Law relating to the Protection of Personal Data and Privacy, supervisory authority, penalties and offences
Law N° 58/2021, arts. 27-28 and 53-65 (supervisory authority, penalties, offences and compensation)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 15 October 2021.
An enforcement supervision rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Comply with the supervisory authority's oversight, including its inspections, its register of data controllers and processors, and any regulation it issues to implement this Law.
- Expect an administrative fine of RWF 2,000,000 to 5,000,000, or one percent of your preceding year's global turnover, for misconducts including failing to register, log processing, maintain records, designate a data protection officer, or notify, report or communicate a breach; a corporate body or legal entity is fined one percent of global turnover alone.
- Expect criminal liability, on conviction, for unlawfully accessing, using, sharing, transferring or disclosing personal data, re-identifying de-identified data, destroying or altering data, selling data, unlawfully collecting or processing sensitive personal data, or providing false registration information, each carrying its own imprisonment and fine range, with a fine of five percent of turnover where a corporate body or legal entity is convicted.
- Expect a data subject who suffers serious damage from your violation of this Law to have the right to claim compensation before a competent court, unless you prove you were not responsible for the damage.
- Expect the supervisory authority to be the organ that settles conflicts arising under this Law in the first instance, subject to your right to take an unresolved conflict, or a disputed administrative sanction, to a competent court.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
Imprisonment and fine ranges scale by offence: one to three years and a fine of RWF 7,000,000 to 10,000,000 for unlawfully accessing, using, sharing, transferring, or disclosing personal data (art. 56) or for unlawful re-identification of de-identified personal data (art. 57); three to five years and the same fine range for unlawful destruction, erasure, concealment, or alteration of personal data (art. 58); five to seven years and RWF 12,000,000 to 15,000,000 for unlawful sale of personal data (art. 59); seven to ten years and RWF 20,000,000 to 25,000,000 for unlawfully collecting or processing sensitive personal data (art. 60); and one to three years and RWF 3,000,000 to 5,000,000 for providing false information during or after registration (art. 61). A corporate body or legal entity convicted of any of these offences is fined five percent of its preceding financial year's annual turnover (art. 62).
Penalty structure
Article 53's administrative fine for listed administrative misconducts (failure to register, to designate a data protection officer, to log processing, or to notify or report a breach, among others): for an individual, not less than RWF 2,000,000 and not more than RWF 5,000,000, or one percent of the preceding financial year's global turnover; for a corporate body or legal entity, one percent of global turnover alone. Separately, articles 56 to 61 set criminal fines up to RWF 25,000,000 (see criminal_exposure_note), and article 62 fines a convicted corporate body five percent of its annual turnover.
- Rule
- Higher of
- As of
- 5 September 2026
- Currency
- RWF
- Fixed cap
- 5,000,000
- Turnover percentage cap
- 1
Who enforces it
Enforcement body
National Cyber Security Authority (the supervisory authority)
What it reaches
Obligation class
Governance, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 27 tasks the supervisory authority with overseeing the Law's implementation, responding to requests for an opinion, informing data subjects, controllers, processors and third parties of their rights and obligations, keeping the register of data controllers and processors, investigating and deciding complaints, and cooperating with domestic and foreign counterparts, and article 28 gives it the power to issue registration certificates, ensure compliance, protect public freedoms and privacy from information and communication technologies, make regulations, and impose administrative sanctions.
Article 53 sets an administrative fine, for an individual, of between two million and five million Rwandan francs or one percent of the preceding financial year's global turnover for listed misconducts including failure to maintain records, log processing, register, report a certificate change, designate a data protection officer, or notify, report or communicate a breach, and one percent of global turnover alone for a corporate body or legal entity, with article 54 letting anyone dissatisfied with an administrative sanction apply to the competent court and article 55 depositing the fine with the Public Treasury.
Articles 56 to 61 create separate criminal offences, each with its own imprisonment and fine range, for unlawfully accessing, using, sharing, transferring or disclosing personal data, re-identifying de-identified data, destroying, erasing, concealing or altering data, selling data, unlawfully collecting or processing sensitive personal data, and providing false registration information, article 62 fines a corporate body or legal entity convicted of any of those offences five percent of its preceding financial year's annual turnover, and article 63 lets the court order seizure or confiscation of items and proceeds and the permanent or temporary closure of the offending entity or premises.
Article 64 makes the supervisory authority the organ that settles conflicts arising under this Law in the first instance, subject to a party's right to take an unresolved conflict to a competent court, and article 65 gives a person who suffers serious damage from a controller's or processor's violation of this Law the right to claim compensation before a competent court, unless the controller or processor proves it was not responsible for the damage.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbothigh_risk_decisionsis_listed_company
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.