UgandaIn ForceData Protection

Data Protection and Privacy Regulations, 2021 (SI No. 21 of 2021) (Uganda)

ug-dpp-regs-2021 · Regulation

Verified entryReviewed by Ademola Adekunbi · 27 June 2026
Summary

The Data Protection and Privacy Regulations, 2021 (Statutory Instrument No. 21 of 2021) are the principal subsidiary legislation under Uganda's Data Protection and Privacy Act 2019. They were made on 29 January 2021 in exercise of the powers conferred by section 39 of the Act and took effect on 12 March 2021. (Note: this instrument is correctly cited as SI No. 21 of 2021; some secondary sources, and an earlier ATLPF note, erroneously refer to it as SI No. 42 of 2021.) The Regulations provide the operational detail needed to implement the Act. They address the establishment and management of the Personal Data Protection Office (PDPO), including its additional functions and powers; data collection and processing requirements, including objections to collection, special provisions for children's data, and data protection impact assessments; and procedural matters such as the registration of data collectors, processors, and controllers, and the procedures for enforcement of personal data privacy rights. They give practical effect to the Act's registration regime and to data-subject-rights mechanics. Together with the 2019 Act, these Regulations form the operative core of Uganda's data protection framework, administered by the PDPO (an office within NITA-U). This entry was created during a June 2026 documentation pass and is AI-drafted; the primary text is available via ULII and the PDPO website. Reviewer should confirm any subsequent amendments. Source language: English.

Key provisions
  1. Principal subsidiary legislation under the Data Protection and Privacy Act 2019; made 29 January 2021 under section 39, effective 12 March 2021 (SI No. 21 of 2021).
  2. Correct citation is SI No. 21 of 2021 (not 42, as some sources state).
  3. Provides for the establishment, functions, and powers of the Personal Data Protection Office (PDPO).
  4. Sets out data collection and processing requirements, including objections, children's data, and data protection impact assessments.
  5. Establishes procedures for registration of data collectors, processors, and controllers.
  6. Sets out procedures for enforcement of personal data privacy rights.
  7. Reviewer action: confirm any subsequent amendments.