One Address Ghana processes personal data of citizens and assembly officers. We are committed to handling that data lawfully, fairly, and securely, in accordance with the Data Protection Act, 2012 (Act 843) and the directions of Ghana's Data Protection Commission (the “DPC”). This page complements our Privacy Policy.
1. Our commitment
We treat the personal data entrusted to us as a responsibility, not an asset. We collect only what we need, use it only for the purposes we have explained, protect it with appropriate safeguards, and respect your rights as a data subject. Where MMDAs moderate records, they too are controllers and carry their own obligations under Act 843.
2. Registration with the Data Protection Commission
As an organisation that processes personal data in Ghana, we [are registered / are in the process of registering] as a data controller with the DPC under Act 843. Our registration reference is [registration number]. We renew our registration as required.
3. The data-protection principles we follow
We apply the principles set out in Act 843:
| Principle | What it means for us |
|---|---|
| Accountability | We are responsible for, and can demonstrate, our compliance. |
| Lawfulness of processing | We process data only with a valid lawful basis (section 4). |
| Specification of purpose | We collect data for clear, stated purposes and do not repurpose it incompatibly. |
| Compatibility / further processing | Any further use is compatible with the original purpose. |
| Quality of information | We keep data accurate and up to date, and enable you to correct it. |
| Openness | We are transparent about what we do, through these notices. |
| Data security safeguards | We protect data with technical and organisational measures (section 9). |
| Data subject participation | We uphold your rights to access, correct, and control your data. |
4. Our lawful basis for processing
Depending on the activity, we rely on: your consent; the performance of the service you have requested; the legitimate interests of a trustworthy, accountable address register (balanced against your rights); a public-interest task carried out by an MMDA; and compliance with legal obligations. The mapping of purposes to bases is set out in our Privacy Policy, section 5.
5. Special and sensitive personal data
Some data we handle is particularly sensitive and receives extra care:
- National ID — we store only a one-way hash of a Ghana Card number, never the raw number, PIN, or biometrics, and we do not connect to the NIA.
- Precise location — captured only with your device permission and only to pin a property.
- Photographs — stored to evidence a property; you are asked not to capture identifiable individuals or private interiors without a lawful basis.
We process special data only where permitted by Act 843, with appropriate consent and safeguards.
6. Your rights in detail
| Right | How it works here |
|---|---|
| Be informed | Through this page and our Privacy Policy. |
| Access | Request a copy of the personal data we hold about you. |
| Correction | Fix inaccurate data — much of it directly in the app. |
| Erasure | Delete your account and personal data, subject to lawful retention. |
| Object / restrict | Object to certain processing, including analytics. |
| Withdraw consent | Withdraw consent at any time, without affecting prior lawful processing. |
| Prevent processing likely to cause harm/distress | Ask us to stop processing that would cause you unwarranted damage or distress. |
| Complain | Lodge a complaint with Ghana's Data Protection Commission. |
7. How to make a data-subject request
To exercise any right above:
- Send your request to support@oneaddressghana.com, describing what you want (access, correction, deletion, etc.) and the account email or phone number involved.
- Verify your identity — we will ask for reasonable confirmation that the request is genuinely yours, to protect your data from others.
- We respond within the period required by Act 843, and in any case without undue delay. Reasonable requests are free; we may charge a proportionate fee only for manifestly excessive or repetitive requests, and will tell you first.
- If we cannot fully comply (for example, where we must retain certain records by law), we will explain why and what we can do.
For requests about a verified record already adopted into an MMDA's register, we may need to involve the relevant assembly as a joint controller, and will help route your request.
8. Cross-border data transfers
Our primary database and authentication are hosted in the European Union (Ireland). Where personal data is transferred outside Ghana, we ensure an adequate level of protection through appropriate safeguards — including contractual data-protection terms with our processors and the use of providers operating under recognised data-protection frameworks — consistent with Act 843's requirements on foreign processing.
9. Technical and organisational security measures
Technical
- Row-Level Security in the database, scoping every read and write to the entitled user or MMDA;
- TLS encryption in transit and encryption at rest;
- Hashing of passwords and Ghana Card numbers;
- Signed, time-limited media uploads and strict isolation of privileged keys from client apps;
- Server-side integrity controls preventing forgery of ownership, status, or verification;
- Audit logging, monitoring, and error tracking.
Organisational
- Least-privilege access for staff and officers, with role-based scoping;
- Confidentiality obligations and data-protection contracts with processors;
- Secure development practices and review before changes reach production;
- An appointed Data Protection Officer (section 12).
10. Data-breach notification
We maintain procedures to detect, contain, and assess personal-data breaches. Where a breach is likely to affect your rights, we will, as required by Act 843, notify the Data Protection Commission and the affected data subjects without undue delay, and explain what happened and the steps we are taking.
11. Retention schedule
| Data | Retention |
|---|---|
| Account & profile | While active; deleted/anonymised within [30 days] of account closure |
| Address records & photos | While active; verified records adopted into an MMDA register follow that assembly's rules |
| Audit & activity logs | [24 months] |
| One-time SMS codes | Minutes (expire shortly after issue) |
| Diagnostics / crash data | [90 days] |
12. Our Data Protection Officer
We have appointed a Data Protection Officer responsible for overseeing compliance and acting as your point of contact for any data-protection matter.