Law / Uganda

Uganda

4 of 6 named instruments researched to a stage, across three of the six areas of law we track: 3 in force and 1 repealed, withdrawn or blocked. As of 5 September 2026.

  1. AI law none researched
  2. Privacy law 1
  3. Scraping law 2
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law1 instrument, 1 in force

Research summary (179 words)

Uganda's comprehensive personal-data regime is the Data Protection and Privacy Act, 2019 (Chapter 97), which binds any person, institution or public body that collects, processes, holds or uses personal data within Uganda, or outside Uganda in relation to a Ugandan citizen's data.

The Act requires a lawful basis, most often the data subject's prior consent, before personal data is collected or processed, gives a data subject rights of access, correction and objection to processing (including for direct marketing and against a purely automated decision), and requires notice to the National Information Technology Authority of an unauthorised access to or acquisition of personal data.

Its list of specially protected categories covers religious or philosophical belief, political opinion, sexual life, financial information, and health status, but does not name biometric or genetic data as a special category, and a cross-border transfer requires either an adequacy-equivalent destination or the data subject's consent rather than prior government authorisation.

Unlawfully obtaining, disclosing, destroying, altering or selling personal data is a criminal offence carrying a fine or imprisonment of up to ten years, or both.

Comprehensive regime

Data Protection and Privacy Act, 2019, comprehensive personal-data regime

Data Protection and Privacy Act, 2019 (Chapter 97)official Act text as published by the Uganda Legal Information Institute (ULII), preserved in an Internet Archive capture of the ULII page

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://ulii.org/en/akn/ug/act/2019/9/eng@2019-05-03

In force since 3 May 2019. Binds public and private bodies.

What this law does

The Act establishes a personal data protection office within the National Information Technology Authority - Uganda (the Authority) to enforce data-protection principles requiring accountable, fair, lawful, adequate and transparent collection and processing of personal data.

A person must not collect or process personal data without the data subject's prior consent unless a specific ground applies, such as a public duty, national security, a contract with the data subject, or a legal obligation, and a child's personal data additionally needs the consent of the child's parent or guardian.

Special personal data (religious or philosophical belief, political opinion, sexual life, financial information, or health status) may not be collected or processed outside narrow grounds such as an employer's legal duty or the data subject's free consent; the list does not name biometric or genetic data.

A data controller must give a data subject notice before collecting their data, retain it no longer than necessary, secure it against unauthorised access, and notify the Authority immediately of any unauthorised access or acquisition of personal data, with the Authority deciding whether the affected data subject must also be told.

A data subject may access, correct or object to processing of their own data, stop processing for direct marketing, and require that a decision producing legal or similarly significant effects not be based solely on automated processing. Transferring or storing personal data outside Uganda requires either that the destination country's protection be at least equivalent to the Act's or the data subject's consent.

A data controller must register with the Authority, and unlawfully obtaining, disclosing, destroying, altering or selling personal data is an offence carrying a fine of 240 to 245 currency points (UGX 4,800,000 to UGX 4,900,000 at UGX 20,000 per currency point) or imprisonment of up to ten years, or both; a convicted corporation may additionally be fined up to two percent of its annual gross turnover.

What it requires

Scraping law2 instruments, 1 in force, 1 repealed, withdrawn or blocked

Research summary (207 words)

Uganda has no scraping-specific statute, so general law governs each dimension separately.

The Computer Misuse Act, 2011 criminalised unauthorised access to a computer, but Uganda's Constitutional Court permanently enjoined enforcement of that provision on 17 March 2026, both because the Computer Misuse (Amendment) Act, 2022 that produced its current wording was passed without the constitutionally required parliamentary quorum and because the provision itself was held vague and overbroad, so no operative unauthorised-access offence currently exists on the point.

No reported Ugandan case addresses the enforceability of a browsewrap or clickwrap terms-of-service against a scraper, and no Ugandan statute or case establishes a scraping-specific unfair-competition, misappropriation or trespass doctrine, assigns legal weight to a robots.txt directive, or imposes an AI-training-specific rule.

The Copyright and Neighbouring Rights Act, 2006 permits fair use for private study, quotation compatible with fair practice, and teaching, but Uganda has no text-and-data-mining exception and no sui generis database right.

The Data Protection and Privacy Act, 2019 applies to personal data without a general carve-out for information that is publicly accessible, so scraping personal data from a public Ugandan website remains subject to the Act's consent and purpose-limitation duties, narrowed only where a public record or the data subject's own act made the data public.

Computer misuse

Computer Misuse Act, 2011, unauthorised access

Computer Misuse Act, 2011 (Act 2 of 2011; Chapter 96), s. 11 (unauthorised access), as amended by the Computer Misuse (Amendment) Act, 2022official Act text as published by the Uganda Legal Information Institute (ULII), preserved in an Internet Archive capture of the ULII page

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://ulii.org/en/akn/ug/act/2011/2/eng@2023-12-31

Struck down: invalidated by a court, effective 15 April 2011. Binds public and private bodies.

What this law does

As originally enacted, section 12 (renumbered section 11 by the Computer Misuse (Amendment) Act, 2022) made it an offence to access or intercept another person's program, data or information without authorisation, and the 2022 amendment added voice or video recording of another person and sharing information about another person without authorisation to the same offence, carrying a fine of up to 750 currency points (UGX 15,000,000) or imprisonment of up to ten years, or both.

On 17 March 2026, in a consolidated ruling on three petitions filed in 2022, Uganda's Constitutional Court held that the Computer Misuse (Amendment) Act, 2022 was passed without the quorum of one-third of all members required by the Rules of Procedure of Parliament and Articles 88 and 89 of the Constitution, and separately found section 11, along with sections 23 and 26 to 29, vague, overbroad and inconsistent with the constitutional guarantees of freedom of expression and access to information.

The court declared the Computer Misuse (Amendment) Act, 2022 null and void and issued a permanent injunction restraining its enforcement of section 11, so no unauthorised-access offence under this Act currently binds a person accessing a computer system in Uganda.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (147 words)

Uganda has no press-publisher neighbouring right, no mandatory platform-to-publisher bargaining code, no recognised hot-news misappropriation doctrine distinct from ordinary copyright law, and no located statute or case law addressing hyperlinking or framing liability specifically; each of those dimensions is a sourced absence rather than an unresolved question.

The relevant instrument is the Copyright and Neighbouring Rights Act, 2006, which excludes the news of the day and mere facts from copyright protection outright, holding the Government as trustee of those works for the public benefit, and separately lets a person quote a published work, including a newspaper or periodical in the form of a press summary, without infringing copyright, provided the quotation is compatible with fair practice, no more extensive than its purpose justifies, and credits its source.

The Act predates the concept of a machine-readable text-and-data-mining reservation entirely, so no opt-out mechanism of that kind exists either.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.