Rwanda
East Africa
Rwanda regulates personal data through Law N° 058/2021 of 13 October 2021 relating to the protection of personal data and privacy, its first dedicated data protection statute, in force from 15 October 2021. The law applies to any controller or processor handling the personal data of individuals in Rwanda, including entities located outside the country, and excludes purely personal or household processing. It is grounded in the standard modern principles (lawfulness, fairness, transparency, purpose limitation, minimisation, accuracy, storage limitation, accountability), requires consent to be prior, free, specific, informed, and unambiguous, and recognises additional lawful bases including contractual necessity and legal obligation. Two features stand out. Sensitive categories, racial or ethnic origin, political opinions, religious or philosophical belief, health, genetic and biometric data, and sexual orientation, attract strict conditions, and data subjects hold the full suite of rights: access, rectification, erasure, restriction, portability, and objection. Second, Rwanda imposes a comparatively demanding data-localisation requirement: personal data must generally be stored within Rwanda unless the supervisory authority issues a certificate authorising offshore storage, with cross-border transfers otherwise limited to adequate jurisdictions. Breach notification to the authority is mandatory within 72 hours, with notice to affected individuals for high-risk breaches. Enforcement rests with the National Cyber Security Authority (NCSA), the designated supervisory authority, acting through its Data Protection and Privacy Office (dpo.gov.rw). Locating data protection supervision within the cybersecurity authority is a distinctive institutional choice. With an in-force modern statute and a named, operational regulator, Rwanda has one of the more robust frameworks in East Africa, its localisation regime making it notably stricter than several neighbours.
| Topic | Instruments | Cases | Coverage |
|---|---|---|---|
| Data Protection | 3 | 0 | ◐ |
| AI Governance | 1 | 0 | ◐ |
| Fintech | 5 | 0 | ◐ |
| Cybercrime | 1 | 0 | ◐ |
| Digital Rights | 4 | 0 | ◐ |
| Platform Liability | 0 | 0 | ○ |
| Telecoms | 1 | 0 | ◐ |
● Covered ◐ Partially covered ○ Not yet covered
Constitution of the Republic of Rwanda of 2003 (revised in 2015), Article 23 (Privacy and confidentiality of correspondence and communication)
Enacted 26 May 2003
Law N° 04/2013 of 08/02/2013 relating to Access to Information
Enacted 8 Feb 2013
Law N° 60/2013 of 22/08/2013 regulating the Interception of Communications
Enacted 22 Aug 2013
Law N° 60/2018 of 22/08/2018 on Prevention and Punishment of Cyber Crimes
Enacted 22 Aug 2018
Regulation N° 74/2023 of 18/09/2023 governing Payment Services Providers
Enacted 18 Sept 2023
Regulation N° 41/2022 of 13/04/2022 governing the Regulatory Sandbox
Enacted 13 Apr 2022
Regulation N° 54/2022 of 19/09/2022 governing Electronic Money Issuers
Enacted 19 Sept 2022
Law n° 023/2026 of 25/05/2026 regulating Virtual Asset Business (Rwanda)
Enacted 25 May 2026
Law N° 61/2021 of 01/11/2021 governing the Payment System
Enacted 1 Nov 2021
The National AI Policy (Rwanda)
Enacted 20 Apr 2023
Law N° 058/2021 of 13/10/2021 Relating to the Protection of Personal Data and Privacy
Enacted 13 Oct 2021
The data-localisation and registration-certificate model imposes a heavier operational burden than most regional peers and depends on the NCSA's certification capacity. ATLPF holds the primary law but no implementing regulations or guidance as separate instruments.