Other Developments
PDPO investigative powers and penalty structure. The Personal Data Protection Office holds investigative power over complaints under Section 32 of the Data Protection and Privacy Act, and Regulation 48 of the Data Protection and Privacy Regulations, 2021 provides a penalty for non-compliance with a PDPO notice. The Ssekamwa Frank decision demonstrates these powers being exercised against a specific respondent rather than remaining a theoretical enforcement mechanism, though the precise remedy or penalty imposed in that decision is not established in the evidence available this cycle.
Limits on PDPO remedial power and the route to court. The Data Protection and Privacy Act requires a data subject who has suffered damage or distress to apply to a court for compensation, since the PDPO itself cannot award such compensation under Section 33. This creates a bifurcated redress structure: the PDPO can investigate and act on regulatory non-compliance, but a complainant seeking monetary compensation for harm must pursue a separate civil claim. Read together with the Ssekamwa Frank decision, this means the PDPO's July 2025 resolution addressed the complaint at the regulatory level without necessarily resolving any compensation claim the complainants might separately pursue.
Appeal window. A PDPO decision may be appealed to the Minister within 30 days under Section 34 of the Act, a standing procedural feature of the enforcement and redress architecture rather than a new development this cycle, but one directly relevant to understanding the finality and appeal posture of the Ssekamwa Frank decision.
Cross-Monitor Connections
The Ssekamwa Frank decision names Google LLC as respondent, a detail with potential relevance to advennt's and financial-integrity's platform and cross-border technology-provider coverage where Ugandan regulatory engagement with major international technology companies is tracked. No direct AML, payments, or crypto nexus is established in the evidence for this specific enforcement decision, and this brief does not extend the finding into those domains.
Outlook
The principal marker to watch is whether the Ssekamwa Frank decision is appealed to the Minister within the 30-day window the Act provides, and whether the PDPO publishes further detail on the substance of the decision or any associated remedial order. A second marker is whether the PDPO's exercise of investigative powers in this case establishes a template the office applies to subsequent complaints against other technology providers operating in Uganda, which would be a meaningful signal for the broader enforcement-and-redress trajectory beyond this single decision.
Standing brief · as of 25 August 2026
Written before the update above. Where they differ, the update is the more recent position.
Lead Signal
Uganda's data protection regulator has shifted from a quiet implementing office into an actively enforcing authority. The Personal Data Protection Office (PDPO) is understood to be an independent office under NITA-U. It is understood to be itself responsible for overseeing implementation and enforcement of the Data Protection and Privacy Act, 2019. This corrects an earlier reading of the PDPO/NITA-U relationship, verified against the PDPO's own published materials. The PDPO is understood to have secured its first-ever criminal conviction under the Act in July 2025. The conviction was against a director of digital lender Nano Loans. In the same month, the PDPO is understood to have ordered Google to register and comply with Uganda's data protection laws. The order followed findings of unlawful cross-border transfers of personal data. The Google order is treated as enforcement-based confirmation that Uganda's data protection obligations reach entities handling Ugandan citizens' data regardless of location. This is so even though the Act does not carry an explicit GDPR Article 3(2)-style trigger for extraterritorial application.
Other Developments
This cycle also establishes a fuller baseline picture of Uganda's framework. The Data Protection and Privacy Act, 2019 is understood to be supplemented by the Data Protection and Privacy Regulations, 2021. Together these form Uganda's primary statutory framework. Personal data under the Act is understood to be defined to include nationality, age, marital status, education, occupation, financial transactions, and identification numbers assigned to a person. Section 7 of the Act is understood to require prior consent for processing unless an enumerated exception applies. The exceptions include authorisation by law, public duty, contract performance, legal obligation, and offence prevention. The Act is understood to set distinct conditions for consent involving minors and other special categories of data subjects.
On data subject rights, Section 16 of the Act is understood to allow data subjects to request correction or deletion of incorrect, outdated, or unlawfully held data. Rights broadly equivalent to GDPR Articles 15 through 22 and 34 are understood to be required to be provided free of charge. Reports suggest the framework may lack an explicit data-portability right equivalent to GDPR Article 20. This finding remains pending primary-text confirmation. Section 31 of the Act is understood to empower the Authority to investigate rights-infringement complaints and assign compensation.
On controller duties, the Data Protection and Privacy Regulations, 2021 are understood to require a Data Protection Impact Assessment before high-risk processing. The Act and Regulations are understood to require appointment of a Data Protection Officer. Neither instrument defines the term itself. Part 4 of the Act is understood to require reasonable technical and organisational security measures. The Act and Regulations are understood to require breach notification to the Authority within a specified timeframe, without explicit exceptions comparable to GDPR Articles 33 and 34. Section 18 of the Act is understood to limit retention to what is necessary or specified by law, except that Section 18(2)(f) exempts data retained for historical, statistical, or research purposes.
On cross-border transfers, the Data Protection and Privacy Regulations, 2021 are understood to introduce additional transfer-related provisions beyond the base Act. The specific named safeguards were not retrievable this pass. The clearest transfer-related development remains the PDPO's order against Google, discussed above.
On sectoral activity, the Uganda Ministry of Health is understood to have mandated, as of 29 April 2026, that health facilities comply with national data protection requirements, including DPO appointment and security measures. The Nano Loans conviction marks the PDPO's first fintech-sector criminal enforcement outcome. Reports suggest the Uganda Communications Commission's historical comments on the 2015 data protection bill leave telecom subscriber data governed by the Act's general consent principle, absent a dedicated ePrivacy statute.
On children and vulnerable groups, Section 8 of the Act is understood to require prior parental or guardian consent before collecting or processing a child's personal data. The Act does not itself define "child." Regulation 11 of the 2021 Regulations is understood to require every controller and processor to establish a system to ascertain the age of data subjects and specify how parental consent is obtained where data relates to a child.
On algorithmic and surveillance governance, reports suggest the Regulation of Interception of Communications Act, 2010 operates alongside the Data Protection and Privacy Act, 2019 to govern state interception of communications. This is an adjacent instrument rather than a data-protection-specific carve-out.
On enforcement more broadly, the Act is understood to criminalise unlawful obtaining, disclosure, and sale of personal data, each carrying a maximum ten-year prison sentence alongside statutory fines. A PDPO report from February 2023 is understood to have identified skill gaps among appointed data protection officers and recommended additional training.
Cross-Monitor Connections
The Nano Loans conviction is flagged for the financial-integrity monitor as a possible fintech-sector data-protection enforcement nexus with illicit-finance-adjacent significance. The PDPO's order against Google over unlawful cross-border transfers is flagged for the world-payments monitor as touching payments-adjacent cross-border data-flow infrastructure. The absence of any identified AI-specific risk-assessment or automated-decision-making transparency regime in Uganda is flagged for the artificial-intelligence monitor as an absence worth noting in that monitor's own framing.
Outlook
Uganda's trajectory this cycle points toward tightening enforcement rather than legislative change. The corrected regulator-authority mapping, the first criminal conviction, and the Google transfer order together signal a PDPO willing to use its existing powers. Several evidentiary gaps remain open for future cycles, including primary-gazette verification of statutory penalty figures and breach-notification timeframes, the scope of named cross-border transfer safeguards, and whether ROPA-equivalent, joint-controller, and AI-transparency provisions exist beyond what secondary sources have so far surfaced.