Skip to the content
Global Data RulesData governance rules, country by country

Ghana

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.

The answer

Depends on your industryWork: MediumEnforcement: Waking up

Ghana's main privacy law does not stop personal data leaving the country. You simply tell the regulator, when you register, which countries you send data to. The real work is elsewhere: you must be on the public register before you touch anyone's data, you must report a cyber incident within 24 hours, and banks and payment firms need the central bank's permission before moving to the cloud.

Data governance in Ghana

The eight things that decide how you handle data about people in Ghana. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law reaches a company with no office in Ghana in two ways: if it uses equipment or a supplier in Ghana to process the data, or if the information came from Ghana in the first place. There is no size or revenue threshold, so a two-person startup is caught exactly like a bank. A foreign company that is caught must also register locally as an external company, which in practice means having a Ghanaian address and named representatives.

High confidenceNational rulesRegister or notifyAppoint a local representative

Where the data is allowed to live

In general, yes, and with no paperwork. Ghana's privacy law contains no rule stopping personal data going abroad and no list of approved or banned countries. But three pockets override that. Money: banks, payment firms and other lenders may only keep data in countries the central bank has approved, and need its permission before moving to the cloud. Surveillance kit: if you are ordered to install interception equipment, that equipment must stay in Ghana. Government: state bodies are pushed onto the national cloud and national data centre.

High confidenceDepends on your industryNo restriction

Sending data out of the country

Under the general law, nothing. There is no standard contract to sign, no government permission to seek, and no list of approved destinations. The only thing you must do is name the countries you send data to when you register, and keep that entry accurate. If you are a bank, a payment firm or a lender, that freedom disappears and you need the central bank's approval instead.

High confidenceNo restrictionNothing requiredGovernment sign-off needed

The regulator, and whether it actually acts

Two very different regulators. The Data Protection Commission exists, is staffed and has an Executive Director, and it runs the public register, training and accreditation - but we found no published fines or decisions against any named company. The Cyber Security Authority is the one with teeth: it licenses cybersecurity firms, publicly warns that unlicensed practice is illegal, and works on live criminal investigations. The Bank of Ghana enforces its own rules on the firms it licenses.

Medium confidenceWaking upRegulator

How long you must keep it — and when to delete it

There is a floor and a ceiling, and they point in opposite directions. The privacy law says delete personal data once you no longer need it, and destroy it so it cannot be pieced back together. The cybersecurity law says a service provider must keep customer account information for at least six years, and connection and content records for twelve months. Where a law tells you to keep something, the privacy law's delete duty gives way.

High confidenceDelete data after a periodKeep data for a minimum periodKeep logs

If something goes wrong

Count three clocks, not one. Any organisation must report a cyber incident to the national or its sector response team within 24 hours of detecting it. Separately, if personal data has been accessed by someone who should not have it, you must tell the privacy regulator and the affected people as soon as reasonably practicable - no fixed hours, which sounds softer but is harder to defend. Critical infrastructure operators carry a third duty: report weaknesses found in a security test within 72 hours.

High confidenceReport cyber incidentsReport breaches to the regulatorTell affected people

What catches people out

Five things that catch people out. You may not process personal data at all until you are on the register, so the paperwork is a gate, not a formality. Penalties are criminal, with prison terms, rather than European-style fines. Selling cybersecurity services in Ghana needs a licence from the cybersecurity regulator. If you are told to install interception equipment, it must stay in Ghana, and the chief executive and finance chief can personally be treated as having committed the offence. And the retention duty for service providers is written widely enough to reach cloud and hosting firms.

High confidenceRegister or notifyCriminal liabilityAppoint a data protection officerKeep the data in the countryChildren's data

What's changing next

One big thing is coming: a new Data Protection Bill. The regulator published a draft in November 2025 and asked for comments. If passed in its current shape it would be a sharp turn - some categories of data would have to stay in Ghana, and sending personal data abroad would need the person's written consent plus, for large-scale transfers, the regulator's approval. As of today the draft has not been laid before Parliament, so nothing in it binds anyone yet.

Medium confidenceProposedA copy must stay

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Telecoms

Cybersecurity Act, 2020 - sections 76 and 77

Act of parliament · Act 1038

In forceNo — it stays put

The one genuine in-country requirement in Ghanaian law: lawful-interception equipment must sit in Ghana and may not be remotely maintained from abroad, with the offence attributed personally to named senior officers. The same part of the Act sets hard retention floors of six years for subscriber information and twelve months for traffic and content data.

In force since 29 December 2020

Enforced by Cyber Security Authority

Transfer model: Not allowed

High confidence

Directive for the Protection of Critical Information Infrastructure

Government rules · Issued under sections 35 to 40 and 92 of Act 1038; designated sectors set by Gazette Notice No. 132

In forceYes — store it anywhere

Thirteen sectors are designated critical - from banking and health to water, mining and food - and their operators carry extra security, audit and reporting duties, including 24 hours to report an incident and 72 hours to disclose a vulnerability. The directive imposes no storage-location rule.

In force since 1 October 2021

Enforced by Cyber Security Authority

Transfer model: No restriction · Accepted routes: Nothing required

High confidence
Finance

Cyber and Information Security Directive

Regulator directive · Issued under section 4 of the Bank of Ghana Act 2002, section 92(1) of Act 930 and section 84 of Act 1032

In forceYes, with paperwork

The rule that actually bites in Ghanaian financial services. Banks, payment firms, lenders, credit bureaux, foreign exchange businesses and virtual asset providers need the Bank of Ghana's prior approval to move to cloud services, and their data may only sit in jurisdictions the Bank of Ghana has approved. There is no published list of approved jurisdictions, so this operates as case-by-case supervisory permission.

In force since 1 March 2026

Enforced by Bank of Ghana

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed, Security review needed

High confidence

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Data Protection Act, 2012

Act of parliament · Act 843

In forceYes — store it anywhere

Ghana's general privacy law. It is permissive about sending data abroad - there is no transfer restriction at all - but it makes registration with the Commission a precondition for processing any personal data, and it backs its duties with criminal penalties including imprisonment rather than large administrative fines.

In force since 16 October 2012

Enforced by Data Protection Commission

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Licensing of Cybersecurity Service Providers and accreditation of Cybersecurity Establishments and Professionals

Licence condition · Cybersecurity Act, 2020 (Act 1038), sections 49 to 59

In forceYes — store it anywhere

Selling cybersecurity services in Ghana for money requires a licence from the Cyber Security Authority, and the individuals doing the work must be separately accredited. Licensing started on 1 March 2023 and the Authority says it is actively enforcing it, which catches foreign consultancies that assume a professional-services engagement needs no local permission.

In force since 1 March 2023

Enforced by Cyber Security Authority

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Data Protection Bill, 2025 (draft published for public comment, November 2025)

Draft law

ProposedA copy must stay

A draft bill published by the Commission for comment in November 2025 that would turn Ghana from one of the most open transfer regimes in the region into a consent-plus-approval one, with hard localisation for identity, children's, biometric, health and genetic data. It has no legal effect: it had not been laid before Parliament when we checked on 18 August 2026.

Enforced by Data Protection Commission

Transfer model: Approval each time · Accepted routes: Government sign-off needed, Explicit consent, Standard contract clauses, Approved group rules

Medium confidence

Who you would hear from

  • Data Protection Commission of Ghana

    General personal data protection, the public register of controllers and processors, accreditation of practitioners

    Staffed and functioning: it has an Executive Director (Dr Arnold Kavaarpuo as at January 2026), operates an online registration and compliance system, publishes a fee schedule approved by Parliament and runs awareness campaigns. However, we found no published enforcement decision, fine or prosecution against a named organisation on the Commission's own site as at 18 August 2026. Its practical leverage is registration, which the Bank of Ghana treats as a licensing precondition for fintech applicants.

  • Cybersecurity regulation, critical information infrastructure, national computer emergency response team, licensing of cybersecurity service providers

    Clearly active. Licensing of cybersecurity service providers has run since 1 March 2023 and the acting Director-General publicly states it is being enforced; the Authority publishes advisories, ran regional and international events through 2026, opened regional offices, and reported in June 2026 that its intelligence led to an arrest in an international cyber fraud case.

  • Banks, deposit-taking institutions, development finance institutions, payment service providers, credit bureaux, foreign exchange businesses and virtual asset service providers

    Fully operational and the most demanding supervisor for data questions in practice. It issued a completely new Cyber and Information Security Directive in March 2026 and gates cloud adoption through prior approval.

  • Telecommunications licensing and regulation

    Operational and publishing consultations through 2026. We found no data localisation or cross-border transfer rule in its published material.

  • Government information technology standards, the government cloud and the Ghana National Data Centre, licensing of information technology service providers

    Operational. Runs G-Cloud and the Ghana National Data Centre for public sector agencies and publishes standards binding on ministries, departments and agencies.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The current cash value of a 'penalty unit' in Ghana

    Both the Data Protection Act and the Cybersecurity Act express fines in penalty units defined by separate legislation. We could not open an official current text of that legislation, or confirm whether the value has been revised, so all money figures in this record are left in penalty units rather than converted.

  • Whether the Data Protection Bill, 2025 has since been laid before Parliament

    The Parliament of Ghana bills listing we checked on 18 August 2026 is rendered dynamically and we could only read the most recent page reliably. No Data Protection Bill appeared, but we cannot prove it is absent from every page.

  • Whether the Data Protection Commission has issued any enforcement decision, fine or prosecution

    The Commission's own news section carried only a handful of items, none announcing an outcome. Absence of publication is not proof that nothing has happened; enforcement under this Act runs through the criminal courts, whose decisions we did not search.

  • Whether any localisation or transfer rule exists for health records, insurance, securities, education, gambling or mapping data

    No rule found, checked 18 August 2026. The Gaming Commission's published licence conditions do not mention server location. We were unable to reach machine-readable rulebooks for the insurance and securities regulators, so this is a negative asserted at medium confidence, not a verified absence.

  • Whether government agencies are legally barred from hosting data outside Ghana

    The National Information Technology Agency provides a government cloud and a national data centre and describes the cloud as hosting sensitive citizen data, but we did not find a binding instrument prohibiting foreign hosting. Treat this as procurement practice.

  • The practical scope of the six-year and twelve-month retention duties in the Cybersecurity Act

    The Act's definition of 'service provider' is wide enough on its face to cover cloud and hosting businesses, but the duty sits in a chapter about lawful interception and we found no regulator guidance confirming how widely it is applied.

  • Whether the National Communications Authority imposes data location conditions through telecom licences

    Licence conditions are not published in full on the Authority's site. No localisation rule found in the public material, checked 18 August 2026.

  • The exact adoption date of the Bank of Ghana Cyber and Information Security Directive

    The document is dated March 2026 on its cover and was launched with speeches by the Governor and First Deputy Governor, but we could not find a day-precise issue date, so the first of the month is used as an approximation.

60-day cadence. Two things can move quickly: the draft Data Protection Bill, which would reverse the open transfer position, and the Bank of Ghana's unpublished set of approved jurisdictions, which is a supervisory decision rather than a published rule and can change without consultation.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Ghana versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.