Law / Uganda

Uganda

9 of 11 named instruments researched to a stage, across three of the six areas of law we track: 8 in force and 1 repealed, withdrawn or blocked. As of 19 September 2026.

When they take effect9 of 9 carry a date. Earlier is before 2014.
Before 2014: 3 instruments (2 in force, 1 repealed, withdrawn or blocked) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 6 instruments (6 in force) 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (233 words)

Uganda's comprehensive personal-data regime is the Data Protection and Privacy Act, 2019 (Chapter 97), which binds any person, institution or public body that collects, processes, holds or uses personal data within Uganda, or outside Uganda in relation to a Ugandan citizen's data.

The Act requires a lawful basis, most often the data subject's prior consent, before personal data is collected or processed; bars collection or processing of a child's data without a parent's or guardian's consent and of specially protected categories (religious or philosophical belief, political opinion, sexual life, financial information, and health status) outside narrow exceptions, without naming biometric or genetic data as a special category; gives a data subject rights of information, access, correction, objection (including to direct marketing) and against a purely automated decision; requires notice to the National Information Technology Authority of an unauthorised access to or acquisition of personal data, with the Authority deciding whether the affected data subject must also be told and the Act setting no fixed deadline for that second notice; and requires either an adequacy-equivalent destination or the data subject's consent, rather than prior government authorisation, before personal data is processed or stored outside Uganda.

A data subject harmed by a contravention may sue for compensation in court, and unlawfully obtaining, disclosing, destroying, altering or selling personal data is a criminal offence carrying a fine or imprisonment of up to ten years, or both.

Breach notification

Data Protection and Privacy Act, 2019, breach notification

Data Protection and Privacy Act, 2019, s. 23 (breach notification)official Act text as published by the Uganda Legal Information Institute (ULII), preserved in an Internet Archive capture of the ULII page

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://ulii.org/en/akn/ug/act/2019/9/eng@2019-05-03

In force since 3 May 2019. Binds public and private bodies.

What this law does

Section 23(1) requires a data collector, processor or controller that believes a data subject's personal data has been accessed or acquired by an unauthorised person to notify the Authority immediately, in the prescribed manner, of the access or acquisition and the remedial action taken; the Act states no numbered grace period, the clock is 'immediately' from the point the collector, processor or controller believes the breach occurred.

Section 23(2) leaves the decision on whether the data subject must also be told to the Authority rather than to the data collector, processor or controller, and the Act sets no independent deadline for that data-subject notice; it runs from the Authority's own determination, not from the breach.

Where the Authority does direct notice to the data subject, section 23(3) requires it by registered mail to their last known address, electronic mail to their last known address, a prominent position on the responsible party's website, or publication in the mass media, and section 23(4) requires it to carry sufficient information for the data subject to take protective measures.

Section 23(5) lets the Authority direct the responsible party to publicise the breach where the Authority has grounds to believe publicity would protect an affected data subject.

What it requires

Comprehensive regime

Data Protection and Privacy Act, 2019, comprehensive personal-data regime

Data Protection and Privacy Act 2019 (Chapter 97), ss. 1-7, 10-12, 14-15, 17-18, 20-22, 29-30 (principles, lawful basis, security and registration)official Act text as published by the Uganda Legal Information Institute (ULII), preserved in an Internet Archive capture of the ULII page

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://ulii.org/en/akn/ug/act/2019/9/eng@2019-05-03

In force since 3 May 2019. Binds public and private bodies.

What this law does

The Act applies to a person, institution or public body collecting, processing, holding or using personal data within Uganda, and to a person outside Uganda doing the same in relation to a Ugandan citizen's data (s. 1).

It establishes a personal data protection office within the National Information Technology Authority - Uganda (the Authority) to enforce the accountability, fairness, lawfulness, adequacy, quality, transparency and security principles of s. 3, and requires every institution to designate its own data protection officer (s. 6).

A person must not collect or process personal data without the data subject's prior consent, unless a public duty, national security, an offence-related purpose, a contract with the data subject, a medical purpose or another legal obligation applies, and processing must stop if the data subject objects outside those grounds (s. 7).

Personal data must be collected directly from the data subject unless a listed exception applies, such as the data already being in a public record or made public by the data subject, and it must be collected only for a specific, explicitly defined lawful purpose related to the collector's functions (ss. 11-12).

Further processing of data already held must stay compatible with the purpose it was collected for, unless the data subject consents, the data is public, or a listed law-enforcement, national-security, public-health or research ground applies (s. 17).

A data controller must process no more than the necessary or relevant data, keep it complete, accurate, up to date and not misleading, retain it no longer than necessary unless a listed ground extends retention, and destroy or de-identify it at the expiry of the retention period in a manner that prevents reconstruction (ss. 14-15, 18).

A data controller, collector or processor must secure personal data with appropriate technical and organisational measures against loss, damage, unauthorised destruction and unlawful access, identifying foreseeable risks, maintaining safeguards against them, verifying they work and updating them, and observing generally accepted security practices (s. 20); a data controller may not let a data processor handle personal data unless the processor meets those same security measures, and the processing contract between them must require it (s. 21), while an operator or other person processing on a controller's behalf must treat the data as confidential and not disclose it except where the law requires or the duty calls for it (s. 22).

The Authority keeps a data protection register in which every person, institution or public body collecting or processing personal data must register, and makes that register available for public inspection (ss. 29-30).

What it requires

Cross border transfer

Data Protection and Privacy Act, 2019, cross-border transfer

Data Protection and Privacy Act, 2019, s. 19 (cross-border transfer)official Act text as published by the Uganda Legal Information Institute (ULII), preserved in an Internet Archive capture of the ULII page

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://ulii.org/en/akn/ug/act/2019/9/eng@2019-05-03

In force since 3 May 2019. Binds public and private bodies.

What this law does

Section 19 requires a data processor or data controller based in Uganda that processes or stores personal data outside Uganda to ensure either that the destination country has measures protecting personal data at least equivalent to this Act's, or that the data subject has consented to the transfer.

The Act sets no prior government-authorisation requirement and names no localisation duty; the section's two grounds, an adequacy-equivalent destination or consent, are the only conditions it states for a transfer outside Uganda.

What it requires

Data subject rights

Data Protection and Privacy Act, 2019, rights of data subjects

Data Protection and Privacy Act, 2019, ss. 13, 16, 24-28 (rights of data subjects)official Act text as published by the Uganda Legal Information Institute (ULII), preserved in an Internet Archive capture of the ULII page

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://ulii.org/en/akn/ug/act/2019/9/eng@2019-05-03

In force since 3 May 2019. Binds public and private bodies.

What this law does

Section 13 requires a person collecting personal data to inform the data subject, before or as soon as practicable after collection, of the nature and category of the data, the collector's name and address, the purpose, whether supplying the data is discretionary or mandatory, the consequences of not providing it, the authorised or legal requirement for collecting it, the recipients, the existence of the rights of access and rectification, and the retention period, subject to law-enforcement, national-security and revenue-collection exceptions.

Section 16 gives a data subject the right to have a data controller correct or delete personal data that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained, or destroy a record the controller no longer has authority to retain, with the controller telling the data subject the outcome and notifying every person the data was disclosed to of a correction made.

Section 24 gives a data subject who proves their identity the right to confirmation of whether a controller holds their personal data, a description of it, and the identity of any third party with access to it, to be answered within thirty days subject to a third party's own privacy.

Section 25 lets a data subject require a controller or processor in writing to stop processing that causes or is likely to cause them unwarranted substantial damage or distress, other than processing under section 7(2), with the controller answering within fourteen days and the Authority able to order compliance within seven.

Section 26 lets a data subject require a controller in writing to stop processing their data for direct marketing, again with a fourteen-day answer and an Authority order available.

Section 27 lets a data subject require that a decision significantly affecting them not rest solely on automated processing, and where such a decision is made anyway entitles them to be told and to have it reconsidered within twenty-one days of their written request, subject to contract-related and legally required exceptions.

Section 28 lets the Authority, on a data subject's complaint that their data is inaccurate, order a controller to rectify, update, block, erase or destroy it, with the controller then notifying every third party the data was previously disclosed to.

What it requires

Enforcement supervision

Data Protection and Privacy Act, 2019, enforcement and offences

Data Protection and Privacy Act, 2019, ss. 31-38 (enforcement and offences)official Act text as published by the Uganda Legal Information Institute (ULII), preserved in an Internet Archive capture of the ULII page

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://ulii.org/en/akn/ug/act/2019/9/eng@2019-05-03

In force since 3 May 2019. Binds public and private bodies.

What this law does

Section 31 lets a data subject or any other person complain to the Authority in the prescribed manner that a data collector, processor or controller is infringing their rights or violating the Act, and lets a data collector, processor or controller itself complain to the Authority in writing about a violation or non-compliance.

Section 32 requires the Authority to investigate every complaint and lets it direct a data collector, processor or controller to remedy a breach or take other action to restore the integrity of the data or the data subject's rights.

Section 33 gives a data subject who suffers damage or distress through a contravention of the Act a right to apply to a court of competent jurisdiction for compensation from the data collector, processor or controller responsible, a private right of action, subject to the defence that the person took reasonable care to comply. Section 34 lets a person aggrieved by an Authority decision appeal to the Minister within thirty days, with a copy of the appeal going to the Authority.

Sections 35 to 37 make it an offence to unlawfully obtain, disclose or procure the disclosure of personal data, to unlawfully destroy, delete, mislead, conceal or alter it, or to sell or offer to sell it, each punishable on conviction by a fine of two hundred and forty to two hundred and forty five currency points (twenty thousand Uganda shillings per currency point) or imprisonment of up to ten years, or both.

Section 38 extends those offences to a corporation and to any officer who knowingly and wilfully authorises or permits the contravention, and lets a court additionally fine a convicted corporation up to two percent of its annual gross turnover, having regard to the gravity and impact of the offence.

What it requires

Sensitive categories

Data Protection and Privacy Act, 2019, children and special personal data

Data Protection and Privacy Act, 2019, ss. 8-9 (children and special personal data)official Act text as published by the Uganda Legal Information Institute (ULII), preserved in an Internet Archive capture of the ULII page

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://ulii.org/en/akn/ug/act/2019/9/eng@2019-05-03

In force since 3 May 2019. Binds public and private bodies.

What this law does

Section 8 bars a person from collecting or processing a child's personal data unless it is carried out with the prior consent of the child's parent, guardian or another person with authority to decide for the child, or is necessary to comply with the law, or is for research or statistical purposes.

Section 9(1) bars a person from collecting or processing personal data relating to an individual's religious or philosophical beliefs, political opinion, sexual life, financial information, or health status or medical records, and section 9(2) exempts information collected under the Uganda Bureau of Statistics Act from that bar.

Section 9(3) permits collection or processing of that special personal data only where it is exercised or performed under a right or obligation a law imposes on an employer, where the data subject gives it freely and with consent, or where a non-profit political, philosophical, religious or trade union body collects or processes it for its own legitimate activities about its own members or regular contacts and does not disclose it to a third party without the data subject's consent.

The enumerated special-category list does not name biometric or genetic data, so a biometric identifier is not treated as special personal data under this Act.

What it requires

Scraping law2 instruments, 1 in force, 1 repealed, withdrawn or blocked

Research summary (207 words)

Uganda has no scraping-specific statute, so general law governs each dimension separately.

The Computer Misuse Act, 2011 criminalised unauthorised access to a computer, but Uganda's Constitutional Court permanently enjoined enforcement of that provision on 17 March 2026, both because the Computer Misuse (Amendment) Act, 2022 that produced its current wording was passed without the constitutionally required parliamentary quorum and because the provision itself was held vague and overbroad, so no operative unauthorised-access offence currently exists on the point.

No reported Ugandan case addresses the enforceability of a browsewrap or clickwrap terms-of-service against a scraper, and no Ugandan statute or case establishes a scraping-specific unfair-competition, misappropriation or trespass doctrine, assigns legal weight to a robots.txt directive, or imposes an AI-training-specific rule.

The Copyright and Neighbouring Rights Act, 2006 permits fair use for private study, quotation compatible with fair practice, and teaching, but Uganda has no text-and-data-mining exception and no sui generis database right.

The Data Protection and Privacy Act, 2019 applies to personal data without a general carve-out for information that is publicly accessible, so scraping personal data from a public Ugandan website remains subject to the Act's consent and purpose-limitation duties, narrowed only where a public record or the data subject's own act made the data public.

Computer misuse

Computer Misuse Act, 2011, unauthorised access

Computer Misuse Act, 2011 (Act 2 of 2011; Chapter 96), s. 11 (unauthorised access), as amended by the Computer Misuse (Amendment) Act, 2022official Act text as published by the Uganda Legal Information Institute (ULII), preserved in an Internet Archive capture of the ULII page

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://ulii.org/en/akn/ug/act/2011/2/eng@2023-12-31

Struck down: invalidated by a court, effective 15 April 2011. Binds public and private bodies.

What this law does

As originally enacted, section 12 (renumbered section 11 by the Computer Misuse (Amendment) Act, 2022) made it an offence to access or intercept another person's program, data or information without authorisation, and the 2022 amendment added voice or video recording of another person and sharing information about another person without authorisation to the same offence, carrying a fine of up to 750 currency points (UGX 15,000,000) or imprisonment of up to ten years, or both.

On 17 March 2026, in a consolidated ruling on three petitions filed in 2022, Uganda's Constitutional Court held that the Computer Misuse (Amendment) Act, 2022 was passed without the quorum of one-third of all members required by the Rules of Procedure of Parliament and Articles 88 and 89 of the Constitution, and separately found section 11, along with sections 23 and 26 to 29, vague, overbroad and inconsistent with the constitutional guarantees of freedom of expression and access to information.

The court declared the Computer Misuse (Amendment) Act, 2022 null and void and issued a permanent injunction restraining its enforcement of section 11, so no unauthorised-access offence under this Act currently binds a person accessing a computer system in Uganda.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (147 words)

Uganda has no press-publisher neighbouring right, no mandatory platform-to-publisher bargaining code, no recognised hot-news misappropriation doctrine distinct from ordinary copyright law, and no located statute or case law addressing hyperlinking or framing liability specifically; each of those dimensions is a sourced absence rather than an unresolved question.

The relevant instrument is the Copyright and Neighbouring Rights Act, 2006, which excludes the news of the day and mere facts from copyright protection outright, holding the Government as trustee of those works for the public benefit, and separately lets a person quote a published work, including a newspaper or periodical in the form of a press summary, without infringing copyright, provided the quotation is compatible with fair practice, no more extensive than its purpose justifies, and credits its source.

The Act predates the concept of a machine-readable text-and-data-mining reservation entirely, so no opt-out mechanism of that kind exists either.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.