Rwanda DPL

Rwanda's data law: NCSA registration, a 48-hour breach clock, and data stored in Rwanda by default.

Market regime · Law N° 058/2021 relating to the protection of personal data and privacy (Rwanda)

Issued by

Republic of Rwanda

Region

Rwanda

Effective

2021; NCSA supervision, registration enforced

Oversight

National Cyber Security Authority (NCSA)

Applies when

You process personal data of data subjects in Rwanda

In the catalog

Curated, versioned & cross-mapped

The obligation, plainly.

Rwanda's 2021 law is among Africa's strictest: controllers and processors register with the National Cyber Security Authority, breaches are notified within 48 hours, and personal data is stored in Rwanda unless the controller holds authorisation to host it abroad.

The 48-hour clock and the storage rule are the operational teeth, both tighter than the regional norm, and both exactly the kind of requirement that has to live in workflows and architecture decisions rather than policy documents.

Where programmes are tested.

01

NCSA registration

Controllers and processors registered before processing, and renewed.

02

The 48-hour breach clock

Breaches notified to the NCSA within 48 hours, the region's shortest general deadline.

03

Storage in Rwanda

Personal data hosted in Rwanda unless authorised otherwise, an architecture-level obligation.

Curated once, evidenced continuously.

  • The law is curated with its localisation and clock requirements explicit, cross-mapped to the shared privacy controls, with hosting posture treated as evidence, not assumption.
  • Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
  • Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
  • Every attestation carries maker/checker, and every action lands in an append-only audit trail.

Rwanda DPL, asked plainly.

The questions compliance teams actually ask before an adoption decision or an audit.

Is data localisation really required in Rwanda?

By default, yes: the law requires personal data to be stored in Rwanda unless the registration/authorisation permits hosting abroad. For cloud-first companies this is an architecture decision to make early, with the authorisation evidence kept current.

How short is the breach deadline?

48 hours to the NCSA, tighter than the 72-hour convention of GDPR-style laws. Detection-to-notification has to be a rehearsed workflow with the clock built in, which is exactly how the incident module models it.

Who is the regulator?

The National Cyber Security Authority, which is also Rwanda's cybersecurity agency, an unusual pairing that means privacy supervision sits next to technical security expertise, and filings go to a technically literate audience.

Where it connects.

The full catalog

Compliance you can prove.
Walk into your next audit ready.

Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.

The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.