Law / Uganda

Data Protection and Privacy Act, 2019, comprehensive personal-data regime

Data Protection and Privacy Act 2019 (Chapter 97), ss. 1-7, 10-12, 14-15, 17-18, 20-22, 29-30 (principles, lawful basis, security and registration)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 3 May 2019.

A comprehensive regime rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Obtain the data subject's prior consent before collecting or processing their personal data, unless a specific ground in section 7(2) applies, such as a legal requirement, a public duty, national security, a contract with the data subject, or a legal obligation.
  • Stop collecting or processing a data subject's personal data if they object, unless the collection or processing falls under one of the section 7(2) grounds.
  • Collect personal data directly from the data subject, unless a listed exception applies, such as the data being in a public record, already made public by the data subject, or collected with their consent.
  • Collect personal data only for a lawful purpose that is specific, explicitly defined, and related to your functions or activities.
  • Process only the personal data that is necessary or relevant, and never in excess of what the law authorises or the purpose requires.
  • Keep the personal data you collect, process, use or hold complete, accurate, up to date and not misleading.
  • Use personal data collected for a specific purpose only for that purpose, unless the data subject consents, the data is already public, or a listed law-enforcement, national-security, public-health or research ground applies.
  • Retain personal data no longer than necessary for the purpose collected, and destroy, delete or de-identify it at the expiry of the retention period in a manner that prevents its reconstruction.
  • Identify foreseeable risks to personal data in your possession, establish and maintain safeguards against them, verify regularly that the safeguards work, and update them as risks or deficiencies change.
  • Do not let a data processor handle personal data on your behalf unless it has established and complies with this Act's security measures, and require that in your contract with the processor.
  • As an operator or other person processing personal data on a controller's behalf, treat the data as confidential and do not disclose it unless required by law or in the course of discharging your duty.
  • Register with the National Information Technology Authority as a data controller or other prescribed person before collecting or processing personal data.

What it reaches

Obligation class

Consent, Retention, Security, Licensing, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Act applies to a person, institution or public body collecting, processing, holding or using personal data within Uganda, and to a person outside Uganda doing the same in relation to a Ugandan citizen's data (s. 1).

It establishes a personal data protection office within the National Information Technology Authority - Uganda (the Authority) to enforce the accountability, fairness, lawfulness, adequacy, quality, transparency and security principles of s. 3, and requires every institution to designate its own data protection officer (s. 6).

A person must not collect or process personal data without the data subject's prior consent, unless a public duty, national security, an offence-related purpose, a contract with the data subject, a medical purpose or another legal obligation applies, and processing must stop if the data subject objects outside those grounds (s. 7).

Personal data must be collected directly from the data subject unless a listed exception applies, such as the data already being in a public record or made public by the data subject, and it must be collected only for a specific, explicitly defined lawful purpose related to the collector's functions (ss. 11-12).

Further processing of data already held must stay compatible with the purpose it was collected for, unless the data subject consents, the data is public, or a listed law-enforcement, national-security, public-health or research ground applies (s. 17).

A data controller must process no more than the necessary or relevant data, keep it complete, accurate, up to date and not misleading, retain it no longer than necessary unless a listed ground extends retention, and destroy or de-identify it at the expiry of the retention period in a manner that prevents reconstruction (ss. 14-15, 18).

A data controller, collector or processor must secure personal data with appropriate technical and organisational measures against loss, damage, unauthorised destruction and unlawful access, identifying foreseeable risks, maintaining safeguards against them, verifying they work and updating them, and observing generally accepted security practices (s. 20); a data controller may not let a data processor handle personal data unless the processor meets those same security measures, and the processing contract between them must require it (s. 21), while an operator or other person processing on a controller's behalf must treat the data as confidential and not disclose it except where the law requires or the duty calls for it (s. 22).

The Authority keeps a data protection register in which every person, institution or public body collecting or processing personal data must register, and makes that register available for public inspection (ss. 29-30).

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • generates_content

Read the law

official Act text as published by the Uganda Legal Information Institute (ULII), preserved in an Internet Archive capture of the ULII page

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://ulii.org/en/akn/ug/act/2019/9/eng@2019-05-03

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app