Our Expert in Uganda
No results available
Understanding how to conduct a DPIA in Uganda is now an operational priority for every technology, media and telecommunications (TMT) business that collects or processes personal data at scale. The Data Protection and Privacy Act, 2019 and the Data Protection and Privacy Regulations, 2021 require data controllers to carry out a Data Protection Impact Assessment before any processing that is likely to result in high risk to the rights and freedoms of data subjects. With Uganda’s Personal Data Protection Office (PDPO) accelerating enforcement readiness through toolkit launches and sector‑specific training programmes during 2024–2026, the obligation has shifted from aspirational best practice to an immediate compliance trigger, particularly for platforms deploying AI features, large‑scale profiling systems and cross‑border data transfers.
A Data Protection Impact Assessment is a structured risk‑analysis exercise designed to identify, evaluate and mitigate the privacy risks of a proposed data‑processing activity before it begins. Under the Data Protection and Privacy Act, 2019, the obligation sits primarily with the data controller, the entity that determines the purpose and means of processing. Where a data processor is involved, that processor must provide whatever information the controller reasonably needs to complete the assessment.
The Data Protection Officer (DPO), where one has been appointed, plays an advisory role: reviewing the screening decision, validating the methodology and monitoring implementation of the mitigation measures that the DPIA produces. The PDPO’s guidance notes emphasise that many controllers, particularly those whose core activities involve processing special categories of personal data or systematic monitoring, are expected to designate a DPO and to involve that officer in every DPIA cycle.
For TMT companies operating in Uganda, the practical triggers are familiar: launching a new mobile‑money product, rolling out a biometric identity‑verification feature, deploying algorithmic content‑recommendation systems, or transferring customer data sets to servers outside East Africa. Telecoms operators, fintech platforms, health‑tech providers and any entity processing children’s data at scale should treat a DPIA in Uganda as a pre‑condition of product release, not a post‑launch audit.
Not every processing activity demands a full DPIA. The first task is to run a structured screening exercise that maps the DPIA requirements under Uganda law to the facts of the proposed processing. The Data Protection and Privacy Regulations, 2021 and the PDPO’s registration and classification guidance notes set out the criteria. A DPIA is required where the processing is likely to result in high risk, taking into account the nature, scope, context and purpose of the processing.
Industry observers expect the PDPO to continue aligning its screening criteria with international standards, in particular the nine‑criteria framework used by European regulators, while tailoring thresholds to the Ugandan market. The practical screening test below reflects the statutory position and the PDPO’s published guidance.
Answer each question below. If you answer “yes” to any two or more, a DPIA should be conducted before processing begins.
| Screening Question | Yes / No |
|---|---|
| Does the processing involve systematic evaluation or scoring of individuals (e.g., credit scoring, algorithmic profiling)? | |
| Does the processing involve automated decision‑making with legal or similarly significant effects? | |
| Does the processing involve systematic monitoring of a publicly accessible area (e.g., CCTV, location tracking)? | |
| Does the processing involve special categories of data (health, biometric, genetic, political opinion, sexual orientation)? | |
| Is personal data processed on a large scale (high volume of data subjects or data records)? | |
| Does the processing involve matching or combining data sets from multiple sources? | |
| Does the processing involve personal data of vulnerable individuals, including children? | |
| Does the processing involve the use of new or innovative technology (AI, machine learning, IoT)? | |
| Does the processing involve cross‑border transfers of personal data outside Uganda? |
Where the screening result is borderline, the safest course is to proceed with the full assessment. A completed screening record, whether or not a full DPIA follows, must be retained as evidence of compliance and made available to the PDPO upon request.
The data protection impact assessment procedure below follows the methodology endorsed by the UK Information Commissioner’s Office (ICO) and adapted to Uganda’s statutory framework. Each step produces a defined deliverable and a clear sign‑off point.
Using the screening checklist above, the product owner (or project lead) completes the threshold test and circulates the result to Legal and the DPO. The output is a short screening decision memo that records which criteria were triggered, the date of the decision and the identity of the decision‑maker. If no DPIA is required, file the screening memo and proceed with standard privacy‑by‑design controls. If the threshold is met, open a formal DPIA project file and move to Step 1.
The controller must describe how and why it plans to use the personal data. The project description should state the nature, scope, context and purposes of the processing, exactly the language the Data Protection and Privacy Act, 2019 requires. At this stage the team should identify the lawful basis for each processing operation (consent, contractual necessity, legal obligation, legitimate interest or other statutory ground), catalogue the categories of personal data involved and estimate the number of data subjects affected. For TMT projects, this step typically involves the product manager drafting a data‑processing specification and Legal reviewing it for completeness.
Engineering and security teams produce annotated data‑flow diagrams showing how personal data moves from collection through storage, processing, sharing with third parties and eventual deletion. Every point at which data leaves the controller’s direct custody, cloud hosting providers, analytics sub‑processors, international API endpoints, must be mapped. The privacy lead then conducts a risk‑identification exercise, scoring each data‑flow node against likelihood and severity of harm to data subjects. Common risk categories for TMT include unauthorised access, data‑quality degradation through algorithmic inference, excessive retention and uncontrolled cross‑border transfers.
For every processing operation, the DPIA must assess whether the processing is necessary and proportionate to the stated purpose. This is the legal core of the assessment. Where the risk score exceeds the controller’s acceptable threshold, the team must design specific mitigation measures, technical controls (encryption, pseudonymisation, access controls), organisational controls (staff training, data‑minimisation policies) and contractual controls (processor agreements with appropriate security terms). Each mitigation is logged in the risk register with an owner, a deadline and a residual‑risk score.
The DPO must be consulted and must record an independent opinion on whether the proposed mitigations are sufficient. Where third‑party processors or joint controllers are involved, consultation with those parties is also required. If, after all proposed mitigations, the residual risk remains high, the controller should consult the PDPO before proceeding. The PDPO’s response timeline is not fixed by statute, and early indications suggest consultations may take 7 to 30 days depending on complexity. Initiating contact early in the project timeline is strongly advisable.
The DPIA report consolidates the outputs of Steps 0–4 into a single document. It must include: the processing description, the necessity and proportionality assessment, the risk register with mitigation measures, the DPO’s opinion and the sign‑off of senior management. The report should be reviewed by legal counsel before sign‑off. Where PDPO guidance or good practice requires publication of a summary, the communications team prepares a plain‑language extract for external stakeholders.
A DPIA is not a one‑off exercise. Engineering and security teams must implement all agreed mitigations before the processing goes live. The DPO then establishes a formal review cycle, at minimum every 6 to 12 months, or immediately upon any significant change to the processing scope, technology stack or regulatory environment. For platforms and telecoms, where product iterations are frequent, a rolling review triggered by material feature releases is the likely practical approach.
| Step | Who Does It | Typical Duration |
|---|---|---|
| Screening (initial threshold test) | Product owner / Legal / DPO | 1–3 days |
| Scoping & context | Product owner / Legal / DPO / Security | 3–7 days |
| Data flow mapping & technical review | Engineering / Security / Privacy lead | 7–14 days |
| Risk assessment & mitigation design | Privacy lead / Security / Legal | 3–7 days |
| Consultation (internal & external) | DPO / Legal / Third‑party vendors / PDPO if required | 7–30 days |
| Sign‑off & publication of summary | Senior management / DPO / Legal | 1–3 days |
| Implementation & monitoring | Engineering / Security / DPO | Ongoing; formal review every 6–12 months |
Assembling the right documentation before and during the data protection impact assessment procedure saves time and reduces the risk of regulatory challenge. The table below lists the documents needed for a DPIA under Ugandan law and good practice, along with who is responsible for producing each one.
| Document | Notes |
|---|---|
| DPIA report (final) | Lawyer‑reviewed PDF or Word document containing purpose, scope, methodology, risk register, mitigation plan and sign‑offs from DPO and Head of Product. Required for internal records and PDPO audits. |
| Project description / business case | Prepared by the product owner or project team. Describes objectives, data types, volumes and affected data subjects. |
| Data flow map / system architecture | Produced by Engineering and Security. Annotated diagrams showing collection points, storage, processing, third‑party endpoints and retention periods. |
| Risk register & mitigation log | Maintained by the privacy lead and Security. Includes risk scoring, residual risk levels, mitigation owners and implementation deadlines. |
| Lawful basis memo or records of consent | Prepared by Legal / Compliance. Documents the statutory ground for each processing operation and, where consent is relied upon, the consent‑collection mechanism and storage reference. |
| DPO appointment letter | Issued by HR / Legal. Scanned copy showing DPO contact details and scope of appointment. The PDPO expects a designated DPO for controllers whose core activities involve special categories of data. |
| Vendor / processor agreements & SCCs | Prepared by Legal. Signed contracts setting out processor obligations, security requirements and, where relevant, standard contractual clauses for cross‑border transfers. |
| PDPO registration certificate / PRN payment proof | Obtained via the PDPO portal. Controllers must register with the PDPO and pay the prescribed fee before processing; retain the registration certificate and URA PRN payment receipt. |
| Technical test evidence | Security or third‑party provider. Penetration test summaries, vulnerability assessments or security‑audit executive summaries (redacted as necessary). |
| Communications plan & DPIA summary | Prepared by Communications / Legal. A short, plain‑language summary of the DPIA findings for stakeholders, published where required by the PDPO or as a matter of good practice. |
Each document should be version‑controlled and stored in a central compliance repository. The PDPO may request access to any of these records during an audit or investigation, so maintaining a complete, up‑to‑date file is essential. Where the controller uses the PDPO’s registration portal and Form 2 (Application for Registration / Renewal of Registration), the DPIA file should cross‑reference the registration number and any correspondence with the PDPO.
No single statutory provision in Uganda prescribes a fixed number of days within which a DPIA must be completed. The overriding requirement is that the assessment must be finished before the relevant processing begins. For TMT product teams, this means the DPIA timeline must be embedded in the product‑development lifecycle, ideally starting at the design‑specification stage.
Based on the step durations in the timeline table above, a straightforward DPIA for a single‑product feature with limited cross‑border exposure can be completed within 3 to 5 weeks. Complex assessments, involving multiple data processors, AI‑based profiling, or transfers to jurisdictions without adequacy findings, may take 8 to 12 weeks, particularly if PDPO consultation is required.
Key regulator‑facing deadlines to incorporate into internal planning include the following. Controllers must apply for PDPO registration online and pay the fee of UGX 100,000 via a URA Payment Registration Number (PRN) before commencing processing. PDPO‑registered entities are expected to submit annual compliance reports. For platforms and telecoms, the recommended internal service‑level agreement is: screening within 3 working days of project initiation; full DPIA approved before any development freeze or release gate; and formal DPIA review every 6 months or immediately after a significant product change.
| Item | Amount / Range | Notes |
|---|---|---|
| PDPO registration fee (new registration) | UGX 100,000 | Payable via URA PRN generated through the PDPO portal. Confirm the current fee on the PDPO registration page before payment. |
| Certified extract of the register | UGX 25,000 | Payable where a certified extract of the PDPO register is requested, per the PDPO Registration, Classification and Guidance Notes. |
| External DPIA consultant / lawyer | USD 1,000 – 10,000+ | Market rates vary by scope, complexity, number of cross‑border transfers and industry. TMT and platform engagements typically fall at the higher end. |
| Penetration test / security audit | USD 2,000 – 20,000+ | Depends on scope, number of applications tested and whether an external certification body is engaged. |
| Internal project staff time | Variable | Estimate 1–4 person‑weeks of combined effort from Legal, Security, Engineering and the DPO, depending on complexity. |
Budgeting for the DPIA should be treated as a project cost embedded in the product‑development budget, not an ad hoc compliance expense. Early investment in a thorough assessment reduces the risk of costly remediation, enforcement action or reputational damage after launch.
The PDPO has significantly expanded its operational capacity since the launch of the data protection and privacy portal in 2022, supported by partners including the UN Capital Development Fund (UNCDF). During 2024–2026, the PDPO has rolled out a compliance toolkit designed to help organisations meet their obligations under the Act, including guidance specific to conducting DPIAs. Sector‑focused training programmes, several of which have been held in Kampala in 2026, signal that the regulator is moving toward active supervision rather than awareness‑raising alone.
For TMT and platform teams, the likely practical effect is threefold. First, DPIA screening should now be applied to AI‑driven features, algorithmic recommendation engines and large‑scale identity‑verification systems as a matter of course. Second, DPIA templates should be updated to incorporate AI‑specific risk factors, bias, explainability, automated decision‑making. Third, organisations that have not yet registered with the PDPO or designated a DPO should treat these as immediate priorities, since enforcement activity in 2026 is expected to focus on registration compliance as a gateway to broader audits.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Brian Kalule at Af Mpanga Advocates, a member of the Global Law Experts network.
posted 3 minutes ago
posted 32 minutes ago
posted 56 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
posted 4 hours ago
posted 5 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message