Skip to the content
Global Data RulesData governance rules, country by country

Ethiopia

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.

The answer

A copy must stayWork: HighEnforcement: Dormant

Ethiopia's privacy law says personal data collected in the country must be kept on a server or in a data centre inside Ethiopia. A copy may go abroad, but usually only if the regulator first accepts that the destination protects data well enough. The law has been in force since July 2024. Almost nothing is being enforced: the regulator has published no rules and runs no register.

Data governance in Ethiopia

The eight things that decide how you handle data about people in Ethiopia. Same eight on every country page, so you can compare.

Who has to follow these rules

Only partly, and this is Ethiopia's oddest feature. The law covers any organisation set up in Ethiopia. A foreign company with no office is covered only if it uses equipment inside Ethiopia to process the data and has a representative based in Ethiopia. There is no size or revenue threshold. Read literally, a purely foreign online service with no kit and no representative in the country falls outside the law.

High confidenceNational rulesLocal representative

Where the data is allowed to live

A copy must stay in the country. Every organisation must keep personal data collected or obtained in Ethiopia on a server or in a data centre located in Ethiopia. A copy may then go abroad, but only in the situations the law allows. Data the law treats as sensitive needs the regulator's permission before it goes anywhere, and that category is wide: health, biometrics, race, religion, political views, criminal records, and the content and details of people's messages.

High confidenceA copy must stayKeep the data in the countryApproval each timeSensitive personal data

Sending data out of the country

You need the regulator to bless the destination first. Before personal data leaves Ethiopia you must give the regulator evidence that the receiving country protects data properly, and the regulator must decide that it does. If it does not, the transfer is banned unless you fall into a narrow exception: the person's explicit and informed consent, or the transfer is genuinely necessary for a contract, a legal claim, an important public interest or to save a life. Nothing you sign with the recipient replaces that.

High confidenceApproval each timeOfficial 'this country is safe' decisionGovernment sign-off neededExplicit consentNeeded for a contractLegal claimsImportant public interestSomeone's life is at risk

The regulator, and whether it actually acts

The Ethiopian Communications Authority, the telecoms regulator, was handed the job. On its own website it says it registers and supervises data controllers, investigates complaints and issues directives. In practice we could find none of that happening. Two years after the law started, it has published no data protection directive, offers no way to register, and has announced no decisions or fines. The telecoms side of the same regulator is busy and effective, so this is a choice about priorities rather than an empty building.

High confidenceDormantRegulator

How long you must keep it — and when to delete it

The ceiling is clear, the floor mostly is not. Once the reason for holding personal data has gone, you must destroy it as soon as you reasonably can, and in a way that stops anyone rebuilding it. The clearest minimum we could confirm is in telecoms: when a mobile line is switched off, the operator keeps that subscriber's records for three months. Ethiopia is also unusual in that a person's privacy rights survive them, and last for ten years after death.

Medium confidenceDelete data after a periodKeep data for a minimum periodKeep logsTell people what you do

If something goes wrong

Count three clocks, soon to be four. Within 72 hours of learning of a personal data breach you must tell the regulator, and within 72 hours you must also tell the people affected — Ethiopia puts a hard deadline on telling individuals, where most countries only say 'promptly'. Banks have a separate two working day deadline to the central bank for serious technology incidents. From July 2027, organisations in twelve critical sectors get a 48 hour deadline to the national cyber emergency team. Failing to report a breach at all is a crime.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidentsCriminal liability

What catches people out

Five things that will ruin someone's week. First, you must be registered with the regulator before you process any personal data at all — but the regulator offers no way to register, so the duty cannot be met. Second, a child here is anyone under sixteen, not thirteen. Third, breaking the export rules is a crime punishable by five to ten years in prison, and prison does not need the missing fine regulation to work. Fourth, the content and details of people's messages count as sensitive data, so exporting communications records needs prior permission. Fifth, the servers, firewalls and security modules you would need to store data locally are on a government control list and need a security clearance permit before you can import or use them.

High confidenceRegister or notifyGet a parent's consent for childrenCriminal liabilityPercentage of global turnoverTelecom network data

What's changing next

One dated change and several switches that could flip without warning. The dated one: the Critical Infrastructure Cybersecurity Proclamation was published on 21 July 2026 and takes effect on 21 July 2027, giving twelve sectors — including finance, health, energy, transport and government services — eighteen security duties, a 48 hour incident deadline, and a licensing regime for anyone selling cybersecurity products or services into Ethiopia. The switches: the government has not yet issued the regulation that sets privacy fines, the regulator has issued no directives, and it can at any time name categories of data that may never leave the country.

High confidencePassed, not yet fully in forceAct of parliament

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Telecoms

SIM Card Registration Directive No. 799/2021

Government rules · Directive No. 799/2021

In forceA copy must stay

Every mobile subscriber's identity record, including biometric data where available, sits in a national registry held on the telecoms regulator's own premises, with operators uploading updates within 72 hours. In practice subscriber identity data cannot leave Ethiopia, and the communications data attached to it counts as sensitive under the privacy law.

In force since 1 January 2021

Enforced by Ethiopian Communications Authority

Transfer model: Not allowed

High confidence
Telecoms

Telecommunications Licensing Directive No. 792/2021

Licence condition · Directive No. 792/2021

In forceYes, with paperwork

Storing other people's data in Ethiopia as a business is a licensed activity. The telecoms regulator issues separate Data Center Service Provider and Hosting Service Provider licences, so the obvious way to satisfy the national storage rule — hiring local hosting — is itself gated by a licence.

In force since 1 January 2021

Enforced by Ethiopian Communications Authority

Transfer model: No restriction · Accepted routes: Nothing required

High confidence
Banking

Requirements for Information Technology (IT) Management of Banks, Directive No. SBB/83/2022

Regulator directive · Directive No. SBB/83/2022

In forceYes, with paperwork

The central bank's technology rulebook for banks. It requires a disaster recovery site detached from the main site, a customer data privacy policy, and notification of significant technology incidents within two working days. We found no banking or payments rule requiring data to stay in Ethiopia — the national privacy law supplies that on its own.

In force since 15 January 2022

Enforced by National Bank of Ethiopia

Transfer model: No restriction · Accepted routes: Nothing required

Medium confidence

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

የግል ዳታ ጥበቃ አዋጅ ቁጥር ፩ሺ፫፻፳፩/፪ሺ፲፮ — Personal Data Protection Proclamation No. 1321/2024

Act of parliament · Proclamation No. 1321/2024, Federal Negarit Gazette 30th Year No. 35

In forceA copy must stay

Ethiopia's general privacy law, in force since 24 July 2024 with no transition period. It requires personal data collected locally to be stored in Ethiopia, makes cross-border transfer conditional on the regulator accepting the destination, demands registration before any processing, and backs the whole thing with prison sentences rather than the usual administrative fines.

In force since 24 July 2024

Enforced by Ethiopian Communications Authority

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, Important public interest, Someone's life is at risk

High confidence

Critical Infrastructure Cybersecurity Protection Proclamation No. 1426/2026

Act of parliament · Proclamation No. 1426/2026, Federal Negarit Gazette No. 41, 21 July 2026

Passed, not yet fully in forceYes, with paperwork

Passed on 10 June 2026 and published on 21 July 2026, this law does not take effect until 21 July 2027. It names twelve critical sectors, imposes eighteen security duties including a 48 hour incident deadline, reaches Ethiopian critical infrastructure located abroad, and licenses anyone selling cybersecurity products or services into the country.

In force since 21 July 2027

Enforced by Information Network Security Administration

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Information Technology Products Security Clearance and Control Proclamation No. 1310/2023

Act of parliament · Proclamation No. 1310/2023, Federal Negarit Gazette No. 18, 6 March 2024

In forceYes, with paperwork

A permit regime for technology hardware that quietly shapes data storage. Both control lists are populated today: servers above 5.0 GHz, high performance computing, large firewalls and switches, and hardware security modules are restricted, while satellite internet terminals and forensic tools are prohibited outright. Building compliant local storage therefore needs a security clearance first.

In force since 6 March 2024

Enforced by Information Network Security Administration

Transfer model: Allowlist · Accepted routes: Government sign-off needed

Medium confidence

Who you would hear from

  • የኢትዮጵያ ኮሙኒኬሽን ባለሥልጣን

    Telecoms, postal and courier regulation, and the national data protection authority under Proclamation No. 1321/2024

    Fully operational as a telecoms regulator — it licenses operators, approves interconnection offers and published notices in October and December 2025. Its data protection function is not operational: as of 18 August 2026 it has published no data protection directive, offers no data controller registration among its listed services, and has announced no decisions or penalties. It hosts a copy of the proclamation on its Resources page, uploaded in October 2025, and claims the mandate on its About page.

  • National cybersecurity, critical infrastructure protection, technology import clearance, national computer emergency response

    Visibly active: published the Critical Infrastructure Cybersecurity Proclamation and prohibited and restricted technology product lists, runs audit and clearance services, and briefed the press in August 2026.

  • Banking, insurance, microfinance, payments and the national payment system

    Issuing directives regularly, including several in late 2025 and January 2026.

  • National data centre and government cloud; digital policy

    Operates the Ethiopian National Data Center, marketed on local data sovereignty.

  • Securities markets and market intermediaries

    Active and issuing directives and guidance through 2025, but none found that touch data location.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • That no Council of Ministers regulation and no regulator directive under the Personal Data Protection Proclamation exists as of 18 August 2026

    We checked the regulator's own Resources and Services pages and the Ministry of Justice information and communications technology law list. The Ministry of Justice search function and its machine-readable index both returned server errors during this run, so we cannot fully exclude a recent instrument published elsewhere.

  • That the regulator has published no finding that any destination country offers an adequate level of protection

    No such list appears on the regulator's site. A determination could in principle be made privately, per transfer, without publication — that is how the law is drafted.

  • Whether the regulator has quietly opened any registration channel for data controllers and processors

    Its Services page lists no such registration and its separate registration portal would not resolve to us. Absence of a public listing is strong but not conclusive.

  • The general commercial record-keeping floor — how many years tax, accounting and company records must be kept

    The Ministry of Revenue website failed certificate validation throughout this run, so we could not read the Tax Administration Proclamation from an official source. Assume ordinary multi-year tax retention and verify locally.

  • Whether any payments or insurance directive of the National Bank imposes its own data localisation

    The payment instrument issuer and payment system operator directives are published only as scanned images. We machine-read the 2023 payment instrument issuer directive and the 2025 amendment and found no location clause, but optical character recognition can miss text, and the 2020 payment system operators directive was only partly readable.

  • Whether health, insurance, education, gaming or mapping regulators have issued any data location or transfer rule

    No rule found on official sites, checked 18 August 2026. The health ministry's website was unreachable through our network during this run.

  • Whether any prosecution has been brought under the criminal provisions of the privacy law

    Ethiopian court decisions are not systematically published online, so an absence of reported cases is not evidence of an absence of cases.

60-day cadence. Ethiopia has several switches that can flip with one instrument and no consultation: the fines regulation, the first regulator directives, the designation of critical personal data that may never leave, and the technology control lists. The critical infrastructure regime also starts on 21 July 2027, with implementing directives expected before then.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Ethiopia versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.