Ethiopia
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
Ethiopia's privacy law says personal data collected in the country must be kept on a server or in a data centre inside Ethiopia. A copy may go abroad, but usually only if the regulator first accepts that the destination protects data well enough. The law has been in force since July 2024. Almost nothing is being enforced: the regulator has published no rules and runs no register.
Data governance in Ethiopia
The eight things that decide how you handle data about people in Ethiopia. Same eight on every country page, so you can compare.
Who has to follow these rules
Only partly, and this is Ethiopia's oddest feature. The law covers any organisation set up in Ethiopia. A foreign company with no office is covered only if it uses equipment inside Ethiopia to process the data and has a representative based in Ethiopia. There is no size or revenue threshold. Read literally, a purely foreign online service with no kit and no representative in the country falls outside the law.
The scope test sits in Article 3(2) of Proclamation No. 1321/2024. Limb (b) is cumulative: 'It is not established in Ethiopia but uses equipment in Ethiopia for processing the data otherwise than for the purposes of transit through Ethiopia and has a representative established in Ethiopia.' That drafting makes the local representative a condition of being caught rather than an obligation imposed on those caught, which is the reverse of the European and Indian pattern. Do not plan around the gap: the government can close it by amendment, the criminal provisions bite on anyone in Ethiopia who sends data out unlawfully, and the separate Critical Infrastructure Cybersecurity Proclamation No. 1426/2026 is expressly extraterritorial, applying to designated Ethiopian critical infrastructure located outside the country and to anyone supplying cybersecurity products or services to it. Article 3(3) also confirms the law binds federal and regional government bodies and the Addis Ababa and Dire Dawa city administrations.
Sources
- Official sourceFederal Negarit Gazette / Ministry of Justice of EthiopiaPersonal Data Protection Proclamation No. 1321/2024, Article 3 (Scope of Application), Federal Negarit Gazette No. 35, 24 July 2024
justice.gov.et
“It is not established in Ethiopia but uses equipment in Ethiopia for processing the data otherwise than for the purposes of transit through Ethiopia and has a representative established in Ethiopia.”
Link checked 18 August 2026
- Official sourceInformation Network Security AdministrationCritical Infrastructure Cybersecurity Proclamation No. 1426/2026, Article 3 (Scope of Application), Federal Negarit Gazette No. 41, 21 July 2026
insa.gov.et
“This Proclamation shall apply to designated critical infrastructures of the country located within or outside the territory of Ethiopia, as well as to persons providing cybersecurity products or services.”
Link checked 18 August 2026
Where the data is allowed to live
A copy must stay in the country. Every organisation must keep personal data collected or obtained in Ethiopia on a server or in a data centre located in Ethiopia. A copy may then go abroad, but only in the situations the law allows. Data the law treats as sensitive needs the regulator's permission before it goes anywhere, and that category is wide: health, biometrics, race, religion, political views, criminal records, and the content and details of people's messages.
The duty is in Article 22, headed 'Data Sovereignty': every controller or processor 'shall ensure the storage, on a server or data center located in Ethiopia, of personal data collected or obtained locally'. There is no size threshold, no grace period and no exemption for cloud services. Article 22(2) hands the regulator a dormant switch: it is to designate categories of 'critical personal data' that may be processed only on a server or data centre in Ethiopia, on grounds of the strategic interests of the state. We found no such designation published as of 18 August 2026. Article 22(3) requires prior approval from the regulator for any cross-border transfer of sensitive personal data, and Article 2(5) defines sensitive data to include communications data, content and metadata. Sector by sector, checked 18 August 2026: - Telecoms: tighter. Under the SIM Card Registration Directive the regulator keeps a National Subscriber Registry on its own premises, and every operator must upload subscriber records to it within 72 hours. Communications content and metadata are sensitive data, so exporting them needs prior approval. - Commercial hosting: to store data in Ethiopia as a business you need a Data Center Service Provider licence or a Hosting Service Provider licence from the communications regulator. - Government: the national data centre and government cloud are run by the Ministry of Innovation and Technology and marketed on local data sovereignty. - Banking and payments: the central bank's information technology directive for banks requires a disaster recovery site detached from the main site, but we found no separate banking or payments localisation rule; the national rule applies anyway. - Securities: the capital market regulator's published directives cover offerings, dematerialisation and self-regulatory organisations; we found no data location rule. - Health, insurance, education, gaming and mapping: no separate location rule found on official sites, checked 18 August 2026. - Critical infrastructure: from July 2027 twelve sectors, including finance, health, energy and government services, pick up eighteen cybersecurity duties under a new proclamation.
Sources
- Official sourceFederal Negarit Gazette / Ministry of Justice of EthiopiaPersonal Data Protection Proclamation No. 1321/2024, Article 22 (Data Sovereignty)
justice.gov.et
“Every data controller or data processor shall ensure the storage, on a server or data center located in Ethiopia, of personal data collected or obtained locally.”
Link checked 18 August 2026
- Official sourceEthiopian Communications AuthoritySIM Card Registration Directive No. 799/2021, Articles 5 and 7 — National Subscriber Registry hosted on the Authority's premises
eca.et
“The Authority shall: a) Host the National Subscriber Registry in a secure location on its premise;”
Link checked 18 August 2026
- Official sourceEthiopian Communications AuthorityEthiopian Communications Authority — licence list including Data Center Service Provider and Hosting Service Provider licences
eca.et
Link checked 18 August 2026
- Official sourceMinistry of Innovation and TechnologyEthiopian National Data Center / government cloud, operated by the Ministry of Innovation and Technology
cloud.gov.et
Link checked 18 August 2026
- Official sourceEthiopian Capital Market AuthorityEthiopian Capital Market Authority — published proclamation, directives and guidelines (no data location rule found)
ecma.gov.et
Link checked 18 August 2026
Sending data out of the country
You need the regulator to bless the destination first. Before personal data leaves Ethiopia you must give the regulator evidence that the receiving country protects data properly, and the regulator must decide that it does. If it does not, the transfer is banned unless you fall into a narrow exception: the person's explicit and informed consent, or the transfer is genuinely necessary for a contract, a legal claim, an important public interest or to save a life. Nothing you sign with the recipient replaces that.
The chain runs Articles 18 to 22 of Proclamation No. 1321/2024. Article 18 allows transfer only where the destination 'ensures appropriate levels of protection'. Article 19(5) is blunt: transfer to a jurisdiction that does not ensure an appropriate level of protection 'is prohibited'. Article 19(3) lets the regulator authorise a limited transfer anyway, if the person consents and the data is cut down. Article 20 sets the four gateways. Article 21 lets the regulator demand proof that your safeguards work and prohibit or suspend a transfer. Article 22(3) adds prior approval for sensitive data. The model is case-by-case approval, not an approved-country list and not a standard contract. There is no Ethiopian equivalent of European standard contractual clauses or binding corporate rules, no certification scheme, and we found no published finding that any country is adequate — the list, in effect, is empty. That leaves a hard practical problem: the mechanism the law depends on does not yet exist in usable form, while sending data out without it is a criminal offence carrying five to ten years' imprisonment.
Sources
- Official sourceFederal Negarit Gazette / Ministry of Justice of EthiopiaPersonal Data Protection Proclamation No. 1321/2024, Articles 18-22 (transfer principle, level of protection, conditions, safeguards, data sovereignty)
justice.gov.et
“the transfer of personal data to a third-party jurisdiction that does not ensure appropriate level of protection is prohibited.”
Link checked 18 August 2026
- Official sourceEthiopian Communications AuthorityEthiopian Communications Authority — Resources page listing every law, regulation and directive it has published (no transfer directive, no adequacy list)
eca.et
Link checked 18 August 2026
The regulator, and whether it actually acts
The Ethiopian Communications Authority, the telecoms regulator, was handed the job. On its own website it says it registers and supervises data controllers, investigates complaints and issues directives. In practice we could find none of that happening. Two years after the law started, it has published no data protection directive, offers no way to register, and has announced no decisions or fines. The telecoms side of the same regulator is busy and effective, so this is a choice about priorities rather than an empty building.
Proclamation No. 1321/2024 defines 'Authority' as the Ethiopian Communications Authority, established under Communications Service Proclamation No. 1148/2019. The Authority's own about page states it 'serves as the national authority responsible for regulating and enforcing personal data protection in Ethiopia' and that it 'registers and supervises data controllers and processors'. Against that: its Resources page lists eleven telecoms directives from 2021 plus a fees directive, and under Laws it simply hosts a copy of the data protection proclamation, uploaded in October 2025; its Services page lists telecoms, postal and internet licences with no data controller registration; and its public notices in October and December 2025 concern interconnection offers by Ethio Telecom and Safaricom. Article 60(3) of the proclamation also says the detail of administrative offences and fines is to be set by a Council of Ministers regulation, and we found no such regulation, so the administrative fine machinery is not yet usable. The criminal offences in Article 64 do not depend on any regulation and are enforced by prosecutors and courts, not by the regulator. Other regulators are genuinely active in their own lanes: the National Bank of Ethiopia supervises bank technology risk, and the Information Network Security Administration publishes standards, controls technology imports and now administers the critical infrastructure regime.
Sources
- Official sourceEthiopian Communications AuthorityEthiopian Communications Authority — About page, data protection mandate
eca.et
“Under the Personal Data Protection Proclamation No. 1321/2024, the Ethiopian Communications Authority (ECA) also serves as the national authority responsible for regulating and enforcing personal data protection in Ethiopia.”
Link checked 18 August 2026
- Official sourceEthiopian Communications AuthorityEthiopian Communications Authority — Resources: laws, regulations and directives published to date
eca.et
Link checked 18 August 2026
- Official sourceEthiopian Communications AuthorityEthiopian Communications Authority — Services: licence types offered (no data controller registration)
eca.et
Link checked 18 August 2026
- Official sourceFederal Negarit Gazette / Ministry of Justice of EthiopiaPersonal Data Protection Proclamation No. 1321/2024, Article 2(36) and Article 60 (Administrative Sanctions)
justice.gov.et
“the details of administrative offences and fines shall be governed by regulation.”
Link checked 18 August 2026
How long you must keep it — and when to delete it
The ceiling is clear, the floor mostly is not. Once the reason for holding personal data has gone, you must destroy it as soon as you reasonably can, and in a way that stops anyone rebuilding it. The clearest minimum we could confirm is in telecoms: when a mobile line is switched off, the operator keeps that subscriber's records for three months. Ethiopia is also unusual in that a person's privacy rights survive them, and last for ten years after death.
Article 50 of Proclamation No. 1321/2024 imposes the duty to destroy, and requires deletion to be done so the record cannot be reconstructed in intelligible form; the controller must also tell every processor holding the data to do the same. Article 30 requires you to publish retention periods in your privacy notice. Article 23 keeps privacy rights alive for ten years after death, which affects deletion routines built for living users only. Article 46 leaves the retention period for access logs to be fixed by the regulator, and it has not fixed one, so log retention is currently undefined by law rather than unlimited. The SIM Card Registration Directive sets the three-month floor for deactivated subscribers. Ordinary commercial floors — tax, company and accounting records — almost certainly apply through Ethiopian tax and commercial law, but the Ministry of Revenue website would not serve to us during this run, so we do not assert a number.
Sources
- Official sourceFederal Negarit Gazette / Ministry of Justice of EthiopiaPersonal Data Protection Proclamation No. 1321/2024, Articles 23, 46 and 50 (duration of protection, logs, duty to destroy)
justice.gov.et
“where the purpose for storing personal data has lapsed, every data controller shall destroy the personal data as soon as is reasonably practicable.”
Link checked 18 August 2026
- Official sourceEthiopian Communications AuthoritySIM Card Registration Directive No. 799/2021, Article 20(4) — three-month retention after deactivation
eca.et
“the Telecommunications Operator shall retain the records of the relevant Subscriber for three (3) months;”
Link checked 18 August 2026
If something goes wrong
Count three clocks, soon to be four. Within 72 hours of learning of a personal data breach you must tell the regulator, and within 72 hours you must also tell the people affected — Ethiopia puts a hard deadline on telling individuals, where most countries only say 'promptly'. Banks have a separate two working day deadline to the central bank for serious technology incidents. From July 2027, organisations in twelve critical sectors get a 48 hour deadline to the national cyber emergency team. Failing to report a breach at all is a crime.
Articles 43 and 44 of Proclamation No. 1321/2024 set the two 72-hour clocks and list what the notification must contain; a late notification must explain the delay, and processors must tell their controller without undue delay. Directive No. SBB/83/2022 requires a bank to notify the National Bank's Banking Supervision Directorate within two working days of any information technology incident that could have significant impact. Critical Infrastructure Cybersecurity Proclamation No. 1426/2026 requires notification to the National Computer Emergency Response Centre within 48 hours; it was published on 21 July 2026 and takes effect one year later. Under Article 64(1) of the privacy law, not notifying a breach, or not taking technical and organisational measures once one has happened, is punishable by one to three years' simple imprisonment or a fine of 60,000 to 100,000 birr, roughly 375 to 625 US dollars, or both.
Sources
- Official sourceFederal Negarit Gazette / Ministry of Justice of EthiopiaPersonal Data Protection Proclamation No. 1321/2024, Articles 43 and 44 (notification of personal data breach)
justice.gov.et
“Where there is a personal data breach, the data controller shall within 72 hours after having become aware of it, notify the personal data breach to the Authority.”
Link checked 18 August 2026
- Official sourceNational Bank of EthiopiaDirective No. SBB/83/2022, Requirements for Information Technology Management of Banks — two working day incident notification
nbe.gov.et
“A bank shall notify Banking Supervision Directorate of the National Bank within 2 (two) working days any IT incidents that could have significant impact”
Link checked 18 August 2026
- Official sourceInformation Network Security AdministrationCritical Infrastructure Cybersecurity Proclamation No. 1426/2026, Article 8 — 48 hour incident notification
insa.gov.et
“To notify cybersecurity incidents the National Computer Emergency Response Center within 48 hours”
Link checked 18 August 2026
What catches people out
Five things that will ruin someone's week. First, you must be registered with the regulator before you process any personal data at all — but the regulator offers no way to register, so the duty cannot be met. Second, a child here is anyone under sixteen, not thirteen. Third, breaking the export rules is a crime punishable by five to ten years in prison, and prison does not need the missing fine regulation to work. Fourth, the content and details of people's messages count as sensitive data, so exporting communications records needs prior permission. Fifth, the servers, firewalls and security modules you would need to store data locally are on a government control list and need a security clearance permit before you can import or use them.
(1) Article 33 requires a data controller or processor to be registered with the Authority in order to process personal data, with a certificate valid for two years; the Authority's own services list contains no such registration, so every organisation in the country is technically in breach. (2) Article 2(15) defines a minor as a data subject below the age of sixteen; Article 12 requires parental or guardian consent and restricts marketing and profiling of minors. (3) Article 64(3) makes re-identifying de-identified data, selling personal data, or transferring personal data outside Ethiopia in violation of the proclamation punishable by five to ten years' rigorous imprisonment and a fine of 200,000 to 600,000 birr, roughly 1,250 to 3,750 US dollars. Where the offender is an institution, or the case involves sensitive data or a minor, Article 60(2) allows an administrative fine of up to 4 per cent of total worldwide turnover for the preceding financial year, and any gain made goes to the government. (4) Article 2(5)(i) puts 'communications data, including content and metadata' inside the sensitive category, which pulls telecoms, messaging and email providers into the prior-approval regime of Article 22(3); the Authority may also add new categories of sensitive data at any time. (5) The Information Technology Products Security Clearance and Control Proclamation No. 1310/2023 requires a security clearance permit to import, export or use listed products, and the Information Network Security Administration publishes both lists: the restricted list includes servers above 5.0 GHz, high performance computing systems, network switches at or above 1 Tbps, firewalls at or above 20 Gbps and hardware security modules; the prohibited list includes low-earth-orbit satellite internet terminals and digital forensic tools. Both lists are populated today.
Sources
- Official sourceFederal Negarit Gazette / Ministry of Justice of EthiopiaPersonal Data Protection Proclamation No. 1321/2024, Articles 2(5), 2(15), 33, 60 and 64
justice.gov.et
“In order to process personal data the data controller or the data processor shall be registered with the Authority.”
Link checked 18 August 2026
- Official sourceEthiopian Communications AuthorityEthiopian Communications Authority — Services page: no data controller or processor registration offered
eca.et
Link checked 18 August 2026
- Official sourceInformation Network Security AdministrationInformation Technology Products Security Clearance and Control Proclamation No. 1310/2023, Federal Negarit Gazette No. 18, 6 March 2024
insa.gov.et
Link checked 18 August 2026
- Official sourceInformation Network Security AdministrationAppendix 01 — Restricted Technology Product Lists (servers, firewalls, switches, hardware security modules)
insa.gov.et
Link checked 18 August 2026
- Official sourceInformation Network Security AdministrationAppendix 02 — Prohibited Technology Product Lists
insa.gov.et
Link checked 18 August 2026
What's changing next
One dated change and several switches that could flip without warning. The dated one: the Critical Infrastructure Cybersecurity Proclamation was published on 21 July 2026 and takes effect on 21 July 2027, giving twelve sectors — including finance, health, energy, transport and government services — eighteen security duties, a 48 hour incident deadline, and a licensing regime for anyone selling cybersecurity products or services into Ethiopia. The switches: the government has not yet issued the regulation that sets privacy fines, the regulator has issued no directives, and it can at any time name categories of data that may never leave the country.
Dated: Proclamation No. 1426/2026 was done at Addis Ababa on 21 July 2026 and enters into force one year after publication in the Federal Negarit Gazette, so 21 July 2027. During the grace period the Information Network Security Administration says it will issue implementing directives and standards. Suppliers of cybersecurity products or services will need a licence, security clearance, minimum capital and a permanent address in Ethiopia. Dormant switches, any of which can change the picture with no consultation: (1) the Council of Ministers regulation on administrative offences and fines under Article 60(3), which would switch on the 4 per cent turnover penalty machinery; (2) the Authority's power under Article 69(2) to issue directives, including the registration requirements every organisation is already supposed to satisfy; (3) Article 22(2), which requires the Authority to designate categories of 'critical personal data' processable only inside Ethiopia — an unbounded local-only category that does not exist yet; (4) Article 2(5)(j), letting the Authority declare any other data sensitive, which would drag it into the prior-approval regime; (5) Article 46, the unset retention period for access logs; and (6) the Information Network Security Administration's prohibited and restricted technology product lists, which are administrative documents it can revise at will.
Sources
- Official sourceInformation Network Security AdministrationCritical Infrastructure Cybersecurity Proclamation No. 1426/2026, Article 28 (Effective Date), Federal Negarit Gazette No. 41, 21 July 2026
insa.gov.et
“This Proclamation shall enter into force One year after its publication in the Federal Negarit Gazette.”
Link checked 18 August 2026
- Official sourceInformation Network Security AdministrationInformation Network Security Administration press briefing, 7 August 2026 — twelve sectors, eighteen obligations, 48 hour reporting, one-year grace period
insa.gov.et
Link checked 18 August 2026
- Official sourceFederal Negarit Gazette / Ministry of Justice of EthiopiaPersonal Data Protection Proclamation No. 1321/2024, Articles 22(2), 46, 60(3) and 69 (dormant powers)
justice.gov.et
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
SIM Card Registration Directive No. 799/2021
Government rules · Directive No. 799/2021
Every mobile subscriber's identity record, including biometric data where available, sits in a national registry held on the telecoms regulator's own premises, with operators uploading updates within 72 hours. In practice subscriber identity data cannot leave Ethiopia, and the communications data attached to it counts as sensitive under the privacy law.
Enforced by Ethiopian Communications Authority
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryThe National Subscriber Registry is hosted by the regulator on its own premises; operators must keep their own subscriber database and upload updates.
- Keep records of processing — within 72 hoursUpdated operator database must reach the Authority within 72 hours of registering a subscriber.
- Keep data for a minimum period — 3 monthsRecords of a deactivated subscriber kept for three months.
- Secure the dataAccess to subscriber information restricted unless requested by the Authority or ordered by a court.
What it costs if you get it wrong
- Loss of your licenceNon-compliance by a licensed telecommunications operator
Sources
- Official sourceEthiopian Communications AuthoritySIM Card Registration Directive No. 799/2021, Articles 5, 6, 7 and 20
eca.et
“The Authority shall establish and maintain a database of all registered Subscribers' information in a central database referred to as the “National Subscriber Registry.””
Link checked 18 August 2026
- Official sourceEthiopian Communications AuthorityEthiopian Communications Authority — Resources page listing Directive No. 799/2021
eca.et
Link checked 18 August 2026
Telecommunications Licensing Directive No. 792/2021
Licence condition · Directive No. 792/2021
Storing other people's data in Ethiopia as a business is a licensed activity. The telecoms regulator issues separate Data Center Service Provider and Hosting Service Provider licences, so the obvious way to satisfy the national storage rule — hiring local hosting — is itself gated by a licence.
Enforced by Ethiopian Communications Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Register or notifyA Data Center Service Provider licence or a Hosting Service Provider licence is needed to run a data centre or host third-party data commercially in Ethiopia. Internet service, internet exchange point and satellite terminal licences sit in the same directive.
What it costs if you get it wrong
- Loss of your licenceOperating an unlicensed data centre or hosting service
Sources
- Official sourceEthiopian Communications AuthorityTelecommunications Licensing Directive No. 792/2021, definitions of Data Center Service Provider Licence and Hosting Service Provider Licence
eca.et
““Data Center Service Provider License” means a License issued by the Authority”
Link checked 18 August 2026
- Official sourceEthiopian Communications AuthorityEthiopian Communications Authority — licence list
eca.et
Link checked 18 August 2026
Requirements for Information Technology (IT) Management of Banks, Directive No. SBB/83/2022
Regulator directive · Directive No. SBB/83/2022
The central bank's technology rulebook for banks. It requires a disaster recovery site detached from the main site, a customer data privacy policy, and notification of significant technology incidents within two working days. We found no banking or payments rule requiring data to stay in Ethiopia — the national privacy law supplies that on its own.
Enforced by National Bank of Ethiopia
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — within 48 hoursTwo working days to the National Bank's Banking Supervision Directorate for high-impact incidents, plus quarterly incident reports.
- Secure the dataBoard-approved information technology strategy, risk register updated quarterly, customer data privacy policy, vendor management.
- Independent auditDedicated information technology audit function inside internal audit.
- Written vendor contractThird party service providers who access confidential information are expressly in scope.
What it costs if you get it wrong
- Order to stopSupervisory action by the National Bank for non-compliance
Sources
- Official sourceNational Bank of EthiopiaDirective No. SBB/83/2022, Requirements for Information Technology Management of Banks
nbe.gov.et
“A bank shall set up or build a disaster recovery site that is maintained at safe place with adequate detachment from the main site of the IT systems.”
Link checked 18 August 2026
- Official sourceNational Bank of EthiopiaNational Bank of Ethiopia — directive record page
nbe.gov.et
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
የግል ዳታ ጥበቃ አዋጅ ቁጥር ፩ሺ፫፻፳፩/፪ሺ፲፮ — Personal Data Protection Proclamation No. 1321/2024
Act of parliament · Proclamation No. 1321/2024, Federal Negarit Gazette 30th Year No. 35
Ethiopia's general privacy law, in force since 24 July 2024 with no transition period. It requires personal data collected locally to be stored in Ethiopia, makes cross-border transfer conditional on the regulator accepting the destination, demands registration before any processing, and backs the whole thing with prison sentences rather than the usual administrative fines.
Enforced by Ethiopian Communications Authority
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, Important public interest, Someone's life is at risk
What it makes you do
- Keep the data in the countryPersonal data collected or obtained in Ethiopia must be stored on a server or in a data centre located in Ethiopia. No threshold, no transition period.
- Register or notifyRegistration with the Authority is required before processing any personal data; certificate valid two years. No registration channel exists in practice.
- Put a transfer safeguard in placeRegulator must accept the destination's level of protection; sensitive data needs prior approval.
- Get consent
- Tell people what you doMust state retention periods and any transfers to another country.
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people object
- Limit automated decisions
- Secure the data
- Report breaches to the regulator — within 72 hours
- Tell affected people — within 72 hoursHard 72-hour deadline to individuals, not the usual 'without undue delay'.
- Appoint a data protection officer — applies at: Government bodies; large-scale regular and systematic monitoring; large-scale sensitive dataContact details must be published and given to the Authority. A group may share one officer if each entity can reach them easily.
- Assess high-risk projectsRequired where processing is likely to risk people's rights and freedoms; prior consultation with the Authority in high-risk cases.
- Delete data after a periodDestroy as soon as reasonably practicable once the purpose has lapsed, in a way that prevents reconstruction.
- Get a parent's consent for children — applies at: under 16
- Written vendor contract
What it costs if you get it wrong
- Criminal liability: 5-10 years rigorous imprisonment and ETB 200,000-600,000 — about $4 thousandTransferring personal data outside Ethiopia in violation of the proclamation; selling personal data; re-identifying de-identified data
- Criminal liability: 3-5 years imprisonment and ETB 100,000-200,000 — about $1 thousandIgnoring erasure, objection, restriction or automated-decision rights
- Criminal liability: 1-3 years simple imprisonment or ETB 60,000-100,000 — about $622Failing to report a breach, failing to act on one, or processing contrary to the principles
- Percentage of global turnover: 4% of total worldwide turnover of the preceding financial yearOffence committed by an institution, or involving sensitive data or a minor. Detail left to a regulation that has not been issued.
Sources
- Official sourceFederal Negarit Gazette / Ministry of Justice of EthiopiaPersonal Data Protection Proclamation No. 1321/2024, full text, Federal Negarit Gazette No. 35, 24 July 2024
justice.gov.et
“Every data controller or data processor shall ensure the storage, on a server or data center located in Ethiopia, of personal data collected or obtained locally.”
Link checked 18 August 2026
- Official sourceMinistry of Justice of EthiopiaMinistry of Justice — Personal Data Protection Proclamation record page
justice.gov.et
Link checked 18 August 2026
- Official sourceEthiopian Communications AuthorityEthiopian Communications Authority — Resources page hosting the proclamation under Laws
eca.et
Link checked 18 August 2026
Critical Infrastructure Cybersecurity Protection Proclamation No. 1426/2026
Act of parliament · Proclamation No. 1426/2026, Federal Negarit Gazette No. 41, 21 July 2026
Passed on 10 June 2026 and published on 21 July 2026, this law does not take effect until 21 July 2027. It names twelve critical sectors, imposes eighteen security duties including a 48 hour incident deadline, reaches Ethiopian critical infrastructure located abroad, and licenses anyone selling cybersecurity products or services into the country.
Enforced by Information Network Security Administration
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — within 48 hours, from 21 July 2027To the National Computer Emergency Response Centre.
- Independent audit — from 21 July 2027Cybersecurity audit certification must be obtained and renewed, and findings acted on.
- Hold a security certificate — from 21 July 2027Security assurance required before deploying acquired information and communications technology systems.
- Register or notify — from 21 July 2027Cybersecurity product and service providers need a licence, security clearance, minimum capital and a permanent address in Ethiopia.
- Secure the data — from 21 July 2027Eighteen duties in total, including a security operations centre and supply chain security.
What it costs if you get it wrong
- Criminal liability: 7-10 years rigorous imprisonmentActs harming national security, public health or life through critical infrastructure
- Criminal liability: 3-5 years rigorous imprisonmentThe same acts committed negligently
Sources
- Official sourceInformation Network Security AdministrationCritical Infrastructure Cybersecurity Proclamation No. 1426/2026, full text
insa.gov.et
“This Proclamation shall enter into force One year after its publication in the Federal Negarit Gazette.”
Link checked 18 August 2026
- Official sourceInformation Network Security AdministrationInformation Network Security Administration statement, 7 August 2026
insa.gov.et
Link checked 18 August 2026
- Official sourceInformation Network Security AdministrationInformation Network Security Administration — documentation portal
insa.gov.et
Link checked 18 August 2026
Information Technology Products Security Clearance and Control Proclamation No. 1310/2023
Act of parliament · Proclamation No. 1310/2023, Federal Negarit Gazette No. 18, 6 March 2024
A permit regime for technology hardware that quietly shapes data storage. Both control lists are populated today: servers above 5.0 GHz, high performance computing, large firewalls and switches, and hardware security modules are restricted, while satellite internet terminals and forensic tools are prohibited outright. Building compliant local storage therefore needs a security clearance first.
Enforced by Information Network Security Administration
Transfer model: Allowlist · Accepted routes: Government sign-off needed
What it makes you do
- Register or notifySecurity clearance permit required to import, export or use a listed information technology product.
- Hold a security certificateProducts on the restricted list may be used only with clearance; products on the prohibited list not at all.
What it costs if you get it wrong
- Criminal liabilityImporting, exporting or using prohibited or restricted technology products without clearance
Sources
- Official sourceInformation Network Security AdministrationInformation Technology Products Security Clearance and Control Proclamation No. 1310/2023
insa.gov.et
Link checked 18 August 2026
- Official sourceInformation Network Security AdministrationAppendix 01 — Restricted Technology Product Lists
insa.gov.et
Link checked 18 August 2026
- Official sourceInformation Network Security AdministrationAppendix 02 — Prohibited Technology Product Lists
insa.gov.et
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
That no Council of Ministers regulation and no regulator directive under the Personal Data Protection Proclamation exists as of 18 August 2026
We checked the regulator's own Resources and Services pages and the Ministry of Justice information and communications technology law list. The Ministry of Justice search function and its machine-readable index both returned server errors during this run, so we cannot fully exclude a recent instrument published elsewhere.
That the regulator has published no finding that any destination country offers an adequate level of protection
No such list appears on the regulator's site. A determination could in principle be made privately, per transfer, without publication — that is how the law is drafted.
Whether the regulator has quietly opened any registration channel for data controllers and processors
Its Services page lists no such registration and its separate registration portal would not resolve to us. Absence of a public listing is strong but not conclusive.
The general commercial record-keeping floor — how many years tax, accounting and company records must be kept
The Ministry of Revenue website failed certificate validation throughout this run, so we could not read the Tax Administration Proclamation from an official source. Assume ordinary multi-year tax retention and verify locally.
Whether any payments or insurance directive of the National Bank imposes its own data localisation
The payment instrument issuer and payment system operator directives are published only as scanned images. We machine-read the 2023 payment instrument issuer directive and the 2025 amendment and found no location clause, but optical character recognition can miss text, and the 2020 payment system operators directive was only partly readable.
Whether health, insurance, education, gaming or mapping regulators have issued any data location or transfer rule
No rule found on official sites, checked 18 August 2026. The health ministry's website was unreachable through our network during this run.
Whether any prosecution has been brought under the criminal provisions of the privacy law
Ethiopian court decisions are not systematically published online, so an absence of reported cases is not evidence of an absence of cases.
60-day cadence. Ethiopia has several switches that can flip with one instrument and no consultation: the fines regulation, the first regulator directives, the designation of critical personal data that may never leave, and the technology control lists. The critical infrastructure regime also starts on 21 July 2027, with implementing directives expected before then.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
Ethiopia versus
Compare