Tanzania
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
Data can leave Tanzania, but only after the privacy regulator grants a permit for that exact transfer. No country is pre-approved, so each move abroad is its own application. Before you process anything you must register with the regulator and name a data protection officer, who then reports every three months. Some industries must keep their main systems in the country.
Data governance in Tanzania
The eight things that decide how you handle data about people in Tanzania. Same eight on every country page, so you can compare.
Who has to follow these rules
It can reach a foreign company, but the test is narrower than in Europe. The law covers anyone who is based in Tanzania, and also covers a company that is not based in Tanzania if the processing itself happens inside the country. Simply passing data through Tanzania on the way somewhere else does not count. There is no size or revenue threshold to fall below, and no separate rule forcing a foreign firm to appoint a local representative.
Personal Data Protection Act, Chapter 44 (Act No. 11 of 2022), section 24(1)(b) and (c): the Act reaches processing by a controller domiciled in the United Republic, and processing by a controller or processor NOT domiciled in the United Republic 'if the processing of the personal data is in United Republic and such processing is not for the purposes of mere transit of personal data through Tanzania to another country'. This is a location-of-processing test, not the targeting test used in the European Union or India, so a pure offshore software-as-a-service provider with no local processing has a genuine argument that it falls outside. In practice the argument is academic for anyone with staff, agents or infrastructure in-country, because section 14 bars any collection or processing without registration. The definitions of 'data controller' and 'data processor' in the 2023 Regulations each end with the words 'and it includes his representative', which pulls a local agent into the same duties. Note the practical gate: the regulator's registration process requires a Business Registrations and Licensing Agency certificate, a Tanzanian Taxpayer Identification Number certificate and audited accounts, so registering without a Tanzanian legal entity is difficult. The Act applies to Mainland Tanzania and to Zanzibar, but in Zanzibar only for union matters.
Sources
- Official sourcePersonal Data Protection CommissionPersonal Data Protection Act, Chapter 44 (Act No. 11 of 2022), sections 2, 14 and 24
pdpc.go.tz
“the processing of personal data by a data controller or data processor who is not domiciled in the United Republic, if the processing of the personal data is in United Republic and such processing is not for the purposes of mere transit of personal data through Tanzania to another country.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionRegistration service — documents required to register as a data controller or processor
pdpc.go.tz
“For Private organizations, they are required to have three documents, which are the organization BRELA certificate, Tax Identification Number certificate and financial year audited report”
Link checked 18 August 2026
Where the data is allowed to live
Yes, but you must ask first, every time. Tanzania does not publish a list of countries that are automatically safe, so there is no shortcut: you apply to the privacy regulator for a permit naming the exact data, the exact recipient and the exact destination. The regulator says it had issued about 39 of these permits by May 2026. Four industries are stricter still — banking, payments, online gambling and government — because their main systems have to be physically in Tanzania whatever any permit says.
General rule: Personal Data Protection Act sections 31 and 32 allow transfer to a country with adequate protection, and to a country without it only where the recipient country's protection is assessed as adequate, or one of the narrow exceptions applies (the person consented, the transfer is needed for a contract, for legal claims, on public interest grounds, or to protect the person's own interests), or the Commission is satisfied that contractual and security safeguards make up the difference. Section 31(1) also lets the Commission simply prohibit transfer of personal data to a place outside the country. The 2023 Regulations turn this into a per-transfer licence: regulation 20 requires a written application on Form No. 7 before any transfer, the Commission has 14 days to decide, and an approved transfer is documented on a permit (Form No. 8). Regulation 22 fixes the conditions: named recipient only, stated purpose only, no onward transfer without further approval. Regulation 21 lets the Commission refuse where the transfer endangers national security or another written law restricts it. SECTOR OVERRIDES: - Banking (a copy must stay in the country, in practice a hard wall for the primary site): the Bank of Tanzania's Outsourcing Guidelines 2021 list 'primary data centre outside the country' among the things a bank or financial institution may not outsource. - Payments and electronic money (a copy must stay in the country): Payment Systems (Licensing and Approval) Regulations 2015, regulation 42 — a payment system provider shall place its primary data centre for payment system services in Tanzania. - Online gambling (a copy must stay in the country): Gaming (Internet Gaming) Regulations 2022, regulation 9 — the licensee's primary server must be in Mainland Tanzania; if the Board temporarily allows it abroad, a replica server must be physically in Mainland Tanzania and the financial control system must stay in Mainland Tanzania. - Government and public bodies (data must stay in the country in practice): e-Government Act 2019 sections 25 and 45 — public institutions must host systems in the Government approved hosting environment and use government processing and hosting facilities or a government-approved supplier environment only. - Telecommunications (data can leave with paperwork plus a licensing layer): mobile operators' subscriber registration systems must be permanently connected to the national identity authority, the immigration department and the regulator's central subscriber database, which in practice pins the registration system to Tanzania. Anyone selling data centre space to the public needs a network facility licence from the communications regulator. - Insurance and securities: no localisation or storage rule found on the insurance or capital markets regulators' own sites, checked 18 August 2026. The general permit rule still applies. - Health, education, mapping and defence: no sector-specific data storage rule found on the relevant ministries' own sites, checked 18 August 2026. Confidence medium — absence of a published rule is not proof there is none.
Sources
- Official sourcePersonal Data Protection CommissionPersonal Data Protection (Personal Data Collection and Processing) Regulations, 2023, GN No. 449C, regulations 20 to 22
pdpc.go.tz
“A data controller or data processor who intends to transfer personal data outside the country, shall submit an application for permit to the Commission using Form No. 7 set out in the First Schedule to these Regulations.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionCross-border data transfer permit — service description and application procedure
pdpc.go.tz
“Issues permits to entities intending to transfer personal data outside the country”
Link checked 18 August 2026
- Official sourceBank of TanzaniaOutsourcing Guidelines for Banks and Financial Institutions, 2021, paragraph 10(g)
bot.go.tz
“Banks and financial institutions shall not outsource the following: ... (g) Primary data centre outside the country.”
Link checked 18 August 2026
- Official sourceGaming Board of TanzaniaGaming (Internet Gaming) Regulations, 2022, GN No. 478T, regulation 9
gamingboard.go.tz
“A licensee shall have its primary server located within Mainland Tanzania.”
Link checked 18 August 2026
Sending data out of the country
The model is case-by-case permission. There is no approved-country list to rely on and no standard contract you can just sign, so nothing lawful leaves the country until the regulator says yes to that specific transfer. You apply with the type of data, the purpose, the recipient, the destination country, proof that the destination protects data properly, evidence of a binding contract with the recipient, and the person's consent. The regulator has fourteen days to decide and the permit only covers the recipient it names.
Model: approval each time. There is no populated allowlist and no published adequacy decision for any country as at 18 August 2026 — the Commission assesses adequacy inside each application instead, using the factors in section 32(2) of the Act (nature of the data, purpose and duration, the recipient's country, the laws in force there, and the professional rules and security measures applied there). Practical mechanics under regulation 20 of the 2023 Regulations: application on Form No. 7; the applicant must also produce proof that the destination country has ratified an international data protection agreement, or that Tanzania has an agreement with that country, or that there is a contract between the sender and the overseas recipient. Decision within 14 days; approval issued on Form No. 8; onward transfer to a further recipient needs fresh approval. The statutory exceptions in section 32(4) — consent, contract necessity, legal claims, public interest, protecting the person's interests — exist in the Act, but the Regulations impose the permit procedure without carving those cases out, so relying on an exception alone and skipping the permit is a live risk rather than a settled route. The Commission reported roughly 39 transfer permits issued as at May 2026, which is a small number relative to about 14,400 registered organisations: most cross-border processing in Tanzania is therefore probably unpermitted.
Sources
- Official sourcePersonal Data Protection CommissionPersonal Data Protection (Personal Data Collection and Processing) Regulations, 2023, GN No. 449C, regulation 20(3) and (4)
pdpc.go.tz
“The Commission shall consider the application submitted under subregulation (1) within a period of fourteen days after receiving the application”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionPersonal Data Protection Act, Chapter 44, sections 31 and 32
pdpc.go.tz
“The Commission may, subject to the provisions of this Act, prohibit the transfer of personal data to a place outside the country.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionPersonal Data Protection Commission homepage — 39+ data transfer permits, 14400+ registered organisations, May 2026 figures
pdpc.go.tz
“39+ Data Transfer Permits Offered - May 2026”
Link checked 18 August 2026
The regulator, and whether it actually acts
The Personal Data Protection Commission, based in Dodoma, is the main regulator. It is genuinely up and running: it has a director general, a governing board with named members, an online registration system, and by May 2026 it reported over fourteen thousand registered organisations, more than three hundred and forty complaints received and thirty-nine transfer permits granted. What is missing is published punishment — its own decisions page was empty when checked, so we cannot show a single fine actually imposed. Other regulators police their own industries: the central bank, the communications authority, the gaming board and the e-Government Authority.
Personal Data Protection Commission: established by section 6 of the Act, sits under the Ministry of Communication and Information Technology, offices at 1 Moshi Street, Viwandani, Dodoma. Director General Dr. Emmanuel Lameck Mkilia. The board is constituted with a chairman, vice-chairman and five members named on the Commission's own site. Observable activity in the last twelve months: a first national data privacy conference held in Dar es Salaam from 29 June to 1 July 2026, a data protection officer training programme run with the Open University of Tanzania, and a certified-officer scheme announced. Why the rating is 'waking' and not 'active': the Act commenced on 1 May 2023; the Commission's own public notice of 10 January 2025 said voluntary registration ended on 31 December 2024, gave a final registration deadline of 30 April 2025, and said that from 1 May 2025 the Commission, working with law enforcement, would begin taking legal action against non-compliant institutions. So the enforcement phase formally began over a year ago and the registration volume shows real engagement. But the Commission's 'Determinations' page carried no published decisions when checked on 18 August 2026, and we found no published monetary penalty against any named organisation. A regulator that processes registrations and complaints but publishes no penalties is waking, not active. Sector regulators with their own powers over data: Bank of Tanzania (banking, payments, electronic money — licence conditions and revocation), Tanzania Communications Regulatory Authority (telecoms, online content, public data centres, cybersecurity service licences), Gaming Board of Tanzania (internet gaming servers), e-Government Authority (public sector systems and hosting). Police also hold direct powers over data under the Cybercrimes Act 2015.
Sources
- Official sourcePersonal Data Protection CommissionPersonal Data Protection Commission — activity figures as at May 2026
pdpc.go.tz
“14400 + Number of Registered Organizations - May 2026 ... 340 + Complaints Received - May 2026 ... 4+ Determinations - May 2026”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionPublic notice: compliance with registration requirements, 10 January 2025 (Swahili)
pdpc.go.tz
“Kuanzia tarehe 1 Mei, 2025, PDPC kwa kushirikiana na vyombo vya utekelezaji wa sheria, itaanza kuchukua hatua za kisheria dhidi ya taasisi zote ambazo hazijazingatia matakwa ya Sheria husika.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionDeterminations page — no decisions published as at 18 August 2026
pdpc.go.tz
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionBoard of the Personal Data Protection Commission — named members
pdpc.go.tz
Link checked 18 August 2026
How long you must keep it — and when to delete it
The floor is set by other laws, and in finance it is long: banks, insurers and other firms covered by the money-laundering rules must keep customer and transaction records for at least ten years, and payment providers must keep every transaction record for at least ten years too. The ceiling comes from the privacy law, which says personal data may only be kept for the period the relevant law or regulations set, and only in a form that identifies people for as long as the purpose needs. Where the two collide the specific keeping period in the sector law wins, and you delete when that clock runs out rather than earlier.
FLOOR (minimum keeping periods, verified): - Anti-Money Laundering Regulations 2012, regulation 30: a reporting person shall retain records required by section 16 of the Anti-Money Laundering Act for a minimum of ten years. Insurers are separately directed to ten years after termination of a business relationship and ten years after completion of a transaction. - Payment Systems (Licensing and Approval) Regulations 2015, regulation 41: payment system providers keep records of all transactions for not less than ten years from the date of the transaction. - Telecommunications: under the 2025 subscriber registration rules an operator must keep the information gathered on a line replacement in an easily accessible database for twelve months. CEILING (when you must stop keeping it): - Personal Data Protection Act section 28: personal data is retained for the period specified in the relevant laws or prescribed in regulations, so that the person has a reasonable opportunity to access it; the Minister may prescribe retention and disposal rules matching the purpose. - 2023 Regulations, regulation 23: personal data must be stored in a form which permits identification of people only as long as necessary, and must not be transferred abroad contrary to the Act. CONFLICT RULE: there is no general override clause. In practice the sector minimum is a statutory obligation the privacy law expressly defers to (section 28 points outward to 'the relevant laws'), so the ten-year finance clocks beat any argument for early deletion, and a deletion request from an individual does not shorten them. We did not find a published Tanzania Revenue Authority record-keeping period on the revenue authority's own site during this run.
Sources
- Official sourceBank of TanzaniaAnti-Money Laundering Regulations, 2012, regulation 30 (records retention period)
bot.go.tz
“A reporting person shall retain records required by section 16 of the Act for a minimum period of ten years”
Link checked 18 August 2026
- Official sourceBank of TanzaniaPayment Systems (Licensing and Approval) Regulations, 2015, regulation 41
bot.go.tz
“A payment system provider shall obtain records of all transactions conducted in the course of business and keep them for a period of not less than ten years from the date of the transaction.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionPersonal Data Protection Act, Chapter 44, section 28 (retention and disposal)
pdpc.go.tz
Link checked 18 August 2026
If something goes wrong
The privacy law gives you no clock in hours. It says only that you must tell the regulator about a security breach affecting personal data without undue delay, and it does not require you to tell the affected people at all. Treat twenty-four to seventy-two hours as the safe reading, because there is no published guidance setting a number. Separately, the police can order you to freeze data for up to fourteen days during an investigation, and licensed communications companies have their own reporting duties to the national cyber incident team.
CLOCK 1 — privacy regulator: Personal Data Protection Act section 27(5): 'The data controller shall notify the Commission, without any undue delay, of any security breach affecting personal data being processed by or on behalf of the data controller.' No hour figure appears in the Act or in the 2023 Regulations. There is no statutory duty to notify affected individuals — a real gap compared with most modern regimes, and one that does not remove the reputational and contractual pressure to tell them anyway. CLOCK 2 — criminal investigation: Cybercrimes Act 2015 section 33 lets a police officer in charge of a station order the person in control of a device or data to preserve it for up to fourteen days, extendable by a court. Section 32(1) lets that same officer order disclosure of data without going to court first. CLOCK 3 — communications sector: licensed operators and cybersecurity service providers deal with the national computer emergency response team under the Electronic and Postal Communications (Computer Emergency Response Team) Regulations 2018, amended by GN No. 56 of 31 January 2025. The amendment requires a licence for anyone providing cybersecurity services and gives a fourteen-day window to notify the Authority of changes. We could not retrieve the principal 2018 regulations from the Authority's own site during this run, so the incident-reporting deadline inside them is unverified. OVERLAP RISK: an incident at a licensed bank or payment provider can trigger the privacy notification, a supervisory notification to the central bank and a communications-sector report at the same time, on three different clocks, with the shortest one unwritten.
Sources
- Official sourcePersonal Data Protection CommissionPersonal Data Protection Act, Chapter 44, section 27(5)
pdpc.go.tz
“The data controller shall notify the Commission, without any undue delay, of any security breach affecting personal data being processed by or on behalf of the data controller.”
Link checked 18 August 2026
- Official sourceTanzania Communications Regulatory AuthorityElectronic and Postal Communications (Computer Emergency Response Team) (Amendment) Regulations, 2025, GN No. 56
tcra.go.tz
“A person who intends to provide cybersecurity services within the United Republic shall obtain an individual licence from the Authority”
Link checked 18 August 2026
- Official sourcee-Government AuthorityCybercrimes Act, 2015 (Act No. 14 of 2015), sections 32 and 33
ega.go.tz
“the police officer incharge of a police station or a law enforcement officer of a similar rank may issue an order requiring the person in control of a device or computer data to preserve the device or computer data for a period not exceeding fourteen days.”
Link checked 18 August 2026
What catches people out
Five things cost people their weekend here. The criminal fine is fifty times the regulator's fine, and directors are personally on the hook. Every single organisation must appoint a data protection officer who then files a report to the regulator every three months. You cannot register without Tanzanian company papers, and you cannot lawfully process anything until you are registered. Every organisation must also write its own code of ethics and get the regulator to approve it. And the police can demand your data without a court order.
TRAP 1 — the criminal fine dwarfs the administrative one. The Commission's maximum penalty notice is one hundred million Tanzanian shillings, roughly thirty-seven thousand United States dollars. But unlawfully disclosing, transmitting or selling personal data is a criminal offence: a company faces a fine of up to five billion shillings, roughly one point nine million dollars, and an individual up to ten years in prison. Under section 62 the company AND every officer who knowingly authorised or permitted the contravention are liable. The real exposure is criminal, not regulatory. TRAP 2 — a data protection officer for everyone, reporting quarterly to the state. Section 27(3) of the Act requires every controller and every processor to appoint one, with no size threshold. Regulation 32(c) of the 2023 Regulations then requires that officer 'to prepare and submit quarterly reports on the compliance of the Act to the Commission'. Four filings a year, from every registered organisation, is unusual and easy to miss. TRAP 3 — registration is a hard gate and a local-entity gate. Section 14: a person shall not collect or process personal data without being registered. Registration lasts five years, renewal must be applied for at least three months before expiry or you start again, and fees run from one hundred thousand shillings for a small organisation to one million shillings for a large one, roughly thirty-seven to three hundred and seventy dollars. The documents demanded — company registration certificate, taxpayer identification number, audited accounts — assume a Tanzanian entity. TRAP 4 — the code of ethics. Section 65: every data controller must draw up a code of ethics or policy for personal data protection and submit it to the Commission for consideration and approval. This is an approval, not a filing, and it is not satisfied by an off-the-shelf global privacy policy. TRAP 5 — sensitive data needs prior WRITTEN consent, and children's data is automatically sensitive. Section 30(1) forbids processing sensitive personal data without prior written consent, and the definition of sensitive personal data expressly includes data related to children as well as genetic data. Consent captured by a tick box is not written consent on any conservative reading. TRAP 6 — police access without a judge. Cybercrimes Act section 32(1): a police officer in charge of a station may order any person in possession of data to disclose it, for a criminal investigation, with court involvement only as a fallback if that order does not work. TRAP 7 — if you sell hosting, you must hand over your customer list. Anyone providing public data centre services needs a network facility licence from the communications regulator and must submit a list of all hosted customers to it every quarter.
Sources
- Official sourcePersonal Data Protection CommissionPersonal Data Protection Act, Chapter 44, sections 14, 27, 30, 47, 60, 62 and 65
pdpc.go.tz
“in the case of a company or corporation, a fine of not less than one million shillings but not exceeding five billion shillings.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionPersonal Data Protection (Personal Data Collection and Processing) Regulations, 2023, regulations 4 to 8, 32 and Second Schedule
pdpc.go.tz
“to prepare and submit quarterly reports on the compliance of the Act to the Commission”
Link checked 18 August 2026
- Official sourceTanzania Communications Regulatory AuthorityElectronic and Postal Communications (Licensing) (Amendment) Regulations, 2025, GN No. 157, new regulation 4E
tcra.go.tz
“A public data centre service provider shall be required to submit to the Authority on quarterly basis a list of all hosted customers.”
Link checked 18 August 2026
- Official sourcee-Government AuthorityCybercrimes Act, 2015, section 32(1)
ega.go.tz
Link checked 18 August 2026
What's changing next
Nothing big is scheduled in the next twelve months that we could verify. The most recent change already landed: from the first of July 2026 the rules on online media services were widened, so more online publishers need a licence from the communications regulator. The bigger risk is what the government can already do without warning. The minister can write regulations naming types of data that may never leave the country, the privacy regulator can ban transfers to a whole destination, and it can refuse any permit on national security grounds.
ALREADY LANDED, STILL BEDDING IN: - Electronic and Postal Communications (Online Content) (Amendment) Regulations 2026, GN No. 158i, published 30 June 2026 and in operation from 1 July 2026: adds an 'Online Media Service Category C' covering amateur online media and rewrites the licence application route through the Authority's licensing portal. Anyone publishing news or current affairs online for a Tanzanian audience should re-check whether they now need a licence. - Public data centre licensing and the quarterly hosted-customer list, in force since 21 March 2025 (GN No. 157 of 2025). DORMANT SWITCHES — powers already held, usable with no consultation: 1. Section 32(3) of the Personal Data Protection Act: the Minister, after consulting the Commission, may by regulations specify categories of processing and circumstances in which transfer of personal data outside the United Republic is not authorised. That is an open-ended power to create hard localisation for named data types. Not used as at 18 August 2026. 2. Section 31(1): the Commission may prohibit the transfer of personal data to a place outside the country. A single destination could be closed off overnight. 3. Regulation 21(a) of the 2023 Regulations: a permit may be refused because the transfer endangers national security. There is no published test for this and no published appeal outcome. 4. Section 64(2)(a): the Minister may make regulations exempting things from the Act entirely — the switch also works in the permissive direction. 5. Section 18 of the Act and regulation 11: the Commission may deregister a controller or processor, which removes the right to process at all. WATCH ITEMS: the Commission signed a five-year agreement with the Open University of Tanzania to train and certify data protection officers, and its January 2025 public notice told organisations to work only with professionals recognised by the Commission — a certified-officer requirement could harden from guidance into a rule. No data protection amendment bill was visible on the ministry's own site when checked on 18 August 2026.
Sources
- Official sourceTanzania Communications Regulatory AuthorityElectronic and Postal Communications (Online Content) (Amendment) Regulations, 2026, GN No. 158i published on 30 June 2026
tcra.go.tz
“shall come into operation on 1st July, 2026”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionPersonal Data Protection Act, Chapter 44, sections 31(1), 32(3) and 64
pdpc.go.tz
“The Minister shall, after consultation with Commission and by regulations, specify categories of processing for which and the circumstances in which the transfer of personal data to countries outside the United Republic is not authorised.”
Link checked 18 August 2026
- Official sourceMinistry of Communication and Information TechnologyMinistry of Communication and Information Technology — no data protection amendment bill listed, checked 18 August 2026
mawasiliano.go.tz
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries5 rules
If your product does one of these things, read this group first — industry rules beat the general position.
The Payment Systems (Licensing and Approval) Regulations, 2015
Directly binding regulation · Made under section 56(1), (2)(a) and (b) of the National Payment Systems Act, 2015
Every licensed payment system provider must keep its primary data centre for payment services inside Tanzania, and must keep transaction records for at least ten years. This is a location rule on the main system, not just a copy rule.
Enforced by Bank of Tanzania
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryThe primary data centre for payment system services must be in Tanzania. Copies and secondary sites abroad are not forbidden by this rule, but the main one must be local.
- Keep data for a minimum period — 10 yearsRecords of all transactions kept for at least ten years from the date of the transaction.
- Independent auditManagement information system must produce an audit trail usable by internal auditors, external auditors and the central bank.
What it costs if you get it wrong
- Loss of your licenceBreach of licence conditions under the National Payment Systems Act
Sources
- Official sourceBank of TanzaniaPayment Systems (Licensing and Approval) Regulations, 2015, regulations 41 and 42
bot.go.tz
“A payment system provider shall place its primary data center in relation to payment system services in Tanzania.”
Link checked 18 August 2026
Outsourcing Guidelines for Banks and Financial Institutions, 2021
Regulator guideline · Issued under section 71 of the Banking and Financial Institutions Act, 2006
Banks and financial institutions in Tanzania cannot put their primary data centre outside the country. Offshore arrangements are treated as outsourcing even when the supplier is the bank's own foreign head office or a group company.
Enforced by Bank of Tanzania
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryA bank may not outsource its primary data centre outside the country. Offshore processing of other functions is allowed but must be covered by the outsourcing policy.
- Written vendor contractThe outsourcing policy must state how the bank recovers outsourced resources such as data if the contract fails or political conditions change. Group and head-office arrangements count as outsourcing.
What it costs if you get it wrong
- Loss of your licenceNon-compliance with directives issued under the Banking and Financial Institutions Act
Sources
- Official sourceBank of TanzaniaOutsourcing Guidelines for Banks and Financial Institutions, 2021, paragraphs 3(b) and 10(g)
bot.go.tz
“Banks and financial institutions shall not outsource the following: ... (g) Primary data centre outside the country.”
Link checked 18 August 2026
The Gaming (Internet Gaming) Regulations, 2022
Directly binding regulation · GN No. 478T published on 1 July 2022, made under section 85 of the Gaming Act, Chapter 41
Online gambling operators must run their main server inside Mainland Tanzania, keep a staffed administration office in the country, and get the regulator's approval for the hosting setup. Hosting abroad is only a time-limited exception and requires a mirror server at home.
Enforced by Gaming Board of Tanzania
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryPrimary server must be in Mainland Tanzania. The Board may allow it abroad for a fixed period only if a replica server sits physically in Mainland Tanzania and the financial control system stays in Mainland Tanzania.
- Appoint a local representativeThe licensee must establish and maintain a physical administration centre in Mainland Tanzania with at least one director and key person.
- Secure the dataThe hosting environment plan and network topology must be approved by the Board before operations, and the hosting provider may be required to hold a certificate of suitability.
What it costs if you get it wrong
- Loss of your licenceBreach of licence conditions under the Gaming Act
Sources
- Official sourceGaming Board of TanzaniaGaming (Internet Gaming) Regulations, 2022, GN No. 478T, regulations 9, 10 and 12
gamingboard.go.tz
“Provided that, for the period the licensee server is hosted outside Mainland Tanzania, licensee shall install a replica server physically located in Mainland Tanzania.”
Link checked 18 August 2026
The e-Government Act, 2019
Act of parliament · Act No. 10 of 2019, Act Supplement No. 10 to Gazette No. 39 Vol. 100 of 20 September 2019
Government bodies must keep their systems and data in the government's approved hosting environment or with a government-approved supplier. If you sell cloud services to a Tanzanian public institution, the hosting location and the supplier itself have to be approved first.
Enforced by e-Government Authority
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryPublic institutions must host systems in the Government approved hosting environment and use available government processing and hosting facilities, or a government-approved supplier environment only.
- Secure the dataData must be secured against interception, alteration and destruction in storage, in transit and while being processed.
- Independent auditRegular independent security assessments and audits, in the manner the Authority prescribes.
- Keep records of processingIdentify, classify, manage and report ICT assets including storage devices and data to the Authority.
Sources
- Official sourcee-Government Authoritye-Government Act, 2019 (Act No. 10 of 2019), sections 25, 38, 39 and 45
ega.go.tz
“use the available Government ICT processing and hosting facilities or use Government approved supplier environment only”
Link checked 18 August 2026
The Electronic and Postal Communications (Licensing) (Amendment) Regulations, 2025
Directly binding regulation · GN No. 157 published on 21 March 2025, made under section 165 of the Electronic and Postal Communications Act, Chapter 306, amending GN No. 57 of 2018
Selling hosting, colocation, call centre or cybersecurity services in Tanzania now requires a licence from the communications regulator. Data centre operators must also hand the regulator a full list of their hosted customers four times a year.
Enforced by Tanzania Communications Regulatory Authority
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Register or notifyA network facility licence is needed to provide data centre services to the public, meaning colocation or co-hosting of a customer's network, servers and storage. Providing call centre services for someone else needs an application service licence. Cybersecurity services need an individual licence.
- Keep records of processing — 3 monthsA public data centre provider must give the Authority a list of all hosted customers every quarter.
What it costs if you get it wrong
- Loss of your licenceOperating without the required licence under the Electronic and Postal Communications Act
Sources
- Official sourceTanzania Communications Regulatory AuthorityElectronic and Postal Communications (Licensing) (Amendment) Regulations, 2025, GN No. 157, regulations 2 and 4C to 4E
tcra.go.tz
“A person shall not provide data centre services to the public unless he has obtained a network facility licence from the Authority.”
Link checked 18 August 2026
- Official sourceTanzania Communications Regulatory AuthorityElectronic and Postal Communications (SIM Card Registration) Regulations, 2025, GN No. 59 of 31 January 2025 (Swahili)
tcra.go.tz
“mfumo wake wa usajili umeunganishwa na kanzidata kuu ya usajili wa laini za simu ya Mamlaka, unafanya kazi na unapatikana muda wote”
Link checked 18 August 2026
Applies to every company1 rule
These bind you whatever business you are in, once the country's rules reach you.
The Personal Data Protection Act, 2022 / Sheria ya Ulinzi wa Taarifa Binafsi
Act of parliament · Act No. 11 of 2022, Chapter 44; English version published as GN No. 395B of 13 June 2023; read with the Personal Data Protection (Personal Data Collection and Processing) Regulations, 2023, GN No. 449C of 4 July 2023
Tanzania's general privacy law. You must register with the regulator before you process anything, appoint a data protection officer who reports to the regulator every three months, get your own code of ethics approved, and obtain a permit for each transfer of data out of the country. The regulator's own fines are modest, but the criminal offences behind them reach five billion shillings for a company and prison for individuals.
Enforced by Personal Data Protection Commission
Transfer model: Approval each time · Accepted routes: Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, Important public interest
What it makes you do
- Register or notifyNo collection or processing at all without registration. Valid five years; renewal must be applied for at least three months before expiry or you must register afresh. Fees 100,000 to 1,000,000 Tanzanian shillings depending on size.
- Appoint a data protection officerRequired of every controller and every processor, with no size threshold.
- Keep records of processing — 3 monthsThe data protection officer must send the Commission a compliance report every quarter.
- Put a transfer safeguard in placePer-transfer permit on Form No. 7, decided within 14 days, issued on Form No. 8, valid only for the named recipient and purpose.
- Get consentSensitive personal data needs prior written consent. Sensitive includes genetic data and any data relating to children.
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Secure the data
- Report breaches to the regulatorWithout undue delay. No hour figure in the Act or Regulations, and no duty to notify affected individuals.
- Assess high-risk projectsRequired before processing likely to affect rights and freedoms, including large-scale reuse and automated decisions with legal effect.
- Written vendor contractThe processor must be bound by a contract placing it under the controller's instructions and making it responsible for the Act's security standards.
- Delete data after a periodKept only for the period set by the relevant law or regulations, and in identifiable form only as long as the purpose requires.
What it costs if you get it wrong
- Fixed maximum fine: TZS 100,000,000 — about $37 thousandMaximum administrative penalty the Commission may impose in a penalty notice
- Criminal liability: TZS 5,000,000,000 (company); TZS 20,000,000 or 10 years imprisonment (individual) — about $2 millionUnlawful disclosure, transmission or sale of personal data
- Criminal liability: TZS 10,000,000 or 5 years imprisonment — about $4 thousandUnlawfully destroying, deleting, concealing or altering personal data
- Criminal liability: TZS 5,000,000 or 5 years imprisonment — about $2 thousandGeneral penalty where no specific penalty is provided; company officers who knowingly authorised the breach are personally liable
- Order to stopDeregistration by the Commission, which removes the right to process personal data at all
Sources
- Official sourcePersonal Data Protection CommissionPersonal Data Protection Act, Chapter 44 (Act No. 11 of 2022)
pdpc.go.tz
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionPersonal Data Protection (Personal Data Collection and Processing) Regulations, 2023, GN No. 449C
pdpc.go.tz
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionPublic notice on registration compliance and start of enforcement, 10 January 2025
pdpc.go.tz
“Sheria ya Ulinzi wa Taarifa Binafsi ilianza kufanya kazi tangu tarehe 01 Mei, 2023”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
Whether the Personal Data Protection Commission has actually imposed any fine or issued any published determination
The Commission's homepage counter claims 4 or more determinations as at May 2026, but its determinations page listed no documents when checked on 18 August 2026 and we found no named enforcement decision on any government site. The enforcement rating of 'waking' rests on this gap.
The exact deadline for reporting a personal data breach
The Act says 'without any undue delay' and the 2023 Regulations set no hour figure. No guidance document setting a number was found on the Commission's own site. Any specific hour count you see elsewhere is somebody's inference.
Incident reporting duties and deadlines to the national computer emergency response team
Only the 2025 amending regulations (GN No. 56) are published on the communications regulator's own site; the principal Computer Emergency Response Team Regulations 2018 (GN No. 60 of 2018) could not be retrieved from a government domain during this run.
Whether any country has been recognised as having adequate data protection, or any destination banned
No adequacy list and no prohibition notice was found on the Commission's site. We infer from the permit procedure that adequacy is assessed inside each application, which is consistent with the 39 permits reported, but the absence of a list is a negative we cannot fully prove.
Whether the transfer permit is legally required where a statutory exception such as consent or contract necessity applies
The Act's exceptions and the Regulations' permit procedure are not reconciled in the text, and no regulator guidance or court decision resolving the overlap was found. Treat the permit as required.
Sector storage rules in health, education, insurance, securities, mapping and defence
Checked the insurance regulator's published guidelines, the capital markets authority's publications, the health ministry site and the lands ministry's survey and mapping pages on 18 August 2026 and found no data localisation or storage rule. Several of these sites are difficult to search automatically, so this is 'not found', not 'does not exist'.
General tax and company record-keeping minimum periods
The revenue authority's site could not be navigated to a published Tax Administration Act record-keeping provision during this run. The ten-year floors cited are the money-laundering and payment-systems ones, which are verified.
How the law applies in Zanzibar for non-union matters, and whether Zanzibar has its own data protection instrument
The Act states it does not apply in Zanzibar to non-union matters, but we did not locate a Zanzibar-specific data protection law or regulator on a government domain.
Government notice number and exact commencement date of the Payment Systems (Licensing and Approval) Regulations 2015
The copy published on the central bank's own site is the version with a blank government notice number and date line. The substance is verified; the citation details are not.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
Tanzania versus
Compare