A summary of the Data Privacy and Governance Society of Kenya (DPGSK) webinar comparing data protection regimes in Kenya and Uganda, featuring Brian Kalule (Partner, Technology Practice) and Judith Kagoro (Associate), from a leading Kampala-based law firm, in conversation with Mutua of DPGSK’s litigation committee.
Overview
This webinar grew out of a benchmarking study trip by Ugandan practitioners to Kenya, and examined how the two countries’ data protection regimes compare across regulatory structure, enforcement, compliance practice, and cross-border cooperation — most notably through the DTB Kenya–DTB Uganda case, where the two national data protection authorities collaborated on a cross-border investigation.
Regulatory Structure: Similarities and Differences
Both regimes are broadly modelled on the GDPR and are data-subject centric, with consent playing a central role and privacy recognised as a constitutional and human right in both jurisdictions. Key differences include:
- Registration: Uganda’s law requires all data controllers and processors to register, with no general exemptions. Kenya’s regime exempts certain categories of entities from registration.
- Data Protection Impact Assessments (DPIAs): Kenya’s framework is more prescriptive — defining what constitutes “high-risk processing,” outlining the DPIA procedure, and specifying decision-making roles. Uganda’s equivalent requirement exists but is less detailed, though new guidelines are in development to address this gap.
- Maturity and activity levels: Despite Kenya’s Data Protection Act being younger than Uganda’s, the Kenyan regulator (ODPC) has issued a significantly higher volume of decisions and guidance in a shorter period.
Enforcement Powers: The Key Divergence
The most significant structural difference raised was administrative fining power:
- Kenya’s ODPC can issue administrative fines directly, which panellists said has driven strong public awareness and even created an incentive for individuals to actively pursue privacy rights claims.
- Uganda’s Personal Data Protection Office (PDPO) cannot issue fines. It can only make administrative orders or recommend criminal prosecution to the Director of Public Prosecutions, a route that is slower and, in the panellists’ view, creates a weaker deterrent effect.
Notable Ugandan enforcement cases discussed:
- A criminal conviction of a loan-app company director for failing to register as a data controller/processor.
- An administrative (non-monetary) determination against Google for failing to register locally — a decision credited with prompting a wave of voluntary registrations by multinational and international entities without a local Ugandan presence.
Cross-Border Cooperation: The DTB Case
The DTB Kenya / DTB Uganda determination was highlighted as a landmark example of cross-border regulatory collaboration. Both national authorities have extraterritorial jurisdiction under their respective statutes, and the ODPC formally engaged Uganda’s PDPO during its investigation into unlawful cross-border data sharing between related entities. Panellists noted this illustrates two important points:
- No single data protection authority can fully address cross-border data risks in isolation — joint enforcement mandates matter.
- The case originated from ordinary internal business processes (identity verification, cross-entity data checks) rather than a traditional external breach, underscoring that routine processing activity in financial services can itself trigger regulatory action.
Compliance in Practice
Panellists identified cross-border data transfers as the most burdensome compliance challenge in Uganda, since the law requires either data subject consent or a fresh “adequacy assessment” of the receiving country for each transfer — a process seen as repetitive and costly when done transaction-by-transaction. A proposed compromise is to allow a single upfront adequacy assessment covering anticipated future transfers to named countries.
By sector, telecoms and financial services were cited as generally the most compliant (attributed to greater resources for DPOs, security testing, and periodic reviews), while public sector/government entities were flagged as the least compliant — partly because regulators currently have limited practical means to enforce against government bodies.
Emerging Issues on the Horizon (Next 1–2 Years)
- Geopolitics and government data-sharing agreements — referencing a publicised Uganda–US bilateral health data arrangement, and parallel concerns raised in Kenya (e.g., the Worldcoin matter), around data sovereignty and government as the largest data controller in the region.
- Special/sensitive personal data — readiness of legislation to handle biometric and health data given increasing use cases (elections, health agreements, national ID systems).
- Data localisation and data centre growth, driving more adequacy-framework discussions for cross-border flows.
- Enforceability in the AI era — panellists raised open questions about how regulators can meaningfully verify compliance with orders (e.g., data deletion) once data has been used to train AI models.
Should There Be a Regional (EAC) Framework?
Panellists agreed a harmonised East African Community framework — covering mutual recognition of enforcement decisions and aligned interpretation of DPIAs, adequacy assessments, and registration requirements — would benefit the region, but noted this depends on sustained political and institutional buy-in across member states. Asked what three principles an African data protection framework should prioritise, the suggested pillars were:
- Collaboration between regulators
- Independence of data protection authorities from political influence
- Administrative fining powers for all regional authorities, not just some
Cross-Border Law Enforcement and Privacy
On a question about a cross-border abduction case (Kenya–Uganda) and its data protection implications for police access to personal data, panellists noted that national security is a recognised lawful processing ground in both countries, but this does not override core data protection principles — fairness, proportionality, and the constitutional right to privacy still apply to how law enforcement handles personal data in cross-border investigations.
Source: DPGSK webinar recording, a joint discussion between DPGSK and Ugandan data protection practitioners. For more sessions on data privacy and governance across East Africa, follow DPGSK on LinkedIn or visit datprivacyke.africa.