Ethiopia’s Data Sovereignty Regime: A Framework in Search of Enforcement
On 24 July 2024, the Personal Data Protection Proclamation No. 1321/2024 (the “Proclamation”) entered into force, establishing Ethiopia’s first comprehensive legal framework for the protection of personal data. Among its most significant features is the recognition of data sovereignty as a statutory principle, introducing important requirements concerning the storage, processing, and cross-border transfer of personal data.
This legal update examines the principal data sovereignty and cross-border transfer requirements under the Proclamation, their practical implications for data controllers and processors, and the current state of implementation. The analysis is based on the legal framework currently in force and publicly available information as of August 2026.
The Proclamation expressly recognises data sovereignty as a fundamental principle of personal data protection. Article 6(7) requires personal data to be processed in a manner that ensures the sovereignty of the data. This principle is given practical effect through the Proclamation’s requirements concerning local storage, critical personal data, and cross-border transfers.
The most significant requirement is contained in Article 22(1), which requires every data controller and processor to ensure that personal data collected or obtained locally is stored on a server or data centre located in Ethiopia. This establishes a general data localisation requirement and has potentially significant implications for organisations that rely on foreign cloud infrastructure or international data hosting arrangements. The Full update is attached above.