Data Protection Act
Data Protection Act, 2012 (Act 843), ss. 1-30, 45-74 and 82-94
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Have a lawful basis for processing personal data, and register with the Data Protection Commission before processing begins.
- Tell a data subject, before or as soon as practicable after collecting their personal data, the nature of the data, your identity, the purpose of collection, the recipients, and whether supplying the data is mandatory or discretionary.
- Take appropriate, reasonable technical and organisational measures to secure personal data against loss, damage, unauthorised destruction, and unlawful access, and require a data processor acting on your behalf to maintain the same measures under a written contract.
- When registering as a data controller, disclose the countries to which personal data may be transferred.
- Do not require a person to supply or produce a particular record, including a health record, as a condition of providing them goods, facilities, or services, unless the requirement is authorised by law or is in the public interest.
What it reaches
Obligation class
Consent, Licensing, Security, Disclosure, Access restriction
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Data Protection Act, 2012 (Act 843) is administered by the Data Protection Commission, an independent statutory body it establishes. A data controller or processor established in Ghana, or using equipment or a processor in Ghana, must have a lawful basis before processing personal data, and section 27 requires it to register with the Commission before processing begins.
Section 27(2) requires a data controller collecting personal data to tell the data subject the nature of the data, the purpose of collection, the recipients, and whether supplying the data is mandatory or discretionary. Sections 28 to 30 require appropriate, reasonable technical and organisational measures to secure personal data against loss, damage, or unlawful access, and require a data processor acting for a data controller to maintain the same measures under a written contract.
Sections 45 to 59 establish the Data Protection Register and govern an application for registration, its refusal, grant, renewal, removal, and cancellation, and section 47(1)(g) requires an applicant to disclose the countries to which it may transfer the data it holds. Sections 60 to 74 exempt processing carried out for national security, crime and taxation, health, education and social work, regulatory activity, journalism, and research, among other listed purposes.
Section 82 bars a person providing goods, facilities, or services to the public from requiring a person to supply a particular record as a condition of that provision, and section 83 bars demanding a record of a person's physical or mental health or condition. The Act binds the Republic itself, treating each government department as a data controller. The Act was gazetted on 18 May 2012. Its commencement was left to a date the Minister specifies by notice in the Gazette. The Act came into force in October 2012.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreach
Read the law
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived May 23, 2026. Publisher's page: https://nita.gov.gh/wp-content/uploads/2017/12/Data-Protection-Act-2012-Act-843.pdfEvery line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.