Cross-Border Data Transfer
Law relating to the Protection of Personal Data and Privacy — storage and transfer of personal data outside Rwanda
Rwanda · October 15, 2021; two-year transition period ended October 15, 2023
Verify detailsRwanda's default is localisation with case-by-case release, not adequacy with a mechanism menu. Personal data is to be stored in Rwanda, and transferring it outside the country requires authorisation from the National Cyber Security Authority — which is a materially heavier operational burden than signing standard clauses, because it puts a regulator in the path of each transfer arrangement rather than after it. That sits on top of Rwanda's mandatory registration regime for controllers and processors. A business planning to serve Rwandan users from an overseas cloud region should treat the authorisation as a gating item in the project plan, not a compliance formality. Marked 'check': the article numbering and the precise scope of the localisation default versus the authorisation route were triangulated across independent legal-reference sources rather than read in the Official Gazette text — confirm with the NCSA before designing an architecture around it.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.