Biometric
Biometrics & eKYCUpdated September 24, 20267 min

Ghana Data Protection Act 2012: biometrics and identity verification

Apply Act 843 to identity verification: purpose, minimisation, lawful justification, retention, processors, incidents and the 2026 Ghana Card change.

In Ghana, a visual check of the Ghana Card no longer counts. In 2026 the National Identification Authority announced real-time biometric verification through its platform and said organisations must not copy or retain the card for identity verification except where the law permits it. For eKYC and biometric identity-verification teams, that raises a design question: once the NIA has responded, what data does the verifying organisation keep, and on what basis?

The Data Protection Act, 2012 (Act 843) has no single biometric rule. It sets a series of controls: lawfulness, defined purpose, minimality, notice, retention, security, processor governance and breach response. To defend an identity-verification flow under it, map each data object separately; a “biometric” label on the whole flow explains nothing.

The 2026 operating change

The NIA’s official notice on L.I. 2523 says the amendments came into force on 9 June 2026. It requires real-time biometric verification against the NIA database through the Identity Verification System Platform and states that visual inspection is insufficient. Organisations must not request, photocopy, scan or retain Ghana Card copies for identity verification unless permitted by law.

That is an operating rule for the Ghana Card. It does not make every local biometric operation lawful, and it does not let anyone keep an NIA response indefinitely. The Data Protection Act still governs the information an organisation obtains, creates, shares and retains.

An Act 843 control map

Ghana biometric identity control map
Editorial map based on Act 843 and the NIA notice on L.I. 2523. The applicable justification and retention period depend on the deployment and sector rules.dataprotection.org.gh

Question

Evidence to retain

Purpose

the specific transaction and decision that need verification

Data objects

user input, biometric signal, NIA response, score and logs

Justification

consent or the applicable section 20 alternative

Minimality

why each object is necessary, relevant and not excessive

Retention

object-level period, deletion trigger and legal exception

Vendors

role, instructions, access, location and written contract

Incident

detection, containment, notification and restored integrity

Act 843 defines personal data through identifiability. Its definition of special personal data does not expressly list biometrics as a standalone universal category. So you cannot assume that every face frame falls under the special-data classification. A face image, template, fingerprint response or linked identifier is still personal data whenever it relates to an identifiable individual.

The system inventory should distinguish:

  • a Ghana Card PIN or other identifier entered by the user;

  • a face, video or fingerprint signal received by the organisation;

  • a template or derived feature, if one is created;

  • the IVSP response and returned attributes;

  • a score, reason code, reviewer decision and event log;

  • diagnostics, backups and support-ticket contents.

One retention period for the whole bundle usually papers over several purposes. A process may justify keeping “identity verified” for audit. That justification does not stretch to the capture or a card image.

Lawful justification does not displace minimality

Section 20 of Act 843 sets prior consent as the general rule and lists alternatives, including contractual necessity, legal authorisation or requirement, protection of the data subject’s legitimate interest, a statutory duty and the legitimate interest of the controller or a third party. Pick the ground that fits the particular purpose, even when another checkbox would be easier.

Even with a valid ground, section 19 limits processing to information that is necessary, relevant and not excessive. Mandatory verification through NIA gives no licence to request every available attribute. The NIA’s onboarding process asks an institution for the law permitting its collection, a valid data-protection certification, the intended operational use and the datasets required.

Define the purpose before collection

Sections 22–23 of Act 843 require collection for a specific, explicitly defined and lawful purpose related to the controller’s activity, and steps to make the data subject aware of that purpose. “For security” is too vague to cover every downstream use.

Eligibility for account opening, duplicate-account prevention, returning-user authentication and model training are four separate purposes, and one consent screen cannot carry all of them. Run a separate analysis for each secondary operation: compatibility, justification, minimality, recipients and retention.

Design retention before launch

Section 24 of Act 843 prohibits retention beyond what is necessary for the collection and processing purpose unless a listed legal justification permits longer retention. At expiry, the record must be destroyed, deleted or de-identified in a way that prevents reconstruction in intelligible form.

Build an object-level schedule for the card image, capture, template, NIA response, final decision, technical event and backup. For each one, record the period owner, any legal exception, the event that starts the clock and evidence that deletion completed.

The NIA’s specific security, storage and retention guidelines for user agencies concern information obtained from the National Identification Register. Their scope does not extend to every company dataset. Where they do apply, the more specific NIA requirement wins over a generic corporate schedule.

Vendor use remains controller governance

Sections 28–30 of Act 843 require appropriate and reasonable technical and organisational controls, identification of foreseeable risks, regular verification of safeguards and updates as risks change. A processor acts with the controller’s knowledge or authorisation and under confidentiality; processing must be governed by a written contract. Where the processor is not domiciled in Ghana, the controller must ensure compliance with relevant Ghanaian law.

When you review a vendor, cover data objects, instructions, access, subprocessors, regions, logging, deletion, support and model-training restrictions. The public Biometric.Vision security page is one input to that review; you still need the contract and evidence from the actual deployment. Orchestrator can connect steps and record decisions; the organisation still determines the ground, NIA access and retention rules.

Build incident response around the data flow

Section 31 of Act 843 requires notice to the Commission and the data subject where there are reasonable grounds to believe personal data was accessed or acquired by an unauthorised person. Notice must follow as soon as reasonably practicable after discovery, subject to the statutory mechanism for delayed subject notice.

The runbook should connect a technical alert to legal triage: affected objects, reversibility, identities with access, decisions influenced by the data and restoration of system integrity. “The vendor will notify us” means little until someone names the channel, the escalation target, the timing commitment and the evidence owner.

Launch checklist

  • controller registration with the DPC has been addressed before processing;

  • NIA onboarding is distinct from the technology-vendor agreement;

  • the map shows what comes from NIA and what is generated locally;

  • justification is selected per purpose and minimality is tested separately;

  • Ghana Card copies are not used as a workaround for real-time verification;

  • captures, templates, responses, decisions, logs and backups have separate periods;

  • processor terms and access match the real deployment;

  • the incident runbook covers the Commission, subjects and integrity restoration.

Compliance with Act 843 takes more than a consent checkbox or a vendor certificate to prove. You need a traceable link from each purpose to its data objects, justification, retention and decision. Ghanaian counsel should validate the design before publication or deployment against current DPC, NIA and sector-regulator requirements.

Sources

Starter pack · free

Ready to strengthen your customer checks?

500 checks free every month · no card · no contract · no sales call.

Or message us onTelegramWhatsApp— we reply within 5 minutes

Read also