Guide — 7 min read

Uganda's Data Protection and Privacy Act: What Organizations Must Do

A plain-language guide to Uganda's Data Protection and Privacy Act 2019 for businesses, SACCOs, schools and health providers, with practical compliance steps.

What the law covers

Uganda's Data Protection and Privacy Act, 2019 protects personal data: any information that identifies a person, such as names, phone numbers, national ID numbers, health records, financial details and photos. The Data Protection and Privacy Regulations, 2021 set out how it works in practice.

It is overseen by the Personal Data Protection Office (PDPO), which operates under the National Information Technology Authority – Uganda (NITA-U).

Who it applies to

Any organization that collects, holds or uses personal data about people in Uganda: companies, SACCOs and microfinance institutions, hospitals and clinics, schools and universities, NGOs and government bodies. If you keep customer, patient, student, member or staff records, it applies to you.

The core principles

The Act expects organizations to handle personal data in line with a set of principles, including:

  • ↳Collect data only for a lawful, specific purpose, and don't use it for something else.
  • ↳Get consent where the law requires it, and tell people why you collect their data.
  • ↳Collect only what you need, keep it accurate, and don't keep it longer than necessary.
  • ↳Protect it with appropriate security safeguards.
  • ↳Respect people's rights to access and correct their data.

Practical steps to comply

For most organizations, compliance comes down to a clear list of actions:

  • ↳Register with the Personal Data Protection Office as the regulations require.
  • ↳Map what personal data you hold, where it lives, who can access it and why you have it.
  • ↳Update privacy notices and consent forms on your website, apps and paper forms.
  • ↳Appoint a person responsible for data protection.
  • ↳Put security controls in place: access control, encryption, backups, and patching.
  • ↳Have a plan for data breaches, including how you will notify the PDPO.
  • ↳Check that vendors who process data for you, such as hosting or payroll providers, protect it properly.
  • ↳Train staff, since most breaches start with human error.

How ISO 27001 helps

ISO/IEC 27001 is the international standard for information security management. Its risk assessment and controls cover much of the security the Act expects, and a certificate gives clients and regulators independent evidence that you take data protection seriously.

Many SACCOs, FinTechs and health providers use ISO 27001 as the framework for their data protection program.

Published 30 September 2026 by Terry Technologies, Kampala.

FAQ

Quick answers.

Who enforces the Data Protection and Privacy Act in Uganda?

The Personal Data Protection Office (PDPO), which sits under NITA-U.

Do small businesses need to comply?

Yes. The Act applies to any organization that collects or processes personal data, regardless of size.

Is ISO 27001 required by the Act?

No, but it is a widely used framework for meeting the Act's security expectations and demonstrating them.

Move your cursor — then let's talk

Ready to build what's next?