Comprehensive regime
Law relating to the Protection of Personal Data and Privacy
Law N° 58 of 2021 relating to the Protection of Personal Data and PrivacyLaw relating to the Protection of Personal Data and Privacy, RwandaLII (Official Gazette special of 15 October 2021)
In force since 15 October 2021. Binds public and private bodies.
What this law does
Article 4 requires a written contract between a data controller and a data processor before the processor may process personal data on the controller's behalf.
Article 6 requires the data subject's consent to be demonstrated where consent is the ground for processing, article 9 requires the consent of a holder of parental responsibility to process a child's personal data unless necessary to protect the child's vital interest, and article 10 permits processing sensitive personal data, including genetic or biometric information, only on consent, a legal obligation, a vital interest, public health, or archiving, scientific, or statistical grounds, with article 11 adding safeguards including capacity-building for staff and access controls.
Articles 18 to 24 give the data subject rights of access, objection, portability, rectification, and erasure, and article 21 gives the data subject the right not to be subject to a decision based solely on automated personal data processing, including profiling, that may produce legal or significant consequences for them, subject to listed exceptions including the data subject's explicit consent or contract necessity.
Articles 29 to 36 require registration as a data controller or data processor with the supervisory authority, and article 40 requires designation of a data protection officer where the controller or processor is a public or private corporate body, carries out large-scale systematic monitoring, or processes sensitive personal data or criminal-conviction data on a large scale.
Articles 43 to 45 require the data controller to notify the supervisory authority of a personal data breach, report on it, and communicate it to the data subject where it is likely to result in a high risk to their rights and freedoms.
Article 47 requires appropriate technical and organisational security measures, article 48 requires a supervisory-authority authorisation, the data subject's consent, or another listed ground before personal data is shared or transferred to a third party outside Rwanda, and article 50 requires personal data to be stored in Rwanda unless the controller or processor holds a valid registration certificate authorising storage abroad.
Article 53 sets an administrative fine, for an individual, of between two million and five million Rwandan francs or one percent of the preceding financial year's global turnover for listed administrative misconducts including failure to register, failure to designate a data protection officer, or failure to notify a breach, and one percent of global turnover alone for a corporate body or legal entity.
Articles 56 to 61 create separate criminal offences, each with its own imprisonment and fine range, for unlawfully accessing, using, sharing, or disclosing personal data, re-identifying de-identified data, destroying or altering data, selling data, unlawfully collecting or processing sensitive personal data, and providing false registration information, and article 62 fines a corporate body or legal entity convicted of any of those offences five percent of its preceding financial year's annual turnover.
Article 65 gives a person who suffers serious damage from a controller's or processor's violation of the Law the right to claim compensation before a competent court.
What it requires