Skip to content

Evidence request lists

Uganda Data Protection and Privacy Act (2019)

Evidence request list. 17 controls, 17 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Consent and Children

UGA-8
Consent Requirements

Conditions for obtaining valid consent to collect or process personal data

Artefacts an auditor will ask for
  • Sensitive personal data processing justification documentation
  • Cross-border transfer impact assessments for non-Uganda recipients
  • Personal Data Protection Office registration evidence
  • Data Protection Officer appointment letter and responsibilities
  • Consent capture and withdrawal logs for data subjects
Where this commonly fails
  • DPO appointment not registered with Personal Data Protection Office
  • Sensitive personal data processed without explicit lawful basis
  • Children's data processing lacks verifiable parental consent
  • Cross-border transfer safeguards absent for cloud service providers
  • Breach notification timelines not operationalised in incident playbooks
UGA-9
Children's Data (Section on minors)

Special protections for personal data relating to children

Artefacts an auditor will ask for
  • Consent capture and withdrawal logs for data subjects
  • Records of processing activities maintained per Section requirements
  • Sensitive personal data processing justification documentation
  • Cross-border transfer impact assessments for non-Uganda recipients
Where this commonly fails
  • Sensitive personal data processed without explicit lawful basis
  • Children's data processing lacks verifiable parental consent
  • Cross-border transfer safeguards absent for cloud service providers
  • Breach notification timelines not operationalised in incident playbooks

Data Protection Principles

UGA-3
Accountability Principle

Data collectors and processors must be accountable for compliance with data protection principles

Artefacts an auditor will ask for
  • Cross-border transfer impact assessments for non-Uganda recipients
  • Personal Data Protection Office registration evidence
  • Data Protection Officer appointment letter and responsibilities
  • Consent capture and withdrawal logs for data subjects
  • Records of processing activities maintained per Section requirements
  • Sensitive personal data processing justification documentation
Where this commonly fails
  • Cross-border transfer safeguards absent for cloud service providers
  • Breach notification timelines not operationalised in incident playbooks
  • DPO appointment not registered with Personal Data Protection Office
UGA-4
Fairness and Lawfulness

Personal data must be processed fairly and lawfully

Artefacts an auditor will ask for
  • Cross-border transfer impact assessments for non-Uganda recipients
  • Personal Data Protection Office registration evidence
  • Data Protection Officer appointment letter and responsibilities
  • Consent capture and withdrawal logs for data subjects
Where this commonly fails
  • DPO appointment not registered with Personal Data Protection Office
  • Sensitive personal data processed without explicit lawful basis
  • Children's data processing lacks verifiable parental consent
  • Cross-border transfer safeguards absent for cloud service providers
  • Breach notification timelines not operationalised in incident playbooks
UGA-5
Purpose Limitation and Minimization

Data collected only for specific, explicitly defined, and legitimate purposes

Artefacts an auditor will ask for
  • Sensitive personal data processing justification documentation
  • Cross-border transfer impact assessments for non-Uganda recipients
  • Personal Data Protection Office registration evidence
  • Data Protection Officer appointment letter and responsibilities
  • Consent capture and withdrawal logs for data subjects
Where this commonly fails
  • Breach notification timelines not operationalised in incident playbooks
  • DPO appointment not registered with Personal Data Protection Office
  • Sensitive personal data processed without explicit lawful basis
  • Children's data processing lacks verifiable parental consent

Data Subject Rights

UGA-12
Rights of Data Subjects

Rights including access, correction, deletion, and objection to processing

Artefacts an auditor will ask for
  • Sensitive personal data processing justification documentation
  • Cross-border transfer impact assessments for non-Uganda recipients
  • Personal Data Protection Office registration evidence
  • Data Protection Officer appointment letter and responsibilities
  • Consent capture and withdrawal logs for data subjects
  • Records of processing activities maintained per Section requirements
Where this commonly fails
  • Cross-border transfer safeguards absent for cloud service providers
  • Breach notification timelines not operationalised in incident playbooks
  • DPO appointment not registered with Personal Data Protection Office

Governance

UGANDA-4
DPO, Governance, Breach

Per Uganda DPPA: DPO + PDPO (Personal Data Protection Office) + breach + enforcement.

Artefacts an auditor will ask for
  • Uganda evidence for UGANDA-4
Where this commonly fails
  • PDPO + registration partial

Offences and Enforcement

UGA-13
Unlawful Obtaining or Disclosure

Criminal sanctions for unlawful obtaining or disclosing of personal data

Artefacts an auditor will ask for
  • Records of processing activities maintained per Section requirements
  • Sensitive personal data processing justification documentation
  • Cross-border transfer impact assessments for non-Uganda recipients
  • Personal Data Protection Office registration evidence
  • Data Protection Officer appointment letter and responsibilities
Where this commonly fails
  • Children's data processing lacks verifiable parental consent
  • Cross-border transfer safeguards absent for cloud service providers
  • Breach notification timelines not operationalised in incident playbooks
  • DPO appointment not registered with Personal Data Protection Office
  • Sensitive personal data processed without explicit lawful basis
UGA-14
Unlawful Destruction or Alteration

Offenses for unlawful destruction, deletion, concealment, or alteration of data

Artefacts an auditor will ask for
  • Cross-border transfer impact assessments for non-Uganda recipients
  • Personal Data Protection Office registration evidence
  • Data Protection Officer appointment letter and responsibilities
  • Consent capture and withdrawal logs for data subjects
  • Records of processing activities maintained per Section requirements
  • Sensitive personal data processing justification documentation
Where this commonly fails
  • Breach notification timelines not operationalised in incident playbooks
  • DPO appointment not registered with Personal Data Protection Office
  • Sensitive personal data processed without explicit lawful basis
  • Children's data processing lacks verifiable parental consent
  • Cross-border transfer safeguards absent for cloud service providers
UGA-15
Unauthorized Sale of Data

Criminal penalties for the unauthorized sale of personal data

Artefacts an auditor will ask for
  • Personal Data Protection Office registration evidence
  • Data Protection Officer appointment letter and responsibilities
  • Consent capture and withdrawal logs for data subjects
Where this commonly fails
  • Breach notification timelines not operationalised in incident playbooks
  • DPO appointment not registered with Personal Data Protection Office
  • Sensitive personal data processed without explicit lawful basis
  • Children's data processing lacks verifiable parental consent

Regulator and Data Protection Officer

UGA-6
Personal Data Protection Office

Establishment and functions of the Personal Data Protection Office

Artefacts an auditor will ask for
  • Sensitive personal data processing justification documentation
  • Cross-border transfer impact assessments for non-Uganda recipients
  • Personal Data Protection Office registration evidence
Where this commonly fails
  • Sensitive personal data processed without explicit lawful basis
  • Children's data processing lacks verifiable parental consent
  • Cross-border transfer safeguards absent for cloud service providers
UGA-7
Data Protection Officer

Requirement for organizations to designate a Data Protection Officer

Artefacts an auditor will ask for
  • Cross-border transfer impact assessments for non-Uganda recipients
  • Personal Data Protection Office registration evidence
  • Data Protection Officer appointment letter and responsibilities
Where this commonly fails
  • Breach notification timelines not operationalised in incident playbooks
  • DPO appointment not registered with Personal Data Protection Office
  • Sensitive personal data processed without explicit lawful basis
  • Children's data processing lacks verifiable parental consent

Rights

UGANDA-2
Consent, Notice, Rights

Per Uganda DPPA: Consent + Privacy Notice + Data Subject Rights Fulfilment.

Artefacts an auditor will ask for
  • Uganda evidence for UGANDA-2
Where this commonly fails
  • PDPO + registration partial

Scope

UGANDA-1
Registration, Scope, Lawful Basis

Per Uganda DPPA 2019: Registration of Data Collectors + Processors and Controllers + Lawful Basis for Processing.

Artefacts an auditor will ask for
  • Uganda evidence for UGANDA-1
Where this commonly fails
  • PDPO + registration partial

Security

UGANDA-3
Security and Cross-Border

Per Uganda DPPA: security measures + cross-border restrictions.

Artefacts an auditor will ask for
  • Uganda evidence for UGANDA-3
Where this commonly fails
  • PDPO + registration partial

Sensitive Data and Privacy Protection

UGA-10
Sensitive Personal Data Prohibition

Prohibition on collection and processing of special personal data without authorization

Artefacts an auditor will ask for
  • Sensitive personal data processing justification documentation
  • Cross-border transfer impact assessments for non-Uganda recipients
  • Personal Data Protection Office registration evidence
  • Data Protection Officer appointment letter and responsibilities
  • Consent capture and withdrawal logs for data subjects
Where this commonly fails
  • Children's data processing lacks verifiable parental consent
  • Cross-border transfer safeguards absent for cloud service providers
  • Breach notification timelines not operationalised in incident playbooks
  • DPO appointment not registered with Personal Data Protection Office
UGA-11
Protection of Privacy

General provisions ensuring the protection of individuals' privacy rights

Artefacts an auditor will ask for
  • Data Protection Officer appointment letter and responsibilities
  • Consent capture and withdrawal logs for data subjects
  • Records of processing activities maintained per Section requirements
  • Sensitive personal data processing justification documentation
Where this commonly fails
  • Breach notification timelines not operationalised in incident playbooks
  • DPO appointment not registered with Personal Data Protection Office
  • Sensitive personal data processed without explicit lawful basis
  • Children's data processing lacks verifiable parental consent
  • Cross-border transfer safeguards absent for cloud service providers
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Uganda Data Protection and Privacy Act (2019) framework page.