Rwanda’s Law No. 058/2021 relating to the Protection of Personal Data and Privacy has been published in the Official Gazette and comes into force today, with the National Cyber Security Authority as the supervisory authority.
Key points
- Controllers and processors must register with the National Cyber Security Authority.
- Organisations must implement appropriate security measures and notify personal data breaches.
- Personal data must be stored in Rwanda unless the controller or processor holds a registration certificate authorising storage outside Rwanda.
- Data subjects gain rights including access, rectification, erasure and objection.
- Organisations have a two-year transition period to comply.
The data localisation requirement is significant for cloud and SaaS providers. UK organisations serving Rwandan customers, or handling data on Rwandan residents, should plan for registration and review where data is hosted.
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.