The legal framework
Protection rests on the Data Protection Act 2012, administered by the Data Protection Commission, which requires data controllers to register. Registration of data controllers is a distinctive feature, and enforcement has focused on unregistered processing. These statutes follow the familiar pattern: lawful basis, purpose limitation, security, and rights of access, correction and objection.
Key points
| Rights | Access, correction, objection, and erasure under the more recent statutes |
|---|---|
| Registration | Data controllers must often register with the regulator |
| Breach notification | Required under most of these Acts |
| Cross-border transfers | Permitted subject to adequacy or safeguards |
| Regulator | Data Protection Commission of Ghana |
| Sectoral rules | Telecommunications and financial regulators impose additional confidentiality duties |
| Offences | Unlawful processing and failure to register are offences |
| Right to prevent processing | Where it causes damage or distress |
| Enforcement capacity | Limited, with registration the main focus |
In practice
- Write to the organisation first, citing the relevant statutory right; keep proof of the date.
- Set out clearly what you want: a copy of your data, deletion, or an end to marketing.
- If there is no adequate reply within the statutory period, complain to the regulator — it is free.
- For dating, health and fertility apps, ask specifically about third-party sharing and overseas transfers.
- Ask whether the organisation is registered: unregistered processing is itself unlawful.
- Complain to the Commission in writing with the dates and evidence.
Cost and coverage
Complaints to the regulator are free.
Recent changes
Digital lending applications that harvest contact lists have become the most common subject of enforcement across the region, alongside unsolicited marketing.
Where to go
- Data Protection Commission of Ghana — complaints and guidance.
- Telecommunications regulator for mobile and SMS abuse.
- Consumer protection body for related commercial disputes.
Worth knowing
Where a foreign platform is involved, the GDPR often applies in parallel if the company operates in Europe. Complaining in both places at once is legitimate and frequently faster. Checking the register is a quick and effective first move: many organisations processing personal data have never registered, which is an offence in itself.
Official sources and links
- Ghana.gov — official government portal
