Skip to the content
Global Data RulesData governance rules, country by country

Uganda

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.

The answer

Depends on your industryWork: HighEnforcement: Waking up

Uganda lets data leave if the destination protects it about as well as Uganda does, or the person agreed. There is no list of approved countries and no standard contract, so you judge it yourself and keep the paperwork. Banks are the exception: their records must stay in Uganda for ten years. The regulator is staffed but cannot fine you. It sends serious cases to the police.

Data governance in Uganda

The eight things that decide how you handle data about people in Uganda. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. Uganda's privacy law reaches a company with no office in Uganda if it handles personal data about Ugandan citizens. There is no minimum size, revenue or headcount to fall below. Anyone who collects, processes or controls personal data must also sign up to a public register kept by the regulator and renew that registration every year.

High confidenceNational rulesRegister or notifyAppoint a data protection officer

Where the data is allowed to live

In general, yes. Data may leave Uganda if the destination country protects personal data at least as well as Uganda's own law does, or if the person the data is about has agreed. Nobody in government approves the transfer first. But four industries override that headline: banking, payments, telecoms and the public sector. Check your industry before you rely on the general rule.

High confidenceDepends on your industryYes, with paperworkA copy must stayBankingPaymentsTelecomsGovernment

Sending data out of the country

There is no permit to apply for and no government-approved contract to sign. You must either satisfy yourself that the destination country protects data at least as well as Uganda does, or get the person's consent. The government has never published a list of approved countries, so you make the judgement and keep the evidence. The regulator collects that assessment through its online portal and scores it when you file your yearly compliance report.

High confidenceApproval each timeOfficial 'this country is safe' decisionExplicit consent

The regulator, and whether it actually acts

The Personal Data Protection Office, which sits inside the state IT agency. It is genuinely up and running: it has its own building in Kampala, a director, published phone numbers and email addresses, and a live portal that handles registration, complaints, breach reports and yearly compliance filings. What it cannot do is fine you. It can order you to fix things, and it passes serious cases to the police. We found no published fines or formal decisions.

High confidenceWaking upCriminal liabilityClaims by individuals

How long you must keep it — and when to delete it

The ceiling is a judgement call: you must not keep personal data longer than you need it for the purpose you collected it for. The floor is hard and long in finance — a licensed bank or other financial institution must keep its records for at least ten years, and inside Uganda. When the two clash, the law wins: the ceiling has a built-in exception for anything you are required or allowed by law to keep.

High confidenceDelete data after a periodKeep data for a minimum periodKeep the data in the country

If something goes wrong

There are at least three clocks and they do not agree. The law says tell the regulator immediately when you believe someone has got at personal data without permission. The government's own security framework, published in July 2026, says seventy-two hours. Separately, security incidents that do not involve personal data go to the national cyber response team, and banks, telecoms and health bodies must also tell their own regulator. One more twist: you do not decide whether to tell the affected people. The regulator does.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What catches people out

Five things that are not in the summary. One: the law follows Ugandan citizens, not Ugandan residents, so a Ugandan living abroad is still covered. Two: financial information counts as sensitive data in Uganda, which is unusual, so bank and card details attract the strictest rules. Three: there are no regulator fines here — there are criminal charges, up to ten years in prison for an individual, and up to two percent of a company's yearly gross turnover on conviction. Four: if you disagree with the regulator you appeal to a government minister, not to a court. Five: banks must keep their records inside Uganda for ten years, and payment firms need the central bank's written permission before handing core operations to any outside supplier, including a foreign cloud.

High confidenceFinancial dataChildren's dataCriminal liabilityPercentage of global turnoverGet a parent's consent for childrenKeep the data in the country

What's changing next

Nothing dramatic is scheduled in the next twelve months. The main near-term work is rollout: the updated national security framework launched in July 2026 now has to be implemented by government bodies and by operators of critical infrastructure in banking, telecoms, energy, water, transport and health. The bigger risk is the switches the government already holds. The communications regulator can bolt localisation conditions onto any licence with no consultation, and it did exactly that to a satellite operator in May 2026. The ICT minister can rewrite retention periods by statutory instrument, and can raise the value of the fine unit with Cabinet approval alone.

Medium confidenceIn forceLicence conditionRegulator guideline

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries5 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

The Financial Institutions Act

Act of parliament · Cap. 57 (2023 revised edition), section 45

In forceA copy must stay

A licensed bank, credit institution or other financial institution must keep its financial ledgers and records inside Uganda, in English, for at least ten years. Computer records count. Nothing stops a copy also sitting abroad, but the Ugandan copy is mandatory.

In force since 1 March 2004

Enforced by Bank of Uganda

Transfer model: No restriction · Accepted routes: Nothing required

High confidence
Payments

The National Payment Systems Regulations, 2021

Directly binding regulation · Made under the National Payment Systems Act, 2020; regulations 25, 28 and 29

In forceYes, with paperwork

Uganda's payments rules contain no storage-location requirement and expressly send you back to the general privacy law. The real gate is different: a payments licensee cannot hand its licensed services, core payment operations or technical staff to any outside supplier — including a foreign cloud provider — without the central bank's written approval, and cross-border payment services need their own approval.

In force since 1 January 2021

Enforced by Bank of Uganda

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence
Telecoms

Uganda Communications Commission infrastructure and service licence conditions on localisation and oversight

Licence condition · Licence conditions described by the Commission, 22 May 2026 (satellite operator entry)

In forceA copy must stay

The communications regulator attaches localisation conditions directly to operating licences. A licensed operator must run a national gateway with equipment physically in Uganda and route Ugandan users' traffic through it, and must register every device activated in the country. These conditions are negotiated per licence rather than published as regulations.

In force since 22 May 2026

Enforced by Uganda Communications Commission

Transfer model: Approval each time · Accepted routes: Government sign-off needed

Medium confidence

Applies to every company1 rule

These bind you whatever business you are in, once the country's rules reach you.

The Data Protection and Privacy Act, 2019

Act of parliament · Act No. 9 of 2019; consolidated as Cap. 97 in the 2023 revised edition

In forceYes, with paperwork

Uganda's general privacy law. Personal data may leave the country if the destination protects it at least as well as Uganda does, or if the person consented — no permit and no standard contract. Everyone handling personal data must register with the regulator and renew yearly, appoint a data protection officer and file an annual compliance report. Enforcement is criminal, not administrative.

In force since 3 May 2019

Enforced by Personal Data Protection Office

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Explicit consent

High confidence

Who you would hear from

  • Personal Data Protection Office (PDPO)

    General privacy law: registration, complaints, breach reports, cross-border transfer assessments, compliance audits

    Fully staffed and operating as of 18 August 2026. Headed by a National Personal Data Protection Director, sits under the National Information Technology Authority - Uganda, and works from Padre Pio House, Plot 32 Lumumba Avenue, Kampala. Runs a live portal for registration, annual renewal, annual compliance reports, breach reporting and cross-border transfer impact assessments, with a dedicated complaints and breach reporting mailbox. It has no power to impose administrative fines; its complaint workflow includes an 'Escalated to CID' status, referring cases to the police Criminal Investigations Directorate. We could not locate any published enforcement decision or fine.

  • NITA-U

    The 'Authority' named in the privacy law; national data bank; national information security framework; government IT

    Actively publishing. Launched the Updated National Information Security Framework in July 2026 and a 2026 e-Government Interoperability Framework.

  • Banking, microfinance deposit-taking institutions, payment systems and electronic money

    Active. Publishes and updates supervisory circulars and payment system regulations; last revised its payment systems oversight framework in 2025.

  • UCC

    Telecommunications, broadcasting, postal services, data communications and infrastructure licensing

    Active and interventionist. Publishes decisions and rulings, runs enforcement campaigns, and imposed localisation licence conditions on a satellite operator in May 2026.

  • IRA

    Insurance, reinsurance, health membership organisations and intermediaries

    Active — publishes licensing lists and circulars through 2026. We could not open its statute and regulation downloads, so no insurance-specific data rule is recorded here.

  • NLGRB

    Lotteries, gaming and betting

    Active — publishes fee regulations, licensing lists and a machines register. No server-location or data-localisation rule was found in its published regulations.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The full text, statutory instrument number and exact obligations of the Data Protection and Privacy Regulations, 2021

    We could not find a copy hosted on any Ugandan government domain. Their existence and specific regulation numbers (47(3) on the data protection officer's job description, 50 on the annual compliance report) are evidenced only by the regulator's own portal, which quotes them but does not publish the instrument.

  • That the breach notification deadline is exactly 72 hours

    The Act itself says 'immediately'. The 72-hour figure appears in the government's Updated National Information Security Framework 2026, which attributes it to the Act. We could not read the underlying regulation that sets it. Plan to 'immediately'.

  • Registration fees and any size or turnover threshold for registering with the Personal Data Protection Office

    The portal charges fees through a billing step but the fee schedule is behind a login. Not verified.

  • Whether the Personal Data Protection Office has issued any published enforcement decision, order or fine

    No decisions register was found on the regulator's site. We cannot prove a negative; the office may act without publishing. Enforcement is rated 'waking' on that basis.

  • Whether a foreign company with no establishment in Uganda can, or must, complete registration on the regulator's portal

    The Act's scope clearly reaches such a company, and registration is expressed as universal, but the portal's business account flow was not testable without an account.

  • Insurance and securities sector rules on record location and cross-border transfer

    The insurance regulator's statute and regulation downloads are loaded by scripts we could not follow, and the capital markets regulator's document library was not reached. No rule is asserted for these sectors.

  • Whether online gaming or betting licences require servers or transaction data to be held in Uganda

    The gaming board publishes its regulations list but the files themselves are behind a script-driven download handler. Checked 18 August 2026; no such requirement found, confidence low.

  • General company-law and tax record retention periods

    The revenue authority's statute pages returned errors. Only the ten-year banking floor is evidenced here.

  • Whether the 2023 consolidation of the Act as Cap. 97 changed any operative wording

    The regulator now cites Cap. 97 throughout, but the only full text we could open on a government domain is the original Act No. 9 of 2019. Section numbers quoted here are from that original text.

  • Whether the UCC localisation licence conditions apply beyond the single satellite operator described

    The Commission describes them as conditions incorporated in that operator's licence. The licence itself is not published, and we found no general regulation imposing the same requirement on all licensees.

  • Health-sector rules on where patient records may be held

    The Ministry of Health site failed certificate validation from our fetcher and could not be read. No health-specific rule is asserted.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Uganda versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.