Ethiopia'sPersonalDataProtectionProclamation1321/2024:whatyourorganisationhastodo
Proclamation 1321/2024 applies to every organisation handling personal data in Ethiopia, whatever its size. What it requires, and what to do about it.
Proclamation No. 1321/2024 is Ethiopia's first comprehensive personal data protection law. It applies to every data controller and processor regardless of size, revenue or headcount, and requires lawful processing, records of processing activities, data protection impact assessments, appointment of a data protection officer, and notification of personal data breaches within 72 hours.
Last reviewed
It almost certainly applies to you
The most common misreading of this law is that it is aimed at large organisations. It is not. Proclamation 1321/2024 applies to data controllers and processors regardless of size, revenue or number of employees. There is no small-business exemption to fall through.
If you hold personal data about identifiable people - customers, patients, students, employees, job applicants, suppliers' staff - you are a data controller. A twelve-person clinic with a patient list is covered. So is a private college with student records, a retailer with a delivery database, and a company whose only personal data is its own payroll.
The law is closely modelled on the GDPR, which is useful: the concepts, and much of the vocabulary, are the ones an international client or partner will already expect you to know.
What it requires
The obligations that most often require actual work:
| Requirement | What it means in practice |
|---|---|
| Lawful basis for processing | For every category of personal data you hold, a defensible reason for holding it - consent, contract, legal obligation. "We have always collected it" is not one. |
| Records of processing activities | A written record of what you process, why, where it is stored, who it is shared with and how long you keep it. Most organisations have never written this down. |
| Data protection impact assessment | For higher-risk processing, an assessment carried out before you start, identifying the risks to individuals and what you have done about them. |
| Data protection officer | A named person responsible for compliance, with the standing to actually raise problems. |
| Data subject rights | A working process for handling requests for access, correction and deletion - within the statutory timeframe, not eventually. |
| Breach notification within 72 hours | Notify the Authority within 72 hours of becoming aware of a personal data breach, including the nature of the breach and the categories and approximate number of people affected. Affected individuals must be informed too. |
| Technical and organisational security measures | Access control, encryption where appropriate, logging, and the ability to restore availability after an incident. |
Summarised from published legal analyses of Proclamation No. 1321/2024. Confirm the requirements applying to your organisation against the proclamation itself and take legal advice where a decision turns on the detail.
The 72-hour clock is an engineering problem
Of everything in the proclamation, breach notification is the obligation most organisations are structurally unable to meet - and the reason is not legal.
The clock starts when you become aware of a breach. Most Ethiopian organisations have no logging worth the name, no alerting, and no way of telling whether data left the building. They do not miss the 72-hour deadline because they decide not to report; they miss it because six months later they still do not know anything happened.
The notification also has to say something. It must describe the nature of the breach and the categories and approximate number of data subjects affected. Answering that requires knowing what data you held, where it was, and who could reach it - which is the records-of-processing obligation, arriving from a different direction.
So the compliance work and the security work are the same work. An organisation that can detect an incident, scope it and report it accurately within three days has, by construction, built most of what the law asks for.
A realistic sequence
For an organisation starting from nothing, in the order that produces the most protection per week of effort:
- Find the personal dataEvery system, spreadsheet, shared drive, messaging group and third-party service holding data about people. This is always larger than expected, and it is the foundation for everything else.
- Write the record of processingWhat, why, where, who it is shared with, how long. This is a direct obligation and it is also the document you will need in an incident.
- Delete what you should not haveThe fastest reduction in risk available to most organisations. Data you do not hold cannot be breached, cannot be requested, and does not need protecting.
- Fix access controlIndividual accounts rather than shared ones, multi-factor authentication, and access that matches what someone's job actually requires.
- Build detection and the notification pathLogging and alerting, plus a written procedure naming who decides, who notifies the Authority, who tells affected individuals, and by when. Rehearse it once.
- Appoint the DPO and set a review cadenceA named person, with authority to escalate, and a recurring review so this does not decay the moment the project ends.
Questions people ask
Start with knowing what you hold
Most of this becomes tractable once the data inventory exists. Tell us what systems you run and we will tell you what we would look at first.