Ethiopia
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Ethiopia — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Ethiopia's privacy law says personal data collected in the country must be kept on a server or in a data centre inside Ethiopia. A copy may go abroad. Usually that only works if the regulator first accepts that the destination country protects data well enough. The law has been in force since July 2024. Almost nothing is being enforced. The regulator has published no rules and runs no register.
Data governance in Ethiopia
The eight things that decide how you handle data about people in Ethiopia. Same eight on every country page, so you can compare.
Who has to follow these rules
Only partly, and this is Ethiopia's oddest feature. The law covers any organisation set up in Ethiopia. A foreign company with no office is covered only if two things are true. It uses equipment inside Ethiopia to handle the data. And it has a representative based in Ethiopia. There is no size or revenue level below which you are free. Read literally, a purely foreign online service with no equipment and no representative in the country falls outside the law.
The reach test sits in Proclamation No. 1321/2024. For a foreign company both conditions must be met. The company is not set up in Ethiopia, but uses equipment in Ethiopia to handle the data, other than simply passing it through the country. And it has a representative set up in Ethiopia. That wording makes having a local representative part of the test for being covered. In Europe and India, naming a representative is instead a duty for companies that are already covered. Do not plan around this gap. The government can close it by amendment. The criminal penalties apply to anyone in Ethiopia who sends data out unlawfully. And the separate Critical Infrastructure Cybersecurity Proclamation No. 1426/2026 applies even if you have no office there. It covers Ethiopian critical infrastructure located outside the country, and anyone supplying cybersecurity products or services to it. The privacy law also binds federal and regional government bodies, and the Addis Ababa and Dire Dawa city administrations.
Sources
- Official sourceFederal Negarit Gazette / Ministry of Justice of EthiopiaPersonal Data Protection Proclamation No. 1321/2024, Article 3 (Scope of Application), Federal Negarit Gazette No. 35, 24 July 2024
justice.gov.et
“It is not established in Ethiopia but uses equipment in Ethiopia for processing the data otherwise than for the purposes of transit through Ethiopia and has a representative established in Ethiopia.”
Link checked 18 August 2026
- Official sourceInformation Network Security AdministrationCritical Infrastructure Cybersecurity Proclamation No. 1426/2026, Article 3 (Scope of Application), Federal Negarit Gazette No. 41, 21 July 2026
insa.gov.et
“This Proclamation shall apply to designated critical infrastructures of the country located within or outside the territory of Ethiopia, as well as to persons providing cybersecurity products or services.”
Link checked 18 August 2026
Where the data is allowed to live
A copy must stay in the country. Every organisation must keep personal data collected or obtained in Ethiopia on a server or in a data centre in Ethiopia. A copy may then go abroad, but only in the situations the law allows. Data the law treats as sensitive needs the regulator's permission before it goes anywhere. That category is wide. It covers health, biometrics, race, religion, political views, criminal records, and the content and details of people's messages.
- What you have to do here:
- Keep the data in the country
The duty sits in a part of Proclamation No. 1321/2024 headed 'Data Sovereignty'. Everyone who handles personal data must 'ensure the storage, on a server or data center located in Ethiopia, of personal data collected or obtained locally'. There is no size limit, no grace period and no exemption for cloud services. The law also hands the regulator a power it has not used. It is meant to name categories of 'critical personal data'. Those may only be handled on a server or data centre in Ethiopia, on grounds of state strategic interests. We found no such list published as of 18 August 2026. The law also requires the regulator's approval in advance before sensitive personal data goes abroad. Sensitive data is defined to include communications data, both content and the details around it. Industry by industry, checked 18 August 2026: - Telecoms: tighter. Under the SIM Card Registration Directive the regulator keeps a National Subscriber Registry on its own premises. Every operator must upload subscriber records to it within 72 hours. Communications content and details are sensitive data, so sending them abroad needs approval first. - Commercial hosting: to store data in Ethiopia as a business you need a licence from the communications regulator. It is either a Data Center Service Provider licence or a Hosting Service Provider licence. - Government: the national data centre and government cloud are run by the Ministry of Innovation and Technology. They are marketed on keeping data in Ethiopia. - Banking and payments: the central bank's technology rules for banks require a disaster recovery site separate from the main site. We found no separate banking or payments rule about where data sits. The national rule applies anyway. - Securities: the capital market regulator's published rules cover offerings, electronic share records and self-regulatory organisations. We found no rule about where data sits. - Health, insurance, education, gaming and mapping: we found no separate rule about where data sits on official sites, checked 18 August 2026. - Critical infrastructure: from July 2027 twelve industries, including finance, health, energy and government services, take on eighteen cybersecurity duties under a new law.
Sources
- Official sourceFederal Negarit Gazette / Ministry of Justice of EthiopiaPersonal Data Protection Proclamation No. 1321/2024, Article 22 (Data Sovereignty)
justice.gov.et
“Every data controller or data processor shall ensure the storage, on a server or data center located in Ethiopia, of personal data collected or obtained locally.”
Link checked 18 August 2026
- Official sourceEthiopian Communications AuthoritySIM Card Registration Directive No. 799/2021, Articles 5 and 7 — National Subscriber Registry hosted on the Authority's premises
eca.et
“The Authority shall: a) Host the National Subscriber Registry in a secure location on its premise;”
Link checked 18 August 2026
- Official sourceEthiopian Communications AuthorityEthiopian Communications Authority — licence list including Data Center Service Provider and Hosting Service Provider licences
eca.et
Link checked 18 August 2026
- Official sourceMinistry of Innovation and TechnologyEthiopian National Data Center / government cloud, operated by the Ministry of Innovation and Technology
cloud.gov.et
Link checked 18 August 2026
- Official sourceEthiopian Capital Market AuthorityEthiopian Capital Market Authority — published proclamation, directives and guidelines (no data location rule found)
ecma.gov.et
Link checked 18 August 2026
What to do: Plan for a database inside Ethiopia: this data is not allowed to leave.
Sending data out of the country
You need the regulator to approve the destination first. Before personal data leaves Ethiopia you must give the regulator evidence that the receiving country protects data properly. The regulator must then decide that it does. If it does not, the transfer is banned. There are narrow exceptions. The person gives explicit and informed consent. Or the transfer is truly necessary for a contract, a legal claim, an important public interest, or to save a life. Nothing you sign with the recipient replaces the regulator's approval.
- Ways to send data out:
- Official 'this country is safe' decision · Government sign-off needed · Explicit consent · Needed for a contract · Legal claims · Important public interest · To save someone’s life
Proclamation No. 1321/2024 sets out the chain. Data may go abroad only where the destination 'ensures appropriate levels of protection'. The law is blunt about the alternative: sending data to a country that does not ensure appropriate protection 'is prohibited'. The regulator can still allow a limited transfer if the person consents and the data is cut down. The law then sets four exceptions, lets the regulator demand proof that your protections work, and lets it ban or suspend a transfer. Sensitive data needs approval in advance on top of all this. The regulator decides each case one by one. There is no approved-country list and no standard contract. Ethiopia has no equivalent of Europe's standard contract clauses or group-wide internal rules, and no certification scheme. We found no published decision that any country is safe enough, so that list is empty. That leaves a real problem. The route the law depends on does not yet exist in a usable form. Meanwhile sending data out without it is a crime carrying five to ten years in prison.
Sources
- Official sourceFederal Negarit Gazette / Ministry of Justice of EthiopiaPersonal Data Protection Proclamation No. 1321/2024, Articles 18-22 (transfer principle, level of protection, conditions, safeguards, data sovereignty)
justice.gov.et
“the transfer of personal data to a third-party jurisdiction that does not ensure appropriate level of protection is prohibited.”
Link checked 18 August 2026
- Official sourceEthiopian Communications AuthorityEthiopian Communications Authority — Resources page listing every law, regulation and directive it has published (no transfer directive, no adequacy list)
eca.et
Link checked 18 August 2026
What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.
The regulator, and whether it actually acts
The Ethiopian Communications Authority, the telecoms regulator, was given the job. Its own website says it registers and supervises the companies that handle personal data, investigates complaints and issues rules. We could find none of that happening. Two years after the law started, it has published no data protection rules. It offers no way to register. It has announced no decisions or fines. The telecoms side of the same regulator is busy and effective. So this is a choice about priorities, not an empty building.
Proclamation No. 1321/2024 names the Ethiopian Communications Authority as the regulator. That body was set up under Communications Service Proclamation No. 1148/2019. Its own about page says it 'serves as the national authority responsible for regulating and enforcing personal data protection in Ethiopia'. It also says it registers and supervises the organisations that handle personal data. The evidence says otherwise. Its Resources page lists eleven telecoms rules from 2021 plus a fees rule. Under Laws it simply hosts a copy of the privacy law, uploaded in October 2025. Its Services page lists telecoms, postal and internet licences, with no way to register as a company handling personal data. Its public notices in October and December 2025 concern interconnection offers by Ethio Telecom and Safaricom. The privacy law also says the detail of administrative offences and fines is to be set by a Council of Ministers regulation. We found no such regulation, so the administrative fine machinery is not yet usable. The criminal penalties do not depend on any regulation. They are enforced by prosecutors and courts, not by the regulator. Other regulators are active in their own areas. The National Bank of Ethiopia supervises bank technology risk. The Information Network Security Administration publishes standards, controls technology imports, and now runs the critical infrastructure rules.
Sources
- Official sourceEthiopian Communications AuthorityEthiopian Communications Authority — About page, data protection mandate
eca.et
“Under the Personal Data Protection Proclamation No. 1321/2024, the Ethiopian Communications Authority (ECA) also serves as the national authority responsible for regulating and enforcing personal data protection in Ethiopia.”
Link checked 18 August 2026
- Official sourceEthiopian Communications AuthorityEthiopian Communications Authority — Resources: laws, regulations and directives published to date
eca.et
Link checked 18 August 2026
- Official sourceEthiopian Communications AuthorityEthiopian Communications Authority — Services: licence types offered (no data controller registration)
eca.et
Link checked 18 August 2026
- Official sourceFederal Negarit Gazette / Ministry of Justice of EthiopiaPersonal Data Protection Proclamation No. 1321/2024, Article 2(36) and Article 60 (Administrative Sanctions)
justice.gov.et
“the details of administrative offences and fines shall be governed by regulation.”
Link checked 18 August 2026
How long you must keep it — and when to delete it
The maximum is clear. The minimums mostly are not. Once the reason for holding personal data has gone, you must destroy it as soon as you reasonably can. You must destroy it in a way that stops anyone rebuilding it. The clearest minimum we could confirm is in telecoms. When a mobile line is switched off, the operator keeps that subscriber's records for three months. Ethiopia is also unusual in another way. A person's privacy rights survive them, and last for ten years after death.
- What you have to do here:
- Delete data after a period · Keep data for a minimum period · Keep logs · Tell people what you do
Proclamation No. 1321/2024 sets the duty to destroy. Deletion must be done so the record cannot be rebuilt into readable form. You must also tell everyone else holding the data on your behalf to do the same. You must publish your keep-times in your privacy notice. Privacy rights stay alive for ten years after death, which affects deletion routines built only for living users. The law leaves the keep-time for access logs to the regulator, and the regulator has not set one. So log keep-times are undefined by law, not unlimited. The SIM Card Registration Directive sets the three-month minimum for switched-off subscribers. Ordinary business minimums for tax, company and accounting records almost certainly apply through Ethiopian tax and commercial law. The Ministry of Revenue website would not load for us, so we do not state a number.
Sources
- Official sourceFederal Negarit Gazette / Ministry of Justice of EthiopiaPersonal Data Protection Proclamation No. 1321/2024, Articles 23, 46 and 50 (duration of protection, logs, duty to destroy)
justice.gov.et
“where the purpose for storing personal data has lapsed, every data controller shall destroy the personal data as soon as is reasonably practicable.”
Link checked 18 August 2026
- Official sourceEthiopian Communications AuthoritySIM Card Registration Directive No. 799/2021, Article 20(4) — three-month retention after deactivation
eca.et
“the Telecommunications Operator shall retain the records of the relevant Subscriber for three (3) months;”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
There are three separate deadlines, soon to be four. Within 72 hours of learning of a personal data breach you must tell the regulator. Within 72 hours you must also tell the people affected. That is unusual. Most countries only say 'promptly' for telling individuals. Banks have a separate deadline of two working days to the central bank for serious technology incidents. From July 2027, organisations in twelve critical industries get a 48 hour deadline to the national cyber emergency team. Failing to report a breach at all is a crime.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
- What it costs if you get it wrong:
- Criminal liability
Proclamation No. 1321/2024 sets the two 72-hour deadlines and lists what your notice must contain. A late notice must explain the delay. If you handle data on someone else's behalf, you must tell them without undue delay. Directive No. SBB/83/2022 requires a bank to notify the National Bank's Banking Supervision Directorate within two working days of any technology incident that could have significant impact. The Critical Infrastructure Cybersecurity Proclamation No. 1426/2026 requires notice to the National Computer Emergency Response Centre within 48 hours. It was published on 21 July 2026 and takes effect one year later. Under the privacy law, not reporting a breach is a crime. So is failing to take technical and organisational steps once a breach has happened. The penalty is one to three years' simple imprisonment, or a fine of 60,000 to 100,000 birr, roughly 375 to 625 US dollars, or both.
Sources
- Official sourceFederal Negarit Gazette / Ministry of Justice of EthiopiaPersonal Data Protection Proclamation No. 1321/2024, Articles 43 and 44 (notification of personal data breach)
justice.gov.et
“Where there is a personal data breach, the data controller shall within 72 hours after having become aware of it, notify the personal data breach to the Authority.”
Link checked 18 August 2026
- Official sourceNational Bank of EthiopiaDirective No. SBB/83/2022, Requirements for Information Technology Management of Banks — two working day incident notification
nbe.gov.et
“A bank shall notify Banking Supervision Directorate of the National Bank within 2 (two) working days any IT incidents that could have significant impact”
Link checked 18 August 2026
- Official sourceInformation Network Security AdministrationCritical Infrastructure Cybersecurity Proclamation No. 1426/2026, Article 8 — 48 hour incident notification
insa.gov.et
“To notify cybersecurity incidents the National Computer Emergency Response Center within 48 hours”
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things will ruin someone's week. First, you must be registered with the regulator before you touch any personal data. The regulator offers no way to register, so the duty cannot be met. Second, a child here is anyone under sixteen, not thirteen. Third, breaking the export rules is a crime carrying five to ten years in prison. Prison does not need the missing fines regulation to work. Fourth, the content and details of people's messages count as sensitive data. So sending communications records abroad needs permission first. Fifth, the servers, firewalls and security modules you would need to store data locally are on a government control list. You need a security clearance permit before you can import or use them.
- What you have to do here:
- Register or notify · Get a parent's consent for children
- What it costs if you get it wrong:
- Criminal liability · Percentage of global turnover
(1) The privacy law says you must be registered with the Authority before you handle personal data. The certificate lasts two years. The Authority's own services list contains no such registration. So every organisation in the country is technically in breach. (2) The law defines a child as anyone under sixteen. It requires parent or guardian consent, and limits marketing and profiling aimed at children. (3) Three acts carry five to ten years' rigorous imprisonment plus a fine of 200,000 to 600,000 birr, roughly 1,250 to 3,750 US dollars. Those are re-identifying data that had names stripped out, selling personal data, and sending personal data outside Ethiopia against the law. The law adds an administrative fine of up to 4 per cent of total worldwide turnover for the previous financial year. That applies if the offender is an organisation, or if the case involves sensitive data or a child. Any money made from the offence goes to the government. (4) The law puts 'communications data, including content and metadata' inside the sensitive category. That pulls telecoms, messaging and email providers into the rule requiring approval in advance. The Authority may also add new categories of sensitive data at any time. (5) The Information Technology Products Security Clearance and Control Proclamation No. 1310/2023 requires a security clearance permit to import, export or use listed products. The Information Network Security Administration publishes both lists. The restricted list includes servers above 5.0 GHz, high performance computing systems, network switches at or above 1 Tbps, firewalls at or above 20 Gbps, and hardware security modules. The prohibited list includes low-earth-orbit satellite internet terminals and digital forensic tools. Both lists have entries on them today.
Sources
- Official sourceFederal Negarit Gazette / Ministry of Justice of EthiopiaPersonal Data Protection Proclamation No. 1321/2024, Articles 2(5), 2(15), 33, 60 and 64
justice.gov.et
“In order to process personal data the data controller or the data processor shall be registered with the Authority.”
Link checked 18 August 2026
- Official sourceEthiopian Communications AuthorityEthiopian Communications Authority — Services page: no data controller or processor registration offered
eca.et
Link checked 18 August 2026
- Official sourceInformation Network Security AdministrationInformation Technology Products Security Clearance and Control Proclamation No. 1310/2023, Federal Negarit Gazette No. 18, 6 March 2024
insa.gov.et
Link checked 18 August 2026
- Official sourceInformation Network Security AdministrationAppendix 01 — Restricted Technology Product Lists (servers, firewalls, switches, hardware security modules)
insa.gov.et
Link checked 18 August 2026
- Official sourceInformation Network Security AdministrationAppendix 02 — Prohibited Technology Product Lists
insa.gov.et
Link checked 18 August 2026
What's changing next
One dated change, plus several powers that could be used without warning. The dated change: the Critical Infrastructure Cybersecurity Proclamation was published on 21 July 2026 and takes effect on 21 July 2027. It gives twelve industries eighteen security duties, a 48 hour incident deadline, and a licence requirement for anyone selling cybersecurity products or services into Ethiopia. Those industries include finance, health, energy, transport and government services. The powers: the government has not yet issued the regulation setting privacy fines. The regulator has issued no rules. And it can at any time name categories of data that may never leave the country.
Dated. Proclamation No. 1426/2026 was signed at Addis Ababa on 21 July 2026. It comes into force one year after publication in the Federal Negarit Gazette, so 21 July 2027. During that year the Information Network Security Administration says it will issue detailed rules and standards. Suppliers of cybersecurity products or services will need a licence, security clearance, minimum capital and a permanent address in Ethiopia. Powers that could be used at any time, with no consultation. (1) The Council of Ministers regulation on administrative offences and fines. Issuing it would switch on the 4 per cent turnover penalty. (2) The Authority's power to issue rules, including the registration requirements every organisation is already supposed to meet. (3) The duty on the Authority to name categories of 'critical personal data' that may only be handled inside Ethiopia. That category has no size limit and does not exist yet. (4) The Authority's power to declare any other data sensitive, which would drag it into the approval-in-advance rules. (5) The unset keep-time for access logs. (6) The Information Network Security Administration's prohibited and restricted technology product lists, which it can revise at will.
Sources
- Official sourceInformation Network Security AdministrationCritical Infrastructure Cybersecurity Proclamation No. 1426/2026, Article 28 (Effective Date), Federal Negarit Gazette No. 41, 21 July 2026
insa.gov.et
“This Proclamation shall enter into force One year after its publication in the Federal Negarit Gazette.”
Link checked 18 August 2026
- Official sourceInformation Network Security AdministrationInformation Network Security Administration press briefing, 7 August 2026 — twelve sectors, eighteen obligations, 48 hour reporting, one-year grace period
insa.gov.et
Link checked 18 August 2026
- Official sourceFederal Negarit Gazette / Ministry of Justice of EthiopiaPersonal Data Protection Proclamation No. 1321/2024, Articles 22(2), 46, 60(3) and 69 (dormant powers)
justice.gov.et
Link checked 18 August 2026
What to do: Diarise 21 July 2027 — that is the date this changes.
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Telecoms data needs a copy kept in the country
Official name: SIM Card Registration Directive No. 799/2021 · Directive No. 799/2021 · Government rules
Every mobile subscriber's identity record sits in a national registry held on the telecoms regulator's own premises. That includes biometric data where available. Operators must upload updates within 72 hours. So subscriber identity data cannot really leave Ethiopia. The communications data attached to it counts as sensitive under the privacy law.
Enforced by Ethiopian Communications Authority
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryThe regulator hosts the National Subscriber Registry on its own premises. Operators must also keep their own subscriber database and upload updates.
- Keep records of how you use data — within 72 hoursThe updated operator database must reach the Authority within 72 hours of registering a subscriber.
- Keep data for a minimum period — 3 monthsRecords of a switched-off subscriber are kept for three months.
- Secure the dataAccess to subscriber information is restricted, unless the Authority asks for it or a court orders it.
What it costs if you get it wrong
- Loss of your licenceNon-compliance by a licensed telecommunications operator
Sources
- Official sourceEthiopian Communications AuthoritySIM Card Registration Directive No. 799/2021, Articles 5, 6, 7 and 20
eca.et
“The Authority shall establish and maintain a database of all registered Subscribers' information in a central database referred to as the “National Subscriber Registry.””
Link checked 18 August 2026
- Official sourceEthiopian Communications AuthorityEthiopian Communications Authority — Resources page listing Directive No. 799/2021
eca.et
Link checked 18 August 2026
Telecoms rules
Official name: Telecommunications Licensing Directive No. 792/2021 · Directive No. 792/2021 · Licence condition
Storing other people's data in Ethiopia as a business needs a licence. The telecoms regulator issues separate Data Center Service Provider and Hosting Service Provider licences. So the obvious way to meet the national storage rule, hiring local hosting, needs a licence of its own.
Enforced by Ethiopian Communications Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Register or notifyYou need a licence to run a data centre in Ethiopia, or to host other people's data commercially there. It is either a Data Center Service Provider licence or a Hosting Service Provider licence. Internet service, internet exchange point and satellite terminal licences sit in the same rules.
What it costs if you get it wrong
- Loss of your licenceOperating an unlicensed data centre or hosting service
Sources
- Official sourceEthiopian Communications AuthorityTelecommunications Licensing Directive No. 792/2021, definitions of Data Center Service Provider Licence and Hosting Service Provider Licence
eca.et
““Data Center Service Provider License” means a License issued by the Authority”
Link checked 18 August 2026
- Official sourceEthiopian Communications AuthorityEthiopian Communications Authority — licence list
eca.et
Link checked 18 August 2026
Payment data rules
Official name: Requirements for Information Technology (IT) Management of Banks, Directive No. SBB/83/2022 · Directive No. SBB/83/2022 · Regulator directive
The central bank's technology rulebook for banks. It requires a disaster recovery site separate from the main site. It requires a customer data privacy policy. And it requires notice of significant technology incidents within two working days. We found no banking or payments rule requiring data to stay in Ethiopia. The national privacy law already does that on its own.
Enforced by National Bank of Ethiopia
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — within 48 hoursTwo working days to the National Bank's Banking Supervision Directorate for high-impact incidents, plus quarterly incident reports.
- Secure the dataA board-approved technology strategy, a risk register updated quarterly, a customer data privacy policy, and management of your suppliers.
- Independent auditA dedicated technology audit team inside internal audit.
- Written vendor contractOutside suppliers who can see confidential information are expressly covered.
What it costs if you get it wrong
- Order to stopSupervisory action by the National Bank for non-compliance
Sources
- Official sourceNational Bank of EthiopiaDirective No. SBB/83/2022, Requirements for Information Technology Management of Banks
nbe.gov.et
“A bank shall set up or build a disaster recovery site that is maintained at safe place with adequate detachment from the main site of the IT systems.”
Link checked 18 August 2026
- Official sourceNational Bank of EthiopiaNational Bank of Ethiopia — directive record page
nbe.gov.et
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Personal data needs a copy kept in the country
Official name: የግል ዳታ ጥበቃ አዋጅ ቁጥር ፩ሺ፫፻፳፩/፪ሺ፲፮ — Personal Data Protection Proclamation No. 1321/2024 · Proclamation No. 1321/2024, Federal Negarit Gazette 30th Year No. 35 · Act of parliament
Ethiopia's general privacy law, in force since 24 July 2024 with no transition period. Personal data collected locally must be stored in Ethiopia. Sending it abroad depends on the regulator accepting the destination country. You must register before you handle any personal data. The law is backed by prison sentences rather than the usual administrative fines.
Enforced by Ethiopian Communications Authority
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, Important public interest, To save someone’s life
What you have to do
- Keep the data in the countryPersonal data collected or obtained in Ethiopia must be stored on a server or in a data centre in Ethiopia. No size limit, no transition period.
- Register or notifyYou must register with the Authority before you handle any personal data. The certificate lasts two years. No way to register actually exists.
- Put a transfer safeguard in placeThe regulator must accept the destination country's level of protection. Sensitive data needs approval in advance.
- Get consent
- Tell people what you doYou must state your keep-times and any transfers to another country.
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people object
- Limit automated decisions
- Secure the data
- Report breaches to the regulator — within 72 hours
- Tell affected people — within 72 hoursA firm 72-hour deadline for telling individuals, not the usual 'without undue delay'.
- Appoint a data protection officer — applies at: Government bodies; large-scale regular and systematic monitoring; large-scale sensitive dataContact details must be published and given to the Authority. A group may share one officer, as long as each company can reach them easily.
- Assess high-risk projectsYou need this where your use of data is likely to put people's rights and freedoms at risk. In high-risk cases you must consult the Authority first.
- Delete data after a periodDestroy the data as soon as you reasonably can, once you no longer need it. Destroy it so it cannot be rebuilt.
- Get a parent's consent for children — applies at: under 16
- Written vendor contract
What it costs if you get it wrong
- Criminal liability: 5-10 years rigorous imprisonment and ETB 200,000-600,000 — about $4 thousandTransferring personal data outside Ethiopia in violation of the proclamation; selling personal data; re-identifying de-identified data
- Criminal liability: 3-5 years imprisonment and ETB 100,000-200,000 — about $1 thousandIgnoring erasure, objection, restriction or automated-decision rights
- Criminal liability: 1-3 years simple imprisonment or ETB 60,000-100,000 — about $622Failing to report a breach, failing to act on one, or processing contrary to the principles
- Percentage of global turnover: 4% of total worldwide turnover of the preceding financial yearOffence committed by an institution, or involving sensitive data or a minor. Detail left to a regulation that has not been issued.
Sources
- Official sourceFederal Negarit Gazette / Ministry of Justice of EthiopiaPersonal Data Protection Proclamation No. 1321/2024, full text, Federal Negarit Gazette No. 35, 24 July 2024
justice.gov.et
“Every data controller or data processor shall ensure the storage, on a server or data center located in Ethiopia, of personal data collected or obtained locally.”
Link checked 18 August 2026
- Official sourceMinistry of Justice of EthiopiaMinistry of Justice — Personal Data Protection Proclamation record page
justice.gov.et
Link checked 18 August 2026
- Official sourceEthiopian Communications AuthorityEthiopian Communications Authority — Resources page hosting the proclamation under Laws
eca.et
Link checked 18 August 2026
Cyber security rules
Official name: Critical Infrastructure Cybersecurity Protection Proclamation No. 1426/2026 · Proclamation No. 1426/2026, Federal Negarit Gazette No. 41, 21 July 2026 · Act of parliament
Passed on 10 June 2026 and published on 21 July 2026. This law does not take effect until 21 July 2027. It names twelve critical industries. It imposes eighteen security duties, including a 48 hour incident deadline. It reaches Ethiopian critical infrastructure located abroad. And it requires a licence from anyone selling cybersecurity products or services into the country.
Enforced by Information Network Security Administration
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — within 48 hours, from 21 July 2027To the National Computer Emergency Response Centre.
- Independent audit — from 21 July 2027You must get a cybersecurity audit certificate, renew it, and act on what the audit finds.
- Hold a security certificate — from 21 July 2027You need security assurance before you switch on information and communications technology systems you have bought.
- Register or notify — from 21 July 2027Cybersecurity product and service providers need a licence, security clearance, minimum capital and a permanent address in Ethiopia.
- Secure the data — from 21 July 2027Eighteen duties in total, including running a security operations centre and securing your supply chain.
What it costs if you get it wrong
- Criminal liability: 7-10 years rigorous imprisonmentActs harming national security, public health or life through critical infrastructure
- Criminal liability: 3-5 years rigorous imprisonmentThe same acts committed negligently
Sources
- Official sourceInformation Network Security AdministrationCritical Infrastructure Cybersecurity Proclamation No. 1426/2026, full text
insa.gov.et
“This Proclamation shall enter into force One year after its publication in the Federal Negarit Gazette.”
Link checked 18 August 2026
- Official sourceInformation Network Security AdministrationInformation Network Security Administration statement, 7 August 2026
insa.gov.et
Link checked 18 August 2026
- Official sourceInformation Network Security AdministrationInformation Network Security Administration — documentation portal
insa.gov.et
Link checked 18 August 2026
Internet and platform rules
Official name: Information Technology Products Security Clearance and Control Proclamation No. 1310/2023 · Proclamation No. 1310/2023, Federal Negarit Gazette No. 18, 6 March 2024 · Act of parliament
A permit system for technology hardware that quietly shapes where you can store data. Both control lists have entries today. Servers above 5.0 GHz, high performance computing, large firewalls and switches, and hardware security modules are restricted. Satellite internet terminals and forensic tools are banned outright. So building local storage that meets the law needs a security clearance first.
Enforced by Information Network Security Administration
How this country controls where data goes: Only approved countries · Accepted routes: Government sign-off needed
What you have to do
- Register or notifyYou need a security clearance permit to import, export or use a listed information technology product.
- Hold a security certificateYou may use products on the restricted list only with clearance. You may not use products on the prohibited list at all.
What it costs if you get it wrong
- Criminal liabilityImporting, exporting or using prohibited or restricted technology products without clearance
Sources
- Official sourceInformation Network Security AdministrationInformation Technology Products Security Clearance and Control Proclamation No. 1310/2023
insa.gov.et
Link checked 18 August 2026
- Official sourceInformation Network Security AdministrationAppendix 01 — Restricted Technology Product Lists
insa.gov.et
Link checked 18 August 2026
- Official sourceInformation Network Security AdministrationAppendix 02 — Prohibited Technology Product Lists
insa.gov.et
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
That no Council of Ministers regulation and no regulator directive under the Personal Data Protection Proclamation exists as of 18 August 2026
We found no data protection rules issued by the regulator, but we could not check every source. We looked at the regulator's own Resources and Services pages and the Ministry of Justice list of technology laws. The Ministry of Justice search and its machine-readable index both returned server errors. So we cannot fully rule out a recent rule published somewhere else.
That the regulator has published no finding that any destination country offers an adequate level of protection
We found no published list of countries the regulator considers safe enough. No such list appears on the regulator's site. The law lets the regulator decide privately, transfer by transfer, without publishing anything. So a decision may exist that we cannot see.
Whether the regulator has quietly opened any registration channel for data controllers and processors
We could not confirm that any way to register with the regulator exists. Its Services page lists no such registration, and its separate registration portal would not load for us. The lack of a public listing is strong evidence but not conclusive.
The general commercial record-keeping floor — how many years tax, accounting and company records must be kept
We could not confirm Ethiopia's general tax keep-times. The Ministry of Revenue website failed its security certificate check, so we could not read the Tax Administration Proclamation from an official source. Assume ordinary multi-year tax keep-times and check locally before you rely on it.
Whether any payments or insurance directive of the National Bank imposes its own keeping data in the country
We could not fully confirm the payments rules. The rules for payment issuers and payment system operators are published only as scanned images. We machine-read the 2023 payment issuer rules and the 2025 amendment and found no rule about where data sits. Text scanning can miss words, and the 2020 payment system operator rules were only partly readable.
Whether health, insurance, education, gaming or mapping regulators have issued any data location or transfer rule
We found no health rule about where data must sit on official sites, checked 18 August 2026. The health ministry's website was unreachable from our network. If you work in health, check before you rely on this.
Whether any prosecution has been brought under the criminal provisions of the privacy law
We could not confirm whether any court cases have been brought under this law. Ethiopian court decisions are not systematically published online. So finding no reported cases does not mean there are none.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.