Skip to the content
Global Data RulesData governance rules, country by country

Tanzania

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.

The answer

Yes, with paperworkWork: HighEnforcement: Waking up

Data can leave Tanzania, but only after the privacy regulator grants a permit for that exact transfer. No country is pre-approved, so each move abroad is its own application. Before you process anything you must register with the regulator and name a data protection officer, who then reports every three months. Some industries must keep their main systems in the country.

Data governance in Tanzania

The eight things that decide how you handle data about people in Tanzania. Same eight on every country page, so you can compare.

Who has to follow these rules

It can reach a foreign company, but the test is narrower than in Europe. The law covers anyone who is based in Tanzania, and also covers a company that is not based in Tanzania if the processing itself happens inside the country. Simply passing data through Tanzania on the way somewhere else does not count. There is no size or revenue threshold to fall below, and no separate rule forcing a foreign firm to appoint a local representative.

High confidenceNational rulesControllerProcessor

Where the data is allowed to live

Yes, but you must ask first, every time. Tanzania does not publish a list of countries that are automatically safe, so there is no shortcut: you apply to the privacy regulator for a permit naming the exact data, the exact recipient and the exact destination. The regulator says it had issued about 39 of these permits by May 2026. Four industries are stricter still — banking, payments, online gambling and government — because their main systems have to be physically in Tanzania whatever any permit says.

High confidenceYes, with paperworkApproval each timeGovernment sign-off needed

Sending data out of the country

The model is case-by-case permission. There is no approved-country list to rely on and no standard contract you can just sign, so nothing lawful leaves the country until the regulator says yes to that specific transfer. You apply with the type of data, the purpose, the recipient, the destination country, proof that the destination protects data properly, evidence of a binding contract with the recipient, and the person's consent. The regulator has fourteen days to decide and the permit only covers the recipient it names.

High confidenceApproval each timeGovernment sign-off neededExplicit consentNeeded for a contractLegal claims

The regulator, and whether it actually acts

The Personal Data Protection Commission, based in Dodoma, is the main regulator. It is genuinely up and running: it has a director general, a governing board with named members, an online registration system, and by May 2026 it reported over fourteen thousand registered organisations, more than three hundred and forty complaints received and thirty-nine transfer permits granted. What is missing is published punishment — its own decisions page was empty when checked, so we cannot show a single fine actually imposed. Other regulators police their own industries: the central bank, the communications authority, the gaming board and the e-Government Authority.

High confidenceWaking upRegulator

How long you must keep it — and when to delete it

The floor is set by other laws, and in finance it is long: banks, insurers and other firms covered by the money-laundering rules must keep customer and transaction records for at least ten years, and payment providers must keep every transaction record for at least ten years too. The ceiling comes from the privacy law, which says personal data may only be kept for the period the relevant law or regulations set, and only in a form that identifies people for as long as the purpose needs. Where the two collide the specific keeping period in the sector law wins, and you delete when that clock runs out rather than earlier.

High confidenceKeep data for a minimum periodDelete data after a period

If something goes wrong

The privacy law gives you no clock in hours. It says only that you must tell the regulator about a security breach affecting personal data without undue delay, and it does not require you to tell the affected people at all. Treat twenty-four to seventy-two hours as the safe reading, because there is no published guidance setting a number. Separately, the police can order you to freeze data for up to fourteen days during an investigation, and licensed communications companies have their own reporting duties to the national cyber incident team.

Medium confidenceReport breaches to the regulatorReport cyber incidents

What catches people out

Five things cost people their weekend here. The criminal fine is fifty times the regulator's fine, and directors are personally on the hook. Every single organisation must appoint a data protection officer who then files a report to the regulator every three months. You cannot register without Tanzanian company papers, and you cannot lawfully process anything until you are registered. Every organisation must also write its own code of ethics and get the regulator to approve it. And the police can demand your data without a court order.

High confidenceCriminal liabilityAppoint a data protection officerRegister or notifyGet consentChildren's data

What's changing next

Nothing big is scheduled in the next twelve months that we could verify. The most recent change already landed: from the first of July 2026 the rules on online media services were widened, so more online publishers need a licence from the communications regulator. The bigger risk is what the government can already do without warning. The minister can write regulations naming types of data that may never leave the country, the privacy regulator can ban transfers to a whole destination, and it can refuse any permit on national security grounds.

Medium confidenceIn forceDirectly binding regulation

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries5 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Payments

The Payment Systems (Licensing and Approval) Regulations, 2015

Directly binding regulation · Made under section 56(1), (2)(a) and (b) of the National Payment Systems Act, 2015

In forceA copy must stay

Every licensed payment system provider must keep its primary data centre for payment services inside Tanzania, and must keep transaction records for at least ten years. This is a location rule on the main system, not just a copy rule.

In force since 1 January 2015

Enforced by Bank of Tanzania

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence
Banking

Outsourcing Guidelines for Banks and Financial Institutions, 2021

Regulator guideline · Issued under section 71 of the Banking and Financial Institutions Act, 2006

In forceA copy must stay

Banks and financial institutions in Tanzania cannot put their primary data centre outside the country. Offshore arrangements are treated as outsourcing even when the supplier is the bank's own foreign head office or a group company.

In force since 30 June 2021

Enforced by Bank of Tanzania

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence
Online gaming

The Gaming (Internet Gaming) Regulations, 2022

Directly binding regulation · GN No. 478T published on 1 July 2022, made under section 85 of the Gaming Act, Chapter 41

In forceA copy must stay

Online gambling operators must run their main server inside Mainland Tanzania, keep a staffed administration office in the country, and get the regulator's approval for the hosting setup. Hosting abroad is only a time-limited exception and requires a mirror server at home.

In force since 1 July 2022

Enforced by Gaming Board of Tanzania

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Applies to every company1 rule

These bind you whatever business you are in, once the country's rules reach you.

The Personal Data Protection Act, 2022 / Sheria ya Ulinzi wa Taarifa Binafsi

Act of parliament · Act No. 11 of 2022, Chapter 44; English version published as GN No. 395B of 13 June 2023; read with the Personal Data Protection (Personal Data Collection and Processing) Regulations, 2023, GN No. 449C of 4 July 2023

In forceYes, with paperwork

Tanzania's general privacy law. You must register with the regulator before you process anything, appoint a data protection officer who reports to the regulator every three months, get your own code of ethics approved, and obtain a permit for each transfer of data out of the country. The regulator's own fines are modest, but the criminal offences behind them reach five billion shillings for a company and prison for individuals.

In force since 1 May 2023But only enforceable from 1 May 2025

Enforced by Personal Data Protection Commission

Transfer model: Approval each time · Accepted routes: Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, Important public interest

High confidence

Who you would hear from

  • Tume ya Ulinzi wa Taarifa Binafsi

    General privacy law: registration of controllers and processors, cross-border transfer permits, complaints, determinations and penalty notices

    Fully constituted and working. Director General Dr. Emmanuel Lameck Mkilia; a board with a chairman, vice-chairman and five named members; offices in Dodoma; online registration system. Self-reported figures as at May 2026: 14,400+ registered organisations, 340+ complaints received, 39+ transfer permits, 4+ determinations. Enforcement phase began 1 May 2025 per its own public notice. However, no determination or penalty decision was published on its determinations page as at 18 August 2026, so enforcement output cannot be independently evidenced.

  • Benki Kuu ya Tanzania

    Banking, payment systems, electronic money, anti-money laundering record keeping

    Long-established supervisor. Publishes acts, regulations, circulars and guidelines on its own site and licenses payment system providers.

  • Mamlaka ya Mawasiliano Tanzania

    Telecommunications, broadcasting, online content and online media licensing, public data centres, cybersecurity service licences, national computer emergency response team

    Highly active rule-maker: seven new or amended regulations published between January 2025 and June 2026, including the online content amendment in force from 1 July 2026.

  • Mamlaka ya Serikali Mtandao

    Public sector systems, government hosting environment, public sector ICT security standards

  • Bodi ya Michezo ya Kubahatisha Tanzania

    Gaming and internet gaming licences, including server location and hosting approval

  • Mamlaka ya Usimamizi wa Bima Tanzania

    Insurance supervision, including outsourcing rules in the corporate governance guidelines

    Active and publishing guidelines through 2026, but no insurance-specific data localisation or storage rule was found in its published guidelines as at 18 August 2026.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • Whether the Personal Data Protection Commission has actually imposed any fine or issued any published determination

    The Commission's homepage counter claims 4 or more determinations as at May 2026, but its determinations page listed no documents when checked on 18 August 2026 and we found no named enforcement decision on any government site. The enforcement rating of 'waking' rests on this gap.

  • The exact deadline for reporting a personal data breach

    The Act says 'without any undue delay' and the 2023 Regulations set no hour figure. No guidance document setting a number was found on the Commission's own site. Any specific hour count you see elsewhere is somebody's inference.

  • Incident reporting duties and deadlines to the national computer emergency response team

    Only the 2025 amending regulations (GN No. 56) are published on the communications regulator's own site; the principal Computer Emergency Response Team Regulations 2018 (GN No. 60 of 2018) could not be retrieved from a government domain during this run.

  • Whether any country has been recognised as having adequate data protection, or any destination banned

    No adequacy list and no prohibition notice was found on the Commission's site. We infer from the permit procedure that adequacy is assessed inside each application, which is consistent with the 39 permits reported, but the absence of a list is a negative we cannot fully prove.

  • Whether the transfer permit is legally required where a statutory exception such as consent or contract necessity applies

    The Act's exceptions and the Regulations' permit procedure are not reconciled in the text, and no regulator guidance or court decision resolving the overlap was found. Treat the permit as required.

  • Sector storage rules in health, education, insurance, securities, mapping and defence

    Checked the insurance regulator's published guidelines, the capital markets authority's publications, the health ministry site and the lands ministry's survey and mapping pages on 18 August 2026 and found no data localisation or storage rule. Several of these sites are difficult to search automatically, so this is 'not found', not 'does not exist'.

  • General tax and company record-keeping minimum periods

    The revenue authority's site could not be navigated to a published Tax Administration Act record-keeping provision during this run. The ten-year floors cited are the money-laundering and payment-systems ones, which are verified.

  • How the law applies in Zanzibar for non-union matters, and whether Zanzibar has its own data protection instrument

    The Act states it does not apply in Zanzibar to non-union matters, but we did not locate a Zanzibar-specific data protection law or regulator on a government domain.

  • Government notice number and exact commencement date of the Payment Systems (Licensing and Approval) Regulations 2015

    The copy published on the central bank's own site is the version with a blank government notice number and date line. The substance is verified; the citation details are not.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Tanzania versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.