Uganda
East Africa
Uganda regulates personal data through the Data Protection and Privacy Act 2019 (Act No. 9 of 2019), which received assent on 28 February 2019 and commenced on 1 March 2019. It is supplemented by the Data Protection and Privacy Regulations, 2021 (SI No. 21 of 2021), which provide operational detail on registration, data protection officers, and impact assessments and are now recorded as a separate Instrument in the Library. The Act applies to any person, institution, or public body collecting, processing, holding, or using personal data in Uganda, and has extra-territorial reach over processors and controllers outside Uganda handling the personal data of Ugandan citizens; personal/household processing and specified national-security activities are exempt. Data collectors and processors must register annually with the Personal Data Protection Office and renew at least three months before expiry, with failure to register a criminal offence. Data subjects have rights to be informed, to access, to correct inaccurate data, and to compensation for damage or distress caused by a contravention, alongside protections around automated decision-making. A distinctive feature is the narrow cross-border transfer regime: transfers are permitted only where the destination country ensures adequate protection, and data-subject consent is the only expressly recognised alternative mechanism, the Act does not, unlike many peers, provide for standard contractual clauses or binding corporate rules. Criminal penalties run from fines and short custodial terms for registration failures to more serious sanctions for unlawfully obtaining, disclosing, or selling personal data. Enforcement is carried out by the Personal Data Protection Office (PDPO), an independent office within the National Information Technology Authority - Uganda (NITA-U), operationalised in August 2021. With a primary Act, supporting 2021 Regulations now documented, and an operational regulator, Uganda is a multi-instrument jurisdiction with a working, in-force regime, though its transfer mechanism is unusually restrictive.
| Topic | Instruments | Cases | Coverage |
|---|---|---|---|
| Data Protection | 4 | 1 | ● |
| AI Governance | 1 | 0 | ◐ |
| Fintech | 4 | 0 | ◐ |
| Cybercrime | 1 | 1 | ● |
| Digital Rights | 5 | 1 | ● |
| Platform Liability | 0 | 1 | ◐ |
| Telecoms | 2 | 0 | ◐ |
● Covered ◐ Partially covered ○ Not yet covered
The Access to Information Act, 2005 (Act No. 6 of 2005) (Uganda)
Enacted 7 Jul 2005
The Regulation of Interception of Communications Act, 2010 (Act No. 18 of 2010) (Uganda)
Enacted 5 Aug 2010
The Excise Duty (Amendment) Act, 2018, Over-the-Top (social media) tax (Uganda)
Enacted 30 Jun 2018
Constitution of the Republic of Uganda, 1995, Article 27 (Right to privacy of person, home, correspondence and communication)
Enacted 8 Oct 1995
The Computer Misuse Act, 2011 (Act No. 2 of 2011)
Enacted 14 Feb 2011
National Payment Systems (Agents) Regulations, 2021
Enacted 5 Mar 2021
National Payment Systems (Sandbox) Regulations, 2021
Enacted 5 Mar 2021
National Payment Systems Regulations, 2021
Enacted 5 Mar 2021
National Payment Systems Act, 2020 (Act No. 15 of 2020)
Enacted 29 Jul 2020
Uganda National 4IR Strategy (2020)
Data Protection and Privacy Regulations, 2021 (SI No. 21 of 2021) (Uganda)
Enacted 12 Mar 2021
Data Protection and Privacy Act 2019
Enacted 28 Feb 2019
Constitutional Court of Uganda
Decided 10 Jan 2023
Personal Data Protection Office (Uganda Registration Services Bureau)
Decided 18 Jul 2025
ATLPF now holds both the 2019 Act and the Data Protection and Privacy Regulations 2021 (SI No. 21 of 2021, corrected from an earlier mis-citation as SI No. 42). The cross-border transfer regime still recognises only adequacy or data-subject consent, with no statutory basis for standard contractual clauses or binding corporate rules, a practical constraint for international data flows.