Skip to the content
Global Data RulesData governance rules, country by country

Ghana

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Ghana — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: MediumEnforcement: Waking up

Ghana's main privacy law does not stop personal data leaving the country. You simply tell the regulator, when you register, which countries you send data to. The real work is elsewhere. You must be on the public register before you handle anyone's data. You must report a cyber incident within 24 hours. And banks and payment firms need the central bank's permission before moving to the cloud.

Data governance in Ghana

The eight things that decide how you handle data about people in Ghana. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law reaches a company with no office in Ghana in two ways. One, if it uses equipment or a supplier in Ghana to handle the data. Two, if the information came from Ghana in the first place. There is no size or revenue threshold. A two-person startup is caught exactly like a bank. A foreign company that is caught must also register locally as an external company. That means having a Ghanaian address and named representatives.

What you have to do here:
Register or notify · Appoint a representative

Where the data is allowed to live

In general, yes, and with no paperwork. Ghana's privacy law contains no rule stopping personal data going abroad. There is no list of approved or banned countries. But three pockets override that. Money: banks, payment firms and other lenders may only keep data in countries the central bank has approved. They also need its permission before moving to the cloud. Surveillance kit: if you are ordered to install interception equipment, that equipment must stay in Ghana. Government: state bodies are pushed onto the national cloud and national data centre.

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

Under the general law, nothing. There is no standard contract to sign, no government permission to seek, and no list of approved destinations. The only thing you must do is name the countries you send data to when you register, and keep that entry accurate. If you are a bank, a payment firm or a lender, that freedom disappears and you need the central bank's approval instead.

Ways to send data out:
Nothing required · Government sign-off needed

What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.

The regulator, and whether it actually acts

There are two very different regulators. The Data Protection Commission exists, is staffed and has an Executive Director. It runs the public register, training and accreditation. But we found no published fines or decisions against any named company. The Cyber Security Authority is the one that acts. It licenses cybersecurity firms. It publicly warns that unlicensed practice is illegal. It works on live criminal investigations. The Bank of Ghana enforces its own rules on the firms it licenses.

Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

You face minimum keeping times and a maximum, and they point in opposite directions. The privacy law says delete personal data once you no longer need it. You must destroy it so it cannot be pieced back together. The cybersecurity law says a service provider must keep customer account information for at least six years. It must keep connection and content records for twelve months. Where a law tells you to keep something, the privacy law's delete duty gives way.

What you have to do here:
Delete data after a period · Keep data for a minimum period · Keep logs

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

There are three clocks, not one. Any organisation must report a cyber incident within 24 hours of detecting it. You report to the national response team, or to your industry's response team. Separately, if someone who should not have your personal data has got at it, you must tell the privacy regulator and the affected people. That must happen as soon as reasonably practicable. There is no fixed number of hours, which sounds softer but is harder to defend. Critical infrastructure operators carry a third duty. They must report weaknesses found in a security test within 72 hours.

What you have to do here:
Report cyber incidents · Report breaches to the regulator · Tell affected people

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things catch people out. You may not handle personal data at all until you are on the register. The paperwork is a gate, not a formality. Penalties are criminal, with prison terms, rather than European-style fines. Selling cybersecurity services in Ghana needs a licence from the cybersecurity regulator. If you are told to install interception equipment, it must stay in Ghana. The chief executive and the finance chief can personally be treated as having committed that offence. And the duty on service providers to keep records is written widely enough to reach cloud and hosting firms.

What you have to do here:
Register or notify · Keep the data in the country
What it costs if you get it wrong:
Criminal liability

What's changing next

One big thing is coming: a new Data Protection Bill. The regulator published a draft in November 2025 and asked for comments. If it passes in its current shape, it would be a sharp turn. Some categories of data would have to stay in Ghana. Sending personal data abroad would need the person's written consent. Large-scale transfers would also need the regulator's approval. As of today the draft has not been laid before Parliament. So nothing in it binds anyone yet.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Telecoms

Cyber security rules

Official name: Cybersecurity Act, 2020 - sections 76 and 77 · Act 1038 · Act of parliament

In forceNo — it stays put

This is the one real must-stay-in-Ghana requirement in Ghanaian law. Lawful-interception equipment must sit in Ghana. It may not be maintained remotely from abroad. The offence is attributed personally to named senior officers. The same part of the Act sets minimum keeping times: six years for subscriber information, and twelve months for traffic and content data.

In force since 29 December 2020

Enforced by Cyber Security Authority

How this country controls where data goes: Not allowed

Banking rules

Official name: Directive for the Protection of Critical Information Infrastructure · Issued under sections 35 to 40 and 92 of Act 1038; designated sectors set by Gazette Notice No. 132 · Government rules

In forceYes — store it anywhere

Thirteen industries are designated critical, from banking and health to water, mining and food. Their operators carry extra security, audit and reporting duties. That includes 24 hours to report an incident and 72 hours to disclose a weakness. The directive sets no rule about where data must be stored.

In force since 1 October 2021

Enforced by Cyber Security Authority

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Finance

Cloud and outsourcing rules

Official name: Cyber and Information Security Directive · Issued under section 4 of the Bank of Ghana Act 2002, section 92(1) of Act 930 and section 84 of Act 1032 · Regulator directive

In forceYes, with paperwork

This is the rule that really matters in Ghanaian financial services. Banks, payment firms, lenders, credit bureaux, foreign exchange businesses and virtual asset providers need the Bank of Ghana's prior approval to move to cloud services. Their data may only sit in countries the Bank of Ghana has approved. There is no published list of approved countries. So this works as case-by-case supervisory permission.

In force since 1 March 2026

Enforced by Bank of Ghana

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed, Security review needed

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Rules for sending data abroad

Official name: Data Protection Act, 2012 · Act 843 · Act of parliament

In forceYes — store it anywhere

This is Ghana's general privacy law. It is relaxed about sending data abroad. There is no transfer restriction at all. But it makes registration with the Commission a precondition for handling any personal data. It backs its duties with criminal penalties, including prison, rather than large administrative fines.

In force since 16 October 2012

Enforced by Data Protection Commission

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Cyber security rules (2023)

Official name: Licensing of Cybersecurity Service Providers and accreditation of Cybersecurity Establishments and Professionals · Cybersecurity Act, 2020 (Act 1038), sections 49 to 59 · Licence condition

In forceYes — store it anywhere

Selling cybersecurity services in Ghana for money requires a licence from the Cyber Security Authority. The individuals doing the work must be separately accredited. Licensing started on 1 March 2023 and the Authority says it is actively enforcing it. This catches foreign consultancies that assume a professional-services job needs no local permission.

In force since 1 March 2023

Enforced by Cyber Security Authority

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Personal data needs a copy kept in the country

Official name: Data Protection Bill, 2025 (draft published for public comment, November 2025) · Draft law

ProposedA copy must stay

This is a draft bill the Commission published for comment in November 2025. It would turn Ghana from one of the most open countries in the region into a consent-plus-approval one. Identity, children's, biometric, health and genetic data would have to stay in Ghana. It has no legal effect. It had not been laid before Parliament when we checked on 18 August 2026.

Enforced by Data Protection Commission

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Explicit consent, Standard contract clauses, Approved group rules

Not fully verified — see “What we're not sure about” below.

Who you would hear from

  • Data Protection Commission of Ghana

    General personal data protection, the public register of controllers and processors, accreditation of practitioners

    Staffed and functioning. It has an Executive Director, Dr Arnold Kavaarpuo as at January 2026. It runs an online registration and compliance system. It publishes a fee schedule approved by Parliament and runs awareness campaigns. But we found no published enforcement decision, fine or prosecution against a named organisation on the Commission's own site as at 18 August 2026. Its practical leverage is registration. The Bank of Ghana treats that as a licensing precondition for fintech applicants.

  • Cybersecurity regulation, critical information infrastructure, national computer emergency response team, licensing of cybersecurity service providers

    Clearly active. Licensing of cybersecurity service providers has run since 1 March 2023. The acting Director-General publicly says it is being enforced. The Authority publishes advisories. It ran regional and international events through 2026 and opened regional offices. In June 2026 it reported that its intelligence led to an arrest in an international cyber fraud case.

  • Banks, deposit-taking institutions, development finance institutions, payment service providers, credit bureaux, foreign exchange businesses and virtual asset service providers

    Fully working, and the most demanding supervisor for data questions. It issued a completely new Cyber and Information Security Directive in March 2026. It controls cloud adoption through prior approval.

  • Telecommunications licensing and regulation

    Working, and publishing consultations through 2026. We found no rule in its published material about where data must be stored, or about sending data abroad.

  • Government information technology standards, the government cloud and the Ghana National Data Centre, licensing of information technology service providers

    Operational. Runs G-Cloud and the Ghana National Data Centre for public sector agencies and publishes standards binding on ministries, departments and agencies.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The current cash value of a 'penalty unit' in Ghana

    We could not confirm what a penalty unit is worth in cash. Both the Data Protection Act and the Cybersecurity Act express fines in penalty units defined by separate legislation. We could not open an official current text of that legislation, or confirm whether the value has been revised. So all money figures in this record stay in penalty units.

  • Whether the Data Protection Bill, 2025 has since been laid before Parliament

    We could not confirm that no Data Protection Bill has been laid. Parliament's list of bills is built dynamically and we could only read the most recent page reliably. No Data Protection Bill appeared there on 18 August 2026. But we cannot prove it is absent from every page.

  • Whether the Data Protection Commission has issued any enforcement decision, fine or prosecution

    We could not confirm whether the Commission has taken enforcement action. Its news section carried only a handful of items, and none announced an outcome. Enforcement under this Act runs through the criminal courts, and we did not search court decisions.

  • Whether any localisation or transfer rule exists for health records, insurance, securities, education, gambling or mapping data

    We found no such rule, checked 18 August 2026. The Gaming Commission's published licence conditions do not mention server location. We could not reach readable rulebooks for the insurance and securities regulators. Confidence medium. If you work in those industries, check before you rely on it.

  • Whether government agencies are legally barred from hosting data outside Ghana

    We could not confirm any binding rule here. The National Information Technology Agency provides a government cloud and a national data centre. It describes the cloud as hosting sensitive citizen data. But we found no binding law banning foreign hosting. Treat this as purchasing practice.

  • The practical scope of the six-year and twelve-month retention duties in the Cybersecurity Act

    We could not confirm how widely this duty is applied. The Act's definition of 'service provider' is wide on its face and could cover cloud and hosting businesses. But the duty sits in a chapter about lawful interception, and we found no regulator guidance on the point.

  • Whether the National Communications Authority imposes data location conditions through telecom licences

    We could not confirm the full licence conditions, because the Authority does not publish them in full. We found no rule in the public material about where data must be stored, checked 18 August 2026.

  • The exact adoption date of the Bank of Ghana Cyber and Information Security Directive

    We could not confirm the exact issue date. The document is dated March 2026 on its cover. It was launched with speeches by the Governor and First Deputy Governor. We found no day-precise date, so we use the first of the month as an approximation.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.