E-Commerce in East Africa: Privacy and Consumer Law

An online business can sell into four countries without opening four shops. That does not mean it operates outside four legal systems. The website may collect a Kenyan customer’s address, store it on a server abroad, accept payment through a regional provider, send the order from Uganda and sell under terms drafted in another country. Each stage can create a different legal question.

For small and growing businesses, the most useful approach is not to begin with a fifty-page privacy policy. Begin by mapping what the business actually does. This guide compares Kenya, Uganda, Mainland Tanzania and Rwanda and focuses on five connected areas: personal data, electronic contracts, consumer information, payments and cross-border transfers.

Map the transaction before writing the legal documents

An online seller should be able to describe a normal order from beginning to end. What information does the customer enter? Which company receives the order? Which payment provider receives card or mobile-money information? Where is customer data hosted? Who delivers the product? Which entity issues the receipt? What happens if the customer cancels or returns the purchase?

Those answers determine which legal documents are needed. A privacy notice copied from another website cannot accurately explain data processing that the business itself has never mapped. Terms and conditions cannot allocate delivery risk clearly if no one knows whether the seller or marketplace controls fulfilment.

The map should also include service providers. Cloud hosting, email marketing, analytics, customer-support software and payment gateways may all process customer information even if the merchant never sees the underlying technical transfer.

Kenyan online sales combine privacy and consumer duties

Kenya’s Data Protection Act and the Office of the Data Protection Commissioner’s current guidance create obligations concerning lawful processing, security, data-subject rights and, where applicable, registration of data controllers or processors. A business collecting names, phone numbers, delivery addresses, location data or customer profiles should determine its role and legal basis rather than assuming that a checkout box is universal consent for every later use.

Cross-border hosting deserves its own check because Kenya’s data-protection framework regulates transfers of personal data outside the country and expects appropriate safeguards or another lawful basis.

The Consumer Protection Act separately recognises internet and remote agreements. It requires important information to be disclosed and provides cancellation consequences where the supplier fails to comply with the statutory requirements. The legal design of a Kenyan-facing checkout should therefore allow the consumer to see the material terms before committing and should provide a durable copy of the agreement where required.

Electronic contracting is also recognised within Kenya’s communications and electronic-transactions framework. The practical issue is not whether a click can ever form a contract. It is whether the business can prove what the customer was shown and accepted at the time of the transaction.

Uganda makes supplier disclosure central to electronic trade

Uganda’s Electronic Transactions Act provides a useful practical model for online sellers. Official NITA-U guidance states that suppliers offering goods or services electronically should provide accessible terms and conditions and use secure payment systems and procedures. The statutory framework also regulates information that an online supplier should make available to consumers.

Uganda’s Data Protection and Privacy Act adds a separate layer for customer information. A business should identify the purpose for which data is collected, collect only what is needed, protect it and deal carefully with transfers outside Uganda. The existence of an online contract does not itself authorise unrelated marketing or unlimited retention of customer records.

The business should also distinguish customer-service records from payment credentials. Using a licensed payment provider can reduce the need for a merchant to handle sensitive card or financial data directly, but the merchant still remains responsible for its own customer database and its contractual relationship with the payment provider.

Mainland Tanzania now has an active data-protection regulator

Tanzania’s Personal Data Protection Act came into force in 2023 and established the Personal Data Protection Commission, PDPC, which is now operational. The Commission registers data controllers and processors and publishes compliance services.

For a business using foreign cloud services, the cross-border transfer issue is especially important. The PDPC currently operates a cross-border data transfer permit process. Its guidance asks an applicant to identify the data, purpose, destination, recipient, safeguards and risks associated with the transfer. A Tanzanian merchant should therefore not discover only after launch that its website automatically exports its entire customer database.

Tanzania’s Electronic Transactions Act recognises electronic transactions and contracts, while consumer obligations may also arise under the Fair Competition Act and sector rules. The seller should provide accurate information about the goods or services, price, delivery and complaint route rather than assume that online commerce is governed only by the website’s chosen-law clause.

Rwanda’s privacy law can reach a business outside Rwanda

Rwanda’s Law No. 058/2021 relating to the protection of personal data and privacy has an important territorial rule. It applies not only to controllers and processors established in Rwanda but also, in defined circumstances, to a person outside Rwanda who processes personal data of data subjects located in Rwanda.

That matters to a foreign online shop targeting Rwandan customers. The absence of a Rwandan office does not automatically make the privacy law irrelevant.

Rwanda’s Data Protection and Privacy Office also states that persons operating as data controllers or processors are subject to registration requirements. The law regulates processor contracts, records of processing and security. Article 48 controls sharing or transferring personal data outside Rwanda, allowing transfers on specified bases including supervisory-authority authorisation with safeguards, consent and certain contractual or legal necessities.

An online business using an overseas cloud provider should therefore identify that transfer when designing its privacy programme rather than describing the data as if it never left Rwanda.

The checkout page should do more than collect money

A legally useful checkout explains the identity of the seller, the product or service, the total price and material charges, the delivery or performance arrangement, any important restrictions, and the cancellation or return rules that apply. It should also present the terms before the customer commits.

Do not hide important terms in a footer that the customer never has to encounter. If the seller relies on a term limiting cancellation, changing subscription renewal, allocating delivery risk or selecting dispute resolution, the business should be able to show that the customer received reasonable notice of it.

Keep versioned records of terms. If a complaint arrives eight months later, the business should know which version the customer accepted. An undated webpage that has been edited repeatedly is weak evidence of the original agreement.

Privacy notices should describe the real data flow

A privacy notice is useful only if it corresponds to the system. It should identify what information is collected, why, the main recipients or categories of recipients, retention logic, customer rights and relevant international transfers.

Consent should not be requested mechanically for every processing activity. Some processing may be necessary to perform the sale, comply with law or pursue another lawful basis available under the relevant national legislation. Where consent is genuinely used, it should be meaningful rather than bundled into an unrelated purchase.

Marketing deserves separate attention. A customer giving a telephone number for delivery has not necessarily agreed to receive indefinite promotional messages. The business should separate fulfilment communications from direct marketing and honour lawful opt-out rights.

Payment processing creates contracts and regulatory boundaries

Most ordinary merchants should use properly regulated payment providers rather than trying to become payment institutions by accident. The contract with the provider should explain settlement timing, refunds, chargebacks, fraud controls, suspended accounts, foreign-currency conversion and access to transaction records.

A merchant should know which entity is legally taking the payment. If a marketplace collects money and later remits it to the seller, that arrangement may differ from a simple gateway that transfers funds directly to the merchant’s acquiring account.

Customer-facing terms should match the payment architecture. Promising an “instant refund” is risky if the payment provider’s process takes several days. Likewise, a merchant should not retain full payment credentials simply because the technology makes storage possible.

Cross-border transfers should be designed, not discovered

Cloud computing makes international data transfer easy to overlook. A customer service platform may be hosted abroad; backups may be stored in another region; an analytics provider may receive device identifiers; a foreign headquarters may access the same database.

Create a data-transfer register listing the provider, data categories, destination, purpose and legal mechanism relied upon. Tanzania’s current permit-based process makes this particularly concrete. Rwanda’s Article 48 framework and Kenya’s and Uganda’s transfer rules likewise mean that “the cloud” is not a legal destination.

Contracts with processors should deal with confidentiality, security, sub-processors, breach notification, return or deletion of data and assistance with customer rights. A low-cost software subscription should not be adopted without knowing where the data goes.

Consumer complaints are part of compliance

The business should publish a usable complaint channel and preserve the order, invoice, delivery evidence, correspondence and refund history. A complaint-handling record can show whether the business honoured its own policy and the applicable consumer law.

Where goods are sold across borders, a governing-law clause may help structure the contract, but it should not be assumed to remove mandatory consumer protections in the customer’s country. A clause selecting a foreign court can also be commercially self-defeating for low-value consumer transactions.

For that reason, the legal design of an online shop should match the markets it actually serves. A business that actively advertises, prices and delivers into another country should investigate that country’s mandatory rules before assuming its home-country terms control everything.

The strongest e-commerce compliance system is built from the transaction outward. Know who the seller is, what the customer is promised, what data is collected, where it travels, which providers handle payment and fulfilment, and what happens when something goes wrong.

Once that operational picture is accurate, privacy notices, online terms, processor contracts and consumer procedures become useful legal tools rather than decorative pages copied from somebody else’s website.

Source note and disclaimer. This article is based principally on Kenya’s Data Protection Act and Consumer Protection Act and current ODPC guidance; Uganda’s Data Protection and Privacy Act and Electronic Transactions Act together with current NITA-U guidance; Tanzania’s Personal Data Protection Act, current Personal Data Protection Commission cross-border transfer guidance and Electronic Transactions Act; and Rwanda Law No. 058/2021 relating to the protection of personal data and privacy together with current Data Protection and Privacy Office guidance. Payment services, tax and sector rules may create additional obligations. This article is general legal information, not a compliance opinion for a particular online business.

Suggested citation: 

Ronald Serwanga, “E-Commerce in East Africa: Privacy and Consumer Law” East Africa Legal Insight (13 September 2026).