Rwanda
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Rwanda's starting point is that personal data stays in Rwanda. You may host it abroad, but only if the National Cyber Security Authority has given you a certificate that says so. Everyone who handles personal data must register with that authority first, foreign firms must appoint a Rwandan representative, and breaking the rules can mean prison, not just a fine.
Data governance in Rwanda
The eight things that decide how you handle data about people in Rwanda. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law reaches a company with no office in Rwanda as soon as it handles the data of people located in Rwanda. There is no size, revenue or volume threshold to fall below. If you are based outside Rwanda you must also appoint a representative inside Rwanda, and that representative must itself be a Rwandan company that is separately registered with the regulator.
Article 2 of Law No 058/2021 applies the law both to controllers and processors established or residing in Rwanda and to those who are 'neither established nor resides in Rwanda, but processes personal data of data subjects located in Rwanda'. Note the wording is data subjects LOCATED in Rwanda, not Rwandan citizens. Article 29 makes registration mandatory for anyone who intends to be a controller or a processor, with no threshold; the National Cyber Security Authority's registration guide confirms this covers 'all public and private organizations, professionals such as doctors, lawyers, engineers, architects, notaries'. Article 39 requires foreign controllers and processors to designate a representative in writing, and the regulator's own guide adds that the representative must be a corporate body established in Rwanda and must itself hold a controller or processor registration. The representative duty is separate from, and additional to, the duty under Article 40 to designate a data protection officer.
Sources
- Official sourceRepublic of Rwanda, Official Gazette (hosted by the National Cyber Security Authority)Law No 058/2021 of 13/10/2021 relating to the protection of personal data and privacy, Articles 2, 29, 30, 39 and 40 — Official Gazette no Special of 15/10/2021
cyber.gov.rw
“This Law applies to: ... the data controller, the data processor and a third party who: a) is established or resides in Rwanda and processes personal data while in Rwanda; b) is neither established nor resides in Rwanda, but processes personal data of data subjects located in Rwanda.”
Link checked 19 August 2026
- Official sourceData Protection and Privacy Office, National Cyber Security AuthorityGuide on Designation of a Representative, June 2024
dpo.gov.rw
“The designated representative must fulfill the following criteria. They must: 1. Be a corporate body or legal entity established in Rwanda ...; 2. Be registered as a Data Controller or Data Processor with NCSA”
Link checked 19 August 2026
- Official sourceNational Cyber Security AuthorityGuide on Data Controller and Data Processor Registration
cyber.gov.rw
Link checked 19 August 2026
Where the data is allowed to live
Only with the government's permission. The law says plainly that personal data is stored in Rwanda, and hosting it anywhere else is allowed only if the National Cyber Security Authority has issued you a certificate authorising exactly that. Telephone and internet companies are worse off again: their subscriber information may not leave Rwanda at all, and there is no permission route. Tax records must also physically stay in Rwanda for ten years.
Two different provisions are at work and they are easy to confuse. Article 50 governs STORAGE: 'The data controller or the data processor stores personal data in Rwanda. However, the storage of personal data outside Rwanda is only permitted if the data controller or the data processor holds a valid registration certificate authorising him or her to store personal data outside Rwanda, which is issued by the supervisory authority.' There is no consent exception and no necessity exception to Article 50. Article 48 governs SHARING AND TRANSFER to a third party outside Rwanda, and that one does have alternatives to regulator authorisation: the data subject's consent, or necessity for a contract, a public interest, a legal claim, someone's vital interests, a compelling legitimate interest, or an international instrument Rwanda has ratified. So a transfer can be lawful under Article 48 while the resulting offshore hosting is still unlawful under Article 50. SECTOR OVERRIDES: (1) TELECOMS — closed. RURA's telecom network security regulation requires that licensees ensure 'Subscriber's information are not transferred, stored or processed outside of the Republic of Rwanda', with no carve-out. (2) TAX AND ACCOUNTING RECORDS, all sectors — a copy must stay. The tax procedures law requires businesses to maintain books and documents for ten years in Rwanda. (3) HEALTH — no separate wall found; the regulator's July 2025 health sector guidance applies the general law and adds no localisation rule of its own. (4) FINANCE, INSURANCE, SECURITIES, GOVERNMENT CLOUD, EDUCATION, GAMBLING, MAPPING — no sector localisation rule found on an official Rwandan source, checked 19 August 2026, confidence medium. The regulator's own application form for offshore storage lists finance, telecommunication, health, education and aviation as the sectors it expects to see, which suggests it handles these through the general Article 50 permission rather than through separate sector bans.
Sources
- Official sourceRepublic of Rwanda, Official Gazette (hosted by the National Cyber Security Authority)Law No 058/2021, Articles 48, 49 and 50 (sharing and transfer outside Rwanda; contract for transfer; storage of personal data)
cyber.gov.rw
“The data controller or the data processor stores personal data in Rwanda. However, the storage of personal data outside Rwanda is only permitted if the data controller or the data processor holds a valid registration certificate authorising him or her to store personal data outside Rwanda, which is issued by the supervisory authority.”
Link checked 19 August 2026
- Official sourceRwanda Utilities Regulatory AuthorityRegulations No 001/R/TD-ICS/RURA/016 governing telecom network security in Rwanda, Article 16
rura.rw
“Subscriber's information are not transferred, stored or processed outside of the Republic of Rwanda.”
Link checked 19 August 2026
- Official sourceRwanda Revenue AuthorityTaxation Procedures, August 2023 — summary of Law No 020/2023 of 31/03/2023 on tax procedures, books of accounts and records keeping
rra.gov.rw
“Maintain books & documents for 10 years in Rwanda starting from 1st January following the fiscal year to which they relate.”
Link checked 19 August 2026
- Official sourceData Protection and Privacy OfficeCloud Storage Under Rwanda's Data Protection Law: What You Need to Know, 25 July 2025
dpo.gov.rw
“storing personal data outside Rwanda requires authorization from the National Cyber Security Authority (NCSA) among other compliance requirements in the Law.”
Link checked 19 August 2026
Sending data out of the country
Rwanda approves organisations, not countries. There is no published list of safe destinations and no list of banned ones. Instead you apply to the National Cyber Security Authority, name the exact countries and hosting providers you will use, and wait for a certificate. There is an official model contract you sign with the overseas recipient, but signing it does not by itself let you host data abroad.
There are two separate application routes and two separate forms, both live on the regulator's website today: 'Authorization to Store Outside Rwanda' and 'Authorization to Transfer Outside Rwanda'. The storage application asks for the name of each hosting provider, the destination country for primary storage and for disaster recovery separately, the type of hosting (shared, virtual private server, dedicated, cloud), any third parties involved, and a description of the data protection laws of each destination country. Supporting documents required are an application letter to the Chief Executive Officer of the National Cyber Security Authority, the hosting agreements, the storage architecture, and a data protection impact assessment for hosting abroad. The regulator has also published Standard Contractual Clauses for Personal Data Transfer Outside Rwanda (February 2024), drafted to satisfy Article 49's requirement of a written contract with the overseas recipient. The regulator's frequently asked questions explain that transfer authorisation is normally granted as part of registration, because the registration application already asks you to name the countries you will send data to, and that a later change means applying to amend your registration certificate. Note two things about the model. First, this is a case-by-case permission model, not a blocklist or an allowlist, so there is no list to check and no list that can be quietly populated. Second, the regulator holds a standing power to prohibit or suspend any transfer outside Rwanda in order to protect people's rights.
Sources
- Official sourceData Protection and Privacy Office, National Cyber Security AuthorityApplication Form — Authorization to Store Personal Data Outside Rwanda
dpo.gov.rw
“SUPPORTING DOCUMENTS 1. Application letter addressed to the Chief Executive Officer of NCSA 2. Hosting agreement (s) with service provider(s) 3. Storage architecture 4. Data Protection Impact Assessment (DPIA) for hosting personal data outside Rwanda”
Link checked 19 August 2026
- Official sourceData Protection and Privacy Office, National Cyber Security AuthorityStandard Contractual Clauses for Personal Data Transfer Outside Rwanda, February 2024
dpo.gov.rw
“The purpose of these standard contractual clauses is to ensure that the transfer of personal data from Rwanda is carried out in compliance with Article 49 of Law No 058/2021”
Link checked 19 August 2026
- Official sourceData Protection and Privacy OfficeServices — Authorization to Store Outside Rwanda
dpo.gov.rw
Link checked 19 August 2026
- Official sourceData Protection and Privacy OfficeFrequently asked questions — storage, sharing and transfer of personal data
dpo.gov.rw
“Authorization provided for under Art.48 (1) of DPP law to transfer personal data outside Rwanda is done during registration to operate as a data controller or data processor”
Link checked 19 August 2026
The regulator, and whether it actually acts
The National Cyber Security Authority, working through its Data Protection and Privacy Office. It is real and it is working: it opened in March 2022, has a named head, its own building in Kigali, a toll-free line, four published email addresses and a full set of application forms, and it ran training and webinars throughout 2025 and 2026. What we could not find is a single published fine or formal decision against a named organisation. Treat it as a regulator that is warming up rather than one that is already punishing.
Law No 058/2021 designates the National Cyber Security Authority as the supervisory authority. The Data Protection and Privacy Office was launched on 31 March 2022. Observable evidence of activity in the last twelve months: a five-day ISO 31000 risk management course for data protection officers in July 2026; a study visit to Kenya's Office of the Data Protection Commissioner in July 2026; an awareness session with Bank of Kigali's insurance arm in June 2026; a week-long training for public and private sector data protection officers in June 2026; a Data Privacy Week campaign from 26 to 30 January 2026 themed 'Compliance is Beyond Registration'; a webinar drawing over 300 data protection officers; and a stakeholder consultation on draft implementing regulations in March 2026 attended by the Ministry of Justice, the National Bank of Rwanda, the utilities regulator and the food and drugs authority. Sector regulators enforce alongside it: the Rwanda Utilities Regulatory Authority audits telecom licensees at least once a year under its network security regulation, the National Bank of Rwanda supervises financial institutions, and the Rwanda Revenue Authority enforces the ten-year in-country books rule. We searched for published enforcement decisions and found none on the regulator's own site; the absence of a public decisions register is itself the finding.
Sources
- Official sourceNational Cyber Security AuthorityWho we are — Data Protection and Privacy Office
dpo.gov.rw
“On 31 March 2022, the National Cyber Security Authority officially launched its data protection office, which will spearhead all activities related to protecting personal data of individuals in Rwanda.”
Link checked 19 August 2026
- Official sourceData Protection and Privacy OfficeNews archive showing continuous regulator activity from April 2025 to July 2026
dpo.gov.rw
Link checked 19 August 2026
- Official sourceNational Cyber Security Authority2026 Data Privacy Week: Compliance Beyond Registration, 20 January 2026
cyber.gov.rw
“the campaign emphasizes that compliance is more than certification, it requires accountability, transparency, and a sustained commitment to safeguarding personal data.”
Link checked 19 August 2026
How long you must keep it — and when to delete it
The ceiling is short and vague: keep personal data only until the purpose you collected it for is finished, then stop. The floors are long and specific. Business books and their supporting documents must be kept for ten years, physically in Rwanda. Banks, insurers, designated essential service providers and government bodies must keep their computer activity logs for at least twelve months. Where a law or a contract requires you to keep something longer, the privacy law lets you.
The ceiling sits in Article 52: retain personal data until the purposes of the processing are fulfilled. The same article then lists the exceptions that let you keep it longer, and they are wide: retention authorised by law; retention required by a contract between the parties; where the data relates to the function or activity for which it was collected; and for preventing, detecting, investigating, prosecuting or punishing an offender. That structure means Rwanda resolves a floor-versus-ceiling conflict in favour of the floor — a longer statutory or contractual retention period overrides the delete-when-done principle rather than colliding with it. On the floors: the tax procedures law requires books and documents to be maintained for ten years in Rwanda, starting from 1 January following the fiscal year they relate to. The National Cyber Security Authority's Minimum Cybersecurity Standards, issued on 28 July 2023 in three versions for the financial sector, for essential service providers and for public institutions, require an event logging system with archiving procedures 'at least for a period of 12 months', and extend the same duty to outsourced service providers by contract. Separately, failure to carry out personal data logging is itself a listed administrative misconduct under Article 53, though the law sets no period for it.
Sources
- Official sourceRepublic of Rwanda, Official Gazette (hosted by the National Cyber Security Authority)Law No 058/2021, Articles 52 and 53
cyber.gov.rw
“The data controller or the data processor retains personal data until the purposes of the processing of personal data are fulfilled.”
Link checked 19 August 2026
- Official sourceRwanda Revenue AuthorityTaxation Procedures, August 2023 — books of accounts and records keeping
rra.gov.rw
“Maintain books & documents for 10 years in Rwanda”
Link checked 19 August 2026
- Official sourceNational Cyber Security AuthorityMinimum Cybersecurity Standards for Essential Service Providers, version 1.0, 28 July 2023
cyber.gov.rw
“An event logging system in networks and ICT systems should be implemented, and procedures for archiving the collected logs should be developed (at least for a period of 12 months)”
Link checked 19 August 2026
- Official sourceNational Cyber Security AuthorityMinimum Cybersecurity Standards for the Financial Sector, version 1.0, 28 July 2023
cyber.gov.rw
Link checked 19 August 2026
If something goes wrong
Two clocks under the privacy law, and they run at the same time. You have 48 hours from becoming aware of a personal data breach to tell the regulator, and 72 hours to file a full written report with all the facts you have. If the breach is likely to seriously affect people, you must also tell them, and the regulator approves how and when you do that. Suppliers have their own 48-hour clock to tell their customer.
Article 43 gives the controller 48 hours from awareness to communicate the breach to the supervisory authority, and gives a processor 48 hours from awareness to notify its controller. Article 44 then requires a report within 72 hours with all facts available, covering the nature of the breach, the approximate numbers of people and records involved, the contact details of the data protection officer, the measures taken to address and mitigate it, and — unusually — the controller's own proposal for how and when to tell affected individuals, for the regulator's approval. Article 45 covers communication to individuals where there is high risk. Missing any of these three steps is a separate listed administrative misconduct. Two more clocks sit on top for some organisations. Telecom licensees must 'immediately' share critical and major security incidents with the utilities regulator, and file a monthly report for moderate ones. Financial institutions, essential service providers and public institutions are told under the Minimum Cybersecurity Standards that Rwanda's national incident response team should be notified of every cyber incident; the standards set no fixed hour count for that, which is a gap worth building conservative internal deadlines around.
Sources
- Official sourceRepublic of Rwanda, Official Gazette (hosted by the National Cyber Security Authority)Law No 058/2021, Articles 43, 44 and 45
cyber.gov.rw
“In case of personal data breach, the data controller, within forty-eight (48) hours after being aware of the incident, must communicate the personal data breach to the supervisory authority.”
Link checked 19 August 2026
- Official sourceRwanda Utilities Regulatory AuthorityRegulations No 001/R/TD-ICS/RURA/016 governing telecom network security in Rwanda, Article 28
rura.rw
“Every Licensee must immediately share with the Regulatory Authority any security incidents which have occurred and considered as critical and major”
Link checked 19 August 2026
- Official sourceData Protection and Privacy OfficeFrequently asked questions — notification of personal data breach and report on personal data breach
dpo.gov.rw
Link checked 19 August 2026
What catches people out
Five things that are not in the summary. One: permission to send data abroad is not permission to keep it abroad — those are two different applications, and consent gets you the first but never the second. Two: a child in Rwanda is anyone under sixteen. Three: breaking this law is a crime, with prison of one to three years for individuals and a fine of five percent of company turnover, and a court can order the business closed. Four: a foreign company needs both a Rwandan representative and a data protection officer, and the representative must be a Rwandan company that is itself registered. Five: telephone and internet companies must have a Rwandan national as their chief technical or information officer.
(1) Article 48 gives you seven routes to a lawful transfer, including the person's consent and contractual necessity. Article 50 gives you exactly one route to lawful offshore storage: a registration certificate that says so. Cloud hosting is storage. This is the single most common way to be compliant on paper and non-compliant in fact. (2) Article 9 sets the children's threshold at under sixteen, which is at the top of the international range and higher than the thirteen used by many global products. (3) Chapter VIII creates real offences, not administrative penalties: unlawful access, collection, use, sharing, transfer or disclosure of personal data carries one to three years' imprisonment and a fine of seven to ten million Rwandan francs (roughly five to eight thousand US dollars) for an individual; a company convicted of the same offences pays five percent of its previous year's annual turnover; and Article 63 lets the court order permanent or temporary closure of the entity or the premises. Separately, administrative misconducts under Article 53 — including operating without a registration certificate or letting one expire — attract a fine of two to five million Rwandan francs (roughly sixteen hundred to four thousand US dollars) or one percent of global turnover for a company. Note that word: GLOBAL turnover for the administrative sanction, annual turnover for the criminal one. (4) The representative and the data protection officer are separate obligations under Articles 39 and 40, and failing to designate a data protection officer is a listed misconduct. (5) The telecom network security regulation requires the licensee to have a Rwandan native as its chief technical officer or chief information officer, and to get the regulator's approval before outsourcing any service or operation to a third party. (6) A bonus trap: the registration application asks for your hosting invoice or agreement, so the regulator sees where your data actually sits at the moment you apply.
Sources
- Official sourceRepublic of Rwanda, Official Gazette (hosted by the National Cyber Security Authority)Law No 058/2021, Articles 9, 39, 40, 48, 50, 53, 56, 62 and 63
cyber.gov.rw
“Upon conviction, he or she is liable to an imprisonment of not less than one (1) year but not more than three (3) years and a fine of not less than seven million Rwandan francs (RWF 7,000,000) but not more than ten million Rwandan francs (RWF 10,000,000) or one of these penalties.”
Link checked 19 August 2026
- Official sourceRwanda Utilities Regulatory AuthorityRegulations No 001/R/TD-ICS/RURA/016 governing telecom network security in Rwanda, Article 18
rura.rw
“The Licensee is required to have a Rwandan native as its Chief Technical Officer (CTO) Chief Information officer (CIO) or equivalent functions”
Link checked 19 August 2026
- Official sourceNational Cyber Security AuthorityGuide on Data Controller and Data Processor Registration — documents to be submitted, including hosting invoice or agreement
cyber.gov.rw
Link checked 19 August 2026
What's changing next
The main thing on the horizon is a set of detailed rules underneath the privacy law. The regulator held a consultation on the draft in March 2026 with the justice ministry, the central bank, the utilities regulator, the food and drugs authority and the law reform commission, covering registration requirements and misconduct rules. Nothing has been published yet, so nothing is binding yet. Watch three powers the regulator already holds that could change the picture without any new law.
PENDING: draft implementing regulations under Law No 058/2021, consulted on 5 March 2026, focused on registration requirements and misconduct provisions. As of 19 August 2026 we found no published text and no adoption date, so this remains a draft with no legal effect. DORMANT SWITCHES, all already in the statute and all usable without consultation: (1) Article 48 final paragraph lets the supervisory authority prohibit or suspend any transfer of personal data outside Rwanda to protect people's rights — a single decision could strand an offshore architecture. (2) Article 53 lets the supervisory authority make a regulation creating additional administrative misconducts and sanctions beyond the nine listed in the law. (3) Article 51 requires the supervisory authority to put in place a regulation on migrating and managing personal data when a business changes hands or closes — that regulation does not appear to exist yet, and when it lands it will bite on every acquisition and wind-down. (4) A registration certificate can be cancelled before expiry on fifteen working days' written notice, which is a faster commercial risk than any fine. Also worth watching: Rwanda gazetted its first law regulating virtual asset business in mid-2026, which brings a new population of firms into scope of the registration and offshore storage regime; we could not verify the text on a Rwandan government domain and so make no claim about its data provisions.
Sources
- Official sourceData Protection and Privacy OfficeDPO engages stakeholders to shape Rwanda's Data Privacy regulations, 5 March 2026
dpo.gov.rw
“the Data Protection & Privacy Office convened a consultation workshop on the draft regulations under Rwanda's Data Protection and Privacy Law. The session brought together representatives from key institutions including the Ministry of Justice, the National Bank of Rwanda, RURA, Rwanda FDA, and the Rwanda Law Reform Commission.”
Link checked 19 August 2026
- Official sourceRepublic of Rwanda, Official Gazette (hosted by the National Cyber Security Authority)Law No 058/2021, Articles 48 (final paragraph), 51, 53 and 66 — standing regulator powers
cyber.gov.rw
“The supervisory authority, in order to protect the rights and freedoms of the data subject, may prohibit or suspend the transfer of personal data outside Rwanda.”
Link checked 19 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Regulations No 001/R/TD-ICS/RURA/016 governing telecom network security in Rwanda
Directly binding regulation · Regulations No 001/R/TD-ICS/RURA/016, signed at Kigali on 02/06/2016 following the Regulatory Board meeting of 06/05/2016
A hard wall for telephone and internet operators. Subscriber information, including call records and billing data, may not be transferred, stored or processed outside Rwanda. The same regulation requires the licensee's chief technical or information officer to be a Rwandan national and requires regulator approval before any outsourcing.
Enforced by Rwanda Utilities Regulatory Authority
Transfer model: Not allowed
What it makes you do
- Keep the data in the countrySubscriber information — voice, SMS, data, call detail records and billing information — must not be transferred, stored or processed outside Rwanda. No permission route is provided.
- Report cyber incidentsCritical and major incidents must be shared with the regulator immediately; moderate incidents monthly.
- Independent auditThe regulator audits every licensee at least once a year.
- Written vendor contractRegulator approval is required before outsourcing any service or operation to a third party.
- Secure the data
What it costs if you get it wrong
- Fixed maximum fine: RWF 5,000,000 — about $4 thousandNon-compliance with any requirement of the regulation — fine of RWF 1,000,000 to RWF 5,000,000
- Daily fine until fixed: RWF 500,000 per day — about $390Continued non-compliance after an enforcement notice
Sources
- Official sourceRwanda Utilities Regulatory AuthorityRegulations No 001/R/TD-ICS/RURA/016 governing telecom network security in Rwanda, Articles 16, 18, 28, 29, 33 and 34
rura.rw
“Any licensee shall ensure that: ... (e) Subscriber's information are not transferred, stored or processed outside of the Republic of Rwanda.”
Link checked 19 August 2026
Minimum Cybersecurity Standards for the Financial Sector (with parallel editions for Essential Service Providers and for Public Institutions)
Government rules · Issued by the National Cyber Security Authority under Articles 9(3) and 10(1) of Law No 26/2017 of 31/05/2017 establishing NCSA; version 1.0
Baseline cyber rules the national cyber authority issued for financial institutions, with near-identical editions for designated essential service providers and for public bodies. The operationally sharp bit is a twelve-month minimum for keeping system activity logs, which also has to be pushed down into outsourcing contracts.
Enforced by National Cyber Security Authority — Data Protection and Privacy Office
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep logs — 1 yearEvent logging system plus archiving procedures for at least 12 months. Outsourced providers must be contractually bound to the same.
- Report cyber incidentsRwanda's national incident response team, Rw-CSIRT, should be notified of every cyber incident. No fixed hour deadline is stated.
- Secure the data
- Independent audit
- Keep records of processingRecords and their retention periods must be identified.
Sources
- Official sourceNational Cyber Security AuthorityMinimum Cybersecurity Standards for the Financial Sector, version 1.0, 28 July 2023
cyber.gov.rw
“The requirements contained in this document apply only to financial sector institutions operating within the territory of the Republic of Rwanda.”
Link checked 19 August 2026
- Official sourceNational Cyber Security AuthorityMinimum Cybersecurity Standards for Essential Service Providers, version 1.0, 28 July 2023
cyber.gov.rw
“procedures for archiving the collected logs should be developed (at least for a period of 12 months)”
Link checked 19 August 2026
- Official sourceNational Cyber Security AuthorityMinimum Cybersecurity Standards for Public Institutions, version 1.0, 28 July 2023
cyber.gov.rw
Link checked 19 August 2026
- Official sourceNational Cyber Security AuthorityNCSA Documentation library listing the three Minimum Cybersecurity Standards as current
cyber.gov.rw
Link checked 19 August 2026
Guidance on Personal Data Protection in the Health Sector
Regulator guideline · Data Protection and Privacy Office guidance, published 2025
Health is one of the sectors people assume has an extra wall in Rwanda, and on the evidence it does not. The regulator's health sector guidance applies the general privacy law to hospitals, pharmacies and insurers and adds no separate localisation rule — so Article 50's storage certificate remains the operative control for health data.
Enforced by National Cyber Security Authority — Data Protection and Privacy Office
Transfer model: Approval each time · Accepted routes: Government sign-off needed, Standard contract clauses
What it makes you do
- Get consentExplicit patient consent is expected for insurer access to health records.
- Secure the data
- Keep data for a minimum periodThe guidance acknowledges legally mandated medical record retention periods but does not state a number.
- Put a transfer safeguard in place
Sources
- Official sourceData Protection and Privacy Office, National Cyber Security AuthorityGuidance on Personal Data Protection in the Health Sector
dpo.gov.rw
“Sharing and transfer of personal data outside Rwanda raises privacy concern, notably when transfer relates to sensitive personal data.”
Link checked 19 August 2026
- Official sourceData Protection and Privacy OfficeCompliance Tools library, listing the health sector guidance as current
dpo.gov.rw
Link checked 19 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Itegeko No 058/2021 ryo ku wa 13/10/2021 rigenga kurinda amakuru bwite n'ubuzima bwite / Law No 058/2021 of 13/10/2021 relating to the protection of personal data and privacy
Act of parliament · Law No 058/2021 of 13/10/2021, Official Gazette no Special of 15/10/2021
Rwanda's general privacy law. Everyone who handles personal data must register with the National Cyber Security Authority and appoint a data protection officer; foreign firms must also appoint a Rwandan representative. Data may go abroad, but only through routes the law names, and offshore hosting needs its own certificate. Breaches carry a 48-hour clock. Penalties are criminal as well as financial.
Enforced by National Cyber Security Authority — Data Protection and Privacy Office
Transfer model: Approval each time · Accepted routes: Government sign-off needed, Standard contract clauses, Explicit consent, Needed for a contract, Important public interest, Legal claims, Someone's life is at risk
What it makes you do
- Register or notifyMandatory for every controller and processor, with no size threshold. Certificate issued within 30 working days; renewal must be applied for 45 working days before expiry.
- Appoint a data protection officerMandatory for all controllers and processors, not only large ones. Failure to designate is a listed administrative misconduct.
- Appoint a local representativeForeign controllers and processors must designate a representative that is a corporate body established in Rwanda and itself registered with the regulator.
- Tell people what you do
- Get consent
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Allow a nomineeRwanda-specific: Article 25 gives a person the right to designate an heir to their personal data.
- Secure the data
- Keep records of processing
- Keep logsFailure to carry out personal data logging is a listed administrative misconduct. The law sets no minimum period.
- Assess high-risk projects
- Written vendor contract
- Put a transfer safeguard in place
- Report breaches to the regulator — within 48 hoursFull written report to the regulator within 72 hours. A processor must tell its controller within 48 hours.
- Tell affected peopleRequired where the breach is likely to result in a high risk. The controller must propose the timing and wording to the regulator for approval.
- Delete data after a periodKeep only until the purpose is fulfilled, subject to wide exceptions in Article 52.
- Get a parent's consent for children — applies at: under 16
What it costs if you get it wrong
- Criminal liability: RWF 10,000,000 and imprisonment of 1 to 3 years — about $8 thousandUnlawful access, collection, use, offering, sharing, transfer or disclosure of personal data; re-identification; destruction or alteration; sale of personal data; unlawful processing of sensitive data; providing false information
- Percentage of global turnover: 5% of the previous financial year's annual turnoverA company convicted of any of the offences in Articles 56 to 61
- Percentage of global turnover: 1% of the preceding financial year's GLOBAL turnoverAny of the nine administrative misconducts, including operating without a registration certificate, using an expired one, failing to designate a data protection officer, or failing to notify or report a breach
- Fixed maximum fine: RWF 5,000,000 — about $4 thousandAdministrative misconduct, individual — fine of RWF 2,000,000 to RWF 5,000,000
- Order to stopThe supervisory authority may prohibit or suspend a transfer of personal data outside Rwanda; a court may order permanent or temporary closure of the entity or premises
- Loss of your licenceCancellation of the registration certificate on 15 working days' written notice, for false information or non-compliance
- Claims by individualsArticle 65 gives data subjects a right to claim compensation
Sources
- Official sourceRepublic of Rwanda, Official Gazette (hosted by the National Cyber Security Authority)Law No 058/2021 of 13/10/2021 relating to the protection of personal data and privacy — Official Gazette no Special of 15/10/2021
cyber.gov.rw
“The data controller or the data processor who is already in operation has a period not exceeding two (2) years from the date of publication of this Law in the Official Gazette of the Republic of Rwanda to conform his or her operations to the provisions of this Law.”
Link checked 19 August 2026
- Official sourceData Protection and Privacy Office, National Cyber Security AuthorityFrequently asked questions by institutions
dpo.gov.rw
Link checked 19 August 2026
Law No 058/2021, Article 50 — Ibikwa ry'amakuru bwite / Storage of personal data
Act of parliament · Law No 058/2021 of 13/10/2021, Article 50
The rule that catches cloud users. Personal data is stored in Rwanda by default, and hosting it abroad is permitted only if the National Cyber Security Authority has issued a certificate saying so. Unlike the transfer rule, there is no consent exception and no necessity exception — a certificate is the only route.
Enforced by National Cyber Security Authority — Data Protection and Privacy Office
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryDefault position: personal data is stored in Rwanda. Offshore hosting is lawful only while a certificate authorising it is in force.
- Assess high-risk projectsA data protection impact assessment for hosting personal data outside Rwanda must accompany the application.
- Register or notifyThe authorisation is tied to the registration certificate; a later change of destination country or hosting provider requires a change to the certificate.
What it costs if you get it wrong
- Criminal liability: RWF 10,000,000 and imprisonment of 1 to 3 years — about $8 thousandStoring personal data outside Rwanda contrary to the Law
Sources
- Official sourceRepublic of Rwanda, Official Gazette (hosted by the National Cyber Security Authority)Law No 058/2021, Article 50 (Storage of personal data)
cyber.gov.rw
“The data controller or the data processor stores personal data in Rwanda. However, the storage of personal data outside Rwanda is only permitted if the data controller or the data processor holds a valid registration certificate authorising him or her to store personal data outside Rwanda, which is issued by the supervisory authority.”
Link checked 19 August 2026
- Official sourceData Protection and Privacy OfficeApplication Form — Authorization to Store Personal Data Outside Rwanda
dpo.gov.rw
Link checked 19 August 2026
- Official sourceData Protection and Privacy OfficeCloud Storage Under Rwanda's Data Protection Law, 25 July 2025
dpo.gov.rw
Link checked 19 August 2026
Law No 020/2023 of 31/03/2023 on tax procedures
Act of parliament · Law No 020/2023 of 31/03/2023, books of accounts and record keeping
An easily missed localisation rule that has nothing to do with privacy law. Every company operating in Rwanda, and every person in business, must maintain books of account and supporting documents for ten years, physically in Rwanda. Customer and employee records embedded in those books therefore cannot be held only offshore.
Enforced by Rwanda Revenue Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep data for a minimum period — 10 yearsTen years, counted from 1 January following the fiscal year the records relate to.
- Keep the data in the countryThe books and documents must be maintained in Rwanda. Nothing prevents an additional copy being held abroad.
- Keep records of processing
What it costs if you get it wrong
- Fixed maximum fineAdministrative fines apply for failure to keep books and records; amounts are set by the tax procedures law
Sources
- Official sourceRwanda Revenue AuthorityTaxation Procedures, August 2023 — summary of Law No 020/2023 of 31/03/2023 on tax procedures, section II 'Books of accounts and records keeping'
rra.gov.rw
“Maintain books & documents for 10 years in Rwanda starting from 1st January following the fiscal year to which they relate.”
Link checked 19 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
Whether the National Cyber Security Authority has ever imposed a fine or issued a formal enforcement decision under the data protection law.
No decisions register, enforcement page or press release announcing a sanction was found on either dpo.gov.rw or cyber.gov.rw as at 19 August 2026. Absence of a published decision is not proof that none exists — Rwanda may simply not publish them. This is why enforcement is rated 'waking' rather than 'active'.
How many organisations are registered as data controllers or processors, and how many hold authorisation to store personal data outside Rwanda.
No public register or statistics page was found on the regulator's website. Without numbers we cannot say whether the offshore storage certificate is routinely granted or rarely granted, which materially changes the practical risk.
Whether there is a fee for registration, for renewal, or for an offshore storage or transfer authorisation.
The regulator's registration guide and application forms list documents but no fee schedule, and no fee order was located.
That the 2016 telecom network security regulation is still the current instrument and has not been amended or replaced.
The PDF is still served live from the Rwanda Utilities Regulatory Authority's own document repository and was fetched successfully on 19 August 2026, but we could not page through the regulator's full published index to confirm it appears there as current. The regulator issued new ICT regulations in January and August 2026 on other topics. Confidence for this rule is set to medium for that reason.
The National Bank of Rwanda's outsourcing regulation (Regulation No 49/2022) and its cybersecurity rules for financial institutions.
A secondary legal database describes an outsourcing regulation requiring prior central bank approval for material outsourcing and addressing cloud services and offshore backup sites. We could not obtain the text from bnr.rw, whose site is a JavaScript application that does not serve its regulation library to automated fetchers, and the regulation is therefore excluded from the rules list rather than asserted on a non-government source.
Whether Rwanda imposes localisation on government cloud, education, gambling, mapping or defence data.
We checked the Rwanda Information Society Authority's Data Center and Cloud Services Directives, which are technical design standards and contain no residency requirement, and searched for gambling and geospatial rules without finding an official Rwandan source. No rule found, checked 19 August 2026, confidence medium. Government bodies are in any event bound by Article 50 like everyone else.
The data provisions, if any, of Rwanda's new virtual assets law reported as gazetted in mid-2026.
Only secondary legal and news sources were located. No Rwandan government copy of the text was retrieved, so no claim is made about its content.
A firm date for the draft implementing regulations under the data protection law.
The regulator confirmed a stakeholder consultation on 5 March 2026 but has published neither the draft text nor a timetable. It is treated as proposed, with no legal effect.
Exact statutory retention periods for medical records in Rwanda.
The regulator's health sector guidance refers to 'retaining medical records for a legally mandated period' without citing the instrument or the number, and we did not locate a health ministry order setting it.
Freshness and refresh
Freshness
Checked today — on 19 August 2026.
Re-checked every 60 days. Next check due 18 October 2026.
Put this next to another country
Rwanda versus
Compare