Uganda's Data Protection and Privacy Act, 2019 (the DPPA) came into full force with the issuance of the Data Protection and Privacy Regulations, 2021, and the commencement of enforcement by the National Information Technology Authority-Uganda (NITA-U) as the supervisory authority. For digital businesses—including e-commerce platforms, fintech apps, health-tech services, and SaaS providers—compliance with the DPPA is now a legal requirement, not merely a best practice.

This article provides a step-by-step compliance checklist for digital businesses handling personal data in Uganda, covering registration, consent, data subject rights, data security, cross-border transfers, and enforcement risks.

1. Registration with NITA-U

The first and most fundamental compliance obligation is registration as a data processor or data controller with NITA-U. The DPPA requires every person who processes personal data to register with the supervisory authority. The registration process includes:

  • Submission of the prescribed application form through the NITA-U online portal, including details of the data controller or processor, the nature of the data processed, the purposes of processing, and the security measures in place.
  • Payment of the prescribed registration fee (currently UGX 200,000 for local entities; higher for foreign entities with a presence in Uganda).
  • Designation of a data protection officer (DPO) whose name and contact details must be submitted to NITA-U. The DPO can be an employee or an external consultant.
  • Annual renewal of registration, with updated information on processing activities and security measures.

Failure to register is an offence under the DPPA, with penalties of up to UGX 5 million (approximately USD 1,350) or imprisonment for up to three years, or both.

2. Lawful Basis for Processing

The DPPA requires that all processing of personal data be based on one or more lawful grounds. For digital businesses, the most common grounds are:

  • Consent: The data subject has given clear, specific, and informed consent. Consent must be freely given, and the data subject has the right to withdraw consent at any time. For digital platforms, consent should be obtained through a clear affirmative action (such as ticking a checkbox) and not through pre-ticked boxes or implied consent.
  • Contractual necessity: Processing is necessary for the performance of a contract with the data subject (e.g., processing payment information to fulfil an order).
  • Legal obligation: Processing is required to comply with a legal obligation (e.g., retaining transaction records for tax purposes).
  • Legitimate interests: Processing is necessary for the legitimate interests of the data controller, provided those interests are not overridden by the data subject's rights. This ground is more limited under the DPPA than under the GDPR and should be used with caution.

3. Consent Management

For digital businesses relying on consent as the basis for processing, the DPPA imposes strict requirements:

  • Consent must be obtained in writing or through a clear affirmative action. Silence or inactivity does not constitute consent.
  • The request for consent must be presented in a manner that is clearly distinguishable from other matters, in an intelligible and easily accessible form, using clear and plain language.
  • Data subjects must be informed of their right to withdraw consent before giving consent, and withdrawal must be as easy as giving consent.
  • Records of consent must be maintained and be producible upon request by NITA-U.
  • For children under 18 years of age, consent must be obtained from a parent or legal guardian. Digital platforms that process children's data should implement age-verification mechanisms.
Practical Tip

Implement a consent management platform (CMP) that records the date, time, and specific scope of each consent. The CMP should also manage cookie consent for websites and mobile apps, in line with NITA-U's guidance on tracking technologies.

4. Data Subject Rights

The DPPA grants data subjects a range of rights that digital businesses must be equipped to honour:

  • Right to information: Data subjects must be informed about what data is collected, the purposes of processing, and with whom the data is shared. A comprehensive privacy policy is the primary mechanism for fulfilling this obligation.
  • Right of access: Data subjects have the right to obtain confirmation of whether their data is being processed and to request a copy of the data.
  • Right to rectification: Data subjects may request correction of inaccurate or incomplete data.
  • Right to erasure: Data subjects may request deletion of their data where the data is no longer necessary for the purpose for which it was collected, or where consent has been withdrawn.
  • Right to restrict processing: Data subjects may request that processing be restricted in certain circumstances, such as where the accuracy of the data is contested.
  • Right to data portability: Data subjects have the right to receive their data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
  • Right to object: Data subjects may object to processing for direct marketing purposes or processing based on legitimate interests.

Digital businesses should implement procedures for handling data subject requests within the statutory timeline (30 days, extendable by a further 30 days for complex requests).

5. Data Security and Breach Notification

The DPPA requires data controllers and processors to implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. Key requirements include:

  • Encryption of personal data in transit and at rest, particularly for sensitive data categories such as financial information, health data, and biometric data.
  • Implementation of access controls, including role-based access, multi-factor authentication, and audit logging.
  • Regular security audits and penetration testing.
  • Data breach notification to NITA-U within 48 hours of becoming aware of a breach, and notification to affected data subjects where the breach is likely to result in a high risk to their rights and freedoms.
  • Maintenance of a data breach register documenting all breaches, their impact, and remedial measures taken.

6. Cross-Border Data Transfers

The DPPA restricts the transfer of personal data outside Uganda unless the transfer is to a country that offers an adequate level of protection, or the data subject has given explicit consent to the transfer after being informed of the possible risks. The Minister of ICT and National Guidance is empowered to prescribe countries with adequate data protection regimes. In the absence of such a determination, digital businesses transferring data across borders should:

  • Obtain explicit consent from data subjects for the specific transfer.
  • Implement standard contractual clauses or binding corporate rules approved by NITA-U.
  • Conduct a data protection impact assessment (DPIA) covering the cross-border transfer.

For digital businesses using cloud service providers (AWS, Google Cloud, Microsoft Azure) with servers outside Uganda, these cross-border transfer requirements are directly relevant.

7. Enforcement and Penalties

NITA-U has investigation and enforcement powers under the DPPA, including the power to issue enforcement notices, impose monetary penalties, and suspend or prohibit processing activities. Contravention of the DPPA may result in penalties of up to UGX 10 million (approximately USD 2,700) or imprisonment for up to five years, or both, depending on the offence. Additionally, data subjects may bring civil claims for damages arising from contravention of the Act.

Our Corporate Advisory practice at Jamani Advocates provides comprehensive data protection compliance services, including DPPA registration, privacy policy drafting, consent mechanism design, and breach response planning. Contact our team for tailored guidance on your data protection obligations.

Previous Article
Structuring for Investment: Choosing the Right Entity in Uganda