What Is Data Protection Act, 2012 (Act 843)?
Ghana’s operative statute is the Data Protection Act, 2012 (Act 843), assented to on 10 May 2012, published on 18 May 2012, and commenced on 16 October 2012. The Data Protection Commission remains the regulator, responsible for compliance monitoring, complaint investigation, fair determinations, and the Data Protection Register. The safest currentness description is that Act 843 remains current law according to DPC and Ministry sources, while the available official text is dated 18 May 2012 and is not confirmed as consolidated through 2026. No enacted amendment or replacement was located. A Data Protection Bill, 2025 is hosted by the DPC, but it is a bill proposing to repeal Act 843 and is not current law. Act 843 provides objection, access, correction, deletion, cessation of harmful processing, direct-marketing opt-out, automated-decision reconsideration, complaint, Commission-ordered correction or erasure, and compensation mechanisms. It also contains extensive exemptions and unusually direct criminal penalties, including imprisonment for selling or offering to sell personal data.
At a glance
- Full name
- Data Protection Act, 2012 (Act 843)
- Short code
- Act 843
- Jurisdiction
- Ghana
- Enacted
- 2012
- Last major update
- No enacted amendment or replacement was located; the available official text is dated 18 May 2012 and is not confirmed as consolidated through 2026. A Data Protection Bill, 2025 is a draft and not current law.
- Regulator
- Data Protection Commission
- Private right of action
- Yes
- Statutory citation
- Data Protection Act, 2012 (Act 843)
Scope, who Act 843 covers
Protected data
Data subject rights
Right to object to processing, unless otherwise legally provided
Right to receive collection information about purpose, controller, recipients, mandatory supply, consequences of refusal, and access and rectification rights
Right of access and correction
Right to rectification, deletion, or destruction of inaccurate, irrelevant, excessive, outdated, incomplete, misleading, unlawfully obtained, or no-longer-authorised data
Right to access data and source information, including decision logic for significant solely automated decisions
Credit-bureau access protections under the Credit Reporting Act
Right to cessation of harmful processing causing unwarranted damage or distress
Right to opt out of direct marketing, which requires prior written consent and can later be stopped
Right to reconsideration of significant solely automated decisions
Right to compensation subject to the controller’s reasonable-care defence
Right to seek Commission-ordered correction or erasure after a complaint
Notable features
Act 843 is notably criminal in tone compared with many privacy frameworks: specific offences carry penalty units and imprisonment, including a five-year maximum for selling or offering to sell personal data. Its extensive statutory exemptions and the unresolved question of whether the available official text is consolidated through 2026 are central to a cautious explanation.
Enforcement & penalties
Regulator: Data Protection Commission
Penalties: The Act uses criminal penalties, including imprisonment. False registration information may attract up to 150 penalty units, one year imprisonment, or both; failure to register and unauthorised assessable processing may attract up to 250 penalty units, two years imprisonment, or both; enforcement or information-notice non-compliance may attract up to 150 penalty units, one year imprisonment, or both; unlawful disclosure of confidential Commission information may attract up to 2,500 penalty units, five years imprisonment, or both. Purchasing, obtaining, or unlawfully disclosing personal data may attract up to 250 penalty units, two years imprisonment, or both. Selling or offering to sell personal data may attract up to 2,500 penalty units, five years imprisonment, or both. Unspecified-penalty offences may attract up to 5,000 penalty units, 10 years imprisonment, or both.
Private right of action: Section 43 provides a compensation right, subject to the controller’s reasonable-care defence. The Act also permits Commission-ordered correction or erasure after a complaint.
Relevance to data brokers
Not located. No Ghana-specific data-broker or public-record route was found; the general correction, deletion, and Data Protection Commission complaint routes are the only identified mechanisms. Sections 21(2)(a) and 25(3)(b) permit public-record-sourced indirect collection in specified circumstances, but that is not an unconditional permission for brokers.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Is Ghana’s Data Protection Bill, 2025 currently law?+
No. It is a bill or draft proposing to repeal Act 843, with commencement conditional on future Gazette publication. It must not be treated as current law.
How long does Ghana’s Data Protection Commission have to resolve a complaint?+
No fixed statutory complaint-resolution deadline was located in the reviewed Act 843 provisions or DPC materials. The DPC’s statement that it endeavors to answer general enquiries within 24 business hours is not a complaint-resolution deadline.
Does Ghana have a dedicated data-broker deletion route?+
Not located. The reviewed materials identify general correction and deletion rights and the DPC complaint process, but no Ghana-specific data-broker or public-record deletion mechanism.
Official sources & citations
Other international privacy regimes
Act 843 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
