Ghana’s push to strengthen data protection, cybersecurity and artificial intelligence governance risks creating overlapping regulatory systems unless authorities establish clearer institutional boundaries and coordination mechanisms, according to privacy professional Frank Bediako.
The country is entering a critical phase in its digital regulatory development as the government advances proposed changes to data protection and cybersecurity laws while expanding its approach to AI governance, Bediako wrote in an analysis titled “Ghana’s Digital Regulation Is Growing Up; Now It Needs to Grow Together.”
The central challenge is no longer whether Ghana should regulate its expanding digital economy, but whether the country is creating a coherent governance framework or multiple powerful regulators with potentially overlapping mandates, he argued.
Ghana already has a Data Protection Commission, the Cyber Security Authority and other sector regulators with responsibilities touching digital services. Proposed legislation could further expand their powers at a time when technologies such as artificial intelligence, cloud computing and automated decision-making increasingly cut across traditional regulatory boundaries.
Bediako said the overlap could become particularly significant during cybersecurity incidents involving personal data. A ransomware attack on a financial institution, for example, could trigger the involvement of the Cyber Security Authority, Data Protection Commission, Bank of Ghana and law enforcement agencies, potentially creating multiple reporting requirements during a crisis.
He called for a formal operational incident protocol between the Cyber Security Authority, Data Protection Commission and relevant sector regulators to clarify notification requirements, lead responsibilities and information-sharing arrangements.
The analysis also raised concerns about proposed expansions of cybersecurity powers and the potential implications for institutional accountability. The draft Cybersecurity Amendment Bill would broaden the Cyber Security Authority’s role in areas including cybercrime enforcement and security standards for emerging technologies such as AI, cloud computing, quantum computing and blockchain.
While stronger enforcement may be necessary, Bediako argued that Ghana should clearly define safeguards where a regulator could simultaneously supervise institutions, receive confidential incident reports and investigate potential criminal conduct.
Artificial intelligence could expose the most significant regulatory overlaps, he said, because a single AI system may raise questions involving privacy, cybersecurity, consumer protection, competition, employment and financial regulation.

The proposed data protection framework could give the privacy regulator greater oversight of AI-related issues, including explainability, human oversight and risk assessment, while proposed cybersecurity legislation would assign the Cyber Security Authority responsibilities for AI security standards.
Bediako said Ghana should explicitly map which institution is responsible for each category of AI risk before the regulatory frameworks mature.
“Neither privacy law nor cybersecurity law, however, should quietly become Ghana’s default AI governance framework,” he wrote, arguing that unclear responsibilities could force businesses to comply with overlapping requirements from multiple regulators.
The analysis also highlighted uncertainty surrounding cross-border data transfers. Ghana’s existing Data Protection Act was enacted in 2012, before widespread cloud adoption and the rapid growth of generative AI, and does not provide the same detailed transfer mechanisms used in some international regulatory systems.
Bediako said Ghana should modernize its rules while avoiding a system in which routine international data processing becomes dependent on repeated case-by-case regulatory approvals.
He recommended clear mechanisms for cross-border transfers, including contractual safeguards and proportionate risk assessments, while reserving regulatory approval for genuinely high-risk processing activities.
The broader objective, Bediako said, should be a regulatory framework that protects citizens without undermining innovation or investment.
“Privacy, cybersecurity and economic growth are therefore not natural enemies; poorly designed regulation is the problem,” he wrote.
Ghana has already established key digital institutions and is now modernizing legislation to reflect technological changes, but the next phase will require ensuring that those institutions operate as parts of a coordinated system rather than separate regulatory silos, according to the analysis.
