Skip to the content
Global Data RulesData governance rules, country by country

Rwanda

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Yes, with paperworkWork: HighEnforcement: Waking up

Rwanda's starting point is that personal data stays in Rwanda. You may host it abroad, but only if the National Cyber Security Authority has given you a certificate that says so. Everyone who handles personal data must register with that authority first, foreign firms must appoint a Rwandan representative, and breaking the rules can mean prison, not just a fine.

Data governance in Rwanda

The eight things that decide how you handle data about people in Rwanda. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law reaches a company with no office in Rwanda as soon as it handles the data of people located in Rwanda. There is no size, revenue or volume threshold to fall below. If you are based outside Rwanda you must also appoint a representative inside Rwanda, and that representative must itself be a Rwandan company that is separately registered with the regulator.

High confidenceNational rulesRegister or notifyAppoint a local representativeAppoint a data protection officer

Where the data is allowed to live

Only with the government's permission. The law says plainly that personal data is stored in Rwanda, and hosting it anywhere else is allowed only if the National Cyber Security Authority has issued you a certificate authorising exactly that. Telephone and internet companies are worse off again: their subscriber information may not leave Rwanda at all, and there is no permission route. Tax records must also physically stay in Rwanda for ten years.

High confidenceYes, with paperworkApproval each timeKeep the data in the country

Sending data out of the country

Rwanda approves organisations, not countries. There is no published list of safe destinations and no list of banned ones. Instead you apply to the National Cyber Security Authority, name the exact countries and hosting providers you will use, and wait for a certificate. There is an official model contract you sign with the overseas recipient, but signing it does not by itself let you host data abroad.

High confidenceApproval each timeGovernment sign-off neededStandard contract clausesExplicit consentNeeded for a contractImportant public interestLegal claimsSomeone's life is at risk

The regulator, and whether it actually acts

The National Cyber Security Authority, working through its Data Protection and Privacy Office. It is real and it is working: it opened in March 2022, has a named head, its own building in Kigali, a toll-free line, four published email addresses and a full set of application forms, and it ran training and webinars throughout 2025 and 2026. What we could not find is a single published fine or formal decision against a named organisation. Treat it as a regulator that is warming up rather than one that is already punishing.

Medium confidenceWaking upRegulator

How long you must keep it — and when to delete it

The ceiling is short and vague: keep personal data only until the purpose you collected it for is finished, then stop. The floors are long and specific. Business books and their supporting documents must be kept for ten years, physically in Rwanda. Banks, insurers, designated essential service providers and government bodies must keep their computer activity logs for at least twelve months. Where a law or a contract requires you to keep something longer, the privacy law lets you.

High confidenceDelete data after a periodKeep data for a minimum periodKeep logsKeep the data in the country

If something goes wrong

Two clocks under the privacy law, and they run at the same time. You have 48 hours from becoming aware of a personal data breach to tell the regulator, and 72 hours to file a full written report with all the facts you have. If the breach is likely to seriously affect people, you must also tell them, and the regulator approves how and when you do that. Suppliers have their own 48-hour clock to tell their customer.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What catches people out

Five things that are not in the summary. One: permission to send data abroad is not permission to keep it abroad — those are two different applications, and consent gets you the first but never the second. Two: a child in Rwanda is anyone under sixteen. Three: breaking this law is a crime, with prison of one to three years for individuals and a fine of five percent of company turnover, and a court can order the business closed. Four: a foreign company needs both a Rwandan representative and a data protection officer, and the representative must be a Rwandan company that is itself registered. Five: telephone and internet companies must have a Rwandan national as their chief technical or information officer.

High confidenceGet a parent's consent for childrenCriminal liabilityPercentage of global turnoverAppoint a local representativeKeep the data in the country

What's changing next

The main thing on the horizon is a set of detailed rules underneath the privacy law. The regulator held a consultation on the draft in March 2026 with the justice ministry, the central bank, the utilities regulator, the food and drugs authority and the law reform commission, covering registration requirements and misconduct rules. Nothing has been published yet, so nothing is binding yet. Watch three powers the regulator already holds that could change the picture without any new law.

Medium confidenceProposedOrder to stop

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Telecoms

Regulations No 001/R/TD-ICS/RURA/016 governing telecom network security in Rwanda

Directly binding regulation · Regulations No 001/R/TD-ICS/RURA/016, signed at Kigali on 02/06/2016 following the Regulatory Board meeting of 06/05/2016

In forceNo — it stays put

A hard wall for telephone and internet operators. Subscriber information, including call records and billing data, may not be transferred, stored or processed outside Rwanda. The same regulation requires the licensee's chief technical or information officer to be a Rwandan national and requires regulator approval before any outsourcing.

In force since 2 June 2016But only enforceable from 2 December 2016

Enforced by Rwanda Utilities Regulatory Authority

Transfer model: Not allowed

Medium confidence
Finance

Minimum Cybersecurity Standards for the Financial Sector (with parallel editions for Essential Service Providers and for Public Institutions)

Government rules · Issued by the National Cyber Security Authority under Articles 9(3) and 10(1) of Law No 26/2017 of 31/05/2017 establishing NCSA; version 1.0

In forceYes, with paperwork

Baseline cyber rules the national cyber authority issued for financial institutions, with near-identical editions for designated essential service providers and for public bodies. The operationally sharp bit is a twelve-month minimum for keeping system activity logs, which also has to be pushed down into outsourcing contracts.

In force since 28 July 2023

Enforced by National Cyber Security Authority — Data Protection and Privacy Office

Transfer model: Approval each time · Accepted routes: Government sign-off needed

Medium confidence
Health and social care

Guidance on Personal Data Protection in the Health Sector

Regulator guideline · Data Protection and Privacy Office guidance, published 2025

In forceYes, with paperwork

Health is one of the sectors people assume has an extra wall in Rwanda, and on the evidence it does not. The regulator's health sector guidance applies the general privacy law to hospitals, pharmacies and insurers and adds no separate localisation rule — so Article 50's storage certificate remains the operative control for health data.

In force since 31 July 2025

Enforced by National Cyber Security Authority — Data Protection and Privacy Office

Transfer model: Approval each time · Accepted routes: Government sign-off needed, Standard contract clauses

Medium confidence

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Itegeko No 058/2021 ryo ku wa 13/10/2021 rigenga kurinda amakuru bwite n'ubuzima bwite / Law No 058/2021 of 13/10/2021 relating to the protection of personal data and privacy

Act of parliament · Law No 058/2021 of 13/10/2021, Official Gazette no Special of 15/10/2021

In forceYes, with paperwork

Rwanda's general privacy law. Everyone who handles personal data must register with the National Cyber Security Authority and appoint a data protection officer; foreign firms must also appoint a Rwandan representative. Data may go abroad, but only through routes the law names, and offshore hosting needs its own certificate. Breaches carry a 48-hour clock. Penalties are criminal as well as financial.

In force since 15 October 2021But only enforceable from 15 October 2023

Enforced by National Cyber Security Authority — Data Protection and Privacy Office

Transfer model: Approval each time · Accepted routes: Government sign-off needed, Standard contract clauses, Explicit consent, Needed for a contract, Important public interest, Legal claims, Someone's life is at risk

High confidence

Law No 058/2021, Article 50 — Ibikwa ry'amakuru bwite / Storage of personal data

Act of parliament · Law No 058/2021 of 13/10/2021, Article 50

In forceYes, with paperwork

The rule that catches cloud users. Personal data is stored in Rwanda by default, and hosting it abroad is permitted only if the National Cyber Security Authority has issued a certificate saying so. Unlike the transfer rule, there is no consent exception and no necessity exception — a certificate is the only route.

In force since 15 October 2021But only enforceable from 15 October 2023

Enforced by National Cyber Security Authority — Data Protection and Privacy Office

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Law No 020/2023 of 31/03/2023 on tax procedures

Act of parliament · Law No 020/2023 of 31/03/2023, books of accounts and record keeping

In forceA copy must stay

An easily missed localisation rule that has nothing to do with privacy law. Every company operating in Rwanda, and every person in business, must maintain books of account and supporting documents for ten years, physically in Rwanda. Customer and employee records embedded in those books therefore cannot be held only offshore.

In force since 31 March 2023

Enforced by Rwanda Revenue Authority

Transfer model: No restriction · Accepted routes: Nothing required

Medium confidence

Who you would hear from

  • Urwego rw'Igihugu rushinzwe Umutekano mu Ikoranabuhanga (NCSA)

    Supervisory authority for personal data protection and privacy; registration of controllers and processors; authorisation of storage and transfer outside Rwanda; breach reporting; national cybersecurity standards

    Yes. The Data Protection and Privacy Office was launched on 31 March 2022, has a named head, a Kigali office, a toll-free number and dedicated addresses for registration, breach reporting and complaints. It ran training, webinars and a national privacy week through 2025 and 2026 and consulted on draft regulations in March 2026. However, we found no published fine or formal decision against a named organisation, and no public decisions register — so its administrative work is visible but its punitive record is not.

  • RURA

    Telecommunications, broadcasting and other utilities. Enforces the telecom network security regulation, including the ban on storing subscriber information outside Rwanda.

    Fully operational and issuing new ICT regulations as recently as August 2026. It commits to auditing every telecom licensee at least once a year.

  • RRA

    Tax administration, including the duty to maintain books and documents for ten years in Rwanda

    Fully operational; publishes taxpayer guidance and enforces administrative fines.

  • Banki Nkuru y'u Rwanda (BNR)

    Banking, payments, insurance, microfinance and pensions supervision, including outsourcing approvals

    Fully operational and took part in the March 2026 consultation on draft data protection regulations. We could not retrieve its outsourcing or cybersecurity regulations from its own website, which runs as a JavaScript application and does not serve document listings to automated fetchers.

  • Rw-CSIRT

    National cyber incident response; receives incident notifications from financial institutions, essential service providers and public bodies

    Operational and publishing alerts and advisories through the National Cyber Security Authority's site.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • Whether the National Cyber Security Authority has ever imposed a fine or issued a formal enforcement decision under the data protection law.

    No decisions register, enforcement page or press release announcing a sanction was found on either dpo.gov.rw or cyber.gov.rw as at 19 August 2026. Absence of a published decision is not proof that none exists — Rwanda may simply not publish them. This is why enforcement is rated 'waking' rather than 'active'.

  • How many organisations are registered as data controllers or processors, and how many hold authorisation to store personal data outside Rwanda.

    No public register or statistics page was found on the regulator's website. Without numbers we cannot say whether the offshore storage certificate is routinely granted or rarely granted, which materially changes the practical risk.

  • Whether there is a fee for registration, for renewal, or for an offshore storage or transfer authorisation.

    The regulator's registration guide and application forms list documents but no fee schedule, and no fee order was located.

  • That the 2016 telecom network security regulation is still the current instrument and has not been amended or replaced.

    The PDF is still served live from the Rwanda Utilities Regulatory Authority's own document repository and was fetched successfully on 19 August 2026, but we could not page through the regulator's full published index to confirm it appears there as current. The regulator issued new ICT regulations in January and August 2026 on other topics. Confidence for this rule is set to medium for that reason.

  • The National Bank of Rwanda's outsourcing regulation (Regulation No 49/2022) and its cybersecurity rules for financial institutions.

    A secondary legal database describes an outsourcing regulation requiring prior central bank approval for material outsourcing and addressing cloud services and offshore backup sites. We could not obtain the text from bnr.rw, whose site is a JavaScript application that does not serve its regulation library to automated fetchers, and the regulation is therefore excluded from the rules list rather than asserted on a non-government source.

  • Whether Rwanda imposes localisation on government cloud, education, gambling, mapping or defence data.

    We checked the Rwanda Information Society Authority's Data Center and Cloud Services Directives, which are technical design standards and contain no residency requirement, and searched for gambling and geospatial rules without finding an official Rwandan source. No rule found, checked 19 August 2026, confidence medium. Government bodies are in any event bound by Article 50 like everyone else.

  • The data provisions, if any, of Rwanda's new virtual assets law reported as gazetted in mid-2026.

    Only secondary legal and news sources were located. No Rwandan government copy of the text was retrieved, so no claim is made about its content.

  • A firm date for the draft implementing regulations under the data protection law.

    The regulator confirmed a stakeholder consultation on 5 March 2026 but has published neither the draft text nor a timetable. It is treated as proposed, with no legal effect.

  • Exact statutory retention periods for medical records in Rwanda.

    The regulator's health sector guidance refers to 'retaining medical records for a legally mandated period' without citing the instrument or the number, and we did not locate a health ministry order setting it.

Freshness and refresh

Freshness

Checked today — on 19 August 2026.

Re-checked every 60 days. Next check due 18 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Rwanda versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.