[codicts-css-switcher id=”346″]

Global Law Experts Logo
how to conduct a DPIA in Uganda

How to Conduct a DPIA in Uganda: Step‑by‑step for TMT, Platforms & Large‑scale Processing

By Global Law Experts
– posted 46 minutes ago

Understanding how to conduct a DPIA in Uganda is now an operational priority for every technology, media and telecommunications (TMT) business that collects or processes personal data at scale. The Data Protection and Privacy Act, 2019 and the Data Protection and Privacy Regulations, 2021 require data controllers to carry out a Data Protection Impact Assessment before any processing that is likely to result in high risk to the rights and freedoms of data subjects. With Uganda’s Personal Data Protection Office (PDPO) accelerating enforcement readiness through toolkit launches and sector‑specific training programmes during 2024–2026, the obligation has shifted from aspirational best practice to an immediate compliance trigger, particularly for platforms deploying AI features, large‑scale profiling systems and cross‑border data transfers.

Overview of the DPIA Process and Who It Applies To

A Data Protection Impact Assessment is a structured risk‑analysis exercise designed to identify, evaluate and mitigate the privacy risks of a proposed data‑processing activity before it begins. Under the Data Protection and Privacy Act, 2019, the obligation sits primarily with the data controller, the entity that determines the purpose and means of processing. Where a data processor is involved, that processor must provide whatever information the controller reasonably needs to complete the assessment.

The Data Protection Officer (DPO), where one has been appointed, plays an advisory role: reviewing the screening decision, validating the methodology and monitoring implementation of the mitigation measures that the DPIA produces. The PDPO’s guidance notes emphasise that many controllers, particularly those whose core activities involve processing special categories of personal data or systematic monitoring, are expected to designate a DPO and to involve that officer in every DPIA cycle.

For TMT companies operating in Uganda, the practical triggers are familiar: launching a new mobile‑money product, rolling out a biometric identity‑verification feature, deploying algorithmic content‑recommendation systems, or transferring customer data sets to servers outside East Africa. Telecoms operators, fintech platforms, health‑tech providers and any entity processing children’s data at scale should treat a DPIA in Uganda as a pre‑condition of product release, not a post‑launch audit.

Eligibility and Prerequisites: The DPIA Screening Checklist

Not every processing activity demands a full DPIA. The first task is to run a structured screening exercise that maps the DPIA requirements under Uganda law to the facts of the proposed processing. The Data Protection and Privacy Regulations, 2021 and the PDPO’s registration and classification guidance notes set out the criteria. A DPIA is required where the processing is likely to result in high risk, taking into account the nature, scope, context and purpose of the processing.

Industry observers expect the PDPO to continue aligning its screening criteria with international standards, in particular the nine‑criteria framework used by European regulators, while tailoring thresholds to the Ugandan market. The practical screening test below reflects the statutory position and the PDPO’s published guidance.

Screening Checklist for TMT and Platform Operators

Answer each question below. If you answer “yes” to any two or more, a DPIA should be conducted before processing begins.

Screening Question Yes / No
Does the processing involve systematic evaluation or scoring of individuals (e.g., credit scoring, algorithmic profiling)?
Does the processing involve automated decision‑making with legal or similarly significant effects?
Does the processing involve systematic monitoring of a publicly accessible area (e.g., CCTV, location tracking)?
Does the processing involve special categories of data (health, biometric, genetic, political opinion, sexual orientation)?
Is personal data processed on a large scale (high volume of data subjects or data records)?
Does the processing involve matching or combining data sets from multiple sources?
Does the processing involve personal data of vulnerable individuals, including children?
Does the processing involve the use of new or innovative technology (AI, machine learning, IoT)?
Does the processing involve cross‑border transfers of personal data outside Uganda?

Where the screening result is borderline, the safest course is to proceed with the full assessment. A completed screening record, whether or not a full DPIA follows, must be retained as evidence of compliance and made available to the PDPO upon request.

How to Conduct a DPIA in Uganda: The Step‑by‑Step Procedure

The data protection impact assessment procedure below follows the methodology endorsed by the UK Information Commissioner’s Office (ICO) and adapted to Uganda’s statutory framework. Each step produces a defined deliverable and a clear sign‑off point.

Step 0, Conduct Initial Screening and Record the Decision (1–3 Days)

Using the screening checklist above, the product owner (or project lead) completes the threshold test and circulates the result to Legal and the DPO. The output is a short screening decision memo that records which criteria were triggered, the date of the decision and the identity of the decision‑maker. If no DPIA is required, file the screening memo and proceed with standard privacy‑by‑design controls. If the threshold is met, open a formal DPIA project file and move to Step 1.

Step 1, Establish Context, Scope and Lawful Basis (3–7 Days)

The controller must describe how and why it plans to use the personal data. The project description should state the nature, scope, context and purposes of the processing, exactly the language the Data Protection and Privacy Act, 2019 requires. At this stage the team should identify the lawful basis for each processing operation (consent, contractual necessity, legal obligation, legitimate interest or other statutory ground), catalogue the categories of personal data involved and estimate the number of data subjects affected. For TMT projects, this step typically involves the product manager drafting a data‑processing specification and Legal reviewing it for completeness.

Step 2, Map Data Flows and Identify Risks (7–14 Days)

Engineering and security teams produce annotated data‑flow diagrams showing how personal data moves from collection through storage, processing, sharing with third parties and eventual deletion. Every point at which data leaves the controller’s direct custody, cloud hosting providers, analytics sub‑processors, international API endpoints, must be mapped. The privacy lead then conducts a risk‑identification exercise, scoring each data‑flow node against likelihood and severity of harm to data subjects. Common risk categories for TMT include unauthorised access, data‑quality degradation through algorithmic inference, excessive retention and uncontrolled cross‑border transfers.

Step 3, Assess Necessity, Proportionality and Design Mitigations (3–7 Days)

For every processing operation, the DPIA must assess whether the processing is necessary and proportionate to the stated purpose. This is the legal core of the assessment. Where the risk score exceeds the controller’s acceptable threshold, the team must design specific mitigation measures, technical controls (encryption, pseudonymisation, access controls), organisational controls (staff training, data‑minimisation policies) and contractual controls (processor agreements with appropriate security terms). Each mitigation is logged in the risk register with an owner, a deadline and a residual‑risk score.

Step 4, Consult Internally and, Where Necessary, with the PDPO (7–30 Days)

The DPO must be consulted and must record an independent opinion on whether the proposed mitigations are sufficient. Where third‑party processors or joint controllers are involved, consultation with those parties is also required. If, after all proposed mitigations, the residual risk remains high, the controller should consult the PDPO before proceeding. The PDPO’s response timeline is not fixed by statute, and early indications suggest consultations may take 7 to 30 days depending on complexity. Initiating contact early in the project timeline is strongly advisable.

Step 5, Document, Approve and Publish the DPIA Report (1–3 Days)

The DPIA report consolidates the outputs of Steps 0–4 into a single document. It must include: the processing description, the necessity and proportionality assessment, the risk register with mitigation measures, the DPO’s opinion and the sign‑off of senior management. The report should be reviewed by legal counsel before sign‑off. Where PDPO guidance or good practice requires publication of a summary, the communications team prepares a plain‑language extract for external stakeholders.

Step 6, Implement Mitigations and Establish a Review Cycle (Ongoing)

A DPIA is not a one‑off exercise. Engineering and security teams must implement all agreed mitigations before the processing goes live. The DPO then establishes a formal review cycle, at minimum every 6 to 12 months, or immediately upon any significant change to the processing scope, technology stack or regulatory environment. For platforms and telecoms, where product iterations are frequent, a rolling review triggered by material feature releases is the likely practical approach.

DPIA Timeline Summary

Step Who Does It Typical Duration
Screening (initial threshold test) Product owner / Legal / DPO 1–3 days
Scoping & context Product owner / Legal / DPO / Security 3–7 days
Data flow mapping & technical review Engineering / Security / Privacy lead 7–14 days
Risk assessment & mitigation design Privacy lead / Security / Legal 3–7 days
Consultation (internal & external) DPO / Legal / Third‑party vendors / PDPO if required 7–30 days
Sign‑off & publication of summary Senior management / DPO / Legal 1–3 days
Implementation & monitoring Engineering / Security / DPO Ongoing; formal review every 6–12 months

Documents Needed for a DPIA in Uganda

Assembling the right documentation before and during the data protection impact assessment procedure saves time and reduces the risk of regulatory challenge. The table below lists the documents needed for a DPIA under Ugandan law and good practice, along with who is responsible for producing each one.

Document Notes
DPIA report (final) Lawyer‑reviewed PDF or Word document containing purpose, scope, methodology, risk register, mitigation plan and sign‑offs from DPO and Head of Product. Required for internal records and PDPO audits.
Project description / business case Prepared by the product owner or project team. Describes objectives, data types, volumes and affected data subjects.
Data flow map / system architecture Produced by Engineering and Security. Annotated diagrams showing collection points, storage, processing, third‑party endpoints and retention periods.
Risk register & mitigation log Maintained by the privacy lead and Security. Includes risk scoring, residual risk levels, mitigation owners and implementation deadlines.
Lawful basis memo or records of consent Prepared by Legal / Compliance. Documents the statutory ground for each processing operation and, where consent is relied upon, the consent‑collection mechanism and storage reference.
DPO appointment letter Issued by HR / Legal. Scanned copy showing DPO contact details and scope of appointment. The PDPO expects a designated DPO for controllers whose core activities involve special categories of data.
Vendor / processor agreements & SCCs Prepared by Legal. Signed contracts setting out processor obligations, security requirements and, where relevant, standard contractual clauses for cross‑border transfers.
PDPO registration certificate / PRN payment proof Obtained via the PDPO portal. Controllers must register with the PDPO and pay the prescribed fee before processing; retain the registration certificate and URA PRN payment receipt.
Technical test evidence Security or third‑party provider. Penetration test summaries, vulnerability assessments or security‑audit executive summaries (redacted as necessary).
Communications plan & DPIA summary Prepared by Communications / Legal. A short, plain‑language summary of the DPIA findings for stakeholders, published where required by the PDPO or as a matter of good practice.

Each document should be version‑controlled and stored in a central compliance repository. The PDPO may request access to any of these records during an audit or investigation, so maintaining a complete, up‑to‑date file is essential. Where the controller uses the PDPO’s registration portal and Form 2 (Application for Registration / Renewal of Registration), the DPIA file should cross‑reference the registration number and any correspondence with the PDPO.

DPIA Timeline and Key Deadlines

No single statutory provision in Uganda prescribes a fixed number of days within which a DPIA must be completed. The overriding requirement is that the assessment must be finished before the relevant processing begins. For TMT product teams, this means the DPIA timeline must be embedded in the product‑development lifecycle, ideally starting at the design‑specification stage.

Based on the step durations in the timeline table above, a straightforward DPIA for a single‑product feature with limited cross‑border exposure can be completed within 3 to 5 weeks. Complex assessments, involving multiple data processors, AI‑based profiling, or transfers to jurisdictions without adequacy findings, may take 8 to 12 weeks, particularly if PDPO consultation is required.

Key regulator‑facing deadlines to incorporate into internal planning include the following. Controllers must apply for PDPO registration online and pay the fee of UGX 100,000 via a URA Payment Registration Number (PRN) before commencing processing. PDPO‑registered entities are expected to submit annual compliance reports. For platforms and telecoms, the recommended internal service‑level agreement is: screening within 3 working days of project initiation; full DPIA approved before any development freeze or release gate; and formal DPIA review every 6 months or immediately after a significant product change.

Costs, Fees and Budget Considerations for a DPIA in Uganda

Item Amount / Range Notes
PDPO registration fee (new registration) UGX 100,000 Payable via URA PRN generated through the PDPO portal. Confirm the current fee on the PDPO registration page before payment.
Certified extract of the register UGX 25,000 Payable where a certified extract of the PDPO register is requested, per the PDPO Registration, Classification and Guidance Notes.
External DPIA consultant / lawyer USD 1,000 – 10,000+ Market rates vary by scope, complexity, number of cross‑border transfers and industry. TMT and platform engagements typically fall at the higher end.
Penetration test / security audit USD 2,000 – 20,000+ Depends on scope, number of applications tested and whether an external certification body is engaged.
Internal project staff time Variable Estimate 1–4 person‑weeks of combined effort from Legal, Security, Engineering and the DPO, depending on complexity.

Budgeting for the DPIA should be treated as a project cost embedded in the product‑development budget, not an ad hoc compliance expense. Early investment in a thorough assessment reduces the risk of costly remediation, enforcement action or reputational damage after launch.

What Changes in 2026: PDPO Enforcement and the DPIA in Uganda

The PDPO has significantly expanded its operational capacity since the launch of the data protection and privacy portal in 2022, supported by partners including the UN Capital Development Fund (UNCDF). During 2024–2026, the PDPO has rolled out a compliance toolkit designed to help organisations meet their obligations under the Act, including guidance specific to conducting DPIAs. Sector‑focused training programmes, several of which have been held in Kampala in 2026, signal that the regulator is moving toward active supervision rather than awareness‑raising alone.

For TMT and platform teams, the likely practical effect is threefold. First, DPIA screening should now be applied to AI‑driven features, algorithmic recommendation engines and large‑scale identity‑verification systems as a matter of course. Second, DPIA templates should be updated to incorporate AI‑specific risk factors, bias, explainability, automated decision‑making. Third, organisations that have not yet registered with the PDPO or designated a DPO should treat these as immediate priorities, since enforcement activity in 2026 is expected to focus on registration compliance as a gateway to broader audits.

Common Pitfalls When Conducting a DPIA in Uganda

  • Late screening. Initiating the DPIA after development is substantially complete, making meaningful design changes impractical. Responsibility: Product owner. Fix: embed screening at the project‑initiation stage.
  • Weak data‑flow maps. Producing generic diagrams that omit third‑party sub‑processors, cloud‑hosting locations or data‑retention points. Responsibility: Engineering / Security. Fix: require annotated, endpoint‑level diagrams reviewed by the privacy lead.
  • Missing vendor contracts. Failing to execute processor agreements or standard contractual clauses before processing begins. Responsibility: Legal. Fix: make signed processor agreements a gating condition in the procurement workflow.
  • Undocumented mitigations. Agreeing mitigation measures verbally but not logging them in the risk register with owners and deadlines. Responsibility: Privacy lead. Fix: maintain a version‑controlled risk register as part of the DPIA file.
  • Ignoring the DPO role. Treating the DPO as a post‑hoc reviewer rather than an active participant throughout the assessment. Responsibility: Senior management. Fix: involve the DPO from the screening stage and require a recorded opinion.
  • Failing to update the DPIA. Treating the assessment as a one‑off document rather than a living record that must be refreshed when the processing changes. Responsibility: DPO. Fix: schedule formal reviews every 6–12 months or upon material product changes.
  • Poor public summary. Publishing an unintelligible or overly legalistic summary that fails to inform data subjects. Responsibility: Communications / Legal. Fix: draft a plain‑language summary reviewed by a non‑specialist before publication.
  • Misclassifying the lawful basis. Selecting consent as the lawful basis when the controller cannot demonstrate that consent is freely given, specific and informed. Responsibility: Legal / Compliance. Fix: conduct a lawful‑basis assessment before the DPIA, not as part of it.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Brian Kalule at Af Mpanga Advocates, a member of the Global Law Experts network.

Sources

  1. Personal Data Protection Office (PDPO), Registration Portal
  2. Data Protection and Privacy Act, 2019, Uganda Legal Information Institute (ULII)
  3. Data Protection and Privacy Regulations, 2021, Uganda Legal Information Institute (ULII)
  4. PDPO Registration, Classification and Guidance Notes
  5. ICO, How Do We Do a DPIA?
  6. UNCDF, Uganda Launches Data Protection & Privacy Portal

FAQs

How do I conduct a DPIA?
A DPIA is conducted by following a structured sequence: screen the proposed processing against high‑risk criteria; establish the scope and lawful basis; map data flows and identify risks; assess necessity and proportionality; design mitigations; consult the DPO and, where residual risk remains high, the PDPO; document and approve the final report; and implement mitigations with a scheduled review cycle. The methodology draws on the ICO’s established framework, adapted to Uganda’s statutory requirements under the Data Protection and Privacy Act, 2019 and supervised by the PDPO.
Under the Data Protection and Privacy Act, 2019, primary responsibility rests with the data controller, the organisation that determines the purpose and means of processing. The data processor must assist by providing information needed for the assessment. The DPO, where appointed, advises on methodology, reviews findings and monitors implementation, but does not carry out the DPIA as principal. Senior management must approve the final report and allocate resources for implementing the recommended mitigations.
At a minimum, a DPIA must include a systematic description of the proposed processing operations and their purposes; an assessment of the necessity and proportionality of the processing in relation to its purpose; an assessment of the risks to the rights and freedoms of data subjects; and the measures envisaged to address those risks, including safeguards, security measures and mechanisms to demonstrate compliance. In practice, the document should also contain a risk register, a mitigation log with owners and deadlines, the DPO’s written opinion and evidence of any consultation with the PDPO.
The DPIA method is a cyclical risk‑assessment process: screen, scope, map, assess, mitigate, document, review. Each phase produces a defined deliverable, a screening decision, a data‑flow diagram, a risk register, a mitigation plan and a final report, and involves specific stakeholders (product, legal, security, DPO). The method is iterative: if the risk assessment reveals that mitigations are insufficient, the team returns to the design phase. Formal review at regular intervals ensures the DPIA remains current as the processing evolves.
A DPIA prepared under another framework, such as the EU GDPR, can serve as a starting point, but it must be mapped to the specific requirements of the Data Protection and Privacy Act, 2019 and the PDPO’s guidance. Differences in lawful‑basis definitions, cross‑border transfer rules and registration obligations mean that a foreign DPIA will almost certainly need supplementary analysis. The foreign company must also register with the PDPO and, where required, designate a locally accessible DPO.
The Data Protection and Privacy Act, 2019 provides for enforcement action, including fines and criminal penalties, against controllers who process personal data without registration or who fail to comply with their obligations under the Act. Where a DPIA has not been conducted for high‑risk processing, the controller is exposed to regulatory sanction, civil claims from affected data subjects and reputational damage. If a deadline has been missed, the recommended course is to commence registration and the DPIA immediately, document the delay and the remediation steps, and, where the circumstances warrant, notify the PDPO proactively. Engaging specialist legal counsel in Uganda at this stage is strongly advisable.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Conduct a DPIA in Uganda: Step‑by‑step for TMT, Platforms & Large‑scale Processing

Send welcome message

Custom Message