Law / Uganda

Data Protection and Privacy Act, 2019, breach notification

Data Protection and Privacy Act, 2019, s. 23 (breach notification)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 3 May 2019.

A breach notification rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Notify the National Information Technology Authority immediately after you believe personal data has been accessed or acquired by an unauthorised person, describing the access or acquisition and the remedial action taken.
  • Wait for the Authority to determine whether you must also notify the affected data subject of the breach; the Act sets no separate deadline for that notice.
  • Where the Authority determines the data subject must be notified, do so by registered mail to their last known address, electronic mail to their last known address, prominent placement on your website, or publication in the mass media, giving sufficient information for them to take protective measures.
  • Publicise the breach in the manner the Authority specifies if it directs you to, where the Authority has grounds to believe publicity would protect an affected data subject.

What it reaches

Obligation class

Breach notice, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 23(1) requires a data collector, processor or controller that believes a data subject's personal data has been accessed or acquired by an unauthorised person to notify the Authority immediately, in the prescribed manner, of the access or acquisition and the remedial action taken; the Act states no numbered grace period, the clock is 'immediately' from the point the collector, processor or controller believes the breach occurred.

Section 23(2) leaves the decision on whether the data subject must also be told to the Authority rather than to the data collector, processor or controller, and the Act sets no independent deadline for that data-subject notice; it runs from the Authority's own determination, not from the breach.

Where the Authority does direct notice to the data subject, section 23(3) requires it by registered mail to their last known address, electronic mail to their last known address, a prominent position on the responsible party's website, or publication in the mass media, and section 23(4) requires it to carry sufficient information for the data subject to take protective measures.

Section 23(5) lets the Authority direct the responsible party to publicise the breach where the Authority has grounds to believe publicity would protect an affected data subject.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • handles_health_records
  • operates_essential_service

Read the law

official Act text as published by the Uganda Legal Information Institute (ULII), preserved in an Internet Archive capture of the ULII page

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://ulii.org/en/akn/ug/act/2019/9/eng@2019-05-03

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app