What Is Law No. 058/2021 of 13 October 2021 Relating to the Protection of Personal Data and Privacy?
Rwanda's Law No. 058/2021 of 13 October 2021, published in the Official Gazette special issue of 15 October 2021 (presented in Kinyarwanda, English, and French), designates the National Cyber Security Authority (NCSA) as supervisory authority, implemented operationally through the Data Protection & Privacy Office (DPO). The law took immediate effect, with a transition period to 15 October 2023 for organizations already processing personal data. The DPO's guidance lists rights to withdraw consent, access personal data, object (including to direct marketing, free of charge), data portability, avoid a decision based solely on automated processing, restrict processing, seek erasure, request rectification, and designate an heir. Erasure grounds include data no longer being necessary, withdrawn consent with no other legal ground, an unopposed objection, or unlawful processing, subject to public-interest and other statutory exceptions. A controller/processor must respond to an access or related-rights request within 30 days, and an unsatisfied person may appeal to the DPO within 30 days of that response. This is a source-backed evidence profile. The official Gazette text is trilingual (Kinyarwanda, English, French) with no explicit controlling-language clause located. No Rwanda-specific data-broker registry or public-record suppression route was located.
At a glance
- Full name
- Law No. 058/2021 of 13 October 2021 Relating to the Protection of Personal Data and Privacy
- Short code
- Rwanda Law 058/2021
- Jurisdiction
- Rwanda
- Enacted
- 2021
- Last major update
- Immediate effect from the 15 October 2021 Official Gazette special issue; organizations already processing data had until 15 October 2023 to complete the transition
- Regulator
- National Cyber Security Authority (NCSA), implemented through the Data Protection & Privacy Office (DPO)
- Private right of action
- Limited
- Statutory citation
- Law No. 058/2021 of 13 October 2021
Scope, who Rwanda Law 058/2021 covers
Protected data
Data subject rights
Withdraw consent
Access personal data, with a controller/processor response within 30 days
Object to processing, including a free objection to direct marketing and related profiling
Data portability
Avoid a decision based solely on automated processing
Restrict processing
Erasure on listed grounds (data no longer necessary, withdrawn consent, unopposed objection, or unlawful processing), subject to public-interest and other exceptions
Rectification, completed or refused with reasons within 30 days
Designate an heir for post-mortem representation
Notable features
The law’s Official Gazette publication presents Kinyarwanda, English, and French text together, reflecting Rwanda’s multilingual official-language structure, though no explicit controlling-language clause was located in this pass.
Enforcement & penalties
Penalties: The reviewed DPO FAQ and Official Gazette materials for this research pass focused on rights, request timelines, and the complaint route rather than a consolidated fine schedule; verify current sanction amounts before publication.
Private right of action: The DPO instructs a person to first contact the organization holding the data, then the DPO if unresolved, using a published complaint form sent to complaint@dpo.gov.rw (copying dpp@ncsa.gov.rw); an unsatisfied requester may appeal to the DPO within 30 days of the controller’s response.
Relevance to data brokers
No Rwanda-specific data-broker registry, opt-out directory, or general public-record suppression route was located. The located general route is a request to the relevant controller/processor, followed by a DPO complaint; whether a particular broker falls within scope and whether a public-record exception applies requires entity- and record-specific review.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
How do I access or correct my data held by a Rwandan controller?+
Send a letter or email to the organization or person holding the data invoking Law No. 058/2021; the DPO says a controller/processor must respond within 30 days.
How do I escalate a complaint in Rwanda if the controller does not resolve it?+
Send the DPO’s complaint form to complaint@dpo.gov.rw (copying dpp@ncsa.gov.rw) after first raising the issue with the organization holding your data.
Official sources & citations
Other international privacy regimes
Rwanda Law 058/2021 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
