Back to Frameworks

Uganda Data Protection and Privacy Act (2019)

Uganda
v2019
10 domains
17 controls

The Uganda Data Protection and Privacy Act, 2019 regulates the collection, processing, and storage of personal data in Uganda. It establishes the Personal Data Protection Office, defines data subject rights, sets obligations for data controllers and processors, and provides for cross-border data transfer restrictions. Applies to all persons who collect, process, hold, or use personal data within Uganda.

Verified

Uganda Data Protection and Privacy Act (2019) is a compliance framework from Uganda with 10 domains and 17 controls that map to 83 other frameworks. The largest domains are Data Protection Principles (3 controls), Offences and Enforcement (3 controls), Consent and Children (2 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (10)

Consent and Children

2 controls

Consent and Children

Controls in the Consent and Children domain of Uganda Data Protection and Privacy Act (2019)2 controls
CodeTitle
UGA-8Consent Requirements
UGA-9Children's Data (Section on minors)

Data Protection Principles

3 controls

Data Protection Principles

Controls in the Data Protection Principles domain of Uganda Data Protection and Privacy Act (2019)3 controls
CodeTitle
UGA-3Accountability Principle
UGA-4Fairness and Lawfulness
UGA-5Purpose Limitation and Minimization

Data Subject Rights

1 controls

Data Subject Rights

Controls in the Data Subject Rights domain of Uganda Data Protection and Privacy Act (2019)1 controls
CodeTitle
UGA-12Rights of Data Subjects

Governance

1 controls
Controls in the Governance domain of Uganda Data Protection and Privacy Act (2019)1 controls
CodeTitle
UGANDA-4DPO, Governance, Breach

Offences and Enforcement

3 controls

Offences and Enforcement

Controls in the Offences and Enforcement domain of Uganda Data Protection and Privacy Act (2019)3 controls
CodeTitle
UGA-13Unlawful Obtaining or Disclosure
UGA-14Unlawful Destruction or Alteration
UGA-15Unauthorized Sale of Data

Regulator and Data Protection Officer

2 controls

Regulator and Data Protection Officer

Controls in the Regulator and Data Protection Officer domain of Uganda Data Protection and Privacy Act (2019)2 controls
CodeTitle
UGA-6Personal Data Protection Office
UGA-7Data Protection Officer

Rights

1 controls
Controls in the Rights domain of Uganda Data Protection and Privacy Act (2019)1 controls
CodeTitle
UGANDA-2Consent, Notice, Rights

Scope

1 controls
Controls in the Scope domain of Uganda Data Protection and Privacy Act (2019)1 controls
CodeTitle
UGANDA-1Registration, Scope, Lawful Basis

Security

1 controls
Controls in the Security domain of Uganda Data Protection and Privacy Act (2019)1 controls
CodeTitle
UGANDA-3Security and Cross-Border

Sensitive Data and Privacy Protection

2 controls

Sensitive Data and Privacy Protection

Controls in the Sensitive Data and Privacy Protection domain of Uganda Data Protection and Privacy Act (2019)2 controls
CodeTitle
UGA-10Sensitive Personal Data Prohibition
UGA-11Protection of Privacy

Your Compliance Coverage

If you comply with Uganda Data Protection and Privacy Act (2019), you already cover:

Maps to 83 other frameworks

17 total controls
ISO/IEC 27400:2022
6 source controls mapped|5 target controls covered
35%
Virginia CDPA
5 source controls mapped|2 target controls covered
29%
Uruguay DPL
5 source controls mapped|3 target controls covered
29%
UK GDPR (UK General Data Protection Regulation)
5 source controls mapped|2 target controls covered
29%
UK AI Regulation Framework
5 source controls mapped|1 target controls covered
29%
Barbados Data Protection Act 2019
5 source controls mapped|5 target controls covered
29%
Saudi Arabia PDPL
5 source controls mapped|5 target controls covered
29%
Bahrain PDPL
5 source controls mapped|5 target controls covered
29%
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
5 source controls mapped|11 target controls covered
29%
UK Age Appropriate Design Code (Children's Code)
5 source controls mapped|6 target controls covered
29%
Sweden Data Protection Act (Dataskyddslag, 2018:218)
5 source controls mapped|4 target controls covered
29%
GDPR
5 source controls mapped|8 target controls covered
29%
Azerbaijan Law on Personal Data (2010)
5 source controls mapped|4 target controls covered
29%
SOC for Cybersecurity - Cybersecurity Risk Management Examination
5 source controls mapped|2 target controls covered
29%
29%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
5 source controls mapped|6 target controls covered
29%
ISO/IEC 23894:2023
5 source controls mapped|1 target controls covered
29%
US ITAR and EAR - Export Control and Data Security
4 source controls mapped|2 target controls covered
24%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
4 source controls mapped|2 target controls covered
24%
ISO 27017
4 source controls mapped|4 target controls covered
24%
ISO/IEC 27011:2024
4 source controls mapped|4 target controls covered
24%
ASD Strategies to Mitigate Cyber Security Incidents
4 source controls mapped|3 target controls covered
24%
ISO 27799
4 source controls mapped|4 target controls covered
24%
Singapore Government Instruction Manual on ICT&SS Management (IM8)
4 source controls mapped|3 target controls covered
24%
ISO 13485
4 source controls mapped|4 target controls covered
24%
NIST SP 800-190
4 source controls mapped|4 target controls covered
24%
ISO 27018
4 source controls mapped|4 target controls covered
24%
SSAE 18 - Attestation Standards (SOC Reporting)
3 source controls mapped|4 target controls covered
18%
South Korea ISMS-P
3 source controls mapped|4 target controls covered
18%
SOC 2
3 source controls mapped|5 target controls covered
18%
UNESCO Recommendation on the Ethics of AI
3 source controls mapped|1 target controls covered
18%
TEFCA - Trusted Exchange Framework and Common Agreement
3 source controls mapped|1 target controls covered
18%
ISO 26000:2010
3 source controls mapped|1 target controls covered
18%
Telecommunications Sector Security Reforms (TSSR)
3 source controls mapped|1 target controls covered
18%
Nebraska Data Privacy Act
3 source controls mapped|2 target controls covered
18%
18%
US Consumer Product Safety Commission (CPSC) - Connected Product Safety
3 source controls mapped|1 target controls covered
18%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
3 source controls mapped|1 target controls covered
18%
ITU-T X.805 - Security Architecture for End-to-End Communications
2 source controls mapped|1 target controls covered
12%
APPI
2 source controls mapped|3 target controls covered
12%
Armenia Law on Protection of Personal Data (2015)
2 source controls mapped|3 target controls covered
12%
MARS-E - Minimum Acceptable Risk Standards for Exchanges
2 source controls mapped|1 target controls covered
12%
SASB Standards
2 source controls mapped|2 target controls covered
12%
AICPA Privacy Management Framework (PMF)
2 source controls mapped|3 target controls covered
12%
Australian Privacy Principles (APPs)
2 source controls mapped|3 target controls covered
12%
ISO/IEC 29100:2024
2 source controls mapped|3 target controls covered
12%
Azure Security Benchmark
2 source controls mapped|1 target controls covered
12%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
2 source controls mapped|1 target controls covered
12%
Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019)
2 source controls mapped|1 target controls covered
12%
COSO Internal Control - Integrated Framework (2013)
2 source controls mapped|1 target controls covered
12%
ISO/IEC 29134:2023
2 source controls mapped|1 target controls covered
12%
WHO Global Strategy on Digital Health 2020-2025
2 source controls mapped|1 target controls covered
12%
Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)
2 source controls mapped|1 target controls covered
12%
UK Open Banking Standard
2 source controls mapped|1 target controls covered
12%
ISO/IEC 38500:2024 - Governance of IT
2 source controls mapped|1 target controls covered
12%
UK Data Protection Act 2018
2 source controls mapped|3 target controls covered
12%
NIST SP 800-53 Rev 5
2 source controls mapped|4 target controls covered
12%
US Automated Commercial Environment (ACE) - CBP Trade Data Requirements
2 source controls mapped|2 target controls covered
12%
US OFAC Sanctions Compliance Framework
1 source controls mapped|4 target controls covered
6%
Singapore Payment Services Act (PSA) - Digital Payment Token Regulation
1 source controls mapped|1 target controls covered
6%
UAE Virtual Asset Regulatory Authority (VARA) Regulations
1 source controls mapped|1 target controls covered
6%
ISO/IEC 29147:2018
1 source controls mapped|1 target controls covered
6%
IAIS Insurance Core Principles (ICPs)
1 source controls mapped|1 target controls covered
6%
NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity
1 source controls mapped|1 target controls covered
6%
Security of Critical Infrastructure Act 2018 (SOCI)
1 source controls mapped|1 target controls covered
6%
ISO 22739:2024 - Blockchain and Distributed Ledger Technologies Vocabulary
1 source controls mapped|3 target controls covered
6%
BSI IT-Grundschutz
1 source controls mapped|1 target controls covered
6%
TISAX - Trusted Information Security Assessment Exchange
1 source controls mapped|1 target controls covered
6%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
1 source controls mapped|1 target controls covered
6%
Authorised Economic Operator (AEO) Programmes - Global Standards
1 source controls mapped|1 target controls covered
6%
ISO/SAE 21434
1 source controls mapped|1 target controls covered
6%
Samoa Telecommunications Act (2005) - Privacy & Data Protection
1 source controls mapped|2 target controls covered
6%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
1 source controls mapped|1 target controls covered
6%
3GPP 5G Security Architecture (TS 33.501)
1 source controls mapped|2 target controls covered
6%
6%
ISO 27043
1 source controls mapped|1 target controls covered
6%
FFIEC Cybersecurity Assessment Tool (CAT)
1 source controls mapped|1 target controls covered
6%
IEC 62351 - Power Systems Communication Security
1 source controls mapped|1 target controls covered
6%
NIST Cybersecurity Framework 2.0
1 source controls mapped|1 target controls covered
6%
UK Telecommunications (Security) Act 2021
1 source controls mapped|1 target controls covered
6%

What is Uganda Data Protection and Privacy Act (2019) and who does it apply to?

Uganda Data Protection and Privacy Act (2019) is a compliance framework from Uganda with 10 domains and 17 controls. The Uganda Data Protection and Privacy Act, 2019 regulates the collection, processing, and storage of personal data in Uganda. It establishes the Personal Data Protection Office, defines data subject rights, sets obligations for data controllers and processors, and provides for cross-border data transfer restrictions. Applies to all persons who collect, process, hold, or use personal data within Uganda. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does Uganda Data Protection and Privacy Act (2019) actually require?

Uganda Data Protection and Privacy Act (2019) has 17 controls organised across 10 domains. The largest domains are Data Protection Principles (3 controls), Offences and Enforcement (3 controls), Consent and Children (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of Uganda Data Protection and Privacy Act (2019) do I already cover?

Uganda Data Protection and Privacy Act (2019) maps to 83 other compliance frameworks. The top mapping partners are ISO/IEC 27400:2022 (35% coverage), Virginia CDPA (29% coverage), Uruguay DPL (29% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement Uganda Data Protection and Privacy Act (2019)?

Start your Uganda Data Protection and Privacy Act (2019) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Uganda Data Protection and Privacy Act (2019) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 17 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required