In July 2024, the Personal Data Protection Proclamation No. 1321/2024 came into effect providing the first comprehensive legislation dealing with individuals’ rights to privacy. The Proclamation will survive the person’s death and will remain valid for ten years after the death. Below, we provide a brief summary of the law.
Scope of Protection
The Proclamation protects the personal data of individuals, defined as information relating to any identifiable nature of a person, directly or indirectly. It includes a name, identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. Moreover, certain data categories are defined as “sensitive personal data” and offered additional protection, which includes racial or ethnic origins, genetic or biometric data, physical or mental health or condition, political opinion, membership of a professional association, religious beliefs or other opinion of a similar nature, the commission or alleged commission of an offence.
Data Processing
The Proclamation provides a broad definition of data processing, encompassing any action that is done to, or with, personal data, including simply collecting, storing, organizing, altering, and deleting personal data. As a result, the Proclamation is likely to apply wherever an organization does anything that involves or affects personal data. Personal data is required to be processed lawfully, fairly and in a transparent manner. Businesses that process personal data are required to obtain the clear consent of the data subject and provide clarity on the usage of the data. Moreover, personal data must be collected for specific purposes, and it shall be obtained only for one or more explicitly specified and lawful purposes. Businesses must, therefore, clearly define the purpose for which the data is collected, and the collected data must also be used for the purpose initially specified and cannot be used for unrelated purposes.
Key principles under the Proclamation include:
- Data sovereignty: Data controllers or data processors are required to store personal data collected or obtained in Ethiopia on a server or data center located in Ethiopia.
- Cross-border transfer of data: A data controller must demonstrate to the Ethiopian Communication Authority (ECA) that the third-party jurisdiction offers an adequate level of data protection. Additionally, the data subject must provide explicit consent to the transfer after being fully informed of any potential risks. The transfer must either be necessary or come from a public register that is intended by law to provide information to the public. Moreover, a cross-border transfer of sensitive personal data must obtain the prior approval of ECA.
- Right of Erasure: an individual has the right to demand his personal data be erased promptly free of charge if the following circumstances exist:
- The data is no longer necessary for the purpose for which it was collected or processed
- The data subject withdraws his consent on which the processing is based or objects to the processing, and there are no overriding legitimate grounds for the process
- There is no legal ground for the processing
- The personal data has been processed unlawfully
- Right to Obtain Information & Copy: The data subject, upon request, has the right to obtain confirmation free of charge whether his personal data is being processed, along with access to the data processed, information on the data origin, and the duration for which it will be stored. This information is required to be provided to the data subject in an electronic or hard copy format.
Data Processor Obligations
A person who processes personal data has the following key obligations:
- Registration: Businesses that intend to process personal data are required to be registered by ECA. ECA will issue a certificate of registration that will be valid for two years subject to renewal. ECA will determine the detailed registration requirements through a directive.
- Appointment of Data Protection Officer: If the core activity of an entity consists of processing operations which, by virtue of their nature, scope or purposes, require regular and systematic monitoring of data subjects on a large scale, or processing on a large scale of sensitive person data, or the processing is carried out by the government body (except for courts acting in their judicial capacity) has to appoint a data protection officer. The Proclamation allows a single data protection officer to be appointed by a group of entities or several public bodies provided that such an officer is easily accessible by each entity.
- Keeping a Record of all Processing Operations: Businesses must maintain, including logging, a record of all processing operations under their responsibility.
- Internal Data Protection Policy and Procedure: An entity shall put in place a data protection policy and implement the appropriate technical and organizational measures to ensure that the processing of personal data is performed per the law. Moreover, an entity is required to perform a data protection impact assessment.
- Notification of Personal Data Breach: When a personal data breach occurs, an entity is required to notify ECA and the data subject within 72 hours after having become aware of it. The notification to ECA is required to be accompanied with details including the nature of the personal data breach and the likely consequences of the personal data breach. The Proclamation provides that if the details cannot be provided within the time limit, the entity must notify ECA and provide the details in phases.
- Duty to Destroy Personal Data: Where the purpose for storing personal data has lapsed, an entity shall destroy the personal data as soon as is reasonably practicable in a manner that prevents its reconstruction in an intelligible form.
Consequences of Breach
The Proclamation empowers ECA to impose administrative fines. If personal data is processed in violation of the Proclamation, particularly by an institution handling sensitive data or the personal data of a minor, ECA can impose an administrative fine of up to 4% of the institution’s total worldwide turnover from the previous year.








