Promoting Effective and Inclusive ICT Policy in Africa

Uganda’s Digital Economy: Rights Trends, Regulatory Gaps and Policy Responses

By Doreen Elizabeth Namuyanja |

Uganda’s digital economy is expanding rapidly across finance, transport, agriculture, commerce, healthcare and public-service delivery. However, this growth is outpacing the legal, regulatory and institutional safeguards needed to address emerging concerns around personal and biometric data, artificial intelligence, platform work, digital exclusion and internet shutdowns.

Drawing on a 2025 survey, two commentaries and a policy submission by CIPESA, this policy brief examines Uganda’s evolving digital business landscape, business data practices, the future of work and the impact of internet disruptions. It highlights the gaps between technological advancement and effective governance and proposes actions for government, businesses, private sector associations and civil society to build an inclusive, resilient, and rights-respecting digital economy.

The brief finds that Uganda has established important legal protections, including the Data Protection and Privacy Act of 2019. The principal challenge, however, is implementation, enforcement, and the ability of regulatory and institutional frameworks to adapt to rapidly evolving technologies and business models. Businesses frequently collect personal and biometric data without sufficiently explaining how it will be used, stored, shared, or deleted. Meaningful consent, data security, and effective retention and deletion practices also remain inconsistent, particularly among businesses with limited compliance capacity.

These gaps have consequences beyond privacy and individual rights. Weak data governance can undermine trust in digital services, while inadequate safeguards for platform workers and persistent digital exclusion can limit who benefits from the digital economy. Internet shutdowns pose a broader threat, disrupting digital financial services, e-commerce, public services and other activities that increasingly depend on reliable connectivity.

The brief calls for coordinated action by government, businesses, private sector associations and civil society to:

Businesses

  • Strengthen data governance and informed consent: implement collection and processing frameworks built on explicit, freely given consent, backed by clear, accessible privacy notices.
  • Improve data security and lifecycle management: adopt encryption, regular security audits, and clear retention, deletion and minimisation policies.
  • Build organisational compliance capacity: appoint and train Data Protection Officers, embed privacy-by-design into product development, and run regular staff training on data protection, cybersecurity and phishing risks.
  • Strengthen digital resilience: develop business continuity plans for internet disruptions, and collaborate with civil society and legal actors to promote an open, secure and reliable internet.

Government of Uganda

  • Strengthen enforcement of the data protection framework by adequately resourcing the Personal Data Protection Office (PDPO) and other regulators to conduct audits, investigate violations, and impose proportionate sanctions.
  • Modernise the legal and policy framework to address biometric data, AI and platform work, aligned with constitutional and international human rights standards, and issue practical, sector-specific guidance to help businesses, particularly SMEs, comply.
  • Promote digital inclusion and public awareness through sustained education campaigns, including in local languages, and continued investment in affordable infrastructure and digital skills.
  • Safeguard the digital economy against internet disruptions by developing clear legal safeguards against shutdowns and ensuring any restrictions comply with constitutional and international human rights obligations.

Private Sector Associations

  • Build members’ capacity through regular training on data protection, cybersecurity, AI governance and business continuity planning.
  • Promote industry standards and peer learning by developing model policies and compliance toolkits for consistent implementation across member organisations.
  • Support risk management by encouraging periodic risk assessments among members and facilitating the sharing of lessons learned and mitigation strategies.

Civil Society Organisations

  • Strengthen multi-stakeholder collaboration among government, businesses, academia and technical experts on data protection, AI governance and digital rights.
  • Promote public awareness and digital rights literacy through accessible educational materials and community outreach.
  • Undertake research and evidence-based advocacy on biometric data governance, AI, platform work and internet shutdowns, including documenting their social, economic and human rights impacts, to support stronger legal frameworks and strategic litigation.
  • Support business compliance and resilience by developing practical guidance, templates and capacity-building support on responsible data governance.

Read the full brief here.