Comprehensive regime
Data Protection and Privacy Act, 2019, comprehensive personal-data regime
Data Protection and Privacy Act, 2019 (Chapter 97)official Act text as published by the Uganda Legal Information Institute (ULII), preserved in an Internet Archive capture of the ULII page
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://ulii.org/en/akn/ug/act/2019/9/eng@2019-05-03In force since 3 May 2019. Binds public and private bodies.
What this law does
The Act establishes a personal data protection office within the National Information Technology Authority - Uganda (the Authority) to enforce data-protection principles requiring accountable, fair, lawful, adequate and transparent collection and processing of personal data.
A person must not collect or process personal data without the data subject's prior consent unless a specific ground applies, such as a public duty, national security, a contract with the data subject, or a legal obligation, and a child's personal data additionally needs the consent of the child's parent or guardian.
Special personal data (religious or philosophical belief, political opinion, sexual life, financial information, or health status) may not be collected or processed outside narrow grounds such as an employer's legal duty or the data subject's free consent; the list does not name biometric or genetic data.
A data controller must give a data subject notice before collecting their data, retain it no longer than necessary, secure it against unauthorised access, and notify the Authority immediately of any unauthorised access or acquisition of personal data, with the Authority deciding whether the affected data subject must also be told.
A data subject may access, correct or object to processing of their own data, stop processing for direct marketing, and require that a decision producing legal or similarly significant effects not be based solely on automated processing. Transferring or storing personal data outside Uganda requires either that the destination country's protection be at least equivalent to the Act's or the data subject's consent.
A data controller must register with the Authority, and unlawfully obtaining, disclosing, destroying, altering or selling personal data is an offence carrying a fine of 240 to 245 currency points (UGX 4,800,000 to UGX 4,900,000 at UGX 20,000 per currency point) or imprisonment of up to ten years, or both; a convicted corporation may additionally be fined up to two percent of its annual gross turnover.
What it requires