Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
RwandaChecked 19 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
In one paragraph
Rwanda's starting point is that personal data stays in Rwanda. You may host it abroad, but only if the National Cyber Security Authority has given you a certificate that says so. Everyone who handles personal data must register with that authority first, foreign firms must appoint a Rwandan representative, and breaking the rules can mean prison, not just a fine.
The catch
Two extra walls catch people out. Telephone and internet companies may not send subscriber information abroad at all, and there is no permission route out of that. Separately, tax law makes every business keep its books and supporting documents inside Rwanda for ten years, whatever the privacy regulator allows.
Does this apply to me?
Yes. The law reaches a company with no office in Rwanda as soon as it handles the data of people located in Rwanda. There is no size, revenue or volume threshold to fall below. If you are based outside Rwanda you must also appoint a representative inside Rwanda, and that representative must itself be a Rwandan company that is separately registered with the regulator.High confidence
Can the data leave the country?
Only with the government's permission. The law says plainly that personal data is stored in Rwanda, and hosting it anywhere else is allowed only if the National Cyber Security Authority has issued you a certificate authorising exactly that. Telephone and internet companies are worse off again: their subscriber information may not leave Rwanda at all, and there is no permission route. Tax records must also physically stay in Rwanda for ten years.High confidence
What do I have to do to send it abroad?
Rwanda approves organisations, not countries. There is no published list of safe destinations and no list of banned ones. Instead you apply to the National Cyber Security Authority, name the exact countries and hosting providers you will use, and wait for a certificate. There is an official model contract you sign with the overseas recipient, but signing it does not by itself let you host data abroad.High confidence
Who enforces this — and are they actually working?
The National Cyber Security Authority, working through its Data Protection and Privacy Office. It is real and it is working: it opened in March 2022, has a named head, its own building in Kigali, a toll-free line, four published email addresses and a full set of application forms, and it ran training and webinars throughout 2025 and 2026. What we could not find is a single published fine or formal decision against a named organisation. Treat it as a regulator that is warming up rather than one that is already punishing.Medium confidence
How long must I keep it, and when must I delete it?
The ceiling is short and vague: keep personal data only until the purpose you collected it for is finished, then stop. The floors are long and specific. Business books and their supporting documents must be kept for ten years, physically in Rwanda. Banks, insurers, designated essential service providers and government bodies must keep their computer activity logs for at least twelve months. Where a law or a contract requires you to keep something longer, the privacy law lets you.High confidence
What happens when something goes wrong?
Two clocks under the privacy law, and they run at the same time. You have 48 hours from becoming aware of a personal data breach to tell the regulator, and 72 hours to file a full written report with all the facts you have. If the breach is likely to seriously affect people, you must also tell them, and the regulator approves how and when you do that. Suppliers have their own 48-hour clock to tell their customer.High confidence
What's the trap?
Five things that are not in the summary. One: permission to send data abroad is not permission to keep it abroad — those are two different applications, and consent gets you the first but never the second. Two: a child in Rwanda is anyone under sixteen. Three: breaking this law is a crime, with prison of one to three years for individuals and a fine of five percent of company turnover, and a court can order the business closed. Four: a foreign company needs both a Rwandan representative and a data protection officer, and the representative must be a Rwandan company that is itself registered. Five: telephone and internet companies must have a Rwandan national as their chief technical or information officer.High confidence
What's about to change?
The main thing on the horizon is a set of detailed rules underneath the privacy law. The regulator held a consultation on the draft in March 2026 with the justice ministry, the central bank, the utilities regulator, the food and drugs authority and the law reform commission, covering registration requirements and misconduct rules. Nothing has been published yet, so nothing is binding yet. Watch three powers the regulator already holds that could change the picture without any new law.Medium confidence
Hardest industry wall
  • Telecoms Regulations No 001/R/TD-ICS/RURA/016 governing telecom network security in Rwanda
  • All industries Law No 020/2023 of 31/03/2023 on tax procedures
AlgeriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
In one paragraph
Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
The catch
The national rule is already strict, and three areas are stricter still. Online shops must run their site on servers inside Algeria under a .com.dz address. Electronic trust services, such as digital signatures and electronic identity, must host all the data they collect inside Algeria. Public bodies must exchange data only over a state-run network that is deliberately kept separate from the internet. Banking, insurance and securities have no storage rule that we could find, but the central bank's own website could not be reached, so treat that as unchecked rather than settled.
Does this apply to me?
Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.High confidence
Can the data leave the country?
Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.High confidence
What do I have to do to send it abroad?
The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.High confidence
Who enforces this — and are they actually working?
The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.High confidence
What happens when something goes wrong?
There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.High confidence
What's the trap?
Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.High confidence
What's about to change?
Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.High confidence
Hardest industry wall
  • Telecoms Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique
  • E-commerce Loi n° 18-05 relative au commerce electronique
  • Government Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees