Skip to the content
Global Data RulesData governance rules, country by country

Ethiopia

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Ethiopia — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

A copy must stayWork: HighEnforcement: Dormant

Ethiopia's privacy law says personal data collected in the country must be kept on a server or in a data centre inside Ethiopia. A copy may go abroad. Usually that only works if the regulator first accepts that the destination country protects data well enough. The law has been in force since July 2024. Almost nothing is being enforced. The regulator has published no rules and runs no register.

Data governance in Ethiopia

The eight things that decide how you handle data about people in Ethiopia. Same eight on every country page, so you can compare.

Who has to follow these rules

Only partly, and this is Ethiopia's oddest feature. The law covers any organisation set up in Ethiopia. A foreign company with no office is covered only if two things are true. It uses equipment inside Ethiopia to handle the data. And it has a representative based in Ethiopia. There is no size or revenue level below which you are free. Read literally, a purely foreign online service with no equipment and no representative in the country falls outside the law.

Where the data is allowed to live

A copy must stay in the country. Every organisation must keep personal data collected or obtained in Ethiopia on a server or in a data centre in Ethiopia. A copy may then go abroad, but only in the situations the law allows. Data the law treats as sensitive needs the regulator's permission before it goes anywhere. That category is wide. It covers health, biometrics, race, religion, political views, criminal records, and the content and details of people's messages.

What you have to do here:
Keep the data in the country

What to do: Plan for a database inside Ethiopia: this data is not allowed to leave.

Sending data out of the country

You need the regulator to approve the destination first. Before personal data leaves Ethiopia you must give the regulator evidence that the receiving country protects data properly. The regulator must then decide that it does. If it does not, the transfer is banned. There are narrow exceptions. The person gives explicit and informed consent. Or the transfer is truly necessary for a contract, a legal claim, an important public interest, or to save a life. Nothing you sign with the recipient replaces the regulator's approval.

Ways to send data out:
Official 'this country is safe' decision · Government sign-off needed · Explicit consent · Needed for a contract · Legal claims · Important public interest · To save someone’s life

What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.

The regulator, and whether it actually acts

The Ethiopian Communications Authority, the telecoms regulator, was given the job. Its own website says it registers and supervises the companies that handle personal data, investigates complaints and issues rules. We could find none of that happening. Two years after the law started, it has published no data protection rules. It offers no way to register. It has announced no decisions or fines. The telecoms side of the same regulator is busy and effective. So this is a choice about priorities, not an empty building.

How long you must keep it — and when to delete it

The maximum is clear. The minimums mostly are not. Once the reason for holding personal data has gone, you must destroy it as soon as you reasonably can. You must destroy it in a way that stops anyone rebuilding it. The clearest minimum we could confirm is in telecoms. When a mobile line is switched off, the operator keeps that subscriber's records for three months. Ethiopia is also unusual in another way. A person's privacy rights survive them, and last for ten years after death.

What you have to do here:
Delete data after a period · Keep data for a minimum period · Keep logs · Tell people what you do

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

There are three separate deadlines, soon to be four. Within 72 hours of learning of a personal data breach you must tell the regulator. Within 72 hours you must also tell the people affected. That is unusual. Most countries only say 'promptly' for telling individuals. Banks have a separate deadline of two working days to the central bank for serious technology incidents. From July 2027, organisations in twelve critical industries get a 48 hour deadline to the national cyber emergency team. Failing to report a breach at all is a crime.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents
What it costs if you get it wrong:
Criminal liability

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things will ruin someone's week. First, you must be registered with the regulator before you touch any personal data. The regulator offers no way to register, so the duty cannot be met. Second, a child here is anyone under sixteen, not thirteen. Third, breaking the export rules is a crime carrying five to ten years in prison. Prison does not need the missing fines regulation to work. Fourth, the content and details of people's messages count as sensitive data. So sending communications records abroad needs permission first. Fifth, the servers, firewalls and security modules you would need to store data locally are on a government control list. You need a security clearance permit before you can import or use them.

What you have to do here:
Register or notify · Get a parent's consent for children
What it costs if you get it wrong:
Criminal liability · Percentage of global turnover

What's changing next

One dated change, plus several powers that could be used without warning. The dated change: the Critical Infrastructure Cybersecurity Proclamation was published on 21 July 2026 and takes effect on 21 July 2027. It gives twelve industries eighteen security duties, a 48 hour incident deadline, and a licence requirement for anyone selling cybersecurity products or services into Ethiopia. Those industries include finance, health, energy, transport and government services. The powers: the government has not yet issued the regulation setting privacy fines. The regulator has issued no rules. And it can at any time name categories of data that may never leave the country.

What to do: Diarise 21 July 2027 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Telecoms

Telecoms data needs a copy kept in the country

Official name: SIM Card Registration Directive No. 799/2021 · Directive No. 799/2021 · Government rules

In forceA copy must stay

Every mobile subscriber's identity record sits in a national registry held on the telecoms regulator's own premises. That includes biometric data where available. Operators must upload updates within 72 hours. So subscriber identity data cannot really leave Ethiopia. The communications data attached to it counts as sensitive under the privacy law.

In force since 1 January 2021

Enforced by Ethiopian Communications Authority

How this country controls where data goes: Not allowed

Telecoms

Telecoms rules

Official name: Telecommunications Licensing Directive No. 792/2021 · Directive No. 792/2021 · Licence condition

In forceYes, with paperwork

Storing other people's data in Ethiopia as a business needs a licence. The telecoms regulator issues separate Data Center Service Provider and Hosting Service Provider licences. So the obvious way to meet the national storage rule, hiring local hosting, needs a licence of its own.

In force since 1 January 2021

Enforced by Ethiopian Communications Authority

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Banking

Payment data rules

Official name: Requirements for Information Technology (IT) Management of Banks, Directive No. SBB/83/2022 · Directive No. SBB/83/2022 · Regulator directive

In forceYes, with paperwork

The central bank's technology rulebook for banks. It requires a disaster recovery site separate from the main site. It requires a customer data privacy policy. And it requires notice of significant technology incidents within two working days. We found no banking or payments rule requiring data to stay in Ethiopia. The national privacy law already does that on its own.

In force since 15 January 2022

Enforced by National Bank of Ethiopia

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Personal data needs a copy kept in the country

Official name: የግል ዳታ ጥበቃ አዋጅ ቁጥር ፩ሺ፫፻፳፩/፪ሺ፲፮ — Personal Data Protection Proclamation No. 1321/2024 · Proclamation No. 1321/2024, Federal Negarit Gazette 30th Year No. 35 · Act of parliament

In forceA copy must stay

Ethiopia's general privacy law, in force since 24 July 2024 with no transition period. Personal data collected locally must be stored in Ethiopia. Sending it abroad depends on the regulator accepting the destination country. You must register before you handle any personal data. The law is backed by prison sentences rather than the usual administrative fines.

In force since 24 July 2024

Enforced by Ethiopian Communications Authority

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, Important public interest, To save someone’s life

Cyber security rules

Official name: Critical Infrastructure Cybersecurity Protection Proclamation No. 1426/2026 · Proclamation No. 1426/2026, Federal Negarit Gazette No. 41, 21 July 2026 · Act of parliament

Passed, not yet fully in forceYes, with paperwork

Passed on 10 June 2026 and published on 21 July 2026. This law does not take effect until 21 July 2027. It names twelve critical industries. It imposes eighteen security duties, including a 48 hour incident deadline. It reaches Ethiopian critical infrastructure located abroad. And it requires a licence from anyone selling cybersecurity products or services into the country.

In force since 21 July 2027

Enforced by Information Network Security Administration

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Internet and platform rules

Official name: Information Technology Products Security Clearance and Control Proclamation No. 1310/2023 · Proclamation No. 1310/2023, Federal Negarit Gazette No. 18, 6 March 2024 · Act of parliament

In forceYes, with paperwork

A permit system for technology hardware that quietly shapes where you can store data. Both control lists have entries today. Servers above 5.0 GHz, high performance computing, large firewalls and switches, and hardware security modules are restricted. Satellite internet terminals and forensic tools are banned outright. So building local storage that meets the law needs a security clearance first.

In force since 6 March 2024

Enforced by Information Network Security Administration

How this country controls where data goes: Only approved countries · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.

Who you would hear from

  • የኢትዮጵያ ኮሙኒኬሽን ባለሥልጣን

    Telecoms, postal and courier regulation, and the national data protection authority under Proclamation No. 1321/2024

    Fully working as a telecoms regulator. It licenses operators, approves interconnection offers, and published notices in October and December 2025. Its data protection side is not working. As of 18 August 2026 it has published no data protection rules. It offers no way to register among its listed services. It has announced no decisions or penalties. It hosts a copy of the privacy law on its Resources page, uploaded in October 2025, and claims the role on its About page.

  • National cybersecurity, critical infrastructure protection, technology import clearance, national computer emergency response

    Visibly active. It published the Critical Infrastructure Cybersecurity Proclamation and the prohibited and restricted technology product lists. It runs audit and clearance services, and briefed the press in August 2026.

  • Banking, insurance, microfinance, payments and the national payment system

    Issuing rules regularly, including several in late 2025 and January 2026.

  • National data centre and government cloud; digital policy

    Runs the Ethiopian National Data Center, marketed on keeping data in Ethiopia.

  • Securities markets and market intermediaries

    Active, issuing rules and guidance through 2025. We found none that touch where data must sit.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That no Council of Ministers regulation and no regulator directive under the Personal Data Protection Proclamation exists as of 18 August 2026

    We found no data protection rules issued by the regulator, but we could not check every source. We looked at the regulator's own Resources and Services pages and the Ministry of Justice list of technology laws. The Ministry of Justice search and its machine-readable index both returned server errors. So we cannot fully rule out a recent rule published somewhere else.

  • That the regulator has published no finding that any destination country offers an adequate level of protection

    We found no published list of countries the regulator considers safe enough. No such list appears on the regulator's site. The law lets the regulator decide privately, transfer by transfer, without publishing anything. So a decision may exist that we cannot see.

  • Whether the regulator has quietly opened any registration channel for data controllers and processors

    We could not confirm that any way to register with the regulator exists. Its Services page lists no such registration, and its separate registration portal would not load for us. The lack of a public listing is strong evidence but not conclusive.

  • The general commercial record-keeping floor — how many years tax, accounting and company records must be kept

    We could not confirm Ethiopia's general tax keep-times. The Ministry of Revenue website failed its security certificate check, so we could not read the Tax Administration Proclamation from an official source. Assume ordinary multi-year tax keep-times and check locally before you rely on it.

  • Whether any payments or insurance directive of the National Bank imposes its own keeping data in the country

    We could not fully confirm the payments rules. The rules for payment issuers and payment system operators are published only as scanned images. We machine-read the 2023 payment issuer rules and the 2025 amendment and found no rule about where data sits. Text scanning can miss words, and the 2020 payment system operator rules were only partly readable.

  • Whether health, insurance, education, gaming or mapping regulators have issued any data location or transfer rule

    We found no health rule about where data must sit on official sites, checked 18 August 2026. The health ministry's website was unreachable from our network. If you work in health, check before you rely on this.

  • Whether any prosecution has been brought under the criminal provisions of the privacy law

    We could not confirm whether any court cases have been brought under this law. Ethiopian court decisions are not systematically published online. So finding no reported cases does not mean there are none.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.