Law / Ghana

Ghana

12 of 15 named instruments researched to a stage, across four of the six areas of law we track: 12 in force. As of 19 September 2026.

When they take effect7 of 12 carry a date, 5 do not. Earlier is before 2014.
Before 2014: 3 instruments (3 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 4 instruments (4 in force) ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 5
  3. Scraping law 3
  4. Cybersecurity law 3
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law5 instruments, 5 in force

Research summary (232 words)

Ghana's comprehensive personal-data statute is the Data Protection Act, 2012 (Act 843), which binds the Republic and every private data controller or processor established in Ghana, or using equipment or a processor in Ghana, and is enforced by the Data Protection Commission.

The Act now files as five provision-scoped instruments: the omnibus regime (registration, security measures, and exemptions), special personal data, the rights of data subjects, notification of security compromises, and enforcement, offences and penalties.

Processing special personal data, including an individual's DNA, health, ethnic origin, religious belief, political opinion, or sexual life, is prohibited unless a listed exception applies, and a data subject has a right to demand that a decision significantly affecting them is not based solely on automated processing.

A data controller must notify both the Commission and the data subject of unauthorized access to personal data as soon as reasonably practicable, and the Act sets no adequacy test or other substantive condition on transferring personal data outside Ghana, though a registering data controller must disclose the countries to which it may transfer data.

The Ministry of Communication, Digital Technology and Innovations announced in March 2026 that a new Data Protection Bill and a separate Emerging Technologies Bill are being developed to address artificial intelligence, automated decision-making, and cross-border data flows, and to provide structured oversight of AI systems and digital platforms, but neither has been tabled in Parliament.

Breach notification

Data Protection Act, notification of security compromises

Data Protection Act, 2012 (Act 843), s. 31 (notification of security compromises)Data Protection Act, 2012 (Act 843), full gazetted text (National Information Technology Agency, Internet Archive copy)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived May 23, 2026. Publisher's page: https://nita.gov.gh/wp-content/uploads/2017/12/Data-Protection-Act-2012-Act-843.pdf

In force. Binds public and private bodies.

What this law does

Section 31(1) requires a data controller, or a third party processing data under its authority, to notify the Data Protection Commission and the affected data subject where there are reasonable grounds to believe personal data has been accessed or acquired by an unauthorised person. Section 31(2) requires that notification to be made as soon as reasonably practicable after discovery of the unauthorised access or acquisition.

Section 31(3) requires the data controller to take steps to restore the integrity of the information system. Section 31(4) lets the data controller delay notifying the data subject where a security agency or the Commission says notification would impede a criminal investigation.

Section 31(5) lets the notification to a data subject be made by registered mail, electronic mail, prominent placement on the responsible party's website, publication in the media, or another manner the Commission directs. Section 31(6) and (7) require the notification to give the data subject enough information to take protective measures, including the identity of the unauthorised person if it is known to the data controller.

Section 31(8) lets the Commission direct the data controller to publicise the compromise where publicity would protect an affected data subject.

What it requires

Comprehensive regime

Data Protection Act

Data Protection Act, 2012 (Act 843), ss. 1-30, 45-74 and 82-94Data Protection Act, 2012 (Act 843), full gazetted text (National Information Technology Agency, Internet Archive copy)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived May 23, 2026. Publisher's page: https://nita.gov.gh/wp-content/uploads/2017/12/Data-Protection-Act-2012-Act-843.pdf

In force. Binds public and private bodies.

What this law does

The Data Protection Act, 2012 (Act 843) is administered by the Data Protection Commission, an independent statutory body it establishes. A data controller or processor established in Ghana, or using equipment or a processor in Ghana, must have a lawful basis before processing personal data, and section 27 requires it to register with the Commission before processing begins.

Section 27(2) requires a data controller collecting personal data to tell the data subject the nature of the data, the purpose of collection, the recipients, and whether supplying the data is mandatory or discretionary. Sections 28 to 30 require appropriate, reasonable technical and organisational measures to secure personal data against loss, damage, or unlawful access, and require a data processor acting for a data controller to maintain the same measures under a written contract.

Sections 45 to 59 establish the Data Protection Register and govern an application for registration, its refusal, grant, renewal, removal, and cancellation, and section 47(1)(g) requires an applicant to disclose the countries to which it may transfer the data it holds. Sections 60 to 74 exempt processing carried out for national security, crime and taxation, health, education and social work, regulatory activity, journalism, and research, among other listed purposes.

Section 82 bars a person providing goods, facilities, or services to the public from requiring a person to supply a particular record as a condition of that provision, and section 83 bars demanding a record of a person's physical or mental health or condition. The Act binds the Republic itself, treating each government department as a data controller. The Act was gazetted on 18 May 2012. Its commencement was left to a date the Minister specifies by notice in the Gazette. The Act came into force in October 2012.

What it requires

Data subject rights

Data Protection Act, rights of data subjects

Data Protection Act, 2012 (Act 843), ss. 32-36 and 39-44 (rights of data subjects)Data Protection Act, 2012 (Act 843), full gazetted text (National Information Technology Agency, Internet Archive copy)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived May 23, 2026. Publisher's page: https://nita.gov.gh/wp-content/uploads/2017/12/Data-Protection-Act-2012-Act-843.pdf

In force. Binds public and private bodies.

What this law does

Section 35 gives a data subject the right to be told the personal data a data controller holds about them, the purpose of processing, the recipients, and the source of the data, communicated in an intelligible form. Section 35(10) requires a data controller to comply with an access request promptly and in any event within forty days of receiving it.

Section 33 gives a data subject the right to have inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or unlawfully obtained personal data corrected or deleted, and requires the data controller to tell every person the data was disclosed to of the correction. Section 39 lets an individual require a data controller to cease or not begin processing personal data that causes or is likely to cause them unwarranted damage or distress.

Section 40 bars a data controller from using a data subject's personal data for direct marketing without their prior written consent, and lets the data subject object to direct marketing at any time. Section 41 gives a data subject the right to demand that a decision significantly affecting them is not based solely on automated processing of their personal data.

Despite the absence of a prior notice, section 41(2) entitles the data subject to require reconsideration of such a decision within twenty-one days after receipt of the notification from the data controller. Section 42 gives a data subject the right to require the rectification, blocking, erasure, or destruction of exempt manual data that is inaccurate or incomplete.

Section 44 lets the Commission order a data controller to rectify, block, erase, or destroy personal data on a data subject's complaint that it is inaccurate. Section 36 applies these rights to a credit bureau acting as a data controller, letting a data subject limit an information request to their financial standing and history for the twelve months before the request.

What it requires

Enforcement supervision

Data Protection Act, enforcement, offences and penalties

Data Protection Act, 2012 (Act 843), ss. 43, 75-81, 88-89 and 95 (enforcement, offences and penalties)Data Protection Act, 2012 (Act 843), full gazetted text (National Information Technology Agency, Internet Archive copy)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived May 23, 2026. Publisher's page: https://nita.gov.gh/wp-content/uploads/2017/12/Data-Protection-Act-2012-Act-843.pdf

In force. Binds public and private bodies.

What this law does

Section 75 lets the Commission serve a data controller who has contravened or is contravening a data protection principle with an enforcement notice requiring it to take or refrain from taking specified steps within a stated time, or to stop processing specified personal data. Section 76 lets the Commission cancel or vary an enforcement notice on its own motion or on the application of the person it was served on.

Section 77 lets a person affected by processing request the Commission to assess whether it complies with the Act, and section 78 lets the Commission make a formal determination that processing is inconsistent with the Act. Section 80 makes it an offence, carrying a fine of not more than one hundred and fifty penalty units or imprisonment of not more than one year or both, to fail to comply with an enforcement notice or an information notice, or to make a false statement in response to one.

Section 43 entitles an individual who suffers damage or distress through a data controller's contravention of the Act to compensation from that data controller, subject to the defence that the data controller took reasonable care to comply. Section 88 bars a person from purchasing, knowingly obtaining, or knowingly or recklessly disclosing another person's personal data, and section 89 bars selling or offering to sell personal data.

Section 95 sets the residual penalty for an offence under the Act with no penalty otherwise specified at a fine of not more than five thousand penalty units or imprisonment of not more than ten years, or both.

What it requires

Sensitive categories

Data Protection Act, special personal data

Data Protection Act, 2012 (Act 843), ss. 37-38 (special personal data)Data Protection Act, 2012 (Act 843), full gazetted text (National Information Technology Agency, Internet Archive copy)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived May 23, 2026. Publisher's page: https://nita.gov.gh/wp-content/uploads/2017/12/Data-Protection-Act-2012-Act-843.pdf

In force. Binds public and private bodies.

What this law does

Section 37(1) prohibits processing personal data relating to a child under parental control, or to an individual's religious or philosophical beliefs, ethnic origin, race, trade union membership, political opinions, health, sexual life, or criminal behaviour, unless the Act otherwise provides.

Section 37(2) permits a data controller to process special personal data only where the processing is necessary or the data subject consents, and section 37(3) treats processing as necessary where it exercises or performs a right or obligation the law imposes on an employer. Section 37(4) permits processing without consent only to protect the vital interests of a data subject who cannot give it, cannot reasonably be expected to give it, or has unreasonably withheld it.

Section 37(5) permits processing for the legitimate activities of a non-profit political, philosophical, religious, or trade union body, limited to its own members and never disclosed to a third party without the data subject's consent. Section 37(8) bars processing special personal data about race or ethnic origin unless it is necessary to identify and eliminate discriminatory practices and is carried out with appropriate safeguards for the data subject's rights and freedoms.

Section 38 exempts a spiritual or religious organisation, or an institution founded on religious or philosophical principles, from the prohibition on processing data about religious or philosophical belief where the processing concerns its own members, employees, or persons belonging to it.

What it requires

Scraping law3 instruments, 3 in force

Research summary (272 words)

Ghana's general computer-misuse authority is the Electronic Transactions Act, 2008 (Act 772), which punishes knowingly and without authority causing a computer to perform any function to secure access to a programme or electronic record, with no carve-out for a publicly accessible, unauthenticated page; a person who accesses a protected computer holding financial, government, or national-security information without authorization faces the Act's highest tier.

The Cybersecurity Act, 2020 (Act 1038) adds a narrower offence, retrieving subscriber information or intercepting traffic or content data without lawful authority, which binds a person dealing in communications data rather than a general web crawler. No statute or reported case addresses terms-of-service enforceability, or whether login or acceptance of terms changes the legal picture; this is unsettled rather than a specific regime.

Copyright protects a database only as a compilation, never through a separate sui generis right: the Copyright Act, 2005 (Act 690) protects a collection such as an encyclopedia, dictionary, or database, whether in machine-readable form, only where the collection is original by reason of the selection or arrangement of its contents, and its personal-use exception expressly does not extend to reproducing the whole or a substantial part of a database in digital form.

The Data Protection Act, 2012 (Act 843) reaches scraped public personal data: its definition of personal data carries no exemption for publicly available information, so a scrape of a public page that captures personal data about an identifiable individual still needs a lawful basis and registration under that Act.

No specific unfair-competition or misappropriation doctrine addresses scraping, and no case law or regulatory statement gives robots.txt legal weight or addresses AI-training-specific access rules.

Computer misuse

Cybersecurity Act, Unlawful Access

Cybersecurity Act, 2020 (Act 1038), s. 94 (Unlawful Access)Cybersecurity Act, 2020 (Act 1038), full text (csdsafrica.org)

In force since 29 December 2020. Binds public and private bodies.

What this law does

Section 94 punishes a person who, without lawful authority, retrieves subscriber information or intercepts traffic data or content data. This offence is narrower than the Electronic Transactions Act's general unauthorized-access offences: it binds a person dealing in communications data held by or passing through a service provider, rather than a general web crawler collecting data from public pages it does not own.

The Act also imposes retention and cooperation duties on a service provider, and creates a licensing regime for cybersecurity service providers, enforced by the Cyber Security Authority.

What it requires

Electronic Transactions Act, Cyber Offences

Electronic Transactions Act, 2008 (Act 772), ss. 124, 130-134 (Cyber Offences)Electronic Transactions Act, 2008 (Act 772), full text (Business Registration and Regulation registry)

In force since 19 December 2008. Binds public and private bodies.

What this law does

Section 124 punishes a person who intentionally accesses or intercepts an electronic record without authority or permission. Section 130 punishes a person who knowingly and without authority causes a computer to perform any function to secure access to a programme or electronic record held in that computer or any other computer, and section 131 punishes an unauthorized modification of a programme or electronic record.

Section 133 creates an aggravated offence, whoever knowingly accesses a computer without authorisation or exceeds authorised access to a protected computer, one holding information from a financial institution, a government department, a national-security matter, or otherwise designated protected, and carries the Act's highest tier. Section 134 punishes intentionally causing a computer to cease to function, including by virus or worm.

None of these provisions exempts a publicly accessible, unauthenticated page from the definition of unauthorized access, which the Act defines as access a person is neither personally entitled to nor has been given consent to obtain.

What it requires

Cybersecurity law3 instruments, 3 in force

Research summary (641 words)

Ghana's cyber-resilience law sits in the Cybersecurity Act, 2020 (Act 1038), assented to on 29 December 2020, which establishes the Cyber Security Authority (the Authority) and gives it standards-setting, licensing and enforcement powers over private and public actors alike.

Section 47(5) places a general duty on the person in charge of any institution, public or private, with no size or sector gate, to report a cybersecurity incident to the relevant Sectoral or National Computer Emergency Response Team within twenty-four hours of its detection, backed by an administrative penalty under section 47(6); a licensed cybersecurity service provider carries a further periodic operations report under section 47(2).

Section 49 separately requires a person to hold an Authority-issued licence before providing a cybersecurity service, a term the First Schedule defines broadly enough to reach a vendor who designs, sells, imports, exports, installs, maintains, repairs or services a cybersecurity solution, so a company distributing security software for reward in Ghana needs the licence even if it performs none of the Schedule's other listed activities such as penetration testing or incident response.

Section 59 gives the Authority a broader standards mandate, to develop, adopt, publish and enforce cybersecurity standards covering education, hardware and software engineering, governance and risk management and research and development, against the public and private sectors generally, with an administrative penalty for breach; the specific content of an adopted standard is set by the Authority outside the Act's own text, so what a software engineering standard would require of a developer is not stated here.

A narrower duty runs to the owner of a computer system the Minister designates a critical information infrastructure under section 35: a twenty-four-hour incident report, an audit and a copy of the audit report to the Authority under section 39.

That designation is a government act directed at a named system rather than a status a business declares of itself, so it is recorded here rather than raised against a guess, the same treatment this profile gives Singapore's Cybersecurity Act critical information infrastructure owners and South Korea's Act on the Protection of Information and Communications Infrastructure.

Section 40's offence of securing or attempting to secure unauthorised access to a critical information infrastructure, and section 94's separate offence of unlawfully retrieving subscriber information or intercepting traffic or content data, both bind the intruder rather than the operator and stay with the scraping topic's existing Ghana row.

The Electronic Transactions Act, 2008 (Act 772) carries an older, narrower critical-database designation regime of its own (sections 55 to 62) and a licensing regime for a certifying agency issuing digital signatures (sections 28 to 45), whose procedures duty in section 45 binds only a person already licensed as a certifying agency; neither reaches a business by a size, sector or product test broader than that narrow licensed class, so neither is filed here.

The Data Protection Act, 2012 (Act 843) carries its own security measures and security-compromise notification duties at sections 28 to 31, addressed to a data controller and processor as such; that is Ghana's privacy row rather than repeated here, the same architecture as General Data Protection Regulation (GDPR) Article 32.

Whether the Bank of Ghana maintains a binding cybersecurity or technology-risk directive for banks and specialised deposit-taking institutions is not confirmed in the primary text read for this row; in any case a Bank of Ghana-regulated financial institution is a status this corpus's activity vocabulary cannot express, so such a directive would be deferred rather than flagged even once located.

Every fine in Act 1038 is denominated in penalty units under Ghana's general Fines (Penalty Units) Act framework rather than stated as a cedi amount on the face of the Act, and the current cedi value of one penalty unit is not confirmed in the primary text read for this row, so the amounts below are stated in penalty units rather than converted.

Sector security regimes

Cybersecurity Act, Licensing of Cybersecurity Service Providers

Cybersecurity Act, 2020 (Act 1038), ss. 49-53, First Schedule, and Second Schedule items 49(2) and 51(5)Cybersecurity Act, 2020 (Act 1038), full text (Centre for Democracy and Development, csdsafrica.org)

In force since 29 December 2020. Binds public and private bodies.

What this law does

A person may not provide a cybersecurity service in Ghana without a licence issued by the Cyber Security Authority. The First Schedule defines a cybersecurity service as one provided for reward and aimed at ensuring or safeguarding the cybersecurity of a computer or computer system.

Its list runs from penetration testing, forensic examination, incident response and threat hunting through to designing, selling, importing, exporting, installing, maintaining, repairing or servicing a cybersecurity solution, so a vendor distributing a security software product for reward in Ghana falls within the licensing duty even without performing any of the Schedule's other listed services.

A granted licence runs for two years and must be renewed at least one month before expiry, may not be transferred, and may not be used for a purpose other than the one for which it was granted. Providing a cybersecurity service without a licence carries an administrative penalty equal to the cost of the damage caused and the value of the financial gain made rather than a fixed sum, while transferring a granted licence is a separate criminal offence.

What it requires

Security baseline statutes

Cybersecurity Act, Cybersecurity Standards and Enforcement

Cybersecurity Act, 2020 (Act 1038), s. 59, and Second Schedule item 59(4)Cybersecurity Act, 2020 (Act 1038), full text (Centre for Democracy and Development, csdsafrica.org)

In force since 29 December 2020. Binds public and private bodies.

What this law does

The Cyber Security Authority must develop, establish and adopt standards for cybersecurity covering education and skills development, hardware and software engineering, governance and risk management, research and development, and any other area it determines in line with international best practice. It must publish them on its website, and take the necessary measures to enforce them and monitor compliance by the public and private sectors.

A person who breaches an adopted standard is liable to an administrative penalty of not less than two hundred and fifty penalty units and not more than twenty-five thousand penalty units, payable to the Authority.

The Act names no size or sector gate for this duty and states no criminal penalty for a breach; the specific technical content of a standard the Authority adopts under this section, including whatever it requires of hardware and software engineering, is set outside the Act's own text and is not described here.

What it requires

Vulnerability and incident reporting

Cybersecurity Act, Duty to Report Cybersecurity Incident

Cybersecurity Act, 2020 (Act 1038), ss. 47(2) and 47(5)-(6), and Second Schedule item 47(6)Cybersecurity Act, 2020 (Act 1038), full text (Centre for Democracy and Development, csdsafrica.org)

In force since 29 December 2020. Binds public and private bodies.

What this law does

The person in charge of any institution, public or private, must report a cybersecurity incident to the relevant Sectoral Computer Emergency Response Team, or to the National Computer Emergency Response Team where no Sectoral team covers that institution, within twenty-four hours after the incident is detected.

A cybersecurity service provider licensed by the Cyber Security Authority carries a further duty to submit a periodic report on its own operations, including any cybersecurity incident, within a period the Authority determines. Failing to report within the twenty-four-hour window is an administrative penalty of not less than two hundred and fifty penalty units and not more than five thousand penalty units, payable to the Authority, rather than a criminal offence.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (206 words)

Ghana has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the general copyright framework of the Copyright Act, 2005 (Act 690) is the only law reaching an aggregator's reproduction of news content.

Its quotation provision permits including, with an indication of the source and the name of the author, quotations from a work in another work, including quotations from articles in newspapers or periodicals in the form of press summaries, subject to a fair-practice and extent-justified test; the provision carries no headline-length or short-extract cap and no restriction to the press industry, and no reported Ghanaian decision applies it to a systematic news aggregator as opposed to an individual quoting a published work.

Neighbouring rights under the Act protect performers and broadcasting organisations, not print or online news publishers, so there is no publisher-side neighbouring right of the kind the European Union's Digital Single Market Directive Article 15 creates. No statute or case law addresses whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer, and no hot-news or misappropriation doctrine distinct from ordinary copyright law exists.

The Act predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.