Rwanda’s law on the protection of personal data and privacy (DPP Law)

DPP Law Table of contents

Art. 30

Requirements for registration as a data controller or a data processor

An applicant for registration as a data controller or a data processor must indicate the following:

  1. his or her identity and his or her designated single point of contact;
  2. the identity and address of his or her representative if he or she has nominated any;
  3. a description of personal data to be processed and the category of data subjects;
  4. whether or not the applicant holds or is likely to hold the types of personal data based on the sectors in which it operates;
  5. the purposes of the processing of personal data;
  6. the categories of recipients to whom the data controller or the data processor intends to disclose the personal data;
  7. the country to which the applicant intends to directly or indirectly transfer the personal data;
  8. risks in the processing of personal data and measures to prevent such risks and protect personal data.

The supervisory authority may put in place a regulation determining additional requirements to be met by an applicant for registration as a data controller or a data processor.