Rwanda’s law on the protection of personal data and privacy (DPP Law)

DPP Law Table of contents

Art. 38

Duties of the data controller and the data processor

In compliance with the principles of the processing of personal data, the data controller and the data processor discharge the following duties:

  1. to implement appropriate technical and organisational measures;
  2. to keep a record of personal data processing operations;
  3. to carry out personal data protection impact assessments where the processing of personal data is likely to result in a high risk to the rights and freedoms of a natural person;
  4. to perform such other duty as may be assigned to him or her by the supervisory authority

The personal data protection impact assessment referred to in item 3o of Paragraph one of this Article is carried out in case of:

  1. a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing of personal data, including profiling, and on which decisions that produce effects concerning such persons are based;
  2. processing on a large scale of sensitive personal data;
  3. a systematic monitoring of a publicly accessible area on a large scale;
  4. processing of personal data identified by the supervisory authority as likely to result in a high risk to the rights and freedoms of natural persons;
  5. new technologies used to process personal data.