Uganda
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
Uganda lets data leave if the destination protects it about as well as Uganda does, or the person agreed. There is no list of approved countries and no standard contract, so you judge it yourself and keep the paperwork. Banks are the exception: their records must stay in Uganda for ten years. The regulator is staffed but cannot fine you. It sends serious cases to the police.
Data governance in Uganda
The eight things that decide how you handle data about people in Uganda. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. Uganda's privacy law reaches a company with no office in Uganda if it handles personal data about Ugandan citizens. There is no minimum size, revenue or headcount to fall below. Anyone who collects, processes or controls personal data must also sign up to a public register kept by the regulator and renew that registration every year.
Section 1 of the Data Protection and Privacy Act (Act 9 of 2019, now consolidated as Cap. 97) applies the Act to a person, institution or public body '(a) collecting, processing, holding or using personal data within Uganda; (b) outside Uganda who collects, processes, holds, or uses personal data relating to Ugandan citizens.' Note the hook is citizenship, not residence — the Act does not use a targeting or 'offering goods and services' test the way Europe or India do. Sections 29 and 30 require the Authority to keep a data protection register covering every person, institution or public body collecting or processing personal data, and to make it open to public inspection. The regulator's own portal runs the registration, annual renewal, change-of-particulars and de-registration workflows. The Act does not itself require a named local representative, though the 2021 Regulations require a data protection officer.
Sources
- Official sourceNational Information Technology Authority - UgandaData Protection and Privacy Act, 2019 (Act 9 of 2019), sections 1, 29 and 30
nita.go.ug
“This Act applies to a person, institution or public body— (a) collecting, processing, holding or using personal data within Uganda; (b) outside Uganda who collects, processes, holds, or uses personal data relating to Ugandan citizens.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection OfficePersonal Data Protection Office compliance portal — registration, annual renewal and de-registration services
pdpo.go.ug
“Registration must be renewed annually. You are advised to renew before expiry to maintain continuous compliance with the Data Protection and Privacy Act, Cap. 97”
Link checked 18 August 2026
Where the data is allowed to live
In general, yes. Data may leave Uganda if the destination country protects personal data at least as well as Uganda's own law does, or if the person the data is about has agreed. Nobody in government approves the transfer first. But four industries override that headline: banking, payments, telecoms and the public sector. Check your industry before you rely on the general rule.
Section 19 of the Act is the whole general rule and it is two lines long. Rated by sector: banking is a copy must stay in the country — the Financial Institutions Act, Cap. 57 requires a licensed institution's financial ledgers and records to be kept in Uganda, and non-financial records to be maintained within Uganda. Payments is data can leave with paperwork with a hard gate — the National Payment Systems Regulations, 2021 forbid a licensee from outsourcing licensed services, the core operation of a payment system, or technical personnel without the central bank's written approval, and forbid offering cross-border payment services without separate written approval; the same Regulations contain no storage-location rule and instead point back to the general privacy law. Telecoms is a copy must stay in the country in practice — the communications regulator attached licence conditions in May 2026 requiring a national gateway with a physical point of presence in Uganda and routing of Ugandan users' traffic through local infrastructure. Government is a copy must stay in the country — public bodies must link their databases into a national data bank managed by the state IT agency inside Uganda. For insurance, securities, health, education, gambling and mapping we found no localisation or transfer rule beyond the general law, checked 18 August 2026, confidence medium; see the unconfirmed list.
Sources
- Official sourceNational Information Technology Authority - UgandaData Protection and Privacy Act, 2019, section 19 (processing personal data outside Uganda)
nita.go.ug
“Where a data processor or data controller based in Uganda processes or stores personal data outside Uganda, the data processor or data controller shall ensure that— (a) the country in which the data is processed or stored has adequate measures in place for the protection of personal data at least equivalent to the protection provided for by this Act; or (b) the data subject has consented.”
Link checked 18 August 2026
- Official sourceBank of UgandaFinancial Institutions Act, Cap. 57, section 45 (financial ledgers and other financial records)
bou.or.ug
“The financial ledgers and other financial records to which this section applies shall be kept in Uganda”
Link checked 18 August 2026
- Official sourceUganda Communications CommissionStarlink in Uganda: Taxation, Data Sovereignty and Regulation, 22 May 2026
ucc.co.ug
“UCC has addressed this through explicit license conditions focused on localisation and oversight. The key measures incorporated within the Starlink licensing conditions include a national gateway with a physical point of presence in Uganda where traffic for Ugandan users must route through local infrastructure”
Link checked 18 August 2026
Sending data out of the country
There is no permit to apply for and no government-approved contract to sign. You must either satisfy yourself that the destination country protects data at least as well as Uganda does, or get the person's consent. The government has never published a list of approved countries, so you make the judgement and keep the evidence. The regulator collects that assessment through its online portal and scores it when you file your yearly compliance report.
The statutory model is self-assessed adequacy with a consent fallback, not a blocklist or an allowlist. No list of adequate or prohibited destinations has been published, so there is nothing to check against. The regulator's portal carries a standing notice that 'Cross border data transfers require an adequacy assessment of the country to which you intend to transfer or consent of the data subject', and runs a Cross-border Transfer Impact Assessment module in which an organisation uploads the destination entity's approved data protection policy and approved information security policy. A cross-border score also feeds the annual compliance report required by regulation 50 of the Data Protection and Privacy Regulations 2021. Practically: the paperwork burden is real even though the approval step is not.
Sources
- Official sourcePersonal Data Protection OfficePersonal Data Protection Office portal — cross-border transfer notice and Cross-border Transfer Impact Assessment module
pdpo.go.ug
“Cross border data transfers require an adequacy assessment of the country to which you intend to transfer or consent of the data subject”
Link checked 18 August 2026
- Official sourceNational Information Technology Authority - UgandaData Protection and Privacy Act, 2019, section 19
nita.go.ug
Link checked 18 August 2026
The regulator, and whether it actually acts
The Personal Data Protection Office, which sits inside the state IT agency. It is genuinely up and running: it has its own building in Kampala, a director, published phone numbers and email addresses, and a live portal that handles registration, complaints, breach reports and yearly compliance filings. What it cannot do is fine you. It can order you to fix things, and it passes serious cases to the police. We found no published fines or formal decisions.
The Office was established under the Data Protection and Privacy Act and operates under the National Information Technology Authority - Uganda, headed by a National Personal Data Protection Director, from the 7th Floor, Padre Pio House, Plot 32 Lumumba Avenue, Kampala. Its portal exposes registration, annual compliance reporting, breach reporting, complaints, cross-border transfer assessments and audits, and its complaint workflow includes a formal status 'Escalated to CID' — the Uganda Police Criminal Investigations Directorate. That is the enforcement route: the Act gives the Authority power under section 32 to direct a controller or processor to remedy a breach, gives data subjects a right under section 33 to sue for compensation in court, and reserves punishment to criminal prosecution under sections 35 to 38. There is no administrative fining power. Appeals against the Authority's decisions go to the Minister, not to a court or tribunal. Rated 'waking' rather than 'active' because the machinery is fully staffed and operating but we could locate no published enforcement decision. Sector regulators — the central bank, the communications regulator and the insurance regulator — are separately and clearly active.
Sources
- Official sourcePersonal Data Protection OfficePersonal Data Protection Office — mandate, contacts and live compliance portal
pdpo.go.ug
“Uganda's independent data protection authority, established to implement and enforce the Data Protection and Privacy Act, Cap. 97”
Link checked 18 August 2026
- Official sourceNational Information Technology Authority - UgandaPersonal Data Protection Office — data protection and privacy audits and advisory service
nita.go.ug
Link checked 18 August 2026
- Official sourceNational Information Technology Authority - UgandaData Protection and Privacy Act, 2019, sections 32, 33 and 34
nita.go.ug
“A person aggrieved by a decision of the Authority under this Act may appeal to the Minister.”
Link checked 18 August 2026
How long you must keep it — and when to delete it
The ceiling is a judgement call: you must not keep personal data longer than you need it for the purpose you collected it for. The floor is hard and long in finance — a licensed bank or other financial institution must keep its records for at least ten years, and inside Uganda. When the two clash, the law wins: the ceiling has a built-in exception for anything you are required or allowed by law to keep.
Section 18 of the Data Protection and Privacy Act sets the ceiling and its own escape hatches: retention is permitted beyond need where it 'is required or authorised by law', is necessary for a lawful purpose related to the activity, is required by a contract between the parties, or the data subject consents. Destruction must be done so the record cannot be reconstructed in an intelligible form. Section 45(5) of the Financial Institutions Act, Cap. 57 sets the banking floor at not less than ten years, and section 45(3) requires those records to be kept in Uganda; 'financial records' is defined to include any computer record. So a bank's conflict resolves cleanly in favour of the ten-year floor. General company and tax record-keeping periods were not verified for this record — see the unconfirmed list.
Sources
- Official sourceNational Information Technology Authority - UgandaData Protection and Privacy Act, 2019, section 18 (retention of records of personal data)
nita.go.ug
“a person who collects personal data shall not retain the personal data for a period longer than is necessary to achieve the purpose for which the data is collected and processed unless— (a) the retention of the data is required or authorised by law;”
Link checked 18 August 2026
- Official sourceBank of UgandaFinancial Institutions Act, Cap. 57, section 45(5)
bou.or.ug
“A financial institution shall preserve the financial ledgers and other financial records referred to in this section for a period of not less than ten years.”
Link checked 18 August 2026
If something goes wrong
There are at least three clocks and they do not agree. The law says tell the regulator immediately when you believe someone has got at personal data without permission. The government's own security framework, published in July 2026, says seventy-two hours. Separately, security incidents that do not involve personal data go to the national cyber response team, and banks, telecoms and health bodies must also tell their own regulator. One more twist: you do not decide whether to tell the affected people. The regulator does.
Section 23 of the Act requires a data collector, processor or controller who believes personal data has been accessed or acquired by an unauthorised person to 'immediately notify the Authority in the prescribed manner' of the unauthorised access and the remedial action taken. The Authority then decides whether the individuals should be told, and if so the notification must go by registered mail, by email, by a prominent notice on the responsible party's website, or by publication in the mass media. The Updated National Information Security Framework 2026, launched by the Minister of ICT and National Guidance on 15 July 2026, states the deadline as 72 hours. Treat 'immediately' as the operative instruction and 72 hours as the outer limit. The regulator runs a dedicated breach reporting workflow and a breach reporting mailbox.
Sources
- Official sourceNational Information Technology Authority - UgandaData Protection and Privacy Act, 2019, section 23 (notification of data security breaches)
nita.go.ug
“the data collector, data processor or data controller, shall immediately notify the Authority in the prescribed manner, of the unauthorised access or acquisition and the remedial action taken.”
Link checked 18 August 2026
- Official sourceNational Information Technology Authority - UgandaUpdated National Information Security Framework (NISF) 2026, section 4.1 (breach notification)
nita.go.ug
“All organisations are required to notify the Personal Data Protection Office (PDPO) of personal data breaches within 72 hours of becoming aware of the incident, as mandated by the DPPA.”
Link checked 18 August 2026
What catches people out
Five things that are not in the summary. One: the law follows Ugandan citizens, not Ugandan residents, so a Ugandan living abroad is still covered. Two: financial information counts as sensitive data in Uganda, which is unusual, so bank and card details attract the strictest rules. Three: there are no regulator fines here — there are criminal charges, up to ten years in prison for an individual, and up to two percent of a company's yearly gross turnover on conviction. Four: if you disagree with the regulator you appeal to a government minister, not to a court. Five: banks must keep their records inside Uganda for ten years, and payment firms need the central bank's written permission before handing core operations to any outside supplier, including a foreign cloud.
On sensitive data: section 9 bans collecting or processing data on religious or philosophical beliefs, political opinion, sexual life, financial information, health status or medical records, subject to narrow exceptions including free and informed consent and employer legal obligations. On children: section 8 requires prior parental or guardian consent unless the processing is required by law or is for research or statistical purposes; Uganda treats a child as a person under 18. On criminal exposure: section 35 (unlawfully obtaining or disclosing personal data) carries a fine of up to 240 currency points or ten years' imprisonment or both; section 36 (unlawful destruction, deletion, concealment or alteration) carries a fine of not less than 240 currency points or up to ten years; section 37 (selling personal data) carries up to 245 currency points or ten years. A currency point is 20,000 Uganda shillings, so 240 currency points is about 4.8 million shillings — roughly 1,300 US dollars, trivially small. The teeth are the prison term and section 38, under which the company and every officer who knowingly and wilfully authorises or permits the contravention commits the offence, and the court may additionally fine the company up to two percent of its annual gross turnover. The regulator's own complaint system contains a status 'Escalated to CID', confirming that criminal referral is a live pathway rather than a theoretical one.
Sources
- Official sourceNational Information Technology Authority - UgandaData Protection and Privacy Act, 2019, sections 8, 9, 35, 36, 37, 38 and Schedule (currency point)
nita.go.ug
“A person shall not collect or process personal data which relates to the religious or philosophical beliefs, political opinion, sexual life, financial information, health status or medical records of an individual.”
Link checked 18 August 2026
- Official sourceBank of UgandaNational Payment Systems Regulations, 2021, regulation 28 (outsourcing requirements)
bou.or.ug
“A licensee shall not outsource its licensed services, core operation of a payment system or technical personnel except with the written approval of the central bank.”
Link checked 18 August 2026
What's changing next
Nothing dramatic is scheduled in the next twelve months. The main near-term work is rollout: the updated national security framework launched in July 2026 now has to be implemented by government bodies and by operators of critical infrastructure in banking, telecoms, energy, water, transport and health. The bigger risk is the switches the government already holds. The communications regulator can bolt localisation conditions onto any licence with no consultation, and it did exactly that to a satellite operator in May 2026. The ICT minister can rewrite retention periods by statutory instrument, and can raise the value of the fine unit with Cabinet approval alone.
Dormant switches to watch. First, licence conditions: the Uganda Communications Commission imposed a national gateway and local traffic-routing requirement on Starlink through licence terms, not through published regulations, and can repeat that for any licensee at any time. Second, section 39 of the Data Protection and Privacy Act empowers the Minister, after consulting the Authority, to make regulations by statutory instrument covering any prescribed matter and specifically 'the retention period of personal data' — a national retention mandate could appear without primary legislation. Third, section 40 lets the Minister amend the Schedule with Cabinet approval, and the Schedule sets the currency point at 20,000 shillings; multiplying that figure multiplies every fine in the Act overnight. Fourth, regulation 3 of the National Data Bank Regulations lets the state IT agency prescribe how every public body links its database into the national data bank, which is a standing power over public-sector architecture. Fifth, the National Payment Systems Regulations give the central bank a thirty-day approval discretion over any outsourcing by a payments licensee. Recurring calendar items: annual registration renewal with the regulator, and the annual compliance report under regulation 50 of the 2021 Regulations, after which you have 14 days to file a remedial action plan if the report is queried.
Sources
- Official sourceNational Information Technology Authority - UgandaMinister launches Updated National Information Security Framework (NISF) 2026, 15 July 2026
nita.go.ug
Link checked 18 August 2026
- Official sourceNational Information Technology Authority - UgandaData Protection and Privacy Act, 2019, sections 39 and 40 (regulation-making and power to amend the Schedule)
nita.go.ug
“The Minister may, after consultation with the Authority by statutory instrument make regulations for— ... (c) the retention period of personal data;”
Link checked 18 August 2026
- Official sourceUganda Communications CommissionStarlink in Uganda: Taxation, Data Sovereignty and Regulation, 22 May 2026 — localisation imposed by licence condition
ucc.co.ug
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries5 rules
If your product does one of these things, read this group first — industry rules beat the general position.
The Financial Institutions Act
Act of parliament · Cap. 57 (2023 revised edition), section 45
A licensed bank, credit institution or other financial institution must keep its financial ledgers and records inside Uganda, in English, for at least ten years. Computer records count. Nothing stops a copy also sitting abroad, but the Ugandan copy is mandatory.
Enforced by Bank of Uganda
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep the data in the countryFinancial ledgers and other financial records must be kept in Uganda; necessary non-financial records must also be maintained within Uganda. 'Financial records' expressly includes computer records.
- Keep data for a minimum period — 10 yearsNot less than ten years.
- Secure the dataThe institution and its agents must prevent loss, destruction and falsification, and stop unauthorised persons accessing the records.
Sources
- Official sourceBank of UgandaFinancial Institutions Act, Cap. 57, section 45 (financial ledgers and other financial records)
bou.or.ug
“Every financial institution shall, without derogation from subsections (1) and (3), maintain within Uganda such non-financial records as are necessary”
Link checked 18 August 2026
The National Payment Systems Regulations, 2021
Directly binding regulation · Made under the National Payment Systems Act, 2020; regulations 25, 28 and 29
Uganda's payments rules contain no storage-location requirement and expressly send you back to the general privacy law. The real gate is different: a payments licensee cannot hand its licensed services, core payment operations or technical staff to any outside supplier — including a foreign cloud provider — without the central bank's written approval, and cross-border payment services need their own approval.
Enforced by Bank of Uganda
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Written vendor contractNo outsourcing of licensed services, the core operation of a payment system, or technical personnel without the central bank's written approval. The central bank has 30 days to decide.
- Register or notifySeparate written approval is needed before operating a cross-border payment system or offering cross-border payment services.
- Independent auditThe management information system must produce an audit trail usable by internal auditors, external auditors and the central bank, and the central bank must be given access to the licensee's electronic systems and records.
- Secure the data
What it costs if you get it wrong
- Daily fine until fixed: 200 currency points per day (UGX 4,000,000 per day) — about $1 thousandMerger or acquisition without the central bank's written approval
Sources
- Official sourceBank of UgandaThe National Payment Systems Regulations, 2021, Part IV (regulations 25, 26, 28 and 29)
bou.or.ug
“A payment service provider shall collect, process, control and manage personal data in accordance with the Data Protection and Privacy Act, 2019.”
Link checked 18 August 2026
Uganda Communications Commission infrastructure and service licence conditions on localisation and oversight
Licence condition · Licence conditions described by the Commission, 22 May 2026 (satellite operator entry)
The communications regulator attaches localisation conditions directly to operating licences. A licensed operator must run a national gateway with equipment physically in Uganda and route Ugandan users' traffic through it, and must register every device activated in the country. These conditions are negotiated per licence rather than published as regulations.
Enforced by Uganda Communications Commission
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryA national gateway with a physical point of presence in Uganda; traffic for Ugandan users must route through local infrastructure.
- Register or notifyLocal registration of every device activated in Uganda.
- Do not hand data to foreign authorities on demandThe stated purpose is to enable lawful interception and monitoring under Ugandan law rather than offshore.
What it costs if you get it wrong
- Loss of your licenceBreach of licence conditions
Sources
- Official sourceUganda Communications CommissionStarlink in Uganda: Taxation, Data Sovereignty and Regulation, 22 May 2026
ucc.co.ug
“Starlink is also required to ensure the local registration of all devices activated within Uganda to enhance accountability and support regulatory enforceability in accordance with national laws.”
Link checked 18 August 2026
The National Information Technology Authority, Uganda (National Data Bank) Regulations, 2019
Directly binding regulation · Statutory Instrument 2019 No. 109; Uganda Gazette No. 64, Volume CXII, 20 December 2019
Every Ugandan public body must link its database into a single national data bank run by the state IT agency, so an in-country instance of government data is effectively mandatory. The agency sets the access levels and keeps a register of every database in the system.
Enforced by National Information Technology Authority - Uganda
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryEvery public body must link its database to the national data bank operated inside Uganda by the state IT agency, in the manner that agency prescribes.
- Register or notifyThe agency keeps a register of every database in the national data bank, naming the database, the public body and the purpose.
- Secure the data
What it costs if you get it wrong
- Criminal liability: 48 currency points (UGX 960,000) or 24 months' imprisonment; 72 currency points or 3 years on repeat; plus up to 10 currency points per day for a continuing offence — about $260Using the national data bank to gain unlawful access to a database
Sources
- Official sourceNational Information Technology Authority - UgandaThe National Information Technology Authority, Uganda (National Data Bank) Regulations, 2019 (S.I. No. 109 of 2019)
nita.go.ug
“For the purposes of this regulation, every data controller shall link its database to the national databank as prescribed by the Authority.”
Link checked 18 August 2026
Updated National Information Security Framework (NISF) 2026
Regulator guideline · Launched by the Minister of ICT and National Guidance, 15 July 2026; successor to the 2014 framework endorsed by Presidential Security Directive No. 1 of 2014
Guidance, not a statute, but it is how the Ugandan state expects government bodies and critical infrastructure operators in finance, telecoms, energy, water, transport and health to behave. It does not require data to stay in Uganda; it requires data sovereignty terms, encryption and certified providers to be written into cloud contracts, and it fixes the personal data breach clock at 72 hours.
Enforced by National Information Technology Authority - Uganda
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report breaches to the regulator — within 72 hoursPersonal data breaches to the Personal Data Protection Office within 72 hours of becoming aware.
- Report cyber incidentsSecurity breaches not involving personal data go to the national computer security incident response team, CERT-UG. Government bodies and critical infrastructure operators must also tell their sector regulator.
- Written vendor contractData sovereignty, encryption in transit and at rest, and the shared responsibility model must be written into every cloud contract and service level agreement.
- Hold a security certificateCloud providers must meet recognised standards such as ISO/IEC 27017, ISO/IEC 27018 and the Cloud Security Alliance Cloud Controls Matrix; third-party audit reports must be reviewed annually.
- Assess high-risk projectsJoint risk assessment by the information risk owner and the data protection officer before adopting cloud.
Sources
- Official sourceNational Information Technology Authority - UgandaUpdated National Information Security Framework (NISF) 2026, sections 4.1, 4.2 and 5.2.4.1
nita.go.ug
“Define data sovereignty, encryption requirements (in transit and at rest), and the shared responsibility model in all contracts and Service Level Agreements (SLAs).”
Link checked 18 August 2026
- Official sourceNational Information Technology Authority - UgandaMinister launches Updated National Information Security Framework (NISF) 2026, 15 July 2026
nita.go.ug
Link checked 18 August 2026
Applies to every company1 rule
These bind you whatever business you are in, once the country's rules reach you.
The Data Protection and Privacy Act, 2019
Act of parliament · Act No. 9 of 2019; consolidated as Cap. 97 in the 2023 revised edition
Uganda's general privacy law. Personal data may leave the country if the destination protects it at least as well as Uganda does, or if the person consented — no permit and no standard contract. Everyone handling personal data must register with the regulator and renew yearly, appoint a data protection officer and file an annual compliance report. Enforcement is criminal, not administrative.
Enforced by Personal Data Protection Office
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Explicit consent
What it makes you do
- Register or notifyEvery data collector, processor and controller must be entered in the public data protection register and renew annually.
- Get consent
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people object
- Limit automated decisions
- Secure the data
- Report breaches to the regulator — within 72 hoursThe Act says 'immediately'. The government's 2026 security framework states 72 hours. Work to 'immediately'.
- Tell affected peopleOnly where the regulator decides the individuals must be told.
- Delete data after a period
- Put a transfer safeguard in placeSelf-assessed adequacy of the destination country, or the person's consent. No government list and no standard contract exists.
- Get a parent's consent for children — applies at: under 18
- Appoint a data protection officerRequired by the 2021 Regulations; the job description must meet regulation 47(3).
- Independent auditAnnual compliance report to the regulator under regulation 50 of the 2021 Regulations; 14 days to file a remedial action plan if queried.
- Assess high-risk projects
What it costs if you get it wrong
- Criminal liability: 240 currency points (UGX 4,800,000) or 10 years' imprisonment or both — about $1 thousandUnlawfully obtaining, disclosing or procuring disclosure of personal data
- Criminal liability: 245 currency points (UGX 4,900,000) or 10 years' imprisonment or both — about $1 thousandSelling or offering to sell personal data
- Percentage of global turnover: 2% of annual gross turnoverAdditional fine a court may order against a convicted corporation
- Claims by individualsA data subject who suffers damage or distress may sue for compensation
Sources
- Official sourceNational Information Technology Authority - UgandaThe Data Protection and Privacy Act, 2019 (Act No. 9 of 2019) — full text
nita.go.ug
Link checked 18 August 2026
- Official sourceNational Information Technology Authority - UgandaLaws and Regulations — Data Protection and Privacy Act No. 9 of 2019
nita.go.ug
Link checked 18 August 2026
- Official sourcePersonal Data Protection OfficePersonal Data Protection Office — registration, annual compliance report (regulation 50) and data protection officer duties (regulation 47(3))
pdpo.go.ug
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The full text, statutory instrument number and exact obligations of the Data Protection and Privacy Regulations, 2021
We could not find a copy hosted on any Ugandan government domain. Their existence and specific regulation numbers (47(3) on the data protection officer's job description, 50 on the annual compliance report) are evidenced only by the regulator's own portal, which quotes them but does not publish the instrument.
That the breach notification deadline is exactly 72 hours
The Act itself says 'immediately'. The 72-hour figure appears in the government's Updated National Information Security Framework 2026, which attributes it to the Act. We could not read the underlying regulation that sets it. Plan to 'immediately'.
Registration fees and any size or turnover threshold for registering with the Personal Data Protection Office
The portal charges fees through a billing step but the fee schedule is behind a login. Not verified.
Whether the Personal Data Protection Office has issued any published enforcement decision, order or fine
No decisions register was found on the regulator's site. We cannot prove a negative; the office may act without publishing. Enforcement is rated 'waking' on that basis.
Whether a foreign company with no establishment in Uganda can, or must, complete registration on the regulator's portal
The Act's scope clearly reaches such a company, and registration is expressed as universal, but the portal's business account flow was not testable without an account.
Insurance and securities sector rules on record location and cross-border transfer
The insurance regulator's statute and regulation downloads are loaded by scripts we could not follow, and the capital markets regulator's document library was not reached. No rule is asserted for these sectors.
Whether online gaming or betting licences require servers or transaction data to be held in Uganda
The gaming board publishes its regulations list but the files themselves are behind a script-driven download handler. Checked 18 August 2026; no such requirement found, confidence low.
General company-law and tax record retention periods
The revenue authority's statute pages returned errors. Only the ten-year banking floor is evidenced here.
Whether the 2023 consolidation of the Act as Cap. 97 changed any operative wording
The regulator now cites Cap. 97 throughout, but the only full text we could open on a government domain is the original Act No. 9 of 2019. Section numbers quoted here are from that original text.
Whether the UCC localisation licence conditions apply beyond the single satellite operator described
The Commission describes them as conditions incorporated in that operator's licence. The licence itself is not published, and we found no general regulation imposing the same requirement on all licensees.
Health-sector rules on where patient records may be held
The Ministry of Health site failed certificate validation from our fetcher and could not be read. No health-specific rule is asserted.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
Uganda versus
Compare