🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
UG v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 1 failing9 sources retrieved model claude-sonnet-5 · 2026-08-05

Based mainly on secondary sources. Only 1 of the sources retrieved for this jurisdiction is official or direct reporting of official material (tier 1 or 2), against the 3 we look for. No finding on this page is shown with confidence above “Uncertain” until stronger sources are retrieved.

Uganda

UG schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 31 claims · 16 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
31Claimsbaseline..claims[]
1Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Uganda's data protection enforcement apparatus has produced its first named regulatory decision this cycle: the Personal Data Protection Office resolved Complaint No. 08/11/24/6683, Ssekamwa Frank and 3 Others v Google LLC, on 18 July 2025. This is a regulatory decision rather than a court judgment, issued under the PDPO's investigative powers, and it represents the first instance of the enforcement architecture the Data Protection and Privacy Act, 2019 established being used to resolve a named complaint against a major technology company. For a jurisdiction whose omnibus framework has been in force since 2019, the emergence of a concrete, named enforcement outcome is a materially significant development in assessing whether the statutory machinery functions in practice and not merely on paper.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive statute plus implementing regulations are in force, and a dedicated regulator (PDPO/NITA-U) is operational with registration and enforcement activity.

Primary frameworkData Protection and Privacy Act, 2019 (Uganda) and Data Protection and Privacy Regulations, 2021
Supervisory authorityNational Information Technology Authority – Uganda (NITA-U) / Personal Data Protection Office (PDPO)
Traffic-light rationale — GreenComprehensive statute plus implementing regulations are in force, and a dedicated regulator (PDPO/NITA-U) is operational with registration and enforcement activity.

Sub-modules (5)

Regulator And AuthorityGreen

The PDPO, established within NITA-U by the 2021 Regulations, is responsible for overall implementation of the Act and Regulations, while NITA-U remains the statutory supervisory/enforcement body and point of contact for suspected breaches.

Claims (1):

  • The Data Protection and Privacy Regulations, 2021 establish the Personal Data Protection Office (PDPO) within NITA-U, which is responsible for the overall implementation of the Data Protection and Privacy Act, 2019 and its Regulations, while NITA-U retains statutory supervisory and enforcement authority.

Act And InstrumentsGreen

Primary instruments are the DPPA 2019 (assented 25 Feb 2019, in force ~May 2019) and the DPPR 2021 (gazetted 12 March 2021).

Claims (1):

  • The Data Protection and Privacy Act, 2019 is the primary data protection statute in Uganda, supplemented by the Data Protection and Privacy Regulations, 2021.

Material ScopeGreen

Personal data is broadly defined to include nationality, age, marital status, education, occupation, financial transactions, identification numbers, and identity data.

Claims (1):

  • Personal data under the Act includes information relating to nationality, age, marital status, education, occupation, financial transactions, and identification numbers/symbols assigned to a person.

Territorial ScopeAmber

The Act applies extraterritorially and may bind entities outside Uganda, but unlike GDPR Art 3 it does not explicitly extend to offering goods/services to, or monitoring, Ugandan data subjects from abroad.

Claims (1):

  • The Act applies extraterritorially and may apply to entities outside Uganda, but does not explicitly regulate goods/services offered from abroad or monitoring of data subjects from abroad, unlike GDPR Article 3.

Regulator Registration And FilingGreen

The 2021 Regulations impose a registration obligation on data collectors, controllers and processors with the PDPO, with detailed application/classification guidance issued by the PDPO (Sept 2021).

Claims (1):

  • The 2021 Regulations establish a registration obligation for data collectors, controllers, and processors, and the PDPO issued Registration Classification and Guidance Notes in September 2021.
Category narrative74 words

Uganda operates a comprehensive omnibus regime under the Data Protection and Privacy Act, 2019 (DPPA), supplemented by the Data Protection and Privacy Regulations, 2021. The Regulations establish the Personal Data Protection Office (PDPO) within the National Information Technology Authority – Uganda (NITA-U); NITA-U retains overarching statutory supervision/enforcement authority while the PDPO performs day-to-day implementation and reports its findings to NITA-U. The Act has extraterritorial reach but does not mirror the GDPR's explicit 'goods/services/monitoring' triggers.

no periodic updates on record for this sub-brief

Sources and claims (5)
  1. UncertainOneTrust DataGuidance — The Data Protection and Privacy Regulations, 2021 establish the Personal Data Protection Office (PDPO) within NITA-U, which is responsible for the overall implementation of the Data Protection and Privacy Act, 2019 and its Regulations, while NITA-U retains statutory supervisory and enforcement authority.observed
  2. UncertainOneTrust DataGuidance — The Data Protection and Privacy Act, 2019 is the primary data protection statute in Uganda, supplemented by the Data Protection and Privacy Regulations, 2021.observed
  3. UncertainOneTrust DataGuidance — Personal data under the Act includes information relating to nationality, age, marital status, education, occupation, financial transactions, and identification numbers/symbols assigned to a person.observed
  4. UncertainOneTrust DataGuidance — The Act applies extraterritorially and may apply to entities outside Uganda, but does not explicitly regulate goods/services offered from abroad or monitoring of data subjects from abroad, unlike GDPR Article 3.observed
  5. UncertainOneTrust DataGuidance — The 2021 Regulations establish a registration obligation for data collectors, controllers, and processors, and the PDPO issued Registration Classification and Guidance Notes in September 2021.observed

#

Core lawful-basis and consent architecture is present and enforced, but pseudonymisation/anonymisation safe-harbours are undefined, creating compliance ambiguity relative to GDPR-aligned regimes.

Primary frameworkData Protection and Privacy Act, 2019 (Uganda), Section 7-8
Supervisory authorityPersonal Data Protection Office (PDPO), NITA-U
Traffic-light rationale — AmberCore lawful-basis and consent architecture is present and enforced, but pseudonymisation/anonymisation safe-harbours are undefined, creating compliance ambiguity relative to GDPR-aligned regimes.

Sub-modules (4)

Lawful BasesGreen

Section 7 requires prior consent for collection/processing unless an enumerated exception applies (authorised by law, public duty, contract performance, legal obligation, offence prevention/detection).

Claims (1):

  • Section 7 of the Act requires prior consent for collection or processing of personal data, unless the processing is authorised or required by law, necessary for a public duty, necessary for contract performance, or required for compliance with a legal obligation.

Special CategoriesAmber

The Act and GDPR share similar concepts of special/sensitive categories; Section 8 requires prior parental/guardian consent for processing a child's data, though the Act does not itself define 'child'.

Claims (1):

  • Section 8 of the Act requires that personal data relating to a child not be collected or processed unless carried out with the prior consent of a parent, though the Act does not itself define 'child'.

Pseudonymisation And AnonymisationRed

Unlike the GDPR, the Act does not directly define or provide safe-harbours for anonymisation or pseudonymisation; related concepts appear only via destruction/de-identification provisions.

Claims (1):

  • Unlike the GDPR, the Act does not directly refer to anonymisation and does not explicitly define pseudonymisation, though it contains related provisions on destruction and de-identification of data.
Category narrative51 words

The Act sets consent as a central lawful-processing principle (Section 7) with statutory exceptions, and imposes specific conditions on consent for children and other special categories. Definitions of personal data and special/sensitive categories parallel the GDPR, but the Act does not directly address anonymisation or pseudonymisation, relying instead on destruction/de-identification concepts.

no periodic updates on record for this sub-brief

Sources and claims (4)
  1. UncertainOneTrust DataGuidance — Section 7 of the Act requires prior consent for collection or processing of personal data, unless the processing is authorised or required by law, necessary for a public duty, necessary for contract performance, or required for compliance with a legal obligation.observed
  2. UncertainOneTrust DataGuidance — The Act establishes consent as a central principle and specifies distinct conditions for consent relating to minors and other special categories of data subjects.observed
  3. UncertainOneTrust DataGuidance — Section 8 of the Act requires that personal data relating to a child not be collected or processed unless carried out with the prior consent of a parent, though the Act does not itself define 'child'.observed
  4. UncertainOneTrust DataGuidance — Unlike the GDPR, the Act does not directly refer to anonymisation and does not explicitly define pseudonymisation, though it contains related provisions on destruction and de-identification of data.observed

#

Correction/deletion and complaint-driven remedies exist and are enforced, but erasure is narrower than GDPR's 'right to be forgotten' and portability is not explicitly legislated.

Primary frameworkData Protection and Privacy Act, 2019 (Uganda), Sections 16, 31
Supervisory authorityPersonal Data Protection Office (PDPO), NITA-U
Traffic-light rationale — AmberCorrection/deletion and complaint-driven remedies exist and are enforced, but erasure is narrower than GDPR's 'right to be forgotten' and portability is not explicitly legislated.

Sub-modules (5)

Access RightAmber

Rights corresponding to GDPR Articles 15-22 and 34 are to be provided to data subjects free of charge under the Act's framework.

Claims (1):

  • Rights equivalent to GDPR Articles 15 to 22 and 34 must be provided to data subjects free of charge under the Ugandan framework.

Rectification And ErasureAmber

Section 16 allows data subjects to request correction or deletion of personal data that is incorrect, out of date, or unlawfully obtained/held — narrower than the GDPR's general erasure right.

Claims (1):

  • Data subjects may request a data controller to correct or delete personal data under Section 16 of the Act where the data is incorrect, out of date, or unlawfully obtained or held.

Restriction And ObjectionAmber

Under Section 31, the PDPO/Authority may investigate complaints of rights infringement and assign compensation to the data subject, functioning as the principal restriction/objection remedy.

Claims (1):

  • Under Article/Section 31 of the Act, the Authority may investigate complaints relating to infringement of data subject rights and assign compensation to the data subject.

Data PortabilityRed

No explicit statutory data-portability right equivalent to GDPR Article 20 was identified in the Act or Regulations during this research pass.

Claims (1):

  • No explicit statutory right to data portability equivalent to GDPR Article 20 was identified in the DPPA 2019 or DPPR 2021.

Deadlines And Response WindowsRed

No specific statutory response-window (e.g., a fixed number of days for controller response to a subject request) was surfaced in available secondary sources; this requires primary-text verification.

Category narrative51 words

Data subjects can request correction or deletion of inaccurate, outdated, or unlawfully held data (Section 16) and may lodge complaints leading to PDPO-assigned compensation (Section 31). Rights equivalent to GDPR Arts 15-22 and 34 must be provided free of charge. No explicit data-portability right analogous to GDPR Art 20 was identified.

no periodic updates on record for this sub-brief

Sources and claims (4)
  1. UncertainOneTrust DataGuidance — Data subjects may request a data controller to correct or delete personal data under Section 16 of the Act where the data is incorrect, out of date, or unlawfully obtained or held.observed
  2. UncertainOneTrust DataGuidance — Rights equivalent to GDPR Articles 15 to 22 and 34 must be provided to data subjects free of charge under the Ugandan framework.observed
  3. UncertainOneTrust DataGuidance — No explicit statutory right to data portability equivalent to GDPR Article 20 was identified in the DPPA 2019 or DPPR 2021.observed
  4. UncertainOneTrust DataGuidance — Under Article/Section 31 of the Act, the Authority may investigate complaints relating to infringement of data subject rights and assign compensation to the data subject.observed

#

Core accountability, DPIA, DPO, security and breach-notification duties exist and are regulator-enforced, but joint-controller and ROPA granularity, and breach-notification exceptions, are thinner than GDPR-equivalent regimes.

Primary frameworkData Protection and Privacy Act, 2019 and Data Protection and Privacy Regulations, 2021 (Uganda)
Supervisory authorityPersonal Data Protection Office (PDPO), NITA-U
Traffic-light rationale — AmberCore accountability, DPIA, DPO, security and breach-notification duties exist and are regulator-enforced, but joint-controller and ROPA granularity, and breach-notification exceptions, are thinner than GDPR-equivalent regimes.

Sub-modules (7)

Accountability And DpiaGreen

While the Act itself does not set DPIA requirements, the 2021 Regulations require a DPIA prior to processing that poses a high risk to natural persons and outline required DPIA content.

Claims (1):

  • The 2021 Regulations require a Data Protection Impact Assessment to be carried out prior to processing that poses a high risk to natural persons, and specify the required contents of a DPIA, even though the Act itself does not address DPIAs.

Dpo RequirementsAmber

The Act requires DPO appointment; the Regulations add detail on DPO tasks and qualifications, though neither instrument defines 'data protection officer'.

Claims (1):

  • The Act provides for the requirement to appoint a DPO, while the Regulations provide further detail on DPO tasks and qualifications; neither instrument defines the term 'data protection officer'.

Ropa RequirementsRed

No detailed Records-of-Processing-Activities regime equivalent to GDPR Art 30 was surfaced distinctly from the general registration obligation; treated as an evidentiary gap pending primary-text review.

Joint Controller ArrangementsRed

The Act provides similar controller/processor definitions and requires inter-party agreements, but does not set out GDPR Art 26-equivalent joint-controller obligations in explicit terms.

Claims (1):

  • The Act provides similar definitions for data controllers and processors and requires agreements between them, but does not set out explicit GDPR Art 26-equivalent joint-controller obligations.

Security MeasuresGreen

Part 4 of the Act requires data collectors, controllers and processors to take reasonable technical and organisational security measures.

Claims (1):

  • Part 4 of the Data Protection and Privacy Act, 2019 requires companies to take reasonable technical and organisational security measures in respect of personal data.

Breach NotificationAmber

The Act and Regulations require notification of the Authority within a specified timeframe following a breach, and empower the PDPO to require data-subject notification, but do not set explicit exceptions to the notification duty (unlike GDPR Art 33-34).

Claims (1):

  • The Act and Regulations require that authorities be notified of data breaches within a specific timeframe and empower the PDPO to require that data subjects also be notified, but unlike the GDPR the Act does not provide specific exceptions to the breach-notification duty.

Retention And DisposalAmber

Retention is limited to what is necessary or as specified by law (Section 18); Section 18(2)(f) exempts data retained for historical, statistical, or research purposes from the standard retention limitation.

Claims (1):

  • Personal data may only be retained for as long as necessary or as specified in law (Section 18), with Section 18(2)(f) exempting data retained for historical, statistical, or research purposes.
Category narrative51 words

Part 4 of the Act requires reasonable technical/organisational security measures; the Regulations add DPIA obligations for high-risk processing, DPO appointment/qualification detail, registration, and breach-notification mechanics. Retention is capped at what is 'necessary' with a research/statistics carve-out (Section 18(2)(f)). Joint-controller-specific obligations and formal ROPA requirements are less detailed than under the GDPR.

no periodic updates on record for this sub-brief

Sources and claims (6)
  1. UncertainOneTrust DataGuidance — The 2021 Regulations require a Data Protection Impact Assessment to be carried out prior to processing that poses a high risk to natural persons, and specify the required contents of a DPIA, even though the Act itself does not address DPIAs.observed
  2. UncertainOneTrust DataGuidance — The Act provides for the requirement to appoint a DPO, while the Regulations provide further detail on DPO tasks and qualifications; neither instrument defines the term 'data protection officer'.observed
  3. UncertainOneTrust DataGuidance — Part 4 of the Data Protection and Privacy Act, 2019 requires companies to take reasonable technical and organisational security measures in respect of personal data.observed
  4. UncertainOneTrust DataGuidance — The Act and Regulations require that authorities be notified of data breaches within a specific timeframe and empower the PDPO to require that data subjects also be notified, but unlike the GDPR the Act does not provide specific exceptions to the breach-notification duty.observed
  5. UncertainOneTrust DataGuidance — Personal data may only be retained for as long as necessary or as specified in law (Section 18), with Section 18(2)(f) exempting data retained for historical, statistical, or research purposes.observed
  6. UncertainOneTrust DataGuidance — The Act provides similar definitions for data controllers and processors and requires agreements between them, but does not set out explicit GDPR Art 26-equivalent joint-controller obligations.observed

#

A transfer-mechanism concept and active enforcement exist, but the mechanics (adequacy, SCCs/BCRs, TIA, localisation) remain largely unevidenced in available secondary sources.

Primary frameworkData Protection and Privacy Regulations, 2021 (Uganda)
Supervisory authorityPersonal Data Protection Office (PDPO), NITA-U
Traffic-light rationale — AmberA transfer-mechanism concept and active enforcement exist, but the mechanics (adequacy, SCCs/BCRs, TIA, localisation) remain largely unevidenced in available secondary sources.

Sub-modules (6)

Transfer MechanismsAmber

The 2021 Regulations added provisions on data transfers not present in the base Act, per comparative legal analysis, though granular transfer-mechanism detail (e.g. named safeguards) was not retrievable in this pass.

Claims (1):

  • The Data Protection and Privacy Regulations, 2021 introduced additional provisions relating to data transfers beyond what is contained in the base Act.

Adequacy ReceivedRed

No evidence found that Uganda has received an adequacy determination from another regime (e.g. EU/UK).

Adequacy GrantedRed

No evidence found that Uganda has issued formal adequacy determinations regarding other jurisdictions.

Sccs And BcrsRed

No codified Standard Contractual Clauses or Binding Corporate Rules framework was identified for Uganda in available sources.

Transfer Impact AssessmentRed

No explicit transfer-impact-assessment requirement analogous to post-Schrems II EU practice was identified.

Data LocalisationRed

No general data-localisation mandate was identified in the Act or Regulations during this research pass.

Category narrative57 words

The 2021 Regulations introduced additional provisions on data transfers beyond the base Act, and the PDPO has taken active enforcement steps against at least one major cross-border transferor (Google) for unlawful data transfers. However, no evidence was found of Uganda having received or granted formal adequacy decisions, a codified SCC/BCR regime, a transfer-impact-assessment requirement, or data-localisation mandates.

no periodic updates on record for this sub-brief

Sources and claims (2)
  1. UncertainOneTrust DataGuidance — The Data Protection and Privacy Regulations, 2021 introduced additional provisions relating to data transfers beyond what is contained in the base Act.observed
  2. UncertainOneTrust DataGuidance — In July 2025, the PDPO ordered Google to register and comply with Uganda's data protection laws following findings of unlawful cross-border data transfers, evidencing active enforcement of transfer obligations.observed

#

Partial, enforcement-evidenced sectoral coverage in health and fintech/lending; other sectors (credit scoring, education, insurance, employment) lack identified dedicated overlays.

Primary frameworkData Protection and Privacy Act, 2019 (Uganda) with sector-specific administrative directives
Supervisory authorityPersonal Data Protection Office (PDPO), NITA-U
Traffic-light rationale — AmberPartial, enforcement-evidenced sectoral coverage in health and fintech/lending; other sectors (credit scoring, education, insurance, employment) lack identified dedicated overlays.

Sub-modules (7)

Financial Sector OverlayAmber

PDPO secured its first criminal conviction under the Act against a director of digital lender 'Nano Loans' for data violations, signalling active fintech/lending-sector enforcement rather than a codified financial-sector DP overlay.

Claims (1):

  • The PDPO obtained its first criminal conviction under the Data Protection and Privacy Act, 2019 against a director of digital lender Nano Loans for data violations, evidencing fintech/lending-sector enforcement.

Health Sector OverlayAmber

Uganda's Ministry of Health mandates health facilities to comply with national data protection requirements, including DPO appointment and security-measure implementation.

Claims (1):

  • Uganda's Ministry of Health mandates health facilities to comply with national data protection requirements, including appointing DPOs and implementing security measures.

Telecoms And EprivacyAmber

The Uganda Communications Commission engaged with the Data Protection and Privacy Bill process; general commentary notes telecom subscriber-data practices are affected by the Act's consent principle, but no distinct ePrivacy/cookie-specific telecom statute was identified.

Claims (1):

  • The Uganda Communications Commission submitted comments on the Data Protection and Privacy Bill 2015, and telecom operators' longstanding subscriber-data practices are affected by the Act's consent principle.

Employment DataRed

No dedicated employment-data DP overlay was identified in available sources.

Credit And ScoringRed

No dedicated credit-scoring DP overlay was identified.

EducationRed

No dedicated education-sector DP overlay was identified.

InsuranceRed

No dedicated insurance-sector DP overlay was identified.

Category narrative58 words

Sectoral overlays are thin but emerging: Uganda's Ministry of Health has mandated health-facility compliance including DPO appointment and security measures; the PDPO's first criminal conviction involved a digital-lending ('Nano Loans') director, indicating fintech/financial-sector enforcement; the Uganda Communications Commission (UCC) engaged with the legislative process affecting telecom subscriber-data practices. No dedicated credit-scoring, education-sector, or insurance-sector DP overlays were identified.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. UncertainOneTrust DataGuidance — Uganda's Ministry of Health mandates health facilities to comply with national data protection requirements, including appointing DPOs and implementing security measures.observed
  2. UncertainOneTrust DataGuidance — The Uganda Communications Commission submitted comments on the Data Protection and Privacy Bill 2015, and telecom operators' longstanding subscriber-data practices are affected by the Act's consent principle.observed
  3. UncertainOneTrust DataGuidance — The PDPO obtained its first criminal conviction under the Data Protection and Privacy Act, 2019 against a director of digital lender Nano Loans for data violations, evidencing fintech/lending-sector enforcement.observed

#

No adtech/commercial-privacy-specific sub-regime was surfaced in the searches conducted; entire module rests on absent_field_provenance rather than affirmative findings.

Traffic-light rationale — Not assessedNo adtech/commercial-privacy-specific sub-regime was surfaced in the searches conducted; entire module rests on absent_field_provenance rather than affirmative findings.

Sub-modules (6)

Cookies And TrackersRed

No cookie/tracker-specific consent regime identified for Uganda distinct from the Act's general consent principle.

Dark PatternsRed

No dark-pattern prohibition identified.

Opt Out SignalsRed

No recognised opt-out signal framework (e.g., GPC/DAA equivalent) identified.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rules identified.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' cross-context-advertising concept identified.

Direct MarketingRed

No direct-marketing-specific consent/suppression regime identified beyond the Act's general consent principle.

Category narrative68 words

No dedicated cookie/tracker consent regime, dark-pattern prohibition, recognised opt-out signal (e.g., GPC/DAA equivalent), clean-room/data-collaboration rule, cross-context-advertising concept, or direct-marketing-specific suppression regime distinct from the Act's general consent principle was identified across the searches performed for this run (regulator/framework, lawful-basis, breach-notification, cross-border, enforcement, and sectoral queries). This is an evidentiary gap rather than a confirmed absence of any commercial-privacy law; primary-text review of the Act's advertising/marketing provisions is recommended.

#

Only one adjacent state-surveillance instrument was identified; profiling, ADM-transparency, AI-risk-assessment, biometric, and genetic sub-modules are evidentiary gaps.

Traffic-light rationale — RedOnly one adjacent state-surveillance instrument was identified; profiling, ADM-transparency, AI-risk-assessment, biometric, and genetic sub-modules are evidentiary gaps.

Sub-modules (6)

Profiling RestrictionsRed

No Art 22-equivalent profiling restriction identified in the DPPA 2019 or Regulations.

Automated Decision Making TransparencyRed

No ADM transparency/explanation right identified.

Ai Risk AssessmentsRed

No AI-specific risk-assessment regime identified.

Biometric RegimeRed

No dedicated biometric-data regime distinct from the Act's general special-category concept was identified.

Genetic DataRed

No dedicated genetic-data regime identified.

State Surveillance CarveoutsAmber

The Regulation of Interception of Communications Act, 2010 operates as a sectoral instrument governing state interception of communications alongside the DPPA 2019.

Claims (1):

  • The Regulation of Interception of Communications Act, 2010 is a sectoral Ugandan law that operates alongside the Data Protection and Privacy Act, 2019 to govern state interception of communications.
Category narrative51 words

No Art 22-equivalent profiling/ADM restriction, ADM transparency right, AI-specific risk-assessment regime, dedicated biometric-data regime, or genetic-data regime was surfaced. The one identified adjacent instrument is the Regulation of Interception of Communications Act, 2010, which operates alongside the DPPA 2019 to govern state interception of communications and functions as a state-surveillance carve-out.

no periodic updates on record for this sub-brief

Sources and claims (1)
  1. UncertainOneTrust DataGuidance — The Regulation of Interception of Communications Act, 2010 is a sectoral Ugandan law that operates alongside the Data Protection and Privacy Act, 2019 to govern state interception of communications.observed

#

Parental-consent mechanics exist and are regulator-enforceable, but the absence of a defined age threshold and of minor-profiling/education/dependent-adult provisions leaves material gaps.

Primary frameworkData Protection and Privacy Act, 2019, Section 8; Data Protection and Privacy Regulations, 2021, Regulation 11
Supervisory authorityPersonal Data Protection Office (PDPO), NITA-U
Traffic-light rationale — AmberParental-consent mechanics exist and are regulator-enforceable, but the absence of a defined age threshold and of minor-profiling/education/dependent-adult provisions leaves material gaps.

Sub-modules (5)

Age VerificationAmber

Regulation 11 requires every data collector, controller, and processor to establish a system to ascertain the age of persons whose data is collected, processed, or stored.

Claims (1):

  • Regulation 11 of the 2021 Regulations requires every data collector, controller, and processor to establish a system to ascertain the age of persons whose personal data is collected, processed, or stored, and specify the manner of obtaining parental/guardian consent where the data relates to a child.

Minor Profiling BansRed

No minor-specific profiling ban was identified in the Act or Regulations.

Education SettingsRed

No education-settings-specific data protection rule was identified.

Dependent AdultsRed

No dependent-adults-specific (elderly/mentally incapacitated) data protection provision was identified.

Category narrative59 words

Section 8 of the Act requires prior parental/guardian consent for processing a child's personal data, and Regulation 11 requires collectors/controllers/processors to establish an age-ascertainment system and a defined manner of obtaining parental/guardian consent. The Act does not, however, specifically define 'child' or set a minimum age threshold, and no minor-specific profiling ban, education-settings rule, or dependent-adults provision was identified.

no periodic updates on record for this sub-brief

Sources and claims (2)
  1. UncertainOneTrust DataGuidance — Section 8 of the Act provides that a person shall not collect or process personal data relating to a child unless it is carried out with the prior consent of the parent or legal guardian.observed
  2. UncertainOneTrust DataGuidance — Regulation 11 of the 2021 Regulations requires every data collector, controller, and processor to establish a system to ascertain the age of persons whose personal data is collected, processed, or stored, and specify the manner of obtaining parental/guardian consent where the data relates to a child.observed

#

Statutory penalties are defined and the regulator has demonstrated escalating, multi-sector enforcement activity within the last 12 months, including a first criminal conviction and a major cross-border order against Google.

Primary frameworkData Protection and Privacy Act, 2019 (Uganda), Part 8 (Offences), Section 31
Supervisory authorityPersonal Data Protection Office (PDPO), NITA-U
Traffic-light rationale — GreenStatutory penalties are defined and the regulator has demonstrated escalating, multi-sector enforcement activity within the last 12 months, including a first criminal conviction and a major cross-border order against Google.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The Authority may investigate complaints and assign compensation (Section 31); offences such as unlawful obtaining/disclosure and sale of personal data carry statutory fines and up to 10 years' imprisonment.

Claims (1):

  • Under the Act, the Authority may investigate complaints and assign compensation to the data subject; collectors, controllers and processors may be criminally charged for unlawful obtaining/disclosure of personal data and for sale of personal data, each carrying a maximum prison sentence of 10 years alongside statutory fines.

Enforcement Activity IndexGreen

Enforcement activity has increased materially in 2023-2025: PDPO investigations (USE/Soft Edge Uganda, 2023), first criminal conviction (Nano Loans director, July 2025), and an order against Google over unlawful data transfers (July 2025).

Claims (1):

  • The PDPO secured its first criminal conviction under the Act against the director of digital lender Nano Loans (July 2025) and separately ordered Google to register and comply with Uganda's data protection laws after finding unlawful data transfers (July 2025), following an earlier 2023 investigation into a security breach involving USE and Soft Edge Uganda.

Regulator Funding And CapacityAmber

A PDPO report (Feb 2023) identified skill gaps among appointed DPOs and recommended training, indicating capacity constraints in the broader compliance ecosystem rather than confirmed regulator underfunding.

Claims (1):

  • A PDPO report (February 2023) revealed skill gaps among appointed data protection officers and recommended additional training to achieve compliance with the Act.

Collective Redress And Class ActionsRed

No dedicated collective-redress or class-action mechanism for data subjects was identified beyond the individual complaint-and-compensation route under Section 31.

Private Right Of ActionAmber

Data subjects can access a compensation remedy via a PDPO/Authority complaint under Section 31, functioning as a quasi private-right-of-action route mediated by the regulator rather than direct, unmediated court access.

Claims (1):

  • Under the Act, the Authority may investigate complaints and assign compensation to the data subject; collectors, controllers and processors may be criminally charged for unlawful obtaining/disclosure of personal data and for sale of personal data, each carrying a maximum prison sentence of 10 years alongside statutory fines.

Recent Developments 180DAmber

Within the 180 days preceding this run (early Feb 2026 - Aug 2026), the most notable development is the Ministry of Health's mandate (dated 29 April 2026) requiring health facilities to comply with national data protection requirements, including DPO appointment and security measures.

Claims (1):

  • Uganda's Ministry of Health mandated, as of 29 April 2026, that health facilities comply with national data protection requirements, including appointing DPOs and implementing security measures.
Category narrative100 words

The PDPO/NITA-U has become progressively active: it can investigate complaints and assign compensation (Section 31), and the Act criminalises unlawful obtaining/disclosure and sale of personal data with fines and up to 10 years' imprisonment. Recent enforcement (2025-2026) includes the PDPO's first criminal conviction (Nano Loans director), an order against Google over unlawful data transfers, and a Ministry of Health compliance mandate for health facilities. A PDPO report also identified DPO skill gaps, pointing to residual capacity constraints in the compliance ecosystem. No collective-redress/class-action mechanism or standalone private right of direct court action (outside the Section 31 complaint-and-compensation route) was identified.

Periodic update · new data 2026-09-28

Enforcement & Redress

The Personal Data Protection Office resolved its first named regulatory decision this cycle: Complaint No. 08/11/24/6683, Ssekamwa Frank and 3 Others v Google LLC, decided 18 July 2025. The decision is understood to be a regulatory decision issued under the PDPO's own investigative and enforcement powers rather than a court judgment, marking a concrete instance of the enforcement architecture the Data Protection and Privacy Act, Cap. 97 (2019) established being exercised against a named respondent. The PDPO holds power to investigate complaints under Section 32 of the Act, and Regulation 48 of the Data Protection and Privacy Regulations, 2021 provides a penalty mechanism for non-compliance with a PDPO notice, giving the office a functioning enforcement toolkit distinct from criminal prosecution.

The Act structurally separates regulatory enforcement from monetary compensation. Under Section 33, the PDPO cannot itself award compensation to a data subject who has suffered damage or distress; such a subject must instead apply to a court for compensation. This means the Ssekamwa Frank decision, however it resolved the underlying complaint at the regulatory level, does not by itself establish that any compensation was awarded to the complainants; a separate civil route would be required for that outcome. A PDPO decision, including this one, is subject to a defined appeal window: appeal to the Minister must occur within 30 days under Section 34, a standing procedural safeguard applicable to any PDPO determination.

Taken together, this cycle's enforcement development demonstrates that Uganda's PDPO is capable of resolving named complaints against significant respondents, including a major international technology company, using its statutory investigative powers, while the underlying redress architecture continues to require a separate civil claim for any compensation sought beyond the PDPO's own regulatory remedy.

Outlook

Watch for whether the Ssekamwa Frank decision is appealed to the Minister within the Section 34 30-day window, and whether the PDPO publishes additional detail on the substance of its decision or any remedial order issued. Whether this decision represents an isolated enforcement instance or the first of a pattern against major technology-sector respondents operating in Uganda is the key trajectory question for subsequent cycles.

Sources and claims (4)
  1. UncertainOneTrust DataGuidance — Under the Act, the Authority may investigate complaints and assign compensation to the data subject; collectors, controllers and processors may be criminally charged for unlawful obtaining/disclosure of personal data and for sale of personal data, each carrying a maximum prison sentence of 10 years alongside statutory fines.observed
  2. UncertainOneTrust DataGuidance — The PDPO secured its first criminal conviction under the Act against the director of digital lender Nano Loans (July 2025) and separately ordered Google to register and comply with Uganda's data protection laws after finding unlawful data transfers (July 2025), following an earlier 2023 investigation into a security breach involving USE and Soft Edge Uganda.observed
  3. UncertainOneTrust DataGuidance — A PDPO report (February 2023) revealed skill gaps among appointed data protection officers and recommended additional training to achieve compliance with the Act.observed
  4. UncertainOneTrust DataGuidance — Uganda's Ministry of Health mandated, as of 29 April 2026, that health facilities comply with national data protection requirements, including appointing DPOs and implementing security measures.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

Blocking. 1 failing check(s).

schema_validpass
min_t1_per_instrument_metwaived
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metFAIL
tier_a_b_national_primary_pct9.09
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Uganda
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 31 claim(s) (31 category placement(s)), 16 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, lawful_processing_and_special_data, controller_processor_duties, children_and_vulnerable_groups, and enforcement_and_redress rest primarily on T3 secondary legal-analysis sources (OneTrust DataGuidance overviews, comparison memos, and guidance notes) corroborated across multiple independent DataGuidance publications, with no direct T1 full-text extraction achieved for the DPPA 2019 or DPPR 2021 in this pass (search results for the raw PDFs returned only landing-page/marketing text, not substantive statutory text). data_subject_rights and cross_border_and_adequacy are partially evidenced (rights/complaints mechanics and one major transfer-enforcement action) but lack granular statutory deadline/adequacy/SCC detail. adtech_and_commercial_privacy and algorithmic_biometric_and_surveillance_governance are almost entirely evidentiary gaps (T4/absent), aside from one adjacent state-surveillance instrument (RICA 2010). sectoral_watch has partial T3 evidence for health and fintech/lending but no coverage for credit-scoring, education, insurance, or employment overlays.

Unresolved questions (6):

  • What is the exact statutory response-window (days) for controller responses to data subject access/correction requests under the DPPA 2019/DPPR 2021?
  • Does the DPPR 2021 contain a codified SCC/BCR-equivalent transfer mechanism, and if so what are its named safeguards?
  • Has Uganda received or granted any formal adequacy-style determination with any other jurisdiction?
  • Is there a distinct Records-of-Processing-Activities (ROPA) obligation separate from the general registration requirement?
  • Does any Ugandan instrument address automated decision-making/profiling transparency or AI-specific risk assessment?
  • What are the current, verified corrected monetary penalty figures under Part 8 of the Act (the OCR'd secondary-source figures for 'unlawful obtaining/disclosure' and 'sale of personal data' fines appear inconsistent and require primary-gazette verification)?

Escalate to primary-source review: yes