Law / Uganda

Data Protection and Privacy Act, 2019, rights of data subjects

Data Protection and Privacy Act, 2019, ss. 13, 16, 24-28 (rights of data subjects)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 3 May 2019.

A data subject rights rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Before or as soon as practicable after collecting personal data, tell the data subject its nature and category, your name and address, the purpose, whether supplying it is discretionary or mandatory, the consequences of not providing it, the recipients, their rights of access and rectification, and the retention period.
  • Correct or delete personal data on a data subject's request where it is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully, tell the data subject the outcome, and notify every person the data was previously disclosed to of a correction made.
  • Answer a data subject's request to confirm whether you hold their personal data, describe it, and identify any third party with access to it, within thirty days of the request.
  • Stop processing personal data within fourteen days of a data subject's written notice that the processing causes or is likely to cause them unwarranted substantial damage or distress, unless the processing falls under section 7(2), and comply within seven days if the Authority orders you to.
  • Stop processing a data subject's personal data for direct marketing within fourteen days of their written notice to do so.
  • Do not base a decision that significantly affects a data subject solely on automated processing where they have given written notice against it, and where such a decision is made, notify the data subject and reconsider it within twenty-one days of their written request.
  • Rectify, update, block, erase or destroy personal data the Authority finds inaccurate on a data subject's complaint, and notify every third party the data was previously disclosed to of that action.

What it reaches

Obligation class

Data subject rights, Disclosure

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 13 requires a person collecting personal data to inform the data subject, before or as soon as practicable after collection, of the nature and category of the data, the collector's name and address, the purpose, whether supplying the data is discretionary or mandatory, the consequences of not providing it, the authorised or legal requirement for collecting it, the recipients, the existence of the rights of access and rectification, and the retention period, subject to law-enforcement, national-security and revenue-collection exceptions.

Section 16 gives a data subject the right to have a data controller correct or delete personal data that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained, or destroy a record the controller no longer has authority to retain, with the controller telling the data subject the outcome and notifying every person the data was disclosed to of a correction made.

Section 24 gives a data subject who proves their identity the right to confirmation of whether a controller holds their personal data, a description of it, and the identity of any third party with access to it, to be answered within thirty days subject to a third party's own privacy.

Section 25 lets a data subject require a controller or processor in writing to stop processing that causes or is likely to cause them unwarranted substantial damage or distress, other than processing under section 7(2), with the controller answering within fourteen days and the Authority able to order compliance within seven.

Section 26 lets a data subject require a controller in writing to stop processing their data for direct marketing, again with a fourteen-day answer and an Authority order available.

Section 27 lets a data subject require that a decision significantly affecting them not rest solely on automated processing, and where such a decision is made anyway entitles them to be told and to have it reconsidered within twenty-one days of their written request, subject to contract-related and legally required exceptions.

Section 28 lets the Authority, on a data subject's complaint that their data is inaccurate, order a controller to rectify, update, block, erase or destroy it, with the controller then notifying every third party the data was previously disclosed to.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • generates_content

Read the law

official Act text as published by the Uganda Legal Information Institute (ULII), preserved in an Internet Archive capture of the ULII page

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://ulii.org/en/akn/ug/act/2019/9/eng@2019-05-03

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app