Wakilii

Ssekamwa Frank and 3 others v Google LLC (Complaint No. 08 11 24 6683)

Tribunal · [2026] PDPO 086 · 2025 Application Partly Allowed AI-generated summary ↓ Download Pin to watchlist Add to matter
Jurisdiction
Uganda
Case Type
Complaint lodged with the Personal Data Protection Office alleging contraventions of the Data Protection and Privacy Act, Cap 97 by WhatsApp LLC and Meta Platforms, Inc. in relation to the January 2021 Privacy Policy update
Decision
Complaint partly upheld. WhatsApp LLC ordered to revise privacy policy, implement structural differentiation between essential and ancillary processing, submit cross-border compliance documentation, and conduct Data Protection Impact Assessment within ninety days. Meta Platforms, Inc. joined for limited purpose of ensuring effective implementation of remedial directions concerning intra-group processing.

Observed later treatment

No later-treatment classification is recorded for this judgment.

Citator coverage is limited to judgments in the Wakilii corpus and source-matched treatment records. Absence of a signal is not an assertion that the case remains good law.

AI-generated summary. This summary was generated by AI from the full text of the judgment. It may contain errors or omissions—always read the source judgment before relying on it.

Holding

The Personal Data Protection Office held that WhatsApp LLC's January 2021 Privacy Policy failed to adequately correlate data categories, processing purposes, and lawful bases in a structured manner, contravening transparency and purpose specification requirements. The policy bundled essential messaging data with ancillary ecosystem-level processing without demonstrating necessity or providing differentiated user choice. Cross-border data transfers to jurisdictions outside Uganda were not demonstrated to meet adequacy and safeguard requirements. While intra-group data sharing was disclosed, the structural deficiencies materially impaired users' ability to exercise informed control. WhatsApp was ordered to revise its Uganda-facing policy, differentiate essential from ancillary processing, implement granular opt-in mechanisms for profiling, and submit cross-border compliance documentation within ninety days.

Outcome

Complaint partly upheld. WhatsApp LLC ordered to revise privacy policy, implement structural differentiation between essential and ancillary processing, submit cross-border compliance documentation, and conduct Data Protection Impact Assessment within ninety days. Meta Platforms, Inc. joined for limited purpose of ensuring effective implementation of remedial directions concerning intra-group processing.

Facts

Adlegal International Limited lodged a complaint on 31 March 2025 alleging that WhatsApp LLC's January 2021 Privacy Policy update contravened the Data Protection and Privacy Act, Cap 97. The complaint alleged that WhatsApp shared Ugandan users' personal data with Meta Platforms, Inc. without freely given, informed, and explicit consent; collected personal data beyond what was strictly necessary for providing WhatsApp Messenger; afforded Ugandan users materially weaker structured transparency than users in certain other jurisdictions; and transferred personal data outside Uganda without demonstrating compliance with Section 19 of the Act. The January 2021 Privacy Policy disclosed intra-group data sharing with other Meta companies for purposes including operating and improving services, promoting safety and integrity, improving user experiences, showing relevant offers across Meta company products, and enabling integrations. WhatsApp LLC and Meta Platforms, Inc. filed responses on 22 May 2025. Both respondents are registered with PDPO but are incorporated outside Uganda. WhatsApp operates WhatsApp Messenger globally and processes Ugandan users' data on infrastructure hosted by Meta.

Issues

  1. Whether Meta Platforms, Inc. is properly joined as a respondent in this complaint and, if so, the scope of any findings applicable to Meta.
  2. Whether the January 2021 WhatsApp Privacy Policy update afforded users a meaningful opportunity to consent, and obtained valid consent where required.
  3. Whether WhatsApp's January 2021 Privacy Policy permitted excessive data collection and unlawfully bundled non-essential processing without a valid lawful basis.
  4. Whether the conduct by WhatsApp constitutes harm to Ugandan users by undermining data subjects' ability to exercise meaningful control over the use of their data.
  5. Whether the Respondents complied with Section 19 of the Act, Cap 97 and Regulation 30 in relation to processing or storage of personal data outside Uganda.
  6. Whether WhatsApp LLC subjected Ugandan users to disparate treatment by providing materially weaker privacy disclosures and safeguards than those provided to users in other jurisdictions.
  7. Whether the Complainant is entitled to the orders sought and other remedies arising from the Respondents' alleged violations of the Act, Cap 97 and its Regulations.

Orders

  • Within ninety (90) days, WhatsApp LLC shall revise the Uganda-facing Privacy Policy to clearly correlate categories of personal data, specific purposes of processing, the lawful basis for each purpose, and categories of recipients including intra-group recipients.
  • Within ninety (90) days, WhatsApp LLC shall implement clear structural differentiation between processing strictly necessary for core messaging functionality and ancillary ecosystem-level processing.
  • Where ancillary processing relies on consent, such consent must meet the statutory definition under Section 2 of the Act, Cap 97.
  • Where ancillary processing constitutes profiling for advertising or analytics, WhatsApp LLC shall implement a granular, freely given opt-in mechanism enabling users to consent to or decline each category separately.
  • Within ninety (90) days, WhatsApp LLC shall submit to PDPO a documented adequacy and safeguard assessment under Regulation 30 addressing legal protections in receiving jurisdictions, enforceable rights for Ugandan data subjects, and safeguards governing onward transfers.
  • WhatsApp LLC shall conduct and submit a Data Protection Impact Assessment (DPIA) addressing intra-group sharing within ninety (90) days.
  • Where WhatsApp LLC invokes legitimate interests under Regulation 10(2)(b), it shall prepare a written legitimate interests assessment (LIA) and submit it to PDPO within the ninety (90) day compliance period.
  • Failure to comply with the above orders is an offence under Regulation 48 and may attract a fine for each day in default.
  • Non-compliance with orders relating to cross-border transfers may expose the Respondents to further sanctions under Regulation 30(6), including fines and imprisonment.
  • This Decision is served on the Respondents as an enforcement notice under Regulation 45(3).
  • Any party aggrieved by this Decision may appeal to the Minister of ICT and National Guidance within thirty (30) days.

Rules and key headnotes

Data Protection — Territorial Jurisdiction — Extra-territorial Application
An entity offering services to persons in Uganda and determining the purposes and means of processing of their personal data falls within the scope of the Data Protection and Privacy Act, Cap 97 irrespective of its place of incorporation, pursuant to Section 1(b) of the Act.
Data Protection — Standing — Public Interest Complaints
Section 31(1) of the Data Protection and Privacy Act, Cap 97, read with Regulation 41(1)(a), permits any person to lodge a complaint with the Personal Data Protection Office where they have reason to believe that a contravention of the Act has occurred. The Act does not restrict complaints to individual data subjects personally affected; it contemplates complaints in the public interest.
Data Protection — Consent — Statutory Definition and Requirements
Consent under the Data Protection and Privacy Act, Cap 97 means any freely given, specific, informed, and unambiguous indication of the data subject's wish by which he or she, by a statement or a clear affirmative action, signifies agreement to the collection or processing of personal data. Where consent is relied upon as a lawful basis, it must be clear, informed, and demonstrable, and a data subject must be placed in a position to understand what they are agreeing to before consent can be regarded as valid.
Data Protection — Transparency — Purpose Specification and Lawful Basis Correlation
Sections 3(1)(a), 12, and 13 of the Data Protection and Privacy Act, Cap 97 require that personal data be collected for specific and explicitly stated purposes and that data subjects be provided, prior to collection, with clear and intelligible information regarding the purposes of processing and any disclosures. A privacy policy must correlate, in a structured and intelligible manner, specific categories of data with specific purposes and the particular lawful basis relied upon for each purpose. The absence of such structured correlation materially impairs the data subject's ability to assess necessity, challenge processing, and exercise rights under Part V of the Act.
Data Protection — Data Minimisation — Proportionality and Necessity
Section 3(1)(c) and Section 14(2) of the Data Protection and Privacy Act, Cap 97 require that personal data be adequate, relevant, and not excessive or unnecessary in relation to the purposes for which it is collected or processed. The statutory test is one of proportionality and objective necessity. Where processing extends beyond core service functionality, the controller bears the burden of demonstrating objective necessity for each category of data collected. Processing indispensable to a messaging service includes account registration data, message routing metadata, and limited device and connection data necessary for security and integrity. Processing for broader ecosystem-level purposes such as integration across corporate group products, product improvement across the group, personalization, and related optimization functions is not, on its face, strictly necessary for the transmission of messages between users.
Data Protection — Cross-Border Transfers — Adequacy and Safeguards
Section 19 of the Data Protection and Privacy Act, Cap 97 and Regulation 30 regulate processing or storage of personal data outside Uganda and require that such processing ensure an adequate level of protection equivalent to that provided under the Act, or that other lawful conditions apply. A transfer includes any situation where personal data collected from data subjects in Uganda is processed or stored in a foreign jurisdiction, whether through direct upload to overseas servers, remote hosting arrangements, onward disclosure, or shared infrastructure operations. In the absence of an officially recognized adequacy determination under Regulation 30(4), the burden of proof lies squarely on the controller to demonstrate that the receiving jurisdiction ensures protection at least equivalent to that provided under the Act, or that appropriate safeguards exist.
Privacy — Informational Self-Determination — Privacy Harms
Article 27 of the Constitution of the Republic of Uganda recognizes that every person has a right to privacy, which encompasses informational self-determination. Privacy harms are not limited to economic or physical injuries but extend to harms to autonomy, dignity, and self-determination. A lack of meaningful control over personal data can itself constitute a privacy harm, even when no immediate financial loss is shown. Part V of the Data Protection and Privacy Act, Cap 97 confers enforceable rights to safeguard informational control; structural impairment of those rights is legally cognizable. Transparency and informed control are not mere procedural formalities but substantive protections through which the data subject's autonomy interest is given legal effect.

Legislation cited (26)

Cases cited (3)

  • Ssekamwa Frank and 3 Others v Google LLC (Complaint No. 08 11 24 6683) [2025] PDPO 2 (18 July 2025)
  • Nalubega Shadia v Stabex International Ltd (Civil Suit No. 665 of 2021)
  • Akzo Nobel NV v Commission (Case C-97/08 P)

Full judgment

↓ Download PDF

The original judgment as reported. Read the original PDF before relying on any passage.

Ssekamwa Frank and 3 others v Google LLC (Complaint No. 08 11 24 6683) [2025] PDPO 2 (18 July 2025)
Source: this page presents Wakilii’s issue analysis and metadata for a publicly reported Ugandan judgment. Any AI-generated summary is marked as such. Judgment text is sourced from the Uganda Legal Information Institute (ulii.org). Wakilii is not affiliated with ULII.