EnglishSW
Tanzania flag

Tanzania

Tanzania Data Privacy Laws: PDPA 2022 Guide (2026)

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 8 primary sources cited on this page. How we verify our legal content

Tanzania Data Privacy Laws: PDPA 2022 Guide (2026)

Frequently Asked Questions

What is Tanzania's main data protection law?

Tanzania's primary data protection legislation is the Personal Data Protection Act (PDPA) No. 11 of 2022, which came into force on 1 May 2023. It establishes comprehensive requirements for the collection, processing, storage, and transfer of personal data. The Act is supplemented by implementing regulations issued in 2023 and enforced by the Personal Data Protection Commission (PDPC), which launched on 3 April 2024 and began active enforcement on 9 April 2026.

Who enforces data protection laws in Tanzania?

The Personal Data Protection Commission (PDPC) is the primary enforcement authority. Launched on 3 April 2024, the PDPC has the power to investigate complaints, conduct audits, issue enforcement notices, impose administrative fines of up to TZS 100 million, and order compensation to affected data subjects. Failing to register is an offence under Section 19, punishable under Section 63 by a fine of TZS 100,000 to TZS 5 million, imprisonment of up to five years, or both. The TZS 1 million to TZS 5 billion band is the Section 60 penalty for a company or corporation convicted of unlawfully disclosing, obtaining, or offering personal data for sale. The Tanzania Communications Regulatory Authority (TCRA) retains a separate enforcement role for telecommunications-specific data protection under the Electronic and Postal Communications Act (EPOCA).

What are the penalties for violating data protection laws in Tanzania?

Penalties depend on the offence. Administrative penalties imposed by the Commission in a penalty notice reach up to TZS 100 million under Section 47. Failing to register, and any other contravention for which no specific penalty is provided, carries a fine of TZS 100,000 to TZS 5 million, imprisonment of up to five years, or both, under Section 63. Unlawful disclosure, unauthorised obtaining, or offering personal data for sale under Section 60 carries TZS 100,000 to TZS 20 million or up to 10 years imprisonment for an individual, and TZS 1 million to TZS 5 billion for a company or corporation. The PDPC can also order uncapped compensation payments to affected data subjects.

Does the PDPA apply in Zanzibar?

The PDPA applies to Mainland Tanzania and to Tanzania Zanzibar, but in Zanzibar only for Union Matters as defined in the First Schedule to the Constitution of the United Republic of Tanzania. Union Matters include 22 enumerated areas such as banking, telecommunications, civil aviation, customs, and immigration. Data processing activities in Zanzibar that fall outside Union Matters are not governed by the PDPA. Zanzibar does not currently have its own separate data protection legislation, and the PDPC has indicated that further clarifying guidance will be issued.

Must every organization in Tanzania appoint a Data Protection Officer?

Yes. Section 27(3) of the PDPA requires all data controllers and data processors to appoint a Data Protection Officer. There are no organizational size thresholds or exemptions. The DPO may be an internal employee or an external professional. Key DPO responsibilities include monitoring PDPA compliance, managing data subject requests, overseeing Data Protection Impact Assessments, and submitting quarterly compliance reports to the PDPC.

Can personal data be transferred outside Tanzania?

Yes, but only under strict conditions, and the Act has two routes. Section 31 covers transfers to a country whose legal framework already provides adequate data protection. Section 32 covers transfers to other countries, and allows them where an adequate level of protection is ensured in the recipient country and the data is transferred solely to permit processing the controller is authorised to undertake. Either way, data controllers must apply for a permit from the PDPC under Regulation 20 of the 2023 Regulations and show that the recipient country has appropriate international agreements, bilateral arrangements, or contractual safeguards in place. The Commission decides the application within fourteen days and may reject it on the grounds listed in Regulation 21, including a threat to national security.

What is the breach notification requirement in Tanzania?

Section 27(5) requires the data controller to notify the Commission 'without any undue delay' of any security breach affecting personal data processed by or on behalf of the controller. A breach covers negligent loss or unauthorized modification, destruction, disclosure, access, or processing of personal data. The Act imposes no express processor-to-controller notification duty, so controllers should require one by contract under Section 27(4). The PDPA does not specify a fixed number of hours for notification, unlike the GDPR's 72-hour window. Until the PDPC issues specific guidance, organizations are advised to treat 72 hours as a working target.

Were any parts of Tanzania's PDPA found unconstitutional?

Yes. On 8 May 2024, the High Court of Tanzania ruled that Section 22(3) (on unlawful means of collecting personal data) and Section 23(3)(c) and (e) (exceptions to the duty to collect personal data directly from the data subject) were unconstitutionally vague. The court ordered the government to amend both provisions within one year, failing which they were to be struck from the law. No amendment has been enacted: the National Assembly's index of acts shows no Personal Data Protection (Amendment) Act as of September 2026, so the window lapsed on 8 May 2025. The PDPC still publishes the unamended text and no repeal has been gazetted, so seek Tanzanian legal advice before relying on either provision.

Do organizations need to register with the PDPC?

Yes. The registration deadline was April 8, 2026. Organizations that have not yet registered are operating illegally and face enforcement action that began on April 9, 2026. Registration requires providing information about data processing activities, categories of personal data handled, the identity of the appointed DPO, and security measures in place. A certificate of registration, once issued, is valid for five years.

Updates

Second-round corrections: the Quick Answer now matches the body on the lapsed 2024 High Court amendment deadline; section 34 restated in its statutory terms (substantial damage); a stale currency conversion and an unsourced SIM-registration penalty row removed.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Major refresh: added Data Protection Officers section (PDPA s. 27(3)), Zanzibar and the PDPA section (PDPA s. 2 Union Matters limitation), Recent Developments 2024-2026 section covering the Magoti v. AG constitutional ruling and the April 2026 enforcement deadline. Updated registration deadline timeline (Dec 2024 to Apr 2025 to Apr 2026). Corrected initial deadline from Oct 2024 (unverified) to Dec 31, 2024 (presidential grace period set at April 2024 PDPC launch).. Updated penalty table with the statutory bands. Expanded FAQ section. Updated meta description and title.

Reviewed and approved by an editor

Sources and References

  1. Personal Data Protection Act No. 11 of 2022, Cap. 44 (official text, GN No. 395B)(pdpc.go.tz).gov
  2. Personal Data Protection Commission (PDPC) Official Website(pdpc.go.tz).gov
  3. PDPC Publications: Acts, Regulations and Guidelines(pdpc.go.tz).gov
  4. Personal Data Collection and Processing Regulations 2023 (GN No. 449C)(mawasiliano.go.tz).gov
  5. Constitution of the United Republic of Tanzania, 1977 (Office of the Attorney General constitutions register)(oagmis.oag.go.tz).gov
  6. PDPC Data Protection Officer Page(pdpc.go.tz).gov
  7. Tanzania Communications Regulatory Authority (TCRA)(tcra.go.tz).gov
  8. Cybercrimes Act No. 14 of 2015 (National Assembly official text)(polis.bunge.go.tz).gov
  9. Clyde & Co -- The Role of Data Protection Officers(clydeco.com)
  10. Clyde & Co -- Cross-Border Personal Data Transfers in Tanzania(clydeco.com)
  11. Clyde & Co -- Key Obligations for Data Controllers and Processors(clydeco.com)
  12. Biometric Update -- Court Orders Changes to Tanzania's Data Protection Law(biometricupdate.com)
  13. The Chanzo -- PDPC Final Warning Ahead of April Enforcement Deadline(thechanzo.com)
  14. FB Attorneys -- Personal Data Protection in Zanzibar(fbattorneys.co.tz)
  15. Future of Privacy Forum -- Tanzania's PDPA Overview(fpf.org)
  16. DLA Piper -- Data Protection Laws of the World (Tanzania)(dlapiperdataprotection.com)
  17. CIPESA -- Data Governance Regulation in Tanzania(cipesa.org)
Share: