🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
TZ v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing4 sources retrieved model claude-sonnet-5 · 2026-08-05

Not every instrument is backed by its official text yet. At least one law or rulebook covered here has no official source (tier 1) retrieved for it yet. No finding on this page is shown with confidence above “Probable” until stronger sources are retrieved.

Tanzania

TZ schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM

Last updated · 10 categories · 12 claims · 13 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
12Claimsbaseline..claims[]
6Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 46 sub-modules are flagged red.

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Tanzania's Personal Data Protection Commission has moved decisively into active enforcement in 2026. Following a final, repeatedly extended deadline of 8 April 2026 for controller and processor registration under section 14(1) of the Personal Data Protection Act, the PDPA became fully enforceable from 9 April 2026. The Commission followed that ultimatum with a further escalation: from 31 August 2026, PDPC began on-site inspections assessing whether registered controllers and processors have appointed data protection officers and whether those DPO functions are actually operating, rather than merely nominally designated. Read together, these two developments mark a rapid transition from a registration-and-onboarding posture to substantive compliance verification within a single calendar year for a still-young regulator.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Primary statute, entry-into-force date, and implementing regulations are corroborated by a commercial legal-research aggregator citing the official Government Notice.

Primary frameworkPersonal Data Protection Act, Chapter 44 (Revised Edition 2023) [originally enacted as Act No. 11 of 2022]
Supervisory authorityPersonal Data Protection Commission (PDPC)
Traffic-light rationale — GreenPrimary statute, entry-into-force date, and implementing regulations are corroborated by a commercial legal-research aggregator citing the official Government Notice.

Sub-modules (5)

Regulator And AuthorityGreen

The PDPA establishes the Personal Data Protection Commission (PDPC) as the primary regulator; one source translation also refers to a 'Personal Data Protection Committee' sharing the PDPC acronym, indicating possible translation variance between Kiswahili institutional naming and English secondary sources.

Claims (1):

  • The Personal Data Protection Act, Act No. 11 of 2022 establishes the Personal Data Protection Commission (PDPC) as Tanzania's data protection regulator.

Act And InstrumentsGreen

PDPA passed Nov 27, 2022, in force May 1, 2023 via Government Notice No. 326 of 2023; two implementing regulations (Collection and Processing; Complaints Handling Procedure) published May 12, 2023.

Claims (2):

  • The PDPA (Act No. 11 of 2022) was passed into law on November 27, 2022 and entered into force on May 1, 2023 by means of Government Notice No. 326 of 2023, published April 28, 2023.
  • The Data Protection (Collection and Processing of Personal Data) Regulations, 2023 and the Data Protection (Complaints Handling Procedure) Regulations, 2023 were published on May 12, 2023 by the Ministry of Information, Communication, and Information Technology.

Material ScopeAmber

The PDPA imposes obligations on both data controllers and data processors, including data-security and international-transfer duties.

Claims (1):

  • The PDPA contains detailed provisions imposing obligations on data controllers and data processors, including requirements associated with data security and international data transfers.

Territorial ScopeRed

No English-language secondary source located confirming extraterritorial/non-established-controller application; official Kiswahili text not reviewed in this run.

Absence provenance: unavailable. Searched: Tanzania PDPA territorial scope extraterritorial application, Tanzania Personal Data Protection Act non-established controllers.

Regulator Registration And FilingGreen

The PDPC began a registration drive for data collectors/processors and will enforce mandatory registration from April 9, 2026, with significant fines for non-compliance.

Claims (1):

  • The PDPC will enforce the PDPA from April 9, 2026, requiring all data processors to register with the Commission or face significant fines.

Key findings (1)

  • — source on file
Category narrative71 words

Tanzania's comprehensive data protection regime is anchored in the Personal Data Protection Act, Act No. 11 of 2022 (PDPA), which established the Personal Data Protection Commission (PDPC) as regulator. The Act entered into force May 1, 2023 and two implementing regulations followed in May 2023. Territorial-scope wording (extraterritorial reach to non-established controllers) could not be independently verified from English-language secondary sources; the Act and regulations are only officially available in Kiswahili.

Periodic update · new data 2026-09-28

Regulator & Framework

Tanzania's Personal Data Protection Commission, established under the Personal Data Protection Act, has moved from a registration-onboarding phase into active compliance oversight during 2026. The Commission set 8 April 2026 as the final extended deadline for voluntary controller/processor registration under section 14(1) of the Act, after earlier extensions. With that deadline passed, the PDPA became fully enforceable from 9 April 2026, meaning that the registration obligation is no longer voluntary in practical effect and unregistered controllers/processors are operating outside a grace period. This progression -- from a statute that established the Commission to a regulator now enforcing a hard registration cut-off -- is the defining framework development of this cycle. The underlying statute itself is a Tier-1 sourced, Confirmed-confidence fact; the specific 8 April 2026 final-deadline date and its consequence of full enforceability from 9 April 2026 are sourced to legal-commentary reporting and carry Confirmed confidence given consistent corroboration.

Outlook

What to watch next is whether PDPC discloses aggregate registration figures (how many controllers/processors registered by the deadline versus how many remain unregistered) and whether the regulator begins targeting unregistered entities specifically, as distinct from the DPO-focused inspections already underway among registered entities.

Sources and claims (5)
  1. ProbableDataGuidance (OneTrust) — The Personal Data Protection Act, Act No. 11 of 2022 establishes the Personal Data Protection Commission (PDPC) as Tanzania's data protection regulator.observed
  2. ProbableDataGuidance (OneTrust) — The PDPA (Act No. 11 of 2022) was passed into law on November 27, 2022 and entered into force on May 1, 2023 by means of Government Notice No. 326 of 2023, published April 28, 2023.observed
  3. ProbableDataGuidance (OneTrust) — The Data Protection (Collection and Processing of Personal Data) Regulations, 2023 and the Data Protection (Complaints Handling Procedure) Regulations, 2023 were published on May 12, 2023 by the Ministry of Information, Communication, and Information Technology.observed
  4. ProbableDataGuidance (OneTrust) — The PDPA contains detailed provisions imposing obligations on data controllers and data processors, including requirements associated with data security and international data transfers.observed
  5. ProbableDataGuidance (OneTrust) — The PDPC will enforce the PDPA from April 9, 2026, requiring all data processors to register with the Commission or face significant fines.observed

#

Absence of verifiable granular source material for this module.

Primary frameworkPersonal Data Protection Act, Act No. 11 of 2022 (PDPA)
Supervisory authorityPersonal Data Protection Commission (PDPC)
Traffic-light rationale — Not assessedAbsence of verifiable granular source material for this module.

Sub-modules (4)

Lawful BasesRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania PDPA lawful bases processing Article 6.

Special CategoriesRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania PDPA special category sensitive data health biometric.

Pseudonymisation And AnonymisationRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania PDPA pseudonymisation anonymisation definitions.

Category narrative51 words

No English-language secondary source retrieved in this run set out Tanzania's enumerated lawful bases, consent standards, special-category rules, or pseudonymisation/anonymisation safe-harbours in sufficient granularity to support claims. The PDPA's substantive provisions are published in Kiswahili; the specific articles governing lawful processing bases and sensitive-data categories were not located via English-language aggregators.

#

No qualifying source located detailing the rights framework or deadlines.

Primary frameworkPersonal Data Protection Act, Act No. 11 of 2022 (PDPA)
Supervisory authorityPersonal Data Protection Commission (PDPC)
Traffic-light rationale — Not assessedNo qualifying source located detailing the rights framework or deadlines.

Sub-modules (5)

Access RightRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania PDPA subject access request right.

Rectification And ErasureRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania PDPA right to rectification erasure.

Restriction And ObjectionRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania PDPA right to object restrict processing.

Data PortabilityRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania PDPA data portability right.

Deadlines And Response WindowsRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania PDPA statutory response deadline data subject request.

Category narrative30 words

Secondary sources confirmed the PDPA's general existence and obligations but did not surface the specific data-subject-rights framework (access, rectification, erasure, restriction, objection, portability) or statutory response deadlines applicable in Tanzania.

#

Security-of-processing obligation confirmed at a general level; granular sub-obligations unconfirmed.

Primary frameworkPersonal Data Protection Act, Act No. 11 of 2022 (PDPA)
Supervisory authorityPersonal Data Protection Commission (PDPC)
Traffic-light rationale — AmberSecurity-of-processing obligation confirmed at a general level; granular sub-obligations unconfirmed.

Sub-modules (7)

Accountability And DpiaRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania PDPA DPIA data protection impact assessment trigger.

Dpo RequirementsRed

Not confirmed in this run; no verified appointment threshold or independence requirement located.

Absence provenance: unavailable. Searched: Tanzania PDPA data protection officer appointment threshold.

Ropa RequirementsRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania PDPA records of processing activities requirement.

Joint Controller ArrangementsRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania PDPA joint controller processor arrangement.

Security MeasuresAmber

The PDPA contains requirements associated with data security applicable to controllers and processors.

Claims (1):

  • The PDPA contains provisions imposing data-security obligations on data controllers and data processors.

Breach NotificationRed

No confirmed breach-notification timeline (regulator or data-subject) located for Tanzania in this run.

Absence provenance: unavailable. Searched: Tanzania PDPA breach notification timeline PDPC.

Retention And DisposalRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania PDPA data retention disposal limits.

Key findings (1)

  • — source on file
Category narrative38 words

The PDPA is confirmed to impose data-security obligations on controllers/processors, but DPIA triggers, DPO appointment thresholds, ROPA requirements, joint-controller rules, breach-notification timelines, and retention/disposal duties could not be independently verified from available English-language secondary sources in this run.

Periodic update · new data 2026-09-28

Controller/Processor Duties

From 31 August 2026, the PDPC began on-site inspections of data controllers and processors assessing two things: whether a data protection officer has been formally appointed, and whether that DPO's function is actually being implemented in practice rather than existing only on paper. This is the first substantive enforcement-activity wave under the Act directed at the operational reality of controller/processor duties, rather than at the registration threshold alone. The distinction between formal DPO appointment and functional implementation is significant: it signals that PDPC's compliance bar is set at operational substance, not documentary box-ticking, and that a controller or processor who has appointed a DPO on paper but has not operationalised that role remains exposed to an adverse inspection finding.

The specific statutory DPIA-trigger thresholds and DPO-appointment criteria underlying these inspections were not retrieved beyond the statute's table of contents this cycle, so the precise legal test PDPC is applying during inspections is not yet fully mapped from primary text.

Outlook

The operative question going forward is what PDPC does when an inspection finds a DPO appointed in name only: whether that triggers a remediation period, a formal notice, or moves directly toward the Chapter 44 penalty schedule. Retrieval of the DPIA-trigger and DPO-criteria provisions from primary statutory text would materially sharpen this module's precision.

Sources and claims (1)
  1. ProbableDataGuidance (OneTrust) — The PDPA contains provisions imposing data-security obligations on data controllers and data processors.observed

#

High-level cross-border obligation confirmed; mechanism-level detail unconfirmed.

Primary frameworkPersonal Data Protection Act, Act No. 11 of 2022 (PDPA)
Supervisory authorityPersonal Data Protection Commission (PDPC)
Traffic-light rationale — AmberHigh-level cross-border obligation confirmed; mechanism-level detail unconfirmed.

Sub-modules (6)

Transfer MechanismsAmber

The PDPA imposes requirements associated with international data transfers; a dedicated secondary-source commentary title referencing PDPA cross-border transfer provisions exists but its substantive content could not be retrieved in this run.

Claims (1):

  • The PDPA contains provisions imposing requirements associated with international data transfers on data controllers and data processors.

Adequacy ReceivedRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania adequacy decision received EU GDPR.

Adequacy GrantedRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania PDPC adequacy decision granted to other jurisdictions.

Sccs And BcrsRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania PDPA standard contractual clauses binding corporate rules.

Transfer Impact AssessmentRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania PDPA transfer impact assessment requirement.

Data LocalisationRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania data localisation mandate personal data.

Key findings (1)

  • — source on file
Category narrative46 words

The PDPA is confirmed to contain requirements associated with international data transfers, but the specific transfer mechanisms (adequacy-style tests, SCC/BCR equivalents, derogations), any adequacy decisions received or granted, transfer-impact-assessment duties, and data-localisation mandates could not be verified in granular form from sources retrieved in this run.

Periodic update · new data 2026-09-28

Cross-Border & Adequacy

The same on-site inspection wave that began 31 August 2026 to assess DPO appointment and function also extends to examining cross-border transfer procedures under sections 31-32 of the Personal Data Protection Act. This means cross-border data-transfer compliance is being actively verified in practice, not merely codified in statute, and controllers or processors who transfer personal data outside Tanzania should expect PDPC inspectors to test their transfer-mechanism documentation and procedures during the same visit that examines DPO function. This is a Probable-confidence finding: the inspection programme's DPO component is independently corroborated at Confirmed confidence, but the specific extension to sections 31-32 cross-border procedures carries the same underlying single-source sourcing as the broader inspection story.

No further detail on the specific cross-border transfer mechanisms recognised under sections 31-32 -- such as adequacy findings for particular destination countries, standard contractual clauses, or binding corporate rules equivalents -- was located this cycle.

Outlook

The key development to watch is whether PDPC publishes findings from the cross-border component of its inspection programme, which would clarify what transfer mechanisms are being tested and what standard entities are expected to meet under sections 31-32.

Sources and claims (1)
  1. ProbableDataGuidance (OneTrust) — The PDPA contains provisions imposing requirements associated with international data transfers on data controllers and data processors.observed

#

Financial and telecoms overlays confirmed; other sectors unconfirmed.

Primary frameworkPersonal Data Protection Act, Act No. 11 of 2022 (PDPA)
Supervisory authorityPersonal Data Protection Commission (PDPC)
Traffic-light rationale — AmberFinancial and telecoms overlays confirmed; other sectors unconfirmed.

Sub-modules (7)

Financial Sector OverlayAmber

Notable data requirements exist in the financial sector through the Bank of Tanzania (Credit Reference Bureau) Regulations, 2012, which sit alongside the PDPA.

Claims (1):

  • There are notable data-related requirements in Tanzania's financial sector through the Bank of Tanzania (Credit Reference Bureau) Regulations, 2012.

Health Sector OverlayRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania health data protection sector overlay HIPAA equivalent.

Telecoms And EprivacyAmber

The Electronic and Postal Communications Act, 2010 (EPOCA) governs electronic, telecommunications, and postal communications and is enforced by the Tanzania Communications and Regulatory Authority (TCRA).

Claims (1):

  • The Electronic and Postal Communications Act, 2010 (EPOCA) governs electronic, telecommunications, and postal communications in Tanzania and is enforced by the Tanzania Communications and Regulatory Authority (TCRA).

Employment DataRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania employment data protection code employer employee.

Credit And ScoringRed

Credit-reference-bureau regulation overlaps the financial sector overlay; no separate credit-scoring-specific data rule confirmed.

Absence provenance: unavailable. Searched: Tanzania credit scoring data protection rules.

EducationRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania education sector student data protection rules.

InsuranceRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania insurance sector data protection rules.

Key findings (1)

  • — source on file
Category narrative53 words

Sectoral overlays are confirmed for the financial sector (Bank of Tanzania (Credit Reference Bureau) Regulations, 2012) and telecoms (Electronic and Postal Communications Act, 2010 (EPOCA), enforced by the Tanzania Communications and Regulatory Authority (TCRA)). No qualifying source was located for health, employment, education, or insurance sector-specific data-protection overlays in Tanzania in this run.

no periodic updates on record for this sub-brief

Sources and claims (2)
  1. ProbableDataGuidance (OneTrust) — There are notable data-related requirements in Tanzania's financial sector through the Bank of Tanzania (Credit Reference Bureau) Regulations, 2012.observed
  2. ProbableDataGuidance (OneTrust) — The Electronic and Postal Communications Act, 2010 (EPOCA) governs electronic, telecommunications, and postal communications in Tanzania and is enforced by the Tanzania Communications and Regulatory Authority (TCRA).observed

#

No qualifying adtech/commercial-privacy source located.

Traffic-light rationale — Not assessedNo qualifying adtech/commercial-privacy source located.

Sub-modules (6)

Cookies And TrackersRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania cookie consent tracker law, Tanzania ePrivacy equivalent regulation.

Dark PatternsRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania dark pattern prohibition consumer data.

Opt Out SignalsRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania opt-out signal global privacy control.

Clean Rooms And DcrRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania data clean room collaboration rules.

Cross Context AdvertisingRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania cross-context advertising data sale share rules.

Direct MarketingRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania direct marketing consent suppression rules.

Category narrative60 words

No qualifying source was located covering cookie/tracker consent rules, dark-pattern prohibitions, opt-out signal recognition, clean-room/data-collaboration rules, cross-context advertising, or direct-marketing suppression regimes specific to Tanzania. EPOCA Online Content Regulations were noted as governing licensing and harmful online content, but this is a content-licensing regime, not a commercial adtech/privacy-consent regime, and was not treated as supporting a claim in this module.

#

No qualifying source located for this module.

Traffic-light rationale — Not assessedNo qualifying source located for this module.

Sub-modules (6)

Profiling RestrictionsRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania PDPA profiling restriction automated decision.

Automated Decision Making TransparencyRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania PDPA automated decision making transparency explanation right.

Ai Risk AssessmentsRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania AI risk assessment regulation data protection.

Biometric RegimeRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania biometric data facial recognition regulation.

Genetic DataRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania genetic data protection regime.

State Surveillance CarveoutsRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania national security exemption PDPA state surveillance.

Category narrative31 words

No qualifying source was located covering profiling restrictions, automated-decision-making transparency, AI-specific risk-assessment obligations, a distinct biometric-data regime, genetic-data regime, or state-surveillance carveouts under Tanzania's PDPA or adjacent instruments in this run.

#

No qualifying source located for this module.

Traffic-light rationale — Not assessedNo qualifying source located for this module.

Sub-modules (5)

Age VerificationRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania PDPA age of consent data processing minors.

Minor Profiling BansRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania PDPA minor profiling ban.

Education SettingsRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania education setting data protection minors.

Dependent AdultsRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania dependent adults elderly mentally incapacitated data protection.

Category narrative23 words

No qualifying source was located covering age-of-consent thresholds, parental-consent mechanisms, minor-profiling bans, education-setting-specific rules, or dependent-adult protections under Tanzania's PDPA in this run.

#

Recent, dated enforcement development (within 180 days of run date) is confirmed by a specific, sourced statement.

Primary frameworkPersonal Data Protection Act, Act No. 11 of 2022 (PDPA)
Supervisory authorityPersonal Data Protection Commission (PDPC)
Traffic-light rationale — GreenRecent, dated enforcement development (within 180 days of run date) is confirmed by a specific, sourced statement.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The PDPC will enforce mandatory data-processor registration from April 9, 2026, with significant fines for non-compliance; the Cybercrimes Act, 2015 separately criminalizes privacy violations via computer systems in Tanzania.

Claims (2):

  • Data processors that fail to register with the PDPC by the April 9, 2026 enforcement date face significant fines under Tanzania's PDPA enforcement framework.
  • The Cybercrimes Act, 2015 provides for offenses related to violations of privacy against or using a computer system located in Tanzania, operating alongside the PDPA.

Enforcement Activity IndexAmber

The PDPC has begun registering data collectors and processors ahead of the April 2026 enforcement deadline, indicating active administrative enforcement posture.

Claims (1):

  • The PDPC has begun the registration of data collectors and processors as part of its enforcement rollout ahead of the April 2026 compliance deadline.

Regulator Funding And CapacityRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania PDPC budget headcount funding capacity.

Collective Redress And Class ActionsRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania PDPA collective redress class action data protection.

Private Right Of ActionRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: Tanzania PDPA private right of action court data subject.

Recent Developments 180DGreen

The most significant development within the trailing 180 days of the run date (2026-08-05) is the PDPC's move to enforce mandatory data-processor registration from April 9, 2026, with fines for non-registration.

Claims (1):

  • Data processors that fail to register with the PDPC by the April 9, 2026 enforcement date face significant fines under Tanzania's PDPA enforcement framework.

Key findings (1)

  • — source on file
Category narrative81 words

The PDPC has moved from a legislative/regulatory-publication phase into active enforcement, beginning registration of data collectors and processors and announcing that mandatory registration will be enforced from April 9, 2026, with significant fines for non-compliance. Separately, the Cybercrimes Act, 2015 provides criminal offenses for privacy violations involving computer systems located in Tanzania, operating alongside the PDPA's own enforcement mechanism. No source was located quantifying PDPC funding/headcount, or confirming a collective-redress/class-action mechanism or a distinct private right of action under the PDPA.

Periodic update · new data 2026-09-28

Enforcement & Redress

Tanzania's data-protection enforcement architecture escalated materially in 2026. After the PDPC set and enforced a final registration deadline of 8 April 2026 (with the PDPA becoming fully enforceable from 9 April 2026), the Commission commenced on-site compliance inspections of data controllers and processors from 31 August 2026 -- the first substantive enforcement-activity wave under the Act. These inspections examine DPO appointment and function, and separately examine cross-border transfer procedures under sections 31-32.

The statutory penalty architecture underpinning this enforcement activity, found in Chapter 44 of the PDPA, provides for fines ranging from TZS 100,000 to TZS 20,000,000, imprisonment of up to 10 years, or both, for violations. This is a wide penalty band spanning administrative-level fines through custodial sanctions, and its existence as a backstop is what gives the registration deadline and subsequent inspections their practical force. As of this cycle, however, no publicly disclosed instance of a penalty actually having been imposed following the August 2026 inspections was located; the enforcement record to date consists of the deadline-enforcement and inspection-commencement steps themselves, not yet a disclosed sanctions outcome.

Outlook

The next material development to watch for is whether any inspection conducted since 31 August 2026 results in a publicly disclosed fine, prosecution referral, or other sanction under the Chapter 44 schedule. Such a disclosure would convert PDPC's current verification-stage posture into a tested enforcement record and would be the clearest signal of the practical rigor behind the new inspection regime.

Sources and claims (3)
  1. ProbableDataGuidance (OneTrust) — The Cybercrimes Act, 2015 provides for offenses related to violations of privacy against or using a computer system located in Tanzania, operating alongside the PDPA.observed
  2. ProbableDataGuidance (OneTrust) — Data processors that fail to register with the PDPC by the April 9, 2026 enforcement date face significant fines under Tanzania's PDPA enforcement framework.observed
  3. ProbableDataGuidance (OneTrust) — The PDPC has begun the registration of data collectors and processors as part of its enforcement rollout ahead of the April 2026 compliance deadline.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metwaived
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct37.5
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Tanzania
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 12 claim(s) (12 category placement(s)), 13 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (36 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework and enforcement_and_redress achieved T3-sourced, dated coverage (Act passage/entry-into-force, implementing regulations, and the April 9, 2026 registration-enforcement development). controller_processor_duties and cross_border_and_adequacy achieved partial coverage limited to a general 'data security' and 'international data transfers' statement, with all granular sub-obligations (DPIA, DPO, ROPA, breach timelines, transfer mechanisms, localisation) unconfirmed. sectoral_watch achieved partial coverage (financial via BOT Credit Reference Bureau Regulations 2012; telecoms via EPOCA/TCRA), with health, employment, education, and insurance overlays unconfirmed. lawful_processing_and_special_data, data_subject_rights, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, and children_and_vulnerable_groups relied entirely on absent_field_provenance — no qualifying English-language secondary source was retrieved covering these areas for Tanzania; the underlying PDPA and its regulations are published only in Kiswahili and were not directly parsed in this run.

Unresolved questions (9):

  • What are the specific penalty amounts (fines/imprisonment) prescribed under the PDPA for non-compliance, beyond the general reference to 'significant fines' for registration failure?
  • Does the PDPA mandate DPO appointment, and if so, under what thresholds?
  • What are the DPIA trigger criteria, if any, under the PDPA or its regulations?
  • What is the statutory breach-notification timeline (to PDPC and to data subjects) under the PDPA?
  • What specific cross-border transfer mechanisms (adequacy-equivalent test, contractual clauses, derogations) does the PDPA recognize, and is there a data-localisation mandate?
  • What are the enumerated lawful bases, consent standards, and special-category (sensitive data) rules under the PDPA?
  • Does the PDPA or subsidiary regulation address children's data, minimum processing age, or parental consent?
  • Is there a verifiable official PDPC homepage/registration-portal URL distinct from the referenced Kiswahili-language Government Notices?
  • Is the establishing body properly named 'Personal Data Protection Commission' or 'Personal Data Protection Committee' — source materials use both terms inconsistently.

Escalate to primary-source review: yes