Law Without Sovereignty: Can Ghana’s Data Protection Act Protect What It Does Not Own?

By William Song-Aabo

Every time a Ghanaian taps their phone to send mobile money, check a bank balance, or verify their Ghana Card, a quiet exchange takes place as personal data leaves their hands and begins a journey through cables, servers, and platforms owned almost entirely by foreign companies. Government agencies and private enterprises now collect more personal information about citizens than ever before, yet beneath this gleaming surface of progress lies an uncomfortable truth: the digital infrastructure that carries this precious data is not Ghanaian. This raises a difficult question, namely whether a law drafted in Accra can truly protect a citizen’s digital footprint when that footprint is stored on a server in California or Amsterdam. The Data Protection and Privacy Act, 2012 (Act 843) is an impressive statute, but as this article will argue, because Ghana does not own or meaningfully control the digital infrastructure it depends on, the law’s promise remains only partially fulfilled. It can safeguard some rights, but not all, and never automatically.

To understand why, it helps to borrow a lens from Samir Amin, the Egyptian-French economist who spent his career studying the unequal relationship between rich and poor nations. Amin (1974) argued that the world economy is divided into a dominant core and a dependent periphery, where the periphery does not simply lag behind but is actively structured to serve the core’s needs. Amin called this “extraversion,” an economy oriented relentlessly outward, exporting raw materials and importing finished goods. Decades later, his insight still resonates because in today’s digital economy, Ghanaian data such as biometric identifiers, financial histories, and private conversations has become the raw material. It streams into foreign clouds and platforms, where it is refined into algorithms, targeted advertising, and artificial intelligence models, then sold back to Ghana at a premium. Couldry and Mejias (2019) call this “data colonialism,” the systematic appropriation of human experience through relentless data extraction. It is unequal exchange in its most modern form.

The Data Protection and Privacy Act, 2012 (Act 843) is, without question, a serious legislative achievement, as it establishes the Data Protection Commission, grants Ghanaians the right to access, correct, and object to the use of their personal information, and restricts cross-border data transfers. The statute even extends limited authority over foreign companies that use equipment within Ghana’s borders, though this provision remains narrow and largely untested. In theory, a citizen whose data has been misused can file a complaint and seek redress, but the entire legal framework rests on a fragile assumption, namely that data processing occurs within Ghana’s territorial control. That assumption collapses in everyday reality, because a Ghanaian using WhatsApp on a Chinese-made phone, with messages routed through American servers, is subject to multiple overlapping legal systems, none of which are fully answerable to Accra. The law was written for a sovereign digital space that simply does not exist.

The ownership gap is where dependency becomes visible, because the undersea fibre-optic cables that connect Ghana to the global internet, including SAT-3, WACS, ACE, MainOne, and Google’s Equiano, are controlled by consortia dominated by foreign capital. Much of the country’s internet traffic is routed through Europe or the United States before reaching its destination, while cloud services used by Ghanaian businesses and government agencies, such as Amazon Web Services, Microsoft Azure, and Google Cloud, store sensitive records in foreign data centres. Everyday platforms like WhatsApp, Facebook, X, TikTok, and Google Workspace are operated by global corporations that answer to foreign courts and foreign laws. The legal consequence is profound, because under the United States CLOUD Act, American authorities can compel technology companies to disclose data even when it is stored outside American territory (U.S. Department of Justice, 2018), and Ghana’s Data Protection Act has no response to that. The economic consequence is equally sobering, since Accra pays for cloud storage, software licences, and digital services while its citizens’ data is quietly extracted as fuel for foreign artificial intelligence and advertising markets. This is external dependence in its purest form, with Ghanaian data as raw material, siphoned through foreign pipelines, refined in the core, and resold as expensive finished products.

Consider, for example, a single mobile money transaction in which a customer sends money to a relative in Kumasi. While a Ghanaian fintech company may handle the actual processing, the cloud infrastructure supporting that transaction is almost certainly provided by Amazon Web Services or Microsoft Azure, the confirmation message is likely delivered through WhatsApp, and the fraud-detection systems run on Google’s analytics tools. Each of these layers belongs to a foreign corporation with its own legal obligations and commercial interests, which means that Ghanaian regulators may exercise meaningful oversight over the local fintech but cannot reach the cloud provider, the messaging platform, or the analytics firm with the same authority. Consequently, even the most well-intentioned domestic regulation operates only at the edges of a system whose centre of gravity lies far beyond Ghana’s shores.

Even where Act 843 does apply, enforcement quickly lays bare the power imbalance at the heart of the problem. The Commission operates with a skeletal staff and a constrained budget, yet it is expected to regulate corporate giants whose market values exceed Ghana’s entire gross domestic product (Privacy International, 2020). If the Commission were to order a foreign platform to stop processing Ghanaian data, could it realistically compel obedience? The uncomfortable answer is probably not. After all, fines that would severely punish a local enterprise are little more than rounding errors for a multinational corporation. One only needs to imagine the Commission issuing a penalty to a company like Meta or Google. Would the company even acknowledge it, let alone comply? The result is a legal regime that commands deference in principle but possesses precious little leverage in practice. Amin’s point applies with force here: dependent states are not merely short of capacity; they are structurally positioned as rule-takers rather than rule-makers.

This does not mean Act 843 is worthless, because for data processed by Ghanaian banks, telecommunications companies, hospitals, and government agencies within the country’s borders, the law provides genuine protection. It creates enforceable rights, imposes clear duties, and offers a formal complaints mechanism that citizens can actually use. Ghana has also made modest progress in building local infrastructure, as the National Information Technology Agency operates a data centre and private providers are slowly emerging. However, this capacity remains far short of the growing demand. The most sensitive categories of information, including biometric records, financial histories, and medical files, increasingly flow through foreign-owned clouds and platforms where Ghanaian law is a polite guest rather than a commanding landlord. It can request cooperation, but it cannot always demand compliance. This is dependent sovereignty: formal legal authority without the underlying infrastructural control to give it teeth. The law safeguards rights where the infrastructure is domestic, yet it stumbles wherever the infrastructure is foreign.

This reality invites a practical question: what can Ghana do? Amin’s controversial call for “delinking” is frequently misunderstood as a plea for isolation, yet in the digital context it simply means building enough infrastructural and regulatory autonomy to make Ghanaian law genuinely meaningful (Amin, 1990). This does not require abandoning Google or WhatsApp, nor does it demand cutting the country off from the global digital economy. Rather, it requires ensuring that Ghanaian data has a secure home within Ghana, that the Data Protection Commission possesses the resources and technical expertise to regulate effectively, and that African states negotiate collectively with global platforms from a position of strength rather than supplication.

Concretely, the nation should invest in national and regional data centres for sensitive public records, adopt strict data residency rules for critical categories such as national identification, health, and financial information, and significantly strengthen the Data Protection Commission with adequate funding, skilled technical staff, and modern forensic tools. Government agencies should also promote open-source software to reduce dependence on proprietary foreign vendors, while mandating rigorous data protection impact assessments before any major digitisation project is launched. At the regional level, the African Union’s Data Policy Framework and the African Continental Free Trade Area’s digital protocol provide promising starting points for building collective bargaining power (African Union, 2022). Digital delinking, in this sense, is not isolation but leverage.

Dependency theorists have long observed that poorer nations are not underdeveloped because they lack resources, but because the global economic system is designed to keep them serving wealthier, more powerful countries. The same logic applies with equal force to Ghana’s digital environment, where Act 843 stands as a vital legal foundation that cannot, on its own, protect data flowing through an infrastructure the nation does not control. Ghana’s data protection regime will remain little more than a fence around a field owned elsewhere unless the state invests decisively in local infrastructure, strengthens enforcement capacity, and negotiates as part of a unified African bloc. The law is absolutely necessary, yet it is not remotely sufficient. Sovereignty, whether digital or otherwise, must be painstakingly built rather than merely declared.

References

African Union. (2022).AU data policy framework. African Union Commission.

Amin, S. (1974).Accumulation on a world scale: A critique of the theory of underdevelopment. Monthly Review Press.

Amin, S. (1990).Delinking: Towards a polycentric world. Zed Books.

Couldry, N., & Mejias, U. A. (2019).The costs of connection: How data is colonizing human life and appropriating it for capitalism. Stanford University Press.

Data Protection and Privacy Act, 2012 (Act 843) (Ghana).

Privacy International. (2020).State of privacy Ghana. Retrieved from https://privacyinternational.org/state-privacy/1004/state-privacy-ghana

U.S. Department of Justice. (2018).Clarifying Lawful Overseas Use of Data (CLOUD) Act, Pub. L. No. 115-141, 18 U.S.C. § 2523.

Share with friends

Leave a Reply

Your email address will not be published. Required fields are marked *