Rwanda's Data Protection Law: A Practical Checklist for Every Website and App

Every contact form, customer database, booking system and mobile app collects personal data. In Rwanda, that data is regulated by Law No. 058/2021 of 13 October 2021 relating to the protection of personal data and privacy, which was gazetted on 15 October 2021. The National Cyber Security Authority (NCSA) is the supervisory authority.
Organisations that were already operating were given a transition period that ended on 15 October 2023, so this is no longer “something to prepare for”. It is something to have in place.
What the law expects from organisations
- Appoint a data protection officer to oversee compliance.
- Register with the NCSA as a data controller or data processor.
- Publish a privacy policy that explains what you collect and how you use it.
- Protect the data with appropriate technical measures against loss, damage or destruction.
- Get authorisation before transferring data outside Rwanda, which matters if your hosting, email or analytics tools are abroad.
A practical checklist for your website or app
- Know what you collect. List every form, login, analytics tool and database that touches personal data.
- Collect only what you need. If a contact form does not need a phone number or national ID, do not ask for it.
- Add a clear privacy policy and consent wording wherever people submit their details.
- Use HTTPS everywhere and keep software, plugins and servers up to date.
- Control access. Give staff only the access they need, use strong passwords and two-factor authentication, and remove accounts when people leave.
- Encrypt and back up. Store sensitive data encrypted, and keep tested backups in a separate location.
- Check your suppliers. Know where your host, email provider and payment or analytics tools store data.
- Have a plan for problems. Decide who does what if data is lost or exposed, and how you would notify the people affected.
A note on compliance
This article is a plain-language overview, not legal advice. For your specific situation, speak to a lawyer or contact the NCSA’s Data Protection and Privacy Office directly.
Where Enoveta fits in
Much of compliance is technical: secure hosting, encryption, access control, safe forms and regular security checks. Our team builds this into every project and offers dedicated cybersecurity services, from security audits to data protection. If you would like your website or system reviewed, get in touch.

