§ Dossier · EAST AFRICA · updated 22 July 2026
in force
DP law status
Personal Data Protection Proclamation No. 1321/2024
None found
enforcement activity
as of the last landscape verification
No
decisions published
no public record to collect
The law
Personal Data Protection Proclamation No. 1321/2024 IN FORCE
commenced 2024-07-24 (entered into force on publication, art. 70; Federal Negarit Gazette No. 35 of 24 July 2024) · Official full text ↗
- Scope
- Automated processing, filing-system data and accessible public records (art. 2(1)); personal data defined GDPR-style (art. 2(2)); the sensitive-data list is notably NARROW: race/ethnicity, genetic/biometric data, and health only (art. 2(5)), excluding religion, politics and sex life.
- Key obligations
- Registration and licensing of data controllers and processors with the Ethiopian Communications Authority; DPO designation for government bodies (except courts acting judicially), large-scale regular and systematic monitoring, and large-scale sensitive-data processing; 72-hour breach notification to the ECA; GDPR-family principles and data subject rights, sitting alongside the ATI Proclamation 590/2008 for government-held data
- DPO required
- Yes, in defined cases: government bodies, large-scale regular and systematic monitoring, or large-scale sensitive-data processing.
- Registration
- Yes: controllers and processors must be registered with and licensed by the ECA.
- Cross-border transfers
- Adequacy-based: transfers to a third-party jurisdiction only where it ensures an appropriate level of protection (arts. 18-19), assessed by the Authority, which may also authorize limited transfers absent adequacy with data-subject consent and severance of data elements (art. 19(3)-(4)). Transfer routes (art. 20): Authority adequacy determination, explicit informed consent, necessity (contract performance, contract in the data subject's interest, important public interest, legal claims, vital interests), or a public register. The Authority may demand proof of safeguards and may prohibit, suspend or condition any transfer (art. 21). Data sovereignty (art. 22): locally collected personal data MUST be stored on a server or data center in Ethiopia; the Authority may designate critical personal data processable ONLY in Ethiopia; cross-border transfer of sensitive personal data requires prior Authority approval. No SCC/BCR mechanism in the Proclamation. Verified against the archived text 2026-07-11.
- Breach notification
- Notify the ECA within 72 hours of becoming aware of a personal data breach.
- Penalties
- Administrative: the Authority imposes administrative fines on an effective/proportionate/dissuasive standard (art. 59); offences by an institution, involving sensitive data or a minor's data are punishable by a fine of up to 4% of total worldwide turnover of the preceding financial year, with fine details otherwise left to regulation not yet issued (art. 60). Criminal (art. 64): breach-notification/security/principles violations - simple imprisonment 1-3 years or fine ETB 60,000-100,000 or both; data-subject-rights violations (erasure, objection, restriction, automated decisions) - 3-5 years or ETB 100,000-200,000 or both; re-identification, sale of personal data or unlawful cross-border transfer - rigorous imprisonment 5-10 years or ETB 200,000-600,000 or both; aggravated cases (institution, damage, sensitive data, minors) - up to 4% of total worldwide turnover (art. 64(4)). All quanta verified against the archived Negarit Gazette text (English column) 2026-07-11.
- Authority
- Ethiopian Communications Authority (ECA, designated supervisory authority)
Verified 2026-07-11
Access to information
Freedom of the Mass Media and Access to Information Proclamation No. 590/2008 IN FORCE
The regulator
- Authority
- Ethiopian Communications Authority (ECA, designated supervisory authority)
- Website
- https://eca.et ↗
- Established
- 2019
- Operational
- Yes
- Enforcing
- No enforcement activity found
- Publishes decisions
- No
Enforcement record
No enforcement decisions could be found for this jurisdiction as of the last verification pass (22 July 2026). A country with no published enforcement is a data point, not a gap: see the 54-state publication scorecard.
Related reading
Analysis is at lawlab.africa/analysis;
method, inclusion rules and the correction policy are on the
methodology page.
Track Ethiopia
Get decision alerts by email
Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.