Aller au contenu

What Rwanda's data protection law means for your software

Law No. 058/2021 changes how organisations collect, store and share personal data. A practical summary for product owners — not legal advice.

1 min de lecture

Rwanda's Law No. 058/2021 on the protection of personal data and privacy applies to any organisation that processes personal data of people in Rwanda. This is a practical summary for product teams; always confirm details with a legal adviser.

Register as a data controller

Organisations that process personal data register with the National Cyber Security Authority (NCSA).

Keep data in Rwanda — or get authorisation

Personal data must be stored in Rwanda unless the NCSA authorises storage abroad. This affects where your database and file storage live.

Collect less, and ask clearly

  • Only collect what you need for a stated purpose.
  • Ask for consent in plain language, with an unticked box.
  • Record what people agreed to, and when.

Be ready for requests and incidents

People can ask to see, correct or delete their data. And a personal-data breach must be reported to the NCSA within 48 hours of becoming aware of it. Build the tools for both before you launch, not after.

Partager