Law / Rwanda

Rwanda

9 of 12 named instruments researched to a stage, across four of the six areas of law we track: 9 in force. As of 19 September 2026.

When they take effect9 of 9 carry a date. Earlier is before 2014.
Before 2014: 1 instrument (1 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 1 instrument (1 in force) 2019: 0 instruments 2020: 0 instruments ’20 2021: 6 instruments (6 in force) 2022: 0 instruments 2023: 0 instruments 2024: 1 instrument (1 in force) 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law 1
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (177 words)

Rwanda's comprehensive data-protection regime is Law N° 58/2021 of 13 October 2021 relating to the Protection of Personal Data and Privacy, assented to on 13 October 2021 and in force since 15 October 2021, enforced by a supervisory authority defined as the public authority in charge of cyber security, the National Cyber Security Authority.

The Law binds any data controller, data processor, or third party established or residing in Rwanda who processes personal data, and any such person outside Rwanda who processes the personal data of a data subject located in Rwanda.

It classes race, health status, criminal records, genetic or biometric information, religious or philosophical beliefs, political opinion, and sexual life among sensitive personal data, sets a registration and data-protection-officer regime, requires a supervisory-authority authorisation, the data subject's consent, or another listed ground before personal data is shared or transferred outside Rwanda, and otherwise requires personal data to be stored in Rwanda unless the controller or processor holds a registration certificate authorising storage abroad.

It sets tiered administrative fines and, separately, tiered criminal penalties by offence.

Breach notification

Law relating to the Protection of Personal Data and Privacy, personal data breach notification

Law N° 58/2021, arts. 43-45 (personal data breach notification)Law relating to the Protection of Personal Data and Privacy, RwandaLII (Official Gazette special of 15 October 2021)

In force since 15 October 2021. Binds public and private bodies.

What this law does

Article 43 requires the data controller, within forty-eight hours of becoming aware of a personal data breach, to notify it to the supervisory authority, and requires a data processor who becomes aware of a breach to notify the data controller within the same forty-eight hours.

Article 44 requires the data controller to submit a full report to the supervisory authority no later than seventy-two hours after becoming aware of the breach, describing its nature, the affected categories and approximate numbers of data subjects and records, the data protection officer's or other contact point's details, the measures taken or proposed to address it and mitigate its effects, and a proposal and timeline for communicating it to affected data subjects.

Article 45 requires the data controller to communicate a breach likely to result in a high risk to a data subject's rights and freedoms to that data subject, in writing or electronically, after becoming aware of it, but sets no separate deadline for that communication, and excuses it where the data was already protected by measures such as encryption, the high risk is no longer likely to materialize, or an equally effective public communication was made instead; the supervisory authority may still require the communication to be made.

What it requires

Comprehensive regime

Law relating to the Protection of Personal Data and Privacy

Law N° 58/2021, arts. 1-8, 13-17, 29-41, 46-47 and 51-52, relating to the Protection of Personal Data and PrivacyLaw relating to the Protection of Personal Data and Privacy, RwandaLII (Official Gazette special of 15 October 2021)

In force since 15 October 2021. Binds public and private bodies.

What this law does

Article 2 applies the Law to processing personal data by electronic or other means, including through a non-automated platform, by a data controller, data processor or third party established or residing in Rwanda, and to any such person outside Rwanda who processes the personal data of a data subject located in Rwanda.

Article 4 requires a written contract between a data controller and a data processor before the processor may process personal data on the controller's behalf, and article 46 lists eight grounds, led by consent, on which processing personal data is lawful.

Article 6 requires the data subject's consent to be demonstrated where consent is the ground for processing, requires that consent to follow the data subject's free and informed decision, and permits it in oral, written or electronic form, and article 8 lets the data subject withdraw consent at any time without affecting the lawfulness of processing carried out before the withdrawal.

Article 13 relieves a controller or processor of any duty to acquire identifying information solely to comply with this Law where its processing purpose does not require identification, and articles 14 and 15 require personal data collected from someone other than the data subject to meet one of four listed grounds and require all personal data to be kept complete, accurate, current and not misleading.

Articles 16 and 17 require the data controller or processor to log data collection, alteration, access, disclosure, combination and erasure, and to maintain a record of all processing activities, both producible to the supervisory authority on request.

Articles 29 to 36 require registration as a data controller or data processor with the supervisory authority before processing personal data, govern the registration certificate's issuance, renewal, modification and cancellation, and require the supervisory authority to keep a public register.

Article 37 carries the lawfulness, purpose limitation, accuracy and storage limitation principles, article 38 requires appropriate technical and organisational measures, a record of processing, and a data protection impact assessment before high-risk processing such as large-scale processing of sensitive personal data or systematic monitoring of a publicly accessible area, and article 39 requires a data controller or processor with no establishment or residence in Rwanda to designate a representative there.

Article 40 requires designation of a data protection officer where the controller or processor is a public or private corporate body, carries out large-scale systematic monitoring, or processes sensitive personal data or criminal-conviction data on a large scale, and article 41 sets the officer's duties. Article 47 requires appropriate technical measures against loss, damage or destruction of personal data, regularly verified and kept updated against new risks.

Article 52 limits retention of personal data to the purpose for which it was collected unless a listed ground, such as a legal obligation, a court order or the data subject's consent, extends it, and requires destruction in a manner that prevents reconstruction once the retention period ends.

What it requires

Cross border transfer

Law relating to the Protection of Personal Data and Privacy, cross-border transfer and data storage

Law N° 58/2021, arts. 48-50 (cross-border transfer and data localisation)Law relating to the Protection of Personal Data and Privacy, RwandaLII (Official Gazette special of 15 October 2021)

In force since 15 October 2021. Binds public and private bodies.

What this law does

Article 48 permits a data controller or data processor to share or transfer personal data to a third party outside Rwanda only on a listed ground: the supervisory authority's authorisation with proof of appropriate safeguards, the data subject's consent, contractual necessity, public interest, the establishment or defence of a legal claim, protecting a vital interest, the controller's or processor's own compelling legitimate interests where the transfer is not repetitive and safeguards have been assessed, or performance of an international instrument Rwanda has ratified.

Article 49 requires a written contract with anyone authorised to access, share or transfer personal data outside Rwanda, and lets the supervisory authority demand proof of compliance or prohibit or suspend a transfer to protect data subjects' rights. Article 50 requires personal data to be stored in Rwanda, permitting storage abroad only where the controller or processor holds a valid registration certificate from the supervisory authority authorising it.

What it requires

Data subject rights

Law relating to the Protection of Personal Data and Privacy, rights of the data subject

Law N° 58/2021, arts. 18-26 and 42 (rights of the data subject and the information notice)Law relating to the Protection of Personal Data and Privacy, RwandaLII (Official Gazette special of 15 October 2021)

In force since 15 October 2021. Binds public and private bodies.

What this law does

Articles 18 to 26 give the data subject rights of access, objection, portability, rectification, erasure, restriction of processing, and, at article 21, the right not to be subject to a decision based solely on automated personal data processing, including profiling, that may produce legal or other significant consequences for them, subject to listed exceptions including the data subject's explicit consent, contract necessity, or an authorising law with safeguards.

Article 22 lets the data subject or the supervisory authority restrict processing while accuracy, lawfulness, or an objection is being resolved, article 25 excludes personal data from succession except by will, and article 26 lets a minor, a person with a physical or mental impairment, or anyone else designate a representative to exercise these rights.

A data subject dissatisfied with a controller's or processor's response to an objection, portability, erasure, or rectification request may appeal to the supervisory authority within thirty days, which must answer the appeal within sixty days.

Article 42 requires the data controller, when collecting personal data, to give the data subject an information notice covering identity and contact details, the purposes and recipients of processing, whether provision of the data is mandatory, the existence and consequences of automated decision making, the retention period, and the rights this Law gives the data subject, including the right to withdraw consent and to appeal to the supervisory authority.

What it requires

Enforcement supervision

Law relating to the Protection of Personal Data and Privacy, supervisory authority, penalties and offences

Law N° 58/2021, arts. 27-28 and 53-65 (supervisory authority, penalties, offences and compensation)Law relating to the Protection of Personal Data and Privacy, RwandaLII (Official Gazette special of 15 October 2021)

In force since 15 October 2021. Binds public and private bodies.

What this law does

Article 27 tasks the supervisory authority with overseeing the Law's implementation, responding to requests for an opinion, informing data subjects, controllers, processors and third parties of their rights and obligations, keeping the register of data controllers and processors, investigating and deciding complaints, and cooperating with domestic and foreign counterparts, and article 28 gives it the power to issue registration certificates, ensure compliance, protect public freedoms and privacy from information and communication technologies, make regulations, and impose administrative sanctions.

Article 53 sets an administrative fine, for an individual, of between two million and five million Rwandan francs or one percent of the preceding financial year's global turnover for listed misconducts including failure to maintain records, log processing, register, report a certificate change, designate a data protection officer, or notify, report or communicate a breach, and one percent of global turnover alone for a corporate body or legal entity, with article 54 letting anyone dissatisfied with an administrative sanction apply to the competent court and article 55 depositing the fine with the Public Treasury.

Articles 56 to 61 create separate criminal offences, each with its own imprisonment and fine range, for unlawfully accessing, using, sharing, transferring or disclosing personal data, re-identifying de-identified data, destroying, erasing, concealing or altering data, selling data, unlawfully collecting or processing sensitive personal data, and providing false registration information, article 62 fines a corporate body or legal entity convicted of any of those offences five percent of its preceding financial year's annual turnover, and article 63 lets the court order seizure or confiscation of items and proceeds and the permanent or temporary closure of the offending entity or premises.

Article 64 makes the supervisory authority the organ that settles conflicts arising under this Law in the first instance, subject to a party's right to take an unresolved conflict to a competent court, and article 65 gives a person who suffers serious damage from a controller's or processor's violation of this Law the right to claim compensation before a competent court, unless the controller or processor proves it was not responsible for the damage.

What it requires

Sensitive categories

Law relating to the Protection of Personal Data and Privacy, sensitive personal data and children's data

Law N° 58/2021, arts. 9-12 (sensitive personal data, children's data and criminal records)Law relating to the Protection of Personal Data and Privacy, RwandaLII (Official Gazette special of 15 October 2021)

In force since 15 October 2021. Binds public and private bodies.

What this law does

Article 9 requires the consent of a holder of parental responsibility before processing personal data belonging to a child under sixteen, permits that consent only where given in the child's interest, and dispenses with it where processing is necessary to protect the child's vital interest.

Article 10 permits processing sensitive personal data, defined at article 3 to include race, health status, criminal records, medical records, social origin, religious or philosophical beliefs, political opinion, genetic or biometric information, sexual life and family details, only on the data subject's consent, the controller's or processor's legal obligations, a vital interest, public health, or archiving, scientific, historical or statistical purposes.

Article 11 layers safeguards onto that processing: compliance with the sensitive-data retention periods this Law sets, staff-capacity building, controls on who may access it, and technical and organisational measures appropriate to the risk, including storing it separately from other data and applying tokenisation, pseudonymisation or encryption.

Article 12 places processing personal data of a convict, whose criminal record is itself a category of sensitive personal data, under the supervisory authority's supervision, and requires safeguards for that data subject's rights and freedoms.

What it requires

Scraping law1 instrument, 1 in force

Research summary (304 words)

Rwanda has no scraping-specific statute, so general law governs each dimension separately.

The Law on Prevention and Punishment of Cybercrimes, 2018 criminalises unauthorised access to computer or computer system data, and unlike a security-measure-triggered offence, its own three grounds turn on lacking consent, lacking entitlement to control or access, or accessing another person's computer system without authorisation, none of which require defeating a technical access control, so whether reading a public, unauthenticated page falls inside or outside the provision has not been tested in a reported Rwandan case.

No Rwandan court has ruled on the enforceability of a browsewrap or clickwrap terms of service against a scraper.

The Law on the Protection of Intellectual Property, 2009 permits free reproduction in the form of quotation of a short part of a published work, compatible with fair practice and not exceeding the extent justified by the purpose, and separately excludes published daily news from copyright protection outright, but Rwanda has not enacted a text-and-data-mining exception, so training a model on scraped copyrighted text rests only on the quotation exception if the reproduction can be characterised as a short, fair-practice quotation.

The same Law defines an act of unfair competition broadly, as any act or practice which, in the exercise of industrial or commercial activities, is unlawful or contrary to honest use, but confers no sui generis database right, and no located case law applies the unfair-competition definition to data scraping.

The Law relating to the Protection of Personal Data and Privacy, 2021 applies to personal data without a general carve-out for information the data subject has made public, so scraping personal data from a public Rwandan website remains subject to the Law's lawful-basis, purpose-limitation, registration, and cross-border-transfer duties. No Rwandan statute or reported case assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Law on Prevention and Punishment of Cybercrimes, unauthorized access

Law N° 60/2018 of 25/09/2018 on Prevention and Punishment of Cyber Crimes art. 16 (Unauthorized access to a computer or a computer system data)official Law text, RwandaLII (Official Gazette special of 25 September 2018)

In force since 25 September 2018. Binds public and private bodies.

What this law does

Article 16 makes it an offence for a person to intentionally and unlawfully get access to computer or computer system data where the person does not have consent from someone entitled to give it, is not entitled to control or access the data, or accesses another person's computer system without authorization to know recorded or transmitted data, by any means and regardless of location. The offence carries imprisonment of six months to two years and a fine of RWF 1,000,000 to 2,000,000.

None of article 16's three grounds requires infringing a technical security measure; each turns instead on the absence of consent, entitlement, or authorization.

What it requires

Age gating law1 instrument, 1 in force

Research summary (244 words)

Rwanda has no adult-content age-verification statute, no social-media minor-access restriction, and no app-store age-verification requirement, but it does have an age-appropriate design duty. The Ministry of Information, Communication, Technology and Innovation issued Ministerial Instructions N° 001/MINICT/2024 of 22/01/2024 on Child Online Protection, in force since their publication in the Official Gazette on 23 January 2024.

The instructions bind any person or organisation that broadcasts or provides content online or provides access to online content, a scope reaching general-purpose digital content providers and internet service providers rather than only services aimed at children, and require them to put in place a mechanism to prevent children from accessing age-inappropriate content, sites, products, or interactive services, and to label content for suitability for children.

Separately, Law N° 71/2018 of 31/08/2018 relating to the Protection of the Child criminalises showing a child pornographic images or sounds, recording a child's pornographic picture or voice, and advertising children's pornographic images, but those provisions bind the person who commits those acts rather than imposing an age-verification or age-gating duty on a service.

In April 2026 the Minister of ICT and Innovation said a draft law under review would bar children under sixteen from major social media and video-sharing platforms and would draw on Rwanda's national digital identity system for age verification; as of this review no such bill had been published in the Official Gazette or otherwise located as an official text, so it does not appear as an instrument here.

Age-appropriate design code

Ministerial Instructions on Child Online Protection

Ministerial Instructions N° 001/MINICT/2024 of 22/01/2024 on Child Online ProtectionMinisterial Instructions N° 001/MINICT/2024 of 22/01/2024 on Child Online Protection

In force since 23 January 2024. Binds public and private bodies.

What this law does

Article 3 applies these instructions to any person or organisation that broadcasts or provides content online or provides access to online content, a scope not confined to services aimed at children or to social media platforms.

Article 4 requires digital content providers and retailers to make available digital content filtering tools, maintain plans to manage harmful online content, provide a reporting function for users, give a clear external label describing whether platform content is suitable for children, and put in place a mechanism to prevent children from accessing age-inappropriate content, sites, products, or interactive services.

Article 5 requires internet service providers to inform subscribers of risks to children, support reporting of child abuse, block access to child-abuse material once identified, and make parental-control tools available where applicable. Article 6 requires cybercafes and public Wi-Fi providers in public places to proactively block access to sites known for hosting content harmful to children.

Article 7 requires broadcasters and television service providers to indicate the suitability of content for various age categories. It also requires them to implement technical barriers, including parental controls and age-verification tools, so that children are not exposed to harmful content.

Article 8 requires social media users to self-regulate by refraining from creating or publishing videos of child actors in age-inappropriate roles, and from creating or publishing children's images or videos for entertainment or commercial purposes without the consent of a holder of parental responsibility.

The instructions themselves do not define the term child; they are issued pursuant to Law N° 71/2018 relating to the Protection of the Child, which defines a child as any person under eighteen years of age.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (262 words)

Rwanda has no press-publisher neighbouring right, no mandatory platform-to-publisher bargaining code, no recognized hot-news misappropriation doctrine distinct from ordinary copyright law, and no located statute or case law addressing hyperlinking or framing liability specifically; each of those dimensions is a sourced absence rather than an unresolved question.

The relevant instrument is the Law on the Protection of Intellectual Property, 2009, which excludes published daily news and news communicated to the public from copyright protection outright (art. 198), so a bare news item is never a protected work under Rwandan law regardless of who first reported it.

The same Law lets a person reproduce, in a newspaper or periodical, or broadcast or otherwise communicate to the public, an article on current economic, political, or religious topics published in a newspaper or periodical, or a broadcast work of the same character, without the author's authorization and without payment, where the right to reproduction, broadcasting, or communication to the public has not been expressly reserved (art. 209, item 1); it separately permits free reproduction in the form of quotation of a short part of a published work, subject to a fair-practice and extent-justified test and an obligation to indicate the source and author (art. 205).

Neither exception is capped at a headline-length threshold beyond that fair-practice test, and no reported Rwandan decision applies either to a systematic news aggregator's reproduction of headlines and snippets, as opposed to a newspaper's own press review or current-events reporting. The Law predates the concept of a machine-readable text-and-data-mining reservation entirely, so no opt-out mechanism of that kind exists either.

Snippet reproduction

Law on the Protection of Intellectual Property, news exclusion and informatory-use and quotation exceptions

Law N° 31/2009 of 26/10/2009 on the Protection of Intellectual Property, arts. 198, 205, 209Law N° 31/2009 of 26/10/2009 on the Protection of Intellectual Property, full text as republished by WIPO Lex

In force since 14 December 2009. Binds public and private bodies.

What this law does

Article 198 excludes published daily news or news communicated to the public, official legislative, administrative, or judiciary texts, and mere ideas, procedures, systems, methods, concepts, principles, or discoveries from copyright protection: a bare news item is never a protected work under Rwandan law, whichever outlet reports it first.

Article 209 separately permits, without the author's authorization and without payment of remuneration, subject to indicating the source and the author's name as far as practicable: the reproduction in a newspaper or periodical, or the broadcasting or other communication to the public, of an article published in a newspaper or periodical on current economic, political, or religious topics, or a broadcast work of the same character, where the right to reproduction, broadcasting, or communication to the public is not expressly reserved; the reproduction or communication to the public, for the purpose of reporting short current events, of a work seen or heard in the course of those events, to the extent justified by the informatory purpose; and the reproduction, broadcasting, or communication to the public of a political speech, lecture, address, sermon, or similar public address, or a speech delivered during legal proceedings, to the extent justified by the purpose of providing current information.

Article 205 separately permits free reproduction in the form of quotation of a short part of a published work, without authorization or payment, provided the reproduction is compatible with fair practice and does not exceed the extent justified by the purpose, and is accompanied by an indication of source and the author's name where it appears in the work quoted.

None of these three provisions is capped at a headline-length threshold distinct from the fair-practice and informatory-purpose tests they each already carry.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.