Rwanda Law No. 058/2021 Relating to the Protection of Personal Data
Rwanda's Law No. 058/2021 Relating to the Protection of Personal Data and Privacy establishes a comprehensive data protection framework. The National Cyber Security Authority (NCSA) serves as the data protection authority. The law establishes processing principles, data subject rights, controller and processor obligations, and provisions for cross-border transfers. Effective from October 2021.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
Chapter I - General Provisions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 6 | Writing |
Chapter II - Processing and Quality of Personal Data
| Code | Title |
|---|---|
| Art. 10 | Consent Requirements |
| Art. 15 | Cybersecurity Requirements |
| Art. 17 | Governance Structure |
| Art. 4 | Participating Institutions |
| Art. 6 | Writing |
| Art. 9 | Free Data Sharing |
Chapter III - Rights of the Data Subject
Rights of individuals whose data is processed
| Code | Title |
|---|---|
| Art. 18 | Central Bank Supervision |
| Art. 19 | Consent Management Controls |
| Art. 20 | Executive Accountability |
| Art. 21 | Administrative Sanctions |
| Art. 23 | Transitional Provisions |
| Art. 24 | Restrictions on Processing Unique Identification Information |
| GDPR-Art.12 | Transparent information, communication and modalities for rights |
| GDPR-Art.13 | Information to be provided where personal data are collected |
| GDPR-Art.14 | Information where personal data have not been obtained from the data subject |
| GDPR-Art.15 | Right of access by the data subject |
| GDPR-Art.16 | Right to rectification |
| GDPR-Art.17 | Right to erasure (right to be forgotten) |
| GDPR-Art.18 | Right to restriction of processing |
| GDPR-Art.19 | Notification obligation regarding rectification, erasure or restriction |
| GDPR-Art.20 | Right to data portability |
| GDPR-Art.21 | Right to object |
| GDPR-Art.22 | Automated individual decision-making, including profiling |
Chapter V - Registration of Data Controller and Processor
| Code | Title |
|---|---|
| Art. 29 | Safety Measures |
| Art. 30 | Privacy Policy |
| Art. 35 | Right of Access |
Chapter VI - Obligations of Data Controller and Processor
| Code | Title |
|---|---|
| Art. 37 | Right to Suspension of Processing |
| Art. 40 | Establishment and Composition |
| Art. 43 | Mediation of Disputes |
| Art. 47 | Existing Legal Procedures |
| Art. 48 | Criminal Penalties |
Chapter VIII - Misconducts, Offences and Sanctions
| Code | Title |
|---|---|
| Art. 53 | Administrative Misconducts |
| Art. 56 | Data Breach Notification |
| Art. 59 | Entry into Force |
| Art. 63 | Interim Measures |
Maps to 616 other frameworks
Frequently Asked Questions
What is Rwanda Law No. 058/2021 Relating to the Protection of Personal Data?
Rwanda Law No. 058/2021 Relating to the Protection of Personal Data is a compliance framework from Rwanda with 6 domains and 40 controls. Rwanda's Law No. 058/2021 Relating to the Protection of Personal Data and Privacy establishes a comprehensive data protection framework. The National Cyber Security Authority (NCSA) serves as the data protection authority. The law establishes processing principles, data subject rights, controller and processor obligations, and provisions for cross-border transfers. Effective from October 2021. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Rwanda Law No. 058/2021 Relating to the Protection of Personal Data have?
Rwanda Law No. 058/2021 Relating to the Protection of Personal Data has 40 controls organised across 6 domains. The largest domains are Chapter III - Rights of the Data Subject (17 controls), Chapter II - Processing and Quality of Personal Data (6 controls), Chapter I - General Provisions (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Rwanda Law No. 058/2021 Relating to the Protection of Personal Data map to?
Rwanda Law No. 058/2021 Relating to the Protection of Personal Data maps to 616 other compliance frameworks. The top mapping partners are Australia Consumer Data Right — Banking (CDR) (50% coverage), BS 65000:2014 — Guidance on Organizational Resilience (47% coverage), Chile Personal Data Protection Law (Law No. 21.719) (47% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Rwanda Law No. 058/2021 Relating to the Protection of Personal Data compliance?
Start your Rwanda Law No. 058/2021 Relating to the Protection of Personal Data compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Rwanda Law No. 058/2021 Relating to the Protection of Personal Data requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 40 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required