Ethiopia Personal Data Protection Proclamation (No. 1321/2024)
Ethiopia's Personal Data Protection Proclamation No. 1321/2024, enacted in July 2024, establishes a comprehensive data protection framework. It creates the Information Network Security Administration (INSA) as the supervisory authority. The law establishes processing principles, data subject rights, controller obligations, and cross-border transfer restrictions. Applies to processing of personal data by public and private entities in Ethiopia.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (27)
Automated Decisions
| Code | Title |
|---|---|
| ET-DPP-16 | Automated Decision-Making and Profiling |
Breach
| Code | Title |
|---|---|
| ET-DPP-12 | Personal Data Breach Notification |
Chapter Four - Data Controllers and Processors
| Code | Title |
|---|---|
| Art. 33 | Criminal Offences |
| Art. 40 | Establishment and Composition |
| Art. 42 | Processing for Archiving Purposes |
| Art. 43 | Mediation of Disputes |
| Art. 47 | Existing Legal Procedures |
| Art. 49 | Collective Dispute Resolution |
Chapter One - General
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 5 | Prohibited AI Practices |
Chapter Six - Monitoring, Sanctions and Offences
| Code | Title |
|---|---|
| Art. 55 | Obligations for Providers of General-Purpose AI Models with Systemic Risk |
| Art. 58 | Scientific Research Data |
| Art. 59 | Entry into Force |
| Art. 60 | Initiation of Proceedings |
| Art. 64 | Transfer Based on Adequacy Decision |
Chapter Three - Rights of Data Subjects
| Code | Title |
|---|---|
| Art. 24 | Restrictions on Processing Unique Identification Information |
| Art. 25 | Criminal Penalties |
| Art. 27 | Fundamental Rights Impact Assessment for High-Risk AI Systems |
| Art. 28 | Notifying Authorities |
| Art. 29 | Application of a Conformity Assessment Body for Notification |
| Art. 31 | Designation of Chief Privacy Officer |
| Art. 32 | Entry into Force |
Chapter Two - Principles of Processing
| Code | Title |
|---|---|
| Art. 11 | Technical Documentation |
| Art. 13 | Transparency and Provision of Information to Deployers |
| Art. 17 | Quality Management System |
| Art. 18 | Documentation Keeping |
| Art. 20 | Corrective Actions and Duty of Information |
| Art. 22 | Authorised Representatives of Providers of High-Risk AI Systems |
| Art. 6 | Writing |
| Art. 7 | Minimum Standards |
| Art. 8 | Compliance with the Requirements |
| Art. 9 | Risk Management System |
Children
| Code | Title |
|---|---|
| ET-DPP-17 | Children's Data |
Consent
| Code | Title |
|---|---|
| ET-DPP-3 | Consent Standard |
DPIA
| Code | Title |
|---|---|
| ET-DPP-10 | Data Protection Impact Assessment |
Exceptions
| Code | Title |
|---|---|
| ET-DPP-22 | Climate, Sustainability, and Special Processing Exceptions |
Governance
| Code | Title |
|---|---|
| ET-DPP-8 | Data Protection Officer |
Lawful Basis
| Code | Title |
|---|---|
| ET-DPP-2 | Lawful Basis for Processing |
Marketing
| Code | Title |
|---|---|
| ET-DPP-15 | Direct Marketing |
PbD
| Code | Title |
|---|---|
| ET-DPP-18 | Privacy by Design and by Default |
Penalties
| Code | Title |
|---|---|
| ET-DPP-20 | Penalties and Enforcement |
Processors
| Code | Title |
|---|---|
| ET-DPP-13 | Processor Obligations and Contracts |
Public Sector
| Code | Title |
|---|---|
| ET-DPP-21 | Processing by Public Bodies |
Records
| Code | Title |
|---|---|
| ET-DPP-9 | Records of Processing |
Registration
| Code | Title |
|---|---|
| ET-DPP-7 | Controller and Processor Registration |
Regulator
| Code | Title |
|---|---|
| ET-DPP-6 | Personal Data Protection Commission |
Retention
| Code | Title |
|---|---|
| ET-DPP-19 | Retention and Erasure |
Rights
| Code | Title |
|---|---|
| ET-DPP-5 | Data Subject Rights |
Scope
| Code | Title |
|---|---|
| ET-DPP-1 | Scope and Territorial Application |
Security
| Code | Title |
|---|---|
| ET-DPP-11 | Security of Processing |
Sensitive Data
| Code | Title |
|---|---|
| ET-DPP-4 | Sensitive Personal Data |
Transfers
| Code | Title |
|---|---|
| ET-DPP-14 | Cross-Border Data Transfer |
Your Compliance Coverage
If you comply with Ethiopia Personal Data Protection Proclamation (No. 1321/2024), you already cover:
EU AI Act
33%
18 controls mapped
Compare →Serbia Law on Personal Data Protection (2018)
33%
18 controls mapped
Compare →Montenegro Law on Personal Data Protection (2023)
33%
18 controls mapped
Compare →+ 558 more: Law on Personal Data Protection (Official Gazette No. 42/2020) (33%), Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) (33%)
See all 561 mapped frameworks ↓Maps to 561 other frameworks
Frequently Asked Questions
What is Ethiopia Personal Data Protection Proclamation (No. 1321/2024)?
Ethiopia Personal Data Protection Proclamation (No. 1321/2024) is a compliance framework from Ethiopia with 27 domains and 55 controls. Ethiopia's Personal Data Protection Proclamation No. 1321/2024, enacted in July 2024, establishes a comprehensive data protection framework. It creates the Information Network Security Administration (INSA) as the supervisory authority. The law establishes processing principles, data subject rights, controller obligations, and cross-border transfer restrictions. Applies to processing of personal data by public and private entities in Ethiopia. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Ethiopia Personal Data Protection Proclamation (No. 1321/2024) have?
Ethiopia Personal Data Protection Proclamation (No. 1321/2024) has 55 controls organised across 27 domains. The largest domains are Chapter Two - Principles of Processing (10 controls), Chapter Three - Rights of Data Subjects (7 controls), Chapter Four - Data Controllers and Processors (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Ethiopia Personal Data Protection Proclamation (No. 1321/2024) map to?
Ethiopia Personal Data Protection Proclamation (No. 1321/2024) maps to 561 other compliance frameworks. The top mapping partners are EU AI Act (33% coverage), Serbia Law on Personal Data Protection (2018) (33% coverage), Montenegro Law on Personal Data Protection (2023) (33% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Ethiopia Personal Data Protection Proclamation (No. 1321/2024) compliance?
Start your Ethiopia Personal Data Protection Proclamation (No. 1321/2024) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Ethiopia Personal Data Protection Proclamation (No. 1321/2024) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 55 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required