A school processing learner names, dates of birth, health information, guardian contacts and results is a data controller. Edves acts as a data processor on the school’s instructions; the registration obligation and the duties to learners and families remain the school’s.
The obligation most Ghanaian schools have not met
Act 843 was assented to in May 2012 and came into force in October 2012. It is administered by the Data Protection Commission, which holds registration, monitoring and enforcement powers.
Section 27(1) requires every data controller intending to process personal data to register with the Commission. Registration is valid for a period of two years and must then be renewed. The obligation is reinforced elsewhere in the Act, with penalties including fines and imprisonment.
A school holds learner names, dates of birth, photographs, guardian contact details, health and medical information, assessment results and fee records. That is personal data, some of it sensitive, and it makes the school a data controller.
Enforcement is changing. During 2026 the Data Protection Commission signalled a shift from awareness to enforcement. At the launch of Data Protection Week in January 2026 the Commission’s Executive Director stated there would be no exemptions from the registration requirement, and at the National Data Protection Conference in Accra in early March 2026 the sector minister confirmed a forthcoming policy directive for the Commission to impose fines on organisations that had not registered or complied. Schools that have never registered should treat this as a live compliance question, not a theoretical one. Confirm your position with the Commission directly.
Where the law is going
A Data Protection Bill 2025 has been drafted and publicly consulted, and government confirmed in March 2026 that it remained under development for introduction to Parliament. Until it is enacted, Act 843 remains the operative law. Any advice you receive based on the draft Bill is premature.
Controller and processor
- Your school is the data controller. It decides what learner data is collected and why. That responsibility does not transfer to a software supplier.
- Edves is a data processor, acting on the school’s documented instructions.
- Duties to learners and families — notice, lawful basis, access, correction — remain the school’s.
A supplier saying “we are compliant, so you are covered” has either misunderstood the allocation or is hoping you have. The correct answer to “are you compliant?” is: here is our processing agreement, here is where your data is hosted, here are our sub-processors, and here is what we will sign.
What Act 843 requires in practice
The Act sets out binding data protection principles covering, among other things, lawfulness, purpose specification, data minimisation, accuracy, retention, security and accountability, alongside data subject rights and rules on cross-border transfers.
For a school, that translates into a short list of practical questions:
- Are we registered with the Data Protection Commission, and is the registration current?
- Do we tell families what we collect and why, in language they can actually read?
- Do we collect data we do not need?
- Who in the school can see what, and can we prove it?
- How long do we keep learner records, and on what basis?
- Where is our data physically stored, and does it leave Ghana?
- What happens when a parent asks to see what we hold?
Most schools can answer two or three of these. Question four is usually the weakest.
How Edves handles learner data
- Role-scoped access to field level. A subject teacher sees their own classes; a bursar sees fees, not medical records; health and welfare records sit behind separate permissions.
- Audit logging on every access, with user, time and record. This is what converts an access policy into something enforceable, and it is the control school systems most often lack entirely.
- Configurable retention set to the school’s policy, not a supplier default.
- Data minimisation — the school decides what is collected; unused fields are not forced on it.
- Access request support, so a learner’s full record can be produced without a manual trawl.
- Cross-border transfer disclosure — hosting locations and sub-processors identified, which matters directly under Act 843.
AI and learner data
- Learner data is not used to train general-purpose AI models.
- It is not sold and not used for advertising or commercial profiling.
- Data used to personalise teaching stays within the school’s tenant.
- These terms are contractual, provided during procurement rather than asserted on a marketing page.
See AI in education.
The bigger practical risk
In most schools the realistic breach is not the procured system. It is:
- Learner records in a WhatsApp group that former staff are still members of.
- Result sheets and biodata on personal laptops and phones that leave with the teacher.
- A staff member pasting learner names and results into a consumer AI tool.
- Photographs of learners published for marketing with no record of parental consent.
- A departed bursar holding the only complete fee record.
A single system with proper access control and a leaver process helps with all of these. But policy has to arrive alongside the software, or the underlying pressure simply routes around it.
Data ownership and exit
| Question | Position |
|---|---|
| Who owns the data? | The school, stated in contract |
| Can we export everything? | Yes, including full academic and financial history, at any time |
| What does export cost? | Nothing, including at termination |
| Is access ever contingent on renewal? | No |
This page describes Edves’s posture and summarises publicly reported positions. It is not legal advice. Confirm your school’s obligations with the Data Protection Commission or your own legal adviser.