Ethiopia's Personal Data Protection Proclamation 1321/2024: Your First 90 Days

Bemnet Aschalew

Ethiopia's Personal Data Protection Proclamation 1321/2024: Your First 90 Days

Who this is for: Anyone handed responsibility for privacy — a Data Protection Officer, a Company Secretary, a Head of Risk, or an IT lead — in a bank, insurer, hospital, hotel, school, NGO or government programme.

The news hook

Ethiopia now has a comprehensive data-protection regime. The Personal Data Protection Proclamation No. 1321/2024 establishes rules for how organisations collect, use, store and share personal data, sets out the rights of data subjects, and designates the Ethiopian Communications Authority (ECA) as the supervisory authority. The ECA's information is published at eca.et. This lands alongside the national digital-ID rollout (Fayda) and a growing body of INSA cybersecurity guidance — so personal data is moving to the centre of the compliance agenda.

Here is the part most organisations miss: this is not a banking law. If you hold customer records, patient files, guest bookings, student data, employee files, donor lists or beneficiary registers, you are a data controller, and the proclamation applies to you. Near-zero practical guidance exists in the Ethiopian market — which is precisely why a clear starting plan is worth more than another summary of the statute.

Why "we'll deal with it later" is the expensive option

Data protection has a peculiar risk profile: nothing appears to be wrong until something goes very wrong — a breach, a complaint, a subject-access request you cannot answer, an ECA enquiry. At that point you cannot retro-fit consent, reconstruct a data map, or invent a retention schedule. The organisations that handle their first incident well are the ones that did the unglamorous groundwork first. Comparative enforcement across the region — Nigeria's NDPC, Kenya's ODPC — shows the pattern: regulators move from guidance to penalties, and the first cases target organisations that had done nothing demonstrable.

Your first 90 days

Treat this as a phased plan, not a single project. You are moving from exposed to defensible — full maturity comes later.

Days 1–30: See what you actually hold

You cannot protect what you have not mapped.

  • Build a first-cut Record of Processing Activities (ROPA). For each major system and process, note: what personal data, whose, why, where it lives, who it is shared with, and how long it is kept.
  • Identify your special-category and high-risk data — health, biometric (including any Fayda-linked data), financial, children's data.
  • List your processors and vendors — anyone who touches personal data on your behalf, including cloud providers.
  • Decide who owns privacy. Assess whether your processing warrants appointing a Data Protection Officer, and name an accountable person either way.

Days 31–60: Fix the lawful basis and the obvious gaps

  • Assign a lawful basis to each processing activity — consent, contract, legal obligation, legitimate interest. If you are relying on consent, is it freely given and recorded, or assumed?
  • Publish or refresh a privacy notice in plain language — and in the languages your data subjects actually read.
  • Set retention schedules. "We keep everything forever" is a liability, not a policy.
  • Review vendor contracts for data-processing terms. Handshake arrangements with a cloud provider are a gap.
  • Check cross-border transfers. If personal data leaves Ethiopia — a foreign cloud region, an overseas group company — understand the restriction before, not after.

Days 61–90: Be ready for the bad day

  • Stand up a breach-response routine. Who is called, in what order, and what are your detection-to-containment-to-notification steps and timelines?
  • Handle data-subject rights requests. Have a simple process to receive, verify and respond to access, correction and deletion requests.
  • Run baseline cyber-hygiene awareness — phishing, MFA, device security. Most breaches start with a person, not a server.
  • Log your decisions. Accountability means being able to show your reasoning, not just assert compliance.

The first 72 hours of a breach

If you do one tabletop exercise this quarter, make it a breach walkthrough. When a laptop is lost or a database is exposed, the clock starts. Your team should know, without improvising: how to confirm and contain, how to assess what data and how many subjects are affected, when and how notification obligations are triggered, and how to record every step. Rehearsed teams act; unrehearsed teams freeze.

The Ethiopian context — and the localisation advantage

Two local realities shape good practice here. First, Fayda: organisations consuming national digital-ID data inherit real obligations around how that data is handled and secured — treat it as high-risk from day one. Second, language: a security-awareness programme delivered only in English will not change behaviour on a frontline that works in Amharic, Afaan Oromo, Tigrinya or Somali. Localised awareness is not a nicety — it is what makes the control actually work.

Your next step

Data protection fails on people far more often than on technology — an untrained employee clicks the link, mishandles a request, or emails a spreadsheet to the wrong recipient. DaraCorp's Cybersecurity & Data Protection course turns Proclamation 1321/2024 from a legal text into daily habits your whole workforce can follow, in the languages they work in. Pair it with Risk Management & Compliance for the person who owns the programme, and your 90-day plan has an engine behind it.

This article is a practical starting guide, not legal advice or a definitive interpretation of Proclamation No. 1321/2024. Confirm your specific obligations against the proclamation and any directives issued by the Ethiopian Communications Authority, and take advice on your organisation's particular circumstances.

DaraCorp AI assistant

How can I assist you today?

Powered by CopilotKit