Law No 058/2021
Rwanda’s personal data and privacy law governs processing obligations, data subject rights and controller or processor registration. Legal review is required before deployment.
MoTa’s production architecture must protect fiscal records, respect Rwanda’s data requirements and give institutions control over their infrastructure.
Explore Live SandboxRwanda’s personal data and privacy law governs processing obligations, data subject rights and controller or processor registration. Legal review is required before deployment.
Evaluate AOS National Data Center services and RISA directives. These are proposed residency options, not MoTa’s confirmed hosting or a compliance endorsement.
Least privilege, authenticated production endpoints, encrypted storage, key rotation and auditable access are required controls.
SHA-256 fingerprints detect changes when compared with a trusted record. A hash alone is not a digital signature, proof of origin or RRA approval.
SIMULATEDRequired production trail: append-only events, restricted writes, retention policy and independently verified backups.
Security must protect both the content of a fiscal record and the authority to access or change it. Data location, cryptographic integrity, identity, operational audit and recovery are separate controls. A strong design explains what each control proves and what still requires independent verification.
SHA-256 produces a fingerprint of a defined byte sequence. For repeatable verification, a production format must fix field ordering, number formatting, text encoding and versioning before hashing. Changing a quantity or total then changes the fingerprint. Comparison is meaningful only against an independently trusted record, not a hash supplied alongside data by an untrusted caller.
A proposed audit chain can include the previous event hash in the next event’s canonical payload, with periodic checkpoints stored independently. This helps detect missing or altered events but does not prevent a privileged actor from rebuilding an entire unanchored chain. Digital signatures require protected signing keys, and official fiscal signatures require certified authority processing. Neither is created by the hash preview above.
hash[n] = SHA-256(canonical(event[n]) + hash[n-1])Law No 058/2021 frames personal-data obligations and data subject rights. A deployment review must establish controller and processor responsibilities, registration requirements, processing purposes and transfer rules with qualified local advice. Kigali residency planning should cover primary storage, backups, logs and support access, not only the location of the main application.
AOS National Data Center services and RISA directives are options and references to evaluate, not confirmed MoTa hosting. Independent operation requires documented deployment procedures, exportable data, infrastructure ownership and tested restoration outside a single vendor. Sovereignty also depends on who controls keys, access approvals and incident response. No current hosting certification is implied.
Production authorization must be enforced at the data and service boundary, not just by hiding buttons. Merchant users should access only their permitted records; district reviewers receive scoped read access; national analysts receive approved aggregates. Privileged administration should be separated from routine reporting, with role assignment protected from user-editable profile fields.
Every sensitive request must authenticate its caller, authorize the requested operation and verify the scope of the target record. TLS, encryption at rest, key rotation and short-lived credentials are complementary controls, not substitutes for authorization. Public simulations must never gain the privileges of a certified fiscal adapter or an institutional administrator.
| Role | Permitted evidence |
|---|---|
| Merchant | Own sales, receipts and daily exports. No cross-merchant access. |
| Authorized reviewer | Read-only records within the approved institutional scope. |
| Institutional analyst | Approved aggregates with restricted personal-data exposure. |
| Privileged operator | Separately authorized administration with audited actions. |
A proposed append-only audit trail captures actor, action, object, time, result and correlation reference. Sensitive values should be minimized or redacted, and access to the trail must itself be audited. Fiscal corrections retain links to the original transaction and the approving actor. Retention periods must follow the applicable legal and institutional policy rather than an arbitrary product default.
Recovery readiness requires independently protected backups, restoration drills and a reconciliation procedure for events received during an outage. Incident response assigns responsibility for containment, evidence preservation, stakeholder notification and controlled restart. Data-loss and recovery-time objectives must be agreed and tested before a production claim is made. These are deployment requirements, not assertions that every control is already operating.
Mobile Tax Automation