Uganda Data Protection and Privacy Act (2019)
The Uganda Data Protection and Privacy Act, 2019 regulates the collection, processing, and storage of personal data in Uganda. It establishes the Personal Data Protection Office, defines data subject rights, sets obligations for data controllers and processors, and provides for cross-border data transfer restrictions. Applies to all persons who collect, process, hold, or use personal data within Uganda.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (25)
Awareness
| Code | Title |
|---|---|
| UG-DPPA-21 | Staff Training and Awareness on Data Protection |
Breach Management
| Code | Title |
|---|---|
| UG-DPPA-12 | Personal Data Breach Notification to PDPO and Data Subjects |
Children's Data
| Code | Title |
|---|---|
| UG-DPPA-07 | Children's Personal Data Processing |
Complaints
| Code | Title |
|---|---|
| UG-DPPA-19 | Complaints Handling and Internal Redress |
Consent Management
| Code | Title |
|---|---|
| UG-DPPA-03 | Consent Requirements and Withdrawal Mechanisms |
Data Quality
| Code | Title |
|---|---|
| UG-DPPA-08 | Data Minimisation and Purpose Limitation |
| UG-DPPA-09 | Data Accuracy and Quality Maintenance |
Data Subject Rights
| Code | Title |
|---|---|
| UG-DPPA-05 | Data Subject Rights Fulfilment |
Documentation
| Code | Title |
|---|---|
| UG-DPPA-17 | Records of Processing Activities |
Governance
| Code | Title |
|---|---|
| UG-DPPA-14 | Data Protection Officer Appointment |
International Transfers
| Code | Title |
|---|---|
| UG-DPPA-13 | Cross-Border Transfer Conditions |
Lawful Processing
| Code | Title |
|---|---|
| UG-DPPA-02 | Lawful Basis for Processing Personal Data |
Marketing
| Code | Title |
|---|---|
| UG-DPPA-20 | Direct Marketing Restrictions |
Offenses and Penalties
| Code | Title |
|---|---|
| UGA-13 | Unlawful Obtaining or Disclosure |
| UGA-14 | Unlawful Destruction or Alteration |
| UGA-15 | Unauthorized Sale of Data |
Part I — Preliminary
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Sec. 1 | Short Title and Commencement |
| Sec. 2 | Interpretation |
| Sec. 3 | Scope and Application |
| Sec. 4 | Exemptions |
| UGA-1 | Application |
| UGA-2 | Interpretation |
| ZWE-1 | Objectives (Section 2) |
| ZWE-2 | Definitions (Section 3) |
| ZWE-3 | Application (Section 4) |
Part II — Principles of Data Protection
| Code | Title |
|---|---|
| UGA-3 | Accountability Principle |
| UGA-4 | Fairness and Lawfulness |
| UGA-5 | Purpose Limitation and Minimization |
Part III — Data Collection and Processing
| Code | Title |
|---|---|
| UGA-10 | Sensitive Personal Data Prohibition |
| UGA-6 | Personal Data Protection Office |
| UGA-7 | Data Protection Officer |
| UGA-8 | Consent Requirements |
| UGA-9 | Children's Data (Section on minors) |
Protection of Privacy
| Code | Title |
|---|---|
| UGA-11 | Protection of Privacy |
| UGA-12 | Rights of Data Subjects |
Registration and Notification
| Code | Title |
|---|---|
| UG-DPPA-01 | Registration of Data Collectors, Processors and Controllers with PDPO |
Regulatory Engagement
| Code | Title |
|---|---|
| UG-DPPA-18 | PDPO Inspection and Investigation Cooperation |
Retention
| Code | Title |
|---|---|
| UG-DPPA-10 | Storage Limitation and Retention Schedules |
Risk Management
| Code | Title |
|---|---|
| UG-DPPA-15 | Data Protection Impact Assessments |
Security
| Code | Title |
|---|---|
| UG-DPPA-11 | Security of Processing and Technical Safeguards |
Sensitive Data
| Code | Title |
|---|---|
| UG-DPPA-06 | Special Category Personal Data Safeguards |
Third Party Management
| Code | Title |
|---|---|
| UG-DPPA-16 | Processor Contracts and Oversight |
Transparency
| Code | Title |
|---|---|
| UG-DPPA-04 | Privacy Notice and Transparency Obligations |
Your Compliance Coverage
If you comply with Uganda Data Protection and Privacy Act (2019), you already cover:
Angola Personal Data Protection Law (Law No. 22/11)
28%
13 controls mapped
Compare →FAA Cybersecurity Framework for Aviation
28%
13 controls mapped
Compare →MiFID II / MiFIR
28%
13 controls mapped
Compare →+ 593 more: Australia Consumer Data Right — Banking (CDR) (28%), CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 (28%)
See all 596 mapped frameworks ↓Maps to 596 other frameworks
Frequently Asked Questions
What is Uganda Data Protection and Privacy Act (2019)?
Uganda Data Protection and Privacy Act (2019) is a compliance framework from Uganda with 25 domains and 47 controls. The Uganda Data Protection and Privacy Act, 2019 regulates the collection, processing, and storage of personal data in Uganda. It establishes the Personal Data Protection Office, defines data subject rights, sets obligations for data controllers and processors, and provides for cross-border data transfer restrictions. Applies to all persons who collect, process, hold, or use personal data within Uganda. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Uganda Data Protection and Privacy Act (2019) have?
Uganda Data Protection and Privacy Act (2019) has 47 controls organised across 25 domains. The largest domains are Part I — Preliminary (13 controls), Part III — Data Collection and Processing (5 controls), Offenses and Penalties (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Uganda Data Protection and Privacy Act (2019) map to?
Uganda Data Protection and Privacy Act (2019) maps to 596 other compliance frameworks. The top mapping partners are Angola Personal Data Protection Law (Law No. 22/11) (28% coverage), FAA Cybersecurity Framework for Aviation (28% coverage), MiFID II / MiFIR (28% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Uganda Data Protection and Privacy Act (2019) compliance?
Start your Uganda Data Protection and Privacy Act (2019) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Uganda Data Protection and Privacy Act (2019) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 47 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required