If your business keeps staff records, customer phone numbers, a visitor book or CCTV footage, it processes personal data. In Ghana that falls under the Data Protection Act, 2012 (Act 843), supervised by the Data Protection Commission. This is a practical overview, not legal advice.

Who must register

Section 27(1) of Act 843 requires every data controller that intends to process personal data to register with the Commission. A data controller is whoever decides why and how personal data is processed. For most businesses that is the business itself, whatever its size.

Common examples of personal data a business holds:

  • Staff files, payroll and Ghana Card numbers
  • Customer and supplier contact lists
  • CCTV recordings and access control logs
  • Visitor books and delivery records
  • Phone numbers and chats in WhatsApp groups used for work

Renewal

Registration is renewed every two years. Put the date in a calendar the day you register.

What happens if you do not

A person who processes personal data without registering commits an offence. On summary conviction the penalty is a fine of up to 250 penalty units, up to two years' imprisonment, or both. At the launch of Data Protection Week 2026, the Commission said 2026 would be a year of enforcement, with more compliance checks on data controllers and processors.

How to register

Registration is done with the Commission; its website, dataprotection.org.gh, sets out the current process. Before you start, write down:

  • What personal data you hold, and about whom
  • Why you hold it
  • Where it is stored: paper files, laptops, the cloud, the CCTV recorder
  • Who can see it, inside and outside the business

Registering is the start, not the end

Act 843 sets out eight principles for processing: accountability, lawful processing, a specified purpose, compatible further use, quality of information, openness, security safeguards, and the participation of the people the data is about. Security safeguards are where IT comes in:

  • Each person has their own login; no shared passwords.
  • Laptops and phones that hold customer data are encrypted and locked.
  • Backups exist, are tested and are not reachable by everyone.
  • CCTV and access control recorders are in a locked space with the default passwords changed.
  • When someone leaves, their accounts are closed the same day.

The Act also allows a data controller to appoint a qualified Data Protection Supervisor to oversee compliance. For CCTV specifically, see CCTV and the Data Protection Act.