Uganda
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Uganda — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can send data out of Uganda if the destination protects it about as well as Uganda does. The person agreeing also works. There is no list of approved countries and no standard contract. You judge it yourself and keep the paperwork. Banks are the exception. Their records must stay in Uganda for ten years. The regulator is staffed but cannot fine you. It sends serious cases to the police.
Data governance in Uganda
The eight things that decide how you handle data about people in Uganda. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. Uganda's privacy law reaches a company with no office in Uganda, if it handles personal data about Ugandan citizens. There is no minimum size, revenue or staff count that keeps you out. Anyone who collects, uses or controls personal data must also sign up to a public register kept by the regulator. You renew that registration every year.
- What you have to do here:
- Register or notify · Appoint a data protection officer
Section 1 of the Data Protection and Privacy Act (Act 9 of 2019, now consolidated as Cap. 97) sets out who it covers. It covers a person, institution or public body that collects, handles, holds or uses personal data within Uganda. It also covers one outside Uganda that does the same with personal data about Ugandan citizens. The hook is citizenship, not where the person lives. The Act does not use a targeting test, or an 'offering goods and services' test, the way Europe and India do. Sections 29 and 30 require the Authority to keep a data protection register. It covers every person, institution or public body that collects or handles personal data. It must be open to public inspection. The regulator's own portal runs registration, annual renewal, changes of details and de-registration. The Act does not itself require a named local representative. The 2021 Regulations do require a data protection officer.
Sources
- Official sourceNational Information Technology Authority - UgandaData Protection and Privacy Act, 2019 (Act 9 of 2019), sections 1, 29 and 30
nita.go.ug
“This Act applies to a person, institution or public body— (a) collecting, processing, holding or using personal data within Uganda; (b) outside Uganda who collects, processes, holds, or uses personal data relating to Ugandan citizens.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection OfficePersonal Data Protection Office compliance portal — registration, annual renewal and de-registration services
pdpo.go.ug
“Registration must be renewed annually. You are advised to renew before expiry to maintain continuous compliance with the Data Protection and Privacy Act, Cap. 97”
Link checked 18 August 2026
Where the data is allowed to live
In general, yes. Data may leave Uganda if the destination country protects personal data at least as well as Uganda's own law does. It may also leave if the person the data is about has agreed. Nobody in government approves the transfer first. But four industries change that answer: banking, payments, telecoms and the public sector. Check your industry before you rely on the general rule.
Section 19 of the Act is the whole general rule, and it is two lines long. Industry by industry. BANKING: a copy must stay in the country The Financial Institutions Act, Cap. 57 requires a licensed institution to keep its financial ledgers and records in Uganda. Necessary non-financial records must also be kept within Uganda. PAYMENTS: data can leave only if conditions are met, with a firm gate. The National Payment Systems Regulations, 2021 forbid a licensee from outsourcing three things without the central bank's written approval. Those are licensed services, the core operation of a payment system, and technical personnel. Offering cross-border payment services needs separate written approval. The same Regulations set no rule about where data is stored. They point back to the general privacy law instead. TELECOMS: a copy must stay in the country The communications regulator attached licence conditions in May 2026. They require a national gateway with a physical point of presence in Uganda. Ugandan users' traffic must route through local infrastructure. GOVERNMENT: a copy must stay in the country Public bodies must link their databases into a national data bank managed by the state IT agency inside Uganda. INSURANCE, SECURITIES, HEALTH, EDUCATION, GAMBLING AND MAPPING: we found no storage or transfer rule beyond the general law. Checked 18 August 2026, confidence medium. See the unconfirmed list.
Sources
- Official sourceNational Information Technology Authority - UgandaData Protection and Privacy Act, 2019, section 19 (processing personal data outside Uganda)
nita.go.ug
“Where a data processor or data controller based in Uganda processes or stores personal data outside Uganda, the data processor or data controller shall ensure that— (a) the country in which the data is processed or stored has adequate measures in place for the protection of personal data at least equivalent to the protection provided for by this Act; or (b) the data subject has consented.”
Link checked 18 August 2026
- Official sourceBank of UgandaFinancial Institutions Act, Cap. 57, section 45 (financial ledgers and other financial records)
bou.or.ug
“The financial ledgers and other financial records to which this section applies shall be kept in Uganda”
Link checked 18 August 2026
- Official sourceUganda Communications CommissionStarlink in Uganda: Taxation, Data Sovereignty and Regulation, 22 May 2026
ucc.co.ug
“UCC has addressed this through explicit license conditions focused on localisation and oversight. The key measures incorporated within the Starlink licensing conditions include a national gateway with a physical point of presence in Uganda where traffic for Ugandan users must route through local infrastructure”
Link checked 18 August 2026
What to do: Plan for a database inside Uganda: this data is not allowed to leave.
Sending data out of the country
There is no permit to apply for and no government-approved contract to sign. Either you satisfy yourself that the destination country protects data at least as well as Uganda does, or you get the person's consent. The government has never published a list of approved countries. So you make the judgement and keep the evidence. The regulator collects that assessment through its online portal. It scores it when you file your yearly compliance report.
- Ways to send data out:
- Official 'this country is safe' decision · Explicit consent
The model is your own assessment of the destination, with consent as a fallback. There is no list of banned countries and no list of approved ones. Nothing has been published either way, so there is nothing to check against. The regulator's portal carries a standing notice. It says cross-border transfers need an assessment of how well the destination country protects data, or the consent of the person the data is about. The portal also runs a Cross-border Transfer Impact Assessment module. You upload the destination organisation's approved data protection policy and approved information security policy. A cross-border score also feeds the annual compliance report required by regulation 50 of the Data Protection and Privacy Regulations 2021. So the paperwork is real, even though there is no approval step.
Sources
- Official sourcePersonal Data Protection OfficePersonal Data Protection Office portal — cross-border transfer notice and Cross-border Transfer Impact Assessment module
pdpo.go.ug
“Cross border data transfers require an adequacy assessment of the country to which you intend to transfer or consent of the data subject”
Link checked 18 August 2026
- Official sourceNational Information Technology Authority - UgandaData Protection and Privacy Act, 2019, section 19
nita.go.ug
Link checked 18 August 2026
The regulator, and whether it actually acts
The Personal Data Protection Office, which sits inside the state IT agency. It is up and running. It has its own building in Kampala, a director, and published phone numbers and email addresses. It runs a live portal for registration, complaints, breach reports and yearly compliance filings. What it cannot do is fine you. It can order you to fix things, and it passes serious cases to the police. We found no published fines or formal decisions.
- What it costs if you get it wrong:
- Criminal liability · Claims by individuals
The Office was created under the Data Protection and Privacy Act. It operates under the National Information Technology Authority - Uganda. It is headed by a National Personal Data Protection Director. It works from the 7th Floor, Padre Pio House, Plot 32 Lumumba Avenue, Kampala. Its portal handles registration, annual compliance reporting, breach reporting, complaints, cross-border transfer assessments and audits. Its complaint workflow includes a formal status of 'Escalated to CID'. That is the Uganda Police Criminal Investigations Directorate. That is the enforcement route. Section 32 lets the Authority direct an organisation to put a breach right. Section 33 gives the person the data is about a right to sue for compensation in court. Punishment is reserved to criminal prosecution under sections 35 to 38. There is no power to impose administrative fines. Appeals against the Authority's decisions go to the Minister, not to a court or tribunal. We rate it 'waking' rather than 'active'. The office is fully staffed and operating, but we could find no published enforcement decision. Industry regulators are separately and clearly active. Those are the central bank, the communications regulator and the insurance regulator.
Sources
- Official sourcePersonal Data Protection OfficePersonal Data Protection Office — mandate, contacts and live compliance portal
pdpo.go.ug
“Uganda's independent data protection authority, established to implement and enforce the Data Protection and Privacy Act, Cap. 97”
Link checked 18 August 2026
- Official sourceNational Information Technology Authority - UgandaPersonal Data Protection Office — data protection and privacy audits and advisory service
nita.go.ug
Link checked 18 August 2026
- Official sourceNational Information Technology Authority - UgandaData Protection and Privacy Act, 2019, sections 32, 33 and 34
nita.go.ug
“A person aggrieved by a decision of the Authority under this Act may appeal to the Minister.”
Link checked 18 August 2026
How long you must keep it — and when to delete it
The maximum is a judgement call. You must not keep personal data longer than you need it for the purpose you collected it for. The minimum is firm and long in finance. A licensed bank or other financial institution must keep its records for at least ten years, and inside Uganda. When the two clash, the law wins. The maximum has a built-in exception for anything you are required or allowed by law to keep.
- What you have to do here:
- Delete data after a period · Keep data for a minimum period
Section 18 of the Data Protection and Privacy Act sets the maximum, and its own exceptions. You may keep data beyond need where keeping it 'is required or authorised by law'. Also where it is necessary for a lawful purpose related to the activity. Also where a contract between the parties requires it. Or where the person the data is about consents. Destruction must be done so the record cannot be rebuilt in a readable form. Section 45(5) of the Financial Institutions Act, Cap. 57 sets the banking minimum at not less than ten years. Section 45(3) requires those records to be kept in Uganda. 'Financial records' is defined to include any computer record. So for a bank the clash resolves cleanly in favour of the ten-year minimum. We did not verify general company and tax record-keeping periods for this record. See the unconfirmed list.
Sources
- Official sourceNational Information Technology Authority - UgandaData Protection and Privacy Act, 2019, section 18 (retention of records of personal data)
nita.go.ug
“a person who collects personal data shall not retain the personal data for a period longer than is necessary to achieve the purpose for which the data is collected and processed unless— (a) the retention of the data is required or authorised by law;”
Link checked 18 August 2026
- Official sourceBank of UgandaFinancial Institutions Act, Cap. 57, section 45(5)
bou.or.ug
“A financial institution shall preserve the financial ledgers and other financial records referred to in this section for a period of not less than ten years.”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
There are at least three deadlines and they do not agree. The law says tell the regulator immediately when you believe someone has got at personal data without permission. The government's own security rules, published in July 2026, say seventy-two hours. Security incidents that do not involve personal data go to the national cyber response team. Banks, telecoms and health bodies must also tell their own regulator. One more twist. You do not decide whether to tell the people affected. The regulator does.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Section 23 of the Act covers anyone who collects, handles or controls data. You must 'immediately notify the Authority in the prescribed manner' if you believe someone has accessed or acquired personal data without permission. You report the unauthorised access and the action you took to fix it. The Authority then decides whether the people affected should be told. If they must be told, there are four ways to do it. Registered mail, email, a prominent notice on your website, or publication in the mass media. The Updated National Information Security Framework 2026 states the deadline as 72 hours. The Minister of ICT and National Guidance launched it on 15 July 2026. Treat 'immediately' as the instruction to follow, and 72 hours as the outer limit. The regulator runs a dedicated breach reporting workflow and a breach reporting mailbox.
Sources
- Official sourceNational Information Technology Authority - UgandaData Protection and Privacy Act, 2019, section 23 (notification of data security breaches)
nita.go.ug
“the data collector, data processor or data controller, shall immediately notify the Authority in the prescribed manner, of the unauthorised access or acquisition and the remedial action taken.”
Link checked 18 August 2026
- Official sourceNational Information Technology Authority - UgandaUpdated National Information Security Framework (NISF) 2026, section 4.1 (breach notification)
nita.go.ug
“All organisations are required to notify the Personal Data Protection Office (PDPO) of personal data breaches within 72 hours of becoming aware of the incident, as mandated by the DPPA.”
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things. One: the law follows Ugandan citizens, not Ugandan residents. A Ugandan living abroad is still covered. Two: financial information counts as sensitive data in Uganda, which is unusual. Bank and card details attract the strictest rules. Three: there are no regulator fines here. There are criminal charges instead, with up to ten years in prison for an individual. A company can be fined up to two percent of its yearly gross turnover on conviction. Four: if you disagree with the regulator, you appeal to a government minister, not to a court. Five: banks must keep their records inside Uganda for ten years. Payment firms need the central bank's written permission before handing core operations to any outside supplier, including a foreign cloud.
- What you have to do here:
- Get a parent's consent for children
- What it costs if you get it wrong:
- Criminal liability · Percentage of global turnover
SENSITIVE DATA. Section 9 bans collecting or using data about religious or philosophical beliefs, political opinion, sexual life, financial information, health status or medical records. Narrow exceptions apply. They include free and informed consent, and an employer's legal duties. CHILDREN. Section 8 requires the parent's or guardian's consent in advance. The exceptions are where the law requires the data to be used, or where it is for research or statistical purposes. Uganda treats a child as a person under 18. CRIMINAL EXPOSURE. Section 35 covers unlawfully obtaining or disclosing personal data. It carries a fine of up to 240 currency points, or ten years in prison, or both. Section 36 covers unlawful destruction, deletion, concealment or alteration. It carries a fine of not less than 240 currency points, or up to ten years. Section 37 covers selling personal data, with up to 245 currency points or ten years. A currency point is 20,000 Uganda shillings. So 240 currency points is about 4.8 million shillings, roughly 1,300 US dollars. That is very small. The real risk is the prison term, and section 38. Under section 38 the company and every officer who knowingly and wilfully authorises or permits the breach commits the offence. The court may also fine the company up to two percent of its annual gross turnover. The regulator's own complaint system has a status of 'Escalated to CID'. That confirms criminal referral is a live route, not a theoretical one.
Sources
- Official sourceNational Information Technology Authority - UgandaData Protection and Privacy Act, 2019, sections 8, 9, 35, 36, 37, 38 and Schedule (currency point)
nita.go.ug
“A person shall not collect or process personal data which relates to the religious or philosophical beliefs, political opinion, sexual life, financial information, health status or medical records of an individual.”
Link checked 18 August 2026
- Official sourceBank of UgandaNational Payment Systems Regulations, 2021, regulation 28 (outsourcing requirements)
bou.or.ug
“A licensee shall not outsource its licensed services, core operation of a payment system or technical personnel except with the written approval of the central bank.”
Link checked 18 August 2026
What's changing next
Nothing dramatic is scheduled in the next twelve months. The main near-term work is rollout. The updated national security rules launched in July 2026 now have to be put in place. That applies to government bodies, and to operators of critical infrastructure in banking, telecoms, energy, water, transport and health. The bigger risk is the powers the government already holds. The communications regulator can attach conditions to any licence forcing data to stay in Uganda, with no consultation. It did exactly that to a satellite operator in May 2026. The ICT minister can rewrite retention periods by making new regulations. The minister can also raise the value of the fine unit with Cabinet approval alone.
POWERS ALREADY HELD, TO WATCH. First, licence conditions. The Uganda Communications Commission imposed a national gateway and local traffic-routing requirement on Starlink. It did that through licence terms, not through published regulations. It can repeat that for any licensee at any time. Second, section 39 of the Data Protection and Privacy Act. After consulting the Authority, the Minister may make regulations on any prescribed matter. That expressly includes 'the retention period of personal data'. A national retention rule could appear without a new act of Parliament. Third, section 40 lets the Minister amend the Schedule with Cabinet approval. The Schedule sets the currency point at 20,000 shillings. Multiplying that figure multiplies every fine in the Act overnight. Fourth, regulation 3 of the National Data Bank Regulations. It lets the state IT agency prescribe how every public body links its database into the national data bank. That is a standing power over public sector systems. Fifth, the National Payment Systems Regulations give the central bank thirty days to approve any outsourcing by a payments licensee. RECURRING CALENDAR ITEMS: annual registration renewal with the regulator, and the annual compliance report under regulation 50 of the 2021 Regulations. If the report is queried, you have 14 days to file a remedial action plan.
Sources
- Official sourceNational Information Technology Authority - UgandaMinister launches Updated National Information Security Framework (NISF) 2026, 15 July 2026
nita.go.ug
Link checked 18 August 2026
- Official sourceNational Information Technology Authority - UgandaData Protection and Privacy Act, 2019, sections 39 and 40 (regulation-making and power to amend the Schedule)
nita.go.ug
“The Minister may, after consultation with the Authority by statutory instrument make regulations for— ... (c) the retention period of personal data;”
Link checked 18 August 2026
- Official sourceUganda Communications CommissionStarlink in Uganda: Taxation, Data Sovereignty and Regulation, 22 May 2026 — localisation imposed by licence condition
ucc.co.ug
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries5 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Banking data needs a copy kept in the country
Official name: The Financial Institutions Act · Cap. 57 (2023 revised edition), section 45 · Act of parliament
A licensed bank, credit institution or other financial institution must keep its financial ledgers and records inside Uganda, in English, for at least ten years. Computer records count. Nothing stops a copy also sitting abroad, but the Ugandan copy is mandatory.
Enforced by Bank of Uganda
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep the data in the countryFinancial ledgers and other financial records must be kept in Uganda. Necessary non-financial records must also be kept within Uganda. 'Financial records' expressly includes computer records.
- Keep data for a minimum period — 10 yearsNot less than ten years.
- Secure the dataThe institution and its agents must prevent loss, destruction and falsification, and stop unauthorised persons accessing the records.
Sources
- Official sourceBank of UgandaFinancial Institutions Act, Cap. 57, section 45 (financial ledgers and other financial records)
bou.or.ug
“Every financial institution shall, without derogation from subsections (1) and (3), maintain within Uganda such non-financial records as are necessary”
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: The National Payment Systems Regulations, 2021 · Made under the National Payment Systems Act, 2020; regulations 25, 28 and 29 · Directly binding regulation
Uganda's payments rules set no requirement about where data is stored. They expressly send you back to the general privacy law. The real gate is different. A payments licensee cannot hand its licensed services, core payment operations or technical staff to any outside supplier. The central bank must approve that in writing first. This includes a foreign cloud provider. Cross-border payment services need their own approval.
Enforced by Bank of Uganda
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Written vendor contractNo outsourcing of licensed services, the core operation of a payment system, or technical personnel without the central bank's written approval. The central bank has 30 days to decide.
- Register or notifySeparate written approval is needed before operating a cross-border payment system or offering cross-border payment services.
- Independent auditThe management information system must produce an audit trail. Internal auditors, external auditors and the central bank must be able to use it. The central bank must also be given access to the licensee's electronic systems and records.
- Secure the data
What it costs if you get it wrong
- Daily fine until fixed: 200 currency points per day (UGX 4,000,000 per day) — about $1 thousandMerger or acquisition without the central bank's written approval
Sources
- Official sourceBank of UgandaThe National Payment Systems Regulations, 2021, Part IV (regulations 25, 26, 28 and 29)
bou.or.ug
“A payment service provider shall collect, process, control and manage personal data in accordance with the Data Protection and Privacy Act, 2019.”
Link checked 18 August 2026
Telecoms rules
Official name: Uganda Communications Commission infrastructure and service licence conditions on localisation and oversight · Licence conditions described by the Commission, 22 May 2026 (satellite operator entry) · Licence condition
The communications regulator attaches location conditions directly to operating licences. A licensed operator must run a national gateway with equipment physically in Uganda. Ugandan users' traffic must route through it. The operator must also register every device activated in the country. These conditions are negotiated licence by licence, not published as regulations.
Enforced by Uganda Communications Commission
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryA national gateway with a physical point of presence in Uganda; traffic for Ugandan users must route through local infrastructure.
- Register or notifyLocal registration of every device activated in Uganda.
- Do not hand data to foreign authorities on demandThe stated purpose is to enable lawful interception and monitoring under Ugandan law rather than offshore.
What it costs if you get it wrong
- Loss of your licenceBreach of licence conditions
Sources
- Official sourceUganda Communications CommissionStarlink in Uganda: Taxation, Data Sovereignty and Regulation, 22 May 2026
ucc.co.ug
“Starlink is also required to ensure the local registration of all devices activated within Uganda to enhance accountability and support regulatory enforceability in accordance with national laws.”
Link checked 18 August 2026
Government data needs a copy kept in the country
Official name: The National Information Technology Authority, Uganda (National Data Bank) Regulations, 2019 · Statutory Instrument 2019 No. 109; Uganda Gazette No. 64, Volume CXII, 20 December 2019 · Directly binding regulation
Every Ugandan public body must link its database into a single national data bank. The state IT agency runs it. So a copy of government data ends up inside the country. The agency sets the access levels and keeps a register of every database in the system.
Enforced by National Information Technology Authority - Uganda
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryEvery public body must link its database to the national data bank operated inside Uganda by the state IT agency, in the manner that agency prescribes.
- Register or notifyThe agency keeps a register of every database in the national data bank, naming the database, the public body and the purpose.
- Secure the data
What it costs if you get it wrong
- Criminal liability: 48 currency points (UGX 960,000) or 24 months' imprisonment; 72 currency points or 3 years on repeat; plus up to 10 currency points per day for a continuing offence — about $260Using the national data bank to gain unlawful access to a database
Sources
- Official sourceNational Information Technology Authority - UgandaThe National Information Technology Authority, Uganda (National Data Bank) Regulations, 2019 (S.I. No. 109 of 2019)
nita.go.ug
“For the purposes of this regulation, every data controller shall link its database to the national databank as prescribed by the Authority.”
Link checked 18 August 2026
Cloud and outsourcing rules (Government)
Official name: Updated National Information Security Framework (NISF) 2026 · Launched by the Minister of ICT and National Guidance, 15 July 2026; successor to the 2014 framework endorsed by Presidential Security Directive No. 1 of 2014 · Regulator guideline
This is guidance, not a statute. It is how the Ugandan state expects government bodies and critical infrastructure operators to behave. That covers finance, telecoms, energy, water, transport and health. It does not require data to stay in Uganda. It requires cloud contracts to include data sovereignty terms, encryption and certified providers. It also sets the personal data breach deadline at 72 hours.
Enforced by National Information Technology Authority - Uganda
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report breaches to the regulator — within 72 hoursPersonal data breaches to the Personal Data Protection Office within 72 hours of becoming aware.
- Report cyber incidentsSecurity breaches not involving personal data go to the national computer security incident response team, CERT-UG. Government bodies and critical infrastructure operators must also tell their sector regulator.
- Written vendor contractData sovereignty, encryption in transit and at rest, and the shared responsibility model must be written into every cloud contract and service level agreement.
- Hold a security certificateCloud providers must meet recognised standards. Those include ISO/IEC 27017, ISO/IEC 27018 and the Cloud Security Alliance Cloud Controls Matrix. Outside audit reports must be reviewed every year.
- Assess high-risk projectsJoint risk assessment by the information risk owner and the data protection officer before adopting cloud.
Sources
- Official sourceNational Information Technology Authority - UgandaUpdated National Information Security Framework (NISF) 2026, sections 4.1, 4.2 and 5.2.4.1
nita.go.ug
“Define data sovereignty, encryption requirements (in transit and at rest), and the shared responsibility model in all contracts and Service Level Agreements (SLAs).”
Link checked 18 August 2026
- Official sourceNational Information Technology Authority - UgandaMinister launches Updated National Information Security Framework (NISF) 2026, 15 July 2026
nita.go.ug
Link checked 18 August 2026
Applies to every company1 rule
These bind you whatever business you are in, once the country's rules reach you.
General data protection law
Official name: The Data Protection and Privacy Act, 2019 · Act No. 9 of 2019; consolidated as Cap. 97 in the 2023 revised edition · Act of parliament
This is Uganda's general privacy law. Personal data may leave the country if the destination protects it at least as well as Uganda does. Consent from the person also works. There is no permit and no standard contract. Everyone handling personal data must register with the regulator and renew every year. You must also appoint a data protection officer and file an annual compliance report. Enforcement is criminal, not administrative.
Enforced by Personal Data Protection Office
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Explicit consent
What you have to do
- Register or notifyEveryone who collects, handles or controls data must be entered in the public data protection register. You renew every year.
- Get consent
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people object
- Limit automated decisions
- Secure the data
- Report breaches to the regulator — within 72 hoursThe Act says 'immediately'. The government's 2026 security rules state 72 hours. Work to 'immediately'.
- Tell affected peopleOnly where the regulator decides the individuals must be told.
- Delete data after a period
- Put a transfer safeguard in placeYou assess the destination country yourself, or you get the person's consent. There is no government list and no standard contract.
- Get a parent's consent for children — applies at: under 18
- Appoint a data protection officerRequired by the 2021 Regulations. The job description must meet regulation 47(3).
- Independent auditAnnual compliance report to the regulator, under regulation 50 of the 2021 Regulations. If it is queried, you have 14 days to file a remedial action plan.
- Assess high-risk projects
What it costs if you get it wrong
- Criminal liability: 240 currency points (UGX 4,800,000) or 10 years' imprisonment or both — about $1 thousandUnlawfully obtaining, disclosing or procuring disclosure of personal data
- Criminal liability: 245 currency points (UGX 4,900,000) or 10 years' imprisonment or both — about $1 thousandSelling or offering to sell personal data
- Percentage of global turnover: 2% of annual gross turnoverAdditional fine a court may order against a convicted corporation
- Claims by individualsA data subject who suffers damage or distress may sue for compensation
Sources
- Official sourceNational Information Technology Authority - UgandaThe Data Protection and Privacy Act, 2019 (Act No. 9 of 2019) — full text
nita.go.ug
Link checked 18 August 2026
- Official sourceNational Information Technology Authority - UgandaLaws and Regulations — Data Protection and Privacy Act No. 9 of 2019
nita.go.ug
Link checked 18 August 2026
- Official sourcePersonal Data Protection OfficePersonal Data Protection Office — registration, annual compliance report (regulation 50) and data protection officer duties (regulation 47(3))
pdpo.go.ug
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The full text, statutory instrument number and exact obligations of the Data Protection and Privacy Regulations, 2021
We could not confirm the full text of the 2021 Regulations. We found no copy on any Ugandan government website. Their existence and numbering come only from the regulator's own portal. It quotes regulation 47(3) on the data protection officer's job description, and regulation 50 on the annual compliance report. The portal does not publish the text itself.
That the breach notification deadline is exactly 72 hours
We could not confirm the breach reporting deadline. The Act itself says 'immediately'. The 72-hour figure appears in the government's Updated National Information Security Framework 2026, which attributes it to the Act. We could not read the underlying regulation that sets it. Work to 'immediately'.
Registration fees and any size or turnover threshold for registering with the Personal Data Protection Office
We could not confirm the registration fees, or whether any size or turnover cut-off applies. The portal charges fees through a billing step, but the fee schedule sits behind a login. Ask the regulator if the cost matters to you.
Whether the Personal Data Protection Office has issued any published enforcement decision, order or fine
We could not confirm whether the regulator has taken any enforcement action. We found no decisions register on its site. It may act without publishing. Our enforcement rating of 'waking' rests on that gap.
Whether a foreign company with no establishment in Uganda can, or must, complete registration on the regulator's portal
We could not confirm how a foreign company with no Ugandan office registers. The Act's scope clearly reaches such a company, and registration is written as universal. But we could not test the portal's business account flow without an account. Ask the regulator before you rely on this.
Insurance and securities sector rules on record location and cross-border transfer
We found no rule for insurance or capital markets on where records sit or on sending data abroad. The insurance regulator's statute and regulation downloads load through scripts we could not follow. We could not reach the capital markets regulator's document library. If you work in these industries, check before you rely on this.
Whether online gaming or betting licences require servers or transaction data to be held in Uganda
We found no rule requiring gaming servers or transaction data to be held in Uganda. Checked 18 August 2026, confidence low. The gaming board publishes its regulations list, but the files sit behind a script-driven download handler we could not use. Ask the board if this affects you.
General company-law and tax record retention periods
We could not confirm general company and tax record-keeping periods. The revenue authority's statute pages returned errors. Only the ten-year banking minimum is evidenced here. Ask the revenue authority about tax records.
Whether the 2023 consolidation of the Act as Cap. 97 changed any operative wording
We could not confirm whether the 2023 consolidation changed any wording. The regulator now cites Cap. 97 throughout. The only full text we could open on a government website is the original Act No. 9 of 2019. The section numbers quoted here come from that original text.
Whether the UCC localisation licence conditions apply beyond the single satellite operator described
We could not confirm how widely these licence conditions apply. The Commission describes them as conditions written into that one operator's licence. The licence itself is not published. We found no general regulation putting the same requirement on all licensees.
Health-sector rules on where patient records may be held
We could not confirm whether health has its own rule on where patient records may be held. The Ministry of Health site failed certificate checks from our tools and could not be read. We make no claim about health data here.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.