Rwanda Law No. 058/2021 Relating to the Protection of Personal Data
Rwanda's Law No. 058/2021 Relating to the Protection of Personal Data and Privacy establishes a comprehensive data protection framework. The National Cyber Security Authority (NCSA) serves as the data protection authority. The law establishes processing principles, data subject rights, controller and processor obligations, and provisions for cross-border transfers. Effective from October 2021.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (26)
Accountability
| Code | Title |
|---|---|
| RW058-ART32 | Records of Processing Activities |
Assurance
| Code | Title |
|---|---|
| RW058-ART53 | Codes of Conduct and Certification |
Awareness
| Code | Title |
|---|---|
| RW058-ART52 | Training and Awareness |
Chapter I - General Provisions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 6 | Writing |
Chapter II - Processing and Quality of Personal Data
| Code | Title |
|---|---|
| Art. 10 | Data and Data Governance |
| Art. 15 | Accuracy, Robustness and Cybersecurity |
| Art. 17 | Quality Management System |
| Art. 4 | Participating Institutions |
| Art. 6 | Writing |
| Art. 9 | Risk Management System |
Chapter III - Rights of the Data Subject
Rights of individuals whose data is processed
| Code | Title |
|---|---|
| Art. 18 | Documentation Keeping |
| Art. 19 | Automatically Generated Logs |
| Art. 20 | Corrective Actions and Duty of Information |
| Art. 21 | Cooperation with Competent Authorities |
| Art. 23 | Transitional Provisions |
| Art. 24 | Restrictions on Processing Unique Identification Information |
| GDPR-Art.12 | Transparent information, communication and modalities for rights |
| GDPR-Art.13 | Information to be provided where personal data are collected |
| GDPR-Art.14 | Information where personal data have not been obtained from the data subject |
| GDPR-Art.15 | Right of access by the data subject |
| GDPR-Art.16 | Right to rectification |
| GDPR-Art.17 | Right to erasure (right to be forgotten) |
| GDPR-Art.18 | Right to restriction of processing |
| GDPR-Art.19 | Notification obligation regarding rectification, erasure or restriction |
| GDPR-Art.20 | Right to data portability |
| GDPR-Art.21 | Right to object |
| GDPR-Art.22 | Automated individual decision-making, including profiling |
Chapter V - Registration of Data Controller and Processor
| Code | Title |
|---|---|
| Art. 29 | Application of a Conformity Assessment Body for Notification |
| Art. 30 | Privacy Policy |
| Art. 35 | Right of Access |
Chapter VI - Obligations of Data Controller and Processor
| Code | Title |
|---|---|
| Art. 37 | Right to Suspension of Processing |
| Art. 40 | Establishment and Composition |
| Art. 43 | Mediation of Disputes |
| Art. 47 | Existing Legal Procedures |
| Art. 48 | Criminal Penalties |
Chapter VIII - Misconducts, Offences and Sanctions
| Code | Title |
|---|---|
| Art. 53 | Obligations for Providers of General-Purpose AI Models |
| Art. 56 | Data Breach Notification |
| Art. 59 | Entry into Force |
| Art. 63 | Interim Measures |
Children
| Code | Title |
|---|---|
| RW058-ART09 | Children's Data |
Complaints
| Code | Title |
|---|---|
| RW058-ART51 | Whistleblowing and Internal Complaints |
Consent
| Code | Title |
|---|---|
| RW058-ART06 | Consent Requirements |
Enforcement
| Code | Title |
|---|---|
| RW058-ART45 | Sanctions and Administrative Fines |
Governance
| Code | Title |
|---|---|
| RW058-ART29 | Data Protection Officer |
Incident Response
| Code | Title |
|---|---|
| RW058-ART34 | Personal Data Breach Notification |
International Transfers
| Code | Title |
|---|---|
| RW058-ART37 | Cross-Border Data Transfers |
Lawfulness
| Code | Title |
|---|---|
| RW058-ART05 | Lawful Basis for Processing |
Marketing
| Code | Title |
|---|---|
| RW058-ART41 | Direct Marketing and Profiling |
Registration
| Code | Title |
|---|---|
| RW058-ART11 | Registration of Data Controllers and Processors |
Rights
| Code | Title |
|---|---|
| RW058-ART20 | Data Subject Rights |
Risk Management
| Code | Title |
|---|---|
| RW058-ART36 | Data Protection Impact Assessment |
Scope
| Code | Title |
|---|---|
| RW058-ART04 | Scope and Territorial Application |
Security
| Code | Title |
|---|---|
| RW058-ART33 | Security of Processing |
Sensitive Data
| Code | Title |
|---|---|
| RW058-ART08 | Special Categories of Personal Data |
Transparency
| Code | Title |
|---|---|
| RW058-ART14 | Privacy Notice and Transparency |
Vendor Management
| Code | Title |
|---|---|
| RW058-ART40 | Processor Obligations and Contracts |
Your Compliance Coverage
If you comply with Rwanda Law No. 058/2021 Relating to the Protection of Personal Data, you already cover:
Australia Consumer Data Right — Banking (CDR)
33%
19 controls mapped
Compare →BS 65000:2014 — Guidance on Organizational Resilience
31%
18 controls mapped
Compare →EU AI Act
31%
18 controls mapped
Compare →+ 637 more: Chile Personal Data Protection Law (Law No. 21.719) (31%), Turkey Personal Data Protection Law (KVKK — Law No. 6698) (31%)
See all 640 mapped frameworks ↓Maps to 640 other frameworks
Frequently Asked Questions
What is Rwanda Law No. 058/2021 Relating to the Protection of Personal Data?
Rwanda Law No. 058/2021 Relating to the Protection of Personal Data is a compliance framework from Rwanda with 26 domains and 60 controls. Rwanda's Law No. 058/2021 Relating to the Protection of Personal Data and Privacy establishes a comprehensive data protection framework. The National Cyber Security Authority (NCSA) serves as the data protection authority. The law establishes processing principles, data subject rights, controller and processor obligations, and provisions for cross-border transfers. Effective from October 2021. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Rwanda Law No. 058/2021 Relating to the Protection of Personal Data have?
Rwanda Law No. 058/2021 Relating to the Protection of Personal Data has 60 controls organised across 26 domains. The largest domains are Chapter III - Rights of the Data Subject (17 controls), Chapter II - Processing and Quality of Personal Data (6 controls), Chapter I - General Provisions (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Rwanda Law No. 058/2021 Relating to the Protection of Personal Data map to?
Rwanda Law No. 058/2021 Relating to the Protection of Personal Data maps to 640 other compliance frameworks. The top mapping partners are Australia Consumer Data Right — Banking (CDR) (33% coverage), BS 65000:2014 — Guidance on Organizational Resilience (31% coverage), EU AI Act (31% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Rwanda Law No. 058/2021 Relating to the Protection of Personal Data compliance?
Start your Rwanda Law No. 058/2021 Relating to the Protection of Personal Data compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Rwanda Law No. 058/2021 Relating to the Protection of Personal Data requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 60 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required