WorldPrivacyAtlas
Laws by country

Comprehensive Privacy Law

Law relating to the Protection of Personal Data and Privacy

Rwanda DPP Law

Rwanda · October 15, 2021; two-year transition period ended October 15, 2023

Verify details

A GDPR-influenced statute with explicit extraterritorial reach: it applies to controllers and processors established or residing in Rwanda that process personal data while in Rwanda, and to those established or residing outside Rwanda that process the personal data of data subjects located in Rwanda. The two-year transition ended October 15, 2023, so obligations are fully operative. Supervision sits with the National Cyber Security Authority, acting through its Data Protection and Privacy Office, which operates a mandatory registration regime for data controllers and processors (with fees), alongside DPO appointment duties, breach notification, impact assessments, and authorization requirements for cross-border transfers. Penalties include administrative fines calibrated to global turnover for corporate offenders and, for certain violations, criminal liability.

Law No. 058/2021 of 13/10/2021, Art. 3 (scope)Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.