As Uganda undergoes a rapid digital transformation, personal data has become the new currency of modern life, shaping how people access services, communicate, and do business.
Yet, this shift has also exposed citizens to rising privacy risks and data misuse.
To understand how Uganda is safeguarding digital privacy in this evolving landscape, Baker Birikujja, the National Personal Data Protection director, takes us through the progress so far made in enforcing the Data Protection and Privacy Act, the challenges faced, and the future of data protection in Uganda.
What is the mandate of the Personal Data Protection Office?
We are the national regulator for data protection and privacy. We operate independently under the National Information Technology Authority-Uganda (NITA-U) and enforce the Data Protection and Privacy Act and attendant regulations.
Our mandate is to safeguard the right to privacy by monitoring compliance, investigating breaches, reporting on the state of data protection, and maintaining the national register of data collectors, processors, and controllers.
We also handle complaints from individuals whose privacy may have been violated.
How much progress has been made in implementing the law?
The journey has been both challenging and rewarding. Since our establishment, we have made significant strides.
A landmark moment came in July 2025, when Uganda achieved its first conviction under the Data Protection and Privacy Act, proving the law is being actively enforced.
Over the past four years, we have had several milestones on which we have built a stronger culture of stronger accountability in relation to personal data protection.
What key challenges have you faced, and how have you managed them?
Being a young institution, we have faced resource constraints, particularly limited staffing and funding.
Despite that, we have prioritised capacity building, streamlined operations, and adopted digital tools to improve efficiency in areas like registration and complaint handling.
We also work closely with other regulators, civil society, and private sector partners.
These collaborations help us extend our reach and build a stronger national system for data protection.
How are you ensuring compliance in high-data sectors such as telecoms, finance, and healthcare?
We have developed practical tools to guide organisations in complying with the law.
We also hold regional compliance clinics, where our officers work directly with businesses to assess their practices and offer legal guidance. In addition, we conduct audits and inspections of large data handlers.
Our Annual Compliance Report compiles findings from these exercises, helping institutions identify gaps and improve.
Data breaches are on the rise globally. What is the situation in Uganda?
Uganda has experienced several data breaches in the past year, mostly involving phishing attacks, employee errors, or weak internal controls rather than advanced cyberattacks. Some cases involved exposure of customer or financial data, but most were quickly contained.
These incidents underscore the need for robust data governance, strong authentication systems, and continuous staff training.
Awareness is key to compliance. How are you educating the public and organizations?
We run public education campaigns through radio, television, and social media, simplifying legal concepts for ordinary citizens.
We also organize community outreaches and monthly training sessions for data protection officers. Currently, we are running the ‘Beera Ku Guard’ campaign with NITA-U, encouraging Ugandans to stay alert about their privacy online and offline.
With the rise of AI and emerging technologies, how are you preparing to regulate new data risks?
We are developing Guidelines for Data Protection Impact Assessments to ensure responsible data use, especially in activities involving AI and emerging technologies.
We are also working with innovators, government agencies, and private companies to embed privacy-by-design into digital systems. Internationally, we participate in forums like the Africa-Asia AI Policymaker Network and the Global Privacy Assembly to align Uganda with global standards.
How does Uganda’s data protection law compare with regional and global frameworks?
We are aligned with international standards that emphasize lawfulness, transparency, and accountability for data controllers and processors.
We are now working with our East African counterparts to harmonize data protection frameworks, particularly on cross-border data transfers, to facilitate digital trade and ensure consistent protection for citizens’ data across the region.
What message do you have for Ugandans about data privacy?
Your personal data is your identity; protect it. Every digital action leaves a footprint that defines who you are. Safeguarding that data protects your dignity, security, and choices.
As individuals, we must stay informed and cautious about where and how we share our information.
Organisations, on the other hand, must handle personal data responsibly and transparently. Remember, innovation thrives best where privacy is respected.