WorldPrivacyAtlas
Laws by country

Cross-Border Data Transfer

Law relating to the Protection of Personal Data and Privacy — storage and transfer of personal data outside Rwanda

Rwanda transfer authorisation

Rwanda · October 15, 2021; two-year transition period ended October 15, 2023

Verify details

Rwanda's default is localisation with case-by-case release, not adequacy with a mechanism menu. Personal data is to be stored in Rwanda, and transferring it outside the country requires authorisation from the National Cyber Security Authority — which is a materially heavier operational burden than signing standard clauses, because it puts a regulator in the path of each transfer arrangement rather than after it. That sits on top of Rwanda's mandatory registration regime for controllers and processors. A business planning to serve Rwandan users from an overseas cloud region should treat the authorisation as a gating item in the project plan, not a compliance formality. Marked 'check': the article numbering and the precise scope of the localisation default versus the authorisation route were triangulated across independent legal-reference sources rather than read in the Official Gazette text — confirm with the NCSA before designing an architecture around it.

Law No. 058/2021 of 13/10/2021, Art. 48 and related provisions on data localisationRead regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.