Ghana
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
Ghana's main privacy law does not stop personal data leaving the country. You simply tell the regulator, when you register, which countries you send data to. The real work is elsewhere: you must be on the public register before you touch anyone's data, you must report a cyber incident within 24 hours, and banks and payment firms need the central bank's permission before moving to the cloud.
Data governance in Ghana
The eight things that decide how you handle data about people in Ghana. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law reaches a company with no office in Ghana in two ways: if it uses equipment or a supplier in Ghana to process the data, or if the information came from Ghana in the first place. There is no size or revenue threshold, so a two-person startup is caught exactly like a bank. A foreign company that is caught must also register locally as an external company, which in practice means having a Ghanaian address and named representatives.
Data Protection Act, 2012 (Act 843) section 45(1) applies the Act where the controller is established in Ghana and processes there, or is not established in Ghana but uses equipment or a data processor carrying on business in Ghana, or where the processing concerns information originating partly or wholly from Ghana. Section 45(3) defines 'established' broadly, down to anyone maintaining an office, branch or agency through which business is carried out. Section 45(4) carves out data that merely transits Ghana. Section 45(2) requires a controller not incorporated in Ghana to register as an external company; the Commission's own registration guidance asks external entities for 'the name and address of the company's representatives'. Note there is no separate 'data protection representative' office as in Europe - the requirement is a corporate registration one.
Sources
- Official sourceData Protection Commission of GhanaData Protection Act, 2012 (Act 843), section 45 - application of the Act
dataprotection.org.gh
“the data controller is not established in this country but uses equipment or a data processor carrying on business in this country to process the data, or ... processing is in respect of information which originates partly or wholly from this country.”
Link checked 18 August 2026
- Official sourceData Protection Commission of GhanaData Protection Commission - Registration: who must register, including foreign companies
dataprotection.org.gh
“Foreign Companies - International businesses processing personal data within Ghana.”
Link checked 18 August 2026
Where the data is allowed to live
In general, yes, and with no paperwork. Ghana's privacy law contains no rule stopping personal data going abroad and no list of approved or banned countries. But three pockets override that. Money: banks, payment firms and other lenders may only keep data in countries the central bank has approved, and need its permission before moving to the cloud. Surveillance kit: if you are ordered to install interception equipment, that equipment must stay in Ghana. Government: state bodies are pushed onto the national cloud and national data centre.
SECTOR BY SECTOR, checked 18 August 2026. BANKING, PAYMENTS, LENDING, CREDIT REFERENCE, FOREIGN EXCHANGE AND VIRTUAL ASSET FIRMS - conditional. The Bank of Ghana's Cyber and Information Security Directive of March 2026 applies to institutions licensed under the Banks and Specialised Deposit-Taking Institutions Act 2016 (Act 930), the Development Finance Institutions Act 2020 (Act 1032), the Non-Bank Financial Institutions Act 2008 (Act 774), the Payment Systems and Services Act 2019 (Act 987), the Credit Reporting Act 2007 (Act 726), the Foreign Exchange Act 2006 (Act 732) and the Virtual Service Providers Act 2025 (Act 1154). It requires prior Bank of Ghana approval to move to cloud services, requires contracts with managed security providers to state that data must remain within jurisdictions approved by the Bank of Ghana, and requires cloud readiness checks to confirm approvals for cross-border transfers. It does not say the data must physically stay in Ghana. TELECOMS AND ONLINE SERVICE PROVIDERS - a narrow hard wall. Cybersecurity Act 2020 (Act 1038) section 76(5) forbids interception equipment being installed, managed or monitored in a foreign country, or remotely accessible from abroad for maintenance. GOVERNMENT - the National Information Technology Agency runs a government cloud and the Ghana National Data Centre for public sector agencies and describes the cloud as hosting sensitive citizen data; we did not find a binding instrument forbidding foreign hosting of government data, so treat this as procurement practice rather than law. HEALTH, INSURANCE, SECURITIES, EDUCATION, GAMBLING AND MAPPING - no localisation or transfer rule found, checked 18 August 2026, medium confidence. The Gaming Commission's published licence conditions turn on ownership and due diligence, not server location. CRITICAL INFRASTRUCTURE - thirteen sectors are designated critical, but the directive governing them imposes security and reporting duties, not storage location.
Sources
- Official sourceData Protection Commission of GhanaData Protection Act, 2012 (Act 843) - full text; contains no restriction on transferring personal data out of Ghana
dataprotection.org.gh
“the name or description of the country to which the appli- cant may transfer the data”
Link checked 18 August 2026
- Official sourceBank of GhanaBank of Ghana Cyber and Information Security Directive, March 2026 - cloud approval and approved jurisdictions
bog.gov.gh
“Unambiguous data ownership, data sovereignty (data must remain within jurisdictions approved by the Bank of Ghana), and secure data destruction clauses upon contract termination”
Link checked 18 August 2026
- Official sourceCyber Security AuthorityCybersecurity Act, 2020 (Act 1038), section 76(5) - interception equipment may not sit abroad
csa.gov.gh
“Equipment obtained for the purpose of the interception capability under this Act shall not be (a) installed, managed or monitored in a foreign country; or (b) in a form to enable the equipment to be remotely accessed from a foreign country for the purposes of maintenance.”
Link checked 18 August 2026
- Official sourceNational Information Technology AgencyNational Information Technology Agency - G-Cloud and Ghana National Data Centre for public sector agencies
nita.gov.gh
Link checked 18 August 2026
Sending data out of the country
Under the general law, nothing. There is no standard contract to sign, no government permission to seek, and no list of approved destinations. The only thing you must do is name the countries you send data to when you register, and keep that entry accurate. If you are a bank, a payment firm or a lender, that freedom disappears and you need the central bank's approval instead.
Ghana is best described as unrestricted at the national layer. There is no adequacy machinery, no standard contractual clauses and no binding corporate rules regime. The registration form under section 47(1)(g) of Act 843 asks for 'the name or description of the country to which the applicant may transfer the data', which makes the destination a disclosure item rather than a permission. Section 30(4) puts the burden on the Ghanaian controller: where a processor is not domiciled in Ghana, the controller must ensure the processor complies with Ghanaian law. Section 18(2) runs in the opposite direction and is often misread - it deals with data sent INTO Ghana for processing, and requires the Ghanaian processor to respect the foreign country's rules. In the regulated financial sector the model becomes case-by-case: prior Bank of Ghana approval to transition to cloud, and jurisdictions approved by the Bank of Ghana. The draft Data Protection Bill published for comment in November 2025 would replace all of this with a consent-plus-approval regime and some hard localisation; it is not law.
Sources
- Official sourceData Protection Commission of GhanaData Protection Act, 2012 (Act 843), sections 30 and 47 - processor abroad, and destination country declared at registration
dataprotection.org.gh
“Where a data processor is not domiciled in this country, the data controller shall ensure that the data processor complies with the relevant laws of this country.”
Link checked 18 August 2026
- Official sourceBank of GhanaBank of Ghana Cyber and Information Security Directive, March 2026 - prior approval to use cloud services
bog.gov.gh
“An RFI shall seek approval from BoG to transit to cloud services.”
Link checked 18 August 2026
- Official sourceData Protection Commission of GhanaData Protection Commission - Documents register, including the draft Data Protection Bill published for comment
dataprotection.org.gh
Link checked 18 August 2026
The regulator, and whether it actually acts
Two very different regulators. The Data Protection Commission exists, is staffed and has an Executive Director, and it runs the public register, training and accreditation - but we found no published fines or decisions against any named company. The Cyber Security Authority is the one with teeth: it licenses cybersecurity firms, publicly warns that unlicensed practice is illegal, and works on live criminal investigations. The Bank of Ghana enforces its own rules on the firms it licenses.
DATA PROTECTION COMMISSION - operational but quiet. Established by Act 843, based in Accra, Executive Director Dr Arnold Kavaarpuo as at the Commission's own January 2026 Data Protection Week launch. Its published output is registration, an amnesty for late registrants, compliance guidance, accreditation of practitioners and awareness campaigns. Its news page carried only a handful of items when checked on 18 August 2026 and none of them announced an enforcement outcome. Act 843 gives it enforcement notices and criminal offences rather than European-style administrative fines, so 'no published fine' is partly a design feature. Its real leverage is indirect: the Bank of Ghana asks fintech licence applicants for a Data Protection Certificate, so registration becomes a gate to doing business. CYBER SECURITY AUTHORITY - active. Licensing of cybersecurity service providers began 1 March 2023; the acting Director-General has publicly stated the Authority is 'actively enforcing its licensing and accreditation framework' and that only licensed providers and accredited professionals may operate. It publishes advisories, runs the national computer emergency response team, and reported in June 2026 that its intelligence led to an arrest in an international cyber fraud investigation. BANK OF GHANA - active, and the most demanding supervisor in practice. Overall rating: waking, because the privacy regulator specifically has not yet shown enforcement outcomes.
Sources
- Official sourceData Protection Commission of GhanaData Protection Commission launches Data Protection Week, 26 January 2026 - names the Executive Director and sets out the Commission's compliance agenda
dataprotection.org.gh
Link checked 18 August 2026
- Official sourceCyber Security AuthorityCyber Security Authority warns against unlicensed cybersecurity practice
csa.gov.gh
“we are committed to monitoring and ensuring full compliance with the law to protect critical information infrastructure and the interests of consumers.”
Link checked 18 August 2026
- Official sourceCyber Security AuthorityCyber Security Authority - licensing of cybersecurity service providers, commencement 1 March 2023
csa.gov.gh
Link checked 18 August 2026
- Official sourceBank of GhanaBank of Ghana - fintech licence requirements listing a Data Protection Certificate among required documents
bog.gov.gh
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a floor and a ceiling, and they point in opposite directions. The privacy law says delete personal data once you no longer need it, and destroy it so it cannot be pieced back together. The cybersecurity law says a service provider must keep customer account information for at least six years, and connection and content records for twelve months. Where a law tells you to keep something, the privacy law's delete duty gives way.
CEILING. Act 843 section 24(1) forbids retention longer than necessary for the purpose, unless retention is required or authorised by law, is reasonably necessary for a lawful purpose, is required by contract, or the person consents. Section 24(5) then requires destruction, deletion or de-identification at the end of the period, and section 24(6) requires destruction 'in a manner that prevents its reconstruction in an intelligible form' - which rules out simply marking a record inactive. FLOOR. Cybersecurity Act 2020 (Act 1038) section 77(1) requires a service provider to retain subscriber information for at least six years, traffic data for twelve months and relevant content data for twelve months, with the High Court able to extend the twelve-month periods on an ex parte application. The definition of 'service provider' in Act 1038 is wide enough on its face to include entities that process or store computer data on behalf of a communication service or its users, so cloud and hosting businesses should not assume this is a telecoms-only rule. In the regulated financial sector, the Bank of Ghana's March 2026 directive requires logs and audit trails from artificial intelligence and machine learning systems to be kept securely for at least seven years. CONFLICT RESOLUTION. The carve-out in section 24(1)(a) - 'required or authorised by law' - is what reconciles the two, so the statutory minimum wins.
Sources
- Official sourceData Protection Commission of GhanaData Protection Act, 2012 (Act 843), section 24 - retention limits and destruction
dataprotection.org.gh
“A data controller shall destroy or delete a record of personal data or de-identify the record at the expiry of the retention period.”
Link checked 18 August 2026
- Official sourceCyber Security AuthorityCybersecurity Act, 2020 (Act 1038), section 77 - retention of data by service providers
csa.gov.gh
“A service provider shall retain (a) subscriber information for at least six years; (b) traffic data for a period of twelve months; and (c) relevant content data for a period of twelve months.”
Link checked 18 August 2026
- Official sourceBank of GhanaBank of Ghana Cyber and Information Security Directive, March 2026 - seven-year audit trail retention for AI and machine learning systems
bog.gov.gh
“Logs and audit trails must be retained securely for a minimum period of seven (7) years, or longer if required by other regulations”
Link checked 18 August 2026
If something goes wrong
Count three clocks, not one. Any organisation must report a cyber incident to the national or its sector response team within 24 hours of detecting it. Separately, if personal data has been accessed by someone who should not have it, you must tell the privacy regulator and the affected people as soon as reasonably practicable - no fixed hours, which sounds softer but is harder to defend. Critical infrastructure operators carry a third duty: report weaknesses found in a security test within 72 hours.
CLOCK ONE, 24 hours. Cybersecurity Act 2020 (Act 1038) section 47(5) requires 'a person in charge of an institution' to report a cybersecurity incident to the relevant Sectoral Computer Emergency Response Team, or to the National Computer Emergency Response Team, within not more than 24 hours after detection. Failure attracts an administrative penalty under the Act's Second Schedule. Reporting routes are published by the Cyber Security Authority, including a short code and an incident form. CLOCK TWO, no fixed deadline. Act 843 section 31 requires notification to both the Data Protection Commission and the affected individual, 'as soon as reasonably practicable after the discovery of the unauthorised access or acquisition'. Notification to individuals may be delayed if the Commission or the security agencies say it would impede a criminal investigation. CLOCK THREE, 72 hours. The Cyber Security Authority's directive on critical information infrastructure requires designated owners to disclose vulnerabilities found in internal or external audits within 72 hours, and to report incidents within 24 hours. FOURTH, sector. Regulated financial institutions must notify the Bank of Ghana immediately for defined events, including customer information leaking outside the institution, plus a monthly incident report by the 15th and a nil return in a quiet month.
Sources
- Official sourceCyber Security AuthorityCybersecurity Act, 2020 (Act 1038), section 47(5) - 24-hour incident reporting by any institution
csa.gov.gh
“A person in charge of an institution shall report a cybersecurity incident to the relevant Sectoral Computer Emergency Response Team or the National Computer Emergency Response Team within a period of not more than twenty-four hours after the incident is detected.”
Link checked 18 August 2026
- Official sourceData Protection Commission of GhanaData Protection Act, 2012 (Act 843), section 31 - breach notification to the Commission and the individual
dataprotection.org.gh
“The notification shall be made as soon as reasonably practicable after the discovery of the unauthorised access or acquisition of the data.”
Link checked 18 August 2026
- Official sourceCyber Security AuthorityDirective for the Protection of Critical Information Infrastructure - 24-hour incident and 72-hour vulnerability reporting
csa.gov.gh
“Disclose and report any vulnerabilities identified or discovered through internal or external security audits and assessments, within 72 hours of identifying or discovering the vulnerability.”
Link checked 18 August 2026
- Official sourceBank of GhanaBank of Ghana Cyber and Information Security Directive, March 2026 - immediate notification triggers and monthly reporting
bog.gov.gh
“Sensitive information about bank customers has been exposed or leaked outside the bank.”
Link checked 18 August 2026
What catches people out
Five things that catch people out. You may not process personal data at all until you are on the register, so the paperwork is a gate, not a formality. Penalties are criminal, with prison terms, rather than European-style fines. Selling cybersecurity services in Ghana needs a licence from the cybersecurity regulator. If you are told to install interception equipment, it must stay in Ghana, and the chief executive and finance chief can personally be treated as having committed the offence. And the retention duty for service providers is written widely enough to reach cloud and hosting firms.
(1) REGISTRATION IS A PRECONDITION. Act 843 section 53 states plainly that an unregistered controller shall not process personal data. Registration is renewable every two years, and the Bank of Ghana asks fintech applicants for a Data Protection Certificate, so lapsing has commercial consequences well beyond the regulator. (2) CRIMINAL, NOT ADMINISTRATIVE. Act 843 penalties are expressed as penalty units and imprisonment on summary conviction - up to two years for failing to register, up to five years for unlawful disclosure or selling personal data, and a general penalty of up to ten years. Fines are set in 'penalty units' whose current cash value we could not confirm from an official source; historically the unit has been small, so the prison exposure and the reputational damage matter far more than the money. (3) CYBERSECURITY WORK NEEDS A LICENCE. Under Act 1038 anyone providing penetration testing, digital forensics, managed security services, cybersecurity governance and risk work, or cybersecurity training for reward needs a licence; licences last two years and cannot be transferred. The Authority says it is actively enforcing this. (4) PERSONAL LIABILITY FOR EQUIPMENT SITED ABROAD. Act 1038 section 76 forbids interception equipment being installed, managed or monitored abroad, and section 76(10) deems the chief executive, deputy chief executive, chief legal officer and the officer in charge of finance to have also committed the offence. (5) THE DATA PROTECTION SUPERVISOR MISMATCH. The Act says a controller 'may' appoint a certified data protection supervisor, while the Commission's compliance guidance tells medium and large controllers to appoint a full-time in-house supervisor. Treat the guidance as the operative expectation. (6) CHILDREN. Act 843 treats the data of 'a child who is under parental control in accordance with the law' as special personal data, but sets no numeric age of digital consent - so there is no equivalent of the European thirteen-to-sixteen band to design to.
Sources
- Official sourceData Protection Commission of GhanaData Protection Act, 2012 (Act 843), sections 53, 56, 58, 89 and 95 - registration gate, offences and the data protection supervisor
dataprotection.org.gh
“A data controller who has not been registered under this Act shall not process personal data.”
Link checked 18 August 2026
- Official sourceCyber Security AuthorityCybersecurity Act, 2020 (Act 1038), sections 49 to 53 and section 76 - licensing of cybersecurity service providers and personal liability of officers
csa.gov.gh
“The Chief Executive Officer, Deputy Chief Executive Officer, Chief Legal Officer or the officer-in-charge of finance for the service provider that commits an offence under subsection (9) shall be deemed to have also committed the offence.”
Link checked 18 August 2026
- Official sourceData Protection Commission of GhanaData Protection Commission - compliance guidance recommending a full-time in-house data protection supervisor for medium and large controllers
dataprotection.org.gh
Link checked 18 August 2026
- Official sourceCyber Security AuthorityCyber Security Authority - scope of licensable cybersecurity services
csa.gov.gh
Link checked 18 August 2026
What's changing next
One big thing is coming: a new Data Protection Bill. The regulator published a draft in November 2025 and asked for comments. If passed in its current shape it would be a sharp turn - some categories of data would have to stay in Ghana, and sending personal data abroad would need the person's written consent plus, for large-scale transfers, the regulator's approval. As of today the draft has not been laid before Parliament, so nothing in it binds anyone yet.
THE DRAFT BILL. Clause 96 of the Data Protection Bill, 2025 would require localisation for data critical to national defence, security and intelligence; data in national identity and civil registration systems including voter databases; and children's data, biometric data, health records and genetic data. Clause 96(4) would allow transfer abroad only with written, free, explicit and informed consent plus one of a short list of necessity grounds, and clause 96(4)(c) would require the regulator's authorisation where large-scale data is involved. Clause 97 would require regulator approval before processing special personal data outside Ghana, allow the regulator to prohibit or suspend a transfer, and require a transfer impact assessment for large-scale high-risk processing. Clause 96(1) also contains a general 'make reasonable efforts to localise' duty. We checked the Parliament of Ghana's list of bills laid on 18 August 2026 and found no Data Protection Bill, so this remains a consultation draft. DORMANT SWITCHES, which matter more than the bill. First, the Cyber Security Authority may issue a directive to a critical infrastructure owner 'without any notice' and the owner must comply. Second, the Bank of Ghana controls which jurisdictions financial data may sit in through approval, not through published rules, so the set of acceptable countries can change by supervisory letter. Third, the High Court can extend telecom and service provider content and traffic retention beyond twelve months on an application made without the provider present.
Sources
- Official sourceData Protection Commission of GhanaData Protection Bill, 2025 (draft published for public comment), clauses 96 and 97
dataprotection.org.gh
“There shall be no requirement for a data controller to localise personal data unless: (a) the personal data is critical to national defence, security and intelligence of the country; or (b) the personal data concern national identity ID systems and civil registration systems including voter databases (c) the personal data concerns children's data, biometric data, health records and genetic data.”
Link checked 18 August 2026
- Official sourceParliament of GhanaParliament of Ghana - list of bills laid, checked 18 August 2026; no Data Protection Bill listed
parliament.gh
Link checked 18 August 2026
- Official sourceCyber Security AuthorityDirective for the Protection of Critical Information Infrastructure - power to issue further directives without notice
csa.gov.gh
“The CSA may issue any additional directive to a designated CII Owner without any notice and a designated CII Owner shall comply.”
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Cybersecurity Act, 2020 - sections 76 and 77
Act of parliament · Act 1038
The one genuine in-country requirement in Ghanaian law: lawful-interception equipment must sit in Ghana and may not be remotely maintained from abroad, with the offence attributed personally to named senior officers. The same part of the Act sets hard retention floors of six years for subscriber information and twelve months for traffic and content data.
Enforced by Cyber Security Authority
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryApplies to lawful-interception equipment, not to customer data generally: the equipment may not be installed, managed or monitored in a foreign country, nor be remotely accessible from abroad for maintenance.
- Keep data for a minimum period — 6 yearsSubscriber information, at least six years.
- Keep data for a minimum period — 1 yearTraffic data and relevant content data. Extendable beyond twelve months by the High Court on an application made without the provider present.
- Appoint a local representativeA provider required to install interception capability must appoint a focal person, who is subject to security clearance by the National Security Co-ordinator.
What it costs if you get it wrong
- Criminal liability: 10,000 to 20,000 penalty unitsInterception equipment installed, managed or monitored abroad
- Criminal liability: Deemed liability of the chief executive, deputy chief executive, chief legal officer and finance officerSame offence, attributed to named officers unless they prove diligence
- Fixed maximum fine: 1,000 to 10,000 penalty unitsFailure to retain subscriber, traffic or content data for the statutory periods
Sources
- Official sourceCyber Security AuthorityCybersecurity Act, 2020 (Act 1038), sections 76 and 77
csa.gov.gh
“Equipment obtained for the purpose of the interception capability under this Act shall not be (a) installed, managed or monitored in a foreign country”
Link checked 18 August 2026
- Official sourceCyber Security AuthorityCybersecurity Act, 2020 (Act 1038), Second Schedule - table of administrative penalties for retention failures
csa.gov.gh
Link checked 18 August 2026
Directive for the Protection of Critical Information Infrastructure
Government rules · Issued under sections 35 to 40 and 92 of Act 1038; designated sectors set by Gazette Notice No. 132
Thirteen sectors are designated critical - from banking and health to water, mining and food - and their operators carry extra security, audit and reporting duties, including 24 hours to report an incident and 72 hours to disclose a vulnerability. The directive imposes no storage-location rule.
Enforced by Cyber Security Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — within 24 hoursTo the sector response team, or the national one if the sector has none.
- Secure the data
- Independent auditThe Authority may audit a designated operator, and audit reports and the risk register must be filed.
- Assess high-risk projectsRisk assessment and an annually reviewed board-approved cybersecurity policy.
- Appoint a data protection officerA senior accountable officer for cybersecurity governance.
- Hold a security certificateAdopt international standards approved by the Authority; keep source code of critical systems in escrow.
What it costs if you get it wrong
- Fixed maximum fine: 250 to 10,000 penalty unitsFailure to comply with a directive of the Authority
- Daily fine until fixed: 100 penalty units per dayContinuing failure to provide requested information
Sources
- Official sourceCyber Security AuthorityDirective for the Protection of Critical Information Infrastructure, in force 1 October 2021
csa.gov.gh
“Report all cybersecurity incidents to relevant Sectoral CERTs or in case of its non-existence, directly to the National Computer Emergency Response Team (CERT-GH) of the CSA within twenty-four (24) hours of becoming aware of an incident”
Link checked 18 August 2026
- Official sourceCyber Security AuthorityCybersecurity Act, 2020 (Act 1038), sections 35 to 40 - critical information infrastructure
csa.gov.gh
Link checked 18 August 2026
Cyber and Information Security Directive
Regulator directive · Issued under section 4 of the Bank of Ghana Act 2002, section 92(1) of Act 930 and section 84 of Act 1032
The rule that actually bites in Ghanaian financial services. Banks, payment firms, lenders, credit bureaux, foreign exchange businesses and virtual asset providers need the Bank of Ghana's prior approval to move to cloud services, and their data may only sit in jurisdictions the Bank of Ghana has approved. There is no published list of approved jurisdictions, so this operates as case-by-case supervisory permission.
Enforced by Bank of Ghana
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed, Security review needed
What it makes you do
- Put a transfer safeguard in placeData must remain within jurisdictions approved by the Bank of Ghana; cloud readiness checks must confirm approvals for cross-border transfers.
- Prove the data stays under local controlData sovereignty, ownership and destruction terms must be written into managed security and cloud contracts.
- Report cyber incidentsImmediate ad hoc notification for defined events including customer data leaking outside the institution, plus a monthly report by the 15th and a nil return if there was nothing.
- Keep logs — 7 yearsArtificial intelligence and machine learning audit trails.
- Written vendor contract
- Independent audit
- Hold a security certificateISO 27001, ISO 27017, ISO 27018, SOC 2 Type II, CSA STAR and PCI DSS where applicable.
- Appoint a data protection officerA chief information security officer, a board committee and a management committee meeting at least quarterly.
- Check your algorithmsExplainability, logging and governance duties for AI and machine learning systems.
What it costs if you get it wrong
- Order to stopNon-compliance attracts supervisory sanctions under the banking laws
- Loss of your licencePersistent non-compliance by a licensed institution
Sources
- Official sourceBank of GhanaBank of Ghana Cyber and Information Security Directive, March 2026
bog.gov.gh
“An RFI shall seek approval from BoG to transit to cloud services.”
Link checked 18 August 2026
- Official sourceBank of GhanaBank of Ghana - Cyber and Information Security Directive (2026), regulations and directives page
bog.gov.gh
Link checked 18 August 2026
- Official sourceBank of GhanaBank of Ghana - fintech licence requirements, including a Data Protection Certificate and ISO 27001 and PCI DSS expectations
bog.gov.gh
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Data Protection Act, 2012
Act of parliament · Act 843
Ghana's general privacy law. It is permissive about sending data abroad - there is no transfer restriction at all - but it makes registration with the Commission a precondition for processing any personal data, and it backs its duties with criminal penalties including imprisonment rather than large administrative fines.
Enforced by Data Protection Commission
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Register or notifyMandatory before any processing. Renewable every two years. A controller not incorporated in Ghana must also register as an external company.
- Tell people what you do
- Get consent
- Secure the data
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people object
- Report breaches to the regulatorAs soon as reasonably practicable. No fixed hour count in the Act.
- Tell affected peopleMay be delayed where the Commission or security agencies say it would impede a criminal investigation.
- Delete data after a periodDelete or de-identify at the end of the retention period, in a way that prevents reconstruction.
- Appoint a data protection officerThe Act says a controller 'may' appoint a certified data protection supervisor; the Commission's guidance tells medium and large controllers to appoint a full-time one.
- Written vendor contractWhere the processor is not domiciled in Ghana the controller must ensure it complies with Ghanaian law.
- Put a transfer safeguard in placeOnly a disclosure duty: destination countries are declared on the registration form.
What it costs if you get it wrong
- Criminal liability: 250 penalty units or 2 years imprisonment or bothProcessing without registration
- Criminal liability: 2,500 penalty units or 5 years imprisonment or bothUnlawful disclosure, or selling personal data
- Criminal liability: 5,000 penalty units or 10 years imprisonment or bothGeneral penalty where no other penalty is specified
- Criminal liability: 150 penalty units or 1 year imprisonment or bothFailing to comply with an enforcement or information notice
Sources
- Official sourceData Protection Commission of GhanaData Protection Act, 2012 (Act 843) - full text published by the Data Protection Commission
dataprotection.org.gh
“A data controller who has not been registered under this Act shall not process personal data.”
Link checked 18 August 2026
- Official sourceData Protection Commission of GhanaData Protection Commission - Documents register hosting the Act
dataprotection.org.gh
Link checked 18 August 2026
Licensing of Cybersecurity Service Providers and accreditation of Cybersecurity Establishments and Professionals
Licence condition · Cybersecurity Act, 2020 (Act 1038), sections 49 to 59
Selling cybersecurity services in Ghana for money requires a licence from the Cyber Security Authority, and the individuals doing the work must be separately accredited. Licensing started on 1 March 2023 and the Authority says it is actively enforcing it, which catches foreign consultancies that assume a professional-services engagement needs no local permission.
Enforced by Cyber Security Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Register or notify — from 1 March 2023Licence required to sell penetration testing, digital forensics, managed security services, cybersecurity governance and risk work, or cybersecurity training. Valid two years, non-transferable, renewal one month before expiry.
- Hold a security certificateIndividual practitioners are separately accredited as cybersecurity professionals.
What it costs if you get it wrong
- Criminal liability: 5,000 to 10,000 penalty units or 6 months to 2 years imprisonment or bothTransferring a licence
- Loss of your licenceUsing a licence for a purpose other than that granted
Sources
- Official sourceCyber Security AuthorityCyber Security Authority - licensing and accreditation, with commencement dates
csa.gov.gh
“A cybersecurity service is a service for reward that is intended primarily for or aimed at ensuring or safeguarding the cybersecurity of a computer or computer system belonging to a person”
Link checked 18 August 2026
- Official sourceCyber Security AuthorityCybersecurity Act, 2020 (Act 1038), sections 49 to 53 - licensing, duration and non-transferability
csa.gov.gh
“A licence granted under this Act is valid for two years from the date that the licence is granted.”
Link checked 18 August 2026
Data Protection Bill, 2025 (draft published for public comment, November 2025)
Draft law
A draft bill published by the Commission for comment in November 2025 that would turn Ghana from one of the most open transfer regimes in the region into a consent-plus-approval one, with hard localisation for identity, children's, biometric, health and genetic data. It has no legal effect: it had not been laid before Parliament when we checked on 18 August 2026.
Enforced by Data Protection Commission
Transfer model: Approval each time · Accepted routes: Government sign-off needed, Explicit consent, Standard contract clauses, Approved group rules
What it makes you do
- Keep the data in the countryPROPOSED ONLY. Would apply to national defence, security and intelligence data; national identity, civil registration and voter databases; and children's, biometric, health and genetic data.
- Put a transfer safeguard in placePROPOSED ONLY. Written explicit consent plus a necessity ground, and regulator authorisation for large-scale transfers.
- Assess high-risk projectsPROPOSED ONLY. A transfer impact assessment for large-scale high-risk processing.
Sources
- Official sourceData Protection Commission of GhanaData Protection Bill, 2025 - draft published by the Data Protection Commission for public comment
dataprotection.org.gh
“A data controller shall transfer personal data outside Ghana only if the following conditions are met: (a) the data subject has provided written, free, explicit and informed consent to the proposed transfer after being informed of the possible risks involved”
Link checked 18 August 2026
- Official sourceData Protection Commission of GhanaData Protection Commission - Documents page listing the draft bill and the comment submission format
dataprotection.org.gh
Link checked 18 August 2026
- Official sourceParliament of GhanaParliament of Ghana - bills laid before the House, checked 18 August 2026
parliament.gh
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The current cash value of a 'penalty unit' in Ghana
Both the Data Protection Act and the Cybersecurity Act express fines in penalty units defined by separate legislation. We could not open an official current text of that legislation, or confirm whether the value has been revised, so all money figures in this record are left in penalty units rather than converted.
Whether the Data Protection Bill, 2025 has since been laid before Parliament
The Parliament of Ghana bills listing we checked on 18 August 2026 is rendered dynamically and we could only read the most recent page reliably. No Data Protection Bill appeared, but we cannot prove it is absent from every page.
Whether the Data Protection Commission has issued any enforcement decision, fine or prosecution
The Commission's own news section carried only a handful of items, none announcing an outcome. Absence of publication is not proof that nothing has happened; enforcement under this Act runs through the criminal courts, whose decisions we did not search.
Whether any localisation or transfer rule exists for health records, insurance, securities, education, gambling or mapping data
No rule found, checked 18 August 2026. The Gaming Commission's published licence conditions do not mention server location. We were unable to reach machine-readable rulebooks for the insurance and securities regulators, so this is a negative asserted at medium confidence, not a verified absence.
Whether government agencies are legally barred from hosting data outside Ghana
The National Information Technology Agency provides a government cloud and a national data centre and describes the cloud as hosting sensitive citizen data, but we did not find a binding instrument prohibiting foreign hosting. Treat this as procurement practice.
The practical scope of the six-year and twelve-month retention duties in the Cybersecurity Act
The Act's definition of 'service provider' is wide enough on its face to cover cloud and hosting businesses, but the duty sits in a chapter about lawful interception and we found no regulator guidance confirming how widely it is applied.
Whether the National Communications Authority imposes data location conditions through telecom licences
Licence conditions are not published in full on the Authority's site. No localisation rule found in the public material, checked 18 August 2026.
The exact adoption date of the Bank of Ghana Cyber and Information Security Directive
The document is dated March 2026 on its cover and was launched with speeches by the Governor and First Deputy Governor, but we could not find a day-precise issue date, so the first of the month is used as an approximation.
60-day cadence. Two things can move quickly: the draft Data Protection Bill, which would reverse the open transfer position, and the Bank of Ghana's unpublished set of approved jurisdictions, which is a supervisory decision rather than a published rule and can change without consultation.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
Ghana versus
Compare