RW

Rwanda

East Africa

11Instruments
0Cases
3Regulators
65%Coverage
Overview

Rwanda regulates personal data through Law N° 058/2021 of 13 October 2021 relating to the protection of personal data and privacy, its first dedicated data protection statute, in force from 15 October 2021. The law applies to any controller or processor handling the personal data of individuals in Rwanda, including entities located outside the country, and excludes purely personal or household processing. It is grounded in the standard modern principles (lawfulness, fairness, transparency, purpose limitation, minimisation, accuracy, storage limitation, accountability), requires consent to be prior, free, specific, informed, and unambiguous, and recognises additional lawful bases including contractual necessity and legal obligation. Two features stand out. Sensitive categories, racial or ethnic origin, political opinions, religious or philosophical belief, health, genetic and biometric data, and sexual orientation, attract strict conditions, and data subjects hold the full suite of rights: access, rectification, erasure, restriction, portability, and objection. Second, Rwanda imposes a comparatively demanding data-localisation requirement: personal data must generally be stored within Rwanda unless the supervisory authority issues a certificate authorising offshore storage, with cross-border transfers otherwise limited to adequate jurisdictions. Breach notification to the authority is mandatory within 72 hours, with notice to affected individuals for high-risk breaches. Enforcement rests with the National Cyber Security Authority (NCSA), the designated supervisory authority, acting through its Data Protection and Privacy Office (dpo.gov.rw). Locating data protection supervision within the cybersecurity authority is a distinctive institutional choice. With an in-force modern statute and a named, operational regulator, Rwanda has one of the more robust frameworks in East Africa, its localisation regime making it notably stricter than several neighbours.

Topic coverage
TopicInstrumentsCasesCoverage
Data Protection30
AI Governance10
Fintech50
Cybercrime10
Digital Rights40
Platform Liability00
Telecoms10

● Covered  ◐ Partially covered  ○ Not yet covered

Instruments
rw-const-privacy·Act

Constitution of the Republic of Rwanda of 2003 (revised in 2015), Article 23 (Privacy and confidentiality of correspondence and communication)

RwandaDigital RightsData ProtectionIn Force
Verified

Enacted 26 May 2003

rw-ati-2013·Act

Law N° 04/2013 of 08/02/2013 relating to Access to Information

RwandaDigital RightsIn Force
Verified

Enacted 8 Feb 2013

rw-interception-2013·Act

Law N° 60/2013 of 22/08/2013 regulating the Interception of Communications

RwandaDigital RightsTelecomsIn Force
Verified

Enacted 22 Aug 2013

rw-cyber-2018·Act

Law N° 60/2018 of 22/08/2018 on Prevention and Punishment of Cyber Crimes

RwandaCybercrimeData ProtectionDigital RightsIn Force
Verified

Enacted 22 Aug 2018

rw-pspregulation-2023·Regulation

Regulation N° 74/2023 of 18/09/2023 governing Payment Services Providers

RwandaFintechIn Force
Verified

Enacted 18 Sept 2023

rw-sandbox-2022·Regulation

Regulation N° 41/2022 of 13/04/2022 governing the Regulatory Sandbox

RwandaFintechIn Force
Verified

Enacted 13 Apr 2022

rw-emoney-2022·Regulation

Regulation N° 54/2022 of 19/09/2022 governing Electronic Money Issuers

RwandaFintechIn Force
Verified

Enacted 19 Sept 2022

rw-vasplaw-2026·Act

Law n° 023/2026 of 25/05/2026 regulating Virtual Asset Business (Rwanda)

RwandaFintechIn Force
Verified

Enacted 25 May 2026

rw-paymentsystemlaw-2021·Act

Law N° 61/2021 of 01/11/2021 governing the Payment System

RwandaFintechIn Force
Verified

Enacted 1 Nov 2021

rw-ai-2023·Guidance

The National AI Policy (Rwanda)

RwandaAI GovernanceProposed
Verified

Enacted 20 Apr 2023

rw-dpl-2021·Act

Law N° 058/2021 of 13/10/2021 Relating to the Protection of Personal Data and Privacy

RwandaData ProtectionIn Force
Verified

Enacted 13 Oct 2021

Notable gaps

The data-localisation and registration-certificate model imposes a heavier operational burden than most regional peers and depends on the NCSA's certification capacity. ATLPF holds the primary law but no implementing regulations or guidance as separate instruments.