Uganda’s Digital Economy: Rights Trends, Regulatory Gaps and Policy Responses

By Doreen Elizabeth Namuyanja |

Uganda’s digital economy is expanding rapidly across finance, transport, agriculture, commerce, healthcare and public-service delivery. However, this growth is outpacing the legal, regulatory and institutional safeguards needed to address emerging concerns around personal and biometric data, artificial intelligence, platform work, digital exclusion and internet shutdowns.

Drawing on a 2025 survey, two commentaries and a policy submission by CIPESA, this policy brief examines Uganda’s evolving digital business landscape, business data practices, the future of work and the impact of internet disruptions. It highlights the gaps between technological advancement and effective governance and proposes actions for government, businesses, private sector associations and civil society to build an inclusive, resilient, and rights-respecting digital economy.

The brief finds that Uganda has established important legal protections, including the Data Protection and Privacy Act of 2019. The principal challenge, however, is implementation, enforcement, and the ability of regulatory and institutional frameworks to adapt to rapidly evolving technologies and business models. Businesses frequently collect personal and biometric data without sufficiently explaining how it will be used, stored, shared, or deleted. Meaningful consent, data security, and effective retention and deletion practices also remain inconsistent, particularly among businesses with limited compliance capacity.

These gaps have consequences beyond privacy and individual rights. Weak data governance can undermine trust in digital services, while inadequate safeguards for platform workers and persistent digital exclusion can limit who benefits from the digital economy. Internet shutdowns pose a broader threat, disrupting digital financial services, e-commerce, public services and other activities that increasingly depend on reliable connectivity.

The brief calls for coordinated action by government, businesses, private sector associations and civil society to:

Businesses

  • Strengthen data governance and informed consent: implement collection and processing frameworks built on explicit, freely given consent, backed by clear, accessible privacy notices.
  • Improve data security and lifecycle management: adopt encryption, regular security audits, and clear retention, deletion and minimisation policies.
  • Build organisational compliance capacity: appoint and train Data Protection Officers, embed privacy-by-design into product development, and run regular staff training on data protection, cybersecurity and phishing risks.
  • Strengthen digital resilience: develop business continuity plans for internet disruptions, and collaborate with civil society and legal actors to promote an open, secure and reliable internet.

Government of Uganda

  • Strengthen enforcement of the data protection framework by adequately resourcing the Personal Data Protection Office (PDPO) and other regulators to conduct audits, investigate violations, and impose proportionate sanctions.
  • Modernise the legal and policy framework to address biometric data, AI and platform work, aligned with constitutional and international human rights standards, and issue practical, sector-specific guidance to help businesses, particularly SMEs, comply.
  • Promote digital inclusion and public awareness through sustained education campaigns, including in local languages, and continued investment in affordable infrastructure and digital skills.
  • Safeguard the digital economy against internet disruptions by developing clear legal safeguards against shutdowns and ensuring any restrictions comply with constitutional and international human rights obligations.

Private Sector Associations

  • Build members’ capacity through regular training on data protection, cybersecurity, AI governance and business continuity planning.
  • Promote industry standards and peer learning by developing model policies and compliance toolkits for consistent implementation across member organisations.
  • Support risk management by encouraging periodic risk assessments among members and facilitating the sharing of lessons learned and mitigation strategies.

Civil Society Organisations

  • Strengthen multi-stakeholder collaboration among government, businesses, academia and technical experts on data protection, AI governance and digital rights.
  • Promote public awareness and digital rights literacy through accessible educational materials and community outreach.
  • Undertake research and evidence-based advocacy on biometric data governance, AI, platform work and internet shutdowns, including documenting their social, economic and human rights impacts, to support stronger legal frameworks and strategic litigation.
  • Support business compliance and resilience by developing practical guidance, templates and capacity-building support on responsible data governance.

Read the full brief here.

CIPESA and UNESCO Partner on Project to Strengthen Climate Change Information Integrity in Africa

By Juliet Nanfuka |

The Collaboration on International ICT Policy for East and Southern Africa (CIPESA), in partnership with UNESCO, is launching a new project to address the growing challenge of climate change disinformation and strengthen information integrity in the public sphere.

At a time when false and misleading narratives are weakening public trust and distorting public understanding of the climate crisis, the initiative will support fact-based public discourse and strengthen the ability of journalists and civil society actors to engage with climate issues using credible information.

Reliable climate information is essential to informed public debate and effective climate action. Yet journalists, content creators, and Civil Society Organisations (CSOs) working on climate and environmental issues often lack the resources and skills needed to verify information, identify disinformation and effectively communicate accurate findings to the public.

CIPESA’s research has documented some of these challenges. Journalists and activists working on climate-related issues, including environment, land and extractives, face significant information gaps and have to navigate disinformation and misinformation campaigns, often with limited avenues to independently verify information.

The initiative recognises that public communication relies on facts and the ability of credible voices to deliver information. The project is supported by the UNESCO-led Global Initiative for Information Integrity on Climate  Change, which was established to investigate, expose, and dismantle disinformation related to climate change.

The project will respond to these challenges by combining research, capacity building, and public communication. Research will map how climate disinformation spreads across African digital ecosystems, who drives it, and what tactics they use. Findings will inform a Fact-checking Masterclass at the upcoming 2026 Forum on Internet Freedom in Africa, an online training for journalists and civil society actors, and a communications campaign aimed at strengthening public awareness of climate disinformation and promoting credible sources of information.

This approach builds on the Declaration on Information Integrity on Climate Change, which commits its signatories to protect information integrity on climate change at international, national, and local levels. It also reflects the broader United Nations Global Principles for Information Integrity, which envision “an information ecosystem that delivers choice, freedom, privacy and safety for all,” and support those working to share facts in the public interest.

Reporting on climate change in Africa is increasingly taking place in a difficult information environment. Journalists, activists and human rights defenders covering environmental, land and extractives issues face surveillance, censorship, online harassment and coordinated disinformation campaigns. CIPESA’s research has documented these risks, as well as the limited digital security resources available to many of those doing this work.

The project will focus on Uganda and Ethiopia, both of which are experiencing a rise in misleading narratives related to climate change in their digital ecosystems. These narratives frequently revolve around issues such as deforestation, dam and water system developments, droughts, landslides, oil and gas exploration.

The project’s research will also track the information environment, including the public positions and communications of African governments ahead of the 31st Session of the Conference of Parties (COP31) scheduled for November 2026 in Ankara, Türkiye. The conference brings together nearly 200 nations under the United Nations Framework Convention on Climate Change (UNFCCC) to negotiate climate action, set emission-reduction targets, and coordinate policies to limit global warming.

Looking further ahead, Ethiopia’s hosting of the 32nd session of the (COP32) in 2027, will bring the global climate conversation back to Africa for the fifth time after Kenya (2006), South Africa (2011), Morocco (2016), and Egypt (2022). This makes the CIPESA-UNESCO partnership particularly timely.  As technology increasingly shapes how people access, interpret and contest information about the environment, there is a growing need to understand the evolving relationship between digital platforms, climate narratives, and the integrity of public debate.

Is Africa’s Digital Future Being Bargained Away?

By Juliet Nanfuka |

Africa’s digital future is being negotiated away piece by piece – through opaque infrastructure deals, data-sharing arrangements, and political decisions that narrow the space for journalists, civil society, and other stakeholders to gather and speak freely.

Just over a month ago, this year’s UNESCO World Press Freedom Day (WPFD) Global Conference was set to be held under the theme “Journalism Shapes Peace: Promoting Press Freedom for Human Rights, Development and Security” – and it could not have come at a more critical time, as media freedom and digital rights in Africa are under pressure.

The WPFD was scheduled to share a host city (Lusaka, in Zambia) with RightsCon, the world’s largest gathering on technology and human rights. Combined, the events were set to attract thousands of journalists, technologists, human rights defenders, and policymakers from all over the world, signaling Africa’s growing role in global debates on journalism, digital rights, and internet governance.

However, the Government of Zambia abruptly “postponed” RightsCon, citing the need to ensure “full alignment with Zambia’s national values, policy priorities, and broader public interest considerations.” According to Access Now, the conference organiser, “foreign interference” was the reason RightsCon 2026 did not proceed in Zambia.

Officials from Zambia’s Ministry of Technology and Science had purportedly informed Access Now that they were under pressure from Chinese diplomats over the participation of Taiwanese civil society actors in RightsCon. Critics have argued that this is a clear abuse of power and influence over other governments to silence dissent and restrict fundamental rights.

Following this, Zambia also lost out on hosting key WPFD-related events, which shifted online or to Paris, France. A scaled-down physical event was held in Zambia.

These developments exposed a broader pattern: civic space in Africa is not only constrained by arrests, vague laws and media intimidation, but also by foreign pressure and various forms of dependence. Zambia illustrated how quickly external political pressure can contribute to narrowing civic space on the continent, and how geopolitical influence is most dangerous where local institutions are already vulnerable and democracy is under strain.

Geopolitical tensions are no longer limited to military alliances or commodity diplomacy. They are instead increasingly being exercised through digital infrastructure, platform governance, cross-border data arrangements, cyber laws, standards-setting, mining rights, and now, the policing of civic forums. Powerful states are influencing digital policy choices through debt dependency, mineral extraction, infrastructure dependence, diplomatic pressure, or access to funding and technical systems.

The developments in Zambia illustrate a worrying phenomenon that the Collaboration on International ICT Policy for East and Southern Africa (CIPESA) has been tracking – the steady erosion of digital rights and press freedom on the continent, through attacks on information integrity and financial dependency on larger economies.

Text Block: In Zambia, China is also deeply embedded in mining, energy, healthcare, and the construction of national facilities, including the conference venue where RightsCon was due to be held. Source:  Just Security

Over the years, Chinese firms such as Huawei have invested heavily in Africa’s internet infrastructure, including through “smart city” deployments,  national fibre-optic backbones, and data transmission projects including in South Africa and in Senegal. In Uganda, China has invested more than USD 110 million in the National Backbone Data Transmission Project through additional concessional financing. Critics have argued that these investments also limit civic rights, including through enabling surveillance and undermining elections.

However, not every African government decision involving China is coerced. Yet dependence can narrow the room for resistance when political demands are made, and that influence can extend into tighter restrictions on civic participation and digital rights organising.

Moreover, to frame Africa’s sovereignty challenges as a problem created only by China is incorrect, as some Western powers are also advancing strategic interests through data-heavy arrangements that can test national safeguards.

For instance, as part of the America First Global Health Strategy, the United States has signed bilateral health agreements with numerous African states including Botswana, Cameroon, Côte d’Ivoire, the Democratic Republic of Congo, Kenya, Nigeria, Rwanda, Lesotho, and Uganda.

These agreements tie funding to extensive data-related cooperation including long-term sharing of comprehensive national health data for periods of up to 25 years, alongside expansive health surveillance arrangements. In exchange for financial support, African states are surrendering health data without the guarantee of equitable access to vaccines or research outputs developed from that data. Zambia, Ghana, and Zimbabwe have expressed reservations about signing on, and a court in Kenya suspended implementation of the agreement pending alignment with the country’s national data protection regime.

As African countries navigate shifting technology standards, expanding digital infrastructure, and competing data governance regimes – often without a shared rights-based framework – the result is an increasingly fragmented digital landscape. This fragmentation is not accidental; it is being shaped by geopolitical interests and power asymmetries that determine who builds the technologies, who controls the data, and ultimately, who governs the digital future.

 Meanwhile, African governments appear ready to trade civic rights, with countries like Nigeria, Ghana, Morocco, Malawi, and Zambia collectively spending at least USD 1 billion a year on digital surveillance technology contracts with companies in the United States, the United Kingdom, China, the European Union, and Israel.

Text block: However, the key policy challenge facing Africa is not whether governments should work with powerful economies like China, the United States, and various European states, or private technology firms. They will, and they must. The issue is whether African states have the legal, institutional, and political capacity to engage those powers without trading away civic space, data autonomy, and democratic accountability.

The continent is not without policy tools. The African Union Data Policy Framework, the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention), the African Continental Free Trade Area Digital Trade Protocol, and new calls such as the African Declaration on Digital Freedom and Democracy all point toward a more rights-respecting path. They emphasise harmonised safeguards, trusted data governance, universal and meaningful internet access, transparency, and accountability. However, implementation remains a persistent challenge, with limited progress in practice across many states.

The Zambia case offers clear lessons.  African governments should require parliamentary review and public engagement for all major cross-border data-sharing and digital infrastructure agreements. Procurement contracts involving critical digital systems should be published, including provisions on data storage, access, transfers, and vendor liability. Transparency in DPI procurement processes is critical in ensuring that deployed systems are rights-respecting and those responsible can be held accountable.

While numerous global convenings are hosted on the continent, Zambia set a worrying precedent. Organisations that co-host global convenings in Africa should demand enforceable non-discrimination and freedom-of-assembly guarantees from host states as regional civil society spaces must be protected and expanded, not treated as expendable.

The spaces where African civil society, journalists, and policymakers can gather are fundamental to the digital rights movement on the continent. If African governments cannot protect the right of journalists and civil society actors to assemble freely, then they will struggle to protect anything else in the digital age. These communities are integral parts of the democratic infrastructure Africa needs to negotiate its way out of debt dependency, surveillance overreach, and geopolitical capture.

This is why global and regional gatherings, such as the upcoming Forum on Internet Freedom in Africa (FIFAfrica26), are critical. They are necessary spaces for interrogation, debate, and the forging of consensus on civic and digital rights. These are the convenings where the shifts in sovereignty are understood, including the risks of opaque cross-border data-sharing agreements, unchecked surveillance infrastructure, and politically motivated cyber laws, all of which are named and challenged through multistakeholder engagement.

Ultimately, Africa’s digital future should not be bargained away through debt dependency, opacity agreements and geopolitical pressure. It must be shaped openly, democratically, and on terms that serve its people rather than the geopolitical interests of others.

Protecting Children Online in Africa Must Move from Policy to Practice

By Patricia Ainembabazi |

Child online safety has returned to the forefront of digital governance discussions across Africa and globally. New regulatory initiatives from the United Nations, the African Union, and industry coalitions reflect growing concern about the risks children face in increasingly digital societies. Yet, while policy commitments are multiplying, implementation continues to lag.

The challenge is particularly acute in Africa, where internet access is expanding rapidly while child protection systems struggle to keep pace. As more children go online, they are increasingly exposed to cyberbullying, online grooming, sexual exploitation, harmful content, privacy violations, and emerging Artificial Intelligence (AI)-enabled risks such as disinformation and misinformation.

Just last month, the United Nations Human Rights Office called for stronger regulation and government oversight, publishing 10 key points to make platforms safer for children, urging technology companies to embed child safety into their product design and address the growing risk posed by AI. This reflects a broader shift in global digital policy. The Global Digital Compact has committed states to strengthen legal and policy frameworks for children’s rights in digital spaces and to prioritise national online child safety policies and standards by 2030.

At the continental level, the African Union Child Online Safety and Empowerment Policy of 2024 sets out principles on children’s safety and privacy, and participation to guide member states in developing national strategies, while the Global System for Mobile Communications Association (GSMA), UNICEF, and partners recently launched the Africa Taskforce on Child Online Protection to strengthen coordination among governments, mobile operators, technology companies, regulators, law enforcement, civil society, and young people.

Some African countries are already taking steps to strengthen child protection online. Rwanda is considering restrictions on social media access for children under 16, while Zimbabwe recently approved a National Child Online Protection Policy for 2026–2030 aimed at addressing online sexual exploitation, cyberbullying, grooming, harmful content, sextortion, and privacy violations.

These developments reflect a broader global shift in approaches to child online safety. Australia has legislated to restrict social media access for children under 16, while the United Kingdom recently concluded a national consultation examining age-based protections and enforcement mechanisms. Across several countries, governments, regulators, and civil society organisations are increasingly calling on technology companies to strengthen safeguards and take greater responsibility for protecting children online.

A broader strategy would expand efforts to ensure that while policies and frameworks on child protection are being developed, children are involved. This would help them understand the several platforms available for use, associated risks, pressures, and opportunities for digital life. The Africa Taskforce on Child Online Protection recognises this mode of participation and has now included youth representatives by integrating their voices for a child-centered digital future in Africa. Replicating this approach at the national level, through wide youth consultations, school-based dialogues, child-friendly policy forums, and participatory design of reporting and safety tools, will foster a healthy digital environment for the young.

It is against this backdrop that the Digital Rights Alliance Africa (DRAA) report, “Child Protection and Safety Online in Africa: The Law, Privacy, Challenges and Solutions, provides crucial, ground-level evidence across 10 countries – Algeria, Botswana, Egypt, Ghana, Kenya, Nigeria, Rwanda, South Africa, Tanzania, and Uganda. It highlights the gaps in child safety and protection online despite technological advancement and expansion.

The report highlights several recommendations that could help foster child safety and protection online, which are directed to different stakeholders, including the government, civil society organisations, international organisations, development partners, the technology sector, media, academia, parents, and the general community, and among others include;

  1. Parliaments should enact specific national laws that protect children’s privacy and safety in digital spaces, with clear safeguards tailored to children’s particular vulnerabilities, such as cyberbullying, grooming, online sexual exploitation, image-based abuse, harmful content, misuse of children’s data, profiling, and age-inappropriate design.
  2. Governments should invest in the implementation of national strategies that set out the roles of government agencies, the judiciary, data protection authorities, law enforcement actors, educators, parents, and the private sector in protecting children in the digital age.
  3. Platforms and telecom companies should design child-friendly products and services, minimise the collection and retention of children’s data, introduce age verification and parental controls, publish transparency reports, and submit protection measures to independent audits.
  4. The media should monitor, document, and report objectively, and expose all cases of online child abuse and demand accountability from the responsible parties.
  5. Civil society organisations should engage in advocacy, awareness raising, legal reform, evidence-based research, and documentation of issues affecting child safety online in order to demand and push for accountability of all the relevant stakeholders.
  6. All stakeholders must ensure that children are meaningfully included in innovation and programming, and that children and young people are actively engaged as participants in discussions, collaborations, and co-design of digital solutions.

Ultimately, for children to stay online, measures must go beyond mere policy expressions and aspirations as reiterated in the Global Digital Compact’s 2030. Laws and frameworks specific to child protection and safety online should be developed and stringently implemented. Moreover, digital service providers must be held accountable, and other stakeholders, including parents, schools, and communities, should join efforts to ensure that children are empowered to safely utilise digital technologies.

CIPESA and partners continue to advocate for rights-respecting policies that advance children’s protection, participation, access, and safe use of digital technologies, while calling on technology companies to embed these principles in platform design, governance, and accountability systems.