By Frank Bediako
I have learnt one lesson from working in privacy across a large multinational environment: the hardest regulatory problems are not always caused by an absence of rules; quite often, the difficulty lies in having plenty of rules, several well-intentioned regulators, overlapping mandates and no sufficiently clear answer to the deceptively simple question of who, ultimately, is responsible for what.
Ghana may now be approaching precisely that point in its digital regulatory journey.
There is much to commend: Ghana was relatively early in Africa in enacting comprehensive data protection legislation; the Cyber Security Authority has developed into a credible and increasingly visible institution; and Government is modernising legislation written before generative AI, large-scale cloud adoption and today’s global digital economy became part of everyday life. Yet 2026 feels, in an important sense, like an inflection point.
The Data Protection Commission has declared this a “Year of Enforcement”; the draft Data Protection Bill, 2025 proposes a replacement data-protection law; the Cybersecurity Act is also the subject of substantial proposed amendments through the draft Cybersecurity (Amendment) Bill, 2025; and the Cyber Security Authority, under its Director-General, Divine Selase Agbeti, is increasingly occupying a central position in Ghana’s digital-security architecture.
The question, therefore, is no longer whether Ghana should regulate the digital economy — of course it should — but whether we are building one coherent system of digital governance, or several powerful regulatory systems that will, with time, increasingly collide with one another.
Privacy did not begin with Act 843
It is worth beginning with something that is often lost in discussions about data protection: in Ghana, privacy is first a constitutional right, not merely a registration requirement administered by the Data Protection Commission. Article 18(2) of the 1992 Constitution protects the privacy of the home, property, correspondence and communication, permitting interference only in accordance with law and where necessary in a free and democratic society for specified legitimate purposes.
In Raphael Cubagee v Michael Yeboah Asare & Others, Reference No. J6/04/2017, [2018] GHASC 14 (28 February 2018), the Supreme Court applied that constitutional protection to the surreptitious recording of a telephone conversation; in doing so, the Court treated privacy as involving a person’s ability to control intrusion into private communications and recognised that technological change makes such intrusion increasingly easy.
Although Cubagee was not a data-protection case in the modern regulatory sense, its reasoning provides an important constitutional foundation for Ghana’s developing privacy jurisprudence; that starting point matters because data protection is not simply about whether an organisation has renewed its DPC registration certificate, nor can cybersecurity powers be assessed solely by asking whether they are authorised under the Cybersecurity Act. Beneath both questions lies a more fundamental one: are we protecting people?
Act 843 has served Ghana well — but the world has moved.
The Data Protection Act, 2012 was a respectable piece of legislation for its time, containing principles that remain entirely recognisable today: accountability, lawfulness, purpose limitation, data quality, openness, security and participation by the individual. It also recognises something that still occasionally gets lost in privacy discussions — namely, that consent is not the only basis for legitimate processing; contractual necessity, statutory duties, legitimate interests and other grounds all have a place.
The Act further contains meaningful security obligations and requires notification to the DPC and affected individuals where personal data has been accessed or acquired by an unauthorised person; nevertheless, legislation enacted in 2012 could hardly have anticipated the world of 2026.
Tennyson’s familiar line, “the old order changeth, yielding place to new”, has an unexpectedly apt resonance here: cloud ecosystems are global; businesses routinely operate shared-service platforms across several continents; artificial intelligence systems consume and infer data at enormous scale; biometric technologies are moving into everyday services; and decisions affecting credit, employment, insurance and access to services are increasingly automated.
Data, moreover, no longer moves neatly from organisation A to organisation B; it may pass through processors, sub-processors, cloud regions, analytics platforms and AI services before anyone in the business has finished explaining the architecture. Against that background, one weakness in the existing Ghanaian framework becomes particularly obvious.
Cross-border data transfers: Ghana needs certainty
Act 843 contains provisions relevant to processing outside Ghana; among other things, section 30(4) requires a controller engaging a processor not domiciled in Ghana to ensure that the processor complies with relevant Ghanaian law. What the Act does not establish, however, is a comprehensive outbound-transfer regime built around mechanisms such as adequacy decisions, recognised standard contractual safeguards, binding corporate rules or a clearly articulated transfer-risk framework; and that matters commercially.
A Ghanaian company moving HR data into a global cloud-based platform, engaging an overseas forensic investigator, sending medical information to an international insurer or deploying a multinational AI system should not have to reverse-engineer the answer from general principles.
The law should tell organisations, with reasonable clarity, what lawful transfer mechanisms are available; the draft Data Protection Bill, 2025 attempts to address this, which is welcome, although there is also a danger of over-correcting. The draft introduces data-localisation expectations and stronger requirements for certain categories of information, including children’s, biometric, health and genetic data; it also provides for regulatory involvement in specified transfers and transfer-impact assessments in defined circumstances.
The policy instinct is understandable — Ghana should care about where sensitive information concerning its citizens goes and what happens to it once it leaves the country — but the means chosen to achieve that objective matter greatly.
The current drafting therefore deserves scrutiny: Clause 96 appears capable of being read as requiring written, free, explicit and informed consent as a threshold condition for outbound transfers, alongside one of a series of specified necessity grounds, while large-scale transfers may also attract additional regulatory requirements and safeguards. If that is the intended effect, routine multinational processing could become materially more difficult.
If it is not the intended effect, the drafting should be clarified, because Ghana should not replace uncertainty with bureaucracy; a modern transfer regime ought to protect people while giving responsible businesses predictable and reusable routes to compliance. Adequacy arrangements, recognised contractual safeguards, binding corporate rules, carefully defined necessity grounds, proportionate transfer-risk assessments and appropriate regulatory oversight can coexist.
In contrast, regulatory approval should be reserved for cases where the nature, scale or risk of the processing genuinely justifies it. Businesses cannot operate efficiently in a system where ordinary international processing repeatedly depends on case-by-case regulatory permission with uncertain criteria and timelines; data sovereignty is important, but it should not become data isolation.
Enforcement is welcome — but enforcement must mature beyond registration.
I welcome the DPC’s decision to become more assertive: Dr Arnold Kavaarpuo has made clear that 2026 marks a move toward enforcement, inspections, and sanctions, while the Commission expands its ability to conduct operations beyond Accra. That evolution is necessary; the next stage of maturity, however, should involve shifting the centre of gravity from formal compliance to substantive accountability.
Registration has value; so do certificates and policies, but none of them, by themselves, protect anybody. A company may possess a beautifully drafted privacy notice and still collect excessive data; it may have a DPO and still deploy a poorly governed AI model; it may complete a DPIA after every important decision has already been taken and still pass an audit, while employees routinely download personal information into spreadsheets and email it around the organisation.
The test of a mature privacy regime, therefore, is not only how many organisations are registered, but whether organisations can demonstrate that privacy considerations genuinely influence how technology is designed, how data is used, how risk is challenged and how people are treated; that is where enforcement should increasingly concentrate.
Then there is the Cyber Security Authority.
Ghana deserves considerable credit for what it has built in cybersecurity: Act 1038 gives the CSA significant responsibilities for cybersecurity regulation, critical information infrastructure, incident management, cybersecurity service providers and national cyber resilience, while its incident-reporting framework is broader than is sometimes appreciated.
The Act requires the person in charge of an institution to report a cybersecurity incident within 24 hours of detection, with additional obligations potentially arising through the critical information infrastructure regime, sector-specific rules, licence conditions or regulatory directives; under Divine Selase Agbeti, meanwhile, the Authority’s public messaging has increasingly treated cybersecurity as a matter of governance and national resilience rather than simply an IT function. That is the right direction.
At the September 2026 launch of National Cybersecurity Awareness Month, the CSA reported that CERT-GH had recorded 3,876 cybersecurity incidents between January and July 2026, of which 1,818 — approximately 47 per cent — were linked to online fraud; the figures illustrate the scale of the challenge, but they also sharpen an important governance question as the CSA becomes stronger.
Where does cybersecurity end and data protection begin?
In reality, the answer is often not straightforward. Consider a ransomware attack on a Ghanaian bank: the CSA will be interested because a cybersecurity incident has occurred; the DPC will be interested if personal data has been compromised; the Bank of Ghana may have its own regulatory interest; law enforcement may become involved; and customers may have to be notified.
If the organisation is multinational, several foreign regulators may start their own clocks at almost the same moment. Anyone who has managed a serious incident knows that this is not an academic problem: when systems are down, facts are uncertain, forensic investigators are still trying to establish what happened, and executives want answers, regulatory ambiguity becomes operational risk.
Ghana already has a statutory mechanism intended to support inter-agency coordination: the Joint Cybersecurity Committee, established under Act 1038, brings together the Cyber Security Authority and representatives of institutions including the Data Protection Commission, the Bank of Ghana, the National Communications Authority and other relevant public bodies.
That is important institutional infrastructure; institutional coordination and operational incident coordination, however, are not necessarily the same. An organisation dealing with a live cyber incident still needs to know which regulator must be notified, when notification must occur, what information must be supplied, whether notifications can be coordinated, which regulator leads on which issue, how duplicative requests will be managed and how information supplied during an emergency may later be used.
Ghana should therefore build on the Joint Cybersecurity Committee by developing a formal operational incident protocol between the CSA, DPC and relevant sector regulators; such a protocol should establish common definitions where practicable, clearly mapped notification channels and timelines, mechanisms for coordinated requests for information, identification of lead and supporting regulators, and rules governing regulatory information-sharing and the onward use of material supplied during incident response. The law can create institutions; operational clarity determines whether those institutions work together when it matters.
The proposed expansion of CSA powers deserves serious debate.
The draft Cybersecurity (Amendment) Bill, 2025 would go far beyond the existing framework: among other things, it proposes powers for the CSA to investigate cybercrime and, subject to Article 88 of the Constitution and with the authority of the Attorney-General, prosecute it; it also proposes expanded enforcement powers, asset-recovery mechanisms and powers relating to information gathering. Perhaps even more interestingly, the draft would give the Authority functions relating to standards and certification for the security of AI, cloud technologies, quantum computing, big data, IoT, blockchain and other emerging technologies.
There are good arguments for some of this: cybercrime is real, and enforcement must be effective; emerging technologies also create genuine security risks, but institutional design matters. A body that regulates an organisation, receives confidential incident reports from it, investigates possible criminal conduct arising from those incidents and potentially participates in prosecution occupies a very different position from a conventional sector regulator; questions of procedural fairness, legal privilege, compelled information, confidentiality, information-sharing and appropriate checks and balances therefore become much more important. This is not an argument for weakening the CSA; on the contrary, it calls for greater clarity and equally strong safeguards, because that is how durable institutions are built.
AI will expose every regulatory overlap we have failed to resolve.
Artificial intelligence will make these questions more urgent because an AI system may simultaneously raise issues of privacy, cybersecurity, consumer protection, discrimination, intellectual property, competition, employment law, financial regulation and national security.
The temptation is to address this by letting every existing regulator extend its mandate a little further; understandable though that may be, it is also how regulatory fragmentation happens. The potential overlap is no longer merely theoretical: Clause 53 of the draft Data Protection Bill, 2025 would give the proposed data-protection framework significant reach into emerging technologies, including issues concerning explainability, contestability, human oversight, risk assessment and, in specified circumstances, ethical auditing.
At the same time, the draft Cybersecurity (Amendment) Bill, 2025 would give the CSA functions to establish and administer security standards and certification for technologies including artificial intelligence, cloud computing, quantum computing, big data, the Internet of Things and blockchain. Each provision is understandable on its own; read together, however, they show precisely why institutional boundaries need to be designed deliberately before both regimes mature. The DPC — or any successor Data Protection Authority — should clearly regulate the processing of personal data used in AI systems.
The CSA should, just as clearly, regulate cybersecurity risks associated with AI infrastructure and systems. At the same time, other regulators will have legitimate roles where AI affects financial stability, telecommunications, competition, consumer protection, employment or other regulated activities.
Neither privacy law nor cybersecurity law, however, should quietly become Ghana’s default AI governance framework; Ghana needs to decide deliberately which AI risks belong to which institution, where responsibilities overlap and how those institutions are expected to interact. Otherwise, a business deploying one AI system may eventually need to satisfy several regulators applying overlapping standards to essentially the same activity; that does not necessarily produce better regulation and may, sometimes, produce more regulation.
What I would do next
If Ghana wants to turn its current legislative activity into a genuinely coherent digital-governance framework, modernisation alone will not be enough; we must also decide how the various parts of the emerging architecture are meant to fit together. I would therefore prioritise six things.
Modernise cross-border transfers without creating an approval bottleneck: give organisations clear, reusable and internationally interoperable transfer mechanisms while reserving regulatory approval for genuinely high-risk cases; the final legislation should also make it unambiguous when consent, necessity grounds, contractual safeguards, binding corporate rules, transfer-risk assessments and regulatory authorisation are required.
Operationalise existing coordination through a formal DPC–CSA incident protocol: Ghana already has a statutory coordination mechanism through the Joint Cybersecurity Committee; the next step is to translate that institutional coordination into an operational model for incidents involving personal data, with clearly mapped notification requirements, lead and supporting regulators, coordinated information requests and rules governing how information supplied during incident response may subsequently be used or shared.
Draw an explicit regulatory map for AI and emerging technologies: the respective responsibilities of the DPC or any successor authority, the CSA, NCA, Bank of Ghana and any future AI-governance body should be visible before disputes arise; the overlapping emerging-technology provisions already appearing in the draft data-protection and cybersecurity legislation make this increasingly urgent.
Build enforcement around risk and outcomes: regulatory attention should increasingly follow harm, scale, sensitivity, systemic risk and accountability, rather than treating registration as the principal measure of privacy maturity.
Put constitutional rights at the centre of digital regulation: surveillance, interception, compulsory disclosure and increasingly intrusive technologies should always be tested against Article 18(2), not merely against the enabling statute of the regulator exercising the power.
Design Ghana’s framework for African and global interoperability: we should learn from the GDPR, certainly, but Ghana does not need to copy Europe clause by clause; we should also look seriously at Nigeria, Kenya, South Africa, the ECOWAS framework and the wider African digital economy, and ask what architecture will allow trusted data flows across our own continent.
Ghana does not need to choose between innovation and protection.
I sometimes find the public debate on digital regulation unnecessarily binary: one side warns that regulation will kill innovation, while the other responds as though anyone questioning a regulatory requirement must therefore be indifferent to privacy or security; neither position is particularly useful. Good regulation is part of the infrastructure of a successful digital economy: people are more willing to use digital services when they trust them; businesses invest where the rules are reasonably predictable; international partners move data where they believe it will remain protected; and innovation flourishes when entrepreneurs understand the boundaries within which they can build.
Privacy, cybersecurity and economic growth are therefore not natural enemies; poorly designed regulation is the problem. Ghana has already done much of the difficult institution-building: we have a constitutional privacy tradition, a functioning Data Protection Commission and one of Africa’s more visible cybersecurity authorities, while Government is now revisiting legislation that plainly needs modernisation.
The next challenge is harder and more important: to ensure that, as each institution becomes stronger, the system as a whole becomes clearer. Citizens do not experience privacy, cybersecurity, AI, digital finance and online identity as separate regulatory silos; they experience them together, as elements of one digital life. Our regulatory architecture should begin to reflect that.
About the author
Frank Bediako is a senior global privacy professional with experience leading data-protection programmes across multiple jurisdictions; he writes on privacy leadership, digital governance and the development of data-protection regulation in Africa.
