Law / Ethiopia

Personal Data Protection Proclamation

Proclamation No. 1321/2024 (Federal Negarit Gazette), arts. 1-3, 6-8, 12-17, 33-42 and 45-52

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 24 July 2024.

A comprehensive regime rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Have a lawful basis for processing personal data before collecting, storing, or otherwise processing it, whether by automated means or in a filing system.
  • Register with the Ethiopian Communications Authority before processing personal data, and appoint a data protection officer where the Proclamation requires one.
  • Take consent only where it is free, informed, specific and clear and requires an active action from the data subject, request it separately from other terms rather than bundled with them, let the data subject withdraw it at any time, and be able to prove it was given.
  • Implement appropriate technical and organizational measures against unauthorized or unlawful processing and against accidental loss, destruction or damage, including pseudonymization and encryption, the ability to restore access to personal data after a physical or technical incident, and a process for regularly testing their effectiveness.
  • Maintain a record, including logs, of all processing operations under your responsibility, covering the purposes, the categories of data subjects, personal data and recipients, any transfers to another country and their safeguards, and make it available to the Authority on request.
  • Carry out a data protection impact assessment before processing that may risk data subjects' rights and freedoms, including systematic and extensive evaluation based on automated processing, large-scale processing of sensitive personal data, and systematic monitoring of a publicly accessible area on a large scale.
  • Obtain the Authority's prior authorization where you cannot provide appropriate safeguards for a transfer to a third-party jurisdiction, and consult the Authority before processing where an impact assessment indicates the operations are likely to present a high risk.
  • Destroy personal data as soon as is reasonably practicable once the purpose for storing it has lapsed, in a manner that prevents its reconstruction in an intelligible form, and tell any data processor holding the data to do the same.

What it reaches

Obligation class

Consent, Security, Retention, Governance, DPIA

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 3 applies the Proclamation to processing personal data wholly or partly by automated means, and to other processing where the data form part of a filing system, by a data controller or data processor established in Ethiopia or using equipment in Ethiopia and represented there; it reaches private and public institutions of the federal and regional governments alike, and its exceptions are exhaustive, covering only an individual's purely personal or household activity, need-to-know exchange between government agencies, restricted application, and data merely transiting Ethiopia.

Article 7 bars processing unless one of the listed conditions is met, beginning with the data subject's consent and running through contractual necessity, a legal obligation, vital interests, a public health crisis or national emergency, and legitimate interests that the data subject's fundamental rights do not override.

Article 8 requires consent to be free, informed, specific and clear, to be requested separately from other terms rather than bundled with them, and to be withdrawable at any time, with the burden of proving consent on the data controller.

Articles 12 to 15 carry the fairness, transparency, purpose-limitation, accuracy and storage-limitation principles, and articles 16 and 17 require appropriate technical and organizational measures against unauthorized or unlawful processing and against accidental loss, destruction or damage, including pseudonymization and encryption, the ability to restore access after a physical or technical incident, and regular testing of those measures.

Article 33 makes registration with the Authority a precondition of processing personal data, articles 34 to 39 govern refusal, effects, change, removal and cancellation of that registration, and article 40 requires a data protection officer where processing is carried out by a government body, where core activities require regular and systematic monitoring of data subjects on a large scale, or where core activities involve large-scale processing of sensitive personal data.

Article 46 requires a record, including logs, of all processing operations, article 47 requires a data protection impact assessment before processing that may risk data subjects' rights and freedoms, article 48 requires prior authorization from or consultation with the Authority in the cases it lists, article 49 requires data protection by design and by default, and article 50 requires personal data to be destroyed as soon as is reasonably practicable once the purpose for storing it has lapsed, in a manner that prevents reconstruction.

Article 70 enters the Proclamation into force on the date of its publication in the Negarit Gazeta, and it was signed at Addis Abeba on the 24th day of July 2024, so these provisions bind today.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach

Read the law

Personal Data Protection Proclamation No. 1321/2024, full English text (MetaAppz Ethiopian Federal Laws reference)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app