Verbatim · Section 20(1)
A data controller, data collector or data processor shall secure the integrity
of personal data in the possession or control of a data controller, data
processor or data collector by adopting appropriate, reasonable, technical
and organisational measures to prevent loss, damage, or unauthorised destruction
and unlawful access to or unauthorised processing of the personal data.
The Data Protection and Privacy Act, 2019 — No. 9 of 2019
Section 20(1) · Republic of Uganda
Enforced by the Personal Data Protection Office under NITA-U
Who it applies to
Every public or private organisation in Uganda that collects, processes, holds,
or uses personal data. The Act is also extraterritorial — it
applies to organisations outside Uganda that handle personal data of Ugandan
citizens.
What "organisational measures" means
Section 20(2) sets out the obligations underneath the standard: identify
foreseeable internal and external risks, and establish and
maintain appropriate safeguards. The Data Protection and Privacy
Regulations, 2021 make staff training an enumerated safeguard.
Who enforces it
The Personal Data Protection Office (PDPO), established under
the National Information Technology Authority, Uganda (NITA-U), has
investigation, audit, and enforcement powers. Breach notifications flow through
this office.