§ Dossier · EAST AFRICA · updated 22 July 2026
in force
DP law status
Law No. 058/2021 on the Protection of Personal Data and Privacy
None found
enforcement activity
as of the last landscape verification
No
decisions published
no public record to collect
The law
Law No. 058/2021 of 13 October 2021 relating to the Protection of Personal Data and Privacy IN FORCE
commenced 2021-10-15 (Official Gazette publication; registration transition ran to October 2023) · Official full text ↗
- Scope
- Any information relating to an identified or identifiable natural person (art. 3(1°)), processed by natural persons, public or private bodies; the sensitive-data definition adds 'family details' and criminal records to the usual categories (art. 3(2°)).
- Key obligations
- Mandatory registration of data controllers AND processors with the NCSA (art. 29), with a 30-day certificate decision and filing content incl. intended transfer destinations (arts. 30-31); DPO designation for corporate bodies (except courts), large-scale regular and systematic monitoring, and large-scale sensitive/convict data processing (art. 40); 48-hour breach notification chain: processor→controller and controller→NCSA (art. 43), high-risk communication to data subjects (art. 45); GDPR-family principles and data subject rights
- DPO required
- Yes, in defined cases: processing by public or private corporate bodies (except courts), large-scale regular and systematic monitoring, or large-scale processing of sensitive personal data and convicts' data (art. 40).
- Registration
- Yes: controllers and processors register with the NCSA (art. 29); the certificate issues within 30 days (art. 30); operating without a certificate is administratively sanctionable (art. 53).
- Cross-border transfers
- No adequacy mechanism - transfers outside Rwanda ride one of three routes (art. 48): supervisory-authority authorisation on proof of appropriate safeguards, the data subject's consent, or necessity grounds (contract, contract in the data subject's interest, public interest, legal claims, vital interests, compelling legitimate interests with safeguards, ratified international instruments); every transfer-enabling arrangement needs a written contract (art. 49) and the authority may prohibit or suspend transfers. Art. 50: personal data is stored IN Rwanda by default - storage abroad only with an authority-issued registration certificate. (Verified from the archived Official Gazette text 2026-07-11, S27.)
- Breach notification
- Controller notifies the NCSA within 48 hours of becoming aware of a breach; processor notifies the controller within 48 hours (art. 43); high-risk breaches communicated to data subjects in writing or electronically (art. 45), with GDPR-style exemptions.
- Penalties
- Administrative fines of RWF 2,000,000 to 5,000,000 or 1% of global turnover of the preceding year for corporates (art. 53) for misconduct incl. unregistered operation, missing DPO and breach-duty failures; criminal offences (arts. 56-61) incl. unlawful disclosure, re-identification, data sale and false information: corporates convicted face 5% of annual turnover (art. 62), plus seizure and closure (art. 63).
- Authority
- National Cyber Security Authority (NCSA)
Verified 2026-07-10
Access to information
Law No. 04/2013 on Access to Information IN FORCE
The regulator
- Authority
- National Cyber Security Authority (NCSA)
- Website
- https://cyber.gov.rw ↗
- Established
- 2017
- Operational
- Yes
- Enforcing
- No enforcement activity found
- Publishes decisions
- No
Enforcement record
No enforcement decisions could be found for this jurisdiction as of the last verification pass (22 July 2026). A country with no published enforcement is a data point, not a gap: see the 54-state publication scorecard.
Related reading
Analysis is at lawlab.africa/analysis;
method, inclusion rules and the correction policy are on the
methodology page.
Track Rwanda
Get decision alerts by email
Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.