Breach notification
Data Protection and Privacy Act, 2019, breach notification
Data Protection and Privacy Act, 2019, s. 23 (breach notification)official Act text as published by the Uganda Legal Information Institute (ULII), preserved in an Internet Archive capture of the ULII page
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://ulii.org/en/akn/ug/act/2019/9/eng@2019-05-03In force since 3 May 2019. Binds public and private bodies.
What this law does
Section 23(1) requires a data collector, processor or controller that believes a data subject's personal data has been accessed or acquired by an unauthorised person to notify the Authority immediately, in the prescribed manner, of the access or acquisition and the remedial action taken; the Act states no numbered grace period, the clock is 'immediately' from the point the collector, processor or controller believes the breach occurred.
Section 23(2) leaves the decision on whether the data subject must also be told to the Authority rather than to the data collector, processor or controller, and the Act sets no independent deadline for that data-subject notice; it runs from the Authority's own determination, not from the breach.
Where the Authority does direct notice to the data subject, section 23(3) requires it by registered mail to their last known address, electronic mail to their last known address, a prominent position on the responsible party's website, or publication in the mass media, and section 23(4) requires it to carry sufficient information for the data subject to take protective measures.
Section 23(5) lets the Authority direct the responsible party to publicise the breach where the Authority has grounds to believe publicity would protect an affected data subject.
What it requires