Rwanda
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 19 August 2026.
If you collect data about people in Rwanda — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
By default, personal data must stay in Rwanda. You can host it abroad only if the National Cyber Security Authority gives you a certificate that says so. Everyone who handles personal data must register with that authority first. If you are based outside Rwanda, you must also appoint a Rwandan representative. Breaking these rules can mean prison, not just a fine.
Data governance in Rwanda
The eight things that decide how you handle data about people in Rwanda. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law applies even if you have no office in Rwanda. It covers you as soon as you handle data about people located in Rwanda. There is no size, revenue or volume limit below which you are safe. If you are based outside Rwanda, you must also appoint a representative inside Rwanda. That representative must be a Rwandan company, and it must be registered with the regulator in its own right.
- What you have to do here:
- Register or notify · Appoint a representative · Appoint a data protection officer
Article 2 of Law No 058/2021 covers two groups. First, anyone based or living in Rwanda who decides how personal data is used, plus the suppliers who handle that data for them. Second, anyone who is neither based nor living in Rwanda but who uses or stores personal data about people located in Rwanda. Note the words: located in Rwanda. That means anyone in the country, not only Rwandan citizens. Article 29 makes registration compulsory for anyone who plans to handle personal data, with no minimum size. The National Cyber Security Authority's registration guide confirms this covers 'all public and private organizations, professionals such as doctors, lawyers, engineers, architects, notaries'. Article 39 says companies from outside Rwanda must appoint a representative in writing. The regulator's own guide adds that the representative must be a company set up in Rwanda. It must also be registered with the regulator in its own right. That is a separate duty from Article 40, which says you must appoint a data protection officer. You need both.
Sources
- Official sourceRepublic of Rwanda, Official Gazette (hosted by the National Cyber Security Authority)Law No 058/2021 of 13/10/2021 relating to the protection of personal data and privacy, Articles 2, 29, 30, 39 and 40 — Official Gazette no Special of 15/10/2021
cyber.gov.rw
“This Law applies to: ... the data controller, the data processor and a third party who: a) is established or resides in Rwanda and processes personal data while in Rwanda; b) is neither established nor resides in Rwanda, but processes personal data of data subjects located in Rwanda.”
Link checked 19 August 2026
- Official sourceData Protection and Privacy Office, National Cyber Security AuthorityGuide on Designation of a Representative, June 2024
dpo.gov.rw
“The designated representative must fulfill the following criteria. They must: 1. Be a corporate body or legal entity established in Rwanda ...; 2. Be registered as a Data Controller or Data Processor with NCSA”
Link checked 19 August 2026
- Official sourceNational Cyber Security AuthorityGuide on Data Controller and Data Processor Registration
cyber.gov.rw
Link checked 19 August 2026
Where the data is allowed to live
Only with the government's permission. The law says personal data is stored in Rwanda. You can host it somewhere else only if the National Cyber Security Authority has given you a certificate allowing exactly that. Telephone and internet companies have it worse. Their subscriber information may not leave Rwanda at all, and there is no permission to apply for. Tax records must also stay physically in Rwanda for ten years.
- What you have to do here:
- Keep the data in the country
Two rules are at work here, and people mix them up. Article 50 is about storage. It says you store personal data in Rwanda. You may store it outside Rwanda only if you hold a valid registration certificate from the supervisory authority that allows this. There is no consent exception and no necessity exception to Article 50. Article 48 is about sharing or sending data to someone else outside Rwanda. That rule does have alternatives to regulator permission. You can rely on the consent of the person the data is about. Or you can show the transfer is needed for a contract, for the public interest, for a legal claim, or for someone's vital interests. A compelling legitimate interest also counts, and so does an international agreement Rwanda has ratified. So a transfer can be legal under Article 48 while the hosting that follows is still illegal under Article 50. Some industries have extra rules. Telephone and internet companies are shut out completely. The utilities regulator's telecom network security rules say licence holders must ensure subscriber information is not transferred, stored or used outside the Republic of Rwanda. There is no exception. Tax and accounting records are a separate point, and this one applies to every industry. A copy must stay in the country. The tax procedures law says businesses must keep their books and documents for ten years in Rwanda. Health has no extra rule. The regulator's health guidance from July 2025 applies the general law and adds nothing about where data must sit. We found no rule about where data must sit for finance, insurance, securities, government cloud, education, gambling or mapping. We checked on 19 August 2026 and our confidence is medium. The regulator's application form for storing data abroad names finance, telecommunication, health, education and aviation as the industries it expects to see. That suggests it handles them through the general Article 50 permission, not through separate bans.
Sources
- Official sourceRepublic of Rwanda, Official Gazette (hosted by the National Cyber Security Authority)Law No 058/2021, Articles 48, 49 and 50 (sharing and transfer outside Rwanda; contract for transfer; storage of personal data)
cyber.gov.rw
“The data controller or the data processor stores personal data in Rwanda. However, the storage of personal data outside Rwanda is only permitted if the data controller or the data processor holds a valid registration certificate authorising him or her to store personal data outside Rwanda, which is issued by the supervisory authority.”
Link checked 19 August 2026
- Official sourceRwanda Utilities Regulatory AuthorityRegulations No 001/R/TD-ICS/RURA/016 governing telecom network security in Rwanda, Article 16
rura.rw
“Subscriber's information are not transferred, stored or processed outside of the Republic of Rwanda.”
Link checked 19 August 2026
- Official sourceRwanda Revenue AuthorityTaxation Procedures, August 2023 — summary of Law No 020/2023 of 31/03/2023 on tax procedures, books of accounts and records keeping
rra.gov.rw
“Maintain books & documents for 10 years in Rwanda starting from 1st January following the fiscal year to which they relate.”
Link checked 19 August 2026
- Official sourceData Protection and Privacy OfficeCloud Storage Under Rwanda's Data Protection Law: What You Need to Know, 25 July 2025
dpo.gov.rw
“storing personal data outside Rwanda requires authorization from the National Cyber Security Authority (NCSA) among other compliance requirements in the Law.”
Link checked 19 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Rwanda.
Sending data out of the country
Rwanda approves companies, not countries. There is no published list of safe destinations and no list of banned ones. You apply to the National Cyber Security Authority instead. You name the exact countries and hosting providers you will use, then wait for a certificate. There is an official model contract you sign with the company receiving the data. Signing it does not on its own let you host data abroad.
- Ways to send data out:
- Government sign-off needed · Standard contract clauses · Explicit consent · Needed for a contract · Important public interest · Legal claims · To save someone’s life
There are two application routes and two forms. Both are live on the regulator's website today. One is 'Authorization to Store Outside Rwanda'. The other is 'Authorization to Transfer Outside Rwanda'. The storage form asks for the name of each hosting provider. It asks for the destination country for your main storage and for your disaster recovery copy, separately. It asks what type of hosting you use: shared, virtual private server, dedicated or cloud. It asks about any other companies involved. It also asks you to describe the data protection laws of each destination country. You must attach four things. A letter addressed to the Chief Executive Officer of the National Cyber Security Authority. Your hosting agreements. A description of your storage setup. And a written risk assessment covering hosting personal data abroad. The regulator has also published Standard Contractual Clauses for Personal Data Transfer Outside Rwanda, dated February 2024. They exist to meet Article 49, which requires a written contract with the company receiving the data overseas. The regulator's frequently asked questions explain that permission to transfer is normally granted as part of registration. That is because the registration form already asks which countries you will send data to. If that changes later, you apply to amend your registration certificate. Two things to understand about how this works. First, the regulator decides case by case. There is no approved list of countries and no banned list. So there is no list to check, and none that can be quietly filled in later. Second, the regulator holds a standing power to stop or pause any transfer out of Rwanda to protect people's rights.
Sources
- Official sourceData Protection and Privacy Office, National Cyber Security AuthorityApplication Form — Authorization to Store Personal Data Outside Rwanda
dpo.gov.rw
“SUPPORTING DOCUMENTS 1. Application letter addressed to the Chief Executive Officer of NCSA 2. Hosting agreement (s) with service provider(s) 3. Storage architecture 4. Data Protection Impact Assessment (DPIA) for hosting personal data outside Rwanda”
Link checked 19 August 2026
- Official sourceData Protection and Privacy Office, National Cyber Security AuthorityStandard Contractual Clauses for Personal Data Transfer Outside Rwanda, February 2024
dpo.gov.rw
“The purpose of these standard contractual clauses is to ensure that the transfer of personal data from Rwanda is carried out in compliance with Article 49 of Law No 058/2021”
Link checked 19 August 2026
- Official sourceData Protection and Privacy OfficeServices — Authorization to Store Outside Rwanda
dpo.gov.rw
Link checked 19 August 2026
- Official sourceData Protection and Privacy OfficeFrequently asked questions — storage, sharing and transfer of personal data
dpo.gov.rw
“Authorization provided for under Art.48 (1) of DPP law to transfer personal data outside Rwanda is done during registration to operate as a data controller or data processor”
Link checked 19 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The National Cyber Security Authority, working through its Data Protection and Privacy Office. It is real and it is working. It opened in March 2022. It has a named head, its own building in Kigali, a toll-free line, four published email addresses and a full set of application forms. It ran training and webinars throughout 2025 and 2026. We could not find a single published fine or formal decision against a named company. Treat it as a regulator that is getting started, not one that is already punishing people.
Law No 058/2021 names the National Cyber Security Authority as the supervisory authority. Its Data Protection and Privacy Office opened on 31 March 2022. Here is what we can see it doing in the last twelve months. It ran a five-day ISO 31000 risk management course for data protection officers in July 2026. It made a study visit to Kenya's Office of the Data Protection Commissioner in July 2026. It ran an awareness session with Bank of Kigali's insurance arm in June 2026. It ran a week-long training for data protection officers from public and private bodies in June 2026. It ran a Data Privacy Week campaign from 26 to 30 January 2026, themed 'Compliance is Beyond Registration'. It ran a webinar that drew over 300 data protection officers. In March 2026 it consulted on draft rules. The Ministry of Justice, the National Bank of Rwanda, the utilities regulator and the food and drugs authority all took part. Other regulators enforce alongside it. The Rwanda Utilities Regulatory Authority audits telecom licence holders at least once a year under its network security rules. The National Bank of Rwanda supervises financial institutions. The Rwanda Revenue Authority enforces the ten-year rule on keeping books in the country. We searched for published enforcement decisions and found none on the regulator's own site. There is no public register of decisions at all. That absence is itself the finding.
Sources
- Official sourceNational Cyber Security AuthorityWho we are — Data Protection and Privacy Office
dpo.gov.rw
“On 31 March 2022, the National Cyber Security Authority officially launched its data protection office, which will spearhead all activities related to protecting personal data of individuals in Rwanda.”
Link checked 19 August 2026
- Official sourceData Protection and Privacy OfficeNews archive showing continuous regulator activity from April 2025 to July 2026
dpo.gov.rw
Link checked 19 August 2026
- Official sourceNational Cyber Security Authority2026 Data Privacy Week: Compliance Beyond Registration, 20 January 2026
cyber.gov.rw
“the campaign emphasizes that compliance is more than certification, it requires accountability, transparency, and a sustained commitment to safeguarding personal data.”
Link checked 19 August 2026
How long you must keep it — and when to delete it
The general rule is short and vague. Keep personal data only until the purpose you collected it for is finished, then stop. The minimum periods are long and specific. Business books and their supporting papers must be kept for ten years, physically in Rwanda. Banks, insurers, named essential service providers and government bodies must keep their computer activity logs for at least twelve months. Where a law or a contract makes you keep something longer, the privacy law allows that.
- What you have to do here:
- Delete data after a period · Keep data for a minimum period · Keep logs
Article 52 sets the general rule. Keep personal data until the purposes you collected it for are met, then stop. The same article then lists exceptions, and they are wide. You may keep data longer where a law allows it. You may keep it longer where a contract between the parties requires it. You may keep it where the data relates to the function or activity you collected it for. And you may keep it to prevent, detect, investigate, prosecute or punish an offender. The effect is that a longer legal or contractual period wins. It overrides the delete-when-done rule rather than clashing with it. Now the minimum periods. The tax procedures law says books and documents must be kept for ten years in Rwanda. The ten years start on 1 January following the tax year the records relate to. The National Cyber Security Authority issued its Minimum Cybersecurity Standards on 28 July 2023. There are three versions: one for the financial sector, one for essential service providers and one for public institutions. All three require an event logging system with archiving procedures 'at least for a period of 12 months'. You must put the same duty into your contracts with outsourced service providers. Separately, failing to log personal data activity is listed as administrative misconduct under Article 53. The law sets no period for that one.
Sources
- Official sourceRepublic of Rwanda, Official Gazette (hosted by the National Cyber Security Authority)Law No 058/2021, Articles 52 and 53
cyber.gov.rw
“The data controller or the data processor retains personal data until the purposes of the processing of personal data are fulfilled.”
Link checked 19 August 2026
- Official sourceRwanda Revenue AuthorityTaxation Procedures, August 2023 — books of accounts and records keeping
rra.gov.rw
“Maintain books & documents for 10 years in Rwanda”
Link checked 19 August 2026
- Official sourceNational Cyber Security AuthorityMinimum Cybersecurity Standards for Essential Service Providers, version 1.0, 28 July 2023
cyber.gov.rw
“An event logging system in networks and ICT systems should be implemented, and procedures for archiving the collected logs should be developed (at least for a period of 12 months)”
Link checked 19 August 2026
- Official sourceNational Cyber Security AuthorityMinimum Cybersecurity Standards for the Financial Sector, version 1.0, 28 July 2023
cyber.gov.rw
Link checked 19 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
Two deadlines run at the same time under the privacy law. You have 48 hours from finding out about a data breach to tell the regulator. You have 72 hours to file a full written report with all the facts you have. If the breach is likely to seriously affect people, you must tell them too. The regulator approves how and when you do that. Suppliers have their own 48 hours to tell their customer.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Article 43 gives you 48 hours from the moment you learn of a breach to tell the supervisory authority. A supplier who handles data for you gets the same 48 hours to tell you. Article 44 then requires a report within 72 hours with all the facts available. The report must cover what happened, roughly how many people and records are affected, and the contact details of your data protection officer. It must cover what you have done to fix the problem and limit the damage. Unusually, you must also propose how and when you will tell the people affected, and the regulator approves that plan. Article 45 covers telling people directly where the risk to them is high. Missing any of these three steps is separately listed as administrative misconduct. Some organisations have two more deadlines on top. Telecom licence holders must share critical and major security incidents with the utilities regulator immediately, and report moderate ones monthly. Financial institutions, essential service providers and public institutions are told under the Minimum Cybersecurity Standards to notify Rwanda's national incident response team of every cyber incident. The standards set no fixed number of hours. That is a gap, so set your own tight internal deadline.
Sources
- Official sourceRepublic of Rwanda, Official Gazette (hosted by the National Cyber Security Authority)Law No 058/2021, Articles 43, 44 and 45
cyber.gov.rw
“In case of personal data breach, the data controller, within forty-eight (48) hours after being aware of the incident, must communicate the personal data breach to the supervisory authority.”
Link checked 19 August 2026
- Official sourceRwanda Utilities Regulatory AuthorityRegulations No 001/R/TD-ICS/RURA/016 governing telecom network security in Rwanda, Article 28
rura.rw
“Every Licensee must immediately share with the Regulatory Authority any security incidents which have occurred and considered as critical and major”
Link checked 19 August 2026
- Official sourceData Protection and Privacy OfficeFrequently asked questions — notification of personal data breach and report on personal data breach
dpo.gov.rw
Link checked 19 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things the summary does not tell you. One. Permission to send data abroad is not permission to keep it abroad. Those are two different applications, and consent gets you the first but never the second. Two. A child in Rwanda is anyone under sixteen. Three. Breaking this law is a crime. Individuals face one to three years in prison. Companies face a fine of five percent of turnover, and a court can order the business closed. Four. A company based abroad needs both a Rwandan representative and a data protection officer. The representative must be a Rwandan company that is itself registered. Five. Telephone and internet companies must have a Rwandan national as their chief technical officer or chief information officer.
- What you have to do here:
- Get a parent's consent for children · Appoint a representative
- What it costs if you get it wrong:
- Criminal liability · Percentage of global turnover
(1) Article 48 gives you seven routes to a lawful transfer, including the person's consent and the needs of a contract. Article 50 gives you exactly one route to lawful storage abroad: a registration certificate that says you can. Cloud hosting counts as storage. This is the most common way to look compliant on paper while breaking the law in fact. (2) Article 9 sets the age for children at under sixteen. That is at the top of the international range. Many global products use thirteen. (3) Chapter VIII creates real crimes, not administrative penalties. Unlawful access, collection, use, sharing, transfer or disclosure of personal data carries one to three years in prison for an individual. It also carries a fine of seven to ten million Rwandan francs, roughly five to eight thousand US dollars. A company convicted of the same crimes pays five percent of its previous year's annual turnover. Article 63 lets a court close the business or its premises, permanently or temporarily. Administrative misconduct under Article 53 works differently. It includes running without a registration certificate, or letting yours expire. The fine is two to five million Rwandan francs, roughly sixteen hundred to four thousand US dollars. For a company it can be one percent of global turnover instead. Note that difference. The administrative fine uses global turnover. The criminal fine uses annual turnover. (4) The representative and the data protection officer are two separate duties, under Articles 39 and 40. Failing to appoint a data protection officer is listed misconduct. (5) The telecom network security rules require the licence holder to have a Rwandan native as chief technical officer or chief information officer. They also require the regulator's approval before you outsource any service or operation to another company. (6) One more trap. The registration form asks for your hosting invoice or agreement. So the regulator sees where your data actually sits at the moment you apply.
Sources
- Official sourceRepublic of Rwanda, Official Gazette (hosted by the National Cyber Security Authority)Law No 058/2021, Articles 9, 39, 40, 48, 50, 53, 56, 62 and 63
cyber.gov.rw
“Upon conviction, he or she is liable to an imprisonment of not less than one (1) year but not more than three (3) years and a fine of not less than seven million Rwandan francs (RWF 7,000,000) but not more than ten million Rwandan francs (RWF 10,000,000) or one of these penalties.”
Link checked 19 August 2026
- Official sourceRwanda Utilities Regulatory AuthorityRegulations No 001/R/TD-ICS/RURA/016 governing telecom network security in Rwanda, Article 18
rura.rw
“The Licensee is required to have a Rwandan native as its Chief Technical Officer (CTO) Chief Information officer (CIO) or equivalent functions”
Link checked 19 August 2026
- Official sourceNational Cyber Security AuthorityGuide on Data Controller and Data Processor Registration — documents to be submitted, including hosting invoice or agreement
cyber.gov.rw
Link checked 19 August 2026
What's changing next
The main thing on the horizon is a set of detailed rules underneath the privacy law. The regulator consulted on the draft in March 2026. The justice ministry, the central bank, the utilities regulator, the food and drugs authority and the law reform commission all took part. The draft covers registration requirements and misconduct rules. Nothing has been published yet, so nothing is binding yet. Also watch three powers the regulator already holds. It could use them to change your answer without any new law.
- What it costs if you get it wrong:
- Order to stop
Pending: draft rules under Law No 058/2021. The regulator consulted on them on 5 March 2026. They focus on registration requirements and misconduct rules. As of 19 August 2026 we found no published text and no start date. So this is still a draft with no legal effect. The regulator also holds four powers that are already in the law. It can use any of them without consulting anyone. One. The last paragraph of Article 48 lets the supervisory authority stop or pause any transfer of personal data out of Rwanda to protect people's rights. A single decision could strand a setup built on overseas hosting. Two. Article 53 lets the supervisory authority write a rule adding new kinds of administrative misconduct and new penalties, beyond the nine already in the law. Three. Article 51 requires the supervisory authority to write rules on moving and managing personal data when a business changes hands or closes. Those rules do not appear to exist yet. When they arrive they will apply to every acquisition and every wind-down. Four. A registration certificate can be cancelled before it expires, on fifteen working days' written notice. That is a faster commercial risk than any fine. One more thing to watch. Rwanda published its first law regulating virtual asset business in mid-2026. That brings a new group of firms under the registration and overseas storage rules. We could not verify the text on a Rwandan government website, so we make no claim about what it says on data.
Sources
- Official sourceData Protection and Privacy OfficeDPO engages stakeholders to shape Rwanda's Data Privacy regulations, 5 March 2026
dpo.gov.rw
“the Data Protection & Privacy Office convened a consultation workshop on the draft regulations under Rwanda's Data Protection and Privacy Law. The session brought together representatives from key institutions including the Ministry of Justice, the National Bank of Rwanda, RURA, Rwanda FDA, and the Rwanda Law Reform Commission.”
Link checked 19 August 2026
- Official sourceRepublic of Rwanda, Official Gazette (hosted by the National Cyber Security Authority)Law No 058/2021, Articles 48 (final paragraph), 51, 53 and 66 — standing regulator powers
cyber.gov.rw
“The supervisory authority, in order to protect the rights and freedoms of the data subject, may prohibit or suspend the transfer of personal data outside Rwanda.”
Link checked 19 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Telecoms data must stay in the country
Official name: Regulations No 001/R/TD-ICS/RURA/016 governing telecom network security in Rwanda · Regulations No 001/R/TD-ICS/RURA/016, signed at Kigali on 02/06/2016 following the Regulatory Board meeting of 06/05/2016 · Directly binding regulation
A total ban for telephone and internet operators. Subscriber information, including call records and billing data, may not be transferred, stored or used outside Rwanda. The same rules require the licence holder's chief technical officer or chief information officer to be a Rwandan national. They also require regulator approval before any outsourcing.
Enforced by Rwanda Utilities Regulatory Authority
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countrySubscriber information must not be transferred, stored or used outside Rwanda. That covers voice, SMS, data, call detail records and billing information. There is no permission you can apply for.
- Report cyber incidentsCritical and major incidents must be shared with the regulator immediately. Moderate incidents are reported monthly.
- Independent auditThe regulator audits every licence holder at least once a year.
- Written vendor contractYou need the regulator's approval before outsourcing any service or operation to another company.
- Secure the data
What it costs if you get it wrong
- Fixed maximum fine: RWF 5,000,000 — about $4 thousandNon-compliance with any requirement of the regulation — fine of RWF 1,000,000 to RWF 5,000,000
- Daily fine until fixed: RWF 500,000 per day — about $390Continued non-compliance after an enforcement notice
Sources
- Official sourceRwanda Utilities Regulatory AuthorityRegulations No 001/R/TD-ICS/RURA/016 governing telecom network security in Rwanda, Articles 16, 18, 28, 29, 33 and 34
rura.rw
“Any licensee shall ensure that: ... (e) Subscriber's information are not transferred, stored or processed outside of the Republic of Rwanda.”
Link checked 19 August 2026
Cyber security rules (Finance)
Official name: Minimum Cybersecurity Standards for the Financial Sector (with parallel editions for Essential Service Providers and for Public Institutions) · Issued by the National Cyber Security Authority under Articles 9(3) and 10(1) of Law No 26/2017 of 31/05/2017 establishing NCSA; version 1.0 · Government rules
Basic cyber rules the national cyber authority issued for financial institutions. There are near-identical versions for named essential service providers and for public bodies. The sharpest part is a twelve-month minimum for keeping system activity logs. You must write that same duty into your outsourcing contracts.
Enforced by National Cyber Security Authority — Data Protection and Privacy Office
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep logs — 1 yearYou need an event logging system plus archiving procedures covering at least 12 months. Outsourced providers must be bound to the same by contract.
- Report cyber incidentsRwanda's national incident response team, Rw-CSIRT, should be notified of every cyber incident. No fixed hour deadline is stated.
- Secure the data
- Independent audit
- Keep records of how you use dataYou must identify your records and how long each of them is kept.
Sources
- Official sourceNational Cyber Security AuthorityMinimum Cybersecurity Standards for the Financial Sector, version 1.0, 28 July 2023
cyber.gov.rw
“The requirements contained in this document apply only to financial sector institutions operating within the territory of the Republic of Rwanda.”
Link checked 19 August 2026
- Official sourceNational Cyber Security AuthorityMinimum Cybersecurity Standards for Essential Service Providers, version 1.0, 28 July 2023
cyber.gov.rw
“procedures for archiving the collected logs should be developed (at least for a period of 12 months)”
Link checked 19 August 2026
- Official sourceNational Cyber Security AuthorityMinimum Cybersecurity Standards for Public Institutions, version 1.0, 28 July 2023
cyber.gov.rw
Link checked 19 August 2026
- Official sourceNational Cyber Security AuthorityNCSA Documentation library listing the three Minimum Cybersecurity Standards as current
cyber.gov.rw
Link checked 19 August 2026
Insurance rules
Official name: Guidance on Personal Data Protection in the Health Sector · Data Protection and Privacy Office guidance, published 2025 · Regulator guideline
Health data has no extra rule about where it must sit, although people assume it does. The regulator's health guidance applies the general privacy law to hospitals, pharmacies and insurers. It adds nothing of its own about where data must be stored. So the Article 50 storage certificate is still the control that matters for health data.
Enforced by National Cyber Security Authority — Data Protection and Privacy Office
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Standard contract clauses
What you have to do
- Get consentExplicit patient consent is expected for insurer access to health records.
- Secure the data
- Keep data for a minimum periodThe guidance says the law sets how long medical records must be kept. It does not say how long.
- Put a transfer safeguard in place
Sources
- Official sourceData Protection and Privacy Office, National Cyber Security AuthorityGuidance on Personal Data Protection in the Health Sector
dpo.gov.rw
“Sharing and transfer of personal data outside Rwanda raises privacy concern, notably when transfer relates to sensitive personal data.”
Link checked 19 August 2026
- Official sourceData Protection and Privacy OfficeCompliance Tools library, listing the health sector guidance as current
dpo.gov.rw
Link checked 19 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Cyber security rules
Official name: Itegeko No 058/2021 ryo ku wa 13/10/2021 rigenga kurinda amakuru bwite n'ubuzima bwite / Law No 058/2021 of 13/10/2021 relating to the protection of personal data and privacy · Law No 058/2021 of 13/10/2021, Official Gazette no Special of 15/10/2021 · Act of parliament
Rwanda's general privacy law. Everyone who handles personal data must register with the National Cyber Security Authority and appoint a data protection officer. Companies based abroad must also appoint a Rwandan representative. Data may leave Rwanda, but only by the routes the law names. Hosting data abroad needs its own certificate. Breaches must be reported within 48 hours. Penalties are criminal as well as financial.
Enforced by National Cyber Security Authority — Data Protection and Privacy Office
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Standard contract clauses, Explicit consent, Needed for a contract, Important public interest, Legal claims, To save someone’s life
What you have to do
- Register or notifyRequired for everyone who handles personal data, whatever your size. The certificate is issued within 30 working days. You must apply to renew it 45 working days before it expires.
- Appoint a data protection officerRequired for everyone who handles personal data, not only large companies. Failing to appoint one is listed as administrative misconduct.
- Appoint a representativeIf you are based outside Rwanda, your representative must be a company set up in Rwanda. That company must itself be registered with the regulator.
- Tell people what you do
- Get consent
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Allow a nomineeUnusual to Rwanda: Article 25 lets a person name an heir to their personal data.
- Secure the data
- Keep records of how you use data
- Keep logsFailure to carry out personal data logging is a listed administrative misconduct. The law sets no minimum period.
- Assess high-risk projects
- Written vendor contract
- Put a transfer safeguard in place
- Report breaches to the regulator — within 48 hoursFull written report to the regulator within 72 hours. A supplier who handles data for you must tell you within 48 hours.
- Tell affected peopleRequired where the breach is likely to be high risk for people. You must propose the timing and the wording to the regulator for approval.
- Delete data after a periodKeep only until the purpose is fulfilled, subject to wide exceptions in Article 52.
- Get a parent's consent for children — applies at: under 16
What it costs if you get it wrong
- Criminal liability: RWF 10,000,000 and imprisonment of 1 to 3 years — about $8 thousandUnlawful access, collection, use, offering, sharing, transfer or disclosure of personal data; re-identification; destruction or alteration; sale of personal data; unlawful processing of sensitive data; providing false information
- Percentage of global turnover: 5% of the previous financial year's annual turnoverA company convicted of any of the offences in Articles 56 to 61
- Percentage of global turnover: 1% of the preceding financial year's GLOBAL turnoverAny of the nine administrative misconducts, including operating without a registration certificate, using an expired one, failing to designate a data protection officer, or failing to notify or report a breach
- Fixed maximum fine: RWF 5,000,000 — about $4 thousandAdministrative misconduct, individual — fine of RWF 2,000,000 to RWF 5,000,000
- Order to stopThe supervisory authority may prohibit or suspend a transfer of personal data outside Rwanda; a court may order permanent or temporary closure of the entity or premises
- Loss of your licenceCancellation of the registration certificate on 15 working days' written notice, for false information or non-compliance
- Claims by individualsArticle 65 gives data subjects a right to claim compensation
Sources
- Official sourceRepublic of Rwanda, Official Gazette (hosted by the National Cyber Security Authority)Law No 058/2021 of 13/10/2021 relating to the protection of personal data and privacy — Official Gazette no Special of 15/10/2021
cyber.gov.rw
“The data controller or the data processor who is already in operation has a period not exceeding two (2) years from the date of publication of this Law in the Official Gazette of the Republic of Rwanda to conform his or her operations to the provisions of this Law.”
Link checked 19 August 2026
- Official sourceData Protection and Privacy Office, National Cyber Security AuthorityFrequently asked questions by institutions
dpo.gov.rw
Link checked 19 August 2026
Cyber security rules (2023)
Official name: Law No 058/2021, Article 50 — Ibikwa ry'amakuru bwite / Storage of personal data · Law No 058/2021 of 13/10/2021, Article 50 · Act of parliament
The rule that catches cloud users. Personal data stays in Rwanda by default. You can host it abroad only if the National Cyber Security Authority has issued a certificate saying so. Unlike the transfer rule, there is no consent exception and no necessity exception. A certificate is the only way.
Enforced by National Cyber Security Authority — Data Protection and Privacy Office
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryBy default, personal data is stored in Rwanda. Hosting it abroad is lawful only while a certificate allowing it is in force.
- Assess high-risk projectsYou must attach a written risk assessment covering the hosting of personal data outside Rwanda.
- Register or notifyThe permission is tied to your registration certificate. If you later change destination country or hosting provider, you must change the certificate.
What it costs if you get it wrong
- Criminal liability: RWF 10,000,000 and imprisonment of 1 to 3 years — about $8 thousandStoring personal data outside Rwanda contrary to the Law
Sources
- Official sourceRepublic of Rwanda, Official Gazette (hosted by the National Cyber Security Authority)Law No 058/2021, Article 50 (Storage of personal data)
cyber.gov.rw
“The data controller or the data processor stores personal data in Rwanda. However, the storage of personal data outside Rwanda is only permitted if the data controller or the data processor holds a valid registration certificate authorising him or her to store personal data outside Rwanda, which is issued by the supervisory authority.”
Link checked 19 August 2026
- Official sourceData Protection and Privacy OfficeApplication Form — Authorization to Store Personal Data Outside Rwanda
dpo.gov.rw
Link checked 19 August 2026
- Official sourceData Protection and Privacy OfficeCloud Storage Under Rwanda's Data Protection Law, 25 July 2025
dpo.gov.rw
Link checked 19 August 2026
Personal data needs a copy kept in the country
Official name: Law No 020/2023 of 31/03/2023 on tax procedures · Law No 020/2023 of 31/03/2023, books of accounts and record keeping · Act of parliament
An easily missed rule about where data must sit, and it has nothing to do with privacy law. Every company operating in Rwanda, and every person in business, must keep books of account and supporting papers for ten years, physically in Rwanda. So customer and employee records held inside those books cannot sit only abroad.
Enforced by Rwanda Revenue Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep data for a minimum period — 10 yearsTen years, counted from 1 January following the fiscal year the records relate to.
- Keep the data in the countryThe books and documents must be kept in Rwanda. You can hold an extra copy abroad as well.
- Keep records of how you use data
What it costs if you get it wrong
- Fixed maximum fineAdministrative fines apply for failure to keep books and records; amounts are set by the tax procedures law
Sources
- Official sourceRwanda Revenue AuthorityTaxation Procedures, August 2023 — summary of Law No 020/2023 of 31/03/2023 on tax procedures, section II 'Books of accounts and records keeping'
rra.gov.rw
“Maintain books & documents for 10 years in Rwanda starting from 1st January following the fiscal year to which they relate.”
Link checked 19 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Whether the National Cyber Security Authority has ever imposed a fine or issued a formal enforcement decision under the data protection law.
We found no published fines or enforcement decisions from either regulator. That does not prove there are none. Rwanda may simply not publish them. This is why we rate enforcement as waking up rather than active.
How many organisations are registered as data controllers or processors, and how many hold authorisation to store personal data outside Rwanda.
We could not find any numbers on how often the certificate to store data abroad is granted. So we cannot tell you whether approval is routine or rare. That difference changes your real risk a lot. Ask the regulator before you plan around it.
Whether there is a fee for registration, for renewal, or for an offshore storage or transfer authorisation.
We could not confirm what registration costs. The regulator's guide and application forms list the documents you need but no fees. Ask the regulator for the current fee before you apply.
That the 2016 telecom network security regulation is still the current instrument and has not been amended or replaced.
We could not confirm that this regulation is still the current version. It is still published on the Rwanda Utilities Regulatory Authority's own website. The authority issued new information and communications technology rules in January and August 2026 on other topics. Check with the authority if you rely on this rule.
The National Bank of Rwanda's outsourcing regulation (Regulation No 49/2022) and its cybersecurity rules for financial institutions.
We could not confirm this against a government source. Other legal sources describe a central bank rule requiring approval before major outsourcing, covering cloud services and backup sites abroad. We could not get the text from the National Bank of Rwanda, so we left the rule out of the list above. If you are a financial institution, ask the central bank directly.
Whether Rwanda imposes localisation on government cloud, education, gambling, mapping or defence data.
We found no rule requiring this data to stay in Rwanda, checked 19 August 2026, with medium confidence. The Rwanda Information Society Authority's Data Center and Cloud Services Directives are technical design standards and say nothing about where data must sit. We found no official Rwandan source for gambling or mapping rules. Government bodies are covered by Article 50 like everyone else.
The data provisions, if any, of Rwanda's new virtual assets law reported as gazetted in mid-2026.
We could not confirm this against a government source. Only legal databases and news reports mention it, so we make no claim about what it says. Check with the regulator if it could apply to you.
A firm date for the draft implementing regulations under the data protection law.
The regulator confirmed a consultation on 5 March 2026. It has not published the draft text or a timetable. Treat these rules as proposed only. They have no legal effect yet.
Exact statutory retention periods for medical records in Rwanda.
We could not confirm how long medical records must be kept. The regulator's health guidance mentions 'retaining medical records for a legally mandated period' but names no law and no number. We found no health ministry order setting it. Ask the health ministry if this affects you.
Freshness and refresh
Freshness
Checked about 2 months ago, on 19 August 2026.
Re-checked every 60 days. Next check due 18 October 2026.