Skip to the content
Global Data RulesData governance rules, country by country

Uganda

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Uganda — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Waking up

You can send data out of Uganda if the destination protects it about as well as Uganda does. The person agreeing also works. There is no list of approved countries and no standard contract. You judge it yourself and keep the paperwork. Banks are the exception. Their records must stay in Uganda for ten years. The regulator is staffed but cannot fine you. It sends serious cases to the police.

Data governance in Uganda

The eight things that decide how you handle data about people in Uganda. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. Uganda's privacy law reaches a company with no office in Uganda, if it handles personal data about Ugandan citizens. There is no minimum size, revenue or staff count that keeps you out. Anyone who collects, uses or controls personal data must also sign up to a public register kept by the regulator. You renew that registration every year.

What you have to do here:
Register or notify · Appoint a data protection officer

Where the data is allowed to live

In general, yes. Data may leave Uganda if the destination country protects personal data at least as well as Uganda's own law does. It may also leave if the person the data is about has agreed. Nobody in government approves the transfer first. But four industries change that answer: banking, payments, telecoms and the public sector. Check your industry before you rely on the general rule.

What to do: Plan for a database inside Uganda: this data is not allowed to leave.

Sending data out of the country

There is no permit to apply for and no government-approved contract to sign. Either you satisfy yourself that the destination country protects data at least as well as Uganda does, or you get the person's consent. The government has never published a list of approved countries. So you make the judgement and keep the evidence. The regulator collects that assessment through its online portal. It scores it when you file your yearly compliance report.

Ways to send data out:
Official 'this country is safe' decision · Explicit consent

The regulator, and whether it actually acts

The Personal Data Protection Office, which sits inside the state IT agency. It is up and running. It has its own building in Kampala, a director, and published phone numbers and email addresses. It runs a live portal for registration, complaints, breach reports and yearly compliance filings. What it cannot do is fine you. It can order you to fix things, and it passes serious cases to the police. We found no published fines or formal decisions.

What it costs if you get it wrong:
Criminal liability · Claims by individuals

How long you must keep it — and when to delete it

The maximum is a judgement call. You must not keep personal data longer than you need it for the purpose you collected it for. The minimum is firm and long in finance. A licensed bank or other financial institution must keep its records for at least ten years, and inside Uganda. When the two clash, the law wins. The maximum has a built-in exception for anything you are required or allowed by law to keep.

What you have to do here:
Delete data after a period · Keep data for a minimum period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

There are at least three deadlines and they do not agree. The law says tell the regulator immediately when you believe someone has got at personal data without permission. The government's own security rules, published in July 2026, say seventy-two hours. Security incidents that do not involve personal data go to the national cyber response team. Banks, telecoms and health bodies must also tell their own regulator. One more twist. You do not decide whether to tell the people affected. The regulator does.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things. One: the law follows Ugandan citizens, not Ugandan residents. A Ugandan living abroad is still covered. Two: financial information counts as sensitive data in Uganda, which is unusual. Bank and card details attract the strictest rules. Three: there are no regulator fines here. There are criminal charges instead, with up to ten years in prison for an individual. A company can be fined up to two percent of its yearly gross turnover on conviction. Four: if you disagree with the regulator, you appeal to a government minister, not to a court. Five: banks must keep their records inside Uganda for ten years. Payment firms need the central bank's written permission before handing core operations to any outside supplier, including a foreign cloud.

What you have to do here:
Get a parent's consent for children
What it costs if you get it wrong:
Criminal liability · Percentage of global turnover

What's changing next

Nothing dramatic is scheduled in the next twelve months. The main near-term work is rollout. The updated national security rules launched in July 2026 now have to be put in place. That applies to government bodies, and to operators of critical infrastructure in banking, telecoms, energy, water, transport and health. The bigger risk is the powers the government already holds. The communications regulator can attach conditions to any licence forcing data to stay in Uganda, with no consultation. It did exactly that to a satellite operator in May 2026. The ICT minister can rewrite retention periods by making new regulations. The minister can also raise the value of the fine unit with Cabinet approval alone.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries5 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

Banking data needs a copy kept in the country

Official name: The Financial Institutions Act · Cap. 57 (2023 revised edition), section 45 · Act of parliament

In forceA copy must stay

A licensed bank, credit institution or other financial institution must keep its financial ledgers and records inside Uganda, in English, for at least ten years. Computer records count. Nothing stops a copy also sitting abroad, but the Ugandan copy is mandatory.

In force since 1 March 2004

Enforced by Bank of Uganda

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Payments

Cloud and outsourcing rules

Official name: The National Payment Systems Regulations, 2021 · Made under the National Payment Systems Act, 2020; regulations 25, 28 and 29 · Directly binding regulation

In forceYes, with paperwork

Uganda's payments rules set no requirement about where data is stored. They expressly send you back to the general privacy law. The real gate is different. A payments licensee cannot hand its licensed services, core payment operations or technical staff to any outside supplier. The central bank must approve that in writing first. This includes a foreign cloud provider. Cross-border payment services need their own approval.

In force since 1 January 2021

Enforced by Bank of Uganda

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Telecoms

Telecoms rules

Official name: Uganda Communications Commission infrastructure and service licence conditions on localisation and oversight · Licence conditions described by the Commission, 22 May 2026 (satellite operator entry) · Licence condition

In forceA copy must stay

The communications regulator attaches location conditions directly to operating licences. A licensed operator must run a national gateway with equipment physically in Uganda. Ugandan users' traffic must route through it. The operator must also register every device activated in the country. These conditions are negotiated licence by licence, not published as regulations.

In force since 22 May 2026

Enforced by Uganda Communications Commission

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.

Applies to every company1 rule

These bind you whatever business you are in, once the country's rules reach you.

General data protection law

Official name: The Data Protection and Privacy Act, 2019 · Act No. 9 of 2019; consolidated as Cap. 97 in the 2023 revised edition · Act of parliament

In forceYes, with paperwork

This is Uganda's general privacy law. Personal data may leave the country if the destination protects it at least as well as Uganda does. Consent from the person also works. There is no permit and no standard contract. Everyone handling personal data must register with the regulator and renew every year. You must also appoint a data protection officer and file an annual compliance report. Enforcement is criminal, not administrative.

In force since 3 May 2019

Enforced by Personal Data Protection Office

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Explicit consent

Who you would hear from

  • Personal Data Protection Office (PDPO)

    General privacy law: registration, complaints, breach reports, cross-border transfer assessments, compliance audits

    Fully staffed and operating as of 18 August 2026. It is headed by a National Personal Data Protection Director. It sits under the National Information Technology Authority - Uganda. It works from Padre Pio House, Plot 32 Lumumba Avenue, Kampala. It runs a live portal for registration, annual renewal, annual compliance reports, breach reporting and cross-border transfer impact assessments. It has a dedicated complaints and breach reporting mailbox. It has no power to impose administrative fines. Its complaint workflow includes an 'Escalated to CID' status, which refers cases to the police Criminal Investigations Directorate. We could not find any published enforcement decision or fine.

  • NITA-U

    The 'Authority' named in the privacy law; national data bank; national information security framework; government IT

    Actively publishing. Launched the Updated National Information Security Framework in July 2026 and a 2026 e-Government Interoperability Framework.

  • Banking, microfinance deposit-taking institutions, payment systems and electronic money

    Active. It publishes and updates supervisory circulars and payment system regulations. It last revised its payment systems oversight rules in 2025.

  • UCC

    Telecommunications, broadcasting, postal services, data communications and infrastructure licensing

    Active and interventionist. It publishes decisions and rulings, and runs enforcement campaigns. In May 2026 it put licence conditions on a satellite operator that force data through local infrastructure.

  • IRA

    Insurance, reinsurance, health membership organisations and intermediaries

    Active. It publishes licensing lists and circulars through 2026. We could not open its statute and regulation downloads, so no insurance-specific data rule is recorded here.

  • NLGRB

    Lotteries, gaming and betting

    Active. It publishes fee regulations, licensing lists and a machines register. We found no rule in its published regulations about server location, or about keeping data in the country.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The full text, statutory instrument number and exact obligations of the Data Protection and Privacy Regulations, 2021

    We could not confirm the full text of the 2021 Regulations. We found no copy on any Ugandan government website. Their existence and numbering come only from the regulator's own portal. It quotes regulation 47(3) on the data protection officer's job description, and regulation 50 on the annual compliance report. The portal does not publish the text itself.

  • That the breach notification deadline is exactly 72 hours

    We could not confirm the breach reporting deadline. The Act itself says 'immediately'. The 72-hour figure appears in the government's Updated National Information Security Framework 2026, which attributes it to the Act. We could not read the underlying regulation that sets it. Work to 'immediately'.

  • Registration fees and any size or turnover threshold for registering with the Personal Data Protection Office

    We could not confirm the registration fees, or whether any size or turnover cut-off applies. The portal charges fees through a billing step, but the fee schedule sits behind a login. Ask the regulator if the cost matters to you.

  • Whether the Personal Data Protection Office has issued any published enforcement decision, order or fine

    We could not confirm whether the regulator has taken any enforcement action. We found no decisions register on its site. It may act without publishing. Our enforcement rating of 'waking' rests on that gap.

  • Whether a foreign company with no establishment in Uganda can, or must, complete registration on the regulator's portal

    We could not confirm how a foreign company with no Ugandan office registers. The Act's scope clearly reaches such a company, and registration is written as universal. But we could not test the portal's business account flow without an account. Ask the regulator before you rely on this.

  • Insurance and securities sector rules on record location and cross-border transfer

    We found no rule for insurance or capital markets on where records sit or on sending data abroad. The insurance regulator's statute and regulation downloads load through scripts we could not follow. We could not reach the capital markets regulator's document library. If you work in these industries, check before you rely on this.

  • Whether online gaming or betting licences require servers or transaction data to be held in Uganda

    We found no rule requiring gaming servers or transaction data to be held in Uganda. Checked 18 August 2026, confidence low. The gaming board publishes its regulations list, but the files sit behind a script-driven download handler we could not use. Ask the board if this affects you.

  • General company-law and tax record retention periods

    We could not confirm general company and tax record-keeping periods. The revenue authority's statute pages returned errors. Only the ten-year banking minimum is evidenced here. Ask the revenue authority about tax records.

  • Whether the 2023 consolidation of the Act as Cap. 97 changed any operative wording

    We could not confirm whether the 2023 consolidation changed any wording. The regulator now cites Cap. 97 throughout. The only full text we could open on a government website is the original Act No. 9 of 2019. The section numbers quoted here come from that original text.

  • Whether the UCC localisation licence conditions apply beyond the single satellite operator described

    We could not confirm how widely these licence conditions apply. The Commission describes them as conditions written into that one operator's licence. The licence itself is not published. We found no general regulation putting the same requirement on all licensees.

  • Health-sector rules on where patient records may be held

    We could not confirm whether health has its own rule on where patient records may be held. The Ministry of Health site failed certificate checks from our tools and could not be read. We make no claim about health data here.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.