Wakilii
HomeKnowledge › How to complain about misuse of your personal data in Uganda

How to complain about misuse of your personal data in Uganda

Practice note Data & consumer Updated 6 July 2026 14 min read AI-assisted · review recorded

In brief

If your personal data is misused, you can complain to the data protection authority. Under the Data Protection and Privacy Act, Cap. 97, a data subject (or any person who believes a data collector, processor or controller is infringing their rights or breaching the Act) may complain, in the prescribed manner, to the Authority — the National Information Technology Authority - Uganda, operating through the Personal Data Protection Office (PDPO) (s.31). The Authority has power to investigate complaints (s.32), but it cannot itself award compensation — a data subject who has suffered damage or distress must apply to a court for that (s.33). You can also exercise direct rights — to access your data (s.24) and to have inaccurate data corrected (s.16) — and a decision of the Authority can be appealed to the Minister within 30 days (s.34).

1. At a glance

What this note covers

A person whose personal data has been misused in Uganda can complain to the Personal Data Protection Office, which must investigate and can direct remedial action — including ordering an organisation to register or to stop an unlawful practice. What the PDPO cannot do is award you money: compensation for damage or distress is a court remedy under s.33, not something the regulator itself can grant. This note walks through the complaint route end to end, using the PDPO's own published decision against Google LLC as a real worked example of how the process actually runs.

It is written for a data subject — an individual whose personal data has been misused, disclosed without consent, or held inaccurately — and for the advocates advising them. It does not cover an organisation's own compliance obligations under the Act generally (see the companion data-protection-uganda note) or a criminal prosecution for a data-protection offence, which proceeds separately through the ordinary criminal justice system.

Statutory references are to the 2023 Revised Edition of the Laws of Uganda (Data Protection and Privacy Act, Cap. 97). No amendment to the Act's substance has been found since 2019 — the 2023 consolidation only assigned the current chapter number, and whether that number survived the July 2024 renumbering exercise has not been independently confirmed.

2. Why the complaint route matters beyond a direct request

A data subject does not have to go straight to a formal complaint. The Act gives two direct, self-help rights that often resolve a problem faster and more cheaply than a regulatory complaint: the right to access personal data held about you (s.24) and the right to have inaccurate or misleading data corrected (s.16). Both can be exercised directly against the data handler, without involving the PDPO at all, and a cooperative organisation will often resolve a straightforward access or correction request without escalation.

The formal complaint route under ss.31-32 becomes necessary where a direct request is refused, ignored, or where the underlying misuse is more serious than a simple data error — unauthorised disclosure, sale of data, or a systemic failure to register or protect data properly.

3. Who can complain, and about what

Section 31(1) gives the right to complain broadly: a data subject, or any person who believes that a data collector, data processor or data controller is infringing or has infringed their rights, or is in violation of the Act, may make a complaint in the prescribed manner to the Authority. This is not restricted to the data subject alone — a person acting on behalf of a data subject, or a person who has witnessed a violation, can also trigger the process. Section 31(2) separately allows a data collector, processor or controller itself to make a complaint — for example, where one organisation believes another is mishandling data it shared with it.

A complaint need not allege only a personal wrong

A complaint can be about any breach of the Act, not only a breach of the complainant's own individual rights — 'infringing their rights, or is in violation of the Act' is disjunctive. This matters where the concern is systemic (for example, an organisation operating entirely unregistered) rather than a personal grievance.

4. The Authority's duty to investigate (s.32)

Section 32 imposes a mandatory duty, not a discretion: the Authority 'shall investigate every complaint' made to it and may direct remedial action. This is a meaningful procedural guarantee — a complainant is not at the mercy of the regulator's willingness to look into the matter at all, though the pace and depth of that investigation is a separate question from whether one happens.

The PDPO's own published decision in the Google matter shows what that investigation looks like in practice: the complaint was filed on 8 November 2024, the PDPO wrote to Google LLC requiring a response within 14 days, extensions were granted, Google's response was filed on 10 July 2025, and the decision itself issued on 18 July 2025 — roughly an eight-month cycle from complaint to decision on a substantial, contested matter involving a major international respondent.

Investigations take real time — set expectations

Manage a complainant's expectations on timing from the outset. The one documented example available — an eight-month cycle for a contested, high-profile complaint — suggests a genuine, thorough investigation is not a quick process, even though the duty to investigate is mandatory.

5. Worked example: the PDPO's decision against Google LLC

PDPO Complaint No. 08/11/24/6683, Ssekamwa Frank, Leni Sharon Pamela, Amumpaire Raymond and Awino Mercy v Google LLC, decided 18 July 2025, is the clearest available published illustration of the ss.31-32 process actually working. This is a regulatory decision of the PDPO, not a court judgment — it is discussed here for its practical, worked-example value only, and should never be cited or described as case law.

On the facts recorded in the decision, the PDPO found Google LLC in breach of s.29 (the registration requirement — Google had not registered as a data collector/controller/processor in Uganda) and s.19 (the cross-border data transfer rules). Its order was purely directive: it required Google to register and to provide evidence of compliance within 30 days. It did not, and expressly could not, award any compensation to the four complainants — the decision explicitly invoked s.33(1) to direct them to a court of competent jurisdiction for that remedy, stating plainly that 'PDPO does not have authority to award compensation or interest.'

A real result, but a limited one

The Google decision is the single best illustration available of what a PDPO complaint can and cannot achieve: a genuine finding of breach and a compliance order, but no money in the complainant's pocket. Set that expectation with any client considering a complaint over a court claim, or alongside one.

Press reporting (unverified beyond search-snippet level) suggested Google may have withdrawn an appeal of the decision in November 2025 following ministerial intervention — this should be treated as unconfirmed and not asserted as settled fact in any filing or advice.

6. Compensation is a court remedy, not a PDPO remedy

Section 33(1) is the pivotal provision for any client hoping to recover money through a PDPO complaint: 'where a data subject suffers damage or distress ... that data subject is entitled to apply to a Court of competent jurisdiction for compensation.' The right to compensation exists — but it is enforced through ordinary civil litigation, not through the Authority's own complaint process.

This is a structural feature of the Act, not an oversight of the PDPO in any individual case. Unlike some regional peers (Kenya's ODPC, Tanzania's PDPC), the PDPO has no statutory power to impose administrative fines or to award compensation itself — its own published commentary on this gap (echoed in independent commentary on the Google decision) records that PDPO itself regards this as an institutional weakness it wants Parliament to address.

Plan the compensation claim separately

Where real money is the client's primary goal, plan for a two-track approach from the start: a PDPO complaint to establish and formalise the breach (useful as supporting evidence), run alongside — or followed by — a civil claim in court under s.33(1) for the actual compensation. Do not tell a client the PDPO complaint alone will get them paid.

7. Appealing an Authority decision (s.34)

A person aggrieved by a decision of the Authority under the Act may appeal to the Minister (responsible for ICT and National Guidance) within 30 days of the decision (s.34(1)-(2)). This ministerial appeal route was the one actually invoked (per the Regulation-46 framing referenced in the Google matter) — the Act's own s.34 is the parent provision behind that Regulations-level appeal mechanism.

Both a complainant dissatisfied that a remedy went too far, and a respondent organisation dissatisfied that the Authority found against it, have access to this same appeal route — it runs to the Minister, not to a court, and the 30-day window is strict.

An appeal to the Minister is a materially different forum from a court appeal: the Minister is a political and administrative officer, not a judge, and the appeal proceeds under whatever process the Regulations prescribe rather than the rules of civil procedure. A client should understand that this route, while genuinely available, does not carry the same procedural guarantees (a full hearing, a reasoned written judgment, a further right of appeal) that a court appeal would.

The 30-day window is not to be missed

Calendar the 30-day appeal window the moment a decision is received. There is no indication in the Act or the Regulations that this deadline is extendable as of right — treat it the way you would treat any strict appeal timeline.

8. How the courts have treated ss.31-32 — an honest gap

No reported Ugandan court judgment applying or interpreting ss.31-32 of the Act was located in this note's research. This mirrors the position for the Act generally (see the companion data-protection-uganda note): the complaint mechanism is young, its enforcement activity to date has run through the regulator rather than through litigation, and the genuinely litigated compensation claims that s.33(1) contemplates do not yet appear to have produced a reported judgment.

The PDPO's own decision in the Google matter cites general Ugandan constitutional and administrative-law authority for reasoning purposes only — Total Uganda Ltd v URA (HC Civil Appeal No. 6 of 2001), AG v Salvatori Abuki (Constitutional Appeal No. 2 of 1997), and Tinyefuza v AG (Constitutional Appeal No. 1 of 1996) — none of which is itself a data-protection case, and none of which should be cited as authority specific to the DPPA complaint mechanism.

9. Consequences for a data handler who ignores a complaint process

Ignoring a PDPO investigation or a compliance notice issued in the course of one carries its own separate penalty exposure: non-compliance with a PDPO notice/order under Regulation 48 attracts a fine not exceeding 3 currency points per day of default (UGX 60,000/day) or imprisonment not exceeding 6 months, or both — verified directly from the PDPO's own decision quoting the Regulation.

Beyond that per-day penalty, a data handler who is found in breach after refusing to cooperate with an investigation faces the same substantive s.35-38 criminal exposure described in the companion data-protection-uganda note, and — as the Google decision shows — a public, published finding of breach that a public register and regulator decision make permanently visible.

10. Practical guidance for a complainant

Document the direct request first

Before lodging a formal complaint, send a clear written access or correction request directly to the data handler (ss.24, 16), and keep proof it was sent and received. This creates a paper trail showing you tried the direct route first, which strengthens a later complaint if the direct request is refused or ignored.

Build the evidentiary record before filing

Gather concrete evidence before complaining: what data was misused, by whom, when, and what harm or distress resulted. A complaint built on vague suspicion is far harder for the PDPO to investigate effectively than one with dates, screenshots, or specific disclosures identified.

Start planning the s.33(1) claim early

If compensation is the real goal, do not wait for the PDPO process to conclude before consulting counsel about a parallel or follow-on civil claim under s.33(1) — the PDPO's finding of breach, once made, is useful supporting evidence for that claim, but the claim itself must be brought in court.

Plan for a genuinely multi-month process

Where the respondent is a large or foreign organisation, expect the PDPO process to move slowly — the Google matter took roughly eight months from filing to decision, with formal response deadlines and at least one extension along the way. Prepare the client for that timeline honestly rather than promising a quick regulatory fix.

11. Common pitfalls

  • Not trying a direct access (s.24) or correction (s.16) request before or alongside a complaint.
  • Complaining without concrete evidence of the data misused and the resulting harm.
  • Not using the prescribed complaint form or process under the Regulations.
  • Assuming the police or the courts are the first port of call — the PDPO investigates data-protection complaints under ss.31-32.
  • Expecting the PDPO to award compensation directly — that remedy runs through the courts under s.33(1).
  • Missing the 30-day window to appeal an Authority decision to the Minister (s.34).
  • Citing the Ssekamwa v Google PDPO decision as 'case law' rather than what it actually is — a regulatory decision.

12. Grey areas and points to confirm

No reported Ugandan court judgment applying ss.31-32 of the Act has been located — treat this as the honest current state of the law, and advise a client accordingly rather than implying settled judicial guidance exists.

Whether any complaints beyond the Google matter have been decided and published by the PDPO could not be confirmed — no public decisions archive or database beyond that single decision was located in this note's research. If a client asks how many complaints the PDPO has decided, the honest answer is that only one published decision is currently known.

Press reporting that Google withdrew its appeal in November 2025 following ministerial intervention is search-snippet-only and has not been independently confirmed — do not present it as settled fact.

The exact Regulation numbers referred to for complaint procedure and the Regulation 48 penalty were verified only via the PDPO's own decision quoting them directly, not an independent read of the Regulations PDF (a non-machine-readable scan) — confirm directly with the PDPO before citing a specific regulation number in a filing.

13. Practitioner checklist

  1. Try a direct access (s.24) or correction (s.16) request with the data handler first, and keep proof of it.
  2. Gather evidence of the misuse — the data, the person responsible, and the resulting harm or distress.
  3. Lodge a complaint in the prescribed manner with the Authority (PDPO) under s.31.
  4. Cooperate with the Authority's investigation under s.32 and expect a genuinely multi-month process for a contested matter.
  5. If compensation is the goal, prepare a parallel or follow-on civil claim under s.33(1) — the PDPO cannot award it.
  6. Calendar the 30-day window to appeal an unfavourable Authority decision to the Minister (s.34).

14. Recent developments to watch

The Ssekamwa v Google decision (18 July 2025) is, on the research available for this note, the most substantial published exercise of PDPO's ss.31-32 powers to date, and it is worth watching for two reasons beyond its own facts. First, it is a rare public illustration of PDPO actually applying the Act against a major multinational respondent, rather than the smaller domestic operators (like the microfinance lender in the separately reported Mugulusi criminal matter) that press coverage more commonly features. Second, its own reasoning explicitly flags PDPO's lack of fining and compensation powers as a gap the regulator itself wants Parliament to close — a legislative reform that would, if it happens, materially change the practical advice in this note by giving the Authority a genuine financial deterrent it currently lacks.

Watch also for whether PDPO begins publishing a fuller archive of its complaint decisions. At the time of this note's research, only the single Google decision was publicly located — if PDPO starts publishing routinely, that will materially change how much genuine precedent (albeit regulatory, not judicial) practitioners have to draw on when advising a complainant on what outcome to expect.

15. Sources and further verification

Every statutory reference in this note is to the 2023 Revised Edition of the Laws of Uganda. The Ssekamwa v Google PDPO decision should be read in full, and kept clearly labelled as a regulatory/administrative decision rather than case law, before any proposition is drawn from it for a live matter.

  • Data Protection and Privacy Act, Cap. 97 (2023 Revision) — ss.16, 24, 31, 32, 33, 34.
  • Data Protection and Privacy Regulations, 2021 — complaint form/process and Regulation 48 (penalty for non-compliance with a PDPO notice; verified indirectly, see grey areas).
  • PDPO Complaint No. 08/11/24/6683, Ssekamwa Frank & 3 Others v Google LLC (decided 18 July 2025) — regulatory decision, not a court judgment.
  • Statutory text verified against the consolidated Laws of Uganda as at 31 December 2023. Sourced from the Uganda Legal Information Institute (ulii.org).
Was this practice note helpful? Your feedback helps us improve.
Last updated: 6 July 2026.
Next currentness review: 17 August 2027.
This note is a practitioner orientation, not legal advice, and does not create an advocate–client relationship. Ugandan law changes and chapter and section numbers were revised in the 2023 Laws of Uganda. Verify every statute, rule and authority against the current primary source — and the specific facts of your matter — before filing or relying on it.