Expansion
Regional Annexes
Last updated · 21 April 2026Version · 2026.04-rev1Governing law · Republic of Ghana
Vedge launches in Ghana and is expanding across Africa. When we begin processing data for a tenant in another jurisdiction, the country annex for that jurisdiction takes effect and the core Privacy Policy and DPA apply subject to the country-specific overrides below.
Status of each market:
- Ghana — live (primary jurisdiction).
- Nigeria — planned. Not yet operating.
- Kenya — planned. Not yet operating.
- South Africa — planned. Not yet operating.
Nigeria — NDPA 2023
On Nigerian launch, the Nigeria Data Protection Act 2023 and the NDPR 2019 apply to all personal data originating from or relating to data subjects in Nigeria.
- NDPC registration: Vedge will register as Major Data Processor of Major Importance with the Nigeria Data Protection Commission when our patient count in Nigeria crosses the threshold (200 data subjects / year for sensitive categories, including health).
- Breach clock:72 hours to the NDPC after becoming aware of the breach — stricter than Ghana’s “as soon as reasonably practicable.”
- DPO: mandatory under NDPR; our Ghana DPO also serves as DPO for Nigerian processing.
- Annual filing: Vedge will file the annual NDPC compliance audit by the statutory deadline.
- Cross-border: transfers out of Nigeria follow NDPR §2.11; SCCs in place with every relevant sub-processor.
Kenya — DPA 2019
On Kenyan launch, the Data Protection Act 2019 (Kenya) and the Office of the Data Protection Commissioner’s regulations apply.
- ODPC registration: mandatory for health-data processors regardless of size. Vedge will register as Data Processor before onboarding the first Kenyan tenant.
- Breach clock: 72 hours to the ODPC.
- DPIA: Vedge will complete a Data Protection Impact Assessment for health-data processing and file it with ODPC as required.
- Data localisation: while the Kenyan DPA does not mandate localisation, tenant preference is typically for af-south-1 (Cape Town) or a Kenyan region. Vedge can accommodate this on contract.
South Africa — POPIA
On South African launch, the Protection of Personal Information Act 2013 (POPIA) and the Regulations made under it apply to personal information entering or leaving South Africa.
- Information Officer: Vedge will register an Information Officer with the Information Regulator.
- §57 Prior Authorisation: processing personal information for health purposes combined with unique identifiers and transborder flows requires prior authorisation — Vedge will file this before go-live in SA.
- Operator Agreement (§21): every SA tenant signs a POPIA-compliant Operator Agreement in place of or as a rider to our standard DPA.
- Breach clock:“as soon as reasonably possible” to the Information Regulator and affected data subjects.