What the law covers
Uganda's Data Protection and Privacy Act, 2019 protects personal data: any information that identifies a person, such as names, phone numbers, national ID numbers, health records, financial details and photos. The Data Protection and Privacy Regulations, 2021 set out how it works in practice.
It is overseen by the Personal Data Protection Office (PDPO), which operates under the National Information Technology Authority – Uganda (NITA-U).
Who it applies to
Any organization that collects, holds or uses personal data about people in Uganda: companies, SACCOs and microfinance institutions, hospitals and clinics, schools and universities, NGOs and government bodies. If you keep customer, patient, student, member or staff records, it applies to you.
The core principles
The Act expects organizations to handle personal data in line with a set of principles, including:
- ↳Collect data only for a lawful, specific purpose, and don't use it for something else.
- ↳Get consent where the law requires it, and tell people why you collect their data.
- ↳Collect only what you need, keep it accurate, and don't keep it longer than necessary.
- ↳Protect it with appropriate security safeguards.
- ↳Respect people's rights to access and correct their data.
Practical steps to comply
For most organizations, compliance comes down to a clear list of actions:
- ↳Register with the Personal Data Protection Office as the regulations require.
- ↳Map what personal data you hold, where it lives, who can access it and why you have it.
- ↳Update privacy notices and consent forms on your website, apps and paper forms.
- ↳Appoint a person responsible for data protection.
- ↳Put security controls in place: access control, encryption, backups, and patching.
- ↳Have a plan for data breaches, including how you will notify the PDPO.
- ↳Check that vendors who process data for you, such as hosting or payroll providers, protect it properly.
- ↳Train staff, since most breaches start with human error.
How ISO 27001 helps
ISO/IEC 27001 is the international standard for information security management. Its risk assessment and controls cover much of the security the Act expects, and a certificate gives clients and regulators independent evidence that you take data protection seriously.
Many SACCOs, FinTechs and health providers use ISO 27001 as the framework for their data protection program.
Published 30 September 2026 by Terry Technologies, Kampala.
