Rwanda’s law on the protection of personal data and privacy (DPP Law)

DPP Law Table of contents

Art. 53

Administrative misconducts

The data controller, the data processor or a third party who commits one of the following misconducts:

  1. failure to maintain records of processed personal data;
  2. failure to carry out personal data logging;
  3. operating without a registration certificate;
  4. failure to report a change after receiving a registration certificate;
  5. using a certificate whose term of validity has expired;
  6. failure to designate a personal data protection officer;
  7. failure to notify a personal data breach;
  8. failure to make a report on personal data breach;
  9. failure to communicate a personal data breach to the data subject;

commits a misconduct

He or she is liable to an administrative fine of not less than two million Rwandan francs (RWF 2,000,000) but not more than five million Rwandan francs (RWF 5,000,000) or one percent (1%) of the global turnover of the preceding financial year.

In the event of a corporate body or a legal entity, he or she is liable to one percent (1%) of the global turnover of the preceding financial year.

The supervisory authority may put in place a regulation determining other administrative misconducts and sanctions that are not provided for in this Law.