At the media launch of Ghana's 2026 Data Protection Week on 26 January 2026, Data Protection Commission Executive Director Arnold Kavaarpuo confirmed that 2026 marks the start of full-scale enforcement of the Data Protection Act 2012 (Act 843). Organisations processing personal data without DPC registration face fines and possible imprisonment; the DPC had told organisations to regularise by 31 December 2025 and announced nationwide enforcement from January (GhanaWeb; DPC public notice).
Government then raised the stakes. At the National Data Protection Conference on 2 March 2026, Communications Minister Samuel Nartey George announced a policy directive mandating the DPC to impose fines on non-compliant institutions, public and private (NewsGhana). For a regulator that spent a decade on registration drives and awareness campaigns, that is a formal change of mission.
What enforcement looks like under current law. Act 843 makes processing without registration a criminal offence, punishable by a fine of up to 250 penalty units, imprisonment of up to two years, or both. Registration fees are tiered by entity size. As of early July 2026 the DPC had not yet published a penalty decision against a named respondent; the enforcement wave is at the warning-and-audit stage, which is precisely the window in which registration is cheap and non-registration is documented.
The bill behind the enforcement. Ghana is simultaneously replacing Act 843. The Data Protection Bill, 2025 went through public consultation in October and November 2025 and would repeal Act 843 entirely, introducing mandatory data protection officers, 72-hour breach notification, data portability, a right to erasure, rights around automated decision-making and AI, a restructured Data Protection Authority, and substantially higher penalties; fines for non-registration rise to as much as 100,000 penalty units in the proposed regime (Sustineri comparative analysis). The Bill had not been introduced in Parliament as of May 2026, and a companion Emerging Technologies Bill covering AI and digital assets was announced at the same March conference. Until passage, Act 843 remains the operative law; the sensible read is that today's registration sweep is the enforcement floor, and the Bill raises the ceiling.
Who is affected. First, the unregistered: the DPC has said plainly that organisations processing personal data without registration are the primary target. Financial services, healthcare, retail and digital platforms carry the highest immediate risk. Second, anyone building a Ghana compliance programme now, because building to Act 843 alone means rebuilding within a year or two.
What to do now:
- Verify your DPC registration is current, including renewals. It is the single cheapest control against the stated enforcement priority, and the criminal exposure attaches to the organisation's officers.
- Build to the Bill, not just the Act: appoint a DPO, stand up 72-hour breach response, and document automated decision-making. Everything in that list is required somewhere else you likely operate already.
- Watch Parliament. Introduction of the Bill starts the clock on transition planning, and the proposed penalty escalation changes Ghana's place in your risk ranking.