Data Protection and Privacy Act
The Act applies to any person, institution or public body that collects, processes, holds or uses personal data within Uganda, and to those outside Uganda who collect, process, hold or use personal data relating to Ugandan citizens.
- Jurisdiction
- Uganda
- Instrument
- Act or statute
- Citation
- Chapter 97
- Version
- 3 May 2019
- Language
- en
- Official source
- View official record ↗
Source attribution: Source: Uganda Legal Information Institute
Statute overview
About this statute
The Act applies to any person, institution or public body that collects, processes, holds or uses personal data within Uganda, and to those outside Uganda who collect, process, hold or use personal data relating to Ugandan citizens. Section Interpretation Section In this Act unless the context otherwise requires — “ Authority ” means the National Information Technology Authority - Uganda; “ consent ” means any freely given, specific, informed and unambiguous Data collectors, processors and controllers must follow principles of data protection including accountability, fair and lawful processing, data minimisation, retention limits, quality, transparency and security; the Authority must ensure compliance. Establishes a personal data protection office that reports directly to the Board, headed by a national personal data protection director who must meet specified appointment terms and qualifications, and which shall include other officers as necessary. The personal data protection office must oversee and enforce the Act, promote privacy rights, monitor and report on privacy observance, run awareness programmes, investigate complaints, maintain a register, perform other prescribed or necessary functions, and has all powers necessary; it must not be under the direction or control of any person or Authority.
Search within this statute
Search all stored provisions in this version.
Legal text
Provisions of Data Protection and Privacy Act
Showing 40 of 40
Part I
Preliminary
- 1 Verify source ↗
Preliminary - Application
The Act applies to any person, institution or public body that collects, processes, holds or uses personal data within Uganda, and to those outside Uganda who collect, process, hold or use personal data relating to Ugandan citizens.
Section Application Section This Act applies to a person, institution or public body — collecting, processing , holding or using personal data within Uganda; outside Uganda who collects, processes, holds, or uses personal data relating to Ugandan citizens. - 2 Verify source ↗
Preliminary - Interpretation
Section Interpretation Section In this Act unless the context otherwise requires — “ Authority ” means the National Information Technology Authority - Uganda; “ consent ” means any freely given, specific, informed and unambiguous
Section Interpretation Section In this Act unless the context otherwise requires — “ Authority ” means the National Information Technology Authority - Uganda; “ consent ” means any freely given, specific, informed and unambiguous indication of the data subject ’s wish which he or she, by a statement or by a clear affirmative action, signifies agreement to the collection or processing of personal data relating to him or her; “ corporation ” means an entity created under a law and is separate and distinct from its owners; “ currency point ” has the value assigned to it in the Schedule; “ data ” means information which — (a) is processed by means of equipment operating automatically in response to instructions given for that purpose; (b) is recorded with the intention that it should be processed by means of such equipment; (c) is recorded as part of a relevant filing system or with the intention that it should form part of a relevant filing system; or (d) does not fall within paragraph (a), (b) or (c) but forms part of an accessible record; “ data collector ” means a person who collects personal data ; “ data controller ” means a person who alone, jointly with other persons or in common with other persons or as a statutory duty determines the purposes for and the manner in which personal data is processed or is to be processed; “ data processor ” in relation to personal data , means a person other than an employee of the data controller who processes the data on behalf of the data controller ; “ data subject ” means an individual from whom or in respect of whom personal information has been requested, collected, collated, processed or stored; “ information ” includes data , text, images, sounds, codes, computer programmes, software and databases; “ Minister ” means the Minister responsible for information and communications technology; “ personal data ” means information about a person from which the person can be identified, that is recorded in any form and includes data that relates to — (a) the nationality, age or marital status of the person; (b) the educational level, or occupation of the person; (c) an identification number, symbol or other particulars assigned to a person; (d) identity data ; or (e) other information which is in the possession of, or is likely to come into the possession of the data controller and includes an expression of opinion about the individual; “ public body ” includes the Government, a department, service or undertaking of the Government, Cabinet, Parliament, a court, local Government administration or a local council and any committee or commission thereof, an urban authority, a municipal council and any committee of any such council, any corporation , committee, board, commission or similar body whether corporate or incorporate established by an Act of Parliament relating to undertakings of public services or such purpose for the benefit of the public or any section of the public to administer funds or property belonging to or granted by the Government or money raised by public subscription, rates, taxes, cess or charges in pursuance of any written law and any council, board, committee or society established by an Act of Parliament for the benefit, regulation and control of any profession; “ processing ” means any operation which is performed upon collected data by automated means or otherwise including — (a) organisation, adaptation or alteration of the information or data ; (b) retrieval, consultation or use of the information or data ; (c) disclosure of the information or data by transmission, dissemination or otherwise making available; or (d) alignment, combination, blocking, erasure or destruction of the information or data ; “ recipient ” means a person to whom data is disclosed including an employee or agent of the data controller or the data processor to whom data is disclosed in the course of processing the data for the data controller , but does not include a person to whom disclosure is made with respect to a particular inquiry pursuant to an enactment; “ third party ” in relation to personal data , means a person other than the data subject , the data collector , data controller , or any data processor or other person authorised to process data for the data controller or processor.
Part II
Principles of data protection
- 3 Verify source ↗
Principles of data protection - Principles of data protection
Data collectors, processors and controllers must follow principles of data protection including accountability, fair and lawful processing, data minimisation, retention limits, quality, transparency and security; the Authority must ensure compliance.
Section Principles of data protection Section A data collector , data processor or data controller or any person who collects, processes, holds or uses personal data shall — be accountable to the data subject for data collected, processed held or used; collect and process data fairly and lawfully; collect, process, use or hold adequate, relevant and not excessive or unnecessary personal data ; retain personal data for the period authorised by law or for which the data is required; ensure quality of information collected, processed, used or held; ensure transparency and participation of the data subject in the collection, processing , use and holding of the personal data ; and observe security safeguards in respect of the data . The Authority shall ensure that every data collector , data controller , data processor or any other person collecting or processing data complies with the principles of data protection and this Act. - 4 Verify source ↗
Principles of data protection - Establishment of the personal data protection office
Establishes a personal data protection office that reports directly to the Board, headed by a national personal data protection director who must meet specified appointment terms and qualifications, and which shall include other officers as necessary.
Section Establishment of the personal data protection office Section There is established a personal data protection office responsible for personal data protection under the Authority which shall report directly to the Board. The personal data protection office established in subsection (1) shall be headed by a national personal data protection director appointed on such terms and conditions as may be specified in his or her instrument of appointment. The national personal data protection director shall be a person of high moral character, proven integrity and with the relevant qualifications and experience relating to the functions of the office. The personal data protection office shall consist of such other officers as may be necessary for the proper functioning of the office appointed on such terms and conditions as may be specified in the instruments of appointment. - 5 Verify source ↗
Principles of data protection - Functions of the personal data protection office
The personal data protection office must oversee and enforce the Act, promote privacy rights, monitor and report on privacy observance, run awareness programmes, investigate complaints, maintain a register, perform other prescribed or necessary functions, and has all powers necessary; it must not be under the direction or control of any person or Authority.
Section Functions of the personal data protection office Section For purposes of this Act and in addition to its functions under any other law, the personal data protection office shall — oversee the implementation of and be responsible for the enforcement of this Act; promote the protection and observance of the right to the privacy of a person and of personal data ; monitor, investigate and report on the observance of the right to privacy and of personal data ; formulate, implement and oversee programmes intended to raise public awareness about this Act; receive and investigate complaints relating to infringement of the rights of the data subject under this Act; establish and maintain a data protection and privacy register; perform such other functions as may be prescribed by any other law or as the office considers necessary for the promotion, implementation and enforcement of this Act; The office shall have all powers necessary for the performance of its functions under this Act. The office in performing its functions under this Act shall not be under the direction or control of any person or Authority . - 6 Verify source ↗
Principles of data protection - Data protection officer
The head of an institution must designate a person as the data protection officer to ensure compliance with the Act.
Section Data protection officer Section For purposes of this Act, and in so far as it applies to an institution, the head of the institution shall designate a person as the data protection officer responsible for ensuring compliance with this Act.
Part III
Data collection and processing
- 10 Verify source ↗
Data collection and processing - Protection of privacy
Data collectors, data processors and data controllers must not collect, hold or process personal data in a way that infringes the privacy of a data subject.
Section Protection of privacy Section A data collector , data processor or data controller shall not collect, hold or process personal data in a manner which infringes on the privacy of a data subject . - 11 Verify source ↗
Data collection and processing - Collection of data from data subject
A person must collect personal data directly from the data subject, except where the text lists specific exceptions allowing collection from other sources.
Section Collection of data from data subject Section Notwithstanding subsection (1), personal data may be collected from another person, source or public body where — the collection of the data from another source is necessary — A person shall collect personal data directly from the data subject . the data is contained in a public record; the data subject has deliberately made the data public; the data subject has consented to the collection of the information from another source; the collection of the data from another source is not likely to prejudice the privacy of the data subject ; for the prevention, detection, investigation, prosecution or punishment of an offence or breach of law; for the enforcement of a law which imposes a pecuniary penalty; for the enforcement of legislation which concerns public revenue collection; for the conduct of proceedings before any court or tribunal that have commenced or are reasonably contemplated; or for the protection of national security; compliance would prejudice a lawful purpose for the collection; or it is not reasonably practicable to obtain the consent of the data subject . - 12 Verify source ↗
Data collection and processing - Collection of personal data for specific purpose
A person who collects personal data must collect it only for a lawful, specific, explicitly defined purpose related to the collector's functions or activities.
Section Collection of personal data for specific purpose Section A person who collects personal data shall collect the data for a lawful purpose which is specific, explicitly defined and is related to the functions or activity of the data collector , or data controller . - 13 Verify source ↗
Data collection and processing - Information to be given to data subject before collection of data
A person collecting personal data must inform the data subject about specified topics (what data, collector identity, purpose, whether supply is mandatory, consequences of failure, legal basis, recipients, access and rectification rights, and retention period).
Section Information to be given to data subject before collection of data Section A person collecting personal data shall inform the data subject about — Subsection (2) shall not apply — the nature and category of data being collected; the name and address of the person responsible for the collection of data ; the purpose for which the data is required; whether or not the supply of the data by the data subject is discretionary or mandatory; the consequences of failure to provide the data ; the authorised requirement for the collection of the information or the requirement by law for its collection; the recipients of the data ; the existence of the right of access to and the right to request rectification of the data collected before the collection; and the period for which the data will be retained to achieve the purpose for which it is collected. Where the data is collected from a third party , the data subject shall be given the information specified in subsection (1) before the collection of the data or as soon as practicable after the collection of the data . where it is necessary to avoid the compromise of the law enforcement power of a public body responsible for the prevention, detection, investigation, prosecution or punishment of an offence; to information relating to national security; to information relating to the enforcement of a law which imposes a pecuniary penalty; to information relating to the enforcement of legislation which concerns public revenue collection; to information relating to the preparation or conduct of proceedings before a court or tribunal. - 14 Verify source ↗
Data collection and processing - Minimality
A data controller or data processer must only process personal data that is necessary or relevant, and must not process personal data in excess of what is authorised by law or needed for a specific purpose.
Section Minimality Section A data controller or data processer shall only process the necessary or relevant personal data . For the avoidance of doubt, a data controller or data processer shall not process personal data which is in excess of the data which is authorised by law or required for a specific purpose. - 15 Verify source ↗
Data collection and processing - Quality of information
Data collectors/processors/controllers must ensure personal data they handle is complete, accurate, up-to-date and not misleading; data subjects must ensure the personal data they provide meets the same standards.
Section Quality of information Section A data collector or data processor or data controller shall ensure that the data is complete, accurate, up-to-date and not misleading having regard to the purpose for its collection or processing . A data subject shall ensure that the personal data given to the data collector or data processor or data controller is complete, accurate, up to date and not misleading. - 16 Verify source ↗
Data collection and processing - Correction of personal data
Data subjects may request correction or deletion of their personal data; data controllers must comply or notify and explain rejections, inform recipients of corrections, and notify the data subject of actions taken.
Section Correction of personal data Section A data subject may request a data controller to — correct or delete personal data about the data subject held by or under the control of the data controller that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully; or destroy or delete a record of personal data about the data subject held by the data controller which the controller no longer has the authority to retain. On receipt of the request, a data controller shall comply with the request. Where the data controller is not able to comply with the request under subsection (1), the data controller shall inform the data subject of the rejection, and the reasons for the rejection in writing. Where the data controller complies with the request, the data controller shall inform each person to whom the personal data has been disclosed of the correction made. The data controller shall notify the data subject of the action taken as a result of the request. - 17 Verify source ↗
Data collection and processing - Further processing to be compatible with purpose of collection
Persons processing or holding personal data must ensure further processing is compatible with the original purpose; they must consider specified factors, and further processing is allowed in specified cases such as consent, public availability, law enforcement, court proceedings, national security, or serious threats to health or safety.
Section Further processing to be compatible with purpose of collection Section For the purposes of subsection (1), a person who processes personal data under this section shall take into account — The further processing of data is considered to be compatible with the purpose of collection where — further processing is necessary - the data is used for historical, statistical or research purposes and the person responsible for the processing ensures that — Where a person holds personal data collected in connection with a specific purpose, further processing of the personal data shall only be for that specific purpose. the relationship between the purpose of the intended further processing and the purpose for which the data was collected; the nature of the data concerned; the manner in which the data has been collected; the consequences that the further processing is likely to have for the data subject ; and the contractual rights and obligations between the data subject and the person who processes the data . the data subject consents to the further processing of the information ; the data is publicly available or has been made public by the person concerned; for the prevention, detection, investigation, prosecution or punishment for an offence or breach of law; for the enforcement of a law which imposes a pecuniary penalty; for the enforcement of legislation that concerns protection of public revenue collection; for the conduct of proceedings before any court or tribunal that have commenced; for the protection of national security; or to prevent or mitigate a serious and imminent threat to public health or safety or the life or health of the data subject or another individual; the further processing is carried out solely for the purpose for which the data was collected; and that the data is not published in a form likely to reveal the identity of the data subject . - 18 Verify source ↗
Data collection and processing - Retention of records of personal data
Persons who collect personal data must not keep it longer than necessary, except for listed legal and other reasons; those who use data for decisions must retain it as required by law or to allow access; data controllers must destroy or de-identify records at the end of the retention period.
Section Retention of records of personal data Section Subject to subsections (2) and (3), a person who collects personal data shall not retain the personal data for a period longer than is necessary to achieve the purpose for which the data is collected and processed unless — Subsection (1) does not apply to personal data retained for — A person who uses personal data of a data subject to make a decision about the data subject shall — the retention of the data is required or authorised by law; the retention of the data is necessary for a lawful purpose related to a function or activity for which the data is collected or processed; the retention of the data is required by a contract between the parties to the contract; or the data subject consents to the retention of the data . the prevention, detection, investigation, prosecution or punishment of an offence or breach of law; the national security purposes; the enforcement of a law which imposes a pecuniary penalty; the enforcement of legislation relating to public revenue collection; the conduct of proceedings before any court or tribunal; or historical, statistical, or research purposes. retain the data for a period required or prescribed by law; or where no retention period is required by law, retain the data for a period which shall afford the data subject an opportunity to request access to the data . A data controller shall destroy or delete a record of personal data or de-identify the record at the expiry of the retention period. The destruction or deletion of a record of personal data shall be done in a manner that prevents its reconstruction in an intelligible form. - 19 Verify source ↗
Data collection and processing - Processing personal data outside Uganda
When a data processor or data controller based in Uganda processes or stores personal data outside Uganda, they must ensure either that the receiving country has adequate data protection or that the data subject has consented.
Section Processing personal data outside Uganda Section Where a data processor or data controller based in Uganda processes or stores personal data outside Uganda, the data processor or data controller shall ensure that— the country in which the data is processed or stored has adequate measures in place for the protection of personal data at least equivalent to the protection provided for by this Act; or the data subject has consented. - 7 Verify source ↗
Data collection and processing - Consent to collect or process personal data
A person must not collect or process personal data without the prior consent of the data subject, subject to the exceptions listed in subsection (2).
Section Consent to collect or process personal data Section Personal data may be collected or processed — where it is necessary — Subject to subsection (2), a person shall not collect or process personal data without the prior consent of the data subject . where the collection or processing is authorised or required by law; or for the proper performance of a public duty by a public body ; for national security; for the prevention, detection, investigation, prosecution or punishment of an offence or breach of law. for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract; for medical purposes; or for compliance with a legal obligation to which the data controller is subject. Except for data collected or processed under subsection (2) where a data subject objects to the collection or processing of personal data , the person who is collecting or processing the personal data shall stop the collection or processing of the personal data . - 8 Verify source ↗
Data collection and processing - Personal data relating to children
A person must not collect or process personal data relating to a child unless one of three conditions applies: prior consent of a parent/guardian/other decision-maker; necessity to comply with the law; or for research or statistical purposes.
Section Personal data relating to children Section A person shall not collect or process personal data relating to a child unless the collection or processing thereof is; carried out with the prior consent of the parent or guardian or any other person having authority to make decisions on behalf of the child; necessary to comply with the law; or for research or statistical purposes. - 9 Verify source ↗
Data collection and processing - Prohibition on collection and processing of special personal data
The provision forbids persons from collecting or processing highly sensitive personal data (religion, political opinion, sexual life, financial information, health/medical records) while allowing data collectors/processors/controllers to collect or process personal data specified in subsection (1) in several limited situations including legitimate association activities, employer legal obligations, consent, non-profit or association membership contexts; it excludes data collected under the Uganda Bureau of Statistics Act.
Section Prohibition on collection and processing of special personal data Section A data collector , data processor and data controller may collect or process personal data specified under subsection (1) where — the collection or processing of the information is for the purposes of the legitimate activities of a body or association which — A person shall not collect or process personal data which relates to the religious or philosophical beliefs, political opinion, sexual life, financial information , health status or medical records of an individual. This section does not apply to information collected under the Uganda Bureau of Statistics Act. the collection or processing of the data is in the exercise or performance of a right or an obligation conferred or imposed by law on an employer; the information is given freely and with the consent of the data subject ; or is established for non-profit purposes; or exists for political, philosophical, religious or trade union purposes; and relates to individuals who are members of the body or association or have regular contact with the body or association in connection with its purposes, and does not involve disclosure of the personal data to a third party without the consent of the data subject .
Part IV
Security of data
- 20 Verify source ↗
Security of data - Security measures
Data controllers, data collectors and data processors must secure the integrity of personal data by adopting appropriate reasonable technical and organisational measures and data controllers must identify risks, establish safeguards, verify their implementation and keep them updated; data controllers must also observe generally accepted information security practices and any specific industry or professional rules.
Section Security measures Section For the purposes of subsection (1), the data controller shall take measures to— A data controller , data collector or data processor shall secure the integrity of personal data in the possession or control of a data controller , data processor or data collector by adopting appropriate, reasonable, technical and organisational measures to prevent loss, damage, or unauthorised destruction and unlawful access to or unauthorised processing of the personal data . identify reasonably foreseeable internal and external risks to personal data under that person’s possession or control; establish and maintain appropriate safeguards against the identified risks; regularly verify that the safeguards are effectively implemented; and ensure that the safeguards are continually updated in response to new risks or deficiencies. A data controller shall observe generally accepted information security practices and procedures, and specific industry or professional rules and regulations. - 21 Verify source ↗
Security of data - Security measures relating to data processed by data processor
Data controllers must not allow a data processor to process their personal data unless the processor has established and complies with required security measures; contracts between controllers and processors must require the processor to establish and maintain confidentiality and security measures to protect data integrity.
Section Security measures relating to data processed by data processor Section A data controller shall not permit a data processor to process personal data for the data controller , unless the data processor establishes and complies with the security measures specified under this Act. A contract between a data controller and a data processor relating to processing of personal data , shall require the data processor to establish and maintain the confidentiality and security measures necessary to protect the integrity of the personal data . - 22 Verify source ↗
Security of data - Data processed by operator or authorised person
Operators and persons processing personal data for a data controller must process the data only with the controller's prior knowledge or authorisation and must treat such personal data as confidential; a data processor must not disclose the data except when required by law or in the course of discharging a duty.
Section Data processed by operator or authorised person Section An operator or a person who processes personal data on behalf of a data controller shall process the data only with the prior knowledge or authorisation of the data controller and shall treat the personal data which comes to the knowledge of the operator or other person as confidential. A data processor shall not disclose the data unless required by law, or in the course of the discharge of a duty. - 23 Verify source ↗
Security of data - Notification of data security breaches
If a data collector, processor or controller believes personal data was accessed or acquired without authorization they must immediately notify the Authority in the prescribed manner; the Authority will decide if the data subject should be notified and, when it determines notification is required, the notifier must use one of the listed methods.
Section Notification of data security breaches Section Where the Authority determines that the data collector , data processor or data controller should notify the data subject , the notification shall be made by— Where a data collector , data processor or data controller , believes that the personal data of a data subject has been accessed or acquired by an unauthorised person, the data collector , data processor or data controller , shall immediately notify the Authority in the prescribed manner, of the unauthorised access or acquisition and the remedial action taken. The Authority shall determine and notify the data controller , data collector or data processor whether the data controller , data collector or data processor should notify the data subject of the breach. registered mail to the data subject ’s last known residential or postal address; electronic mail to the data subject ’s last known electronic mail address; placement in a prominent position on the website of the responsible party; or publication in the mass media. A notification referred to in sub section (3) shall provide sufficient information relating to the breach to allow the data subject to take protective measures against the consequences of unauthorised access or acquisition of the data . Where the Authority has grounds to believe that publicity would protect a data subject who is affected by the unauthorised access or acquisition of data , the Authority shall direct the responsible party to publicise in the specified manner, the fact of the compromise to the integrity or confidentiality of the personal data .
Part V
Rights of data subjects
- 24 Verify source ↗
Rights of data subjects - Right to access personal information
Data subjects who provide proof of identity may request access to personal information; data controllers must verify identity, may refuse where disclosure would identify another individual unless exceptions apply, and must respond promptly and in any event within thirty days.
Section Right to access personal information Section A data subject who provides proof of identity may request a data controller to — Where a data controller is unable to comply with the request without disclosing data related to another individual who may be identified from the information , the data controller shall not comply with the request unless — For the purposes of subsection (4) — For the purposes of subsection (4), to determine whether it is reasonable to comply with the request without the consent of the other individual concerned, the data controller shall take into account — confirm whether or not the data controller holds personal data about that data subject ; give a description of the personal data which is held by the data controller ; provide the identity of a third party or a category of a third party who has or has had access to information . A request under this section shall be made in the prescribed form and manner. A data controller shall not comply with a request under this section unless the data controller is given information that the data controller may reasonably require to identify the person making the request and to locate the data requested by that person. the other individual consents to the disclosure of the data to the person who makes the request; it is reasonable in all the circumstances to comply with the request without the consent of the other individual; or compelled by a court order. a reference to data related to another individual includes a reference to data which identifies that individual as the source of the data requested; and another individual may be identified from the data disclosed if that individual can be identified from that data , or any other data which in the reasonable belief of the data controller are likely to be in, or come into the possession of the data subject who made the request. A data controller shall not use subsection (4) as an excuse for failing to communicate so much of the information sought that may be communicated without the disclosure of the identity of the individual concerned. The data controller may make the communication under subsection (6) by omitting or deleting the name or other identifying particulars of the other individual. any duty of confidentiality owed to the other individual; any steps taken by the data controller to seek the consent of that other individual; whether the other individual is capable of giving consent ; and any express refusal of consent by the other individual. Subject to subsection (4), a data controller shall comply with a request under this section promptly and in any event within thirty days from the date of receipt of the request. - 25 Verify source ↗
Rights of data subjects - Right to prevent processing of personal data
A data subject may give written notice at any time to a data controller or processor to require them to stop processing personal data that causes or is likely to cause unwarranted substantial damage or distress.
Section Right to prevent processing of personal data Section A data subject shall at any time by notice in writing to a data controller or data processor , require the data controller or data processor to stop processing personal data which causes or is likely to cause unwarranted substantial damage or distress to the data subject . A data controller shall within fourteen days after receipt of a notice inform the data subject in writing that the data controller has complied or intends to comply with the notice of the data subject , or of the reasons for non-compliance. Where the data controller gives reasons for non-compliance, a copy of the notice required by subsection (2) shall be given to the Authority within fourteen days. Where the Authority is satisfied that the data subject is justified, the Authority shall direct the data controller to comply within seven days. This section does not apply to data collected or processed in accordance with section 7 (2). - 26 Verify source ↗
Rights of data subjects - Right to prevent processing of personal data for direct marketing
Data subjects may, by written notice, require a data controller to stop processing their personal data for direct marketing; the data controller must inform the data subject within 14 days whether it has complied or will comply or the reasons for non‑compliance; the Authority may be given a copy of the notice and may direct compliance if satisfied.
Section Right to prevent processing of personal data for direct marketing Section A data subject may by notice in writing to a data controller , require the data controller to stop processing his or her personal data for purposes of direct marketing. A data controller shall within fourteen days after receipt of the notice inform the data subject in writing that the data controller has complied or intends to comply with the notice of the data subject , or of the reasons for non-compliance. Subject to sub-section (1) a data subject may enter into agreement with a data controller for purposes of using or processing his or her personal data for pecuniary benefits. Where the data controller gives reasons for non-compliance, a copy of the notice required by subsection (2) shall be given to the Authority within the time specified in that subsection. Where the Authority is satisfied that the notice in subsection (1) is justified, the Authority may direct the data controller to comply. In this section “direct marketing” includes the communication by whatever means of any advertising or marketing material which is directed at an individual. - 27 Verify source ↗
Rights of data subjects - Rights in relation to automated decision-taking
Section Rights in relation to automated decision-taking Section Without prejudice to subsection (1), where a decision which significantly affects a data subject is based solely on automated processing — This section does not apply to a
Section Rights in relation to automated decision-taking Section Without prejudice to subsection (1), where a decision which significantly affects a data subject is based solely on automated processing — This section does not apply to a decision made — A data subject may by notice in writing to a data controller require the data controller to ensure that any decision taken by or on behalf of the data controller which significantly affects that data subject is not based solely on the processing by automatic means of personal data in respect of that data subject . the data controller shall as soon as reasonably practicable notify the data subject that the decision was taken on that basis, and the data subject is entitled, by notice in writing to require the data controller to reconsider the decision within twenty-one days after receipt of the notification from the data controller . The data controller shall, within twenty-one days after receipt of the notice, inform the data subject in writing of the steps that the data controller has taken to comply with the notice. in the course of considering whether to enter into a contract with the data subject ; with a view to entering into the contract; in the course of the performance of the contract; or for a purpose authorised or required by or under any law. Where the data subject is not satisfied with the decision of the data controller in subsection (3), the data subject shall complain in writing to the Authority within fourteen days. Where the Authority is satisfied on a complaint by a data subject that the data controller has failed to comply, the Authority shall order the data controller to comply within seven days. - 28 Verify source ↗
Rights of data subjects - Rectification, blocking, erasure and destruction of personal data
If the Authority finds personal data about a data subject is inaccurate after a complaint, it may order the data controller to rectify, update, block, erase or destroy the data; and when data has been changed, the data controller must notify third parties previously disclosed to.
Section Rectification, blocking, erasure and destruction of personal data Section Where the Authority is satisfied on a complaint of a data subject that personal data on that data subject is inaccurate, the Authority may order the data controller to rectify, update, block, erase, or destroy the data . Subsection (1) applies whether the data is an accurate record of information received or obtained by the data controller from the data subject or a third party . Where the data is an inaccurate record of the information , the Authority may direct the data controller to update the statement of the true facts which the Authority considers appropriate. Where the data complained of has been rectified, blocked, updated, erased or destroyed, the data controller is required to notify third parties to whom the data has been previously disclosed of the rectification, blocking, updated, erasure or destruction.
Part VI
Data protection register
- 29 Verify source ↗
Data protection register - Data protection register
The Authority must keep and maintain a data protection register and register persons and bodies who collect or process personal data; applications to register by data controllers or other persons must be made in the prescribed manner.
Section Data protection register Section The Authority shall keep and maintain a data protection register. The Authority shall register in the data protection register, every person, institution or public body collecting or processing personal data and the purpose for which the personal data is collected or processed. An application by a data controller or other person to register shall be made in the prescribed manner. - 30 Verify source ↗
Data protection register - Access to register by the public
The Authority must make the information in the Data Protection Register available for inspection by any person.
Section Access to register by the public Section The Authority shall make the information contained in the Data Protection Register available for inspection by any person.
Part VII
Complaints
- 31 Verify source ↗
Complaints - Complaints against breach and non-compliance
A data subject or any person who believes their rights are infringed may make a complaint to the Authority; a data collector, data processor or data controller may in writing complain to the Authority about violations or non-compliance.
Section Complaints against breach and non-compliance Section A data subject or any person who believes that a data collector , data processor or data controller is infringing upon their rights or is in violation of this Act may make a compliant in the prescribed manner to the Authority . A data collector , data processor or data controller may in writing make a complaint to the Authority about any violation or non-compliance with this Act. - 32 Verify source ↗
Complaints - Authority to investigate complaints
The Authority must investigate every complaint made under this Part and may direct data collectors, processors or controllers to remedy breaches or take actions to restore data integrity or data subject rights.
Section Authority to investigate complaints Section The Authority shall investigate every compliant made under this Part and may direct a data collector , data processor or data controller to remedy any breach or take such action as the Authority may specify to restore the integrity of data collected, processed or held by the data collector , data processor or data controller or the rights of the data subject . - 33 Verify source ↗
Complaints - Compensation for failure to comply with this Act
A data subject who suffers damage or distress caused by a data controller, processor or collector breaching the Act may apply to a court for compensation; in proceedings the person can defend by proving they took reasonable care to comply with the Act.
Section Compensation for failure to comply with this Act Section Where a data subject suffers damage or distress through the contravention by a data controller , data processor or data collector of the requirements of this Act, that data subject is entitled to apply to a Court of competent jurisdiction for compensation from the data collector , data processor or data controller for the damage or distress. In proceedings against a person under this section, it is a defence to prove that the person took reasonable care in all the circumstances to comply with the requirements of this Act. - 34 Verify source ↗
Complaints - Appeals
A person aggrieved by a decision of the Authority may appeal to the Minister.
Section Appeals Section A person aggrieved by a decision of the Authority under this Act may appeal to the Minister . The appeal shall be made within thirty days from the date of notice of the decision. A copy of the appeal shall be provided to the Authority .
Part VIII
Offences
- 35 Verify source ↗
Offences - Unlawful obtaining or disclosing of personal data
A person must not unlawfully obtain, disclose or procure disclosure of personal data held or processed by a data collector, data controller or data processor; contravention is an offence punishable by a fine up to 240 currency points or up to ten years' imprisonment or both.
Section Unlawful obtaining or disclosing of personal data Section A person shall not unlawfully obtain, disclose or procure the disclosure to another person of personal data held or processed by a data collector , data controller or data processor . A person who contravenes this section commits an offence and is liable on conviction to a fine not exceeding two hundred and forty currency points or imprisonment for ten years or both. - 36 Verify source ↗
Offences - Unlawful destruction, deletion, concealment or alteration of personal data
A person must not unlawfully destroy, delete, mislead, conceal or alter personal data.
Section Unlawful destruction, deletion, concealment or alteration of personal data Section A person shall not unlawfully destroy, delete, mislead, conceal or alter personal data . A person who contravenes this section commits an offence and is liable on conviction to a fine not less than two hundred and forty currency points or imprisonment not exceeding ten years or both. - 37 Verify source ↗
Offences - Sale of personal data
A person must not sell or offer for sale another person's personal data; violating this is an offence punishable by a fine (not exceeding two hundred and forty five currency points), imprisonment (not exceeding ten years), or both.
Section Sale of personal data Section A person shall not sell or offer for sale personal data of any person. A person who contravenes subsection (1) commits an offence and is liable on conviction to a fine not exceeding two hundred and forty five currency points or imprisonment not exceeding ten years or both. - 38 Verify source ↗
Offences - Offences by corporations
If an offence under sections 35, 36 or 37 is committed by a corporation, the corporation and any officer who knowingly and willfully authorises or permits it commits the offence; a court that convicts may order the corporation to pay a fine not exceeding two percent of the corporation's annual gross turnover, and the court must take into account the gravity and impact of the offence when deciding the fine.
Section Offences by corporations Section Where an offence under sections 35 , 36 and 37 is committed by a corporation, the corporation and every officer of the corporation who knowingly and willfully authorises or permits the contravention commits the offence. A court which convicts a person under subsection (1) may, in addition to the punishment order the corporation , pay a fine not exceeding two percent of the corporation ’s annual gross turnover. A court shall take into consideration the gravity of the offence under subsection (1) and its impact in determining the fine to impose under subsection (2). - 39 Verify source ↗
Offences - Regulations
The Minister may make regulations by statutory instrument, after consulting the Authority, on matters needed to give effect to the Act including retention periods for personal data.
Section Regulations Section The Minister may, after consultation with the Authority by statutory instrument make regulations for — any matter which is required to be prescribed; any administrative or procedural matter which is necessary to give effect to this Act; the retention period of personal data ; or any matter which is necessary and expedient to give effect to this Act. - 40 Verify source ↗
Offences - Power of the Minister to amend Schedule
The Minister may amend the Schedule, subject to Cabinet approval and by statutory instrument.
Section Power of the Minister to amend Schedule Section The Minister may, with the approval of Cabinet, by statutory instrument, amend the Schedule.
Provision text is displayed from LexChat’s stored statute record. Use the official source links to verify amendments, commencement, and current legal force.
Ask AI about this statute
Data Protection and Privacy Act
Sign in to ask AI about this statute
Sign in to start authenticated, citation-grounded statute research.
Sign inLexChat organizes source-backed legal information for research. Verify amendments, commencement, and current legal force with the official publisher before relying on it.