Data Protection in Ethiopia: What the Law Says and Why It Matters
Ethiopia now has a personal data protection law, and it changes the rules for anyone collecting customer data. Here is what businesses need to understand.
For years, Ethiopian businesses collected customer data with very little formal guidance on what they could and could not do with it. That has started to change. Ethiopia now has a formal personal data protection framework under the Personal Data Protection Proclamation No. 1321/2024, which entered into force on July 24, 2024. The law establishes rules around the collection and processing of personal data and creates a dedicated regulatory authority. It is worth understanding before it becomes expensive not to.
What the framework introduces
The new direction brings principles that will feel familiar to anyone who has looked at modern privacy laws. The Personal Data Protection Proclamation establishes an Authority responsible for overseeing personal data protection and sets out rules around how personal data is collected, used, stored, and shared. Article 6 establishes the core processing principles, while Article 8 provides that valid consent must be “free, informed, specific, clear” and require an active action from the data subject.
- Consent. You should have a clear, lawful basis for collecting and processing personal data. Under Article 8, consent must be free, informed, specific, clear, and based on an active action by the data subject.
- Purpose limitation. Article 13 requires the purpose for which personal data are obtained to be specified, limiting the ability to quietly repurpose data for something entirely different.
- Data subject rights. Individuals gain rights to access, correct, and in some cases erase their data. Article 25 provides a right of access, while Article 27 provides a right to correction and Article 28 a right to erasure.
- Cross-border transfer rules. Sending personal data outside the country comes with conditions. Article 20 sets out when cross-border transfers are permitted, while Article 22 requires locally collected personal data to be stored on a server or data center located in Ethiopia.
- Security obligations. Controllers and processors must protect the data they hold, and the Proclamation requires appropriate technical and organizational safeguards. It also requires notification of certain personal data breaches within 72 hours after becoming aware of them.
What this means in practice
For most businesses, the immediate impact is not a legal crisis. It is a set of new habits. Know what data you actually collect, why you collect it, where it is stored, and who can access it. The Proclamation goes further than simply asking companies to be careful: Article 33 requires data controllers and processors to be registered with the Authority, while Article 43 establishes obligations around personal data breaches. Most companies cannot answer those four questions today, and that is where the risk sits.
The law is still maturing in its implementation. Regulations, directives, registration requirements, and enforcement will firm up over time. But waiting for enforcement before you get your house in order is a bad strategy. The Proclamation already provides enforcement mechanisms, including administrative measures and criminal penalties for certain violations. The cost of cleaning up data later is far higher than the cost of collecting it properly now.
Data you never should have collected is a liability you now own.
The practical move is to start with a simple data inventory. What do you hold, where is it, who can see it, and why do you still have it. That single exercise surfaces most of what the law will eventually ask you to prove.
Frequently asked questions
Does Ethiopia have a data protection law?
Yes. Ethiopia has the Personal Data Protection Proclamation No. 1321/2024, which entered into force on July 24, 2024. It establishes a formal personal data protection framework and a dedicated regulatory Authority.
What are the core principles of Ethiopia's data protection law?
The framework covers lawfulness, consent, fairness and transparency, purpose limitation, accuracy, data minimization, security, and accountability, alongside data subject rights such as access, correction, and erasure.
What should a business do first?
Start with a simple data inventory: what you hold, where it lives, who can see it, and why you still have it. Then identify the lawful basis for processing, check your security measures, and determine whether your business has registration or other obligations under the Proclamation.