Skip to content
Regulatory Guide

Ethiopia'sPersonalDataProtectionProclamation1321/2024:whatyourorganisationhastodo

Proclamation 1321/2024 applies to every organisation handling personal data in Ethiopia, whatever its size. What it requires, and what to do about it.

Proclamation No. 1321/2024 is Ethiopia's first comprehensive personal data protection law. It applies to every data controller and processor regardless of size, revenue or headcount, and requires lawful processing, records of processing activities, data protection impact assessments, appointment of a data protection officer, and notification of personal data breaches within 72 hours.

Last reviewed

It almost certainly applies to you

The most common misreading of this law is that it is aimed at large organisations. It is not. Proclamation 1321/2024 applies to data controllers and processors regardless of size, revenue or number of employees. There is no small-business exemption to fall through.

If you hold personal data about identifiable people - customers, patients, students, employees, job applicants, suppliers' staff - you are a data controller. A twelve-person clinic with a patient list is covered. So is a private college with student records, a retailer with a delivery database, and a company whose only personal data is its own payroll.

The law is closely modelled on the GDPR, which is useful: the concepts, and much of the vocabulary, are the ones an international client or partner will already expect you to know.

What it requires

The obligations that most often require actual work:

RequirementWhat it means in practice
Lawful basis for processingFor every category of personal data you hold, a defensible reason for holding it - consent, contract, legal obligation. "We have always collected it" is not one.
Records of processing activitiesA written record of what you process, why, where it is stored, who it is shared with and how long you keep it. Most organisations have never written this down.
Data protection impact assessmentFor higher-risk processing, an assessment carried out before you start, identifying the risks to individuals and what you have done about them.
Data protection officerA named person responsible for compliance, with the standing to actually raise problems.
Data subject rightsA working process for handling requests for access, correction and deletion - within the statutory timeframe, not eventually.
Breach notification within 72 hoursNotify the Authority within 72 hours of becoming aware of a personal data breach, including the nature of the breach and the categories and approximate number of people affected. Affected individuals must be informed too.
Technical and organisational security measuresAccess control, encryption where appropriate, logging, and the ability to restore availability after an incident.

Summarised from published legal analyses of Proclamation No. 1321/2024. Confirm the requirements applying to your organisation against the proclamation itself and take legal advice where a decision turns on the detail.

The 72-hour clock is an engineering problem

Of everything in the proclamation, breach notification is the obligation most organisations are structurally unable to meet - and the reason is not legal.

The clock starts when you become aware of a breach. Most Ethiopian organisations have no logging worth the name, no alerting, and no way of telling whether data left the building. They do not miss the 72-hour deadline because they decide not to report; they miss it because six months later they still do not know anything happened.

The notification also has to say something. It must describe the nature of the breach and the categories and approximate number of data subjects affected. Answering that requires knowing what data you held, where it was, and who could reach it - which is the records-of-processing obligation, arriving from a different direction.

So the compliance work and the security work are the same work. An organisation that can detect an incident, scope it and report it accurately within three days has, by construction, built most of what the law asks for.

A realistic sequence

For an organisation starting from nothing, in the order that produces the most protection per week of effort:

  1. Find the personal dataEvery system, spreadsheet, shared drive, messaging group and third-party service holding data about people. This is always larger than expected, and it is the foundation for everything else.
  2. Write the record of processingWhat, why, where, who it is shared with, how long. This is a direct obligation and it is also the document you will need in an incident.
  3. Delete what you should not haveThe fastest reduction in risk available to most organisations. Data you do not hold cannot be breached, cannot be requested, and does not need protecting.
  4. Fix access controlIndividual accounts rather than shared ones, multi-factor authentication, and access that matches what someone's job actually requires.
  5. Build detection and the notification pathLogging and alerting, plus a written procedure naming who decides, who notifies the Authority, who tells affected individuals, and by when. Rehearse it once.
  6. Appoint the DPO and set a review cadenceA named person, with authority to escalate, and a recurring review so this does not decay the moment the project ends.

Questions people ask

Yes. Proclamation 1321/2024 applies to data controllers and processors regardless of size, revenue or number of employees. There is no small-business exemption. The proportionate response for a small organisation is smaller, but the obligations exist.

72 hours from becoming aware of a personal data breach, notified to the Authority, including the nature of the breach and the categories and approximate number of data subjects affected. Affected individuals must also be informed. The practical constraint is detection - you cannot report what you have not noticed.

The proclamation provides for appointment of a DPO. For a small organisation this is usually an existing person taking on a named responsibility rather than a new hire; what matters is that the role is held by someone with the standing to raise problems and get them acted on.

Proclamation 1321/2024 governs personal data and applies to everyone who handles it. Proclamation 1426/2026 governs critical infrastructure security and applies by designated sector. A private hospital is covered by both; a small e-commerce shop is likely covered only by the first.

Cross-border transfer is one of the areas the proclamation addresses, and it is one of the places where the detail matters and general summaries stop being useful. Get advice on your specific arrangements rather than relying on a page like this one.

Start with knowing what you hold

Most of this becomes tractable once the data inventory exists. Tell us what systems you run and we will tell you what we would look at first.