Rwanda Privacy Centre

Data Processing Policy

Introduction

 

TransUnion operates as a credit information and insights provider in Rwanda and processes personal data in accordance with applicable legal and regulatory requirements.

Its operations are governed by relevant laws, including Law No. 058/2021 Relating to the Protection of Personal Data and Privacy, as well as applicable financial services and regulatory frameworks overseen by the National Bank of Rwanda.

TransUnion is committed to protecting the integrity, confidentiality, and security of all personal data processed in the course of its operations and recognises the importance of privacy and data protection.

TransUnion implements appropriate technical and organisational measures to safeguard personal data and ensure that such information is processed lawfully, fairly, and transparently.

Where applicable, TransUnion aligns its practices with recognised industry standards and requires all entities interacting with TransUnion to maintain equivalent levels of data protection when processing personal data.

This notice covers the following topics:

  1. Purpose
  2. Scope and Application
  3. Definitions
  4. Compliance with Laws
  5. Information Security
  6. Lawful Basis and Consent
  7. Submission and Quality of Information
  8. Use of Information
  9. Protection of Personal data
  10. Data Breach Notification
  11. Retention and Disposal
  12. Confidentiality
  13. Credit Information and Payment Profiles
  14. Removal of Adverse Credit Information
  15. Contact and Queries
  16. Policy Updates

 

1.  Purpose

 

This Policy sets out the requirements and standards for the lawful processing, protection, and secure handling of personal data collected, shared with, or processed by TransUnion in the course of its operations in Rwanda.

 

2.  Scope and Application

 

1.    This policy applies to:

a.    TransUnion, including its employees, contractors, and internal operations that handle personal data; and 

b.    all external organisations that access, use, process, or provide personal data to or from TransUnion (whether directly or through an authorised TransUnion partner or reseller) (“Applicable Parties”).

2.    This Policy establishes the minimum standards for how personal data must be handled and protected. For external parties, this Policy forms part of the terms governing their relationship with TransUnion and must be read together with any applicable agreement.

3.    Non-compliance with this Policy may be treated as a breach of contractual obligations and may be addressed in accordance with the relevant agreement and applicable law.

4.    This Policy continues to apply for as long as TransUnion or any Applicable Party holds or uses personal data, even if the commercial relationship has ended.

5.     If there is any conflict between this policy and another agreement between TransUnion and an Applicable Party, this Policy will apply to matters relating to how personal data is handled, unless the law requires otherwise.

 

3.  Definitions

 

Key terms used in this policy include:

  1. “Data Controller” means the party that determines the purpose and means of processing personal data.
  2. “Data Processor” means a party that processes personal data on behalf of a Data Controller.
  3. “Data Protection Law” means Law No. 058/2021 Relating to the Protection of Personal Data and Privacy, as amended from time to time.
  4. “Data Subject” means an identifiable individual whose personal data is collected or processed.
  5. “Laws” means all applicable laws, regulations, and regulatory requirements in Rwanda.
  6. “Party” or “Parties” means TransUnion and/or any Applicable Party, as the context requires.
  7. “Payment Profile Information” means information relating to a person’s payment behaviour and credit activity.
  8. “Personal data” means any information relating to an identifiable individual.
  9. “Processing” means any activity involving personal data, including collection, use, storage, or deletion.
  10. “TransUnion” means the relevant TransUnion entity operating in the Republic of Rwanda.

 

4.  Compliance with Laws

 

TransUnion and all Applicable Parties must comply with applicable legal and regulatory requirements in Rwanda, including Law No. 058/2021 Relating to the Protection of Personal Data and Privacy and any applicable financial services regulations overseen by the National Bank of Rwanda.

 

5.  Information Security

 

TransUnion implements appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, or damage.

Access to personal data is restricted to authorised individuals, and third-party service providers are required to maintain appropriate security safeguards.

In the event of a security incident, TransUnion will investigate and take appropriate steps to contain and remediate the issue in line with applicable requirements.

 

6.  Lawful Basis and Consent

 

TransUnion processes personal data in a lawful, fair, and transparent manner.

Where required, consent will be obtained before processing takes place, and records of such consent will be maintained. Personal data may also be processed where necessary to fulfil contractual obligations, comply with legal requirements, or for legitimate business purposes.

 

7.  Submission and Quality of Information

 

1.    TransUnion and all parties processing Personal data must ensure that any information collected, used, or submitted is:

  • Accurate, complete, and up to date 
  • Not duplicated or misleading 
  • Processed lawfully and with proper authorisation 
  • Limited to categories of information permitted by applicable law

2.    Where information is submitted to TransUnion or used for credit credit information or risk assessment purposes, the following additional requirements apply:

  • Only information permitted under applicable laws and regulations may be submitted;
  • Data must meet required minimum standards and reporting criteria
  • All submissions must comply with applicable legal and regulatory requirements 

3.    The following types of information must not be submitted to TransUnion:

  • Prescribed debt
  • Duplicate or erroneous listings
  • Unresolved disputed information
  • Restricted categories as defined by law
  • Information that has previously been successfully challenged and removed 

All parties must take reasonable steps to ensure data accuracy and must cooperate in resolving disputes and correcting any inaccurate information.

 

8.  Use of Information

 

Personal data must be used responsibly and only for lawful purposes, such as:

Personal data must:

  • Be used only for the purpose for which it was collected;
  • Not be used in a way that is incompatible with that purpose; and
  • Not be shared with third parties for unauthorised purposes.

In limited cases, credit information may be used for employment-related checks, where:

  • The individual has provided consent; and
  • The role requires a position of trust (for example, handling finances).

TransUnion takes steps to ensure that Personal data is handled in a fair and responsible manner at all times.

 

9.  Protection of Personal data

 

TransUnion ensures that personal data is processed securely and access is limited to authorised individuals.

Appropriate safeguards are in place to protect data from unauthorised access, loss, or misuse. Third parties are required to meet equivalent data protection standards.

 

10.  Data Breach Notification

TransUnion takes the protection of Personal data seriously and has measures in place to identify, manage, and respond to any security incidents that may affect such information.

In the event of a security incident, TransUnion will take appropriate steps to investigate, contain, and address the incident, and to minimise any potential impact on affected individuals. This may include securing systems, assessing the nature and scope of the incident, and implementing measures to prevent a recurrence.

Where required by applicable law, TransUnion will notify affected individuals and the relevant supervisory authority responsible for data protection in Rwanda. TransUnion remains committed to managing such incidents responsibly and transparently.

 

11.  Retention and Disposal

 

TransUnion retains Personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable laws and regulatory obligations.

Once Personal data is no longer required, TransUnion takes appropriate steps to ensure that it is securely deleted, destroyed, or de-identified in a manner that protects privacy and prevents unauthorised access.

 

12.  Confidentiality

 

TransUnion treats Personal data as confidential and takes appropriate steps to protect it from unauthorised access, disclosure, or misuse. 

Access to Personal data is limited to authorised individuals who require it to perform their roles. 

TransUnion remains committed to maintaining the confidentiality of Personal data, even after its relationship with an individual or organisation has ended, where required by law.

 

13.  Credit Information and Payment Profiles

 

TransUnion processes and shares Payment Profile Information in accordance with applicable laws and regulatory requirements in Rwanda, including any requirements imposed by the National Bank of Rwanda. Access to such information is restricted to authorised entities and is permitted only for lawful purposes such as credit risk assessment and financial decision-making.

 

14.  Removal of Adverse Credit Information

 

TransUnion processes adverse credit information in accordance with applicable laws and regulatory requirements in Rwanda, including the Data Protection Law and applicable financial sector regulations.

Adverse credit information may be updated, retained, or removed in accordance with applicable legal and regulatory requirements, including where the underlying obligation has been settled or where the information is inaccurate or no longer required.

Adverse listings will only be amended or removed where permitted by law, including where the information is inaccurate, incomplete, misleading, fraudulent, duplicated, or subject to a valid dispute.

TransUnion does not permit the unlawful or unauthorised removal of adverse credit information.

 

15.  Contact and Queries

 

If you have any questions about this policy or how your Personal data is processed, you may contact TransUnion using the following details:

  • Location: 3rd Floor of Alliance Tower, BPR Building, Plot No 6 Junction of KN 67 & KN  30,Nyarugenge District, Kigali – Rwanda
  • Postal Address: 5733 Kigali- Rwanda
  • Telephone: +250 7889 33094
  • Email:  DPORwanda@transunion.com

 

16.  Policy Updates

 

This policy may be updated from time to time to reflect changes in applicable laws, regulations, or industry practices. 

TransUnion will take reasonable steps to inform relevant stakeholders of any material changes to this policy. The latest version of this policy will always reflect the most recent effective date.

Effective date: 1 June 2026

If you’re a consumer with questions or issues related to your personal credit report, drivers history report, disputes, fraud, identity theft, credit report freeze or credit monitoring services, please visit our Customer Support Center for assistance.

Business Contact Us

We're sorry, your request failed. Please try again in a little while.