Wakilii
HomeKnowledge › Data protection obligations in Uganda

Data protection obligations in Uganda

Practice note Data & consumer Updated 6 July 2026 17 min read AI-assisted · review recorded

In brief

Anyone who collects, processes or holds personal data in Uganda must comply with the Data Protection and Privacy Act, Cap. 97. Its principles (s.3) require those handling personal data to be accountable to the data subject and to collect and process data fairly, lawfully and only to the extent adequate, relevant and not excessive. Personal data may generally only be collected and processed with the data subject's consent (s.7), for a specified purpose, after giving the data subject the required information. A data protection register is maintained by the Authority (the National Information Technology Authority - Uganda), operating through the Personal Data Protection Office (PDPO).

1. At a glance

What this note covers

The Data Protection and Privacy Act, Cap. 97 sets out the principles every data collector, processor or controller in Uganda must follow: accountability, fairness, lawfulness, purpose limitation, and minimality. Consent is the default legal basis for collecting and processing personal data, special personal data gets extra protection, and the Personal Data Protection Office (PDPO) — administratively under NITA-U but legally independent in its decision-making — keeps a public register of who is handling personal data. This note covers the statutory framework: who it binds, what it requires, and what non-compliance costs.

It is written for any business, organisation or individual that collects, processes, holds or uses personal data in Uganda — from a bank running KYC checks to a small fintech app storing customer phone numbers. It does not cover the mechanics of lodging a complaint about a specific breach (see the companion pdpo-complaint-uganda guide) or sector-specific data rules that sit alongside the DPPA (banking confidentiality, telecom interception law, and so on), which need separate advice.

The Act is genuinely and currently cited as Cap. 97 in the 2023 Revised Edition of the Laws of Uganda — confirmed independently through ULII's own document title, the PDPO's own published decisions, and the consolidation's front matter. No amendment to the substance of the Act itself has been found since it was enacted in 2019; the 2023 consolidation only assigned it its current chapter number. Whether Cap. 97 survived the July 2024 seventh-edition renumbering exercise (which reassigns chapter numbers thematically across fourteen volumes) has not been independently confirmed — re-check the chapter number periodically.

2. Why Uganda has a dedicated data protection law

Before the Data Protection and Privacy Act, 2019, Uganda had no general statute governing how organisations collect, store or use personal information — protection depended on scattered sector rules (banking confidentiality, the constitutional right to privacy) with no dedicated regulator and no registration regime. The Act filled that gap: it created a single, general framework that applies across sectors, established the PDPO as a dedicated regulator, and gave data subjects a defined set of rights they can invoke directly against anyone handling their data.

The Act tracks the shape of comparable data protection statutes in the region and beyond (principles, consent, a rights regime, a registration requirement, a complaints mechanism) but with a materially weaker enforcement toolkit than some peer regulators — a point developed further below and in the grey-areas section, since it shapes what a client can realistically expect from non-compliance.

3. Who the Act binds: collectors, processors, controllers

The Act's obligations attach to a 'data collector', 'data processor' and 'data controller' — in substance, anyone who collects, processes, holds or uses personal data, whether directly or on another person's behalf. This is deliberately broad: it catches a bank running its own credit checks, a payroll bureau processing employee records for a client company, and a mobile money platform storing transaction histories, without needing separate categories for each business model.

Size does not exempt an organisation

Do not assume the Act only binds large or sophisticated organisations. A small business that keeps a simple spreadsheet of customer phone numbers and national ID numbers is a data collector for these purposes and is bound by s.3's principles just as much as a bank is.

4. The statutory framework: the s.3 principles

Section 3 sets the core principles that anchor the whole Act. A person who collects, processes, holds or uses personal data must: (a) be accountable to the data subject for data collected, processed, held or used; (b) collect and process data fairly and lawfully; and (c) collect, process, use or hold only data that is adequate, relevant and not excessive or unnecessary, given the purpose for which it was collected.

Data Protection and Privacy Act, Cap. 97

Every other operative provision in the Act — consent, purpose limitation, special-data protection, correction, access — is best read as an application of these three principles to a specific stage of the data lifecycle (collection, use, correction, disclosure). Losing sight of the s.3 anchor makes the later, more granular sections feel like an unconnected checklist rather than a coherent framework.

Read the three principles together

The s.3 principles fit together as a lifecycle test: accountability asks who answers for the data; fairness and lawfulness ask how it was obtained and handled; and adequacy/relevance/non-excessiveness asks whether the volume and type of data collected actually matches the stated purpose. Apply all three whenever a client asks 'can we collect this?' — the answer is rarely a single yes/no, but a fit against all three.

6. Special personal data: extra protection under s.9

Section 9(1) prohibits collecting or processing personal data revealing a person's religious or philosophical beliefs, political opinion, sexual life, financial information, or health status or medical records, subject to the exceptions in s.9(2)-(3) — for example, where the data subject has given express consent, or processing is necessary for specific, recognised purposes such as medical treatment or the establishment of a legal claim.

Financial information sitting inside 'special personal data' is easy to overlook: a bank or fintech that processes ordinary transaction records is handling special personal data by definition, not merely ordinary personal data — the extra layer of care s.9 demands applies from the first transaction, not only once a client's data starts looking obviously sensitive.

7. Data-subject rights: access and correction

A data subject has a right to access their own personal information held by a data collector, processor or controller (s.24), and a right to have inaccurate or misleading personal data corrected (s.16). These rights are the practical lever an individual has to check what an organisation holds about them and to fix errors without needing to go through a complaint to the Authority at all — though a complaint remains available where a data handler refuses or ignores such a request (see the companion pdpo-complaint-uganda note).

Have an access/correction workflow ready

Build a simple internal process for responding to an access or correction request before one arrives. An organisation that has no process for handling a s.24 access request, or a s.16 correction request, is at real risk of the request escalating straight into a PDPO complaint under s.31 — entirely avoidable with a basic response workflow.

8. Registration: the data protection register (ss.29-30)

The Authority — NITA-U, operating through the PDPO — keeps and maintains a data protection register and registers every data collector, controller and processor as required (s.29). The register is open to public access (s.30), so registration is not merely an internal compliance record but a public statement that an organisation handles personal data and is accountable to the regulator for it.

Registration is renewed annually and typically requires an annual compliance report; the exact current registration fee and the compliance-report deadline are matters of Regulations and PDPO practice rather than the Act itself, and should be confirmed directly with the PDPO before advising a client on cost (see the grey-areas section).

9. The PDPO's place inside NITA-U

Section 4(1) establishes the Personal Data Protection Office as 'responsible for personal data protection under the Authority [NITA-U], which shall report directly to the Board [NITA-U's Board].' Structurally, then, the PDPO is not a separate statutory body or legal person in its own right — it is administratively housed within NITA-U and reports to NITA-U's own governing board.

That administrative housing is deliberately balanced against s.5(3), which insulates the Office's actual decision-making: 'the office in performing its functions under this Act shall not be under the direction or control of any person or Authority.' The PDPO itself embraces both framings simultaneously, describing itself publicly as 'Uganda's independent data protection office ... established as an independent office under [NITA-U]' — a description consistent with the statutory split between administrative housing (s.4) and functional independence (s.5(3)).

Section 6 is an internal duty, not the PDPO itself

Every institution handling personal data — not just the PDPO — must designate its own internal Data Protection Officer under s.6, distinct from the PDPO's own National Personal Data Protection Director. This is a genuine, separate obligation, easy to overlook because it is easy to conflate 'the data protection office' generally with the specific national regulator.

10. How the courts have treated the Act — an honest gap

This is the section where honesty matters more than completeness. No reported Ugandan court judgment interpreting or applying the Data Protection and Privacy Act, Cap. 97, was located in the research for this note. That is a real, notable finding in its own right, not a research gap to be papered over with an unrelated citation — the Act is comparatively young (2019), Ugandan court reporting lags actual litigation, and the enforcement activity that exists so far has run through the regulator rather than the courts.

Two data points illustrate where enforcement activity has actually occurred, and why neither is a substitute for genuine judicial precedent. Press reporting (Monitor, ICLG, African Law & Business, PC Tech Mag) described a criminal conviction — Uganda v Ronald Mugulusi, resolved by plea bargain at the Makindye Standards, Wildlife and Utilities Court on 10 July 2025 — of the director of a microfinance lender for failing to register with PDPO and unlawfully using a borrower's personal data (reported 'WhatsApp shaming' of a defaulting borrower), resulting in a UGX 300,000 fine. No citable neutral citation or primary court record for this matter could be located — it is real, on the balance of the press coverage, but should not be cited as a verified precedent without a primary court record.

Separately, the PDPO itself has issued at least one substantive published decision under its own investigatory powers: Ssekamwa Frank & 3 Others v Google LLC, PDPO Complaint No. 08/11/24/6683, decided 18 July 2025, in which the PDPO found Google LLC in breach of the registration requirement (s.29) and the cross-border transfer rules (s.19), and ordered registration within 30 days. This is a genuine, on-the-record exercise of the PDPO's statutory powers and is discussed in detail in the companion pdpo-complaint-uganda guide — but it is an administrative/regulatory decision of the PDPO, not a court judgment, and should never be cited or described as 'case law' or judicial precedent.

No court case law yet — say so plainly

Do not cite the Ssekamwa v Google PDPO decision, or the Mugulusi conviction, as court 'case law' interpreting the DPPA. The honest, correct statement for a Ugandan data-protection matter today is that no reported court judgment interpreting Cap. 97 has yet been located — advise clients accordingly and rely on the statute itself, the Regulations, and the PDPO's own published guidance/decisions where available.

11. Consequences of getting it wrong

The Act's penalty structure is expressed in currency points, at UGX 20,000 per point (confirmed directly from the Act's own Schedule). Unlawfully obtaining or disclosing personal data attracts a fine not exceeding 240 currency points (UGX 4,800,000) or imprisonment for up to 10 years, or both (s.35(2)). Unlawful destruction, deletion or alteration of personal data carries a fine of not less than 240 currency points, or up to 10 years' imprisonment, or both (s.36(2)). Selling personal data attracts a fine not exceeding 245 currency points (UGX 4,900,000) or up to 10 years, or both (s.37(2)). A corporate offender faces an additional fine of up to 2% of its annual gross turnover (s.38(2)).

Beyond the Act's own criminal penalties, the Regulations add administrative-style penalties for registration and compliance failures — a false statement on a registration application can attract a fine not exceeding 6 currency points (UGX 120,000) or 3 months' imprisonment, or both, and non-compliance with a PDPO notice can attract a fine not exceeding 3 currency points per day of default (UGX 60,000/day) or up to 6 months' imprisonment, or both. These Regulation-level figures were verified via the PDPO's own published decision quoting them directly, rather than an independent read of the Regulations PDF (see grey areas).

There is also a real reputational and commercial cost that sits outside the statute's own text: an unregistered or non-compliant data handler exposed by press reporting or a PDPO decision (as with the Google matter) suffers a public compliance finding that a public register makes permanently visible.

12. The PDPO's own acknowledged enforcement gap

A structural point worth flagging to any client assessing real-world risk: unlike some regional peers (Kenya's Office of the Data Protection Commissioner, Tanzania's Personal Data Protection Commission), the PDPO itself has no power under the Act to impose administrative fines. Its own published decision in the Google matter expressly disclaimed any power to award compensation to a complainant, directing them instead to the courts under s.33(1) — and commentary on that decision records the PDPO's own acknowledged view that this is a genuine institutional weakness it wants Parliament to address.

PDPO cannot fine or award compensation itself

Manage a client's expectations honestly: the PDPO can investigate, make findings, and issue directions (such as ordering registration), but it cannot itself fine a non-compliant organisation or award compensation to an aggrieved data subject. Genuine financial redress for a data subject runs through the courts under s.33(1), not through the PDPO's own complaint process.

13. Practical guidance for compliance

Start with a data map, not a policy document

Build a simple data map before anything else: what personal data is collected, from whom, for what stated purpose, and who inside the organisation is accountable for it. Every other compliance step — consent language, registration, an internal DPO — is easier once this map exists, and near-impossible to get right without it.

Purpose-specific consent, not catch-all clauses

Draft consent and privacy notices in plain language that actually states the specific purpose of collection, per ss.11-13 — a vague, catch-all consent clause ('we may use your data for any purpose') sits uneasily against both the purpose-specificity requirement and the s.3(c) adequacy/non-excessiveness principle.

Register early and calendar the renewal

Register with the Authority promptly once an organisation is handling personal data at any meaningful scale, and calendar the annual renewal and compliance-report deadline — a lapsed registration is exactly the kind of gap a PDPO investigation (or an opportunistic complaint) is most likely to catch first, as the Google decision itself illustrates.

14. Common pitfalls

  • Collecting personal data without consent or beyond the stated purpose (ss.7, 11-13).
  • Gathering excessive or unnecessary data relative to the stated purpose (s.3(c)).
  • Treating financial or health information as ordinary data rather than special personal data requiring extra care (s.9).
  • Ignoring data-subject rights to access and correction (ss.24, 16) until they escalate into a PDPO complaint.
  • Failing to register with the Authority, or letting registration lapse without renewal (s.29).
  • Assuming the internal Data Protection Officer duty under s.6 is satisfied simply because PDPO exists — it is a separate, per-institution obligation.
  • Assuming a PDPO finding of breach is 'case law' — it is a regulatory decision, not a court judgment.

15. Grey areas and points to confirm

No reported Ugandan court judgment interpreting or applying the Data Protection and Privacy Act, Cap. 97, has been located — treat this as the current, honest state of the law rather than an oversight in this note's research. If a client-facing situation genuinely needs judicial authority (for example, in civil litigation for compensation under s.33), be clear that the claim will likely be a matter of first impression before the Ugandan courts.

The exact Regulations section numbers referred to above (registration fee provisions, the false-information penalty, the non-compliance-notice penalty) were verified only indirectly — through the PDPO's own published decision quoting them, and a secondary registration-process explainer — because the Data Protection and Privacy Regulations, 2021 PDF available online is a non-machine-readable scan. Confidence is high given the regulator quotes its own Regulations directly, but a direct read of the Regulations text is recommended before quoting a specific regulation number in a filing.

The registration fee (reported at UGX 100,000) and the certified-copy fee (reported at UGX 25,000) are corroborated by two independent secondary sources but were not read directly from the primary fee schedule — confirm the current figure with the PDPO before quoting it to a client.

Whether the Act's Cap. 97 designation survived the July 2024 seventh-edition renumbering of the Laws of Uganda (which reassigns chapter numbers thematically across fourteen volumes) has not been independently confirmed — re-verify the chapter number periodically before it is relied on in a formal filing.

Press reporting that Google LLC withdrew an appeal of the PDPO's decision in November 2025 following ministerial intervention is search-snippet-only and has not been independently confirmed — do not assert it as settled fact.

16. Recent developments to watch

The Data Protection and Privacy Regulations, 2021 took effect on 12 March 2021, and the PDPO became operational in August 2021 — both comparatively recent milestones, meaning the compliance and enforcement ecosystem around the Act is still young by the standards of longer-established regulatory regimes.

The PDPO's July 2025 decision in the Google matter is the most substantial published exercise of its investigatory powers found in this note's research, and is worth monitoring for a published archive of further decisions — at the time of this note's research, no public decisions database or archive beyond that single decision was located.

17. Sources and further verification

Every statutory reference in this note is to the 2023 Revised Edition of the Laws of Uganda, cross-checked against the Data Protection and Privacy Act's full consolidated text and the PDPO's own published decision quoting the Regulations. Confirm the current chapter number and Regulation numbers directly with the PDPO before a formal filing.

  • Data Protection and Privacy Act, Cap. 97 (2023 Revision) — ss.3, 4, 5(3), 6, 7, 9, 11-13, 16, 17, 24, 29, 30, 35(2), 36(2), 37(2), 38(2).
  • Data Protection and Privacy Regulations, 2021 (in force 12 March 2021) — registration and procedural detail (regulation numbers verified indirectly; see grey areas).
  • PDPO Complaint No. 08/11/24/6683, Ssekamwa Frank & 3 Others v Google LLC (decided 18 July 2025) — a regulatory decision, cited for its worked-example value only, never as case law.
  • Statutory text verified against the consolidated Laws of Uganda as at 31 December 2023. Sourced from the Uganda Legal Information Institute (ulii.org).
Was this practice note helpful? Your feedback helps us improve.
Last updated: 6 July 2026.
Next currentness review: 17 August 2027.
This note is a practitioner orientation, not legal advice, and does not create an advocate–client relationship. Ugandan law changes and chapter and section numbers were revised in the 2023 Laws of Uganda. Verify every statute, rule and authority against the current primary source — and the specific facts of your matter — before filing or relying on it.