IOC Law / Africa Intelligence / Rwanda

Data Protection and Privacy in Rwanda

← Back to the Rwanda guide

Law No. 058/2021 applies to controllers and processors established in Rwanda and to persons outside Rwanda who process personal data relating to people located in Rwanda. The Rwanda Data Protection and Privacy Office states that anyone intending to act as controller or processor must register. Its registration guide treats operating without the required certificate as administrative misconduct.

Registration is not a substitute for compliance. Before applying, map the categories of data and data subjects, purposes, lawful grounds, recipients, processors, security risks, retention, locations and international transfers. The supervisory authority states that it issues a certificate within 30 working days after a compliant application and that renewal should be sought within 45 working days before expiry. Changes to registered information should be managed promptly.

Core controls include clear notices; valid consent where consent is the applicable ground; purpose limitation and data minimisation; accurate records; retention and deletion rules; data-subject request procedures; processor agreements; role-based access; security testing; incident response; staff training; and designation of a data protection officer where the law requires one.

Rwanda has specific localisation and transfer controls. The DPO’s cross-border transfer guidance states that overseas transfer may require supervisory-authority authorisation and appropriate safeguards, and that an overseas recipient should be governed by a written agreement allocating compliance responsibilities. Storage outside Rwanda is permitted only under a valid certificate authorising that storage. Cloud hosting, group HR systems, CRM, analytics, support access and disaster recovery should therefore be analysed before procurement, not after deployment.