Policy pillar deep dive · dataset policy-2026-Q3-r16
Data protection
Controller/processor registration, processing preconditions and penalty regimes.
- Coverage
- 89% verified
- Claims
- 19 claims
- Sources
- 19 sources
- Countries covered
- 4/4 markets
- Structured gaps
- 0 gaps
Coverage across the four markets
Uganda UG
83%
5 verified · 1 partial · 0 other
Rwanda RW
80%
4 verified · 1 partial · 0 other
Tanzania TZ
100%
6 verified · 0 partial · 0 other
Kenya KE
100%
2 verified · 0 partial · 0 other
Open the same tiles in the coverage matrix to compare this pillar against every other pillar.
Claims & evidence trails
Uganda UG
6 claims- VerifiedUG-DP-C1
Uganda's Data Protection and Privacy Act, 2019 (now revised as Cap. 97) was assented to on 25 February 2019 and commenced on 3 May 2019, with its implementing Regulations effective 12 March 2021.
Official depository metadata (ULII) and DLA Piper handbook agree. Conflict resolved: Legal500 states commencement 1 March 2019 - rejected as a secondary-source error; the gazette date 3 May 2019 controls.
View evidence trail · 2 sources ▾
- ulii.org — Uganda Legal Information Institute - Data Protection and Privacy Act, Cap. 97 (official depository metadata)T1 · snippetData Protection and Privacy Act. Chapter 97. Published in Uganda Gazette 21 on 3 May 2019; Assented to on 25 February 2019; Commenced on 3 May 2019.
- DLA Piper — DLA Piper Global Data Protection Laws of the World - Uganda chapterT3 · snippetThe Data Protection and Privacy Act commenced on 3 May 2019 while the Regulations took effect on 12 March 2021.
- VerifiedUG-DP-C2
The Act applies extraterritorially: it covers a person, institution or public body outside Uganda who collects, processes, holds or uses personal data relating to Ugandan citizens (s.1).
CIPESA quotes the statutory text; DLA Piper reports the PDPO's own confirmation. Statute text capture-pending (ULII gate) - state self-upgrades on full-text capture.
View evidence trail · 2 sources ▾
- Collaboration on International ICT Policy for East and Southern Africa (CIPESA) — CIPESA: Ugandan Regulator Finds Google in Breach of Country's Data Protection Law, Orders Local RegistrationT2 · capturedIn a July 18, 2025 decision, Uganda's Personal Data Protection Office (PDPO) found Google LLC in breach of the country's data protection law and ordered the global tech giant to register with the local data protection office within 30 days... contravened section 29 of the Data Protection and Privacy Act... in breach of section 19 of the Act.
- DLA Piper — DLA Piper Privacy Matters: Uganda - Data protection Regulator Clarifies Compliance Requirements for Offshore EntitiesT3 · capturedThe PDPO confirmed that the obligations under Uganda's data protection law "attach not only to entities physically present in Uganda but to any entity handling personal data of Ugandan citizens, including those established abroad"... Every data collector, processor or controller is legally required to register with the PDPO and renew its registration every year.
- VerifiedUG-DP-C3
Every data collector, processor or controller must register with the Personal Data Protection Office (s.29) and renew registration annually; the duty applies to foreign entities handling Ugandans' personal data until an exemption is gazetted.
Duty-level claim verified by two independent reports of the PDPO decision and the statute. Fee/portal mechanics deliberately split into UG-DP-C4 (weaker evidence).
View evidence trail · 2 sources ▾
- Collaboration on International ICT Policy for East and Southern Africa (CIPESA) — CIPESA: Ugandan Regulator Finds Google in Breach of Country's Data Protection Law, Orders Local RegistrationT2 · capturedIn a July 18, 2025 decision, Uganda's Personal Data Protection Office (PDPO) found Google LLC in breach of the country's data protection law and ordered the global tech giant to register with the local data protection office within 30 days... contravened section 29 of the Data Protection and Privacy Act... in breach of section 19 of the Act.
- DLA Piper — DLA Piper Privacy Matters: Uganda - Data protection Regulator Clarifies Compliance Requirements for Offshore EntitiesT3 · capturedThe PDPO confirmed that the obligations under Uganda's data protection law "attach not only to entities physically present in Uganda but to any entity handling personal data of Ugandan citizens, including those established abroad"... Every data collector, processor or controller is legally required to register with the PDPO and renew its registration every year.
- PartialUG-DP-C4
Registration is completed online via the PDPO portal (Form 2 application plus Form 3 cross-border undertaking), fee UGX 100,000, typically 4-7 working days for initial registration.
Single Tier-3 source; the PDPO portal itself (pdpo.go.ug/register) was unreachable on 2026-09-22. Verify fees/SLA against the portal or the Regulations before citing operationally. Editorial ruling 2026-09-22 (delegated): kept split from UG-DP-C3 - the legal duty and the operational mechanics have different evidence bases and upgrade paths; folding would misdescribe the duty's verified position.
View evidence trail · 2 sources ▾
- DLA Piper — DLA Piper Privacy Matters: Uganda - Data protection Regulator Clarifies Compliance Requirements for Offshore EntitiesT3 · capturedThe PDPO confirmed that the obligations under Uganda's data protection law "attach not only to entities physically present in Uganda but to any entity handling personal data of Ugandan citizens, including those established abroad"... Every data collector, processor or controller is legally required to register with the PDPO and renew its registration every year.
- Personal Data Protection Office (PDPO), Uganda — PDPO online registration portal (pdpo.go.ug/register)T1 · captured
- VerifiedUG-DP-C5
Cross-border transfer or storage of personal data outside Uganda requires either data-subject consent or adequate protection in the recipient country at least equivalent to the Act (s.19); no advance approval per transfer is required, but records of the legal basis and safeguards must be maintained and produced on audit.
s.19 text quoted by CIPESA; the no-pre-approval clarification is the PDPO's own position reported by DLA Piper. Material to colocation operators serving cross-border workloads (e.g. Kampala-Nairobi replication paths).
View evidence trail · 2 sources ▾
- Collaboration on International ICT Policy for East and Southern Africa (CIPESA) — CIPESA: Ugandan Regulator Finds Google in Breach of Country's Data Protection Law, Orders Local RegistrationT2 · capturedIn a July 18, 2025 decision, Uganda's Personal Data Protection Office (PDPO) found Google LLC in breach of the country's data protection law and ordered the global tech giant to register with the local data protection office within 30 days... contravened section 29 of the Data Protection and Privacy Act... in breach of section 19 of the Act.
- DLA Piper — DLA Piper Privacy Matters: Uganda - Data protection Regulator Clarifies Compliance Requirements for Offshore EntitiesT3 · capturedThe PDPO confirmed that the obligations under Uganda's data protection law "attach not only to entities physically present in Uganda but to any entity handling personal data of Ugandan citizens, including those established abroad"... Every data collector, processor or controller is legally required to register with the PDPO and renew its registration every year.
- VerifiedUG-DP-C6
In a decision of 18 July 2025 (Ssekamwa Frank & 3 Others v Google LLC, Complaint No. 08/11/24/6683), the PDPO found Google LLC in breach of ss.29 and 19 and ordered registration, designation of a data protection officer, and production of a cross-border transfer compliance framework within 30 days - confirming the Act reaches foreign entities with no physical presence in Uganda.
Primary instrument (the decision itself) is capture-pending - not published on the regulator site; two independent reports agree on the findings and the complaint number. If either report is later contradicted, this claim degrades.
View evidence trail · 3 sources ▾
- Personal Data Protection Office (PDPO), Uganda — PDPO decision, Ssekamwa Frank & 3 Others v Google LLC, Complaint No. 08/11/24/6683 (18 July 2025)T1 · capture-pending
- Collaboration on International ICT Policy for East and Southern Africa (CIPESA) — CIPESA: Ugandan Regulator Finds Google in Breach of Country's Data Protection Law, Orders Local RegistrationT2 · capturedIn a July 18, 2025 decision, Uganda's Personal Data Protection Office (PDPO) found Google LLC in breach of the country's data protection law and ordered the global tech giant to register with the local data protection office within 30 days... contravened section 29 of the Data Protection and Privacy Act... in breach of section 19 of the Act.
- DLA Piper — DLA Piper Privacy Matters: Uganda - Data protection Regulator Clarifies Compliance Requirements for Offshore EntitiesT3 · capturedThe PDPO confirmed that the obligations under Uganda's data protection law "attach not only to entities physically present in Uganda but to any entity handling personal data of Ugandan citizens, including those established abroad"... Every data collector, processor or controller is legally required to register with the PDPO and renew its registration every year.
Rwanda RW
5 claims- VerifiedRW-DP-C1
Rwanda's data protection law is Law No 058/2021 of 13/10/2021 relating to the protection of personal data and privacy, officially gazetted on 15 October 2021.
Official gazette PDF captured (82pp bilingual, header 'Official Gazette n° Special of 15/10/2021'); RISA page and DataGuidance corroborate.
View evidence trail · 3 sources ▾
- Republic of Rwanda (Official Gazette n° Special of 15/10/2021), hosted by RISA — Law No 058/2021 of 13/10/2021 relating to the protection of personal data and privacy (official gazette text, bilingual PDF, 82pp, via RISA)T1 · capturedArticle 48: ... share or transfer personal data to a third party outside Rwanda if: 1° he or she has obtained authorisation from the supervisory authority after providing proof of appropriate safeguards ... 2° the data subject has given his or her consent; 3° the transfer is necessary ... Article 50: The data controller or the data processor stores personal data in Rwanda. However, the storage of personal data outside Rwanda is only permitted if ... holds a valid registration certificate authorising him or her to store personal data outside Rwanda, which is issued by the supervisory authority.
- Rwanda Information Society Authority (RISA) — RISA - Data Protection and Privacy Law (official page with article summaries)T1 · capturedOn October 15th 2021, Law No 058/2021 of 13/10/2021 relating to the protection of personal data and privacy was officially gazetted. The law protects personal data and ensures privacy of individual users.
- DataGuidance (OneTrust) — DataGuidance - Rwanda jurisdiction chapterT3 · capturedThe National Cyber Security Authority (NCSA), as the designated supervisory authority under the Data Protection Law, has been active in clarifying compliance ... published on October 15, 2021, in the Rwanda Official Gazette
- VerifiedRW-DP-C2
A person who intends to be a data controller or a data processor must register with the supervisory authority (Art. 29).
Verbatim captured. Practice detail: registration administered through the NCSA/DPO; transitional compliance window ended 15 October 2023 (RW-DP-C6).
View evidence trail · 1 source ▾
- Republic of Rwanda (Official Gazette n° Special of 15/10/2021), hosted by RISA — Law No 058/2021 of 13/10/2021 relating to the protection of personal data and privacy (official gazette text, bilingual PDF, 82pp, via RISA)T1 · capturedArticle 48: ... share or transfer personal data to a third party outside Rwanda if: 1° he or she has obtained authorisation from the supervisory authority after providing proof of appropriate safeguards ... 2° the data subject has given his or her consent; 3° the transfer is necessary ... Article 50: The data controller or the data processor stores personal data in Rwanda. However, the storage of personal data outside Rwanda is only permitted if ... holds a valid registration certificate authorising him or her to store personal data outside Rwanda, which is issued by the supervisory authority.
- VerifiedRW-DP-C3
Cross-border sharing or transfer of personal data outside Rwanda is permitted only if the controller/processor has (1) obtained authorisation from the supervisory authority after providing proof of appropriate safeguards, or (2) the data subject's consent, or (3) necessity grounds (contract performance, public interest, legal claims, vital interests) (Art. 48).
Verbatim captured from the official gazette text. MATERIAL DIFFERENCE vs Uganda: Uganda's PDPO confirmed no advance approval is required (records-based regime; UG-DP-C5). Rwanda requires prior authorisation as the first branch.
View evidence trail · 1 source ▾
- Republic of Rwanda (Official Gazette n° Special of 15/10/2021), hosted by RISA — Law No 058/2021 of 13/10/2021 relating to the protection of personal data and privacy (official gazette text, bilingual PDF, 82pp, via RISA)T1 · capturedArticle 48: ... share or transfer personal data to a third party outside Rwanda if: 1° he or she has obtained authorisation from the supervisory authority after providing proof of appropriate safeguards ... 2° the data subject has given his or her consent; 3° the transfer is necessary ... Article 50: The data controller or the data processor stores personal data in Rwanda. However, the storage of personal data outside Rwanda is only permitted if ... holds a valid registration certificate authorising him or her to store personal data outside Rwanda, which is issued by the supervisory authority.
- VerifiedRW-DP-C5
The National Cyber Security Authority (NCSA) is the designated supervisory authority under the Data Protection Law, and the Data Protection and Privacy Office (DPO) administers registration and authorisations under it.
DataGuidance names NCSA as designated supervisory authority; the official DPO site shows registration 'with NCSA' and the authorisation services. The law text itself uses the generic term 'supervisory authority'.
View evidence trail · 2 sources ▾
- DataGuidance (OneTrust) — DataGuidance - Rwanda jurisdiction chapterT3 · capturedThe National Cyber Security Authority (NCSA), as the designated supervisory authority under the Data Protection Law, has been active in clarifying compliance ... published on October 15, 2021, in the Rwanda Official Gazette
- Data Protection and Privacy Office (Rwanda) — Data Protection & Privacy Office (DPO) - official services siteT1 · capturedServices: Apply as a Data Controller ... Apply as a Data Processor ... Authorization to Transfer Outside Rwanda ... Authorization to Store Outside Rwanda ... What to do after registering with NCSA
- PartialRW-DP-C6
The transitional period for data controller/processor registration ended on 15 October 2023, after which registration became mandatory without the transition window.
Transition-deadline fact (15 Oct 2023) remains snippet-sourced (NCSA T1 snippet + DLA Piper T3). Capture mission 2026-09-22 added the operative T1: DPO registration services page confirms mandatory controller/processor registration is actively operated. Upgrade path: capture an NCSA/DPO announcement or gazette notice restating the transition-end date.
View evidence trail · 3 sources ▾
- National Cyber Security Authority (Rwanda) — NCSA/DPO - Data Protection Office guidance pageT1 · snippetPut in place a register of data controllers and data processors. With the transitional period ending on 15th October 2023 ...
- dpo.gov.rw — Rwanda Data Protection and Privacy Office - Registration services page (apply as controller/processor; transfer and storage authorisations)T1 · capturedRwanda Data Protection and Privacy Office - Services: Apply as a Data Controller; Apply as a Data Processor; Authorization to Transfer Outside Rwanda; Authorization to Store Outside Rwanda. What to do after registering with NCSA.
- DLA Piper Africa — DLA Piper Africa - Deadline for mandatory registration as a data controller or processor in RwandaT3 · snippetDeadline for mandatory registration as a data controller or processor to close on 15 October 2023
Tanzania TZ
6 claims- VerifiedTZ-DP-C1
Tanzania's data protection law is the Personal Data Protection Act, 2022 (Act No 11 of 2022, GN No 395B), which establishes the Personal Data Protection Commission as a body corporate; regulator service pages now cite it as Chapter 44 (revised laws).
Full official Act PDF captured from the regulator itself (42pp): '6.-(1) There is established a Commission to be known as the Personal Data Protection Commission.'
View evidence trail · 2 sources ▾
- Personal Data Protection Commission (Tanzania) — Personal Data Protection Act, 2022 (Act No 11 of 2022, GN No 395B) - official PDF, 42ppT1 · captured14.-(1) A person shall not collect or process personal data without being registered as a data controller or a data processor under this Act. ... 31.-(1) The Commission may, subject to the provisions of this Act, prohibit the transfer of personal data to a place outside the country. ... 32: transfer of personal data to countries outside the United Republic is not authorised (exceptions enumerated).
- Personal Data Protection Commission (Tanzania) — PDPC - The Personal Data Protection Act, 2022 (official instrument page)T1 · capturedTHE PERSONAL DATA PROTECTION ACT, 2022 ... (page hosting the official Act PDF, CHAPTER 44 references on regulator service pages).
- VerifiedTZ-DP-C2
Registration is a strict precondition for processing: 'A person shall not collect or process personal data without being registered as a data controller or a data processor under this Act' (s.14(1)).
Verbatim from the captured official PDF. Directly operator-material: a Tanzanian data centre's processing activities fall inside this duty.
View evidence trail · 1 source ▾
- Personal Data Protection Commission (Tanzania) — Personal Data Protection Act, 2022 (Act No 11 of 2022, GN No 395B) - official PDF, 42ppT1 · captured14.-(1) A person shall not collect or process personal data without being registered as a data controller or a data processor under this Act. ... 31.-(1) The Commission may, subject to the provisions of this Act, prohibit the transfer of personal data to a place outside the country. ... 32: transfer of personal data to countries outside the United Republic is not authorised (exceptions enumerated).
- VerifiedTZ-DP-C3
Registration mechanics (Regulations GN 449C): application on Form No. 1 with fees per the Second Schedule; the Commission verifies within seven days; rejection must be notified with reasons within fourteen days; registration is valid for five years; renewal is on Form No. 3, submitted within three months before expiry.
Verbatim captured (Regs 4-8).
View evidence trail · 1 source ▾
- Personal Data Protection Commission (Tanzania) — Personal Data Protection (Personal Data Collection and Processing) Regulations, 2023 (GN No 449C) - official PDF, 38ppT1 · capturedReg. 4: application for registration using Form No. 1 ... pay the fees specified in the Second Schedule. Reg. 5: verify within seven days. Reg. 6: rejection reasons within fourteen days. Reg. 7: registration valid for five years. Reg. 8: renewal Form No. 3, three months before expiry. Second Schedule: Large-scale (100+ employees, turnover above TZS 500,000,000) registration fee TZS 1,000,000.00; renewal TZS 500,000.00.
- VerifiedTZ-DP-C4
Registration fees are tiered by scale (Second Schedule, TZS): small-scale (1-49 employees, turnover below TZS 100M) TZS 100,000 once / 50,000 renewal; medium (50-99 employees, TZS 100-500M) 200,000 / 150,000; large-scale (100+ employees, turnover above TZS 500M) 1,000,000 / 500,000 - renewal after every 5 years.
Fee table verbatim captured. A typical commercial DC operator registers at the large-scale band.
View evidence trail · 1 source ▾
- Personal Data Protection Commission (Tanzania) — Personal Data Protection (Personal Data Collection and Processing) Regulations, 2023 (GN No 449C) - official PDF, 38ppT1 · capturedReg. 4: application for registration using Form No. 1 ... pay the fees specified in the Second Schedule. Reg. 5: verify within seven days. Reg. 6: rejection reasons within fourteen days. Reg. 7: registration valid for five years. Reg. 8: renewal Form No. 3, three months before expiry. Second Schedule: Large-scale (100+ employees, turnover above TZS 500,000,000) registration fee TZS 1,000,000.00; renewal TZS 500,000.00.
- VerifiedTZ-DP-C5
Transfers to states with adequate protection (s.31): the Commission may prohibit transfer of personal data to a place outside the country; transfers to an adequate legal framework require necessity, the recipient to ensure safeguards, and a provisional evaluation of necessity by the controller.
Verbatim captured.
View evidence trail · 1 source ▾
- Personal Data Protection Commission (Tanzania) — Personal Data Protection Act, 2022 (Act No 11 of 2022, GN No 395B) - official PDF, 42ppT1 · captured14.-(1) A person shall not collect or process personal data without being registered as a data controller or a data processor under this Act. ... 31.-(1) The Commission may, subject to the provisions of this Act, prohibit the transfer of personal data to a place outside the country. ... 32: transfer of personal data to countries outside the United Republic is not authorised (exceptions enumerated).
- VerifiedTZ-DP-C7
Penalty scale (Part VII): for offence classes such as unlawful disclosure, destruction, deletion, concealment or alteration of personal data, an individual is liable to a fine of TZS 100,000 to 20,000,000 or imprisonment up to ten years, and a company or corporation to a fine of TZS 1,000,000 to 5,000,000,000; registration-related false information carries TZS 100,000 to 5,000,000 or up to two years.
Verbatim captured (ss.60-61 and s.19/s.63 cross-reference). The TZS 5 billion corporate ceiling is among the region's sharpest exposure figures.
View evidence trail · 1 source ▾
- Personal Data Protection Commission (Tanzania) — Personal Data Protection Act, 2022 (Act No 11 of 2022, GN No 395B) - official PDF, 42ppT1 · captured14.-(1) A person shall not collect or process personal data without being registered as a data controller or a data processor under this Act. ... 31.-(1) The Commission may, subject to the provisions of this Act, prohibit the transfer of personal data to a place outside the country. ... 32: transfer of personal data to countries outside the United Republic is not authorised (exceptions enumerated).
Kenya KE
2 claims- VerifiedKE-DP-C1
Kenya's data protection law is the Data Protection Act, 2019, and the Office of the Data Protection Commissioner (ODPC) is its supervisory authority, with the Act applying to data controllers and processors and conferring rights on data subjects.
Regulator's own site (T1 captured) states the DPA's scope and the ODPC's role; DLA Piper global guide (T3) corroborates. Act full text pending (Kenya Law JS shell) - section-level citations upgrade on capture.
View evidence trail · 2 sources ▾
- odpc.go.ke — Office of the Data Protection Commissioner (Kenya) - site (DPA scope, registration gateway)T1 · capturedThe Kenya Data Protection Act (DPA) applies to data controllers and processors and provides data subjects with certain rights ... Register as a Data Handler. Data Controller: A person or entity that...
- DLA Piper — DLA Piper Data Protection Laws of the World - Kenya chapter (country profiles landing)T3 · snippetData Protection Laws of the World ... Kenya Kosovo Kuwait ... (country index captured; Kenya chapter content not rendered in text extraction).
- VerifiedKE-DP-C2
Registration with the ODPC is mandatory for data controllers and processors, and the ODPC operates a live public register of registered data handlers showing registration numbers, handler type, county and Active/Expired status.
Two T1 captures from the regulator: the 'Register as a Data Handler' gateway plus the live register (57k chars of rows, INST-... numbers). Registration regime demonstrably operated, not merely enacted.
View evidence trail · 2 sources ▾
- odpc.go.ke — Office of the Data Protection Commissioner (Kenya) - site (DPA scope, registration gateway)T1 · capturedThe Kenya Data Protection Act (DPA) applies to data controllers and processors and provides data subjects with certain rights ... Register as a Data Handler. Data Controller: A person or entity that...
- odpc.go.ke — ODPC - Registered Data Handlers public register (live search: name, type, registration number, county, status)T1 · capturedREGISTRATION STATUS OF DATA HANDLERS - Active Data Handlers ... # | Data Handler Name | Data Handler Type | Registration Number | County | Status. Example rows: 254 BREWING COMPANY LIMITED, Data Controller, INST-..., KIAMBU, Kenya, Active.
Sources behind this pillar
- T1Data Protection and Privacy Office (Rwanda) — Data Protection & Privacy Office (DPO) - official services siteRegulator website · captured · dpo-gov-rw
- T1dpo.gov.rw — Rwanda Data Protection and Privacy Office - Registration services page (apply as controller/processor; transfer and storage authorisations)Regulator service page · captured · dpo-rw-registration-page
- T1National Cyber Security Authority (Rwanda) — NCSA/DPO - Data Protection Office guidance pageRegulator website · snippet · cyber-gov-dpo
- T1odpc.go.ke — Office of the Data Protection Commissioner (Kenya) - site (DPA scope, registration gateway)Regulator official site · captured · odpc-home
- T1odpc.go.ke — ODPC - Registered Data Handlers public register (live search: name, type, registration number, county, status)Regulator public register · captured · odpc-handlers-register
- T1Personal Data Protection Commission (Tanzania) — Personal Data Protection Act, 2022 (Act No 11 of 2022, GN No 395B) - official PDF, 42ppStatute (full text captured) · captured · pdpc-act-pdf
- T1Personal Data Protection Commission (Tanzania) — PDPC - The Personal Data Protection Act, 2022 (official instrument page)Regulator website · captured · pdpc-act-page
- T1Personal Data Protection Commission (Tanzania) — Personal Data Protection (Personal Data Collection and Processing) Regulations, 2023 (GN No 449C) - official PDF, 38ppRegulations (full text captured) · captured · pdpc-regs-pdf
- T1Personal Data Protection Office (PDPO), Uganda — PDPO online registration portal (pdpo.go.ug/register)Regulator portal · captured · pdpo-register-portal
- T1Personal Data Protection Office (PDPO), Uganda — PDPO decision, Ssekamwa Frank & 3 Others v Google LLC, Complaint No. 08/11/24/6683 (18 July 2025)Regulator decision · capture-pending · pdpo-decision-google-2025
- T1Republic of Rwanda (Official Gazette n° Special of 15/10/2021), hosted by RISA — Law No 058/2021 of 13/10/2021 relating to the protection of personal data and privacy (official gazette text, bilingual PDF, 82pp, via RISA)Statute (full text captured) · captured · risa-law-058-2021
- T1Rwanda Information Society Authority (RISA) — RISA - Data Protection and Privacy Law (official page with article summaries)Government agency website · captured · risa-dp-page
- T1ulii.org — Uganda Legal Information Institute - Data Protection and Privacy Act, Cap. 97 (official depository metadata)Official law depository · snippet · ulii-dppa-metadata
- T2Collaboration on International ICT Policy for East and Southern Africa (CIPESA) — CIPESA: Ugandan Regulator Finds Google in Breach of Country's Data Protection Law, Orders Local RegistrationCivil-society policy analysis (quotes statute and decision) · captured · cipesa-google-decision
- T3DataGuidance (OneTrust) — DataGuidance - Rwanda jurisdiction chapterCommercial legal research platform · captured · dataguidance-rwanda
- T3DLA Piper — DLA Piper Global Data Protection Laws of the World - Uganda chapterInternational law firm handbook · snippet · dlapiper-handbook-uganda
- T3DLA Piper — DLA Piper Privacy Matters: Uganda - Data protection Regulator Clarifies Compliance Requirements for Offshore EntitiesInternational law firm analysis (quotes decision and registration process) · captured · dlapiper-pm-offshore
- T3DLA Piper — DLA Piper Data Protection Laws of the World - Kenya chapter (country profiles landing)Law firm global guide · snippet · dlapiper-dataprotection-ke
- T3DLA Piper Africa — DLA Piper Africa - Deadline for mandatory registration as a data controller or processor in RwandaLaw firm briefing · snippet · dlapiper-africa-rw-deadline
Structured gaps
No structured gaps — every market has researched coverage for this pillar.
policy-2026-Q3-r16 · 19 claims in this pillar · 19 sources · editorial gate: EDITORIAL REVIEW COMPLETE (Uganda, Rwanda, Tanzania, Kenya - all four country pipelines approved for publication)