Law relating to the Protection of Personal Data and Privacy
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 15 October 2021.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Have a lawful basis under this Law, such as the data subject's consent or one of the other seven grounds article 46 lists, before processing personal data.
- Where consent is the basis for processing, obtain it only after the data subject is informed of the consequences of consenting, and let the data subject withdraw consent at any time without affecting the lawfulness of processing carried out before the withdrawal.
- Enter into a written contract with a data processor before it processes personal data on your behalf, and authorise only a processor who gives sufficient guarantees to implement appropriate technical and organisational measures.
- Register with the supervisory authority as a data controller or data processor before processing personal data, and designate a data protection officer where article 40 requires one.
- Log every collection, alteration, access, disclosure, combination and erasure of personal data, and maintain a record of all processing activities, producing both to the supervisory authority on request.
- Implement appropriate technical measures against loss, damage or destruction of personal data, verify regularly that they work, and keep them updated against new or identified risks.
- Carry out a data protection impact assessment before processing likely to result in a high risk to a natural person's rights and freedoms, including large-scale processing of sensitive personal data or systematic monitoring of a publicly accessible area on a large scale.
- Retain personal data only until the purpose of processing is fulfilled unless a listed ground extends retention, and destroy it in a manner that prevents reconstruction once the retention period ends.
What it reaches
Obligation class
Consent, Contract terms, Licensing, Governance, Security, DPIA, Retention
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 2 applies the Law to processing personal data by electronic or other means, including through a non-automated platform, by a data controller, data processor or third party established or residing in Rwanda, and to any such person outside Rwanda who processes the personal data of a data subject located in Rwanda.
Article 4 requires a written contract between a data controller and a data processor before the processor may process personal data on the controller's behalf, and article 46 lists eight grounds, led by consent, on which processing personal data is lawful.
Article 6 requires the data subject's consent to be demonstrated where consent is the ground for processing, requires that consent to follow the data subject's free and informed decision, and permits it in oral, written or electronic form, and article 8 lets the data subject withdraw consent at any time without affecting the lawfulness of processing carried out before the withdrawal.
Article 13 relieves a controller or processor of any duty to acquire identifying information solely to comply with this Law where its processing purpose does not require identification, and articles 14 and 15 require personal data collected from someone other than the data subject to meet one of four listed grounds and require all personal data to be kept complete, accurate, current and not misleading.
Articles 16 and 17 require the data controller or processor to log data collection, alteration, access, disclosure, combination and erasure, and to maintain a record of all processing activities, both producible to the supervisory authority on request.
Articles 29 to 36 require registration as a data controller or data processor with the supervisory authority before processing personal data, govern the registration certificate's issuance, renewal, modification and cancellation, and require the supervisory authority to keep a public register.
Article 37 carries the lawfulness, purpose limitation, accuracy and storage limitation principles, article 38 requires appropriate technical and organisational measures, a record of processing, and a data protection impact assessment before high-risk processing such as large-scale processing of sensitive personal data or systematic monitoring of a publicly accessible area, and article 39 requires a data controller or processor with no establishment or residence in Rwanda to designate a representative there.
Article 40 requires designation of a data protection officer where the controller or processor is a public or private corporate body, carries out large-scale systematic monitoring, or processes sensitive personal data or criminal-conviction data on a large scale, and article 41 sets the officer's duties. Article 47 requires appropriate technical measures against loss, damage or destruction of personal data, regularly verified and kept updated against new risks.
Article 52 limits retention of personal data to the purpose for which it was collected unless a listed ground, such as a legal obligation, a court order or the data subject's consent, extends it, and requires destruction in a manner that prevents reconstruction once the retention period ends.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreach
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.