RWANDA-1 | Scope, Lawful Basis, Principles | 0 |
RWANDA-2 | Consent, Notice, Sensitive Data | 0 |
RWANDA-3 | Data Subject Rights | 0 |
RWANDA-4 | Children, DPIA, Privacy by Design | 0 |
RWANDA-5 | Security of Processing | 0 |
RWANDA-6 | Cross-Border Transfer | 0 |
RWANDA-7 | Registration with NCSA, DPO Appointment, Governance | 0 |
RWANDA-8 | Breach Notification, NCSA Cooperation, Enforcement | 0 |
1-3 | Purpose, scope and definitions | 0 |
10 | Grounds for processing sensitive personal data | 0 |
11 | Safeguards when processing sensitive personal data | 0 |
12 | Processing personal data of a convict | 0 |
13 | Processing that does not require identification of the data subject | 0 |
14 | Source of personal data | 0 |
15 | Quality of personal data | 0 |
16 | Personal data logging | 0 |
17 | Records of processing activities | 0 |
18 | Right of access | 0 |
19 | Right to object, including to direct marketing | 0 |
20 | Right to data portability | 0 |
21 | Right not to be subject to solely automated decisions | 0 |
22 | Right to restriction of processing | 0 |
23 | Right to erasure | 0 |
24 | Right to rectification | 0 |
25-26 | Heirs to personal data and representation of the data subject | 0 |
27-28 | Duties and powers of the supervisory authority | 0 |
29-30 | Registration as a data controller or data processor | 0 |
31 | Issuance of a registration certificate | 0 |
32-35 | Registration certificate lifecycle: changes, renewal, modification and cancellation | 0 |
36 | Register of data controllers and data processors | 0 |
37 | Principles relating to processing of personal data | 0 |
38 | Duties of controller and processor: measures, records and data protection impact assessments | 0 |
39 | Representative in Rwanda for foreign controllers and processors | 0 |
4 | Processor contract and controller authorisation | 0 |
40 | Designation of the data protection officer | 0 |
41 | Duties of the data protection officer | 0 |
42 | Lawful purpose of collection and information to be provided at collection | 0 |
43 | Notification of a personal data breach within 48 hours | 0 |
44 | Breach report to the supervisory authority within 72 hours | 0 |
45 | Communication of a breach to the data subject | 0 |
46 | Lawful grounds for processing | 0 |
47 | Measures to ensure security of personal data | 0 |
48 | Sharing and transfer of personal data outside Rwanda | 0 |
49 | Contract for transfer of personal data outside Rwanda | 0 |
5 | Processing that does not infringe the data subject's privacy | 0 |
50 | Storage of personal data in Rwanda | 0 |
51 | Migration and management of personal data after change or closure of business | 0 |
52 | Retention and destruction of personal data | 0 |
53-55 | Administrative misconducts and sanctions | 0 |
56-63 | Offences and penalties | 0 |
6-7 | Valid consent and declarations of consent | 0 |
64-70 | Settlement of conflicts, compensation, regulations, transitional period and commencement | 0 |
8 | Right to withdraw consent | 0 |
9 | Children's personal data: parental consent | 0 |
REG | NCSA regulations and compliance tools under the Law | 0 |