Loading...
Loading...
Copyright © 2026 Anove International B.V.
All product names, logos, and brands are property of their respective owners. Use of these names does not imply affiliation, endorsement, or partnership.
PDPA
Tanzania's PDPA (2022) establishes GDPR-style processing principles, mandatory registration of all controllers and processors with the Personal Data Protection Commission, DPO appointment, breach notification and permit-based cross-border transfers.
The Personal Data Protection Act, 2022 came into force on 1 May 2023 and applies to both public and private entities. The Personal Data Protection Commission (PDPC), headquartered in Dodoma, was established on 1 May 2023 and became fully operational on 3 April 2024. Two sets of implementing rules were issued in 2023: the Personal Data Collection and Processing Regulations and the Complaints Settlement Procedures Regulations. All data controllers and processors must register with the PDPC, with registration valid for five years; in January 2026 the responsible minister issued a final three-month ultimatum for registration. Controllers and processors must appoint a Data Protection Officer who submits quarterly compliance reports to the PDPC.
Sensitive personal data, including genetic, biometric, children's, financial, health and sexual-life data, generally requires prior written consent. Any security breach affecting personal data must be promptly notified to the PDPC. Cross-border transfers require adequacy or appropriate safeguards plus a prior PDPC permit supported by an international agreement, bilateral agreement or contractual safeguards. Enforcement is active: on 10 July 2025 the PDPC applied a continuing-violation doctrine to images posted without consent before the Act that remained online after commencement, ordering deletion and TZS 20 million in moral damages.
All data controllers and processors must register with the Commission, with registration valid for five years; a ministerial final three-month registration ultimatum was issued in January 2026.
Data must be processed lawfully, fairly, transparently and securely for explicit, legitimate purposes; sensitive personal data requires prior written consent, with narrow exceptions.
Controllers and processors must appoint a DPO responsible for security controls, PDPA compliance, data subject requests and quarterly compliance reports to the PDPC.
Every security breach that may affect personal data being processed, including loss, unauthorised modification, destruction, disclosure or access, must be promptly notified to the PDPC.
Read more
Anove scans your stack against PDPA and 260+ other frameworks in minutes.
Transfers outside Tanzania require adequacy or appropriate safeguards and a prior PDPC permit evidencing an international agreement, bilateral agreement or contractual safeguards with the recipient.