems and digital platforms, but neither has been tabled in Parliament.

Comprehensive regime

Data Protection Act

Data Protection Act, 2012 (Act 843)Data Protection Act, 2012 (Act 843), full gazetted text (National Information Technology Agency, Internet Archive copy)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived May 23, 2026. Publisher's page: https://nita.gov.gh/wp-content/uploads/2017/12/Data-Protection-Act-2012-Act-843.pdf

In force. Binds public and private bodies.

What this law does

The Data Protection Act, 2012 (Act 843) is administered by the Data Protection Commission, an independent statutory body it establishes. A data controller or processor established in Ghana, or using equipment or a processor in Ghana, must have a lawful basis before processing personal data. It must also register with the Data Protection Commission before processing begins. The Act binds the Republic itself, treating each government department as a data controller.

Processing special personal data, including an individual's DNA, ethnic origin, political opinion, religious belief, or sexual life, is prohibited unless a listed exception applies, such as the data subject's consent or a legal obligation on an employer. A data subject may require that a decision significantly affecting them is not based solely on automated processing of their personal data.

The data subject may also require reconsideration of such a decision within twenty-one days of being notified of it. A data controller must notify the Commission and the affected data subject of unauthorized access to or acquisition of personal data as soon as reasonably practicable after discovering it. The Act imposes no adequacy test or other substantive condition on transferring personal data outside Ghana.

An applicant for registration as a data controller must, however, disclose the countries to which it may transfer the data it holds. The Act was gazetted on 18 May 2012. Its commencement was left to a date the Minister specifies by notice in the Gazette. The Act came into force in October 2012.

What it requires

Scraping law3 instruments, 3 in force

Research summary (272 words)

Ghana's general computer-misuse authority is the Electronic Transactions Act, 2008 (Act 772), which punishes knowingly and without authority causing a computer to perform any function to secure access to a programme or electronic record, with no carve-out for a publicly accessible, unauthenticated page; a person who accesses a protected computer holding financial, government, or national-security information without authorization faces the Act's highest tier.

The Cybersecurity Act, 2020 (Act 1038) adds a narrower offence, retrieving subscriber information or intercepting traffic or content data without lawful authority, which binds a person dealing in communications data rather than a general web crawler. No statute or reported case addresses terms-of-service enforceability, or whether login or acceptance of terms changes the legal picture; this is unsettled rather than a specific regime.

Copyright protects a database only as a compilation, never through a separate sui generis right: the Copyright Act, 2005 (Act 690) protects a collection such as an encyclopedia, dictionary, or database, whether in machine-readable form, only where the collection is original by reason of the selection or arrangement of its contents, and its personal-use exception expressly does not extend to reproducing the whole or a substantial part of a database in digital form.

The Data Protection Act, 2012 (Act 843) reaches scraped public personal data: its definition of personal data carries no exemption for publicly available information, so a scrape of a public page that captures personal data about an identifiable individual still needs a lawful basis and registration under that Act.

No specific unfair-competition or misappropriation doctrine addresses scraping, and no case law or regulatory statement gives robots.txt legal weight or addresses AI-training-specific access rules.

Computer misuse

Cybersecurity Act, Unlawful Access

Cybersecurity Act, 2020 (Act 1038), s. 94 (Unlawful Access)Cybersecurity Act, 2020 (Act 1038), full text (csdsafrica.org)

In force since 29 December 2020. Binds public and private bodies.

What this law does

Section 94 punishes a person who, without lawful authority, retrieves subscriber information or intercepts traffic data or content data. This offence is narrower than the Electronic Transactions Act's general unauthorized-access offences: it binds a person dealing in communications data held by or passing through a service provider, rather than a general web crawler collecting data from public pages it does not own.

The Act also imposes retention and cooperation duties on a service provider, and creates a licensing regime for cybersecurity service providers, enforced by the Cyber Security Authority.

What it requires

Electronic Transactions Act, Cyber Offences

Electronic Transactions Act, 2008 (Act 772), ss. 124, 130-134 (Cyber Offences)Electronic Transactions Act, 2008 (Act 772), full text (Business Registration and Regulation registry)

In force since 19 December 2008. Binds public and private bodies.

What this law does

Section 124 punishes a person who intentionally accesses or intercepts an electronic record without authority or permission. Section 130 punishes a person who knowingly and without authority causes a computer to perform any function to secure access to a programme or electronic record held in that computer or any other computer, and section 131 punishes an unauthorized modification of a programme or electronic record.

Section 133 creates an aggravated offence, whoever knowingly accesses a computer without authorisation or exceeds authorised access to a protected computer, one holding information from a financial institution, a government department, a national-security matter, or otherwise designated protected, and carries the Act's highest tier. Section 134 punishes intentionally causing a computer to cease to function, including by virus or worm.

None of these provisions exempts a publicly accessible, unauthenticated page from the definition of unauthorized access, which the Act defines as access a person is neither personally entitled to nor has been given consent to obtain.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (206 words)

Ghana has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the general copyright framework of the Copyright Act, 2005 (Act 690) is the only law reaching an aggregator's reproduction of news content.

Its quotation provision permits including, with an indication of the source and the name of the author, quotations from a work in another work, including quotations from articles in newspapers or periodicals in the form of press summaries, subject to a fair-practice and extent-justified test; the provision carries no headline-length or short-extract cap and no restriction to the press industry, and no reported Ghanaian decision applies it to a systematic news aggregator as opposed to an individual quoting a published work.

Neighbouring rights under the Act protect performers and broadcasting organisations, not print or online news publishers, so there is no publisher-side neighbouring right of the kind the European Union's Digital Single Market Directive Article 15 creates. No statute or case law addresses whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer, and no hot-news or misappropriation doctrine distinct from ordinary copyright law exists.

The Act predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.