Law / Uganda

Data Protection and Privacy Act, 2019, comprehensive personal-data regime

Data Protection and Privacy Act, 2019 (Chapter 97)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 3 May 2019.

A comprehensive regime rule binding public and private bodies.

As of 5 September 2026.

What it requires

  • Obtain the data subject's prior consent before collecting or processing their personal data, unless a specific ground in section 7(2) applies.
  • Obtain the consent of a child's parent or guardian before collecting or processing that child's personal data, unless required by law or for research or statistical purposes.
  • Give a data subject notice of who is collecting their data, its purpose, and their rights, before or as soon as practicable after collecting it.
  • Retain personal data no longer than necessary for the purpose collected, and secure it against loss, unauthorised access or destruction.
  • Notify the National Information Technology Authority immediately of any unauthorised access to or acquisition of personal data you hold.
  • Stop processing a data subject's personal data for direct marketing once they give written notice to stop, and let them access and correct their own data.
  • Do not transfer or store personal data outside Uganda unless the destination country's protection is at least equivalent to this Act's or the data subject has consented.
  • Register with the National Information Technology Authority as a data controller or other prescribed person before collecting or processing personal data.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Unlawfully obtaining or disclosing personal data, unlawfully destroying, deleting or altering personal data, or selling personal data is an offence punishable by a fine of 240 to 245 currency points (UGX 4,800,000 to UGX 4,900,000) or imprisonment of up to ten years, or both (ss. 35-37); a convicted corporation may additionally be fined up to two percent of its annual gross turnover (s. 38(2)).

Penalty structure

The highest individual fixed cap among the Act's offences (sale of personal data, s. 37(2), 245 currency points); unlawful obtaining or disclosure and unlawful destruction or alteration (ss. 35-36) each carry 240 currency points (UGX 4,800,000). Each offence also carries imprisonment of up to ten years as an alternative or addition. A convicted corporation may additionally be fined up to two percent of its annual gross turnover (s. 38(2)).

Rule
Fixed only
As of
5 September 2026
Currency
UGX
Fixed cap
4,900,000

Who enforces it

Enforcement body

National Information Technology Authority - Uganda (Personal Data Protection Office)

What it reaches

Obligation class

Consent, Disclosure, Data subject rights, Transfer, Breach notice, Security, Licensing

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Act establishes a personal data protection office within the National Information Technology Authority - Uganda (the Authority) to enforce data-protection principles requiring accountable, fair, lawful, adequate and transparent collection and processing of personal data.

A person must not collect or process personal data without the data subject's prior consent unless a specific ground applies, such as a public duty, national security, a contract with the data subject, or a legal obligation, and a child's personal data additionally needs the consent of the child's parent or guardian.

Special personal data (religious or philosophical belief, political opinion, sexual life, financial information, or health status) may not be collected or processed outside narrow grounds such as an employer's legal duty or the data subject's free consent; the list does not name biometric or genetic data.

A data controller must give a data subject notice before collecting their data, retain it no longer than necessary, secure it against unauthorised access, and notify the Authority immediately of any unauthorised access or acquisition of personal data, with the Authority deciding whether the affected data subject must also be told.

A data subject may access, correct or object to processing of their own data, stop processing for direct marketing, and require that a decision producing legal or similarly significant effects not be based solely on automated processing. Transferring or storing personal data outside Uganda requires either that the destination country's protection be at least equivalent to the Act's or the data subject's consent.

A data controller must register with the Authority, and unlawfully obtaining, disclosing, destroying, altering or selling personal data is an offence carrying a fine of 240 to 245 currency points (UGX 4,800,000 to UGX 4,900,000 at UGX 20,000 per currency point) or imprisonment of up to ten years, or both; a convicted corporation may additionally be fined up to two percent of its annual gross turnover.

When LexLint raises it

  • crawls_web
  • trains_models
  • automated_outreach
  • high_risk_decisions
  • serves_minors

Read the law

official Act text as published by the Uganda Legal Information Institute (ULII), preserved in an Internet Archive capture of the ULII page

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://ulii.org/en/akn/ug/act/2019/9/eng@2019-05-03

Back to the example  ·  Lint your app