Rwanda

Rwanda DPL

55 controls. 0 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

55 controls 0 frameworks share controls with it Rwanda verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

No measured overlap with another framework in the corpus.

Every control

CodeControlAlso in
RWANDA-1Scope, Lawful Basis, Principles0
RWANDA-2Consent, Notice, Sensitive Data0
RWANDA-3Data Subject Rights0
RWANDA-4Children, DPIA, Privacy by Design0
RWANDA-5Security of Processing0
RWANDA-6Cross-Border Transfer0
RWANDA-7Registration with NCSA, DPO Appointment, Governance0
RWANDA-8Breach Notification, NCSA Cooperation, Enforcement0
1-3Purpose, scope and definitions0
10Grounds for processing sensitive personal data0
11Safeguards when processing sensitive personal data0
12Processing personal data of a convict0
13Processing that does not require identification of the data subject0
14Source of personal data0
15Quality of personal data0
16Personal data logging0
17Records of processing activities0
18Right of access0
19Right to object, including to direct marketing0
20Right to data portability0
21Right not to be subject to solely automated decisions0
22Right to restriction of processing0
23Right to erasure0
24Right to rectification0
25-26Heirs to personal data and representation of the data subject0
27-28Duties and powers of the supervisory authority0
29-30Registration as a data controller or data processor0
31Issuance of a registration certificate0
32-35Registration certificate lifecycle: changes, renewal, modification and cancellation0
36Register of data controllers and data processors0
37Principles relating to processing of personal data0
38Duties of controller and processor: measures, records and data protection impact assessments0
39Representative in Rwanda for foreign controllers and processors0
4Processor contract and controller authorisation0
40Designation of the data protection officer0
41Duties of the data protection officer0
42Lawful purpose of collection and information to be provided at collection0
43Notification of a personal data breach within 48 hours0
44Breach report to the supervisory authority within 72 hours0
45Communication of a breach to the data subject0
46Lawful grounds for processing0
47Measures to ensure security of personal data0
48Sharing and transfer of personal data outside Rwanda0
49Contract for transfer of personal data outside Rwanda0
5Processing that does not infringe the data subject's privacy0
50Storage of personal data in Rwanda0
51Migration and management of personal data after change or closure of business0
52Retention and destruction of personal data0
53-55Administrative misconducts and sanctions0
56-63Offences and penalties0
6-7Valid consent and declarations of consent0
64-70Settlement of conflicts, compensation, regulations, transitional period and commencement0
8Right to withdraw consent0
9Children's personal data: parental consent0
REGNCSA regulations and compliance tools under the Law0

Tell me when Rwanda DPL files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Breach response procedure with the 72-hour A05 notification on Form 03 and the four content items
  • Processor contracts requiring notice without undue delay
  • Breach confirmation records and A05 coordination log
  • Breach procedure with the 24-hour response start, the 72-hour URCDP notification and the data subject communication test
  • Notifications to the URCDP with timestamps and content
  • Post-resolution detailed reports to the URCDP
  • Data quality procedures proportionate to the purpose
  • Update and correction workflows
  • Data inventory mapping each data element to a lawful purpose
  • Accuracy maintenance and update procedures

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for Rwanda DPL, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition