Research hub / Rwanda
§ Dossier · EAST AFRICA · updated 22 July 2026

Rwanda

Regulator
National Cyber Security Authority (NCSA) ↗
Law
Law No. 058/2021 on the Protection of Personal Data and Privacy ↗
Status
Law in force, enforcement not found
Authority
National Cyber Security Authority (NCSA), established 2017
in force
DP law status
Law No. 058/2021 on the Protection of Personal Data and Privacy
None found
enforcement activity
as of the last landscape verification
No
decisions published
no public record to collect

The law

Law No. 058/2021 of 13 October 2021 relating to the Protection of Personal Data and Privacy IN FORCE

commenced 2021-10-15 (Official Gazette publication; registration transition ran to October 2023) · Official full text ↗

Scope
Any information relating to an identified or identifiable natural person (art. 3(1°)), processed by natural persons, public or private bodies; the sensitive-data definition adds 'family details' and criminal records to the usual categories (art. 3(2°)).
Key obligations
Mandatory registration of data controllers AND processors with the NCSA (art. 29), with a 30-day certificate decision and filing content incl. intended transfer destinations (arts. 30-31); DPO designation for corporate bodies (except courts), large-scale regular and systematic monitoring, and large-scale sensitive/convict data processing (art. 40); 48-hour breach notification chain: processor→controller and controller→NCSA (art. 43), high-risk communication to data subjects (art. 45); GDPR-family principles and data subject rights
DPO required
Yes, in defined cases: processing by public or private corporate bodies (except courts), large-scale regular and systematic monitoring, or large-scale processing of sensitive personal data and convicts' data (art. 40).
Registration
Yes: controllers and processors register with the NCSA (art. 29); the certificate issues within 30 days (art. 30); operating without a certificate is administratively sanctionable (art. 53).
Cross-border transfers
No adequacy mechanism - transfers outside Rwanda ride one of three routes (art. 48): supervisory-authority authorisation on proof of appropriate safeguards, the data subject's consent, or necessity grounds (contract, contract in the data subject's interest, public interest, legal claims, vital interests, compelling legitimate interests with safeguards, ratified international instruments); every transfer-enabling arrangement needs a written contract (art. 49) and the authority may prohibit or suspend transfers. Art. 50: personal data is stored IN Rwanda by default - storage abroad only with an authority-issued registration certificate. (Verified from the archived Official Gazette text 2026-07-11, S27.)
Breach notification
Controller notifies the NCSA within 48 hours of becoming aware of a breach; processor notifies the controller within 48 hours (art. 43); high-risk breaches communicated to data subjects in writing or electronically (art. 45), with GDPR-style exemptions.
Penalties
Administrative fines of RWF 2,000,000 to 5,000,000 or 1% of global turnover of the preceding year for corporates (art. 53) for misconduct incl. unregistered operation, missing DPO and breach-duty failures; criminal offences (arts. 56-61) incl. unlawful disclosure, re-identification, data sale and false information: corporates convicted face 5% of annual turnover (art. 62), plus seizure and closure (art. 63).
Authority
National Cyber Security Authority (NCSA)

Verified 2026-07-10

Access to information

Law No. 04/2013 on Access to Information IN FORCE

The regulator

Authority
National Cyber Security Authority (NCSA)
Website
https://cyber.gov.rw ↗
Established
2017
Operational
Yes
Enforcing
No enforcement activity found
Publishes decisions
No

Enforcement record

No enforcement decisions could be found for this jurisdiction as of the last verification pass (22 July 2026). A country with no published enforcement is a data point, not a gap: see the 54-state publication scorecard.

Related reading

Analysis is at lawlab.africa/analysis; method, inclusion rules and the correction policy are on the methodology page.


Track Rwanda

Get decision alerts by email

Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.