Data Protection and Privacy Act 2019
ug-dppa-2019 · Act
The Data Protection and Privacy Act 2019 (Act No. 9 of 2019) is Uganda’s primary legislation governing the collection, processing, and protection of personal data. The Act received presidential assent on 28 February 2019 and commenced on 1 March 2019. It is supplemented by the Data Protection and Privacy Regulations 2021 (Statutory Instrument No. 42 of 2021), gazetted in March 2021, which provide operational detail on registration procedures, data protection officers, and data protection impact assessments. The Act applies to any person, institution, or public body that collects, processes, holds, or uses personal data within Uganda. It also has extra-territorial reach, applying to data processors and controllers located outside Uganda when they process personal data of Ugandan citizens. Processing for personal or household purposes is exempt, as are specified national security activities. Data collectors and processors must register annually with the Personal Data Protection Office (PDPO). Registration must be renewed at least three months before expiry; failure to register or renew constitutes a criminal offence. The PDPO maintains the register of all persons collecting or processing personal data, specifying the purpose for which data is collected in each case. Data subjects enjoy the right to be informed of the purposes for which their data is processed, the right of access to personal data held about them, the right to correction of inaccurate data, and the right to compensation for damage or distress suffered as a result of a contravention by a data controller or processor. The Act also provides protections in the context of automated decision-making. Cross-border transfers of personal data are permitted only where the destination country ensures an adequate level of protection comparable to Ugandan law. Consent by the data subject is the only alternative transfer mechanism expressly recognised under the Act; unlike many comparable frameworks, the Act does not provide explicitly for standard contractual clauses or binding corporate rules as additional grounds for transfer. Criminal penalties include fines and imprisonment for up to three months for registration failures, with more severe sanctions for offences such as unlawfully obtaining, disclosing, or selling personal data. The PDPO, an independent office within the structure of the National Information Technology Authority, Uganda (NITA-U) and operationalised in August 2021, enforces the Act through investigations, inspections, and enforcement notices, and may refer serious matters to law enforcement agencies.
- All persons and institutions collecting or processing personal data must register annually with the Personal Data Protection Office (PDPO) and renew at least three months before expiry
- Data subjects have rights to be informed about processing activities, to access personal data held about them, to have inaccurate data corrected, and to receive compensation for damage resulting from unlawful processing
- Cross-border transfers are permitted only where the destination country ensures adequate protection; consent of the data subject is the only expressly recognised alternative transfer mechanism
- Data Protection and Privacy Regulations 2021 (SI No. 42 of 2021) supplement the Act with registration procedures, DPO requirements, and data protection impact assessment obligations
- Criminal penalties include fines and imprisonment for registration failures and for unlawful obtaining, disclosing, or selling of personal data
- The PDPO operates as an independent office within NITA-U with powers of investigation, inspection, and enforcement notice
- Processing of sensitive personal data is subject to heightened conditions including requirements for explicit consent