# Proclamation 1321/2024 makes patient data a legal duty, not a filing habit

> Ethiopia now has a comprehensive personal data protection law. Health data is classified as sensitive personal data, breaches must be reported to the regulator within 72 hours, and the obligations apply to private clinics — not only to hospitals.

Source: https://www.medicine.et/research/patient-data-protection-law  
Site: Bloom Medicine — https://www.medicine.et  
Last updated: 2026-07-25

---

Digital health · Data protection · published July 25, 2026

## Key findings

- Personal Data Protection Proclamation No. 1321/2024 is Ethiopia's first comprehensive data protection law.
- Health data is classified as sensitive personal data — Article 2(5) covers data on physical or mental health or condition — attracting heightened protection.
- The Ethiopian Communications Authority is the supervisory authority, and data breaches must be reported to it within 72 hours of discovery.
- Cross-border transfers require adequate protection in the destination jurisdiction, or explicit consent plus authorisation.

Until recently, "protecting patient data" in an Ethiopian clinic meant a lockable cabinet and a sense of professional discretion. **Personal Data Protection Proclamation No. 1321/2024** changed the basis of that obligation from custom to statute [1].

## What the law establishes

**Health data is sensitive personal data.** The proclamation defines sensitive personal data to include data relating to a person's *physical or mental health or condition* (Article 2(5)) [1]. That classification is the hinge: sensitive categories attract stricter conditions for lawful processing than ordinary personal data.

**There is a regulator.** The **Ethiopian Communications Authority** acts as the national data protection authority, with oversight over controllers and processors [1].

**Breaches have a clock.** Controllers must report a personal data breach to the Authority **within 72 hours of discovery** [1]. A 72-hour duty is only meetable if a clinic can determine, quickly, what data existed and who could access it — which is a records question before it is a legal one.

**Security is an active obligation.** Controllers must implement "appropriate technical and organisational measures" against unauthorised processing and accidental loss or damage [1].

**Cross-border transfer is conditional.** Sending personal data abroad requires either adequate protection in the destination jurisdiction, or explicit consent from the data subject plus authorisation [1]. For a clinic, this is the clause that governs cloud hosting, offshore backups, and any analytics or support arrangement that moves records outside Ethiopia.

**Data minimisation and retention limits apply.** Processing must be lawful, fair and transparent, and data kept "no longer than is necessary for the purposes" [1].

## Why this is harder on paper than on screen

The compliance burden falls awkwardly on paper-based clinics, for reasons the Ethiopian record-quality evidence makes concrete.

To answer a regulator, a clinic must be able to say what was held, about whom, and who touched it. In a review of 2,145 records across 73 public health facilities, **60.3% carried no date and/or signature** [2] — meaning there is often no record of *who wrote what, when*. That is a documentation problem in normal times and an evidentiary problem the moment anyone asks.

A digital record does not automatically solve this, and can create its own exposure. Ethiopian providers have raised data security and privacy concerns as a barrier to EMR adoption [3], and they are right to: a poorly configured system with shared logins and no audit trail concentrates risk rather than reducing it. The distinguishing feature of a compliant system is not that it is digital — it is that access is attributable and revocable.

## A practical starting checklist

1. **Know where the data is.** Charts, registers, lab books, phones with patient photos, spreadsheets, backups. The inventory precedes every other control.
2. **One identity per user.** Shared accounts make attribution impossible, and attribution is what a breach report requires.
3. **Write down a retention period** and apply it. "Keep everything forever" is not compatible with a necessity test.
4. **Decide the hosting question deliberately.** If records leave Ethiopia, the cross-border conditions apply [1].
5. **Have a breach procedure with names in it.** 72 hours is not enough time to invent one.

## What this note does not claim

This is a summary of secondary legal analysis, not legal advice, and not the statute. The provisions above are drawn from a law-firm country guide [1]; the authoritative text is the proclamation as published in the Federal Negarit Gazeta, and specific obligations, transition periods, thresholds and penalties should be verified against it — and with a qualified Ethiopian lawyer — before a clinic acts.

We have deliberately not repeated the sector-specific control counts that circulate in commercial compliance blogs, because we could not verify them against the statute. Nor is there yet Ethiopian enforcement case law to indicate how strictly the healthcare obligations will be applied in practice.

## References

1. DLA Piper. *Data Protection Laws of the World — Ethiopia*. dlapiperdataprotection.com country guide (covering Personal Data Protection Proclamation No. 1321/2024), 2025. https://www.dlapiperdataprotection.com/index.html?t=law&c=ET — Law-firm country guide, not the statute itself. Verify specific obligations against the Federal Negarit Gazeta text before relying on them.
2. Endriyas M, Kawza A, Alano A, Lemango F. *Quality of medical records in public health facilities: A case of Southern Ethiopia, resource limited setting*. Health Informatics Journal 28(3):14604582221112853, 2022. https://doi.org/10.1177/14604582221112853
3. Bekele TA, Gezie LD, Willems H, et al. *Barriers and facilitators of the electronic medical record adoption among healthcare providers in Addis Ababa, Ethiopia*. DIGITAL HEALTH 10:20552076241301946, 2024. https://doi.org/10.1177/20552076241301946
