Don’t do SECURITY. Do business SECURELY.

Rwanda’s data protection and privacy law comes into force

Rwanda publishes Law No. 058/2021 on personal data protection and privacy, introducing registration and data localisation requirements.

Rwanda’s Law No. 058/2021 relating to the Protection of Personal Data and Privacy has been published in the Official Gazette and comes into force today, with the National Cyber Security Authority as the supervisory authority.

Key points

  • Controllers and processors must register with the National Cyber Security Authority.
  • Organisations must implement appropriate security measures and notify personal data breaches.
  • Personal data must be stored in Rwanda unless the controller or processor holds a registration certificate authorising storage outside Rwanda.
  • Data subjects gain rights including access, rectification, erasure and objection.
  • Organisations have a two-year transition period to comply.

The data localisation requirement is significant for cloud and SaaS providers. UK organisations serving Rwandan customers, or handling data on Rwandan residents, should plan for registration and review where data is hosted.

Source: Law No. 058/2021 on the protection of personal data and privacy (Rwanda Data Protection and Privacy Office)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights