What Rwanda's data protection law means for your software
Law No. 058/2021 changes how organisations collect, store and share personal data. A practical summary for product owners — not legal advice.
1 min de lecture
Rwanda's Law No. 058/2021 on the protection of personal data and privacy applies to any organisation that processes personal data of people in Rwanda. This is a practical summary for product teams; always confirm details with a legal adviser.
Register as a data controller
Organisations that process personal data register with the National Cyber Security Authority (NCSA).
Keep data in Rwanda — or get authorisation
Personal data must be stored in Rwanda unless the NCSA authorises storage abroad. This affects where your database and file storage live.
Collect less, and ask clearly
- Only collect what you need for a stated purpose.
- Ask for consent in plain language, with an unticked box.
- Record what people agreed to, and when.
Be ready for requests and incidents
People can ask to see, correct or delete their data. And a personal-data breach must be reported to the NCSA within 48 hours of becoming aware of it. Build the tools for both before you launch, not after.
Articles liés
Entreprise1 min de lecture
Why Kigali works for European and Gulf software teams
Full working-day overlap with Europe, three working languages and a fast-growing tech ecosystem.