Ghana’s Data Protection Act, 2012 (Act 843) establishes foundational principles governing
lawful and secure processing of personal data but provides limited guidance on cross-border
data transfers, a regulatory gap that has become increasingly consequential in the context of
the African Continental Free Trade Area (AfCFTA). As digital trade, artificial intelligence
(AI), and cross-border service delivery expand across Africa, uncertainty regarding
international data transfers threatens privacy protection, regulatory compliance, and
economic integration. This paper examines how Ghana can reform its data protection regime
to enable secure cross-border data flows while safeguarding constitutional privacy rights and
national interests. Using doctrinal and comparative legal analysis, the study draws on two
contrasting yet complementary models: the ECOWAS Supplementary Act on Personal Data
Protection (2010), which prioritises regional harmonisation and mutual recognition, and
China’s Personal Information Protection Law (PIPL, 2021), which adopts a sovereignty
oriented and risk-tiered approach to outbound data transfers. The paper argues that Ghana
should adopt a hybrid regulatory model incorporating presumptive adequacy for regional
partners, standard contractual safeguards for international data transfers, and tiered security
assessments for high-risk data exports. Such reforms would align Ghana’s data protection
framework with AfCFTA digital trade obligations while strengthening the protection of
personal data and promoting Africa’s digital economy. This paper thus contributes to Africandigital governance scholarship and advances a scalable framework for reconciling free data
flows with privacy, security, and sustainable digital development.