WorldPrivacyAtlas
Laws by country

Data Security & Breach Notification

Law relating to the Protection of Personal Data and Privacy — personal data breach notification

Rwanda DPP Law breach duty

Rwanda · October 15, 2021; two-year transition period ended October 15, 2023

Verify details

Rwanda gives 48 hours, not 72: a controller must notify the National Cyber Security Authority within 48 hours of becoming aware of a personal data breach, and a processor must inform its controller within 48 hours of discovery. That is among the tightest windows in this dataset and it sits alongside Rwanda's mandatory registration regime for controllers and processors, so a business caught by the law is already known to the regulator when an incident happens. Penalties under the law include administrative fines calibrated to global turnover for corporate offenders. Marked 'check': the 48-hour figure was triangulated across independent legal-reference sources rather than read in the Official Gazette text, and the NCSA has continued to issue implementing guidance.

Law No. 058/2021 of 13/10/2021Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.