Kit
Start free

Customer phone numbers are personal data: what the PDPO expects

Uganda's Data Protection and Privacy Act covers the customer list in your till. What a shop must do on consent, security, breaches and PDPO registration.

Market trader checking a phone at a stall

Every shop that saves a customer's name and phone number for credit sales, loyalty or delivery is collecting personal data. In Uganda that activity sits under the Data Protection and Privacy Act, 2019 and the Data Protection and Privacy Regulations, 2021. Most owners have never read either, yet the obligations are practical and most of them cost nothing but attention.

Who the law covers

The Act describes three roles: the data collector, the data processor and the data controller. A shop that decides why customer details are kept and how they are used is a data controller; a payroll bureau or software provider that handles the records on its behalf is a processor. The comparison published by DataGuidance quotes Section 3(1) of the Act, which places the principles of accountability, lawfulness and fairness on "a data collector, data processor or data controller or any person who collects" personal data. In plain terms, size does not exempt you.

Consent and purpose

NITA-U's consumer guidance puts it simply: businesses "must obtain your consent before collecting your information and must use it transparently", and a customer has "the right to know how it is collected, stored, and used". For a shop this means two habits:

  • Tell the customer why you are taking the number (a credit ledger, a repair ticket, a delivery) and use it for that.
  • Do not pass the list to a third party, and do not start marketing by SMS to numbers that were collected for deliveries unless the customer agreed.

The same guidance confirms the customer may ask for access, correction and erasure of their data when it is no longer needed. The DataGuidance comparison quotes Section 25(2): a controller must, within fourteen days of a written objection, tell the data subject in writing that it has complied or intends to comply.

Security and breaches

Section 20(1) of the Act requires a data controller, collector or processor to secure the integrity of personal data. Section 23(1) requires that where a controller believes a data subject's personal data has been accessed or acquired by an unauthorised person, the Personal Data Protection Office is notified. The practical reading for a counter business:

  • The customer list lives in one system with a login for each staff member, not in a shared notebook or a cashier's personal phone.
  • Access is removed the day a staff member leaves.
  • If a device with customer data is stolen, treat it as an incident and record what was on it.

Registration with the PDPO

Regulation 15(1) of the 2021 Regulations states that "every data collector, data processor or data controller shall register with the Office". Regulation 15(2) allows the Office to exempt categories by notice in the Gazette, and the Office's decision of 18 July 2025 confirmed that the requirement applies to every qualifying entity until a specific exemption is gazetted. The same Regulations set the mechanics:

Item What the Regulations say
How to apply Form 2 in Schedule 1, with the fee in Schedule 2 (Regulation 16)
Registration fee UGX 100,000
Renewal fee UGX 100,000
Validity Twelve months from the date of registration (Regulation 20)
Penalty for not registering A fine not exceeding six currency points, imprisonment not exceeding three months, or both (Regulation 15(3))

Where the offence is committed by a company, Regulation 15(4) extends liability to every officer who knowingly authorised it. The amounts are small; the point is that registration is an annual compliance item like a trading licence, and it belongs on the same calendar.

A short checklist for this quarter

  1. Write one paragraph that says what customer data you keep, why and for how long. Print it near the counter or add it to receipts.
  2. Move customer records out of personal phones and paper into a system with individual logins.
  3. Review who can open the customer list and remove anyone who does not need it.
  4. Decide who would notify the PDPO if a device or account were compromised.
  5. File the Form 2 registration and diarise the renewal for twelve months later.

None of this requires a lawyer for a single shop, although a group with branches or a business that handles health or financial records should take advice on special personal data under Section 9 of the Act. The habit that matters most is the first one: knowing what you hold and why.

Sources

  1. https://pmlawhub.com/wp-content/uploads/2025/12/Data-Protection-and-Privacy-Regulations-SI-No-21-of-2021-Uganda-1.pdf
  2. https://www.dataguidance.com/sites/default/files/gdpr_v._uganda.pdf
  3. https://consumer.nita.go.ug/publications/understanding-your-digital-rights/
  4. https://privacymatters.dlapiper.com/2025/08/uganda-data-protection-regulator-clarifies-compliance-requirements-for-offshore-entities/

Run the whole business from one login.

Point of sale, stock, CRM, accounting free in every plan, payroll and Kit AI. Start on the web today and add the till, the phone app and the desktop app as you grow.

No card needed · 14-day trial