Ghana Data Protection Act 2012: biometrics and identity verification
Apply Act 843 to identity verification: purpose, minimisation, lawful justification, retention, processors, incidents and the 2026 Ghana Card change.
In Ghana, a visual check of the Ghana Card no longer counts. In 2026 the National Identification Authority announced real-time biometric verification through its platform and said organisations must not copy or retain the card for identity verification except where the law permits it. For eKYC and biometric identity-verification teams, that raises a design question: once the NIA has responded, what data does the verifying organisation keep, and on what basis?
The Data Protection Act, 2012 (Act 843) has no single biometric rule. It sets a series of controls: lawfulness, defined purpose, minimality, notice, retention, security, processor governance and breach response. To defend an identity-verification flow under it, map each data object separately; a “biometric” label on the whole flow explains nothing.
The 2026 operating change
The NIA’s official notice on L.I. 2523 says the amendments came into force on 9 June 2026. It requires real-time biometric verification against the NIA database through the Identity Verification System Platform and states that visual inspection is insufficient. Organisations must not request, photocopy, scan or retain Ghana Card copies for identity verification unless permitted by law.
That is an operating rule for the Ghana Card. It does not make every local biometric operation lawful, and it does not let anyone keep an NIA response indefinitely. The Data Protection Act still governs the information an organisation obtains, creates, shares and retains.
An Act 843 control map

Question | Evidence to retain |
|---|---|
Purpose | the specific transaction and decision that need verification |
Data objects | user input, biometric signal, NIA response, score and logs |
Justification | consent or the applicable section 20 alternative |
Minimality | why each object is necessary, relevant and not excessive |
Retention | object-level period, deletion trigger and legal exception |
Vendors | role, instructions, access, location and written contract |
Incident | detection, containment, notification and restored integrity |
“Biometric data” is not one file or one legal conclusion
Act 843 defines personal data through identifiability. Its definition of special personal data does not expressly list biometrics as a standalone universal category. So you cannot assume that every face frame falls under the special-data classification. A face image, template, fingerprint response or linked identifier is still personal data whenever it relates to an identifiable individual.
The system inventory should distinguish:
a Ghana Card PIN or other identifier entered by the user;
a face, video or fingerprint signal received by the organisation;
a template or derived feature, if one is created;
the IVSP response and returned attributes;
a score, reason code, reviewer decision and event log;
diagnostics, backups and support-ticket contents.
One retention period for the whole bundle usually papers over several purposes. A process may justify keeping “identity verified” for audit. That justification does not stretch to the capture or a card image.
Lawful justification does not displace minimality
Section 20 of Act 843 sets prior consent as the general rule and lists alternatives, including contractual necessity, legal authorisation or requirement, protection of the data subject’s legitimate interest, a statutory duty and the legitimate interest of the controller or a third party. Pick the ground that fits the particular purpose, even when another checkbox would be easier.
Even with a valid ground, section 19 limits processing to information that is necessary, relevant and not excessive. Mandatory verification through NIA gives no licence to request every available attribute. The NIA’s onboarding process asks an institution for the law permitting its collection, a valid data-protection certification, the intended operational use and the datasets required.
Define the purpose before collection
Sections 22–23 of Act 843 require collection for a specific, explicitly defined and lawful purpose related to the controller’s activity, and steps to make the data subject aware of that purpose. “For security” is too vague to cover every downstream use.
Eligibility for account opening, duplicate-account prevention, returning-user authentication and model training are four separate purposes, and one consent screen cannot carry all of them. Run a separate analysis for each secondary operation: compatibility, justification, minimality, recipients and retention.
Design retention before launch
Section 24 of Act 843 prohibits retention beyond what is necessary for the collection and processing purpose unless a listed legal justification permits longer retention. At expiry, the record must be destroyed, deleted or de-identified in a way that prevents reconstruction in intelligible form.
Build an object-level schedule for the card image, capture, template, NIA response, final decision, technical event and backup. For each one, record the period owner, any legal exception, the event that starts the clock and evidence that deletion completed.
The NIA’s specific security, storage and retention guidelines for user agencies concern information obtained from the National Identification Register. Their scope does not extend to every company dataset. Where they do apply, the more specific NIA requirement wins over a generic corporate schedule.
Vendor use remains controller governance
Sections 28–30 of Act 843 require appropriate and reasonable technical and organisational controls, identification of foreseeable risks, regular verification of safeguards and updates as risks change. A processor acts with the controller’s knowledge or authorisation and under confidentiality; processing must be governed by a written contract. Where the processor is not domiciled in Ghana, the controller must ensure compliance with relevant Ghanaian law.
When you review a vendor, cover data objects, instructions, access, subprocessors, regions, logging, deletion, support and model-training restrictions. The public Biometric.Vision security page is one input to that review; you still need the contract and evidence from the actual deployment. Orchestrator can connect steps and record decisions; the organisation still determines the ground, NIA access and retention rules.
Build incident response around the data flow
Section 31 of Act 843 requires notice to the Commission and the data subject where there are reasonable grounds to believe personal data was accessed or acquired by an unauthorised person. Notice must follow as soon as reasonably practicable after discovery, subject to the statutory mechanism for delayed subject notice.
The runbook should connect a technical alert to legal triage: affected objects, reversibility, identities with access, decisions influenced by the data and restoration of system integrity. “The vendor will notify us” means little until someone names the channel, the escalation target, the timing commitment and the evidence owner.
Launch checklist
controller registration with the DPC has been addressed before processing;
NIA onboarding is distinct from the technology-vendor agreement;
the map shows what comes from NIA and what is generated locally;
justification is selected per purpose and minimality is tested separately;
Ghana Card copies are not used as a workaround for real-time verification;
captures, templates, responses, decisions, logs and backups have separate periods;
processor terms and access match the real deployment;
the incident runbook covers the Commission, subjects and integrity restoration.
Compliance with Act 843 takes more than a consent checkbox or a vendor certificate to prove. You need a traceable link from each purpose to its data objects, justification, retention and decision. Ghanaian counsel should validate the design before publication or deployment against current DPC, NIA and sector-regulator requirements.
Sources
Ready to strengthen your customer checks?
500 checks free every month · no card · no contract · no sales call.



