Audio By Carbonatix
The National Identification Authority (NIA) has issued binding guidelines governing how organisations that access data from the National Identity Register (NIR) must store, secure, and eventually dispose of that personal information, effective Thursday, March 19, 2026.
The guidelines, issued under the authority of the National Identity Register Act, 2008 (Act 750) as amended by Act 950 of 2017, are directed at so-called "user agencies", the banks, telecoms companies, government institutions, and other bodies that routinely pull personal data from the NIR for administrative and verification purposes.
The NIA said the guidelines are designed to "ensure that personal information is stored and retained securely and only for as long as necessary," while promoting responsible data management and minimising "the risks of unauthorised access, misuse, or loss of data."
The authority added that the guidelines are intended to ensure compliance with Ghanaian law and alignment with international standards on data protection and information security.
The legal basis for the guidelines rests on Sections 59 and 61 of Act 750, which mandate the NIA to prescribe retention periods for personal information used by user agencies and to guide on how that data should be handled once collected.
In practical terms, this means agencies that collect NIR data, whether for SIM card registration, financial services onboarding, or public sector administration, will now be required to operate within a clear regulatory framework that sets limits on how long they can hold that data and what security standards they must meet while doing so.
The move comes as Ghana continues to deepen its digital identity ecosystem.
The Ghana Card, which the NIA issues, has become a central fixture of everyday life, required for everything from opening a bank account to accessing government services and registering a mobile number.
The sheer volume of personal data flowing through user agencies as a result has made clear data governance rules increasingly urgent.
Ghana's Data Protection Act, 2012 (Act 843) already places general obligations on organisations that process personal data.
User agencies are expected to study and implement the guidelines with immediate effect from Thursday, March 19, 2026.
Latest Stories
-
GH¢2 billion was collected to clean Ghana. So why is Accra still this filthy?
28 minutes -
Sedina Tamakloe Acquittal: Prof Gyampo says corruption fight cannot survive prosecutorial incompetence
2 hours -
Bole-Bamboi MP Yusif Sulemana thanks well-wishers after earning PhD in Business Administration
2 hours -
15 suspected galamseyers arrested near Obuasi school after viral video exposes site
2 hours -
Court of Appeal ignored ‘mountain of evidence’ in Sedina’s acquittal – Alfred Tuah-Yeboah
2 hours -
Minority Leader criticises government over governance, economy and tribunal law
2 hours -
Unemployed Graduates with Disabilities give government one-week ultimatum over GES recruitment
2 hours -
Akim Swedru MP slams COCOBOD Act over restrictions on cocoa farmers’ land use
2 hours -
Mahama cites viral ‘Buz Stop Boys’ video to urge better sanitation practices
2 hours -
Fuel prices could change daily as Bulk Oil Distributors abandon fixed pricing model
2 hours -
Minority criticises Minerals Commission over alleged ‘shoddy’ mining leases
2 hours -
NPPÂ gears up for Oti Regional Elections with 219 accredited delegates
2 hours -
The Law 101: Burden of Proof, Defective Charges, and Constitutional Safeguards -Sedina Christine Tamakloe Attionu v. The Republic (Suit No: H2/17/2026)
2 hours -
Ghana’s 24-Hour economy needs strong foundations to deliver – Prof. Amoah
2 hours -
When they come for you, send them to me – Sam Jonah’s message to new UCC Vice-Chancellor
2 hours