
Ask a Ugandan managing director whether their staff use AI at work and you usually get one of two answers. Either “no, we have not adopted it”, or “some of them, informally”. Both answers mean the same thing in practice: people are pasting company information into chat windows on personal accounts, nobody senior knows which information, and there is no record of any of it. A policy does not stop that. It makes it visible, bounded and defensible, which is a different and more achievable goal.
Key Takeaways
- An organisation with no AI policy does not have less AI use. It has AI use it cannot see.
- The Data Protection and Privacy Act 2019 applies to personal data regardless of which tool processes it. After an incident, the question is what measures were in place beforehand.
- One page does most of the work: a written list of what may never be entered into an AI tool.
- The second most valuable clause is the one that protects staff who report a mistake, because the alternative to honest reporting is silence.
- Consumer accounts and business accounts differ in the written commitments they carry on retention and reuse of content. That difference is the reason to pay for accounts rather than expect staff to use their own.
Why this is a data protection question before it is a technology question
The instinct is to treat AI policy as an IT matter. It is not. Almost every real incident in this category is a personal data incident that happened to travel through an AI tool.
A programme officer pastes a beneficiary list into a chatbot to reformat it. A recruiter uploads twenty CVs to have them summarised. A clinic administrator asks an assistant to draft a letter and includes the patient’s condition. A loans officer pastes a repayment history to get help writing a demand notice. None of those people are behaving badly. All of them have just transferred personal data, in several cases special personal data, to a third party outside the country, with no agreement, no record and no lawful basis anyone considered.
Under the Data Protection and Privacy Act 2019 the obligations sit with the organisation, not the tool. The principles of lawful and fair processing, purpose limitation, minimisation, accuracy, security and retention are all engaged. So is the question of processing outside Uganda, since nearly every mainstream AI tool processes elsewhere. And so are data subject rights: if someone asks what you hold about them, and part of it is sitting in a consumer chat history nobody controls, the answer becomes very hard to give.
The one page that does most of the work
If an organisation adopts nothing else, it should adopt a red list: a written statement of what may never be entered into any AI tool. Print it, brief it, put it where people work.
| Never enter | Which includes |
|---|---|
| Personal data about identifiable people | Names combined with any other detail, phone numbers, national ID numbers, addresses, photographs, dates of birth, staff files, beneficiary lists, student records, patient information |
| Special personal data | Health, religious or political belief, sexual life, financial position, criminal record. Higher restrictions apply and consent alone is often not enough |
| Credentials and keys | Passwords, API keys, tokens, mobile money PINs, bank details, one-time codes |
| Confidential commercial material | Unsigned contracts, pricing, proposals in progress, board papers, donor correspondence, investigation files |
| Third-party confidential material | Anything a client, partner or donor gave you under an agreement limiting its use. Their contract has no exception for convenience |
| Privileged or disputed material | Legal advice, correspondence with counsel, anything relating to a live or threatened claim |
Most organisations write this list and immediately discover a problem: several of the tasks people most want AI for involve exactly this data. That discovery is useful. It moves the conversation from whether to use AI to how, and the answer is usually one of three routes. Remove the identifiers before the data goes anywhere. Use a tool with contractual commitments that cover the category. Or keep the work inside systems you control, which is a project rather than a setting but is the right answer for regular work on sensitive records.
The four other clauses that earn their place
1. A human owns every consequential decision
No decision that affects a person is made by a system. It is made by a person who may use a system to inform it and who remains answerable for it. In practice: where AI ranks or screens people, a named person reviews the individual cases and records that they did. Where a decision is communicated, the person who owns the decision sends it, under their name. And if someone asks why, you must be able to explain it in ordinary language without referring to the tool. If you cannot, the tool should not have been used for that decision.
2. Every fact is checked at source
These systems produce citations, case numbers, statistics and quotations that look correct and do not exist. This is not rare and it is not a sign of a bad tool. Every reference in anything that leaves the organisation must be opened and read at its source before it goes out. Firms in jurisdictions with more forgiving courts than ours have lost cases and careers to this exact failure.
3. Only approved tools, and approval is a decision
Keep a register: the tool, what it is approved for, whether it may touch personal data, whether the account is business or personal, who approved it and when. Adding a tool is a decision, not a download. This clause also has to cover the two things people forget: free trials, which are unapproved tools with a clock on them, and browser extensions, which read the page you are on and are frequently not built by the company whose logo they carry.
4. Prompt honest reporting is protected
Someone will paste something they should not have. The measure of an organisation is not whether that happens but how quickly it is reported, and whether the person felt able to report it. A clause stating that a member of staff who reports a genuine mistake promptly and honestly will not face disciplinary action for the mistake itself is the difference between a small incident and a serious one. Concealment is a different matter, and so is repeated disregard for the red list after training. But the default must be that telling someone is safe.
Consumer accounts versus business accounts
This is where the policy meets the budget. Free and personal-tier AI accounts generally offer weaker commitments on how content is retained and whether it may be used to improve the provider’s systems. Business and enterprise tiers usually offer stronger ones, along with administrative visibility over what is being used.
That difference is the entire argument for paying. Not capability, though that is real. The reason to buy accounts is that it removes the incentive for staff to use their own, and an unapproved consumer account holding beneficiary records is difficult to describe as a reasonable security measure after the fact.
Adoption: nine steps, about a fortnight
- Name the policy owner and the data protection owner. Two names, written down.
- Agree the red list, and cut anything that does not apply to you.
- Ask staff, without blame, which AI tools they already use.
- Fill in the approved tool register.
- Buy business-tier accounts for the tools people genuinely need.
- Have the policy reviewed by counsel or your board, because sector obligations vary.
- Brief staff in person for thirty minutes, then collect signatures.
- Confirm your registration position with the Personal Data Protection Office.
- Diarise the review date and the registration renewal.
The order matters. Steps one and two do more work than everything below them combined. Step seven is where most policies fail, because a circulated PDF changes nothing and a thirty-minute conversation changes behaviour.
What a good policy is actually for
Not to restrict. A policy that reads as a list of prohibitions produces one of two outcomes: nobody uses the tools, which wastes the capability, or people use them quietly, which is where you started. A good policy gives staff explicit permission to use AI properly, tells them the small number of things that are genuinely off limits, and makes clear who to tell when something goes wrong.
The organisations that get value from AI in this market are not the ones with the best tools. They are the ones where staff know what they are allowed to do and are not afraid to say when they have made a mistake. A page of clear rules buys both.
Sources
- Data Protection and Privacy Act 2019 (Uganda), processing principles and section 29.
- Data Protection and Privacy Regulations 2021, regulation 15(1) on registration of data collectors, processors and controllers.
- Published guidance on the registration regime operated by Uganda’s Personal Data Protection Office.
Position stated as at 21 August 2026. This is not legal advice. Have a qualified lawyer review any policy against your sector, your contracts and your registration position before adoption.
