Ghana does not have one single “anti-spam law”. Instead, a marketer sending newsletters from Accra or bulk SMS from Takoradi has to satisfy a handful of statutes and regulators that overlap. The good news is that they point in the same direction: get clear consent, identify yourself, make leaving easy and look after the data. This overview maps the landscape; our page on whether email campaigns are legal in Ghana goes deeper into the specific sections.
This is general information, not legal advice.
The regulators you should know
Data Protection Commission (DPC)
The DPC was set up under the Data Protection Act, 2012 (Act 843). It keeps the register of data controllers, receives complaints and can order an organisation to stop processing someone’s data. If your business holds customer names, phone numbers or email addresses, registration with the DPC is part of the cost of doing business in Ghana, and the certificate must be renewed every two years.
National Communications Authority (NCA)
The NCA licenses telecoms operators and value-added service providers. Its Unsolicited Electronic Communications Code of Conduct, issued under section 50 of the Electronic Transactions Act, 2008 (Act 772), sets opt-in, record-keeping and free-unsubscribe expectations for SMS and other electronic messages that reach subscribers in Ghana, including messages sent from abroad.
Cyber Security Authority (CSA)
The Cybersecurity Act, 2020 (Act 1038) created the CSA. It is not a marketing regulator, but its remit over cyber incidents and critical information infrastructure matters if you run email for a bank, telco or public body, and it reinforces the case for authenticated, secure sending.
Five rules that cover most situations
- Opt-in before promotion. Act 843, section 40 requires prior written consent for direct marketing. Stored electronic records count, so a timestamped web form works. Learn how to collect it in our permission guide.
- Every message must offer a way out. Act 772 requires an option to cancel in commercial electronic messages. In Mailpro, every campaign carries an unsubscribe link that removes the contact automatically.
- Be able to say where the data came from. Act 772 also requires you to disclose the source of a consumer’s details. Keep the source field on each contact up to date.
- Look after the data. Act 843 expects appropriate security safeguards and requires notifying the DPC and affected people of unauthorised access as soon as reasonably practicable.
- Do not trade lists. Act 843 prohibits the sale and purchase of personal data, so “Ghana business email lists” sold online are a legal risk as well as a deliverability one.
When GDPR enters the picture
Ghana’s diaspora is large, and many companies here serve customers in the UK, Germany or the Netherlands. The moment you email people located in the EU or UK, the GDPR or UK GDPR applies to them too, with its own consent and transparency rules. Our page on GDPR compliance at Mailpro explains how the platform supports those obligations.
Where your data lives
Act 843 does not force Ghanaian businesses to keep marketing data inside Ghana, but it does make you responsible for your processor’s security. Mailpro hosts data on private infrastructure in Switzerland, outside US jurisdiction. Switzerland is recognised by an EU adequacy decision, which helps when you also handle EU contacts. Mailpro has been operating since 2001, never sells or rents data and encrypts connections with TLS 1.3. The why Switzerland page sets out the reasoning.
SMS has its own flavour
Because almost every adult in Ghana is reachable by phone, SMS is where regulators see the most complaints. The NCA Code expects consent to be documented, sender information to be accurate and unsubscribing to be free. Read the SMS rules overview and our Ghana SMS marketing guide before your first bulk send.
A compliance checklist for Ghanaian senders
- Register with the Data Protection Commission if you process personal data, and diarise the two-year renewal.
- Publish a privacy notice explaining what you collect, why, and how people can object.
- Use unticked consent boxes, one per channel, and store the date, time and source of every opt-in.
- Identify yourself clearly as the sender in every email and SMS.
- Include a free, working unsubscribe option in every marketing message and act on it straight away.
- Keep transactional messages free of promotional content.
- Authenticate your email domain and protect access to your marketing accounts with strong passwords and two-factor authentication.
- Know what you would do, and whom you would notify, if your contact data were exposed.
Sector notes
Banks, fintechs and insurers
Financial brands are prime targets for phishing. Beyond marketing consent, invest in domain authentication, consistent sender names and customer education that tells people what you will never ask for by email or SMS.
Schools and universities
Contact lists often include parents and minors. Collect only what you need, send marketing to parents or adult students who opted in, and keep academic communications separate from fundraising or promotions.
NGOs and exporters
Donor and buyer lists often span Ghana, Europe and North America, so several laws may apply at once. Designing consent to the strictest standard, usually GDPR, keeps one process for everyone.
A law in transition
A Data Protection Bill intended to replace Act 843 was still being prepared for Parliament in 2026. Reported proposals include a renamed Data Protection Authority and mandatory impact assessments for higher-risk processing. Building your programme on documented consent now means little will need to change when the new law arrives.