Skip to the content
Global Data RulesData governance rules, country by country

Rwanda

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 19 August 2026.

If you collect data about people in Rwanda — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: HighEnforcement: Waking up

By default, personal data must stay in Rwanda. You can host it abroad only if the National Cyber Security Authority gives you a certificate that says so. Everyone who handles personal data must register with that authority first. If you are based outside Rwanda, you must also appoint a Rwandan representative. Breaking these rules can mean prison, not just a fine.

Data governance in Rwanda

The eight things that decide how you handle data about people in Rwanda. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law applies even if you have no office in Rwanda. It covers you as soon as you handle data about people located in Rwanda. There is no size, revenue or volume limit below which you are safe. If you are based outside Rwanda, you must also appoint a representative inside Rwanda. That representative must be a Rwandan company, and it must be registered with the regulator in its own right.

What you have to do here:
Register or notify · Appoint a representative · Appoint a data protection officer

Where the data is allowed to live

Only with the government's permission. The law says personal data is stored in Rwanda. You can host it somewhere else only if the National Cyber Security Authority has given you a certificate allowing exactly that. Telephone and internet companies have it worse. Their subscriber information may not leave Rwanda at all, and there is no permission to apply for. Tax records must also stay physically in Rwanda for ten years.

What you have to do here:
Keep the data in the country

What to do: Get the paperwork for one of the routes below signed before any data leaves Rwanda.

Sending data out of the country

Rwanda approves companies, not countries. There is no published list of safe destinations and no list of banned ones. You apply to the National Cyber Security Authority instead. You name the exact countries and hosting providers you will use, then wait for a certificate. There is an official model contract you sign with the company receiving the data. Signing it does not on its own let you host data abroad.

Ways to send data out:
Government sign-off needed · Standard contract clauses · Explicit consent · Needed for a contract · Important public interest · Legal claims · To save someone’s life

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The National Cyber Security Authority, working through its Data Protection and Privacy Office. It is real and it is working. It opened in March 2022. It has a named head, its own building in Kigali, a toll-free line, four published email addresses and a full set of application forms. It ran training and webinars throughout 2025 and 2026. We could not find a single published fine or formal decision against a named company. Treat it as a regulator that is getting started, not one that is already punishing people.

Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

The general rule is short and vague. Keep personal data only until the purpose you collected it for is finished, then stop. The minimum periods are long and specific. Business books and their supporting papers must be kept for ten years, physically in Rwanda. Banks, insurers, named essential service providers and government bodies must keep their computer activity logs for at least twelve months. Where a law or a contract makes you keep something longer, the privacy law allows that.

What you have to do here:
Delete data after a period · Keep data for a minimum period · Keep logs

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Two deadlines run at the same time under the privacy law. You have 48 hours from finding out about a data breach to tell the regulator. You have 72 hours to file a full written report with all the facts you have. If the breach is likely to seriously affect people, you must tell them too. The regulator approves how and when you do that. Suppliers have their own 48 hours to tell their customer.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things the summary does not tell you. One. Permission to send data abroad is not permission to keep it abroad. Those are two different applications, and consent gets you the first but never the second. Two. A child in Rwanda is anyone under sixteen. Three. Breaking this law is a crime. Individuals face one to three years in prison. Companies face a fine of five percent of turnover, and a court can order the business closed. Four. A company based abroad needs both a Rwandan representative and a data protection officer. The representative must be a Rwandan company that is itself registered. Five. Telephone and internet companies must have a Rwandan national as their chief technical officer or chief information officer.

What you have to do here:
Get a parent's consent for children · Appoint a representative
What it costs if you get it wrong:
Criminal liability · Percentage of global turnover

What's changing next

The main thing on the horizon is a set of detailed rules underneath the privacy law. The regulator consulted on the draft in March 2026. The justice ministry, the central bank, the utilities regulator, the food and drugs authority and the law reform commission all took part. The draft covers registration requirements and misconduct rules. Nothing has been published yet, so nothing is binding yet. Also watch three powers the regulator already holds. It could use them to change your answer without any new law.

What it costs if you get it wrong:
Order to stop
Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Telecoms

Telecoms data must stay in the country

Official name: Regulations No 001/R/TD-ICS/RURA/016 governing telecom network security in Rwanda · Regulations No 001/R/TD-ICS/RURA/016, signed at Kigali on 02/06/2016 following the Regulatory Board meeting of 06/05/2016 · Directly binding regulation

In forceNo — it stays put

A total ban for telephone and internet operators. Subscriber information, including call records and billing data, may not be transferred, stored or used outside Rwanda. The same rules require the licence holder's chief technical officer or chief information officer to be a Rwandan national. They also require regulator approval before any outsourcing.

In force since 2 June 2016Enforced from 2 December 2016

Enforced by Rwanda Utilities Regulatory Authority

How this country controls where data goes: Not allowed

Not fully verified — see “What we're not sure about” below.
Finance

Cyber security rules (Finance)

Official name: Minimum Cybersecurity Standards for the Financial Sector (with parallel editions for Essential Service Providers and for Public Institutions) · Issued by the National Cyber Security Authority under Articles 9(3) and 10(1) of Law No 26/2017 of 31/05/2017 establishing NCSA; version 1.0 · Government rules

In forceYes, with paperwork

Basic cyber rules the national cyber authority issued for financial institutions. There are near-identical versions for named essential service providers and for public bodies. The sharpest part is a twelve-month minimum for keeping system activity logs. You must write that same duty into your outsourcing contracts.

In force since 28 July 2023

Enforced by National Cyber Security Authority — Data Protection and Privacy Office

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.
Health and social care

Insurance rules

Official name: Guidance on Personal Data Protection in the Health Sector · Data Protection and Privacy Office guidance, published 2025 · Regulator guideline

In forceYes, with paperwork

Health data has no extra rule about where it must sit, although people assume it does. The regulator's health guidance applies the general privacy law to hospitals, pharmacies and insurers. It adds nothing of its own about where data must be stored. So the Article 50 storage certificate is still the control that matters for health data.

In force since 31 July 2025

Enforced by National Cyber Security Authority — Data Protection and Privacy Office

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Standard contract clauses

Not fully verified — see “What we're not sure about” below.

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Cyber security rules

Official name: Itegeko No 058/2021 ryo ku wa 13/10/2021 rigenga kurinda amakuru bwite n'ubuzima bwite / Law No 058/2021 of 13/10/2021 relating to the protection of personal data and privacy · Law No 058/2021 of 13/10/2021, Official Gazette no Special of 15/10/2021 · Act of parliament

In forceYes, with paperwork

Rwanda's general privacy law. Everyone who handles personal data must register with the National Cyber Security Authority and appoint a data protection officer. Companies based abroad must also appoint a Rwandan representative. Data may leave Rwanda, but only by the routes the law names. Hosting data abroad needs its own certificate. Breaches must be reported within 48 hours. Penalties are criminal as well as financial.

In force since 15 October 2021Enforced from 15 October 2023

Enforced by National Cyber Security Authority — Data Protection and Privacy Office

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Standard contract clauses, Explicit consent, Needed for a contract, Important public interest, Legal claims, To save someone’s life

Cyber security rules (2023)

Official name: Law No 058/2021, Article 50 — Ibikwa ry'amakuru bwite / Storage of personal data · Law No 058/2021 of 13/10/2021, Article 50 · Act of parliament

In forceYes, with paperwork

The rule that catches cloud users. Personal data stays in Rwanda by default. You can host it abroad only if the National Cyber Security Authority has issued a certificate saying so. Unlike the transfer rule, there is no consent exception and no necessity exception. A certificate is the only way.

In force since 15 October 2021Enforced from 15 October 2023

Enforced by National Cyber Security Authority — Data Protection and Privacy Office

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Personal data needs a copy kept in the country

Official name: Law No 020/2023 of 31/03/2023 on tax procedures · Law No 020/2023 of 31/03/2023, books of accounts and record keeping · Act of parliament

In forceA copy must stay

An easily missed rule about where data must sit, and it has nothing to do with privacy law. Every company operating in Rwanda, and every person in business, must keep books of account and supporting papers for ten years, physically in Rwanda. So customer and employee records held inside those books cannot sit only abroad.

In force since 31 March 2023

Enforced by Rwanda Revenue Authority

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.

Who you would hear from

  • Urwego rw'Igihugu rushinzwe Umutekano mu Ikoranabuhanga (NCSA)

    Supervisory authority for personal data protection and privacy; registration of controllers and processors; authorisation of storage and transfer outside Rwanda; breach reporting; national cybersecurity standards

    Yes. The Data Protection and Privacy Office opened on 31 March 2022. It has a named head, a Kigali office, a toll-free number and separate addresses for registration, breach reporting and complaints. It ran training, webinars and a national privacy week through 2025 and 2026. It consulted on draft rules in March 2026. We found no published fine or formal decision against a named company, and no public register of decisions. So you can see its day-to-day work, but not its punishment record.

  • RURA

    Telecommunications, broadcasting and other utilities. Enforces the telecom network security regulation, including the ban on storing subscriber information outside Rwanda.

    Fully working, and issuing new information and communications technology rules as recently as August 2026. It promises to audit every telecom licence holder at least once a year.

  • RRA

    Tax administration, including the duty to maintain books and documents for ten years in Rwanda

    Fully working. It publishes taxpayer guidance and issues administrative fines.

  • Banki Nkuru y'u Rwanda (BNR)

    Banking, payments, insurance, microfinance and pensions supervision, including outsourcing approvals

    Fully working. It took part in the March 2026 consultation on draft data protection rules. We could not read its outsourcing or cybersecurity rules on its own website.

  • Rw-CSIRT

    National cyber incident response; receives incident notifications from financial institutions, essential service providers and public bodies

    Operational and publishing alerts and advisories through the National Cyber Security Authority's site.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Whether the National Cyber Security Authority has ever imposed a fine or issued a formal enforcement decision under the data protection law.

    We found no published fines or enforcement decisions from either regulator. That does not prove there are none. Rwanda may simply not publish them. This is why we rate enforcement as waking up rather than active.

  • How many organisations are registered as data controllers or processors, and how many hold authorisation to store personal data outside Rwanda.

    We could not find any numbers on how often the certificate to store data abroad is granted. So we cannot tell you whether approval is routine or rare. That difference changes your real risk a lot. Ask the regulator before you plan around it.

  • Whether there is a fee for registration, for renewal, or for an offshore storage or transfer authorisation.

    We could not confirm what registration costs. The regulator's guide and application forms list the documents you need but no fees. Ask the regulator for the current fee before you apply.

  • That the 2016 telecom network security regulation is still the current instrument and has not been amended or replaced.

    We could not confirm that this regulation is still the current version. It is still published on the Rwanda Utilities Regulatory Authority's own website. The authority issued new information and communications technology rules in January and August 2026 on other topics. Check with the authority if you rely on this rule.

  • The National Bank of Rwanda's outsourcing regulation (Regulation No 49/2022) and its cybersecurity rules for financial institutions.

    We could not confirm this against a government source. Other legal sources describe a central bank rule requiring approval before major outsourcing, covering cloud services and backup sites abroad. We could not get the text from the National Bank of Rwanda, so we left the rule out of the list above. If you are a financial institution, ask the central bank directly.

  • Whether Rwanda imposes localisation on government cloud, education, gambling, mapping or defence data.

    We found no rule requiring this data to stay in Rwanda, checked 19 August 2026, with medium confidence. The Rwanda Information Society Authority's Data Center and Cloud Services Directives are technical design standards and say nothing about where data must sit. We found no official Rwandan source for gambling or mapping rules. Government bodies are covered by Article 50 like everyone else.

  • The data provisions, if any, of Rwanda's new virtual assets law reported as gazetted in mid-2026.

    We could not confirm this against a government source. Only legal databases and news reports mention it, so we make no claim about what it says. Check with the regulator if it could apply to you.

  • A firm date for the draft implementing regulations under the data protection law.

    The regulator confirmed a consultation on 5 March 2026. It has not published the draft text or a timetable. Treat these rules as proposed only. They have no legal effect yet.

  • Exact statutory retention periods for medical records in Rwanda.

    We could not confirm how long medical records must be kept. The regulator's health guidance mentions 'retaining medical records for a legally mandated period' but names no law and no number. We found no health ministry order setting it. Ask the health ministry if this affects you.

Freshness and refresh

Freshness

Checked about 2 months ago, on 19 August 2026.

Re-checked every 60 days. Next check due 18 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.