Leading global technology firm WhatsApp LLC has implemented extensive privacy reforms following a February 2026 enforcement decision issued by Uganda’s Personal Data Protection Office (PDPO) in a complaint brought against WhatsApp LLC and Meta Platforms, Inc.
The decision stemmed from a complaint filed by AdLegal International Limited, which alleged that WhatsApp LLC shared Ugandan users’ personal data with Meta Platforms, Inc. without obtaining freely given, informed, and explicit consent; collected more personal data than was necessary to provide its messaging service; afforded Ugandan users lower levels of transparency than users in certain other jurisdictions; and transferred personal data outside Uganda without demonstrating compliance with Uganda’s Data Protection and Privacy Act, Cap. 97. PDPO’s decision of 20th February 2026 partly upheld the complaint, finding deficiencies in transparency and lawful basis correlation, data minimisation shortfalls confined to ancillary, ecosystem-level processing, and a failure to demonstrate compliance with the cross-border transfer requirements. The Office issued five corrective orders against WhatsApp LLC, with Meta Platforms, Inc. joined for the limited purpose of ensuring effective implementation.

No appeal was lodged within the statutory period, and the Office has confirmed, by letter dated 17th July 2026, that WhatsApp LLC implemented the required corrective measures within the prescribed timelines. These included completing key accountability assessments, namely a Data Protection Impact Assessment, an Adequacy Assessment for international data transfers, and a Legitimate Interests Assessment. WhatsApp also published a Uganda-specific Privacy Notice, enhanced disclosures explaining how personal information is collected and shared, strengthened user consent mechanisms, and provided clearer information on the rights available to Ugandan users.
The outcome reflects a broader shift in privacy regulation across Africa, where regulators are increasingly moving beyond the adoption of data protection legislation to active enforcement. Uganda’s data protection legal framework places legal obligations on organisations that collect, process, or share personal data while granting individuals enforceable rights over their personal information.

Although the enforcement proceedings have concluded, the National Personal Data Protection Director, Baker Birikujja, said the case demonstrates that compliance with Uganda’s data protection laws extends well beyond registration with the regulator. He said organisations are expected to identify the lawful basis for every processing activity, provide clear and accessible information to individuals, implement appropriate consent mechanisms where required, and continuously assess privacy risks, particularly where personal data is transferred across borders.
Privacy practitioners have also welcomed the outcome. Barbra Among Arinda, Executive Director of the Credit Reference Bureaus Association Uganda (CRBA), said the case demonstrates the growing maturity of Uganda’s data protection regime and is likely to serve as an important reference point for data protection authorities across Africa.
“This outcome shows that effective regulation is not solely about imposing sanctions. It is equally about guiding organisations towards stronger governance, greater transparency, robust privacy risk management, and the adoption of practical safeguards that enhance the protection of individuals’ personal data,” Among said.
She added that the case illustrates how constructive regulatory engagement can improve organisational compliance while strengthening public trust in the digital economy.