Data Protection Nescience: The Governance Gap
Nescience is not the same as ignorance, and the distinction is worth insisting on. Ignorance describes information that was available and not taken up. Nescience is the deeper condition — the absence of knowledge, awareness or understanding altogether, usually unaccompanied by any sense that something is missing. It is not knowing that you do not know.
Data protection nescience refers to a lack of knowledge, awareness, or understanding of data protection principles and responsibilities. In today’s data-driven environment, nescience can become a significant governance and compliance risk.
In a data-driven economy, this is the more dangerous of the two. Negligence at least recognises the duty it has failed. Nescience does not recognise the duty at all, which is why it so rarely appears on a risk register and so reliably appears in a breach report.
Where nescience actually lives
It is tempting to locate the problem among junior staff. In practice it is distributed far more widely, and its most costly concentrations sit near the top.
It lives in the board that has never received a dedicated privacy report and does not know to ask for one. It lives in the executive who says, with complete sincerity, "IT handles all of that" — not realising that most privacy obligations are legal, human-resources and procurement obligations that no technology function can discharge. It lives in the HR manager who circulates a staff list with dates of birth attached, the marketing team that acquires a database without asking where it came from, and the operations lead who signs a vendor contract with no data-protection clause in it because no one told them one was needed.
None of these people is acting in bad faith. Every one of them is creating exposure. That is precisely what makes nescience a governance failure rather than a discipline problem: the individuals cannot be blamed for a standard that was never set, communicated or resourced.
Governance is not the policy; it is the practice
Most organisations, when challenged, will produce a privacy policy. Fewer can produce evidence that anyone has read it, that it reflects what the organisation actually does, or that it has been reviewed since it was written.
A policy is an artefact of intention. Governance is the operating rhythm that turns intention into practice, and it requires seven things working together: clear leadership that owns the outcome; defined responsibilities that name individuals rather than departments; accountability structures with reporting lines that reach the board; appropriate technical and organisational controls; regular, role-relevant training; documented risk assessment; and continuous monitoring that would detect failure before a regulator or a customer does.
Remove any one of these and the framework becomes decorative. Remove training and risk assessment together, and you have institutionalised nescience — a structure that looks like governance and knows nothing.
What the law already assumes
The Data Protection Act, 2012 (Act 843) does not treat knowledge as optional. It presumes it, and distributes the presumption across the organisation.
Section 17 makes the controller accountable for the privacy principles — and accountability is discharged with evidence, not intention. Section 58 requires a Data Protection Supervisor to oversee compliance, which presupposes someone competent enough to supervise. Section 27 requires registration with the Data Protection Commission, a declaration about processing that someone must understand well enough to make truthfully. Section 28 requires measures that are appropriate and reasonable — a judgement impossible to make without understanding the risk. Sections 29 and 30 require processors to be bound in writing, which assumes someone in procurement knows to ask. Section 31 requires notification of a security compromise within statutory timelines, which assumes staff can recognise a compromise when they see one.
Every one of these duties fails silently in the presence of nescience. The registration is filed and inaccurate. The Supervisor is appointed and untrained. The breach occurs and is not recognised as one for six weeks.
Five questions, answerable by everyone
A useful diagnostic requires no consultant. Ask any five people across the organisation — one director, one manager, one front-line officer, one IT staff member, one vendor — the same five questions: What personal data do we collect? Why do we collect it? How is it used? Who has access to it? How is it protected?
Where the answers converge, you have governance. Where they diverge — or where the question itself produces surprise — you have located your gap precisely, and at no cost.
From compliance to competence
Compliance is a status. It can be achieved accidentally, held briefly, and lost without anyone noticing. Competence is a capability: it survives staff turnover, scales with the business, and is visible in decisions taken before a regulator asks.
A mature framework does not merely satisfy the Commission. It changes what people do when no one is watching — the marketing officer who pauses before buying a list, the developer who asks about lawful basis at design stage, the director who requests the privacy report unprompted. At that point privacy has stopped being an obligation imposed on the organisation and become a property of it.
You cannot govern what you do not understand, and you cannot adequately protect data when those responsible for it lack the necessary knowledge.
Let us move from data protection compliance to data protection competence, accountability and governance.
Author has 70 publications here on modernghana.com
Disclaimer: "The views expressed in this article are the author’s own and do not necessarily reflect ModernGhana official position. ModernGhana will not be responsible or liable for any inaccurate or incorrect statements in the contributions or columns here."