Law / Rwanda

Rwanda

4 of 7 named instruments researched to a stage, across four of the six areas of law we track: 4 in force. As of 5 September 2026.

  1. AI law none researched
  2. Privacy law 1
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law 1
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law1 instrument, 1 in force

Research summary (177 words)

Rwanda's comprehensive data-protection regime is Law N° 58/2021 of 13 October 2021 relating to the Protection of Personal Data and Privacy, assented to on 13 October 2021 and in force since 15 October 2021, enforced by a supervisory authority defined as the public authority in charge of cyber security, the National Cyber Security Authority.

The Law binds any data controller, data processor, or third party established or residing in Rwanda who processes personal data, and any such person outside Rwanda who processes the personal data of a data subject located in Rwanda.

It classes race, health status, criminal records, genetic or biometric information, religious or philosophical beliefs, political opinion, and sexual life among sensitive personal data, sets a registration and data-protection-officer regime, requires a supervisory-authority authorisation, the data subject's consent, or another listed ground before personal data is shared or transferred outside Rwanda, and otherwise requires personal data to be stored in Rwanda unless the controller or processor holds a registration certificate authorising storage abroad.

It sets tiered administrative fines and, separately, tiered criminal penalties by offence.

Comprehensive regime

Law relating to the Protection of Personal Data and Privacy

Law N° 58 of 2021 relating to the Protection of Personal Data and PrivacyLaw relating to the Protection of Personal Data and Privacy, RwandaLII (Official Gazette special of 15 October 2021)

In force since 15 October 2021. Binds public and private bodies.

What this law does

Article 4 requires a written contract between a data controller and a data processor before the processor may process personal data on the controller's behalf.

Article 6 requires the data subject's consent to be demonstrated where consent is the ground for processing, article 9 requires the consent of a holder of parental responsibility to process a child's personal data unless necessary to protect the child's vital interest, and article 10 permits processing sensitive personal data, including genetic or biometric information, only on consent, a legal obligation, a vital interest, public health, or archiving, scientific, or statistical grounds, with article 11 adding safeguards including capacity-building for staff and access controls.

Articles 18 to 24 give the data subject rights of access, objection, portability, rectification, and erasure, and article 21 gives the data subject the right not to be subject to a decision based solely on automated personal data processing, including profiling, that may produce legal or significant consequences for them, subject to listed exceptions including the data subject's explicit consent or contract necessity.

Articles 29 to 36 require registration as a data controller or data processor with the supervisory authority, and article 40 requires designation of a data protection officer where the controller or processor is a public or private corporate body, carries out large-scale systematic monitoring, or processes sensitive personal data or criminal-conviction data on a large scale.

Articles 43 to 45 require the data controller to notify the supervisory authority of a personal data breach, report on it, and communicate it to the data subject where it is likely to result in a high risk to their rights and freedoms.

Article 47 requires appropriate technical and organisational security measures, article 48 requires a supervisory-authority authorisation, the data subject's consent, or another listed ground before personal data is shared or transferred to a third party outside Rwanda, and article 50 requires personal data to be stored in Rwanda unless the controller or processor holds a valid registration certificate authorising storage abroad.

Article 53 sets an administrative fine, for an individual, of between two million and five million Rwandan francs or one percent of the preceding financial year's global turnover for listed administrative misconducts including failure to register, failure to designate a data protection officer, or failure to notify a breach, and one percent of global turnover alone for a corporate body or legal entity.

Articles 56 to 61 create separate criminal offences, each with its own imprisonment and fine range, for unlawfully accessing, using, sharing, or disclosing personal data, re-identifying de-identified data, destroying or altering data, selling data, unlawfully collecting or processing sensitive personal data, and providing false registration information, and article 62 fines a corporate body or legal entity convicted of any of those offences five percent of its preceding financial year's annual turnover.

Article 65 gives a person who suffers serious damage from a controller's or processor's violation of the Law the right to claim compensation before a competent court.

What it requires

Scraping law1 instrument, 1 in force

Research summary (304 words)

Rwanda has no scraping-specific statute, so general law governs each dimension separately.

The Law on Prevention and Punishment of Cybercrimes, 2018 criminalises unauthorised access to computer or computer system data, and unlike a security-measure-triggered offence, its own three grounds turn on lacking consent, lacking entitlement to control or access, or accessing another person's computer system without authorisation, none of which require defeating a technical access control, so whether reading a public, unauthenticated page falls inside or outside the provision has not been tested in a reported Rwandan case.

No Rwandan court has ruled on the enforceability of a browsewrap or clickwrap terms of service against a scraper.

The Law on the Protection of Intellectual Property, 2009 permits free reproduction in the form of quotation of a short part of a published work, compatible with fair practice and not exceeding the extent justified by the purpose, and separately excludes published daily news from copyright protection outright, but Rwanda has not enacted a text-and-data-mining exception, so training a model on scraped copyrighted text rests only on the quotation exception if the reproduction can be characterised as a short, fair-practice quotation.

The same Law defines an act of unfair competition broadly, as any act or practice which, in the exercise of industrial or commercial activities, is unlawful or contrary to honest use, but confers no sui generis database right, and no located case law applies the unfair-competition definition to data scraping.

The Law relating to the Protection of Personal Data and Privacy, 2021 applies to personal data without a general carve-out for information the data subject has made public, so scraping personal data from a public Rwandan website remains subject to the Law's lawful-basis, purpose-limitation, registration, and cross-border-transfer duties. No Rwandan statute or reported case assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Law on Prevention and Punishment of Cybercrimes, unauthorized access

Law N° 60/2018 of 25/09/2018 on Prevention and Punishment of Cyber Crimes art. 16 (Unauthorized access to a computer or a computer system data)official Law text, RwandaLII (Official Gazette special of 25 September 2018)

In force since 25 September 2018. Binds public and private bodies.

What this law does

Article 16 makes it an offence for a person to intentionally and unlawfully get access to computer or computer system data where the person does not have consent from someone entitled to give it, is not entitled to control or access the data, or accesses another person's computer system without authorization to know recorded or transmitted data, by any means and regardless of location. The offence carries imprisonment of six months to two years and a fine of RWF 1,000,000 to 2,000,000.

None of article 16's three grounds requires infringing a technical security measure; each turns instead on the absence of consent, entitlement, or authorization.

What it requires

Age gating law1 instrument, 1 in force

Research summary (244 words)

Rwanda has no adult-content age-verification statute, no social-media minor-access restriction, and no app-store age-verification requirement, but it does have an age-appropriate design duty. The Ministry of Information, Communication, Technology and Innovation issued Ministerial Instructions N° 001/MINICT/2024 of 22/01/2024 on Child Online Protection, in force since their publication in the Official Gazette on 23 January 2024.

The instructions bind any person or organisation that broadcasts or provides content online or provides access to online content, a scope reaching general-purpose digital content providers and internet service providers rather than only services aimed at children, and require them to put in place a mechanism to prevent children from accessing age-inappropriate content, sites, products, or interactive services, and to label content for suitability for children.

Separately, Law N° 71/2018 of 31/08/2018 relating to the Protection of the Child criminalises showing a child pornographic images or sounds, recording a child's pornographic picture or voice, and advertising children's pornographic images, but those provisions bind the person who commits those acts rather than imposing an age-verification or age-gating duty on a service.

In April 2026 the Minister of ICT and Innovation said a draft law under review would bar children under sixteen from major social media and video-sharing platforms and would draw on Rwanda's national digital identity system for age verification; as of this review no such bill had been published in the Official Gazette or otherwise located as an official text, so it does not appear as an instrument here.

Age-appropriate design code

Ministerial Instructions on Child Online Protection

Ministerial Instructions N° 001/MINICT/2024 of 22/01/2024 on Child Online ProtectionMinisterial Instructions N° 001/MINICT/2024 of 22/01/2024 on Child Online Protection

In force since 23 January 2024. Binds public and private bodies.

What this law does

Article 3 applies these instructions to any person or organisation that broadcasts or provides content online or provides access to online content, a scope not confined to services aimed at children or to social media platforms.

Article 4 requires digital content providers and retailers to make available digital content filtering tools, maintain plans to manage harmful online content, provide a reporting function for users, give a clear external label describing whether platform content is suitable for children, and put in place a mechanism to prevent children from accessing age-inappropriate content, sites, products, or interactive services.

Article 5 requires internet service providers to inform subscribers of risks to children, support reporting of child abuse, block access to child-abuse material once identified, and make parental-control tools available where applicable. Article 6 requires cybercafes and public Wi-Fi providers in public places to proactively block access to sites known for hosting content harmful to children.

Article 7 requires broadcasters and television service providers to indicate the suitability of content for various age categories. It also requires them to implement technical barriers, including parental controls and age-verification tools, so that children are not exposed to harmful content.

Article 8 requires social media users to self-regulate by refraining from creating or publishing videos of child actors in age-inappropriate roles, and from creating or publishing children's images or videos for entertainment or commercial purposes without the consent of a holder of parental responsibility.

The instructions themselves do not define the term child; they are issued pursuant to Law N° 71/2018 relating to the Protection of the Child, which defines a child as any person under eighteen years of age.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (262 words)

Rwanda has no press-publisher neighbouring right, no mandatory platform-to-publisher bargaining code, no recognized hot-news misappropriation doctrine distinct from ordinary copyright law, and no located statute or case law addressing hyperlinking or framing liability specifically; each of those dimensions is a sourced absence rather than an unresolved question.

The relevant instrument is the Law on the Protection of Intellectual Property, 2009, which excludes published daily news and news communicated to the public from copyright protection outright (art. 198), so a bare news item is never a protected work under Rwandan law regardless of who first reported it.

The same Law lets a person reproduce, in a newspaper or periodical, or broadcast or otherwise communicate to the public, an article on current economic, political, or religious topics published in a newspaper or periodical, or a broadcast work of the same character, without the author's authorization and without payment, where the right to reproduction, broadcasting, or communication to the public has not been expressly reserved (art. 209, item 1); it separately permits free reproduction in the form of quotation of a short part of a published work, subject to a fair-practice and extent-justified test and an obligation to indicate the source and author (art. 205).

Neither exception is capped at a headline-length threshold beyond that fair-practice test, and no reported Rwandan decision applies either to a systematic news aggregator's reproduction of headlines and snippets, as opposed to a newspaper's own press review or current-events reporting. The Law predates the concept of a machine-readable text-and-data-mining reservation entirely, so no opt-out mechanism of that kind exists either.

Snippet reproduction

Law on the Protection of Intellectual Property, news exclusion and informatory-use and quotation exceptions

Law N° 31/2009 of 26/10/2009 on the Protection of Intellectual Property, arts. 198, 205, 209Law N° 31/2009 of 26/10/2009 on the Protection of Intellectual Property, full text as republished by WIPO Lex

In force since 14 December 2009. Binds public and private bodies.

What this law does

Article 198 excludes published daily news or news communicated to the public, official legislative, administrative, or judiciary texts, and mere ideas, procedures, systems, methods, concepts, principles, or discoveries from copyright protection: a bare news item is never a protected work under Rwandan law, whichever outlet reports it first.

Article 209 separately permits, without the author's authorization and without payment of remuneration, subject to indicating the source and the author's name as far as practicable: the reproduction in a newspaper or periodical, or the broadcasting or other communication to the public, of an article published in a newspaper or periodical on current economic, political, or religious topics, or a broadcast work of the same character, where the right to reproduction, broadcasting, or communication to the public is not expressly reserved; the reproduction or communication to the public, for the purpose of reporting short current events, of a work seen or heard in the course of those events, to the extent justified by the informatory purpose; and the reproduction, broadcasting, or communication to the public of a political speech, lecture, address, sermon, or similar public address, or a speech delivered during legal proceedings, to the extent justified by the purpose of providing current information.

Article 205 separately permits free reproduction in the form of quotation of a short part of a published work, without authorization or payment, provided the reproduction is compatible with fair practice and does not exceed the extent justified by the purpose, and is accompanied by an indication of source and the author's name where it appears in the work quoted.

None of these three provisions is capped at a headline-length threshold distinct from the fair-practice and informatory-purpose tests they each already carry.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.