
A staff member types a paragraph into an AI assistant and presses enter. Ask most managers in this region where that paragraph went, how long it will be kept, whether it can be used to improve the system, and who else could read it, and the honest answer is that nobody has ever asked. That is a manageable position for a paragraph about meeting logistics. It is not a manageable position for a beneficiary list, a payroll file or a draft contract, and the distinction is one an organisation has to make deliberately because nothing in the interface makes it for you.
Key Takeaways
- Almost every mainstream AI tool processes your text outside Uganda. That is not automatically unlawful, but it is a cross-border transfer when personal data is involved and it engages the Data Protection and Privacy Act 2019.
- Consumer and business tiers of the same product often carry materially different written commitments on retention and on whether your content improves the provider’s systems.
- Deleting a conversation from your history is not the same as the provider deleting the data, and the two are commonly confused.
- The practical rule is simpler than the law: assume anything you type leaves the country, and decide what may be typed accordingly.
- Data residency is a contract question, not a settings question. If it is not written down, you do not have it.
What happens to the text, mechanically
When you send a prompt to a hosted AI service, the text travels to servers operated by the provider, which for the major services means data centres in North America, Europe or Asia. It is processed there. Depending on the product and the tier, it may be retained for a period for abuse monitoring, it may be retained in your conversation history, and in some consumer configurations it may be used to improve the provider’s systems.
Attachments behave the same way. A PDF uploaded for summarising has been transmitted in full. So has the spreadsheet, the scanned identity document and the photograph. Voice notes and meeting recordings are the ones people forget entirely, because a transcription tool does not feel like an AI service even though it is carrying the most sensitive conversations in the organisation.
The two settings people conflate
Nearly every service now offers something like a training or improvement toggle, and nearly every organisation treats switching it off as having solved the question. It has not, because there are two separate things going on.
| Question | What the toggle controls | What it does not |
|---|---|---|
| Will my content be used to improve the model? | Usually yes, this is what the toggle addresses | |
| Is my content stored at all? | Content is generally still transmitted and retained for some period regardless of the toggle | |
| Where is it stored? | Unaffected. Residency is a product and contract matter | |
| Who at the provider could access it? | Governed by the provider’s own controls and by your agreement, not by a switch in your account |
Deleting a conversation is a third, separate thing. It removes the item from your view. Whether and when the underlying data is deleted from the provider’s systems is a retention question answered in the terms, not in the interface.
None of this is deceptive. It is simply that the toggle answers one question and organisations treat it as answering four.
Why the tier matters more than the brand
The most consequential difference between a free personal account and a paid business or enterprise account is usually not capability. It is the written commitments attached.
Business and enterprise tiers generally carry stronger contractual terms on retention, on whether content is used for improvement, and on administrative visibility over what is being used inside the organisation. Consumer tiers generally do not, and are governed by terms written for individuals rather than for a data controller with statutory obligations.
This is the entire practical argument for paying for accounts. Not features. The argument is that an unapproved consumer account holding member records or beneficiary data is difficult to describe as a reasonable security measure after an incident, and that paying removes any reason for staff to use their own.
Where Ugandan law sits
The Data Protection and Privacy Act 2019 and its 2021 Regulations govern the processing of personal data regardless of which tool does the processing. Several of its principles bear directly on this question. Purpose limitation means data collected for one purpose is not freely available for another. Minimisation means you send the paragraph you need help with, not the whole file. Security means the arrangements you have made must be reasonable in the circumstances. And the Act places conditions on personal data being processed outside Uganda, which is what these tools do by default.
There is also the practical consequence for data subject rights. If someone exercises a right in relation to data you hold about them, and some of that data sits in a consumer chat history nobody controls, answering becomes genuinely hard. That difficulty is itself a reason not to put it there.
Separately, section 29 of the Act, read with regulation 15(1) of the 2021 Regulations, requires data collectors, processors and controllers to register with the Personal Data Protection Office, with registration valid for a year, renewal to be applied for within three months of expiry, and an annual compliance report. Regulator practice on scope has moved, so check the current published guidance rather than relying on a summary.
What to actually do about it
The full legal analysis is a real piece of work and worth doing for an organisation processing sensitive data at scale. For everyone else, five steps cover most of the exposure.
1. Write the red list
One page: what may never be entered into any AI tool. Personal data about identifiable people, special categories such as health and financial position, credentials and keys, unsigned contracts and board papers, and anything a client or donor gave you under terms limiting its use. This single page prevents most real incidents and costs nothing.
2. Buy business-tier accounts for the people who need them
Roughly a third of staff in most organisations. Allocated by function rather than seniority: the people who write, analyse and answer.
3. Ask three questions of any vendor, in writing
Where is our data stored and processed, including sub-processors. Is there a data processing agreement we can read. What is retained, for how long, and what happens on termination. Verbal answers from a salesperson are not answers.
4. Count the embedded tools
The assistant inside your office suite. The meeting recorder. The translation feature. The browser extension somebody installed. These are the ones that never appear in an AI inventory because nobody thinks of them as AI, and the meeting recorder in particular is carrying your most sensitive discussions to a third party.
5. Handle the incident well when it happens
Someone will paste something they should not have. Say in writing that a member of staff who reports a genuine mistake promptly and honestly will not face disciplinary action for the mistake itself. The alternative to that clause is silence, and silence is what turns a small incident into a serious one.
The one thing that is genuinely different
For work that must stay inside systems you control, the answer is a deployment on infrastructure you own rather than a setting in a consumer product. That is a project rather than a configuration, it carries real cost, and it is the right answer for a narrow set of cases: regular work on sensitive records, sectors with explicit residency requirements, and organisations whose contracts have already committed them to it.
It is not the right answer for most organisations, and vendors who lead with it are usually solving a problem the buyer does not have yet. Establish the red list first. A large share of what people wanted an on-premise deployment for turns out to be work that never needed the identifying data in the first place.
The rule to actually remember
All of the above compresses into one sentence that a staff member can hold in their head on a busy Tuesday: assume anything you type leaves the country, and act accordingly.
It is not legally precise. It produces the right behaviour almost every time, which is more than can be said for a policy nobody finishes reading.
Sources
- Data Protection and Privacy Act 2019 (Uganda), processing principles and section 29.
- Data Protection and Privacy Regulations 2021, regulation 15(1).
- Published guidance from Uganda’s Personal Data Protection Office on registration of data collectors, processors and controllers.
Position stated as at 21 August 2026. This is not legal advice, and provider terms change frequently. Read the terms of the specific tier you are buying.
