Uganda Data Protection and Privacy Act (2019)
Evidence request list. 17 controls, 17 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Consent and Children
Conditions for obtaining valid consent to collect or process personal data
- Sensitive personal data processing justification documentation
- Cross-border transfer impact assessments for non-Uganda recipients
- Personal Data Protection Office registration evidence
- Data Protection Officer appointment letter and responsibilities
- Consent capture and withdrawal logs for data subjects
- DPO appointment not registered with Personal Data Protection Office
- Sensitive personal data processed without explicit lawful basis
- Children's data processing lacks verifiable parental consent
- Cross-border transfer safeguards absent for cloud service providers
- Breach notification timelines not operationalised in incident playbooks
Special protections for personal data relating to children
- Consent capture and withdrawal logs for data subjects
- Records of processing activities maintained per Section requirements
- Sensitive personal data processing justification documentation
- Cross-border transfer impact assessments for non-Uganda recipients
- Sensitive personal data processed without explicit lawful basis
- Children's data processing lacks verifiable parental consent
- Cross-border transfer safeguards absent for cloud service providers
- Breach notification timelines not operationalised in incident playbooks
Data Protection Principles
Data collectors and processors must be accountable for compliance with data protection principles
- Cross-border transfer impact assessments for non-Uganda recipients
- Personal Data Protection Office registration evidence
- Data Protection Officer appointment letter and responsibilities
- Consent capture and withdrawal logs for data subjects
- Records of processing activities maintained per Section requirements
- Sensitive personal data processing justification documentation
- Cross-border transfer safeguards absent for cloud service providers
- Breach notification timelines not operationalised in incident playbooks
- DPO appointment not registered with Personal Data Protection Office
Personal data must be processed fairly and lawfully
- Cross-border transfer impact assessments for non-Uganda recipients
- Personal Data Protection Office registration evidence
- Data Protection Officer appointment letter and responsibilities
- Consent capture and withdrawal logs for data subjects
- DPO appointment not registered with Personal Data Protection Office
- Sensitive personal data processed without explicit lawful basis
- Children's data processing lacks verifiable parental consent
- Cross-border transfer safeguards absent for cloud service providers
- Breach notification timelines not operationalised in incident playbooks
Data collected only for specific, explicitly defined, and legitimate purposes
- Sensitive personal data processing justification documentation
- Cross-border transfer impact assessments for non-Uganda recipients
- Personal Data Protection Office registration evidence
- Data Protection Officer appointment letter and responsibilities
- Consent capture and withdrawal logs for data subjects
- Breach notification timelines not operationalised in incident playbooks
- DPO appointment not registered with Personal Data Protection Office
- Sensitive personal data processed without explicit lawful basis
- Children's data processing lacks verifiable parental consent
Data Subject Rights
Rights including access, correction, deletion, and objection to processing
- Sensitive personal data processing justification documentation
- Cross-border transfer impact assessments for non-Uganda recipients
- Personal Data Protection Office registration evidence
- Data Protection Officer appointment letter and responsibilities
- Consent capture and withdrawal logs for data subjects
- Records of processing activities maintained per Section requirements
- Cross-border transfer safeguards absent for cloud service providers
- Breach notification timelines not operationalised in incident playbooks
- DPO appointment not registered with Personal Data Protection Office
Governance
Per Uganda DPPA: DPO + PDPO (Personal Data Protection Office) + breach + enforcement.
- Uganda evidence for UGANDA-4
- PDPO + registration partial
Offences and Enforcement
Criminal sanctions for unlawful obtaining or disclosing of personal data
- Records of processing activities maintained per Section requirements
- Sensitive personal data processing justification documentation
- Cross-border transfer impact assessments for non-Uganda recipients
- Personal Data Protection Office registration evidence
- Data Protection Officer appointment letter and responsibilities
- Children's data processing lacks verifiable parental consent
- Cross-border transfer safeguards absent for cloud service providers
- Breach notification timelines not operationalised in incident playbooks
- DPO appointment not registered with Personal Data Protection Office
- Sensitive personal data processed without explicit lawful basis
Offenses for unlawful destruction, deletion, concealment, or alteration of data
- Cross-border transfer impact assessments for non-Uganda recipients
- Personal Data Protection Office registration evidence
- Data Protection Officer appointment letter and responsibilities
- Consent capture and withdrawal logs for data subjects
- Records of processing activities maintained per Section requirements
- Sensitive personal data processing justification documentation
- Breach notification timelines not operationalised in incident playbooks
- DPO appointment not registered with Personal Data Protection Office
- Sensitive personal data processed without explicit lawful basis
- Children's data processing lacks verifiable parental consent
- Cross-border transfer safeguards absent for cloud service providers
Criminal penalties for the unauthorized sale of personal data
- Personal Data Protection Office registration evidence
- Data Protection Officer appointment letter and responsibilities
- Consent capture and withdrawal logs for data subjects
- Breach notification timelines not operationalised in incident playbooks
- DPO appointment not registered with Personal Data Protection Office
- Sensitive personal data processed without explicit lawful basis
- Children's data processing lacks verifiable parental consent
Regulator and Data Protection Officer
Establishment and functions of the Personal Data Protection Office
- Sensitive personal data processing justification documentation
- Cross-border transfer impact assessments for non-Uganda recipients
- Personal Data Protection Office registration evidence
- Sensitive personal data processed without explicit lawful basis
- Children's data processing lacks verifiable parental consent
- Cross-border transfer safeguards absent for cloud service providers
Requirement for organizations to designate a Data Protection Officer
- Cross-border transfer impact assessments for non-Uganda recipients
- Personal Data Protection Office registration evidence
- Data Protection Officer appointment letter and responsibilities
- Breach notification timelines not operationalised in incident playbooks
- DPO appointment not registered with Personal Data Protection Office
- Sensitive personal data processed without explicit lawful basis
- Children's data processing lacks verifiable parental consent
Rights
Per Uganda DPPA: Consent + Privacy Notice + Data Subject Rights Fulfilment.
- Uganda evidence for UGANDA-2
- PDPO + registration partial
Scope
Per Uganda DPPA 2019: Registration of Data Collectors + Processors and Controllers + Lawful Basis for Processing.
- Uganda evidence for UGANDA-1
- PDPO + registration partial
Security
Per Uganda DPPA: security measures + cross-border restrictions.
- Uganda evidence for UGANDA-3
- PDPO + registration partial
Sensitive Data and Privacy Protection
Prohibition on collection and processing of special personal data without authorization
- Sensitive personal data processing justification documentation
- Cross-border transfer impact assessments for non-Uganda recipients
- Personal Data Protection Office registration evidence
- Data Protection Officer appointment letter and responsibilities
- Consent capture and withdrawal logs for data subjects
- Children's data processing lacks verifiable parental consent
- Cross-border transfer safeguards absent for cloud service providers
- Breach notification timelines not operationalised in incident playbooks
- DPO appointment not registered with Personal Data Protection Office
General provisions ensuring the protection of individuals' privacy rights
- Data Protection Officer appointment letter and responsibilities
- Consent capture and withdrawal logs for data subjects
- Records of processing activities maintained per Section requirements
- Sensitive personal data processing justification documentation
- Breach notification timelines not operationalised in incident playbooks
- DPO appointment not registered with Personal Data Protection Office
- Sensitive personal data processed without explicit lawful basis
- Children's data processing lacks verifiable parental consent
- Cross-border transfer safeguards absent for cloud service providers
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Uganda Data Protection and Privacy Act (2019) framework page.