Law / Rwanda

Law relating to the Protection of Personal Data and Privacy, personal data breach notification

Law N° 58/2021, arts. 43-45 (personal data breach notification)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 15 October 2021.

A breach notification rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Notify the supervisory authority of the breach within 48 hours of becoming aware of it.
  • As a data processor, notify the data controller of the breach within 48 hours of becoming aware of it.
  • Submit a full report on the breach to the supervisory authority within 72 hours, describing its nature, the contact point for more information, the measures taken to address it, and your proposal and timeline for communicating it to affected data subjects.
  • Communicate the breach to the affected data subject, in writing or electronically after becoming aware of it, where it is likely to result in a high risk to their rights and freedoms; this Law fixes no separate deadline for that communication, and excuses it only where you had already protected the data, neutralised the risk, or made an equally effective public communication.

What it reaches

Obligation class

Breach notice, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 43 requires the data controller, within forty-eight hours of becoming aware of a personal data breach, to notify it to the supervisory authority, and requires a data processor who becomes aware of a breach to notify the data controller within the same forty-eight hours.

Article 44 requires the data controller to submit a full report to the supervisory authority no later than seventy-two hours after becoming aware of the breach, describing its nature, the affected categories and approximate numbers of data subjects and records, the data protection officer's or other contact point's details, the measures taken or proposed to address it and mitigate its effects, and a proposal and timeline for communicating it to affected data subjects.

Article 45 requires the data controller to communicate a breach likely to result in a high risk to a data subject's rights and freedoms to that data subject, in writing or electronically, after becoming aware of it, but sets no separate deadline for that communication, and excuses it where the data was already protected by measures such as encryption, the high risk is no longer likely to materialize, or an equally effective public communication was made instead; the supervisory authority may still require the communication to be made.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics
  • operates_essential_service

Read the law

Law relating to the Protection of Personal Data and Privacy, RwandaLII (Official Gazette special of 15 October 2021)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app