Bidda Sovereign Intelligence · 10,099 Verified Nodes · 39 Sovereign Pillars

Uganda Data Protection and Privacy Act 2019 - PDPO/NITA-U

Uganda's Data Protection and Privacy Act, 2019 (Act No. 2 of 2019) - assented to by President Yoweri Museveni on 26 February 2019 and published in the…

What Uganda Data Protection and Privacy Act 2019 - PDPO/NITA-U requires

Uganda's Data Protection and Privacy Act, 2019 (Act No. 2 of 2019) - assented to by President Yoweri Museveni on 26 February 2019 and published in the Uganda Gazette No. 12 on 19 March 2019, coming into force on 25 May 2019 - is Uganda's primary personal data protection legislation, establishing Uganda as one of the East African states with a comprehensive data protection framework. The Act is implemented through the Data Protection and Privacy Regulations, 2021 (Statutory Instrument No. 39 of 2021), which provide detailed implementing rules. The supervisory authority is the Personal Data Protection Office (PDPO), which operates under the Ministry of ICT and National Guidance and is supported by the National Information Technology Authority Uganda (NITA-U). The PDPO registers data collectors and processors, investigates complaints, and enforces the Act. Key features of Uganda's Data Protection and Privacy Act, 2019: (1) Scope - applies to data collectors, data processors, and data subjects in Uganda; 'data collector' is equivalent to the data controller concept (any person who determines the purpose and means of collecting and processing personal data); (2) Data processing principles - the Act requires compliance with: lawfulness; purpose limitation; proportionality; accuracy; security; openness; data subject participation; and accountability; (3) Sensitive personal data - the Act designates categories requiring heightened protection: data concerning religious or philosophical beliefs; health status; criminal record; sexual orientation; political opinion; race or ethnic origin; and any other category specified by the Minister; (4) Data subject rights - right of access; right to rectification; right to object to processing; right to erasure; right not to be subject to decisions based solely on automated processing; right to complain to the PDPO; (5) Consent - generally required for personal data processing; must be informed, specific, and freely given; explicit consent required for sensitive personal data; (6) Data collector registration - data collectors must apply for registration with the PDPO before collecting or processing personal data; (7) Data Protection Officer - designated for data collectors processing personal data on a large scale or processing sensitive personal data; (8) Breach notification - data collectors must notify the PDPO of data breaches that may affect data subjects' rights; notification must be made within 48 hours of awareness of the breach; data subjects must be notified where the breach may cause substantial harm; (9) Cross-border transfers - personal data may only be transferred to a foreign country with adequate data protection laws; the PDPO may approve transfers to countries without adequate laws subject to safeguards; (10) Penalties - for individuals: a fine not exceeding UGX 2,000,000 (approximately USD 540) or imprisonment not exceeding two years or both; for bodies corporate: a fine not exceeding UGX 5,000,000 (approximately USD 1,350); higher penalties may apply for multiple violations; the Act also provides for data subjects to seek compensation through civil proceedings. Uganda's Constitution guarantees the right to privacy under Article 27, providing the constitutional foundation for the Act.

Pillar: Data Protection & Privacy · Authority: Personal Data Protection Office (PDPO) / National Information Technology Authority Uganda (NITA-U) · Version: 1.0.0 · Last updated:

Primary source: https://www.nita.go.ug/

SHA-256 integrity: 1e31f2f1fbb8caf699f3cfbf546a95aaf19efd86d7705578b330ddf9ef179493

Primary Citations — 7 traced to source

  • Data Protection and Privacy Act, 2019 (Act No. 2 of 2019, Uganda) - assented 26 February 2019; published Uganda Gazette No. 12 on 19 March 2019; in force 25 May 2019; eight processing principles: lawfulness, purpose limitation, proportionality, accuracy, security, openness, data subject participation, accountability; sensitive personal data: religious/philosophical beliefs, health, criminal record, sexual orientation, political opinion, racial/ethnic origin; data subject rights: access, rectification, objection, erasure, automated decision-making protection; explicit consent for sensitive data; 48-hour PDPO breach notification; cross-border transfer adequacy requirement; fines: individuals up to UGX 2,000,000; bodies corporate up to UGX 5,000,000
  • Data Protection and Privacy Regulations 2021 (Statutory Instrument No. 39 of 2021, Uganda) - implementing regulations for the Data Protection and Privacy Act 2019; specifies: data collector registration requirements and PDPO registration process; consent standards including explicit consent for sensitive personal data; Data Protection Officer appointment criteria; breach notification procedures and 48-hour timeline; cross-border transfer approval procedures; data subject rights exercise timelines; PDPO investigation and enforcement procedures

+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.