Law No. 058/2021 art. 21 — right not to be subject to a decision based on automated data processing
Binds Data controllers, data processors and third parties within the scope of art. 2: those established or residing in Rwanda and processing personal data while in Rwanda, and those neither established nor resident in Rwanda that process the personal data of data subjects located in Rwanda. Article 2 reaches processing of personal data by electronic or other means through an automated or non-automated platform. Registration with the supervisory authority is a standing precondition of acting as a controller or processor: arts. 29 to 36 govern registration, the registration certificate, its renewal, modification and cancellation, and the register itself, and operating without a registration certificate is an administrative misconduct under art. 54. The art. 21 right binds any controller taking a solely-automated decision with legal or significant consequences, irrespective of size. The National Cyber Security Authority is the designated supervisory authority. Impact tier: all entities.. Article 21 of Law Nº 058/2021 of 13/10/2021 relating to the protection of personal data and privacy carries Rwanda's operative automated-decision rule, in Chapter III (rights of the data subject). Its first paragraph gives the data subject the right not to be subject to a decision based solely on automated personal data processing, including profiling, which may produce legal consequences or significant consequences to him or her. The second paragraph disapplies that right where the decision is based on the explicit consent of the data subject, is necessary for entering into or performance of a contract between the data subject and the data controller, or is authorised by Laws to which the data controller is subject and which also put in place suitable measures to safeguard the data subject's rights, freedoms and legitimate interests. The third paragraph adds a free-standing limit that binds even inside those exceptions: any automated processing of personal data intended to evaluate certain personal aspects relating to a natural person does not base on sensitive personal data unless one of the grounds in art. 10 is met. Article 3 supplies the definitions that give the rule its reach — item 11° defines profiling as a form of automated processing used to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements; item 8° defines legal consequences as consequences that negatively affect a person's legal status or legal rights; and item 7° defines significant consequences as consequences having an impact as significant as legal effects that negatively affect the behaviour and choices of a data subject. Two adjacent duties attach to the same processing: art. 14 requires the controller to disclose to the data subject the existence of automated decision making, including profiling, together with information about the logic involved and the significance and envisaged consequences of the processing, and art. 45 makes a personal data protection impact assessment mandatory where there is a systematic and extensive evaluation of personal aspects relating to natural persons based on automated processing of personal data, including profiling, on which decisions producing effects concerning such persons are based.
Commencement is stated on the face of the Law and needs no separate instrument: art. 70 provides that the Law comes into force on the date of its publication in the Official Gazette of the Republic of Rwanda, and it was published in Official Gazette nº Special of 15/10/2021, so art. 21 has been in force since 15 October 2021. Article 67 gave a controller or processor already in operation a period not exceeding two years from that publication date to conform its operations to the Law; that transitional window closed on 15 October 2023 and does not defer art. 21 itself. Article 66 lets the competent organ, in collaboration with the supervisory authority, put in place regulations; no regulation specific to automated decision-making has been issued. Coverage symmetry against the four African rows already tracked: art. 21 is a standing prohibition in the GDPR art. 22 shape, like ke-dpa-s35 and ng-ndpa-s37 and unlike the notice-based gh-dpa-s41, but its remedy is the thinnest of the five — where Nigeria's s. 37(3) expressly grants human intervention, the right to express a point of view and the right to contest, and Kenya's s. 35(3)-(4) grants written notification plus reconsideration or a fresh non-automated decision, Rwanda's art. 21 sets out only the right and its exceptions and prescribes no safeguard measures inside the exceptions at all. It carries no hard deadline; the thirty-day and sixty-day clocks in arts. 19, 20 and 22 attach to objection, portability and restriction, not to art. 21. Its distinctive addition is the art. 21 third-paragraph bar on grounding evaluative automated processing in sensitive personal data, which none of the four peers has. Text read in the Official Gazette as published by the National Cyber Security Authority, the supervisory authority designated under the Law; the English, French and Ikinyarwanda columns of the gazette were read together and agree.
Stated maximum penalty — There is no offence specific to art. 21. Enforcement runs through Chapter VIII. Under art. 54 a listed administrative misconduct — including processing personal data contrary to the Law, operating without a registration certificate, failure to designate a personal data protection officer and the breach-notification failures — carries an administrative fine of not less than RWF 2,000,000 and not more than RWF 5,000,000, or one per cent of the global turnover of the preceding financial year, and for a corporate body or legal entity one per cent of that global turnover; the same article lets the supervisory authority make regulations determining further administrative misconducts and sanctions. The criminal tier in arts. 56 to 61 is narrower and does not name automated decision-making: art. 56 punishes accessing, collecting, using, offering, sharing, transferring or disclosing personal data contrary to the Law with one to three years' imprisonment and a fine of RWF 7,000,000 to RWF 10,000,000, or one of those penalties, and art. 60 punishes collecting or processing sensitive personal data contrary to the Law with seven to ten years' imprisonment and a fine of RWF 20,000,000 to RWF 25,000,000, or one of those penalties. Article 62 sets the corporate penalty for any of the arts. 56 to 61 offences at 5% of the annual turnover of the preceding financial year, and art. 63 lets the court order seizure or confiscation of the objects used and the proceeds gained, and permanent or temporary closure of the entity or premises. Article 65 gives a person who suffers serious damage from a controller's or processor's breach a claim for compensation before the competent court.