Mr Privacy

Mr Privacy Mr Privacy is an awareness initiative to create privacy and data protection awareness. Daily Educational Posts to educate the general public!

DAY 23: HOW LONG MAY YOU KEEP SENSITIVE DATA?"As long as necessary" has quietly come to mean "forever" in far too many G...
23/08/2026

DAY 23: HOW LONG MAY YOU KEEP SENSITIVE DATA?
"As long as necessary" has quietly come to mean "forever" in far too many Ghanaian organisations.

Section 24 of Act 843 is clear: personal data must not be retained longer than is necessary to achieve the purpose for which it was collected. For special personal data, every additional year of storage is an additional year of exposure.

Building a schedule that actually works:
• State the retention period for each category, and the event that starts the clock
• Name the legal or business driver — Bank of Ghana, GRA, the Labour Act, clinical standards, PRAAD for public bodies
• Where drivers conflict, the longest applicable statutory period governs that specific data, not the entire record
• Execute it, including backups, archives, data warehouses, test environments and paper files

A warning worth stating plainly: a retention policy that exists on paper but is never executed is worse than having none at all. It proves you knew what should have been destroyed and did not destroy it.

Twenty-year-old sick notes protect nobody.

DAY 22: MINIMALITY — THE CHEAPEST CONTROL YOU HAVEEveryone wants to talk about encryption. Almost nobody wants to talk a...
23/08/2026

DAY 22: MINIMALITY — THE CHEAPEST CONTROL YOU HAVE
Everyone wants to talk about encryption. Almost nobody wants to talk about collecting less.

Section 19 of Act 843 requires that processing be necessary, relevant and not excessive. Applied to special personal data, it is the single most effective control available to any organisation — and the cheapest.

Why minimality outperforms every technical control:
• Data you never collected cannot leak, cannot be subpoenaed, cannot be misused by an insider
• It costs nothing to store, nothing to secure and nothing to delete
• It never appears in a breach notification letter
• It requires no software, no licence and no consultant

The recurring over-collections in Ghana:
• Full Ghana Card images retained when only verification was needed
• Marital status, religion and hometown on forms with no stated purpose
• Medical history collected far beyond the reason for the appointment
• Next-of-kin details gathered from every customer regardless of relevance

Take your busiest form this week. Write the purpose beside every sensitive field. Delete what cannot be justified.

DAY 21: SENSITIVE DATA IN NGOs AND HUMANITARIAN WORKDevelopment and humanitarian organisations often hold the most sensi...
23/08/2026

DAY 21: SENSITIVE DATA IN NGOs AND HUMANITARIAN WORK
Development and humanitarian organisations often hold the most sensitive data in the country — about the most vulnerable people in it.

Health status. Disability. Displacement. Survivors of violence. Orphan and vulnerable child records. All special personal data under Act 843.

The problems specific to this sector:
• Consent that cannot be freely given. A beneficiary who fears losing food, medicine or school fees is not in a position to refuse.
• Donor reporting requirements driving collection of individual-level data well beyond programme need
• Case stories and photographs published for fundraising, with consent obtained in the same breath as the service
• Field data collected on personal phones and unencrypted tablets
• Projects ending with no plan for what happens to beneficiary records

Practical guidance:
• Report to donors in aggregate wherever individual-level data is not strictly necessary
• Obtain photograph and story consent separately from service consent, and make refusal costless
• Plan data disposal at project design, not at project closure

The people you serve trusted you at their most vulnerable. That trust is the programme.

DAY 20: SENSITIVE DATA IN FAITH ORGANISATIONSA subject we rarely discuss in Ghana, and should. Membership of a church, m...
23/08/2026

DAY 20: SENSITIVE DATA IN FAITH ORGANISATIONS
A subject we rarely discuss in Ghana, and should.

Membership of a church, mosque or other religious body is itself special personal data under Act 843 — it reveals religious belief. Add pastoral counselling notes, welfare records and health prayer requests, and a faith organisation holds some of the most sensitive information in any community.

Frequently overlooked:
• Membership databases copied and shared between branches and ministries without restriction
• Counselling and pastoral notes stored with no access control
• Welfare appeals announcing a member's name, illness or financial hardship publicly
• Prayer lists circulating health conditions on WhatsApp broadcast
• Contribution records used for purposes members never anticipated

None of this requires abandoning care for the congregation. It requires care of a second kind.

Faith organisations are data controllers under the law, with the same duties as any company. Ministry and confidentiality are not in tension — they belong together.

DAY 19: SENSITIVE DATA IN INSURANCENo sector processes more health data per customer than insurance. Underwriting, medic...
23/08/2026

DAY 19: SENSITIVE DATA IN INSURANCE
No sector processes more health data per customer than insurance.

Underwriting, medical examinations, claims assessment and reinsurance all involve special personal data under Act 843.

The pressure points:
• Medical reports circulating by unsecured email between broker, insurer, reinsurer and assessor
• Claims investigations that extend well beyond the claim into a claimant's private life
• Surveillance of claimants, often without any documented proportionality assessment
• Health declarations retained for decades after a policy has lapsed
• Broker and agent networks handling medical forms on personal devices

The governing principle is necessity. You may investigate a claim. That is not the same as investigating a person's entire life.

For brokers and agents specifically: the medical form in your bag is special personal data. Where it sleeps tonight matters.

DAY 18: SENSITIVE DATA IN SCHOOLSSchools in Ghana hold an extraordinary concentration of special personal data — about t...
23/08/2026

DAY 18: SENSITIVE DATA IN SCHOOLS
Schools in Ghana hold an extraordinary concentration of special personal data — about the people least able to protect it.

In a typical pupil file:
• Health conditions, allergies and medication
• Learning disabilities and special educational needs assessments
• Family circumstances, including bereavement, separation and financial hardship
• Disciplinary history
• Religion and ethnic origin, collected at admission

Where schools commonly go wrong:
• Admission forms requesting religion and hometown without any stated purpose
• Medical and special-needs information visible in staff rooms to teachers who do not teach the child
• Pupil records retained indefinitely, decades after the child has left
• Photographs published online without a working consent and opt-out
• Edtech platforms adopted without any assessment of what data they collect

A child's record should get smaller as they grow, not larger.

DAY 17: SENSITIVE DATA IN EMPLOYMENT AND HRHere is a question for every organisation: which department holds the most sp...
23/08/2026

DAY 17: SENSITIVE DATA IN EMPLOYMENT AND HR
Here is a question for every organisation: which department holds the most special personal data?

Not IT. Not Operations. HR.

What sits in a typical Ghanaian personnel file:
• Medical certificates, sick notes and occupational health reports
• Disciplinary records and police clearance certificates
• Religion, hometown and denomination captured at recruitment
• Next-of-kin details revealing family and marital circumstance
• Grievance files describing mental health, addiction or domestic difficulty

And who can access it? In many organisations, any line manager who asks.

Three fixes that cost nothing:
• Separate health records from the general personnel file, in a different cabinet or a restricted folder
• Grant access by role, not by seniority
• Delete recruitment data for unsuccessful candidates on a defined schedule

Your employees are data subjects with full rights under Act 843 — including the right to see their own file.

DAY 16: SENSITIVE DATA IN BANKING AND FINTECH"We only hold financial data — how does this apply to us?" I hear this ofte...
23/08/2026

DAY 16: SENSITIVE DATA IN BANKING AND FINTECH
"We only hold financial data — how does this apply to us?"

I hear this often from bankers. Then we open a customer file.

What is actually inside:
• Hometown fields revealing tribal or ethnic origin
• Medical reports supporting a loan restructuring or credit life policy
• Police reports and fraud allegations sitting in customer records
• Health declarations attached to insurance products sold at the branch
• Ghana Card images containing far more than the number you needed to verify

Financial data itself is not on the section 96 list. But the customer file almost always contains data that is — and once it does, the stricter regime applies to that file.

For digital lenders, one further warning: harvesting a borrower's contacts and messages collects data about people who are not your customers, never consented, and have no relationship with you. That is a serious exposure.

Open a file. Read it honestly. You will find more than you expected.

DAY 15: SENSITIVE DATA IN HEALTHCAREEvery patient folder in Ghana is a file of special personal data. So where is the re...
15/08/2026

DAY 15: SENSITIVE DATA IN HEALTHCARE
Every patient folder in Ghana is a file of special personal data. So where is the real risk?

Not usually the electronic system. It is the records room.

The exposures we see repeatedly:
• Patient folders in rooms accessible to cleaners, porters and visitors, with no log of who entered
• Clinical photographs captured on staff personal phones "for reference" and never deleted
• Test results disclosed to a relative who asked, without the patient's authority
• Diagnoses discussed at reception, within earshot of the waiting area
• NHIS and claims data shared with third parties without a written agreement

For facility managers: fix the lock before you buy the software. Train the porter as well as the doctor. A cleaner with access to a records room is a data protection risk in exactly the same way a hacker is.

Patient trust is clinical infrastructure. Once lost, people stop coming — and that is a health outcome, not just a compliance failure.

DAY 14: CONSENT — WHY THE BAR IS HIGHERConsent is the most used and least understood basis in Ghanaian practice. Under A...
15/08/2026

DAY 14: CONSENT — WHY THE BAR IS HIGHER
Consent is the most used and least understood basis in Ghanaian practice.

Under Act 843, consent must be freely given, specific, informed and unambiguous — a statement or clear affirmative action. For special personal data, each of those words carries weight.

Where consent routinely fails in Ghana:
• Employment. A staff member cannot freely refuse an employer's request for a medical certificate or biometric enrolment. The power imbalance defeats "freely given".
• Service access. Consent extracted as the price of treatment, credit or a benefit is not a choice.
• Bundling. One tick box covering health data, marketing and third-party sharing fails "specific".
• Silence. Pre-ticked boxes and continued use are not clear affirmative action.

And remember: consent can be withdrawn at any time. If you rely on it for something you must keep doing, withdrawal leaves you with no basis at all.

If the person cannot say no without penalty, you do not have consent. You have a signature.

Address

Accra
233

Alerts

Be the first to know and let us send you an email when Mr Privacy posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share