What Is Data Protection and Privacy Act, 2019?
Uganda's Data Protection and Privacy Act 2019 is in force from 3 May 2019, with oversight by the Personal Data Protection Office (PDPO). The supplied sources identify rights to access, qualified correction and deletion, prevention of harmful or direct-marketing processing, and review of certain decisions made solely by automated means. The source review separates two timing rules that should not be merged: the Act's access provision has a 30-day ceiling, while the Data Protection and Privacy Regulations 2021 contain a seven-day decision rule for correction and deletion requests. PDPO complaint routes and escalation timelines are documented in the supplied guidance. This is a bounded evidence profile based on the supplied Ugandan statutory, regulatory, and PDPO sources, not a complete claim-by-claim legal review.
At a glance
- Full name
- Data Protection and Privacy Act, 2019
- Short code
- Uganda DPA 2019
- Jurisdiction
- Uganda
- Enacted
- 2019
- Last major update
- Data Protection and Privacy Regulations 2021 provide a separate seven-day decision rule for correction and deletion requests
- Regulator
- Personal Data Protection Office (PDPO)
- Private right of action
- Limited
- Statutory citation
- Data Protection and Privacy Act, 2019
Scope, who Uganda DPA 2019 covers
Protected data
Data subject rights
Right of access, subject to the Act’s 30-day ceiling identified in the supplied research
Qualified right to correction
Qualified right to deletion, with the Regulations’ seven-day decision rule identified in the supplied research
Right to seek prevention of harmful processing
Right to seek prevention of direct-marketing processing
Right to review of certain decisions made solely by automated means
Right to complain through the PDPO routes and use the documented escalation process
Notable features
The Act’s 30-day access ceiling is distinct from the Regulations’ seven-day decision rule for correction and deletion requests. The PDPO publishes complaint routes and escalation timelines, so those sources should be read alongside the Act rather than collapsed into one universal deadline.
Enforcement & penalties
Regulator: Personal Data Protection Office (PDPO)
Penalties: The supplied summary and sources did not provide a consolidated penalty schedule; no penalty amount or timeline is stated here.
Private right of action: The supplied research documented PDPO complaint and escalation routes but did not establish a separate standalone private damages action. This is an evidence limitation, not a definitive statement about every possible remedy.
Relevance to data brokers
The supplied research summary does not identify a Uganda-specific data-broker, people-search, public-record suppression, or broker-removal route. The general rights and PDPO complaint process are not presented here as a guaranteed broker-specific deletion process.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
When did Uganda’s Data Protection and Privacy Act take effect?+
The supplied source identifies 3 May 2019 as the date from which Uganda’s Data Protection and Privacy Act 2019 is in force.
How do Uganda’s access and correction or deletion timelines differ?+
The supplied research identifies a 30-day ceiling for access under the Act and a separate seven-day decision rule in the 2021 Regulations for correction and deletion requests.
Can I require a Uganda data broker to remove my information?+
The supplied research summary does not identify a Uganda-specific data-broker or people-search removal route. The Act’s general rights and PDPO complaint process should not be treated as a guaranteed broker-specific deletion process.
Official sources & citations
Other international privacy regimes
Uganda DPA 2019 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
