Data Protection and Privacy Act s. 27 — notice-based right against solely-automated decisions, an automatic duty to notify and reconsider on a twenty-one-day clock, and a fourteen-day route to the regulator
Binds Data controllers within the scope of s. 1, which applies the Act to a person, institution or public body collecting, processing, holding or using personal data within Uganda, and to a person outside Uganda who collects, processes, holds or uses personal data relating to Ugandan citizens. “Authority” in s. 27(5) is the National Information Technology Authority — Uganda (NITA-U); the Personal Data Protection Office established by s. 4 sits within it and is charged by s. 5 with overseeing implementation and enforcement of the Act. Registration is a standing precondition of processing: s. 29 requires the Authority to register every person, institution or public body collecting or processing personal data in the data protection register. The s. 27 duties bind any controller that takes a solely-automated decision significantly affecting a data subject, irrespective of size or sector. Impact tier: all entities.. Section 27 of the Data Protection and Privacy Act, 2019 (Act 9 of 2019), headed “Rights in relation to automated decision-taking”, is Uganda's operative automated-decision rule and sits in the Part V block of data-subject rights at ss. 23 to 28. Subsection (1) lets a data subject, by notice in writing to a data controller, require the controller to ensure that any decision taken by or on behalf of the controller which significantly affects that data subject is not based solely on the processing by automatic means of personal data in respect of that data subject. Subsection (2) operates without prejudice to subsection (1) and therefore bites even where no such notice has been served: where a decision which significantly affects a data subject is based solely on automated processing, (a) the data controller shall as soon as reasonably practicable notify the data subject that the decision was taken on that basis, and (b) the data subject is entitled, by notice in writing, to require the controller to reconsider the decision within twenty-one days after receipt of that notification. Subsection (3) then gives the controller twenty-one days after receipt of that notice to inform the data subject in writing of the steps the controller has taken in compliance with it. Subsection (4) disapplies the section entirely where the decision is made in the course of considering whether to enter into a contract with the data subject, with a view to entering into the contract, in the course of the performance of the contract, or for a purpose authorised or required by or under any law. Subsection (5) adds an escalation the Ghanaian and Tanzanian analogues do not have: where the data subject is not satisfied with the controller's subsection (3) response, the data subject shall complain in writing to the Authority within fourteen days.
The Act carries no commencement clause of its own, so the default rule supplies the date: s. 14(1) of the Acts of Parliament Act (Chapter 2, Act 16 of 2000) provides that the commencement of an Act shall be such date as is provided in or under the Act, or where no date is provided, the date of its publication as notified in the Gazette, and s. 14(2) deems every Act to come into force at the first moment of the day of commencement. The Act was published in Uganda Gazette no. 21 of 3 May 2019, so s. 27 has been in force since 3 May 2019. The enacted text relied on here is the copy of Act 9 of 2019 published by the Ministry of ICT and National Guidance, which reproduces the printed impression certified by the Clerk to Parliament as a true copy of the bill on 04/02/2019 and the President's assent page dated 25/2/2019; the Clerk's authentication and assent pages were read directly, as was s. 27 in full. Section 39 lets the Minister, after consultation with the Authority, make regulations by statutory instrument; no statutory instrument text could be retrieved from an official host this run, so nothing is claimed here about subsidiary rules, and the entry rests on the statute alone. Coverage symmetry against the seven African rows already tracked: s. 27 belongs to the UK Data Protection Act 1998 s. 12 lineage rather than to GDPR art. 22, and it is a near-verbatim sibling of Ghana's gh-dpa-s41 and a closer sibling still of Tanzania's tz-pdpa-s36 — all three pair a notice-based right with an automatic notify-and-reconsider duty. Uganda now joins Ghana as the only African rows with hard deadlines, and it is the stricter of the two on the data subject's own side: Ghana's twenty-one-day clocks run to reconsideration and to the controller's answer, and Uganda replicates both in s. 27(2)(b) and s. 27(3), but Uganda alone then fixes a further fourteen-day period in s. 27(5) for complaining to the Authority if the answer does not satisfy. Its carve-out in s. 27(4) is as wide as Ghana's — pre-contractual consideration, contract formation and contract performance are all excluded outright, with no compensating safeguards required — and therefore wider than the GDPR-shaped exceptions in ke-dpa-s35, ng-ndpa-s37 and rw-law058-2021-art21. Unlike Kenya, it gives no right to demand a fresh non-automated decision, only reconsideration of the existing one. Two drafting wrinkles in the gazetted text: the printed s. 27(3) duplicates a verb, reading “the steps that the data controller has taken to take …”, and s. 27(5) refers to “sub clause (3)” rather than subsection (3).
Stated maximum penalty — Section 27 non-compliance is not itself an offence: Part VIII creates only three offences — unlawfully obtaining or disclosing personal data (s. 35, fine not exceeding two hundred and forty currency points or imprisonment for ten years or both), unlawfully destroying, deleting, concealing or altering personal data (s. 36, fine not less than two hundred and forty currency points or imprisonment not exceeding ten years or both) and sale of personal data (s. 37, fine not exceeding two hundred and forty five currency points or imprisonment not exceeding ten years or both) — and none of them reaches a solely-automated decision. The Schedule values one currency point at twenty thousand shillings, so the s. 35 to s. 37 ceilings are UGX 4,800,000, UGX 4,800,000 and UGX 4,900,000. Where an offence under ss. 35, 36 or 37 is committed by a corporation, s. 38(1) makes the corporation and every officer who knowingly and willfully authorised or permitted the contravention liable, and s. 38(2) lets the convicting court additionally order the corporation to pay a fine not exceeding two percent of its annual gross turnover. The route to a sanction for s. 27 is administrative and runs through the regulator: s. 27(5) requires the dissatisfied data subject to complain in writing to the Authority within fourteen days, s. 31 lets any person who believes a data collector, processor or controller is infringing their rights or violating the Act complain to the Authority in the prescribed manner, and s. 32 obliges the Authority to investigate every complaint and lets it direct the party to remedy the breach or take such action as the Authority specifies to restore the rights of the data subject. The Act attaches no fine to disobeying such a direction.