Law relating to the Protection of Personal Data and Privacy
Law N° 58 of 2021 relating to the Protection of Personal Data and Privacy
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 15 October 2021.
A comprehensive regime rule binding public and private bodies.
As of 5 September 2026.
What it requires
- Obtain the data subject's explicit, freely given consent before processing their personal data for a specified purpose, unless another lawful ground under this Law applies.
- Before processing a child's personal data, obtain the consent of a holder of parental responsibility over the child, unless the processing is necessary to protect the child's vital interest.
- Process sensitive personal data, including genetic or biometric information, only on one of the grounds this Law lists, and apply additional safeguards including staff-capacity building and access controls.
- Register with the supervisory authority as a data controller or data processor before processing personal data, and designate a data protection officer where the Law requires one.
- Notify the supervisory authority of a personal data breach within the required timeframe, and communicate a breach that is likely to result in a high risk to the data subject.
- Do not share or transfer personal data outside Rwanda without the supervisory authority's authorisation, the data subject's consent, or another listed ground, and store personal data in Rwanda unless registered to store it abroad.
- Let a data subject exercise their rights of access, rectification, erasure, restriction, objection, and portability, and honour their right not to be subject to a decision based solely on automated processing that produces legal or significant consequences for them.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
Imprisonment and fine ranges scale by offence: one to three years and a fine of RWF 7,000,000 to 10,000,000 for unlawfully accessing, using, sharing, transferring, or disclosing personal data (art. 56) or for unlawful re-identification of de-identified personal data (art. 57); three to five years and the same fine range for unlawful destruction, erasure, concealment, or alteration of personal data (art. 58); five to seven years and RWF 12,000,000 to 15,000,000 for unlawful sale of personal data (art. 59); seven to ten years and RWF 20,000,000 to 25,000,000 for unlawfully collecting or processing sensitive personal data (art. 60); and one to three years and RWF 3,000,000 to 5,000,000 for providing false information during or after registration (art. 61). A corporate body or legal entity convicted of any of these offences is fined five percent of its preceding financial year's annual turnover (art. 62).
Penalty structure
Article 53's administrative fine for listed administrative misconducts (failure to register, to designate a data protection officer, to log processing, or to notify or report a breach, among others): for an individual, not less than RWF 2,000,000 and not more than RWF 5,000,000, or one percent of the preceding financial year's global turnover; for a corporate body or legal entity, one percent of global turnover alone. Separately, articles 56 to 61 set criminal fines up to RWF 25,000,000 (see criminal_exposure_note), and article 62 fines a convicted corporate body five percent of its annual turnover.
- Rule
- Higher of
- As of
- 5 September 2026
- Currency
- RWF
- Fixed cap
- 5,000,000
- Turnover percentage cap
- 1
Who enforces it
Enforcement body
National Cyber Security Authority (the supervisory authority)
What it reaches
Obligation class
Consent, Biometric, Breach notice, Data subject rights, Disclosure, Governance, Licensing, Retention, Security, Transfer
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 4 requires a written contract between a data controller and a data processor before the processor may process personal data on the controller's behalf.
Article 6 requires the data subject's consent to be demonstrated where consent is the ground for processing, article 9 requires the consent of a holder of parental responsibility to process a child's personal data unless necessary to protect the child's vital interest, and article 10 permits processing sensitive personal data, including genetic or biometric information, only on consent, a legal obligation, a vital interest, public health, or archiving, scientific, or statistical grounds, with article 11 adding safeguards including capacity-building for staff and access controls.
Articles 18 to 24 give the data subject rights of access, objection, portability, rectification, and erasure, and article 21 gives the data subject the right not to be subject to a decision based solely on automated personal data processing, including profiling, that may produce legal or significant consequences for them, subject to listed exceptions including the data subject's explicit consent or contract necessity.
Articles 29 to 36 require registration as a data controller or data processor with the supervisory authority, and article 40 requires designation of a data protection officer where the controller or processor is a public or private corporate body, carries out large-scale systematic monitoring, or processes sensitive personal data or criminal-conviction data on a large scale.
Articles 43 to 45 require the data controller to notify the supervisory authority of a personal data breach, report on it, and communicate it to the data subject where it is likely to result in a high risk to their rights and freedoms.
Article 47 requires appropriate technical and organisational security measures, article 48 requires a supervisory-authority authorisation, the data subject's consent, or another listed ground before personal data is shared or transferred to a third party outside Rwanda, and article 50 requires personal data to be stored in Rwanda unless the controller or processor holds a valid registration certificate authorising storage abroad.
Article 53 sets an administrative fine, for an individual, of between two million and five million Rwandan francs or one percent of the preceding financial year's global turnover for listed administrative misconducts including failure to register, failure to designate a data protection officer, or failure to notify a breach, and one percent of global turnover alone for a corporate body or legal entity.
Articles 56 to 61 create separate criminal offences, each with its own imprisonment and fine range, for unlawfully accessing, using, sharing, or disclosing personal data, re-identifying de-identified data, destroying or altering data, selling data, unlawfully collecting or processing sensitive personal data, and providing false registration information, and article 62 fines a corporate body or legal entity convicted of any of those offences five percent of its preceding financial year's annual turnover.
Article 65 gives a person who suffers serious damage from a controller's or processor's violation of the Law the right to claim compensation before a competent court.
When LexLint raises it
processes_biometricshigh_risk_decisionsserves_minors