Ghana taps into digital public infrastructure to make data protection enforcement stick
Data protection commissioner, Dr Arnold Kavaarpuo, notes that the value of regulation is that citizens know their rights and how to enforce them, as well as being able to take part in generating economic value from their data.

Fintech pioneer-turned-regulator, Dr Arnold Kavaarpuo, is Ghana’s data protection commissioner. Image: Dr Kavaarpuo's LinkedIn
This story is part of GovInsider's Digital Trust & Cybersecurity Champions 2026 Special Report.
When Ghana’s data protection commission began pushing for data protection compliance, much of the country’s digital public infrastructure (DPI) was already built.
DPI refers to common digital foundations that allow citizens and businesses to transact securely in the digital economy.
In Ghana, a patchwork of digital IDs has been replaced with one Ghana Card, while fintech startups kept scaling digital payment solutions.
Data protection wasn’t a requirement in these early government agreements, says Ghana’s data protection commissioner, Dr Arnold Kavaarpuo.
The commissioner’s answer? Make compliance a condition of access.
For example, the National Identification Authority (NIA) will not let an organisation integrate with the national ID system without meeting data protection requirements.
While data protection exists on paper, enforcement is what Ghana’s Data Protection Commission (DPC) has been focusing on.
Where lapses occur, the fintech pioneer-turned-regulator tells GovInsider that it’s more often because a government agency or organisation has not understood what is required of it.
The commission is now working with sector regulators to embed data protection requirements at the licensing stage, expanding training and awareness workshops, and helping to organise data protection professionals nationwide, says Dr Kavaarpuo.
These interventions ensure that data protection gives people real agency in an increasingly digital and artificial intelligence (AI)-driven economy, instead of just rules on paper.
Devil is in the details of enforcement
Retrofitting data protection into systems has already begun, Dr Kavaarpuo says, with finding out how the systems are used.
When he stepped into his role, he noticed parties accessing government systems through application programming interfaces (APIs) and reselling the API access.
Government agencies that were connected to these APIs also had weak access controls.
Through spot checks, reports to the commission, and the industry intelligence, the commission then enforces the laws.
While the legal foundation was there, there is a lack of enforcement teeth, he notes.
Parliamentary Select Committee on Communications and Information to the commission's office, sharing about the latter's operations, financial performance, and forward strategy, while exploring how both parties can jointly advance Ghana’s data-governance agenda. Image: Dr Kavaapuo's LinkedIn
The data protection principle is grounded in the country’s 1992 Constitution, with the official Act rolled out in 2012 by the Parliament.
Although the commission started operations in 2015, there is still a lack of awareness on the importance of data protection among organisations, says Dr Kavaarpuo, adding that most complied only when asked by a regulator to obtain a certificate.
The work needs to be done at the granular level, he says.
The commission then wrote into the ministries and agencies with sectoral regulatory responsibilities, including the Bank of Ghana, the Public Utilities Regulatory Commission and the National Pensions Regulatory Authority.
Once data protection becomes a requirement, any organisations entering those sectors must subscribe to it.
For example, within the growing digital payments landscape, every fintech organisation needs to be data protection-certified, with electronic money issuers, schemes and payment aggregators registered with the commission.
“We realise who were the gatekeepers when it comes to the economy, then we would invest a lot of efforts with the enforcement and training,” he says, highlighting the Registrar of Companies as one of these gatekeepers.
Aside from the Parliament, the commission needed to work with the operating levels underneath the legislative structure, including the heads of civil service.
Closing compliance gap through training and an industry network
According to Dr Kavaarpuo, the gap between law and enforcement is not so much due to missing frameworks or laws, but because organisations are unaware of what the rules need from them.
“It was not until when we begin doing public education and awareness workshops, and training data protection offices, that we notice the real impact and visibility of the commission,” he says.
One of the core missions in his tenure was also to establish a professional association that brings together data protection professionals across sectors.
As the commission operates with a lean structure, he highlights the need to have “soldiers on the ground,” which led to the eventual launch of the Ghana Association of Privacy Professionals in October 2025.
“I don't want to be that regulator who is all over the place. I want that institution to be self-regulated.
“So that if I'm not there tomorrow, the institution can hold whoever sits in this chair responsible,” he notes.
The association comprises of more than 1,000 data protection professionals, focusing on training and awareness workshops.
The association also gives the commission a way to work with the wider economy.
Its members can press the commission to act, Dr Kavaarpuo says, and because their reach is broader than the commission's, they see what is really happening on the ground.
“Once [members] gain greater confidence in the commission, they become more proactive to inform you of the risks and what’s happening in the industry, which is more than you probably get from your audits or investigations.”
More than ‘a police guy with a hammer’
Dr Kavaarpuo takes a broader view of what a data regulator is for.
He sees his role in data protection morphing from one focused on privacy to broader data governance, especially in an AI-driven economy.
A regulator can choose to be "a police guy with a hammer" and beat organisations into order, he says.
Or they can use the principles of data protection to create economic value for the people whose data is collected.
Many data protection authorities lean on data minimisation, he notes, which is about collecting the least information possible.
If that is the main driver of the data regulator’s work, "you are not enabling innovation and the ecosystem,” he says.
Data protection, according to him, needs to give citizens the agency: “Start from the person whose data is being collected.”
He notes that the value of regulation is that citizens know their rights and how to enforce them, as well as being able to take part in generating economic value from their data.
He sees open banking and open data (both of which enable secure, consented sharing of citizen’s data with other providers) as ways to bring citizens "back into that economic layer.”
It’s something he advocates for as the Ghana’s representative at the Economic Community of West African States (ECOWAS). Another aspect is also data harmonisation across the region.
Success at the end of his tenure rests on a few things.
Firstly, an independent, well-resourced ecosystem that holds everyone accountable, including the commission.
The second is a stronger institution, with a wider presence of data protection officers across the country, more trained staff, and the ability to attract skilled people.
The third is more organisations registered with the commission and enough trained people to enforce compliance.
Finally, it’s to keep reviewing the Data Protection Act to enable a structural change.
“So, there's the act, but there are guidelines, directives and legislative instruments that we can use to really cement all of that.”
