On 18 July 2025, Uganda's Personal Data Protection Office found Google LLC in breach of the Data Protection and Privacy Act 2019 and ordered it to register as a data controller within 30 days. Google had argued it was not subject to Ugandan law because it has no physical presence in Uganda. The PDPO rejected that argument outright: the Act reaches any entity, wherever it sits, that handles the personal data of Ugandan citizens; section 1(b) keys the extraterritorial limb to citizenship (decision PDF; CIPESA analysis).
The complaint, Ssekamwa Frank & 3 Others v Google LLC, was filed in November 2024 by four Ugandan Google users. Two findings matter. First, Google is a data controller under Ugandan law because it collects Ugandan users' data and decides how that data is processed. Second, Google's transfers of that data out of Uganda lacked the safeguards the Act requires, so the PDPO ordered documentary evidence of cross-border transfer compliance alongside registration.
Why it matters. This is the clearest extraterritoriality holding yet from an African data protection authority. The logic is the same one that gives the GDPR its global reach, applied by a regulator in Kampala. Every offshore platform with Ugandan users sits inside the same reasoning: Meta, TikTok, X, and any SaaS or e-commerce business serving Uganda without a local entity. The decision also lands in a wider pattern. Nigeria's NDPC opened its Temu investigation in February 2026 and Kenya's ODPC has been enforcing against Tools for Humanity since 2023. African regulators are no longer treating foreign incorporation as a shield, and they are starting to say so in coordinated forums (the May 2026 Abuja peer exchange brought nine DPAs together on exactly this).
The limitation worth naming. The PDPO issues declaratory orders. It cannot fine, and it cannot award compensation; the complainants were referred to the courts for damages. That gap in Uganda's enforcement architecture reduces the immediate cost of non-compliance, and Google's compliance with the 30-day registration order has not been publicly confirmed as of July 2026. But declaratory today is not declaratory forever. Kenya shows the trajectory: ODPC determinations now convert into court orders with execution machinery. When Uganda's framework grows teeth, the Google precedent is already on the books.
Who is affected. Any entity, anywhere, that handles Ugandan citizens' personal data: global platforms, regional fintechs serving Ugandan customers remotely, offshore analytics and advertising vendors, and group companies processing Ugandan HR or customer data at headquarters outside the country.
What to do now:
- If your organisation serves Ugandan users without a local presence, treat PDPO registration as a live obligation, not a theoretical one. Registration is annual and the process is documentary.
- Map every transfer of Ugandan personal data out of the country and record the legal basis and safeguards for each. The PDPO ordered Google to produce exactly this evidence; it will ask others.
- Track the compensation route. PDPO referrals push data subjects toward the courts, so the litigation exposure sits there, not with the regulator. Uganda's court record on data claims is thin today. It will not stay thin.
Sources: PDPO decision, 18 July 2025 · CIPESA · DLA Piper Privacy Matters · Cliffe Dekker Hofmeyr