Data Protection and Privacy Act, 2019, comprehensive personal-data regime
Data Protection and Privacy Act, 2019 (Chapter 97)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 3 May 2019.
A comprehensive regime rule binding public and private bodies.
As of 5 September 2026.
What it requires
- Obtain the data subject's prior consent before collecting or processing their personal data, unless a specific ground in section 7(2) applies.
- Obtain the consent of a child's parent or guardian before collecting or processing that child's personal data, unless required by law or for research or statistical purposes.
- Give a data subject notice of who is collecting their data, its purpose, and their rights, before or as soon as practicable after collecting it.
- Retain personal data no longer than necessary for the purpose collected, and secure it against loss, unauthorised access or destruction.
- Notify the National Information Technology Authority immediately of any unauthorised access to or acquisition of personal data you hold.
- Stop processing a data subject's personal data for direct marketing once they give written notice to stop, and let them access and correct their own data.
- Do not transfer or store personal data outside Uganda unless the destination country's protection is at least equivalent to this Act's or the data subject has consented.
- Register with the National Information Technology Authority as a data controller or other prescribed person before collecting or processing personal data.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Unlawfully obtaining or disclosing personal data, unlawfully destroying, deleting or altering personal data, or selling personal data is an offence punishable by a fine of 240 to 245 currency points (UGX 4,800,000 to UGX 4,900,000) or imprisonment of up to ten years, or both (ss. 35-37); a convicted corporation may additionally be fined up to two percent of its annual gross turnover (s. 38(2)).
Penalty structure
The highest individual fixed cap among the Act's offences (sale of personal data, s. 37(2), 245 currency points); unlawful obtaining or disclosure and unlawful destruction or alteration (ss. 35-36) each carry 240 currency points (UGX 4,800,000). Each offence also carries imprisonment of up to ten years as an alternative or addition. A convicted corporation may additionally be fined up to two percent of its annual gross turnover (s. 38(2)).
- Rule
- Fixed only
- As of
- 5 September 2026
- Currency
- UGX
- Fixed cap
- 4,900,000
Who enforces it
Enforcement body
National Information Technology Authority - Uganda (Personal Data Protection Office)
What it reaches
Obligation class
Consent, Disclosure, Data subject rights, Transfer, Breach notice, Security, Licensing
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Act establishes a personal data protection office within the National Information Technology Authority - Uganda (the Authority) to enforce data-protection principles requiring accountable, fair, lawful, adequate and transparent collection and processing of personal data.
A person must not collect or process personal data without the data subject's prior consent unless a specific ground applies, such as a public duty, national security, a contract with the data subject, or a legal obligation, and a child's personal data additionally needs the consent of the child's parent or guardian.
Special personal data (religious or philosophical belief, political opinion, sexual life, financial information, or health status) may not be collected or processed outside narrow grounds such as an employer's legal duty or the data subject's free consent; the list does not name biometric or genetic data.
A data controller must give a data subject notice before collecting their data, retain it no longer than necessary, secure it against unauthorised access, and notify the Authority immediately of any unauthorised access or acquisition of personal data, with the Authority deciding whether the affected data subject must also be told.
A data subject may access, correct or object to processing of their own data, stop processing for direct marketing, and require that a decision producing legal or similarly significant effects not be based solely on automated processing. Transferring or storing personal data outside Uganda requires either that the destination country's protection be at least equivalent to the Act's or the data subject's consent.
A data controller must register with the Authority, and unlawfully obtaining, disclosing, destroying, altering or selling personal data is an offence carrying a fine of 240 to 245 currency points (UGX 4,800,000 to UGX 4,900,000 at UGX 20,000 per currency point) or imprisonment of up to ten years, or both; a convicted corporation may additionally be fined up to two percent of its annual gross turnover.
When LexLint raises it
crawls_webtrains_modelsautomated_outreachhigh_risk_decisionsserves_minors