Act
Data Protection And Privacy Act
2019
(4) A data controller shall destroy or delete a record of personal
data or de-identify the record at the expiry of the retention period.
(5) The destruction or deletion of a record of personal data shall
be done in a manner that prevents its reconstruction in an intelligible
form.
19. Processing personal data outside Uganda.
Where a data processor or data controller based in Uganda processes
or stores personal data outside Uganda, the data processor or data
controller shall ensure that(a) the country in which the data is processed or stored has
adequate measures in place for the protection of personal
data at least equivalent to the protection provided for by
this Act; or
(b) the data subject has consented.
PART IV-SECURITY
OF DATA
20. Security measures.
( 1) A data controller, data collector or data processor shall
secure the integrity of personal data in the possession or control of a
data controller, data processor or data collector by adopting
appropriate, reasonable, technical and organisational measures to
prevent loss, damage , or unauthorised destruction and unlawful
access to or unauthorised processing of the personal data.
(2) For the purposes of subsection (1), the data controller shall
take measures to(a) identify reasonably foreseeable internal and external risks
to personal data under that person's possession or control;
(b) establish and maintain appropriate safeguards against the
identified risks;
(c) regularly verify that the safeguards
implemented; and
are effec tively