Countries, Articles, Insights, Rwanda

Renewal of Data Controller and Data Processor Certificates Under Rwanda’s Data Protection Law

Introduction

Rwanda has established a modern legal framework for personal data protection through Law No. 058/2021 relating to the Protection of Personal Data and Privacy (“Data Protection Law”). Under this law, data controllers and data processors must register and obtain certification before processing personal data. Certification must be periodically renewed to ensure continued compliance.

Legal framework

The law requires both data controllers (entities determining purposes and means of processing) and data processors (entities processing on behalf of controllers) to be registered with the National Cyber Security Authority (NCSA). The NCSA is responsible for issuing, renewing, suspending and revoking certificates.

Validity and renewal

The Data Protection law, Article 33 provides that the data controller or the data processor who holds a registration certificate may apply for its renewal within forty-five (45) working days before the expiry date of the existing certificate.

Certificates are valid for a limited period and must be renewed before expiry. Renewal is triggered by expiration or major changes in processing activities. Failure to renew may result in penalties or suspension of processing activities.

Renewal Process

The following documents are required for the renewal application to the NCSA:

  1. Application letter addressed to the Chief Executive Officer of NCSA
  2. Certificate of incorporation
  3. License from Regulator (if applicable) e.g. license issued by RURA, MINICOM
  4. Legal instrument establishing the entity (in case of public entity)
  5. Data Processing Contracts between Data Controller and Data Processor(s)
  6. Contract with the representative (only for those Data Controllers/ Data Processors that are neither established nor reside in Rwanda but process personal data of Data Subjects located in Rwanda)
  7. Filled Compliance checklist form
  8. Compliance Roadmap
  9. Any other supporting document

The NCSA will conduct a compliance review and thereafter issue a renewed certificate upon approval.

Key Compliance Requirements

Companies and Organizations must demonstrate strong data governance, effective security controls, proper record-keeping, respect for data subject rights, and proper management of third-party processors.

Consequences of non-renewal

Failure to renew certification can lead to administrative penalties, operational disruptions, reputational damage, and increased regulatory scrutiny.

A corporate body or legal entity found to non-compliant with the Data Protection Law is,  upon conviction, liable to a fine of Rwandan francs amounting to five percent (5%) of its annual turnover of the previous financial year.

How Adili Rwanda Can Assist

Adili Rwanda provides comprehensive support to organizations seeking to obtain or renew data controller and data processor certificates. Our services include:

  • – Conducting data protection compliance audits
  • – Preparing and reviewing documentation required for renewal
  • – Developing data protection policies and frameworks
  • – Offering staff training and awareness programs
  • – Advising on technical and organizational security measures
  • – Supporting engagement with the NCSA during the renewal process
  • – Providing ongoing compliance monitoring and advisory services

Recent insights