The Data You Didn't Know You Were Collecting: Guard Management and Ghana's Data Protection Act
Guard rostering, biometric clock-ins and patrol apps make the client organisation a data controller under Act 843, with the guarding or CCTV vendor as its processor. Here is what Ghanaian organisations need to check.
Ask a facilities manager what their security operation produces and most will say guard hours, incident reports and CCTV footage. Few will say “personal data at scale” — yet that is precisely what a modern guarding contract generates. Biometric attendance terminals, GPS-tracked patrol apps, visitor management tablets and cloud-hosted rostering platforms all collect, store and transmit personal information about employees, contractors and visitors. In Ghana, that activity falls squarely inside the Data Protection Act, 2012 (Act 843) — and most organisations that operate it have never asked who is actually accountable for it.
This is not a theoretical compliance gap. It sits at the intersection of physical security, HR administration and IT procurement, three functions that rarely talk to each other about data ownership. That gap is where liability accumulates quietly, then surfaces at the worst possible moment — a regulator enquiry, a vendor breach, or a legal dispute involving a dismissed guard’s biometric record.
What your security operation is actually collecting
Walk through a typical Ghanaian site contract and the data footprint is larger than most stakeholders realise:
- Biometric clock-in/out systems capturing fingerprint or facial templates for guards, cleaners and sometimes staff — often stored on a vendor’s server, not the client’s.
- Patrol and lone-worker apps logging GPS coordinates, timestamps and photographs, frequently retained indefinitely on a supplier’s cloud dashboard.
- Visitor management platforms scanning national ID cards, photographing visitors and storing the data alongside host names and visit purposes.
- CCTV systems with analytics — facial recognition, licence-plate reading, people-counting — that process biometric or near-biometric data even when nobody watches the footage live.
- Incident and investigation reports naming individuals, describing conduct, sometimes referencing health information (an injury, a medical emergency, a mental health episode during an incident).
Individually, each system looks like an operational tool. Collectively, they constitute a personal data processing operation that a hospital, bank or manufacturer is legally responsible for, regardless of whether the guarding company or a third-party software vendor built the platform.
The compliance gap: who is the data controller?
Act 843 draws a clear distinction between a data controller (the entity that determines why and how data is processed) and a data processor (the entity processing it on the controller’s instructions). In most Ghanaian guarding arrangements, the client organisation is the controller — it commissioned the security programme and benefits from the data — while the guarding company or software vendor is the processor.
The problem is that contracts rarely say so. Standard guarding agreements in Ghana typically cover deployment, supervision ratios, equipment and SLAs, but say almost nothing about data processing terms, retention periods, sub-processor use, or what happens to biometric templates when the contract ends. Under Act 843, a data controller must:
- Register with the Data Protection Commission if processing falls outside the narrow exemptions.
- Process personal data only for a specified, lawful purpose that the data subject has been informed of.
- Apply appropriate technical and organisational security measures.
- Not retain data longer than necessary for the stated purpose.
- Ensure any processor it engages provides equivalent guarantees.
Guarding and CCTV vendor contracts are rarely reviewed against these obligations, and the question of where the data physically resides is asked even less often.
Where the risk actually bites
Three scenarios illustrate the exposure, none of them exotic:
Offshore hosting. Many patrol and workforce-management apps are white-labelled international platforms with servers outside Ghana, sometimes outside West Africa entirely. Data sovereignty — control over where data sits and under whose legal jurisdiction — has become a live cybersecurity theme globally, and it applies just as much to a guard’s fingerprint template as to a bank’s transaction records. If a vendor’s overseas server is breached, the Ghanaian data controller carries the reputational and regulatory consequence, not the vendor.
Subcontracted guarding. Guarding companies routinely subcontract shifts or share rostering systems across multiple client sites. Personal data — including biometric templates — can end up accessible to staff and systems well beyond the scope the data subject was told about.
Contract termination. When a guarding or CCTV contract ends, what happens to the stored biometric and visitor data? Most termination clauses cover equipment removal and final invoicing; almost none specify secure deletion of personal data, leaving a live but unmanaged repository sitting with a former vendor.
Building a defensible framework
Treating security workforce and visitor data as a compliance-relevant asset — not just an operational convenience — requires four practical moves:
1. Map the data flows. List every system on site that captures personal or biometric data (attendance and access control, patrol, visitor, CCTV analytics), who hosts it, where the servers are, and who has access. Most organisations have never done this exercise for security systems specifically, even where IT has done it for core business applications.
2. Fix the contracts. Guarding, CCTV maintenance and software vendor agreements should include explicit data processing clauses: purpose limitation, retention periods, sub-processor disclosure, breach notification timelines, and secure deletion obligations at contract end.
3. Minimise by default. Not every site needs facial recognition analytics on its CCTV or indefinite GPS logging. Configure systems to collect and retain only what the stated security purpose requires, and set automatic deletion schedules rather than relying on manual housekeeping.
4. Register and train. Confirm Data Protection Commission registration status, and brief control room and HR staff on their obligations when handling guard biometric records, visitor logs and incident reports containing personal detail.
Quick-reference checklist
- Have you listed every system on site that collects biometric, GPS or personal visitor data?
- Do your guarding and CCTV vendor contracts specify data ownership, hosting location and retention?
- Is your organisation registered with the Data Protection Commission for this processing?
- Do sub-processors or subcontracted guards have documented, limited data access?
- Is there a defined, enforced process for deleting personal data at contract end?
- Have control room and HR staff been briefed on their handling obligations under Act 843?
Closing
Security operations were built to manage physical risk, but the systems that support them have quietly made every guarding contract a data protection matter as well. Closing that gap starts with an honest inventory of what your current arrangements actually collect, store and expose — the kind of finding that typically emerges from a structured baseline security assessment rather than a routine vendor review. Until that mapping is done, the exposure sits unmeasured, which in risk management terms is the most expensive place for it to be.
Start with a risk assessment
Every SGT engagement starts with a structured, evidence-led assessment. Tell us about your sites and we'll scope it within one business day.
