The Uganda Edition is written specifically for organisations and practitioners operating under Uganda's legal framework.
It covers Data Protection and Privacy Act, 2019 (Act 9 of 2019), the access to information framework, subsidiary legislation, guidance issued by Personal Data Protection Office, and published Uganda enforcement decisions.
Every lesson explains how compliance operates in practice under Uganda law.
Select a module to see what it covers. In this edition, each module is taught through Uganda's statutes, regulations and regulatory guidance.
The constitutional and statutory basis for privacy protection across African jurisdictions, the core definitions that determine whether a law applies at all (personal data, processing, controller, processor, data subject), and the processing principles that every later obligation is built on: lawfulness, fairness, purpose limitation, minimisation, accuracy, storage limitation, integrity and accountability.
When a data protection statute actually binds an organisation. Material scope, the establishment, targeting and equipment tests that extend a law beyond its borders, the obligation on foreign controllers to appoint a local representative, and the exemptions commonly drawn for household, journalistic, judicial and national security processing.
Selecting and documenting a lawful basis. The conditions that make consent valid and the consequences of withdrawal; contract, legal obligation, vital interests, public interest and legitimate interests; the balancing exercise where legitimate interests is relied on; and the points at which African statutes depart from the familiar European set.
Handling requests defensibly: access, rectification, erasure, restriction, objection, portability and rights in relation to automated decision-making and profiling. Identity verification, statutory response deadlines, the narrow grounds for refusal, and the internal workflow that produces an auditable answer.
Processing that carries heightened conditions: health, genetic and biometric data, race and ethnic origin, political opinion, religious or philosophical belief, trade union membership and sex life, with children's data and, in some jurisdictions, gender treated as sensitive. The narrower grounds, the regulator authorisation routes, and the safeguards expected in practice.
Allocating legal responsibility correctly, including joint controllership and the practical test for who determines purpose and means. The mandatory content of a processing agreement, processor due diligence, sub-processor authorisation, cross-border processing by vendors, and how liability falls between the parties when something goes wrong.
Embedding compliance in systems and products rather than documenting it afterwards. Data minimisation and purpose limitation at the design stage, default settings, retention by design, pseudonymisation and anonymisation, and how to evidence that design decisions were taken and why.
The legal grounds for moving personal data out of a jurisdiction: adequacy determinations, contractual safeguards, binding corporate rules, regulator authorisation, consent and the narrow derogations. Data localisation and copy-retention requirements, onward transfers, and mapping flows in a stack that spans several countries.
Determining whether an incident is a notifiable breach, assessing risk to data subjects, and meeting notification deadlines that range from 24 hours to 72 hours depending on the jurisdiction. Who must be told, when affected individuals must be informed directly, containment and remediation, and the records a regulator will ask to see.
When designation is mandatory and when it is merely permitted, qualification and independence requirements, the statutory tasks of the office, reporting lines and conflicts of interest, group appointments across entities, and the personal exposure carried by officers and directors under several African statutes.
Building and maintaining the processing register that controllers and processors are required to keep: its prescribed content, how it is derived from a data inventory, how it interacts with registration and notification duties, and why it becomes the evidence base for every other obligation in an inspection.
Identifying processing that requires an assessment, working through a defensible methodology, consulting the regulator where the residual risk remains high, selecting mitigations, and recording the decision to proceed. Includes the assessment triggers African regulators have applied in practice.
How African data protection authorities are constituted and what they can compel. Registration and notification regimes, information notices, investigative and audit powers, inspection procedure, and the path a complaint takes from lodgement to a binding determination.
Administrative fines and how they are calculated, enforcement and compliance notices, compensation awards to data subjects, criminal offences and officer liability, and appeal routes. Grounded in published determinations, so participants can see what regulators are penalising and at what level.
Where access to information legislation meets data protection: the duties of public bodies and, in some jurisdictions, private ones; the personal-information exemption and how it is applied; proactive disclosure; and reconciling a transparency request with a competing privacy obligation.
Comparative practice for counsel advising in more than one market: divergent definitions, notification deadlines and registration duties, conflicting transfer rules, regional instruments and their real effect, and how to design one programme that satisfies several regimes without defaulting to the strictest.
Turning obligations into an operating programme: governance and accountability structure, policies and privacy notices, staff training, vendor management, retention schedules, monitoring and internal audit, and assembling the documentation set that demonstrates accountability to a regulator.
A single organisation worked end to end. Map its processing, identify the applicable obligations, draft the core documents, respond to a data subject request and a reportable breach on the statutory clock, and prepare the file for a regulatory inquiry.
Explore the Pan-African Edition or any of the other country editions available across Africa.
The founding cohort is working through the course now. Leave your details and we will tell you first when enrolment for the next cohort opens.