On 9 April 2024, the Data Protection and Privacy Office (DPO) in Rwanda issued the "Guide on Contractual Provisions for Processing of Personal Data," outlining mandatory requirements for data processing agreements under Law N. 058/2021 of 13 October 2021 on personal data protection. The law mandates that Data Controllers and Data Processors formalise their processing activities through legally binding agreements, and the guide outlines provisions such as the scope of processing, data subject categories, retention periods, security measures, and data subject rights. It clarifies obligations for Data Processors, including acting on documented instructions, ensuring confidentiality, implementing security measures, and assisting Data Controllers with compliance tasks such as data breach notifications and data subject requests. The guide also addresses third-party processing and specifies requirements for the return or deletion of data upon contract termination.
Original source