Rwanda's data protection law: awareness, training & human risk
If your organisation processes personal data in Rwanda, Law No. 058/2021 relating to the protection of personal data and privacy applies to you as a data controller or data processor — under the supervision of the National Cyber Security Authority (NCSA). Rwanda's law is one of the stricter regimes on the continent, and nowhere more so than on incident timelines: the breach notification window is forty-eight hours, not seventy-two. A window that tight is won or lost by the first employee who notices something wrong. This page explains what the law expects on the human side of security, and how AfriPhish helps you evidence it.
What Law No. 058/2021 requires on staff awareness and human risk
The law never uses the phrase "security awareness programme". What it imposes instead is a set of duties that an untrained workforce makes impossible to meet.
Registration with the supervisory authority. Data controllers and processors must register with the NCSA before processing personal data. Registration commits you, on the record, to processing data lawfully and securely — and it gives the supervisory authority a standing basis to ask how your declared safeguards work in practice.
Security and confidentiality of processing. The law obliges controllers and processors to implement appropriate technical and organisational measures to safeguard personal data against loss, unauthorised access, disclosure and unlawful processing, and to ensure that persons acting under their authority process data only as instructed and keep it confidential. Organisational measures are, by definition, about people: an employee who reuses passwords, clicks a credential-harvesting link or forwards a spreadsheet to the wrong recipient defeats every technical control behind them. Training that is documented, tested and refreshed is how an organisational measure becomes demonstrable.
48-hour breach notification. Where a personal data breach occurs, the data controller must notify the supervisory authority within forty-eight hours of becoming aware of it, and a processor must inform its controller on the same tight timeline. Forty-eight hours leaves no slack for an employee who deletes a suspicious email and mentions it days later. The single biggest lever on breach-notification readiness is a workforce that recognises an attack and knows exactly where to report it — immediately.
Designation of a Data Protection Officer. The law requires controllers and processors meeting its criteria to designate a Data Protection Officer to monitor compliance and act as the contact point with the NCSA. In practice, the DPO is the person who will be asked to demonstrate that staff-facing safeguards are real — and who needs records, not recollections, to answer.
The obligations AfriPhish helps you evidence
AfriPhish is built around a simple principle: every awareness activity should leave an audit trail. Here is how the platform maps to the law's expectations.
| Law No. 058/2021 expectation | AfriPhish module | Evidence produced |
|---|---|---|
| Organisational security measures | Security awareness training in English, French and Arabic | Per-user completion records, quiz scores, assignment dates |
| Safeguards demonstrably effective | Phishing simulations across realistic scenario families | Click, credential-submission and report rates, trended per campaign |
| Risk identification and follow-up | Human risk scoring | A per-user and per-department risk score that moves with behaviour |
| Confidentiality and instructed processing | Policy management with e-signature attestation | Versioned, timestamped signature registers showing who acknowledged what |
| 48-hour notification readiness | Simulation reporting behaviour and real-time coaching | Records of who reports suspicious mail — and how fast — with targeted coaching for those who do not |
| DPO compliance monitoring | Reports and analytics | Exportable programme reports covering the whole awareness cycle |
Because training completion, simulation outcomes and policy signatures live in one platform, your DPO answers "show me your organisational measures" with a report, not a reconstruction — and your incident-response plan rests on employees who have practised reporting, not just read about it.
What auditors and the NCSA typically ask for
When the supervisory authority, an external auditor or an enterprise customer probes your human safeguards, the requests are predictable:
- Training logs — who was assigned which module, who completed it, when, and with what assessment result.
- A policy attestation register — which version of your data protection or acceptable-use policy each employee signed, with timestamps.
- Simulation trend reports — evidence that you test staff against realistic phishing and that failure rates are measured and falling, not guessed at.
- Reporting-channel records — proof that employees escalate suspected breaches fast enough to make a 48-hour notification window realistic.
- Coverage of new joiners — evidence that awareness is continuous, not a one-off induction slide deck.
Every one of these artefacts is a standard export from AfriPhish. None needs to be assembled by hand the week before an audit.
See where your organisation stands
Before you build or buy anything, measure. Take the free 4-minute Human Risk Maturity Assessment — it benchmarks your current awareness programme against what Rwanda's security and notification duties imply, and tells you exactly where the gaps are.
Prefer to talk it through? Book a demo and we will walk through your Law No. 058/2021 evidence file together.