Jurisdiction Guides / Africa
Rwanda Privacy & Data Protection Laws
Every regime below can apply to a business handling Rwanda residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
A GDPR-influenced statute with explicit extraterritorial reach: it applies to controllers and processors established or residing in Rwanda that process personal data while in Rwanda, and to those established or residing outside Rwanda that process the personal data of data subjects located in Rwanda. The two-year transition ended October 15, 2023, so obligations are fully operative. Supervision sits with the National Cyber Security Authority, acting through its Data Protection and Privacy Office, which operates a mandatory registration regime for data controllers and processors (with fees), alongside DPO appointment duties, breach notification, impact assessments, and authorization requirements for cross-border transfers. Penalties include administrative fines calibrated to global turnover for corporate offenders and, for certain violations, criminal liability.
Cross-Border Data Transfer · 1
Rwanda's default is localisation with case-by-case release, not adequacy with a mechanism menu. Personal data is to be stored in Rwanda, and transferring it outside the country requires authorisation from the National Cyber Security Authority — which is a materially heavier operational burden than signing standard clauses, because it puts a regulator in the path of each transfer arrangement rather than after it. That sits on top of Rwanda's mandatory registration regime for controllers and processors. A business planning to serve Rwandan users from an overseas cloud region should treat the authorisation as a gating item in the project plan, not a compliance formality. Marked 'check': the article numbering and the precise scope of the localisation default versus the authorisation route were triangulated across independent legal-reference sources rather than read in the Official Gazette text — confirm with the NCSA before designing an architecture around it.
Data Security & Breach Notification · 1
Rwanda gives 48 hours, not 72: a controller must notify the National Cyber Security Authority within 48 hours of becoming aware of a personal data breach, and a processor must inform its controller within 48 hours of discovery. That is among the tightest windows in this dataset and it sits alongside Rwanda's mandatory registration regime for controllers and processors, so a business caught by the law is already known to the regulator when an incident happens. Penalties under the law include administrative fines calibrated to global turnover for corporate offenders. Marked 'check': the 48-hour figure was triangulated across independent legal-reference sources rather than read in the Official Gazette text, and the NCSA has continued to issue implementing guidance.
Other Africa jurisdictions