Wakilii

Simbwa Phillip v Chipper Technologies Uganda Limited

Tribunal · [2025] PDPO 1 · 2025 Application Partly Allowed AI-generated summary ↓ Download Pin to watchlist Add to matter
Jurisdiction
Uganda
Case Type
Complaint to the Personal Data Protection Office alleging denial of data deletion request and infringement of data protection rights
Decision
Complaint dismissed with no infringement found; respondent directed to amend privacy notice to clarify consent requirements for data processing beyond regulatory compliance

Observed later treatment

No later-treatment classification is recorded for this judgment.

Citator coverage is limited to judgments in the Wakilii corpus and source-matched treatment records. Absence of a signal is not an assertion that the case remains good law.

AI-generated summary. This summary was generated by AI from the full text of the judgment. It may contain errors or omissions—always read the source judgment before relying on it.

Holding

The Personal Data Protection Office held that the respondent's retention of KYC and transactional data for ten years under the Anti-Money Laundering Act was lawful and did not infringe the complainant's data deletion rights. However, the respondent must obtain explicit consent before processing or sharing retained data beyond regulatory compliance purposes. The respondent's privacy notice adequately addressed notification obligations regarding data breaches and subcontractor access. No infringement was found, but the respondent was directed to amend its privacy notice to clarify consent requirements for additional data processing.

Outcome

Complaint dismissed with no infringement found; respondent directed to amend privacy notice to clarify consent requirements for data processing beyond regulatory compliance

Facts

On 25 November 2024, the complainant requested Chipper Technologies Uganda Limited to delete his personally identifiable information and KYC data. The respondent replied on 26 November 2024, requiring the complainant to cash out all funds before deletion and committing to address the request within 12-24 working hours. Dissatisfied, the complainant lodged a complaint with the Personal Data Protection Office on 27 November 2024. The respondent informed PDPO that it had fulfilled the deletion request but retained KYC and transactional data to comply with the ten-year retention requirement under the Anti-Money Laundering Act. The complainant raised additional concerns including lack of explicit consent for data processing beyond retention, notification of data breaches, notification when subcontractors access his data, and provision of a copy of all collected data. The PDPO reviewed the parties' submissions and the respondent's privacy notice.

Issues

  1. Whether there was an infringement of the Complainant's rights under the Data Protection and Privacy Act Cap. 97.
  2. If there was infringement, what remedies are available to the Complainant.

Orders

  • PDPO finds no infringement of the Complainant's rights under the Data Protection and Privacy Act Cap. 97.
  • The Respondent is required to explicitly clarify in its Privacy Notice that processing or sharing of retained personal data beyond regulatory compliance obligations necessitates prior explicit consent from data subjects.
  • The Complainant retains the right to seek remedies through legal action pursuant to Section 33 of the Act Cap. 97 should the Respondent breach its commitments.
  • Failure by the Respondent to adhere to this decision constitutes an offence under Regulation 48 of the Data Protection and Privacy Regulations, punishable by a fine of three currency points per day of default or imprisonment not exceeding six months, or both.
  • Any party aggrieved by this decision may appeal to the Minister of ICT and National Guidance within thirty days from the date of receipt of this decision.

Rules and key headnotes

Data Protection — Right to Deletion — Statutory Retention Obligations
A data controller's retention of KYC and transactional data for the period mandated by the Anti-Money Laundering Act does not infringe a data subject's right to request deletion of personal data under the Data Protection and Privacy Act, as the retention is required by law and therefore lawful.
Data Protection — Consent Requirements — Processing Beyond Compliance
Where a data controller retains personal data for regulatory compliance purposes, explicit consent from the data subject is required before the controller may process or share that data for any purpose beyond regulatory compliance during the retention period.
Data Protection — Data Breach Notification — Role of PDPO
Under the Data Protection and Privacy Act, a data controller must immediately notify the Personal Data Protection Office of any data breach. The PDPO then assesses the breach and, if necessary, instructs the controller to notify affected data subjects. Direct notification to data subjects is not automatic but depends on the PDPO's assessment of the circumstances.
Data Protection — Liability for Unauthorised Disclosure
Liability for unauthorised disclosure of personal data is governed by statute. A data subject may seek compensation through a court of competent jurisdiction if a data controller's non-compliance results in damage or distress. A data controller cannot agree to or decline unconditional liability in advance, as liability is determined by law based on violations of the Act.
Data Protection — Transparency Obligations — Subcontractor Access
A data controller satisfies its transparency obligations under the Data Protection and Privacy Act by disclosing in its privacy notice the general categories of subcontractors and third parties who may access personal data, and by establishing a mechanism to notify data subjects in advance of material changes to those categories.
Data Protection — Right of Access — Data Portability
The Data Protection and Privacy Act grants data subjects the right to access their personal data held by a data controller but does not confer a specific right to data portability. A data subject seeking access must submit a formal request in the format prescribed by the Data Protection and Privacy Regulations.

Legislation cited (10)

Full judgment

↓ Download PDF

The original judgment as reported. Read the original PDF before relying on any passage.

Simbwa Phillip v Chipper Technologies Uganda Limited [2025] PDPO 1 (12 March 2025)
Source: this page presents Wakilii’s issue analysis and metadata for a publicly reported Ugandan judgment. Any AI-generated summary is marked as such. Judgment text is sourced from the Uganda Legal Information Institute (ulii.org). Wakilii is not affiliated with ULII.