Loading...
Loading...
Copyright © 2026 Anove International B.V.
All product names, logos, and brands are property of their respective owners. Use of these names does not imply affiliation, endorsement, or partnership.
DPPA
Uganda's DPPA (2019) and its 2021 Regulations regulate the collection, processing, use, storage and disclosure of personal data, with mandatory registration with the PDPO. It applies extraterritorially to anyone processing Ugandan citizens' data.
The Data Protection and Privacy Act commenced on 3 May 2019 and the Data Protection and Privacy Regulations took effect on 12 March 2021; the Personal Data Protection Office (PDPO) was operationalised in August 2021 under the National Information Technology Authority Uganda. The Act applies to any person, entity or public body collecting, processing, holding or using personal data within Uganda, and to those outside Uganda processing the personal data of Ugandan citizens. Every data collector, processor or controller must register with the PDPO, which maintains a public register. Consent is the primary basis for collection, and children's data and special personal data (religious or philosophical beliefs, political opinion, sexual life, financial information, health records) face stricter rules.
Breaches must be notified to the PDPO immediately, and registered entities must file annual reports summarising breaches. Cross-border processing or storage requires either adequate protection in the destination country or the data subject's consent. On 18 July 2025 the PDPO decided a collective complaint by four Ugandan citizens against Google LLC: rejecting the argument that no physical presence meant no obligations, the Office held that economic presence sufficed, found Google acted as a data controller, and ordered it to register with the PDPO within 30 days, designate a representative for Uganda and evidence compliance for its cross-border transfers.
Every data collector, processor and controller, in Uganda or abroad when processing Ugandan citizens' data, must register with the Personal Data Protection Office; the July 2025 Google decision confirms this applies to foreign technology companies.
Informed consent must be obtained before collection or processing; data must be collected directly from the data subject for a lawful, specific purpose, with additional restrictions for children's and special personal data.
Unauthorised access or acquisition of personal data must be notified to the PDPO immediately, and registered entities must submit annual breach reports.
Controllers and processors must secure data integrity through risk identification, appropriate precautions, regular verification and updated safeguards, including contractual security duties on processors.
Read more
Anove scans your stack against DPPA and 260+ other frameworks in minutes.
Data may be processed or stored outside Uganda only where the destination country offers at least equivalent protection or the data subject consents.