E-Commerce in East Africa: Privacy and Consumer Law
An online business can sell into four countries without opening four shops. That does not mean it operates outside four legal systems. The website may collect a Kenyan customer’s address, store it on a server abroad, accept payment through a regional provider, send the order from Uganda and sell under terms drafted in another country. Each stage can create a different legal question.
For small and growing businesses, the most useful approach is not to
begin with a fifty-page privacy policy. Begin by mapping what the business
actually does. This guide compares Kenya, Uganda, Mainland Tanzania and Rwanda
and focuses on five connected areas: personal data, electronic contracts,
consumer information, payments and cross-border transfers.
Map the transaction before
writing the legal documents
An online seller should be able to describe a normal order from
beginning to end. What information does the customer enter? Which company
receives the order? Which payment provider receives card or mobile-money
information? Where is customer data hosted? Who delivers the product? Which
entity issues the receipt? What happens if the customer cancels or returns the
purchase?
Those answers determine which legal documents are needed. A privacy
notice copied from another website cannot accurately explain data processing
that the business itself has never mapped. Terms and conditions cannot allocate
delivery risk clearly if no one knows whether the seller or marketplace
controls fulfilment.
The map should also include service providers. Cloud hosting, email
marketing, analytics, customer-support software and payment gateways may all
process customer information even if the merchant never sees the underlying
technical transfer.
Kenyan online sales combine
privacy and consumer duties
Kenya’s Data Protection Act and the Office of the Data Protection
Commissioner’s current guidance create obligations concerning lawful
processing, security, data-subject rights and, where applicable, registration
of data controllers or processors. A business collecting names, phone numbers,
delivery addresses, location data or customer profiles should determine its
role and legal basis rather than assuming that a checkout box is universal
consent for every later use.
Cross-border hosting deserves its own check because Kenya’s
data-protection framework regulates transfers of personal data outside the
country and expects appropriate safeguards or another lawful basis.
The Consumer Protection Act separately recognises internet and
remote agreements. It requires important information to be disclosed and
provides cancellation consequences where the supplier fails to comply with the
statutory requirements. The legal design of a Kenyan-facing checkout should
therefore allow the consumer to see the material terms before committing and
should provide a durable copy of the agreement where required.
Electronic contracting is also recognised within Kenya’s
communications and electronic-transactions framework. The practical issue is
not whether a click can ever form a contract. It is whether the business can
prove what the customer was shown and accepted at the time of the transaction.
Uganda makes supplier
disclosure central to electronic trade
Uganda’s Electronic Transactions Act provides a useful practical
model for online sellers. Official NITA-U guidance states that suppliers
offering goods or services electronically should provide accessible terms and
conditions and use secure payment systems and procedures. The statutory
framework also regulates information that an online supplier should make
available to consumers.
Uganda’s Data Protection and Privacy Act adds a separate layer for
customer information. A business should identify the purpose for which data is
collected, collect only what is needed, protect it and deal carefully with
transfers outside Uganda. The existence of an online contract does not itself
authorise unrelated marketing or unlimited retention of customer records.
The business should also distinguish customer-service records from
payment credentials. Using a licensed payment provider can reduce the need for
a merchant to handle sensitive card or financial data directly, but the
merchant still remains responsible for its own customer database and its
contractual relationship with the payment provider.
Mainland Tanzania now has an
active data-protection regulator
Tanzania’s Personal Data Protection Act came into force in 2023 and
established the Personal Data Protection Commission, PDPC, which is now
operational. The Commission registers data controllers and processors and
publishes compliance services.
For a business using foreign cloud services, the cross-border
transfer issue is especially important. The PDPC currently operates a
cross-border data transfer permit process. Its guidance asks an applicant to
identify the data, purpose, destination, recipient, safeguards and risks
associated with the transfer. A Tanzanian merchant should therefore not
discover only after launch that its website automatically exports its entire
customer database.
Tanzania’s Electronic Transactions Act recognises electronic
transactions and contracts, while consumer obligations may also arise under the
Fair Competition Act and sector rules. The seller should provide accurate
information about the goods or services, price, delivery and complaint route
rather than assume that online commerce is governed only by the website’s
chosen-law clause.
Rwanda’s privacy law can
reach a business outside Rwanda
Rwanda’s Law No. 058/2021 relating to the protection of personal
data and privacy has an important territorial rule. It applies not only to
controllers and processors established in Rwanda but also, in defined
circumstances, to a person outside Rwanda who processes personal data of data
subjects located in Rwanda.
That matters to a foreign online shop targeting Rwandan customers.
The absence of a Rwandan office does not automatically make the privacy law
irrelevant.
Rwanda’s Data Protection and Privacy Office also states that persons
operating as data controllers or processors are subject to registration
requirements. The law regulates processor contracts, records of processing and
security. Article 48 controls sharing or transferring personal data outside
Rwanda, allowing transfers on specified bases including supervisory-authority
authorisation with safeguards, consent and certain contractual or legal
necessities.
An online business using an overseas cloud provider should therefore
identify that transfer when designing its privacy programme rather than
describing the data as if it never left Rwanda.
The checkout page should do
more than collect money
A legally useful checkout explains the identity of the seller, the
product or service, the total price and material charges, the delivery or
performance arrangement, any important restrictions, and the cancellation or
return rules that apply. It should also present the terms before the customer
commits.
Do not hide important terms in a footer that the customer never has
to encounter. If the seller relies on a term limiting cancellation, changing
subscription renewal, allocating delivery risk or selecting dispute resolution,
the business should be able to show that the customer received reasonable
notice of it.
Keep versioned records of terms. If a complaint arrives eight months
later, the business should know which version the customer accepted. An undated
webpage that has been edited repeatedly is weak evidence of the original
agreement.
Privacy notices should
describe the real data flow
A privacy notice is useful only if it corresponds to the system. It
should identify what information is collected, why, the main recipients or
categories of recipients, retention logic, customer rights and relevant
international transfers.
Consent should not be requested mechanically for every processing
activity. Some processing may be necessary to perform the sale, comply with law
or pursue another lawful basis available under the relevant national
legislation. Where consent is genuinely used, it should be meaningful rather
than bundled into an unrelated purchase.
Marketing deserves separate attention. A customer giving a telephone
number for delivery has not necessarily agreed to receive indefinite
promotional messages. The business should separate fulfilment communications
from direct marketing and honour lawful opt-out rights.
Payment processing creates
contracts and regulatory boundaries
Most ordinary merchants should use properly regulated payment
providers rather than trying to become payment institutions by accident. The
contract with the provider should explain settlement timing, refunds,
chargebacks, fraud controls, suspended accounts, foreign-currency conversion
and access to transaction records.
A merchant should know which entity is legally taking the payment.
If a marketplace collects money and later remits it to the seller, that
arrangement may differ from a simple gateway that transfers funds directly to
the merchant’s acquiring account.
Customer-facing terms should match the payment architecture.
Promising an “instant refund” is risky if the payment provider’s process takes
several days. Likewise, a merchant should not retain full payment credentials
simply because the technology makes storage possible.
Cross-border transfers should
be designed, not discovered
Cloud computing makes international data transfer easy to overlook.
A customer service platform may be hosted abroad; backups may be stored in
another region; an analytics provider may receive device identifiers; a foreign
headquarters may access the same database.
Create a data-transfer register listing the provider, data
categories, destination, purpose and legal mechanism relied upon. Tanzania’s
current permit-based process makes this particularly concrete. Rwanda’s Article
48 framework and Kenya’s and Uganda’s transfer rules likewise mean that “the
cloud” is not a legal destination.
Contracts with processors should deal with confidentiality,
security, sub-processors, breach notification, return or deletion of data and
assistance with customer rights. A low-cost software subscription should not be
adopted without knowing where the data goes.
Consumer complaints are part
of compliance
The business should publish a usable complaint channel and preserve
the order, invoice, delivery evidence, correspondence and refund history. A
complaint-handling record can show whether the business honoured its own policy
and the applicable consumer law.
Where goods are sold across borders, a governing-law clause may help
structure the contract, but it should not be assumed to remove mandatory
consumer protections in the customer’s country. A clause selecting a foreign
court can also be commercially self-defeating for low-value consumer
transactions.
For that reason, the legal design of an online shop should match the
markets it actually serves. A business that actively advertises, prices and
delivers into another country should investigate that country’s mandatory rules
before assuming its home-country terms control everything.
The strongest e-commerce compliance system is built from the
transaction outward. Know who the seller is, what the customer is promised,
what data is collected, where it travels, which providers handle payment and
fulfilment, and what happens when something goes wrong.
Once that operational picture is accurate, privacy notices, online
terms, processor contracts and consumer procedures become useful legal tools
rather than decorative pages copied from somebody else’s website.
Source note and disclaimer. This article is based principally on Kenya’s Data Protection Act and Consumer Protection Act and current ODPC guidance; Uganda’s Data Protection and Privacy Act and Electronic Transactions Act together with current NITA-U guidance; Tanzania’s Personal Data Protection Act, current Personal Data Protection Commission cross-border transfer guidance and Electronic Transactions Act; and Rwanda Law No. 058/2021 relating to the protection of personal data and privacy together with current Data Protection and Privacy Office guidance. Payment services, tax and sector rules may create additional obligations. This article is general legal information, not a compliance opinion for a particular online business.
Suggested citation:
Ronald Serwanga, “E-Commerce in East
Africa: Privacy and Consumer Law” East Africa Legal Insight (13 September
2026).