A year on from the Personal Data Protection Act coming into operational effect, the compliance conversation has shifted from “does this apply to us” to “can we prove we are doing it.” The Personal Data Protection Commission is now registering controllers and processors and issuing guidance, and the grace that attended the first months is narrowing. This is where organisations should stand today.
The Framework Now in Force
The Personal Data Protection Act, 2022 (Act No. 11 of 2022) established the substantive regime, and the Personal Data Protection (Personal Data Collection and Processing) Regulations, 2023 put the operational detail in place. Together they impose the familiar architecture of a modern data-protection law: lawful bases for processing, purpose limitation, data-subject rights, security obligations, and oversight by an independent Commission. The important practical development of the past year is that the Commission is a functioning regulator, not a paper one.
Registration Is the Threshold Obligation
The single most common gap we see is registration. Both data controllers and data processors are required to register with the Commission, and operating without registration is itself a breach independent of how carefully data is otherwise handled. Organisations that mapped their compliance around consent and privacy notices but never filed for registration have their foundations in the wrong place. Registration should be confirmed, evidenced and diarised for renewal before any other control is audited.
Lawful Basis and the Consent Reflex
Many organisations default to consent as the basis for every processing activity. Consent is one lawful basis, but it is also the most fragile: it must be freely given, specific and capable of withdrawal, and a withdrawal obliges the organisation to stop. For routine processing that is necessary to perform a contract, to meet a legal obligation or to pursue a legitimate interest, a different basis is usually stronger and less exposed to a data subject simply changing their mind. Re-examining which basis actually supports each activity is a year-two task worth doing.
Cross-Border Transfers
Tanzanian businesses increasingly run on cloud services hosted outside the country, which makes the transfer rules directly relevant. Transferring personal data outside Tanzania is permitted only where the conditions in the Act and Regulations are met - broadly, an adequate level of protection in the destination, or an approved safeguard, or a specified exception. A generic cloud contract signed without regard to these conditions is a live exposure for many organisations that believe themselves compliant.
From Policy to Evidence
The maturity marker in year two is documentation. A privacy policy on a website is necessary but no longer sufficient; the Commission and any data subject who complains will look for records of processing activities, evidence of the lawful basis relied on, a workable process for handling access and erasure requests within statutory timeframes, and a demonstrable security posture. The organisations that are comfortable are those that can produce the paper trail on request - not those that can only point to good intentions.
For general information only - this material does not constitute legal advice.
Have a question about this update?
Speak with our team for confidential, partner-led counsel.
Book a Consultation

