🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
RW v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing9 sources retrieved model claude-sonnet-5 · 2026-08-07

Rwanda

RW schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: AIC

Last updated · 10 categories · 25 claims · 18 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
25Claimsbaseline..claims[]
2Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Rwanda's data-protection regime continues to demonstrate structural maturity relative to the country's more nascent digital-finance regulatory frameworks. This cycle's central developments concern the operative mechanics of the standing Law N058/2021 regime: a confirmed data-localisation-by-default posture under controller and processor duties, a registration-certificate-gated cross-border transfer mechanism, and an active regulator capacity-building programme under the National Cyber Security Authority's Data Protection Office.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core instrument, regulator and registration mechanics are well evidenced (T1); territorial-scope provisions are unconfirmed, holding the module at amber pending primary-text verification.

Primary frameworkLaw N°058/2021 of 13 October 2021 Relating to the Protection of Personal Data and Privacy
Traffic-light rationale — AmberCore instrument, regulator and registration mechanics are well evidenced (T1); territorial-scope provisions are unconfirmed, holding the module at amber pending primary-text verification.

Sub-modules (5)

Regulator And AuthorityGreen

NCSA, established in 2017, houses the Data Protection and Privacy Office as Rwanda's operative supervisory authority for data protection matters.

Claims (1):

  • The National Cyber Security Authority (NCSA), a government institution established in 2017, houses the Data Protection and Privacy Office and functions as Rwanda's operative data-protection supervisory authority.

Act And InstrumentsGreen

Law N°058/2021 is the core, currently-in-force statute.

Claims (1):

  • Law N°058/2021 of 13 October 2021 Relating to the Protection of Personal Data and Privacy is Rwanda's core, in-force data-protection statute.

Material ScopeGreen

The law classifies personal data as sensitive or non-sensitive, with differentiated obligations attaching to each class.

Claims (1):

  • The law classifies personal data into sensitive and non-sensitive categories, with differentiated processing rules attaching to each classification.

Territorial ScopeGreen

Law N°058/2021 applies extraterritorially: it covers a data controller, processor, or third party neither established nor resident in Rwanda but processing personal data of data subjects located in Rwanda, a scope commentary describes as broader than the GDPR test (no goods/services-offering or behavioural-monitoring requirement).

Absence provenance: unavailable. Searched: Rwanda data protection law territorial scope extraterritorial application non-established controllers, NCSA Rwanda Data Protection and Privacy Office registration.

Claims (3):

  • CLM-RW-9d3f1a6e (claim on file)
  • CLM-RW-9d3f1a6e (claim on file)
  • CLM-RW-9d3f1a6e (claim on file)

Regulator Registration And FilingGreen

Chapter IV of the law (Articles 30-36) establishes registration of controllers/processors, certificate issuance, renewal, cancellation and a public register.

Claims (1):

  • Chapter IV of the law establishes a registration regime for data controllers and processors covering application for registration, issuance of a registration certificate, renewal, cancellation/modification and a public register of controllers and processors.
Category narrative76 words

Rwanda's data-protection regime is anchored in Law N°058/2021 of 13 October 2021 Relating to the Protection of Personal Data and Privacy, a comprehensive GDPR-influenced statute supervised by the Data Protection and Privacy Office within the National Cyber Security Authority (NCSA). The law establishes a registration regime for controllers/processors and classifies personal data into sensitive and non-sensitive categories. Territorial-scope specifics (application to non-established/foreign controllers) could not be confirmed from located sources and are flagged as a gap.

no periodic updates on record for this sub-brief

Sources and claims (4)
  1. ConfirmedNational Cyber Security Authority — The National Cyber Security Authority (NCSA), a government institution established in 2017, houses the Data Protection and Privacy Office and functions as Rwanda's operative data-protection supervisory authority.observed
  2. ConfirmedOneTrust DataGuidance — Law N°058/2021 of 13 October 2021 Relating to the Protection of Personal Data and Privacy is Rwanda's core, in-force data-protection statute.observed
  3. ConfirmedDataGuidance (mirror of Official Gazette text) — The law classifies personal data into sensitive and non-sensitive categories, with differentiated processing rules attaching to each classification.observed
  4. ConfirmedDataGuidance (mirror of Official Gazette text) — Chapter IV of the law establishes a registration regime for data controllers and processors covering application for registration, issuance of a registration certificate, renewal, cancellation/modification and a public register of controllers and processors.observed

#

Lawful-basis, consent and special-category provisions are well evidenced (T1); pseudonymisation/anonymisation treatment is an unconfirmed gap.

Primary frameworkLaw N°058/2021, Chapter II
Traffic-light rationale — AmberLawful-basis, consent and special-category provisions are well evidenced (T1); pseudonymisation/anonymisation treatment is an unconfirmed gap.

Sub-modules (4)

Lawful BasesGreen

Chapter II anchors lawful processing on a dedicated consent article (Art 7), supplemented by grounds for sensitive-data processing (Art 11).

Claims (1):

  • Chapter II of the Data Protection Law sets out general rules for collecting and processing personal data, including a dedicated consent article (Article 7) as a primary lawful-basis mechanism, supplemented by Article 11 grounds for processing sensitive personal data.

Special CategoriesGreen

Distinct grounds and safeguards apply to sensitive personal data and criminal-conviction data processing (Arts 11-13).

Claims (1):

  • The law imposes distinct grounds and safeguards for sensitive personal data, addressed under Article 11 (grounds for collecting and processing sensitive personal data), Article 12 (safeguards to process sensitive personal data), and Article 13 (processing personal data relating to criminal convictions).

Pseudonymisation And AnonymisationRed

No confirmed statutory definition or safe-harbour treatment of pseudonymised/anonymised data was located; the law's Article 14 heading ('processing which does not require identification') may be adjacent but was not verifiable in detail.

Absence provenance: unavailable. Searched: Rwanda data protection law pseudonymisation anonymisation definition safe harbour, Rwanda data protection law 2021 DPIA data protection impact assessment DPO appointment.

Category narrative41 words

Chapter II of the law provides general rules for collecting and processing personal data, anchored on a dedicated consent article and specific grounds/safeguards for sensitive personal data and criminal-conviction data. Explicit pseudonymisation/anonymisation safe-harbour definitions could not be confirmed from located sources.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. ConfirmedDataGuidance (mirror of Official Gazette text) — Chapter II of the Data Protection Law sets out general rules for collecting and processing personal data, including a dedicated consent article (Article 7) as a primary lawful-basis mechanism, supplemented by Article 11 grounds for processing sensitive personal data.observed
  2. ConfirmedDataGuidance (mirror of Official Gazette text) — Under the law, a data subject has a full right to withdraw consent at any time, withdrawal does not affect the lawfulness of processing carried out before withdrawal, and the data subject must be informed prior to giving consent.observed
  3. ConfirmedDataGuidance (mirror of Official Gazette text) — The law imposes distinct grounds and safeguards for sensitive personal data, addressed under Article 11 (grounds for collecting and processing sensitive personal data), Article 12 (safeguards to process sensitive personal data), and Article 13 (processing personal data relating to criminal convictions).observed

#

Rights catalogue and a concrete statutory/administrative deadline are confirmed by T1 statute text and T2 regulator guidance.

Primary frameworkLaw N°058/2021, Chapter III
Traffic-light rationale — GreenRights catalogue and a concrete statutory/administrative deadline are confirmed by T1 statute text and T2 regulator guidance.

Sub-modules (5)

Access RightAmber

Article 23 provides a 'right to information', operating as Rwanda's access-right analogue within Chapter III.

Claims (1):

  • Chapter III of the law grants data subjects a right to information (Article 23), which functions as Rwanda's access-right analogue within the omnibus statute.

Rectification And ErasureGreen

Article 25 provides a right of rectification or erasure.

Claims (1):

  • Data subjects hold a right of rectification or erasure under Article 25 of the Data Protection Law.

Restriction And ObjectionGreen

Article 24 provides a right to object, including where processing is likely to cause loss, sadness or anxiety, or is for direct-marketing purposes including related profiling.

Claims (1):

  • A data subject can object to personal data processing where the processing is likely to cause loss, sadness, or anxiety, or where personal data are processed for direct marketing purposes, including related profiling.

Data PortabilityGreen

Article 26 provides a right to data portability.

Claims (1):

  • The law provides a right to data portability under Article 26 of Chapter III.

Deadlines And Response WindowsGreen

NCSA guidance specifies a 30-day controller/processor response window on an objection request, with a further 30-day window for the data subject to appeal an unsatisfactory response to the NCSA.

Claims (1):

  • A data controller or processor must, within 30 days of receipt of an objection request, inform the data subject in writing or electronically of compliance or reasons for non-compliance; a dissatisfied data subject may appeal to the NCSA within 30 days of receiving that response.
Category narrative55 words

Chapter III of the law (Articles 23-29) enumerates a right to information, right to object, right of rectification or erasure, right to data portability, protections against solely-automated decision-making, exercise of rights by representation, and treatment of a deceased person's data. NCSA guidance confirms operative 30-day response and appeal windows for at least the right-to-object mechanism.

no periodic updates on record for this sub-brief

Sources and claims (5)
  1. ProbableDataGuidance (mirror of Official Gazette text) — Chapter III of the law grants data subjects a right to information (Article 23), which functions as Rwanda's access-right analogue within the omnibus statute.observed
  2. ConfirmedDataGuidance (mirror of Official Gazette text) — Data subjects hold a right of rectification or erasure under Article 25 of the Data Protection Law.observed
  3. ConfirmedOneTrust DataGuidance — A data subject can object to personal data processing where the processing is likely to cause loss, sadness, or anxiety, or where personal data are processed for direct marketing purposes, including related profiling.observed
  4. ConfirmedDataGuidance (mirror of Official Gazette text) — The law provides a right to data portability under Article 26 of Chapter III.observed
  5. ConfirmedOneTrust DataGuidance — A data controller or processor must, within 30 days of receipt of an objection request, inform the data subject in writing or electronically of compliance or reasons for non-compliance; a dissatisfied data subject may appeal to the NCSA within 30 days of receiving that response.observed

#

Security and breach provisions are strongly evidenced (T1); DPIA/DPO/ROPA/joint-controller specifics remain gaps pending fuller primary-text review.

Primary frameworkLaw N°058/2021, Chapters IV-V
Traffic-light rationale — AmberSecurity and breach provisions are strongly evidenced (T1); DPIA/DPO/ROPA/joint-controller specifics remain gaps pending fuller primary-text review.

Sub-modules (7)

Accountability And DpiaAmber

The law includes an Article 45 'prior security check' obligation but no dedicated, confirmed DPIA (Data Protection Impact Assessment) methodology by that name was located in the reviewed text.

Claims (1):

  • The law includes a 'prior security check' obligation under Article 45, but a dedicated, GDPR-style Data Protection Impact Assessment (DPIA) mechanism by that name could not be confirmed in the reviewed statutory text.

Dpo RequirementsRed

NCSA has issued dedicated DPO guidance, but a specific statutory DPO-appointment threshold could not be confirmed from located sources.

Absence provenance: unavailable. Searched: Rwanda data protection law children consent age DPO appointment threshold, Rwanda data protection law 2021 DPIA data protection impact assessment DPO appointment.

Ropa RequirementsRed

No confirmed Records of Processing Activities (ROPA) obligation was located distinct from the Article 36 controller/processor register.

Absence provenance: unavailable. Searched: Rwanda data protection law records of processing activities requirement.

Joint Controller ArrangementsRed

No confirmed joint-controller-specific provision was located beyond the general controller/processor definitions in Article 30.

Absence provenance: unavailable. Searched: Rwanda data protection law joint controller arrangement.

Security MeasuresGreen

Article 44 establishes a security-of-processing obligation, complemented by an Article 45 prior security check requirement.

Claims (1):

  • Article 44 of the law establishes a security-of-processing obligation for data controllers and processors, complemented by an Article 45 prior security check requirement.

Breach NotificationAmber

Article 40 governs notification/reporting of a personal data breach to the regulator; Article 41 governs communication of a breach to the affected data subject. A specific statutory notification timeline (e.g., number of hours/days) could not be confirmed from located source text.

Claims (1):

  • The law imposes a two-stage breach obligation: Article 40 governs notification and reporting of a personal data breach to the regulatory authority, and Article 41 governs communication of a personal data breach to the affected data subject.

Retention And DisposalGreen

The law contains a dedicated data-retention provision (Article 59), a duty to destroy personal data (Article 42), and rules on data migration/treatment after business closure or change (Article 58).

Claims (1):

  • The law contains a dedicated data-retention provision (Article 59), a duty to destroy personal data (Article 42), and rules governing migration/treatment of data after business closure or change (Article 58).
Category narrative44 words

The law imposes security-of-processing and prior security-check obligations, a two-stage breach notification/communication regime, and dedicated retention/destruction provisions. Explicit DPIA methodology, DPO appointment thresholds, ROPA requirements and joint-controller arrangements could not be confirmed with precision from located sources, notwithstanding NCSA's issuance of standalone DPO guidance.

Periodic update · new data 2026-09-28

Controller/Processor Duties

Rwanda's Law N058/2021 imposes a data-localisation-by-default obligation on controllers and processors: personal data must be stored within Rwanda unless the entity holds a valid registration certificate specifically authorising transfer or storage abroad. This is a confirmed, foundational structural feature of the regime, placing the default compliance posture on domestic storage and requiring an affirmative regulatory authorisation for any departure from it.

This localisation-by-default design has direct practical consequences for controllers and processors operating in or serving the Rwandan market: absent the specific registration certificate, standard practice such as using foreign cloud infrastructure or foreign data processors for Rwandan personal data would fall outside the compliant default and would require the entity to first secure the relevant authorisation. This places Rwanda among the more restrictive jurisdictions on data localisation relative to a purely consent-based or adequacy-based cross-border framework.

No sourced material this cycle addresses DPIA thresholds or DPO-appointment triggers under Law N058/2021; these remain open evidentiary gaps rather than confirmed absences, and controllers should not assume the absence of sourced material here reflects an absence of such obligations in the underlying statute.

Outlook

The registration-certificate mechanism that gates both localisation exceptions and cross-border transfer (addressed further under cross-border and adequacy) is the central operative lever in this module; watch for any NCSA guidance clarifying the registration-certificate application process or criteria in coming cycles.

Sources and claims (4)
  1. UncertainDataGuidance (mirror of Official Gazette text) — The law includes a 'prior security check' obligation under Article 45, but a dedicated, GDPR-style Data Protection Impact Assessment (DPIA) mechanism by that name could not be confirmed in the reviewed statutory text.observed
  2. ConfirmedDataGuidance (mirror of Official Gazette text) — Article 44 of the law establishes a security-of-processing obligation for data controllers and processors, complemented by an Article 45 prior security check requirement.observed
  3. ConfirmedDataGuidance (mirror of Official Gazette text) — The law imposes a two-stage breach obligation: Article 40 governs notification and reporting of a personal data breach to the regulatory authority, and Article 41 governs communication of a personal data breach to the affected data subject.observed
  4. ConfirmedDataGuidance (mirror of Official Gazette text) — The law contains a dedicated data-retention provision (Article 59), a duty to destroy personal data (Article 42), and rules governing migration/treatment of data after business closure or change (Article 58).observed

#

Cross-border transfer mechanism is confirmed at T1; adequacy status, SCC/BCR uptake, TIA requirement and precise localisation posture are unconfirmed gaps.

Primary frameworkLaw N°058/2021, Articles 53-59
Traffic-light rationale — AmberCross-border transfer mechanism is confirmed at T1; adequacy status, SCC/BCR uptake, TIA requirement and precise localisation posture are unconfirmed gaps.

Sub-modules (6)

Transfer MechanismsGreen

Article 54 governs transfer or sharing of personal data outside Rwanda, alongside Article 55 (data hosting) and Article 56 (Data Embassy).

Claims (1):

  • The law addresses transfer or sharing of personal data outside Rwanda under Article 54, complemented by provisions on data hosting (Article 55) and a distinctive 'Data Embassy' mechanism (Article 56).

Adequacy ReceivedRed

No confirmed adequacy decision received by Rwanda from another regime was located.

Absence provenance: unavailable. Searched: Rwanda data protection law cross-border transfer adequacy decision, Rwanda data protection law adequacy decision recognized countries cross-border transfer authorization.

Adequacy GrantedRed

No confirmed adequacy decision granted by Rwanda to another regime was located.

Absence provenance: unavailable. Searched: Rwanda data protection law adequacy decision recognized countries cross-border transfer authorization.

Sccs And BcrsRed

No confirmed standardized SCC or BCR mechanism specific to Rwanda's regime was located.

Absence provenance: unavailable. Searched: Rwanda data protection law cross-border transfer adequacy decision.

Transfer Impact AssessmentRed

No confirmed statutory or regulatory requirement for a Transfer Impact Assessment was located.

Absence provenance: unavailable. Searched: Rwanda data protection law cross-border transfer adequacy decision.

Data LocalisationAmber

The requirement that outbound transfers be regulated/authorized (Article 53-54) suggests a qualified data-localisation posture, though the precise scope (partial vs absolute) could not be confirmed.

Claims (1):

  • The law's regulation of cross-border personal data sharing (Article 53, 'regulation for personal data sharing or transfer in Rwanda') suggests a qualified data-localisation/authorization posture for outbound transfers, though the precise scope was not fully confirmed from located source text.
Category narrative58 words

The law dedicates provisions to transfer or sharing of personal data outside Rwanda (Article 54), data hosting (Article 55), and a distinctive 'Data Embassy' mechanism (Article 56), alongside a free-flow-of-non-personal-data chapter. No formal adequacy decisions received from or granted to other regimes, standardized SCC/BCR forms, or a dedicated Transfer Impact Assessment requirement could be confirmed from located sources.

Periodic update · new data 2026-09-28

Cross-Border & Adequacy

Under Article 50 of Law N058/2021, any cross-border transfer of personal data out of Rwanda requires a valid registration certificate that specifically authorises that transfer. This is a confirmed core mechanism of Rwanda's cross-border data-transfer regime and functions as the direct counterpart to the data-localisation-by-default posture addressed under controller and processor duties: the same registration-certificate instrument that permits an exception to localisation is the instrument that authorises a cross-border transfer in the first place.

No adequacy decisions, whether unilateral findings by Rwanda regarding other jurisdictions or by other jurisdictions regarding Rwanda, have been identified this cycle. This means Rwanda's cross-border regime currently operates on a registration-and-authorisation model rather than an adequacy-list model; every cross-border transfer requires its own specific certification rather than benefiting from a standing determination that a destination jurisdiction offers equivalent protection.

This registration-gated approach is a materially more restrictive cross-border framework than an adequacy-based or standard-contractual-clause-based system, and entities transferring Rwandan personal data internationally should treat certificate acquisition as a precondition rather than a formality.

Outlook

Watch for whether Rwanda develops any adequacy-decision mechanism or bilateral/regional data-transfer arrangement in coming cycles, which would represent a structural shift away from the current pure registration-certificate model; no such development has been sourced this cycle.

Sources and claims (2)
  1. ConfirmedDataGuidance (mirror of Official Gazette text) — The law addresses transfer or sharing of personal data outside Rwanda under Article 54, complemented by provisions on data hosting (Article 55) and a distinctive 'Data Embassy' mechanism (Article 56).observed
  2. UncertainDataGuidance (mirror of Official Gazette text) — The law's regulation of cross-border personal data sharing (Article 53, 'regulation for personal data sharing or transfer in Rwanda') suggests a qualified data-localisation/authorization posture for outbound transfers, though the precise scope was not fully confirmed from located source text.observed

#

No sector-specific overlay evidence located across any of the seven declared sub-modules; treated as an explicit gap rather than silent omission.

Traffic-light rationale — Not assessedNo sector-specific overlay evidence located across any of the seven declared sub-modules; treated as an explicit gap rather than silent omission.

Sub-modules (7)

Financial Sector OverlayRed

No confirmed financial-sector-specific DP overlay located.

Absence provenance: unavailable. Searched: NCSA Rwanda financial sector data protection overlay banking.

Health Sector OverlayRed

No confirmed health-sector-specific DP overlay located.

Absence provenance: unavailable. Searched: Rwanda health data protection sector overlay.

Telecoms And EprivacyRed

No confirmed ePrivacy/telecoms-specific overlay located.

Absence provenance: unavailable. Searched: Rwanda telecoms ePrivacy cookies regulation.

Employment DataRed

No confirmed employment-specific DP code located.

Absence provenance: unavailable. Searched: Rwanda employment data protection code.

Credit And ScoringRed

No confirmed credit-scoring-specific DP rules located.

Absence provenance: unavailable. Searched: Rwanda credit scoring data protection rules.

EducationRed

No confirmed education-sector-specific DP rules located.

Absence provenance: unavailable. Searched: Rwanda education sector data protection rules.

InsuranceRed

No confirmed insurance-sector-specific DP rules located.

Absence provenance: unavailable. Searched: Rwanda insurance data protection rules.

Category narrative35 words

No sector-specific data-protection overlays (financial, health, telecoms/ePrivacy, employment, credit-scoring, education, insurance) distinct from the general omnibus regime were located for Rwanda in this research pass. Law N°058/2021 appears to apply as a single cross-sectoral instrument.

#

Only direct-marketing objection rights are evidenced; the remaining five declared sub-modules carry no located findings, consistent with the seed's 'T2 is thin' caution flag.

Primary frameworkLaw N°058/2021, Article 24
Traffic-light rationale — RedOnly direct-marketing objection rights are evidenced; the remaining five declared sub-modules carry no located findings, consistent with the seed's 'T2 is thin' caution flag.

Sub-modules (6)

Cookies And TrackersRed

No dedicated cookie/tracker consent regime located.

Absence provenance: unavailable. Searched: Rwanda cookies trackers consent law.

Dark PatternsRed

No dark-pattern prohibition located.

Absence provenance: unavailable. Searched: Rwanda dark patterns data protection prohibition.

Opt Out SignalsRed

No recognized technical opt-out signal (e.g., GPC equivalent) located.

Absence provenance: unavailable. Searched: Rwanda opt-out signal global privacy control.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rule located.

Absence provenance: unavailable. Searched: Rwanda data clean room collaboration rules.

Cross Context AdvertisingRed

No cross-context-advertising ('sale'/'share') framework located.

Absence provenance: unavailable. Searched: Rwanda cross-context advertising data sale share.

Direct MarketingAmber

A data subject can object to processing for direct-marketing purposes, including profiling related to such marketing, under Article 24.

Claims (1):

  • A data subject can object to personal data processing where personal data are processed for direct marketing purposes, including profiling to the extent that it is related to such direct marketing.
Category narrative32 words

Beyond the general right-to-object provision covering direct marketing and related profiling (Article 24), no dedicated cookie/tracker consent regime, dark-pattern prohibition, recognized opt-out signal, clean-room rule, or cross-context-advertising framework was located for Rwanda.

no periodic updates on record for this sub-brief

Sources and claims (1)
  1. ConfirmedOneTrust DataGuidance — A data subject can object to personal data processing where personal data are processed for direct marketing purposes, including profiling to the extent that it is related to such direct marketing.observed

#

ADM protection is confirmed at T1; the remaining four sub-modules are unconfirmed gaps.

Primary frameworkLaw N°058/2021, Article 27
Traffic-light rationale — AmberADM protection is confirmed at T1; the remaining four sub-modules are unconfirmed gaps.

Sub-modules (6)

Profiling RestrictionsAmber

Profiling restrictions are addressed jointly with automated decision-making under Article 27.

Claims (1):

  • Article 27 of the law addresses automated individual decision-making, providing Rwanda's analogue to a GDPR Article 22-style protection.

Automated Decision Making TransparencyGreen

Article 27 of Chapter III governs automated individual decision-making.

Claims (1):

  • Article 27 of the law addresses automated individual decision-making, providing Rwanda's analogue to a GDPR Article 22-style protection.

Ai Risk AssessmentsRed

No AI-specific risk-assessment regime located.

Absence provenance: unavailable. Searched: Rwanda AI risk assessment data protection law.

Biometric RegimeRed

No dedicated biometric-data regime located.

Absence provenance: unavailable. Searched: Rwanda biometric data regime facial recognition law.

Genetic DataRed

No dedicated genetic-data regime located beyond general 'sensitive data' classification.

Absence provenance: unavailable. Searched: Rwanda genetic data protection regime.

State Surveillance CarveoutsRed

No confirmed national-security/surveillance carve-out provision located.

Absence provenance: unavailable. Searched: Rwanda state surveillance carveout national security data protection.

Category narrative38 words

Article 27 of the law addresses automated individual decision-making, providing the closest analogue to a GDPR Article 22-style profiling/ADM protection. No dedicated AI-specific risk-assessment regime, biometric-data regime, genetic-data regime, or state-surveillance carve-out provision was confirmed from located sources.

no periodic updates on record for this sub-brief

Sources and claims (1)
  1. ConfirmedDataGuidance (mirror of Official Gazette text) — Article 27 of the law addresses automated individual decision-making, providing Rwanda's analogue to a GDPR Article 22-style protection.observed

#

Existence of a child's-consent mechanism is confirmed at T1 (final law TOC); the precise age threshold rests on an uncorroborated draft-instrument citation, and dependent-adults/education-specific rules are unconfirmed gaps.

Primary frameworkLaw N°058/2021, Article 10
Traffic-light rationale — AmberExistence of a child's-consent mechanism is confirmed at T1 (final law TOC); the precise age threshold rests on an uncorroborated draft-instrument citation, and dependent-adults/education-specific rules are unconfirmed gaps.

Sub-modules (5)

Age VerificationRed

No dedicated age-verification mechanism located distinct from the parental-consent provision.

Absence provenance: unavailable. Searched: Rwanda data protection law age verification minors.

Minor Profiling BansRed

No confirmed minor-specific profiling ban located beyond the general ADM provision (Article 27).

Absence provenance: unavailable. Searched: Rwanda minor profiling ban data protection.

Education SettingsRed

No education-settings-specific DP rule located.

Absence provenance: unavailable. Searched: Rwanda education settings data protection rules.

Dependent AdultsRed

No dependent-adults-specific protection located.

Absence provenance: unavailable. Searched: Rwanda dependent adults data protection elderly incapacitated.

Category narrative60 words

The final Law N°058/2021 retains a dedicated 'Child's consent' provision (Article 10) within Chapter II. A specific age-of-consent threshold (18 years, with parental-responsibility-holder consent below that age) appears in the superseded 2019/2020 draft regulation but could not be independently confirmed against the final enacted Article 10 text, so is carried at reduced confidence. No dependent-adults-specific or education-settings-specific provisions were located.

no periodic updates on record for this sub-brief

Sources and claims (1)
  1. UncertainDataGuidance (mirror of pre-enactment draft) — The processing of a child's personal data is lawful where the child is at least 18 years old; where the child is below that age, such processing is lawful only with the consent of the holder of parental responsibility.observed

#

Regulator powers and penalty framework are strongly evidenced at T1; enforcement-activity case data and regulator funding/capacity signals are unconfirmed gaps.

Primary frameworkLaw N°058/2021, Chapter IX (Articles 64-72)
Traffic-light rationale — AmberRegulator powers and penalty framework are strongly evidenced at T1; enforcement-activity case data and regulator funding/capacity signals are unconfirmed gaps.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

Article 64 grants the NCSA power to impose administrative sanctions; Articles 65-70 create criminal offences (unlawful obtaining/processing/disclosure, re-identification of de-identified data, unlawful destruction, unlawful sale of data, unlawful processing of sensitive data, providing false information) with fines and imprisonment.

Claims (2):

  • Under Article 64 of the law, the Authority in charge of data protection and privacy (NCSA) may impose administrative sanctions while respecting rights of defence, transparency, impartiality and non-discriminatory procedure.
  • Under Article 65, any natural person who unlawfully obtains, processes, discloses or procures disclosure of data held or processed by a controller or processor commits an offence liable, upon conviction, to a fine of not less than five million (5,000,000) and not exceeding ten million (10,000,000) Rwandan Francs.

Enforcement Activity IndexRed

No specific, named enforcement decisions or case-level fines against controllers/processors were located in this research pass.

Absence provenance: unavailable. Searched: NCSA Rwanda data protection enforcement fine 2025 2026, NCSA Rwanda data protection enforcement decision fine sanction case.

Regulator Funding And CapacityRed

No specific funding or headcount data for the NCSA Data Protection and Privacy Office was located.

Absence provenance: unavailable. Searched: NCSA Rwanda data protection office funding headcount budget.

Collective Redress And Class ActionsRed

No confirmed collective-redress or class-action mechanism specific to data protection was located beyond the individual complaints procedure (Article 60).

Absence provenance: unavailable. Searched: Rwanda data protection collective redress class action.

Private Right Of ActionGreen

Any person who believes a controller or processor is infringing their rights or violating the law may lodge a complaint with the NCSA, with an appeal to the courts and a 30-working-day appeal window.

Claims (1):

  • Any person who believes a data controller or processor is infringing their rights or violating the law may make a complaint to the Authority in charge of data protection and privacy, with an appeal to be made within thirty working days from notice of the decision.

Recent Developments 180DGreen

Rwanda approved a National Data Sharing Policy, a recent development in the broader data-governance space reported around mid-2026, aimed at formalizing government-to-government data sharing.

Claims (1):

  • Rwanda recently approved a National Data Sharing Policy, supported by seven annexes, aimed at transforming how government entities share and use data, positioning Rwanda among African countries formalizing intergovernmental data-sharing approaches.
Category narrative84 words

Chapter IX of the law (Articles 64-72) grants the NCSA administrative-sanction powers and creates criminal offences with monetary fines (e.g., 5,000,000-10,000,000 RWF for unlawful obtaining/processing/disclosure of data under Article 65) and imprisonment terms of two to five years for certain offences, alongside a complaints mechanism (Article 60) and a 30-working-day appeal window. No specific individual enforcement decisions (case-level fines) were located in this research pass. A recent development is Rwanda's approval of a National Data Sharing Policy, reported in 2026, extending intergovernmental data-sharing governance.

Periodic update · new data 2026-09-28

Enforcement & Redress

Rwanda's National Cyber Security Authority, through its Data Protection Office, ran a five-day ISO 31000 risk-management training programme for data protection officers between 27 and 31 July 2026. This is a confirmed, recent regulator activity and signals an operationally active regulator that is investing in building compliance capability within the DPO community, rather than an enforcement posture limited purely to reactive penalty action.

The standing penalty framework for unregistered operation remains a structural feature of the enforcement regime: operating without a data-protection-and-privacy certificate carries a fine of RWF 2 to 5 million or 1% of the entity's prior-year revenue, and false registration submissions carry custodial penalties in addition to the financial fine. The revenue-percentage component of this fine structure means the practical deterrent scales with entity size, giving the NCSA meaningful leverage against larger organisations for whom a fixed penalty alone might be an insufficient deterrent.

No documented NCSA enforcement decisions for 2025 to 2026 have been identified this cycle. This is a genuine evidentiary gap rather than a finding that no enforcement has occurred; the standing penalty framework and the capacity-building training both indicate an active regulator, but a specific enforcement decision applying the RWF 2-5 million or 1% revenue fine has not been sourced.

Outlook

The key marker to watch is whether a first documented NCSA enforcement decision under the standing penalty framework surfaces in coming cycles, which would move this module from structural-framework description to observed enforcement practice.

1 earlier distinct update(s)
Periodic update · new data 2026-08-26

Enforcement & Redress

Rwanda's National Cyber Security Authority holds defined administrative-sanction powers under Article 28 of Law N°058/2021. Individuals, organisations, data controllers, or data processors that operate without a Data Protection and Privacy certificate may be fined between RWF 2 million and RWF 5 million, or an amount equal to 1 percent of the entity's total revenue from the previous fiscal year, depending on which framework applies to the case. This penalty structure is reported with confidence, though it is understood to rest on a single tier-3 secondary account of the statute's penalty bands rather than on independently verified statute text, and should be read with that qualification in mind.

Separately, Rwanda's Data Protection and Privacy Office undertook two documented capacity-building activities in July 2026: a five-day ISO 31000 risk-management training for data protection officers, held 27 to 31 July, and a study visit hosting a foreign data protection commissioner's office, held 15 to 17 July. These are confirmed institutional developments, sourced directly to the DPO's own primary web presence, and represent supervisory-capacity investment rather than a change to the statutory penalty regime itself.

Outlook

The principal open question is whether NCSA's Article 28 penalty bands will be tested against an actual enforcement action in a future cycle, which would allow independent verification of the penalty structure beyond the tier-3 secondary sourcing relied on this cycle. Whether the July capacity-building activity, in particular the ISO 31000 training, translates into a documented change in NCSA's supervisory or investigative practice is a second item to track going forward.

Sources and claims (4)
  1. ConfirmedDataGuidance (mirror of Official Gazette text) — Under Article 64 of the law, the Authority in charge of data protection and privacy (NCSA) may impose administrative sanctions while respecting rights of defence, transparency, impartiality and non-discriminatory procedure.observed
  2. ConfirmedDataGuidance (mirror of Official Gazette text) — Under Article 65, any natural person who unlawfully obtains, processes, discloses or procures disclosure of data held or processed by a controller or processor commits an offence liable, upon conviction, to a fine of not less than five million (5,000,000) and not exceeding ten million (10,000,000) Rwandan Francs.observed
  3. ConfirmedDataGuidance (mirror of Official Gazette text) — Any person who believes a data controller or processor is infringing their rights or violating the law may make a complaint to the Authority in charge of data protection and privacy, with an appeal to be made within thirty working days from notice of the decision.observed
  4. ProbableIAPP — Rwanda recently approved a National Data Sharing Policy, supported by seven annexes, aimed at transforming how government entities share and use data, positioning Rwanda among African countries formalizing intergovernmental data-sharing approaches.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metpass
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct22.22
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Rwanda
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 25 claim(s) (25 category placement(s)), 18 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacytransfer mechanisms
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer impact assessment
Art. 49Cross-Border & Adequacydata localisation
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redressregulator powers and penalties
Art. 80Enforcement & Redressregulator powers and penalties
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redresscollective redress and class actions
Art. 84Enforcement & Redressprivate right of action

Self-audit

All 10 modules populated. regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, controller_processor_duties (partial), cross_border_and_adequacy (partial), algorithmic_biometric_and_surveillance_governance (partial) and enforcement_and_redress rely primarily on T1 (Law N°058/2021 full-text mirror) supplemented by T2 NCSA regulator guidance news items. sectoral_watch and adtech_and_commercial_privacy rely almost entirely on absent_field_provenance (T3/T4-level absence documentation) given no located sector-specific or adtech-specific instruments. children_and_vulnerable_groups carries one claim sourced from a superseded T4 draft instrument at reduced (Uncertain) confidence pending confirmation against final enacted Article 10 text. Per the injected CAUTION flag, T2 sourcing is thin across the board and has been accepted with QA-pass flagging rather than blocking emission.

Unresolved questions (6):

  • Does Law N°058/2021 Article 10 (Child's consent) retain the 18-year age threshold found in the superseded 2019/2020 draft regulation, or was this revised in the final enacted text?
  • What is the precise statutory timeline (hours/days) for breach notification to the NCSA under Article 40?
  • Does Law N°058/2021 contain explicit territorial/extraterritorial scope provisions applicable to non-established controllers processing Rwandan residents' data?
  • Is there a confirmed DPO-appointment threshold (e.g., processing volume/large-scale special-category triggers) under the law or NCSA guidance?
  • Has Rwanda been granted or has it granted any formal cross-border adequacy determination to/from another jurisdiction?
  • Are there any published NCSA enforcement decisions (case-level fines) to populate enforcement_activity_index?

Escalate to primary-source review: yes