The Personal Data Protection Act, No. 11 of 2022 and its subsidiary regulations established Tanzania’s first comprehensive data protection framework and created the Personal Data Protection Commission (PDPC) to enforce it. The transition period has passed, the Commission is registering data controllers and processors, and businesses that handle personal data can no longer treat compliance as optional.
Does the Act Apply to You
The Act applies to any person - public or private - who determines the purpose and means of processing personal data (a data controller) or who processes it on their behalf (a data processor), where the processing takes place in Tanzania or relates to data subjects in Tanzania. In practice this captures almost every business that keeps records of employees, customers or suppliers. Personal data is broadly defined, and sensitive data - health, biometric, financial and similar categories - attracts stricter requirements.
Registration With the Commission
Data controllers and processors are required to register with the PDPC and to renew that registration. Registration is not a formality to be deferred: processing personal data without the required registration is itself a breach. Businesses should identify whether they are acting as controller, processor, or both for different activities, and register accordingly.
Establish a Lawful Basis
Every act of processing must rest on a lawful basis. Consent is one basis, but it must be freely given, specific and informed, and it can be withdrawn - which makes it a fragile foundation for core business processing. Other bases include the performance of a contract with the data subject, compliance with a legal obligation, and the legitimate interests of the controller. Businesses should map their processing activities to a lawful basis rather than relying on consent by default.
Honour Data Subject Rights
The Act confers rights on individuals that a controller must be able to service, including:
- the right to be informed about how their data is used;
- the right of access to their personal data;
- the right to rectification of inaccurate data;
- the right to erasure and to object to certain processing in defined circumstances.
A business needs a documented procedure for receiving and responding to such requests within the statutory timeframe. An ad hoc response when the first request arrives is a recipe for a complaint to the Commission.
Secure the Data
Controllers and processors must implement appropriate technical and organisational measures to protect personal data against loss, unauthorised access and disclosure. What is “appropriate” scales with the sensitivity of the data and the harm that a breach would cause. Practical measures include access controls, encryption of sensitive data, staff training, and a written information-security policy. Where a processor is engaged, a written contract must bind it to equivalent standards.
Manage Cross-Border Transfers
Transferring personal data outside Tanzania - including to overseas cloud providers and group companies - is regulated. Transfers are permitted where the conditions in the Act are met, which may require that the destination offers adequate protection or that the transfer falls within a recognised exception. Any business using foreign-hosted systems should map where its data physically resides and confirm the basis for each transfer.
Prepare for Breaches
A data breach is not merely an IT incident; it can carry a notification obligation. Businesses should have an incident-response plan that enables them to detect, contain, assess and, where required, report a breach to the Commission and affected individuals. The time to write that plan is before, not during, an incident.
Your Compliance Checklist
- Register with the PDPC as controller and/or processor.
- Map your processing and assign a lawful basis to each activity.
- Publish a clear privacy notice.
- Put a data-subject-request procedure in place.
- Implement security measures proportionate to the data.
- Contract processors to equivalent standards.
- Document the basis for every cross-border transfer.
- Adopt a breach-response plan.
Compliance is a programme, not a document. Businesses that build these steps into normal operations will be well placed as the Commission’s enforcement activity intensifies.
For general information only - this material does not constitute legal advice.
Have a question about this update?
Speak with our team for confidential, partner-led counsel.
Book a Consultation

