Legal · Uganda DPPA 2019

Data Protection & Privacy Policy

Version 1.0 · Last updated: 2 July 2026

Our commitment: Basket Advisory Technologies complies with Uganda's Data Protection and Privacy Act, 2019 (Cap. 97) and the Data Protection and Privacy Regulations, 2021. We collect only what we need, we never sell personal data, and we protect it with appropriate security safeguards.

1. Introduction

Basket Advisory Technologies ("Basket", "we", "us", "our") builds technology that brings Uganda's casual and informal workforce into the formal economy. In doing so, we collect and process personal data belonging to workers, agents, clients, patients, farmers and business contacts.

We are committed to protecting that data and to full compliance with the Data Protection and Privacy Act, 2019 (Cap. 97) and the Data Protection and Privacy Regulations, 2021 of Uganda, together with directions issued by the Personal Data Protection Office (PDPO) under the National Information Technology Authority – Uganda (NITA-U).

2. Scope

This policy applies to all personal data we process through our platforms:

It applies to all Basket staff, field agents, contractors, and any third party who processes personal data on our behalf.

3. Our Role Under the Law

For the personal data of our own clients and users, Basket acts as a data controller (we decide why and how data is processed).

For personal data that our client companies upload and manage through our platforms (for example, a manpower company's list of workers), that client is the data controller and Basket acts as a data processor, handling the data on their instructions. Our respective obligations are set out in our client agreements. Where we determine purposes jointly with a client, we act as joint controllers and allocate responsibilities in writing.

4. The Principles We Follow

In line with Section 3 of the Act, we adhere to the seven principles of data protection. We:

5. What Personal Data We Collect

We practise data minimisation — we collect a field only where it is needed for the stated purpose.

Identity and contact data

Full name, telephone number, email address, National Identification Number (NIN), physical location or district, and employer or organisation.

Financial data (special personal data)

Payment amounts, wages and salaries, daily rates, amounts owed and collected, agent float balances, bank or mobile-money account details, and credit-related information used for scoring. Financial information is special personal data under Section 9 of the Act and receives heightened protection.

Biometric data (special personal data)

For worker and beneficiary verification, our platforms are designed to use facial images, fingerprint data, and wristband (QR) identifiers. Biometric identifiers are highly sensitive and are treated as special personal data.

Current status: During pilot phases, biometric verification steps may be operated in a demonstration mode. Where biometric capture is not yet live, we say so plainly and do not represent simulated verification as a completed biometric match. When live biometric capture is enabled, it is governed fully by this policy.

Health data (special personal data)

Through Rafiki, we process data relating to the receipt of donated medical supplies by patients and beneficiaries, including their identity and confirmation of delivery. Health status and medical records are special personal data under Section 9 of the Act.

Geolocation data

GPS coordinates captured at points of hand-off, delivery or payout, used as proof of presence and to prevent fraud.

Account and usage data

Login credentials (passwords are stored in hashed form by our authentication provider, never in plain text), and records of actions taken in the platform for audit purposes.

6. Why We Collect It

We only process personal data where we have a lawful basis under Sections 7 and 9 of the Act:

Special personal data (financial, biometric, health) is only processed where a Section 9 exception applies — most commonly the free and informed consent of the data subject, or an obligation imposed by law on an employer.

Children's data: We do not knowingly collect personal data relating to a child (under 18) without the prior consent of a parent or guardian, and only where necessary and lawful. Our gold-sourcing traceability in Jirani includes an adult-verification step specifically to support the exclusion of child labour.

7. Consent

Where we rely on consent, we request it in clear language before collecting data, explain what is collected and why, and make consent as easy to withdraw as to give. For workers and beneficiaries who may have limited literacy, our field agents explain the purpose verbally, in a language the person understands, before any data is captured. Withdrawing consent does not affect processing already carried out lawfully.

8. How We Protect Your Data

In line with Sections 20 and 22 of the Act, we implement appropriate technical and organisational measures:

9. Sharing and Disclosure

We do not sell personal data — the Act makes the sale of personal data a criminal offence, and we treat it as an absolute prohibition. We share personal data only: with the client company that owns it; with service providers who process it on our behalf under contract; where required by law or a lawful order of a court or the PDPO; or with the data subject's consent.

10. Storage and Cross-Border Transfers

Some infrastructure and service providers may store or process data outside Uganda. Where this occurs, in line with Section 19 of the Act, we ensure that the destination country has data-protection measures at least equivalent to Uganda's, or that the data subject has consented. Where our clients require data to remain within Uganda, we accommodate that.

11. Data Retention

We retain personal data only as long as necessary for the purpose or as required by law. Payroll, payout and financial records are retained for the periods required by Ugandan tax and anti-money-laundering law; traceability and delivery records for the period needed for donor, buyer or regulatory accountability; account data while the account is active and for a reasonable period afterwards. At the end of the retention period we securely destroy or de-identify the data.

12. Your Rights

Under the Act, every person whose data we hold has the right to:

To exercise any of these rights, contact our Data Protection Officer (Section 15). Exercising these rights is free of charge.

13. Data Breaches

If we believe personal data has been accessed or acquired by an unauthorised person, we will act immediately to contain and assess the breach, notify the PDPO as required, and notify affected data subjects where the breach is likely to cause them harm. We maintain an internal breach-response procedure and a record of any breaches.

14. Data Protection Impact Assessments

Because we process special personal data (financial, biometric and health) and monitor location, we carry out a Data Protection Impact Assessment (DPIA) before launching processing activities likely to pose a high risk to data subjects' rights, as anticipated by the Regulations.

15. Our Data Protection Officer

In line with Section 6 of the Act and the Regulations, Basket has designated a Data Protection Officer (DPO) responsible for compliance, liaising with the PDPO, maintaining our record of processing activities, and handling data-subject requests and complaints.

Data Protection Officer
Basket Advisory Technologies
Nakawa, Innovation Hub Port Bell Road, 1st Floor Wing A, Kampala
Email: solutions@basketadvisory.com

We are registered, or are completing registration, with the Personal Data Protection Office as a data collector, processor and controller, as required by Regulation 15, and we renew that registration as required.

16. Complaints

If you have a concern about how we handle your personal data, please contact our DPO first — we aim to resolve complaints amicably and promptly. You also have the right to complain directly to the Personal Data Protection Office (PDPO), National Information Technology Authority – Uganda, at www.pdpo.go.ug.

17. Changes to This Policy

We review this policy regularly and update it to reflect changes in our platforms, our processing activities, or the law. The version number and date at the top show when it was last updated. Material changes will be communicated to affected users.

This policy reflects the requirements of the Data Protection and Privacy Act, 2019 and the Data Protection and Privacy Regulations, 2021 of Uganda. It does not constitute legal advice.