Rwanda’s law on the protection of personal data and privacy (DPP Law)

DPP Law Table of contents

Art. 47

Measures to ensure security of personal data

The data controller or the data processor must ensure security of the personal data in his or her possession by, adopting appropriate, reasonable technical measures to prevent loss, damage or destruction of personal data.

For purposes of enforcing the provisions of Paragraph One of this Article, the data controller or the data processor takes the following measures to ensure security of personal data:

  1. identify foreseeable risks to personal data under that person’s possession or control, establish and maintain appropriate safeguards against those risks;
  2. regularly verify whether the personal data security safeguards are effectively implemented;
  3. ensure that the personal data security safeguards are continually updated in response to new risks or any identified deficiencies.

When the supervisory authority is of the opinion that processing or transferring personal data may infringe the rights and privacy of the data subject, the supervisory authority conducts an inspection and assessment of the measures set out in this Article.