Big laws are remembered for their text, but they are delivered by institutions. Uganda has enacted the Data Protection and Privacy Act, setting rules for the collection, processing, storage and transfer of personal data, and imposing new duties on banks, telecoms, health providers and digital platforms. The temptation is to read the achievement as a single legislative moment. The more useful reading, for anyone building an organisation, is to ask what execution capability the moment reveals — and whether the country and its firms have built the repeatable capacity a law like this demands, or merely reached a milestone.
The Institutional Test: A law is only the first draft of a capability
Passing a statute and operating one are different disciplines. A data-protection regime asks a state to stand up supervision, guidance and enforcement, and asks every regulated firm to build internal governance that runs day after day. Uganda’s ICT institutions, including NITA-U, now carry responsibilities that did not exist before, and the law provides for the bodies that will oversee it. The leadership question is not who signed the Act but who can make it function repeatedly, across thousands of firms, long after the announcement. Takeaway: the milestone is legislation; the capability is administration, and only one of them has been proven.
The Operator’s Burden: From one decision to a standing function
Inside a bank or telecom in Kampala, the Act converts into an execution problem. Someone must own data governance as a standing function — mapping what data the firm holds, building consent and security processes, and answering data-subject requests as routine rather than exception. The organisations that succeed will be those that treat this as institutional capability rather than a one-off compliance project handed to a single manager. This is the familiar test of whether performance depends on one capable individual or on a system that keeps working when that individual leaves. The firms that will look strongest are not those that move fastest to announce a policy but those that quietly embed the function into how the business runs — into onboarding scripts, into system design, into the routine that survives a change of staff. That is unglamorous work, and it is the work that separates a compliant institution from a compliant press release. Takeaway: durable compliance is a built function, not a heroic effort.
The Capacity Gap: Skills as the binding constraint
The constraint on making the law real is people. A regime like this needs data-protection officers, systems staff, supervisors and advisers, and that skill base is thin in a young market. Whether firms and regulators can recruit, train and retain the expertise to operate the regime is the practical limit on how quickly its promises convert into practice. The leaders worth watching are the ones building that bench — investing in the capability rather than buying a one-time fix — because they are the ones who will still be compliant, and credible, when scrutiny arrives. Takeaway: the scarce input is skilled people, and the leaders who build that capacity set the pace for everyone else.
So What: Judge the institution, not the announcement
For an African operator, the lesson is about where to look for a model. Read the enacted law as the start of an execution journey, not its end, and study the firms and agencies that build standing data-governance capability rather than those that publicise a policy. Uganda’s regime will be tested against an uneven regional patchwork, and the operators who invest in repeatable capability now will carry that advantage into every market they enter. The decisive question is not who passed the law. It is who can run it, quarter after quarter, without a hero at the centre. That is the leadership lesson worth copying.




