Data Protection in Tanzania

Data protection laws in Tanzania

On 1 May 2023, the Personal Data Protection Act, 2022 (“PDPA”) came into force. The PDPA provides for matters relating to protection of personal data and establishes the principles guiding and conditions for collection and processing of personal data. The principles guiding protection of personal data are provided under section 5 of the PDPA, which include:

  1. personal data must be processed lawfully, fairly, in a transparent manner ensuring its security and in accordance with the right to privacy of the data subject;
  2. personal data must be collected for explicit, specified, and legitimate purposes and not further processed contrary to those purposes;
  3. personal data must be accurate and kept up to date and corrected or deleted without delay when inaccurate;
  4. personal data must be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed;
  5. personal data must be kept in a form which identifies the data subjects for longer than is necessary for the purposes for which it was processed; and
  6. personal data must not be transferred outside Tanzania contrary to the provisions of the DPA.

In addition, the PDPA provides for the following, among other things:

  • Part 2 establishes the Personal Data Protection Commission (“Commission”) which will be responsible to ensure implementation of the provisions of the Act. The Commission will also be responsible for registration of data processors and data collectors in Tanzania;
  • Part 3 provides for registration of the controllers and processors of personal data;
  • Part 4 provides for principles relating to collection, use, disclosure and storage of personal data;
  • Part 5 provides for transfer of personal data outside Tanzania; and
  • Part 6 provides for rights of the data subjects.

The Personal Data Protection (Personal Data Collection and Processing) Regulations, 2023 (“PDPA Regulations”) made under the PDPA also came into effect on 4 July 2023 and make provisions for matters connected with the PDPA.

The PDPA and its Regulations are the principal data protection laws, supplementing other laws providing for data protection in Tanzania, including the Constitution of the United Republic of Tanzania, 1977 (“Constitution”) and other sector specific legislations, for instance the Electronic and Postal Communications Act, 2010 (“EPOCA”) and its regulations applicable to the electronic and postal communication sector and the National Payment System Act, 2015 (“NPS Act”) and the Bank of Tanzania (Financial Consumer Protection) Regulations, 2019 applicable to the financial services sector.

Back to top