Raymodaw

Cybersecurity

The Data Protection Act: a practical checklist for Ghanaian businesses

Registration, data mapping, consent, security measures and breach handling: what Act 843 actually asks of an ordinary organisation, and where most fall short.

8 min read  ·  Raymodaw

Why this matters more than it used to

Ghana Data Protection Act, 2012 (Act 843) has been in force for over a decade, but enforcement attention and commercial pressure have both increased significantly. Two things have changed in practice. First, the Data Protection Commission has become more visible in pursuing registration and compliance. Second, and in our experience this is the bigger driver, clients, banks, insurers and international partners now routinely ask suppliers to demonstrate how personal data is handled before they will sign a contract.

The result is that data protection has moved from a legal obligation that could be deferred to a commercial requirement that costs you business when it is missing. What follows is a practical checklist of what an ordinary organisation should have in place. It is not legal advice, and where your situation is complex you should involve a lawyer.

1. Register as a data controller

If your organisation collects or processes personal data, and if you have employees or customers you do, you are required to register with the Data Protection Commission and renew that registration. Registration is the single most common gap we find, and it is also the easiest to close. Start here before anything else.

2. Know what personal data you actually hold

You cannot protect or account for data you have not mapped. A basic data inventory should answer, for each system and each process:

  • What personal data is collected, and about whom (staff, customers, applicants, patients, beneficiaries)
  • Why it is collected, the specific purpose, not a general one
  • Where it is stored, including cloud services and anything on individual laptops
  • Who has access to it, internally and externally
  • Who it is shared with, including suppliers and processors
  • How long it is kept, and what triggers deletion

Most organisations discover two things during this exercise: that personal data is held in more places than anyone expected, and that several copies exist in spreadsheets nobody has looked at for years.

3. Establish a lawful basis and be honest about consent

Every processing activity needs a justification. Consent is one, but it is not the only one and it is frequently the weakest choice. Consent must be freely given, specific and capable of being withdrawn, which is difficult to demonstrate for something like payroll processing. Contractual necessity, legal obligation and legitimate interest are often more appropriate. What matters is that you have decided, recorded the decision, and can explain it.

4. Tell people what you are doing with their data

A privacy notice should exist wherever you collect personal data: on your website, on application forms, in employment contracts. It should be written in language an ordinary person can follow and should cover what you collect, why, who you share it with, how long you keep it and how someone can exercise their rights. A three-page document written by a lawyer that nobody reads satisfies nobody.

5. Put proportionate security measures in place

The Act requires appropriate technical and organisational measures. In practice, for most organisations, that means at minimum:

  • Multi-factor authentication on email and any system holding personal data
  • Access granted on a least-privilege basis and reviewed periodically
  • Encryption of devices, particularly laptops and anything that leaves the office
  • Patching and endpoint protection that is managed rather than left to individuals
  • Backups that are protected from ransomware and have been restore-tested
  • A documented joiner, mover and leaver process so access is removed promptly

None of these are exotic. All of them are commonly missing.

6. Manage your suppliers

If a third party processes personal data on your behalf, such as a payroll bureau, a cloud provider, a marketing agency or an IT supplier, you remain accountable. You need a written agreement covering what they may do with the data, what security they maintain and what happens when the relationship ends. Ask your existing suppliers for theirs; the responses are often instructive.

7. Be able to handle a subject access request

Individuals have the right to ask what data you hold about them, to have inaccuracies corrected and, in defined circumstances, to have data deleted. You need a process: who receives the request, how identity is verified, how the data is located across your systems, and the timeline for responding. The first time you work this out should not be when the request arrives.

8. Have a breach plan before you need one

Decide in advance who is called, who decides whether a notification is required, how affected individuals are contacted and how the incident is documented. Write it down and rehearse it once. The organisations that handle incidents badly are almost never the ones that were unlucky; they are the ones that were improvising.

9. Train the people who handle data

Most breaches involve a person making an understandable mistake: an email to the wrong recipient, a document left in a shared folder, a convincing phishing message. Short, practical, repeated training does more for your risk position than most technical controls.

10. Keep the evidence

Compliance you cannot demonstrate is compliance you do not have, at least as far as an auditor or a prospective client is concerned. Keep your data inventory, policies, training records, access reviews, supplier agreements and incident log somewhere organised and current.

Where to start if this list feels long

Register first. Then map your data; it takes less time than people fear and it makes every subsequent decision easier. Then close the security basics, particularly multi-factor authentication and tested backups. Those three steps put you ahead of most organisations of comparable size, and they make the remainder considerably more manageable.

If you would like an independent view of where you stand, our security and compliance assessment covers exactly this ground and produces a prioritised, plain-language action list.

Talk this through with us

If this raises a question about your own organisation, a short conversation costs nothing and usually clarifies more than another article will.

Next step

Let us talk about what your technology should be doing for you.

Book a free, no-obligation consultation. We will listen to what you are dealing with, give you a straight assessment, and set out your options, whether or not you end up working with us.

Scroll to Top