Skip to the content
Global Data RulesData governance rules, country by country

Tanzania

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Tanzania — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: HighEnforcement: Waking up

You can send data out of Tanzania, but only after the privacy regulator grants a permit for that exact transfer. No country is pre-approved. Each move abroad is its own application. Before you collect or use any data, you must register with the regulator. You must also name a data protection officer, who then reports every three months. Some industries must keep their main systems in the country.

Data governance in Tanzania

The eight things that decide how you handle data about people in Tanzania. Same eight on every country page, so you can compare.

Who has to follow these rules

It can reach a foreign company, but the test is narrower than in Europe. The law covers anyone based in Tanzania. It also covers a company that is not based in Tanzania, if the data is handled inside the country. Simply passing data through Tanzania on the way somewhere else does not count. There is no size or revenue cut-off. There is no separate rule making a foreign firm appoint a local representative.

Where the data is allowed to live

Yes, but you must ask first, every time. Tanzania publishes no list of countries that are automatically safe. You apply to the privacy regulator for a permit. The permit names the exact data, the exact recipient and the exact destination. The regulator says it had issued about 39 of these permits by May 2026. Four industries are stricter still: banking, payments, online gambling and government. Their main systems must be physically in Tanzania, whatever any permit says.

Ways to send data out:
Government sign-off needed

What to do: Get the paperwork for one of the routes below signed before any data leaves Tanzania.

Sending data out of the country

You need permission for each transfer. There is no approved-country list to rely on. There is no standard contract you can just sign. Nothing leaves the country lawfully until the regulator says yes to that specific transfer. Your application sets out the type of data, the purpose, the recipient and the destination country. You also need proof that the destination protects data properly, evidence of a binding contract with the recipient, and the person's consent. The regulator has fourteen days to decide. The permit only covers the recipient it names.

Ways to send data out:
Government sign-off needed · Explicit consent · Needed for a contract · Legal claims

What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.

The regulator, and whether it actually acts

The Personal Data Protection Commission, based in Dodoma, is the main regulator. It is up and running. It has a director general, a governing board with named members, and an online registration system. By May 2026 it reported over fourteen thousand registered organisations, more than three hundred and forty complaints received, and thirty-nine transfer permits granted. What is missing is published punishment. Its own decisions page was empty when we checked, so we cannot show a single fine actually imposed. Other regulators police their own industries: the central bank, the communications authority, the gaming board and the e-Government Authority.

How long you must keep it — and when to delete it

Minimum keep times come from other laws, and in finance they are long. Banks, insurers and other firms covered by the money-laundering rules must keep customer and transaction records for at least ten years. Payment providers must keep every transaction record for at least ten years too. The maximum comes from the privacy law. It says personal data may only be kept for the period the relevant law or regulations set. Data may identify people only for as long as the purpose needs. Where the two clash, the specific keep period in the industry law wins. You delete when that period runs out, not earlier.

What you have to do here:
Keep data for a minimum period · Delete data after a period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

The privacy law gives you no deadline in hours. It says only that you must tell the regulator about a security breach affecting personal data, without undue delay. It does not require you to tell the people affected at all. Treat twenty-four to seventy-two hours as the safe reading, because no published guidance sets a number. Separately, the police can order you to freeze data for up to fourteen days during an investigation. Licensed communications companies have their own reporting duties to the national cyber incident team.

What you have to do here:
Report breaches to the regulator · Report cyber incidents

What to do: Your breach process has to reach Tanzania's regulator inside the deadline above.

Not fully verified — see “What we're not sure about” below.

What catches people out

Five things catch people out here. The criminal fine is fifty times the regulator's fine, and directors are personally liable. Every organisation must appoint a data protection officer. That officer then files a report to the regulator every three months. You cannot register without Tanzanian company papers, and you cannot lawfully use any data until you are registered. Every organisation must also write its own code of ethics and get the regulator to approve it. And the police can demand your data without a court order.

What you have to do here:
Appoint a data protection officer · Register or notify · Get consent
What it costs if you get it wrong:
Criminal liability

What's changing next

Nothing big is scheduled in the next twelve months that we could verify. The most recent change has already landed. From 1 July 2026 the rules on online media services were widened. More online publishers now need a licence from the communications regulator. The bigger risk is what the government can already do without warning. The minister can write regulations naming types of data that may never leave the country. The privacy regulator can ban transfers to a whole destination. It can also refuse any permit on national security grounds.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries5 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Payments

Payments data needs a copy kept in the country

Official name: The Payment Systems (Licensing and Approval) Regulations, 2015 · Made under section 56(1), (2)(a) and (b) of the National Payment Systems Act, 2015 · Directly binding regulation

In forceA copy must stay

Every licensed payment system provider must keep its primary data centre for payment services inside Tanzania, and must keep transaction records for at least ten years. This is a location rule on the main system, not just a copy rule.

In force since 1 January 2015

Enforced by Bank of Tanzania

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Banking

Cloud and outsourcing rules

Official name: Outsourcing Guidelines for Banks and Financial Institutions, 2021 · Issued under section 71 of the Banking and Financial Institutions Act, 2006 · Regulator guideline

In forceA copy must stay

Banks and financial institutions in Tanzania cannot put their primary data centre outside the country. Offshore arrangements are treated as outsourcing even when the supplier is the bank's own foreign head office or a group company.

In force since 30 June 2021

Enforced by Bank of Tanzania

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Online gaming

Online gaming data needs a copy kept in the country

Official name: The Gaming (Internet Gaming) Regulations, 2022 · GN No. 478T published on 1 July 2022, made under section 85 of the Gaming Act, Chapter 41 · Directly binding regulation

In forceA copy must stay

Online gambling operators must run their main server inside Mainland Tanzania. They must keep a staffed administration office in the country. They must also get the regulator's approval for the hosting setup. Hosting abroad is only a time-limited exception and requires a mirror server at home.

In force since 1 July 2022

Enforced by Gaming Board of Tanzania

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Applies to every company1 rule

These bind you whatever business you are in, once the country's rules reach you.

Rules for sending data abroad

Official name: The Personal Data Protection Act, 2022 / Sheria ya Ulinzi wa Taarifa Binafsi · Act No. 11 of 2022, Chapter 44; English version published as GN No. 395B of 13 June 2023; read with the Personal Data Protection (Personal Data Collection and Processing) Regulations, 2023, GN No. 449C of 4 July 2023 · Act of parliament

In forceYes, with paperwork

This is Tanzania's general privacy law. You must register with the regulator before you use any data. You must appoint a data protection officer, who reports to the regulator every three months. You must get your own code of ethics approved. And you need a permit for each transfer of data out of the country. The regulator's own fines are modest. The criminal offences behind them reach five billion shillings for a company, and prison for individuals.

In force since 1 May 2023Enforced from 1 May 2025

Enforced by Personal Data Protection Commission

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, Important public interest

Who you would hear from

  • Tume ya Ulinzi wa Taarifa Binafsi

    General privacy law: registration of controllers and processors, cross-border transfer permits, complaints, determinations and penalty notices

    Fully set up and working. The Director General is Dr. Emmanuel Lameck Mkilia. The board has a chairman, a vice-chairman and five named members. It has offices in Dodoma and an online registration system. Its own figures as at May 2026: over 14,400 registered organisations, over 340 complaints received, at least 39 transfer permits, and at least 4 determinations. Its own public notice says the enforcement phase began on 1 May 2025. But no determination or penalty decision was published on its determinations page as at 18 August 2026. So we cannot independently show what it has enforced.

  • Benki Kuu ya Tanzania

    Banking, payment systems, electronic money, anti-money laundering record keeping

    Long-established supervisor. Publishes acts, regulations, circulars and guidelines on its own site and licenses payment system providers.

  • Mamlaka ya Mawasiliano Tanzania

    Telecommunications, broadcasting, online content and online media licensing, public data centres, cybersecurity service licences, national computer emergency response team

    Highly active rule-maker: seven new or amended regulations published between January 2025 and June 2026, including the online content amendment in force from 1 July 2026.

  • Mamlaka ya Serikali Mtandao

    Public sector systems, government hosting environment, public sector ICT security standards

  • Bodi ya Michezo ya Kubahatisha Tanzania

    Gaming and internet gaming licences, including server location and hosting approval

  • Mamlaka ya Usimamizi wa Bima Tanzania

    Insurance supervision, including outsourcing rules in the corporate governance guidelines

    Active and publishing guidelines through 2026. We found no insurance rule in its published guidelines about where data must be stored, as at 18 August 2026.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Whether the Personal Data Protection Commission has actually imposed any fine or issued any published determination

    We could not confirm any enforcement decisions. The Commission's homepage counter claims 4 or more determinations as at May 2026. But its determinations page listed no documents when we checked on 18 August 2026. We found no named enforcement decision on any government site. Our enforcement rating of 'waking' rests on this gap.

  • The exact deadline for reporting a personal data breach

    We could not confirm a deadline in hours for reporting a breach. The Act says 'without any undue delay', and the 2023 Regulations set no hour figure. We found no guidance setting a number on the Commission's own site. Any specific hour count you see elsewhere is someone's inference.

  • Incident reporting duties and deadlines to the national computer emergency response team

    We could not confirm the incident reporting deadline for the communications industry. Only the 2025 amending regulations (GN No. 56) are published on the communications regulator's own site. We could not retrieve the main Computer Emergency Response Team Regulations 2018 (GN No. 60 of 2018) from a government website. If you hold a communications licence, ask the Authority.

  • Whether any country has been recognised as having adequate data protection, or any destination banned

    We could not confirm that there is no approved-country list. We found no list and no ban notice on the Commission's site. The permit procedure suggests each application is judged on its own, which fits the 39 permits reported. But we cannot fully prove that no list exists.

  • Whether the transfer permit is legally required where a statutory exception such as consent or contract necessity applies

    We could not confirm whether the Act's exceptions remove the need for a permit. The Act's exceptions and the Regulations' permit procedure are not reconciled in the text. We found no regulator guidance or court decision settling the overlap. Treat the permit as required.

  • Sector storage rules in health, education, insurance, securities, mapping and defence

    We found no rule about where data must be stored in these industries. On 18 August 2026 we checked four sources. The insurance regulator's published guidelines. The capital markets authority's publications. The health ministry site. And the lands ministry's survey and mapping pages. Several of those sites are hard to search automatically. Treat this as a rule we could not find, not proof that none exists.

  • General tax and company record-keeping minimum periods

    We could not confirm a tax record-keeping period. We could not reach a published Tax Administration Act record-keeping rule on the revenue authority's site. The ten-year minimums we cite come from the money-laundering and payment-systems rules, and those are verified. Ask the revenue authority if tax records matter to you.

  • How the law applies in Zanzibar for non-union matters, and whether Zanzibar has its own data protection instrument

    We could not confirm what applies in Zanzibar for non-union matters. The Act says it does not apply there for those matters. We did not find a Zanzibar-specific data protection law or regulator on a government website. If you operate in Zanzibar, check locally.

  • Government notice number and exact commencement date of the Payment Systems (Licensing and Approval) Regulations 2015

    We could not confirm the citation details of this document. The copy published on the central bank's own site has a blank government notice number and date line. The substance is verified. The citation details are not.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.