{
  "node_id": "ug-pdpa-2019",
  "title": "Uganda Data Protection and Privacy Act 2019 - PDPO/NITA-U",
  "domain": "Data Protection & Privacy",
  "version": "1.0.0",
  "last_updated": "2026-04-27",
  "bluf": "Uganda's Data Protection and Privacy Act, 2019 (Act No. 2 of 2019) - assented to by President Yoweri Museveni on 26 February 2019 and published in the Uganda Gazette No. 12 on 19 March 2019, coming into force on 25 May 2019 - is Uganda's primary personal data protection legislation, establishing Uganda as one of the East African states with a comprehensive data protection framework. The Act is implemented through the Data Protection and Privacy Regulations, 2021 (Statutory Instrument No. 39 of 2021), which provide detailed implementing rules. The supervisory authority is the Personal Data Protection Office (PDPO), which operates under the Ministry of ICT and National Guidance and is supported by the National Information Technology Authority Uganda (NITA-U). The PDPO registers data collectors and processors, investigates complaints, and enforces the Act. Key features of Uganda's Data Protection and Privacy Act, 2019: (1) Scope - applies to data collectors, data processors, and data subjects in Uganda; 'data collector' is equivalent to the data controller concept (any person who determines the purpose and means of collecting and processing personal data); (2) Data processing principles - the Act requires compliance with: lawfulness; purpose limitation; proportionality; accuracy; security; openness; data subject participation; and accountability; (3) Sensitive personal data - the Act designates categories requiring heightened protection: data concerning religious or philosophical beliefs; health status; criminal record; sexual orientation; political opinion; race or ethnic origin; and any other category specified by the Minister; (4) Data subject rights - right of access; right to rectification; right to object to processing; right to erasure; right not to be subject to decisions based solely on automated processing; right to complain to the PDPO; (5) Consent - generally required for personal data processing; must be informed, specific, and freely given; explicit consent required for sensitive personal data; (6) Data collector registration - data collectors must apply for registration with the PDPO before collecting or processing personal data; (7) Data Protection Officer - designated for data collectors processing personal data on a large scale or processing sensitive personal data; (8) Breach notification - data collectors must notify the PDPO of data breaches that may affect data subjects' rights; notification must be made within 48 hours of awareness of the breach; data subjects must be notified where the breach may cause substantial harm; (9) Cross-border transfers - personal data may only be transferred to a foreign country with adequate data protection laws; the PDPO may approve transfers to countries without adequate laws subject to safeguards; (10) Penalties - for individuals: a fine not exceeding UGX 2,000,000 (approximately USD 540) or imprisonment not exceeding two years or both; for bodies corporate: a fine not exceeding UGX 5,000,000 (approximately USD 1,350); higher penalties may apply for multiple violations; the Act also provides for data subjects to seek compensation through civil proceedings. Uganda's Constitution guarantees the right to privacy under Article 27, providing the constitutional foundation for the Act.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "iso-27001-2022",
    "iso-27701-privacy-information-management"
  ],
  "primary_citations_count": 7
}