Tanzania
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Tanzania — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can send data out of Tanzania, but only after the privacy regulator grants a permit for that exact transfer. No country is pre-approved. Each move abroad is its own application. Before you collect or use any data, you must register with the regulator. You must also name a data protection officer, who then reports every three months. Some industries must keep their main systems in the country.
Data governance in Tanzania
The eight things that decide how you handle data about people in Tanzania. Same eight on every country page, so you can compare.
Who has to follow these rules
It can reach a foreign company, but the test is narrower than in Europe. The law covers anyone based in Tanzania. It also covers a company that is not based in Tanzania, if the data is handled inside the country. Simply passing data through Tanzania on the way somewhere else does not count. There is no size or revenue cut-off. There is no separate rule making a foreign firm appoint a local representative.
The reach comes from the Personal Data Protection Act, Chapter 44 (Act No. 11 of 2022), section 24(1)(b) and (c). The Act covers a company that decides how data is used and is domiciled in the United Republic. It also covers a company that is not domiciled there, if the data is handled in the United Republic. It does not cover data that is merely passing through Tanzania on the way to another country. So the test is where the data is handled. It is not the targeting test used in the European Union or India. A pure offshore software-as-a-service provider that handles nothing locally has a real argument that it falls outside. That argument matters little for anyone with staff, agents or infrastructure in the country. Section 14 bars any collection or use of data without registration. The 2023 Regulations define the company that decides how data is used, and the company that handles data for it. Both definitions end with the words 'and it includes his representative'. That pulls a local agent into the same duties. There is also a practical gate. The regulator's registration process requires a Business Registrations and Licensing Agency certificate, a Tanzanian Taxpayer Identification Number certificate, and audited accounts. Registering without a Tanzanian legal entity is difficult. The Act applies to Mainland Tanzania and to Zanzibar. In Zanzibar it applies only to union matters.
Sources
- Official sourcePersonal Data Protection CommissionPersonal Data Protection Act, Chapter 44 (Act No. 11 of 2022), sections 2, 14 and 24
pdpc.go.tz
“the processing of personal data by a data controller or data processor who is not domiciled in the United Republic, if the processing of the personal data is in United Republic and such processing is not for the purposes of mere transit of personal data through Tanzania to another country.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionRegistration service — documents required to register as a data controller or processor
pdpc.go.tz
“For Private organizations, they are required to have three documents, which are the organization BRELA certificate, Tax Identification Number certificate and financial year audited report”
Link checked 18 August 2026
Where the data is allowed to live
Yes, but you must ask first, every time. Tanzania publishes no list of countries that are automatically safe. You apply to the privacy regulator for a permit. The permit names the exact data, the exact recipient and the exact destination. The regulator says it had issued about 39 of these permits by May 2026. Four industries are stricter still: banking, payments, online gambling and government. Their main systems must be physically in Tanzania, whatever any permit says.
- Ways to send data out:
- Government sign-off needed
General rule: sections 31 and 32 of the Personal Data Protection Act. You may send data to a country with adequate protection. You may send it to a country without adequate protection only in limited cases. Either the recipient country's protection is assessed as adequate. Or one of the narrow exceptions applies. The person consented. The transfer is needed for a contract, for legal claims, or on public interest grounds. Or it protects the person's own interests. Or the Commission is satisfied that contract terms and security measures make up the difference. Section 31(1) also lets the Commission simply ban transfers of personal data to a place outside the country. The 2023 Regulations turn this into a permit for each transfer. Regulation 20 requires a written application on Form No. 7 before any transfer. The Commission has 14 days to decide. An approved transfer is documented on a permit (Form No. 8). Regulation 22 sets the conditions: named recipient only, stated purpose only, and no onward transfer without further approval. Regulation 21 lets the Commission refuse where the transfer endangers national security, or where another written law restricts it. INDUSTRY RULES: - Banking (a copy must stay in the country, and a firm rule for the main site). The Bank of Tanzania's Outsourcing Guidelines 2021 name one thing a bank or financial institution may not outsource: a 'primary data centre outside the country'. - Payments and electronic money (a copy must stay in the country): Payment Systems (Licensing and Approval) Regulations 2015, regulation 42. A payment system provider must place its primary data centre for payment system services in Tanzania. - Online gambling (a copy must stay in the country): Gaming (Internet Gaming) Regulations 2022, regulation 9. The licensee's primary server must be in Mainland Tanzania. If the Board temporarily allows it abroad, a replica server must sit physically in Mainland Tanzania. The financial control system must stay in Mainland Tanzania. - Government and public bodies (data must stay in the country): e-Government Act 2019, sections 25 and 45. Public institutions must host systems in the Government approved hosting environment. They must use government facilities, or a government-approved supplier environment only. - Telecommunications (data can leave only if conditions are met, plus a licence layer). Mobile operators' subscriber registration systems must be permanently connected to three systems. Those are the national identity authority, the immigration department and the regulator's central subscriber database. That pins the registration system to Tanzania. Anyone selling data centre space to the public needs a network facility licence from the communications regulator. - Insurance and securities: we found no storage or location rule on the insurance or capital markets regulators' own sites, checked 18 August 2026. The general permit rule still applies. - Health, education, mapping and defence: we found no storage rule for these industries on the relevant ministries' own sites, checked 18 August 2026. Confidence medium. No published rule is not proof that none exists.
Sources
- Official sourcePersonal Data Protection CommissionPersonal Data Protection (Personal Data Collection and Processing) Regulations, 2023, GN No. 449C, regulations 20 to 22
pdpc.go.tz
“A data controller or data processor who intends to transfer personal data outside the country, shall submit an application for permit to the Commission using Form No. 7 set out in the First Schedule to these Regulations.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionCross-border data transfer permit — service description and application procedure
pdpc.go.tz
“Issues permits to entities intending to transfer personal data outside the country”
Link checked 18 August 2026
- Official sourceBank of TanzaniaOutsourcing Guidelines for Banks and Financial Institutions, 2021, paragraph 10(g)
bot.go.tz
“Banks and financial institutions shall not outsource the following: ... (g) Primary data centre outside the country.”
Link checked 18 August 2026
- Official sourceGaming Board of TanzaniaGaming (Internet Gaming) Regulations, 2022, GN No. 478T, regulation 9
gamingboard.go.tz
“A licensee shall have its primary server located within Mainland Tanzania.”
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Tanzania.
Sending data out of the country
You need permission for each transfer. There is no approved-country list to rely on. There is no standard contract you can just sign. Nothing leaves the country lawfully until the regulator says yes to that specific transfer. Your application sets out the type of data, the purpose, the recipient and the destination country. You also need proof that the destination protects data properly, evidence of a binding contract with the recipient, and the person's consent. The regulator has fourteen days to decide. The permit only covers the recipient it names.
- Ways to send data out:
- Government sign-off needed · Explicit consent · Needed for a contract · Legal claims
Model: approval each time There is no list of approved countries. As at 18 August 2026 there is no published official decision that any country is safe enough. The Commission judges that inside each application instead. It uses the factors in section 32(2) of the Act. Those are the nature of the data, and the purpose and duration. Also the recipient's country, the laws in force there, and the professional rules and security measures applied there. How it works under regulation 20 of the 2023 Regulations. You apply on Form No. 7. You must also produce one of three things. Proof that the destination country has ratified an international data protection agreement. Or proof that Tanzania has an agreement with that country. Or a contract between you and the overseas recipient. The decision comes within 14 days. Approval is issued on Form No. 8. Passing the data on to a further recipient needs fresh approval. The Act's exceptions sit in section 32(4). They are consent, contract necessity, legal claims, public interest, and protecting the person's interests. The Regulations impose the permit procedure without excluding those cases. So relying on an exception and skipping the permit is a live risk, not a settled route. The Commission reported roughly 39 transfer permits issued as at May 2026. That is small against about 14,400 registered organisations. Most data leaving Tanzania is therefore probably unpermitted.
Sources
- Official sourcePersonal Data Protection CommissionPersonal Data Protection (Personal Data Collection and Processing) Regulations, 2023, GN No. 449C, regulation 20(3) and (4)
pdpc.go.tz
“The Commission shall consider the application submitted under subregulation (1) within a period of fourteen days after receiving the application”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionPersonal Data Protection Act, Chapter 44, sections 31 and 32
pdpc.go.tz
“The Commission may, subject to the provisions of this Act, prohibit the transfer of personal data to a place outside the country.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionPersonal Data Protection Commission homepage — 39+ data transfer permits, 14400+ registered organisations, May 2026 figures
pdpc.go.tz
“39+ Data Transfer Permits Offered - May 2026”
Link checked 18 August 2026
What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.
The regulator, and whether it actually acts
The Personal Data Protection Commission, based in Dodoma, is the main regulator. It is up and running. It has a director general, a governing board with named members, and an online registration system. By May 2026 it reported over fourteen thousand registered organisations, more than three hundred and forty complaints received, and thirty-nine transfer permits granted. What is missing is published punishment. Its own decisions page was empty when we checked, so we cannot show a single fine actually imposed. Other regulators police their own industries: the central bank, the communications authority, the gaming board and the e-Government Authority.
Personal Data Protection Commission: created by section 6 of the Act. It sits under the Ministry of Communication and Information Technology. Its offices are at 1 Moshi Street, Viwandani, Dodoma. The Director General is Dr. Emmanuel Lameck Mkilia. The board has a chairman, a vice-chairman and five members, all named on the Commission's own site. In the last twelve months it held a first national data privacy conference in Dar es Salaam, from 29 June to 1 July 2026. It also ran a data protection officer training programme with the Open University of Tanzania, and announced a certified-officer scheme. Why we rate it 'waking' and not 'active'. The Act started on 1 May 2023. The Commission's own public notice of 10 January 2025 said voluntary registration ended on 31 December 2024. It gave a final registration deadline of 30 April 2025. It said that from 1 May 2025 the Commission would work with law enforcement to take legal action against organisations that had not complied. So enforcement formally began over a year ago, and the registration numbers show real engagement. But the Commission's 'Determinations' page carried no published decisions when we checked on 18 August 2026. We found no published fine against any named organisation. A regulator that handles registrations and complaints but publishes no penalties is waking, not active. Other regulators have their own powers over data. The Bank of Tanzania covers banking, payments and electronic money, through licence conditions and revocation. The Tanzania Communications Regulatory Authority covers telecoms, online content, public data centres and cybersecurity service licences. The Gaming Board of Tanzania covers internet gaming servers. The e-Government Authority covers public sector systems and hosting. Police also hold direct powers over data under the Cybercrimes Act 2015.
Sources
- Official sourcePersonal Data Protection CommissionPersonal Data Protection Commission — activity figures as at May 2026
pdpc.go.tz
“14400 + Number of Registered Organizations - May 2026 ... 340 + Complaints Received - May 2026 ... 4+ Determinations - May 2026”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionPublic notice: compliance with registration requirements, 10 January 2025 (Swahili)
pdpc.go.tz
“Kuanzia tarehe 1 Mei, 2025, PDPC kwa kushirikiana na vyombo vya utekelezaji wa sheria, itaanza kuchukua hatua za kisheria dhidi ya taasisi zote ambazo hazijazingatia matakwa ya Sheria husika.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionDeterminations page — no decisions published as at 18 August 2026
pdpc.go.tz
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionBoard of the Personal Data Protection Commission — named members
pdpc.go.tz
Link checked 18 August 2026
How long you must keep it — and when to delete it
Minimum keep times come from other laws, and in finance they are long. Banks, insurers and other firms covered by the money-laundering rules must keep customer and transaction records for at least ten years. Payment providers must keep every transaction record for at least ten years too. The maximum comes from the privacy law. It says personal data may only be kept for the period the relevant law or regulations set. Data may identify people only for as long as the purpose needs. Where the two clash, the specific keep period in the industry law wins. You delete when that period runs out, not earlier.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period
MINIMUM KEEP TIMES (verified): - Anti-Money Laundering Regulations 2012, regulation 30. A reporting person must keep the records required by section 16 of the Anti-Money Laundering Act for at least ten years. Insurers are separately directed to keep records for ten years after a business relationship ends, and ten years after a transaction is completed. - Payment Systems (Licensing and Approval) Regulations 2015, regulation 41. Payment system providers keep records of all transactions for not less than ten years from the transaction date. - Telecommunications: the 2025 subscriber registration rules cover line replacements. An operator must keep the information gathered in an easily accessible database for twelve months. WHEN YOU MUST STOP KEEPING IT: - Personal Data Protection Act, section 28. Personal data is kept for the period set in the relevant laws or in regulations. The point is to give the person a reasonable chance to see it. The Minister may set rules on keeping and disposing of data to match the purpose. - 2023 Regulations, regulation 23: personal data must be stored in a form that identifies people only as long as necessary. It must not be sent abroad in breach of the Act. WHICH ONE WINS: there is no general override clause. The industry minimum is a duty set by statute, and section 28 of the privacy law points outward to 'the relevant laws'. So the ten-year finance periods beat any argument for early deletion. A deletion request from an individual does not shorten them. We did not find a published Tanzania Revenue Authority record-keeping period on the revenue authority's own site.
Sources
- Official sourceBank of TanzaniaAnti-Money Laundering Regulations, 2012, regulation 30 (records retention period)
bot.go.tz
“A reporting person shall retain records required by section 16 of the Act for a minimum period of ten years”
Link checked 18 August 2026
- Official sourceBank of TanzaniaPayment Systems (Licensing and Approval) Regulations, 2015, regulation 41
bot.go.tz
“A payment system provider shall obtain records of all transactions conducted in the course of business and keep them for a period of not less than ten years from the date of the transaction.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionPersonal Data Protection Act, Chapter 44, section 28 (retention and disposal)
pdpc.go.tz
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
The privacy law gives you no deadline in hours. It says only that you must tell the regulator about a security breach affecting personal data, without undue delay. It does not require you to tell the people affected at all. Treat twenty-four to seventy-two hours as the safe reading, because no published guidance sets a number. Separately, the police can order you to freeze data for up to fourteen days during an investigation. Licensed communications companies have their own reporting duties to the national cyber incident team.
- What you have to do here:
- Report breaches to the regulator · Report cyber incidents
DEADLINE 1: the privacy regulator. Section 27(5) of the Personal Data Protection Act says you must tell the Commission about any security breach affecting personal data you hold. It covers data someone else holds on your behalf too. You must do it without any undue delay. No hour figure appears in the Act or in the 2023 Regulations. There is no legal duty to tell the people affected. That is a real gap compared with most modern privacy laws. It does not remove the reputational and contractual pressure to tell them anyway. DEADLINE 2: criminal investigation. Section 33 of the Cybercrimes Act 2015 gives a police officer in charge of a station a power. They can order whoever controls a device or data to preserve it for up to fourteen days. A court can extend that. Section 32(1) lets the same officer order disclosure of data without going to court first. DEADLINE 3: the communications industry. Licensed operators and cybersecurity service providers deal with the national computer emergency response team. The rules are the Electronic and Postal Communications (Computer Emergency Response Team) Regulations 2018, amended by GN No. 56 of 31 January 2025. The amendment requires a licence for anyone providing cybersecurity services. It also gives a fourteen-day window to tell the Authority about changes. We could not retrieve the main 2018 regulations from the Authority's own site, so the reporting deadline inside them is unverified. OVERLAP RISK: one incident at a licensed bank or payment provider can trigger three reports at once. The privacy notification, a supervisory notification to the central bank, and a communications-industry report. Three different deadlines, and the shortest one is not written down.
Sources
- Official sourcePersonal Data Protection CommissionPersonal Data Protection Act, Chapter 44, section 27(5)
pdpc.go.tz
“The data controller shall notify the Commission, without any undue delay, of any security breach affecting personal data being processed by or on behalf of the data controller.”
Link checked 18 August 2026
- Official sourceTanzania Communications Regulatory AuthorityElectronic and Postal Communications (Computer Emergency Response Team) (Amendment) Regulations, 2025, GN No. 56
tcra.go.tz
“A person who intends to provide cybersecurity services within the United Republic shall obtain an individual licence from the Authority”
Link checked 18 August 2026
- Official sourcee-Government AuthorityCybercrimes Act, 2015 (Act No. 14 of 2015), sections 32 and 33
ega.go.tz
“the police officer incharge of a police station or a law enforcement officer of a similar rank may issue an order requiring the person in control of a device or computer data to preserve the device or computer data for a period not exceeding fourteen days.”
Link checked 18 August 2026
What to do: Your breach process has to reach Tanzania's regulator inside the deadline above.
Not fully verified — see “What we're not sure about” below.What catches people out
Five things catch people out here. The criminal fine is fifty times the regulator's fine, and directors are personally liable. Every organisation must appoint a data protection officer. That officer then files a report to the regulator every three months. You cannot register without Tanzanian company papers, and you cannot lawfully use any data until you are registered. Every organisation must also write its own code of ethics and get the regulator to approve it. And the police can demand your data without a court order.
- What you have to do here:
- Appoint a data protection officer · Register or notify · Get consent
- What it costs if you get it wrong:
- Criminal liability
TRAP 1: the criminal fine is far bigger than the regulator's fine. The Commission's maximum penalty notice is one hundred million Tanzanian shillings, roughly thirty-seven thousand United States dollars. But unlawfully disclosing, transmitting or selling personal data is a crime. A company faces a fine of up to five billion shillings, roughly one point nine million dollars. An individual faces up to ten years in prison. Under section 62 the company and every officer who knowingly authorised or permitted the breach are liable. The real exposure is criminal, not regulatory. TRAP 2: everyone needs a data protection officer, reporting to the state every quarter. Section 27(3) of the Act requires an appointment from every company that decides how data is used, and every company that handles data for them. There is no size cut-off. Regulation 32(c) of the 2023 Regulations then makes that officer 'prepare and submit quarterly reports on the compliance of the Act to the Commission'. Four filings a year, from every registered organisation, is unusual and easy to miss. TRAP 3: registration is a firm gate, and it assumes a local entity. Section 14 says a person shall not collect or use personal data without being registered. Registration lasts five years. You must apply to renew at least three months before it expires, or you start again. Fees run from one hundred thousand shillings for a small organisation to one million shillings for a large one. That is roughly thirty-seven to three hundred and seventy dollars. The documents demanded assume a Tanzanian entity: company registration certificate, taxpayer identification number and audited accounts. TRAP 4: the code of ethics. Section 65 says every company that decides how data is used must draw up a code of ethics or policy for personal data protection. You then submit it to the Commission for consideration and approval. This is an approval, not a filing. An off-the-shelf global privacy policy will not do. TRAP 5: sensitive data needs written consent in advance, and children's data counts as sensitive. Section 30(1) forbids the use of sensitive personal data without prior written consent. The definition of sensitive personal data expressly includes data related to children, as well as genetic data. A tick box is not written consent on any careful reading. TRAP 6: police access without a judge. Section 32(1) of the Cybercrimes Act covers criminal investigations. A police officer in charge of a station may order any person holding data to disclose it. A court is involved only as a fallback, if that order does not work. TRAP 7: if you sell hosting, you must hand over your customer list. Anyone providing public data centre services needs a network facility licence from the communications regulator. They must also give it a list of all hosted customers every quarter.
Sources
- Official sourcePersonal Data Protection CommissionPersonal Data Protection Act, Chapter 44, sections 14, 27, 30, 47, 60, 62 and 65
pdpc.go.tz
“in the case of a company or corporation, a fine of not less than one million shillings but not exceeding five billion shillings.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionPersonal Data Protection (Personal Data Collection and Processing) Regulations, 2023, regulations 4 to 8, 32 and Second Schedule
pdpc.go.tz
“to prepare and submit quarterly reports on the compliance of the Act to the Commission”
Link checked 18 August 2026
- Official sourceTanzania Communications Regulatory AuthorityElectronic and Postal Communications (Licensing) (Amendment) Regulations, 2025, GN No. 157, new regulation 4E
tcra.go.tz
“A public data centre service provider shall be required to submit to the Authority on quarterly basis a list of all hosted customers.”
Link checked 18 August 2026
- Official sourcee-Government AuthorityCybercrimes Act, 2015, section 32(1)
ega.go.tz
Link checked 18 August 2026
What's changing next
Nothing big is scheduled in the next twelve months that we could verify. The most recent change has already landed. From 1 July 2026 the rules on online media services were widened. More online publishers now need a licence from the communications regulator. The bigger risk is what the government can already do without warning. The minister can write regulations naming types of data that may never leave the country. The privacy regulator can ban transfers to a whole destination. It can also refuse any permit on national security grounds.
ALREADY LANDED, STILL BEDDING IN: - Electronic and Postal Communications (Online Content) (Amendment) Regulations 2026, GN No. 158i. Published 30 June 2026, in operation from 1 July 2026. It adds an 'Online Media Service Category C' covering amateur online media. It also rewrites the licence application route through the Authority's licensing portal. If you publish news or current affairs online for a Tanzanian audience, check whether you now need a licence. - Public data centre licensing and the quarterly hosted-customer list, in force since 21 March 2025 (GN No. 157 of 2025). POWERS ALREADY HELD, USABLE WITH NO CONSULTATION: 1. Section 32(3) of the Personal Data Protection Act. The Minister may make regulations after consulting the Commission. They can name types of data handling, and situations, where sending personal data outside the United Republic is not allowed. That is an open-ended power to force named types of data to stay in the country. Not used as at 18 August 2026. 2. Section 31(1). The Commission may ban the transfer of personal data to a place outside the country. A single destination could be closed off overnight. 3. Regulation 21(a) of the 2023 Regulations. A permit may be refused because the transfer endangers national security. There is no published test for this and no published appeal outcome. 4. Section 64(2)(a). The Minister may make regulations exempting things from the Act entirely. The power works in the permissive direction too. 5. Section 18 of the Act and regulation 11. The Commission may deregister an organisation, which removes its right to use data at all. WATCH ITEMS: the Commission signed a five-year agreement with the Open University of Tanzania to train and certify data protection officers. Its January 2025 public notice told organisations to work only with professionals recognised by the Commission. A certified-officer requirement could harden from guidance into a rule. No data protection amendment bill was visible on the ministry's own site when we checked on 18 August 2026.
Sources
- Official sourceTanzania Communications Regulatory AuthorityElectronic and Postal Communications (Online Content) (Amendment) Regulations, 2026, GN No. 158i published on 30 June 2026
tcra.go.tz
“shall come into operation on 1st July, 2026”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionPersonal Data Protection Act, Chapter 44, sections 31(1), 32(3) and 64
pdpc.go.tz
“The Minister shall, after consultation with Commission and by regulations, specify categories of processing for which and the circumstances in which the transfer of personal data to countries outside the United Republic is not authorised.”
Link checked 18 August 2026
- Official sourceMinistry of Communication and Information TechnologyMinistry of Communication and Information Technology — no data protection amendment bill listed, checked 18 August 2026
mawasiliano.go.tz
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries5 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Payments data needs a copy kept in the country
Official name: The Payment Systems (Licensing and Approval) Regulations, 2015 · Made under section 56(1), (2)(a) and (b) of the National Payment Systems Act, 2015 · Directly binding regulation
Every licensed payment system provider must keep its primary data centre for payment services inside Tanzania, and must keep transaction records for at least ten years. This is a location rule on the main system, not just a copy rule.
Enforced by Bank of Tanzania
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryThe primary data centre for payment system services must be in Tanzania. Copies and secondary sites abroad are not forbidden by this rule, but the main one must be local.
- Keep data for a minimum period — 10 yearsRecords of all transactions kept for at least ten years from the date of the transaction.
- Independent auditManagement information system must produce an audit trail usable by internal auditors, external auditors and the central bank.
What it costs if you get it wrong
- Loss of your licenceBreach of licence conditions under the National Payment Systems Act
Sources
- Official sourceBank of TanzaniaPayment Systems (Licensing and Approval) Regulations, 2015, regulations 41 and 42
bot.go.tz
“A payment system provider shall place its primary data center in relation to payment system services in Tanzania.”
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Outsourcing Guidelines for Banks and Financial Institutions, 2021 · Issued under section 71 of the Banking and Financial Institutions Act, 2006 · Regulator guideline
Banks and financial institutions in Tanzania cannot put their primary data centre outside the country. Offshore arrangements are treated as outsourcing even when the supplier is the bank's own foreign head office or a group company.
Enforced by Bank of Tanzania
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryA bank may not outsource its primary data centre outside the country. It may have other functions handled abroad, but the outsourcing policy must cover them.
- Written vendor contractThe outsourcing policy must state how the bank recovers outsourced resources such as data if the contract fails or political conditions change. Group and head-office arrangements count as outsourcing.
What it costs if you get it wrong
- Loss of your licenceNon-compliance with directives issued under the Banking and Financial Institutions Act
Sources
- Official sourceBank of TanzaniaOutsourcing Guidelines for Banks and Financial Institutions, 2021, paragraphs 3(b) and 10(g)
bot.go.tz
“Banks and financial institutions shall not outsource the following: ... (g) Primary data centre outside the country.”
Link checked 18 August 2026
Online gaming data needs a copy kept in the country
Official name: The Gaming (Internet Gaming) Regulations, 2022 · GN No. 478T published on 1 July 2022, made under section 85 of the Gaming Act, Chapter 41 · Directly binding regulation
Online gambling operators must run their main server inside Mainland Tanzania. They must keep a staffed administration office in the country. They must also get the regulator's approval for the hosting setup. Hosting abroad is only a time-limited exception and requires a mirror server at home.
Enforced by Gaming Board of Tanzania
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryPrimary server must be in Mainland Tanzania. The Board may allow it abroad for a fixed period. Two conditions apply. A replica server must sit physically in Mainland Tanzania. The financial control system must stay in Mainland Tanzania.
- Appoint a representativeThe licensee must establish and maintain a physical administration centre in Mainland Tanzania with at least one director and key person.
- Secure the dataThe Board must approve the hosting environment plan and network topology before you start operating. The hosting provider may be required to hold a certificate of suitability.
What it costs if you get it wrong
- Loss of your licenceBreach of licence conditions under the Gaming Act
Sources
- Official sourceGaming Board of TanzaniaGaming (Internet Gaming) Regulations, 2022, GN No. 478T, regulations 9, 10 and 12
gamingboard.go.tz
“Provided that, for the period the licensee server is hosted outside Mainland Tanzania, licensee shall install a replica server physically located in Mainland Tanzania.”
Link checked 18 August 2026
Cloud and outsourcing rules (Government)
Official name: The e-Government Act, 2019 · Act No. 10 of 2019, Act Supplement No. 10 to Gazette No. 39 Vol. 100 of 20 September 2019 · Act of parliament
Government bodies must keep their systems and data in the government's approved hosting environment or with a government-approved supplier. If you sell cloud services to a Tanzanian public institution, the hosting location and the supplier itself have to be approved first.
Enforced by e-Government Authority
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryPublic institutions must host systems in the Government approved hosting environment. They must use available government data handling and hosting facilities, or a government-approved supplier environment only.
- Secure the dataData must be secured against interception, alteration and destruction in storage, in transit and while being processed.
- Independent auditRegular independent security assessments and audits, in the manner the Authority prescribes.
- Keep records of how you use dataIdentify, classify, manage and report ICT assets including storage devices and data to the Authority.
Sources
- Official sourcee-Government Authoritye-Government Act, 2019 (Act No. 10 of 2019), sections 25, 38, 39 and 45
ega.go.tz
“use the available Government ICT processing and hosting facilities or use Government approved supplier environment only”
Link checked 18 August 2026
Cyber security rules
Official name: The Electronic and Postal Communications (Licensing) (Amendment) Regulations, 2025 · GN No. 157 published on 21 March 2025, made under section 165 of the Electronic and Postal Communications Act, Chapter 306, amending GN No. 57 of 2018 · Directly binding regulation
Selling hosting, colocation, call centre or cybersecurity services in Tanzania now requires a licence from the communications regulator. Data centre operators must also hand the regulator a full list of their hosted customers four times a year.
Enforced by Tanzania Communications Regulatory Authority
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Register or notifyA network facility licence is needed to provide data centre services to the public, meaning colocation or co-hosting of a customer's network, servers and storage. Providing call centre services for someone else needs an application service licence. Cybersecurity services need an individual licence.
- Keep records of how you use data — 3 monthsA public data centre provider must give the Authority a list of all hosted customers every quarter.
What it costs if you get it wrong
- Loss of your licenceOperating without the required licence under the Electronic and Postal Communications Act
Sources
- Official sourceTanzania Communications Regulatory AuthorityElectronic and Postal Communications (Licensing) (Amendment) Regulations, 2025, GN No. 157, regulations 2 and 4C to 4E
tcra.go.tz
“A person shall not provide data centre services to the public unless he has obtained a network facility licence from the Authority.”
Link checked 18 August 2026
- Official sourceTanzania Communications Regulatory AuthorityElectronic and Postal Communications (SIM Card Registration) Regulations, 2025, GN No. 59 of 31 January 2025 (Swahili)
tcra.go.tz
“mfumo wake wa usajili umeunganishwa na kanzidata kuu ya usajili wa laini za simu ya Mamlaka, unafanya kazi na unapatikana muda wote”
Link checked 18 August 2026
Applies to every company1 rule
These bind you whatever business you are in, once the country's rules reach you.
Rules for sending data abroad
Official name: The Personal Data Protection Act, 2022 / Sheria ya Ulinzi wa Taarifa Binafsi · Act No. 11 of 2022, Chapter 44; English version published as GN No. 395B of 13 June 2023; read with the Personal Data Protection (Personal Data Collection and Processing) Regulations, 2023, GN No. 449C of 4 July 2023 · Act of parliament
This is Tanzania's general privacy law. You must register with the regulator before you use any data. You must appoint a data protection officer, who reports to the regulator every three months. You must get your own code of ethics approved. And you need a permit for each transfer of data out of the country. The regulator's own fines are modest. The criminal offences behind them reach five billion shillings for a company, and prison for individuals.
Enforced by Personal Data Protection Commission
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, Important public interest
What you have to do
- Register or notifyYou may not collect or use any data without registration. It lasts five years. You must apply to renew at least three months before it expires, or you register from scratch. Fees are 100,000 to 1,000,000 Tanzanian shillings, depending on size.
- Appoint a data protection officerRequired of every organisation that decides how data is used, and every organisation that handles data for them. There is no size cut-off.
- Keep records of how you use data — 3 monthsThe data protection officer must send the Commission a compliance report every quarter.
- Put a transfer safeguard in placePer-transfer permit on Form No. 7, decided within 14 days, issued on Form No. 8, valid only for the named recipient and purpose.
- Get consentSensitive personal data needs prior written consent. Sensitive includes genetic data and any data relating to children.
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Secure the data
- Report breaches to the regulatorWithout undue delay. No hour figure in the Act or Regulations, and no duty to notify affected individuals.
- Assess high-risk projectsRequired before data use that is likely to affect people's rights and freedoms. That includes large-scale reuse and automated decisions with legal effect.
- Written vendor contractAnyone handling data for you must be bound by a contract. It must put them under your instructions and make them responsible for the Act's security standards.
- Delete data after a periodKept only for the period set by the relevant law or regulations, and in identifiable form only as long as the purpose requires.
What it costs if you get it wrong
- Fixed maximum fine: TZS 100,000,000 — about $37 thousandMaximum administrative penalty the Commission may impose in a penalty notice
- Criminal liability: TZS 5,000,000,000 (company); TZS 20,000,000 or 10 years imprisonment (individual) — about $2 millionUnlawful disclosure, transmission or sale of personal data
- Criminal liability: TZS 10,000,000 or 5 years imprisonment — about $4 thousandUnlawfully destroying, deleting, concealing or altering personal data
- Criminal liability: TZS 5,000,000 or 5 years imprisonment — about $2 thousandGeneral penalty where no specific penalty is provided; company officers who knowingly authorised the breach are personally liable
- Order to stopDeregistration by the Commission, which removes the right to process personal data at all
Sources
- Official sourcePersonal Data Protection CommissionPersonal Data Protection Act, Chapter 44 (Act No. 11 of 2022)
pdpc.go.tz
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionPersonal Data Protection (Personal Data Collection and Processing) Regulations, 2023, GN No. 449C
pdpc.go.tz
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionPublic notice on registration compliance and start of enforcement, 10 January 2025
pdpc.go.tz
“Sheria ya Ulinzi wa Taarifa Binafsi ilianza kufanya kazi tangu tarehe 01 Mei, 2023”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Whether the Personal Data Protection Commission has actually imposed any fine or issued any published determination
We could not confirm any enforcement decisions. The Commission's homepage counter claims 4 or more determinations as at May 2026. But its determinations page listed no documents when we checked on 18 August 2026. We found no named enforcement decision on any government site. Our enforcement rating of 'waking' rests on this gap.
The exact deadline for reporting a personal data breach
We could not confirm a deadline in hours for reporting a breach. The Act says 'without any undue delay', and the 2023 Regulations set no hour figure. We found no guidance setting a number on the Commission's own site. Any specific hour count you see elsewhere is someone's inference.
Incident reporting duties and deadlines to the national computer emergency response team
We could not confirm the incident reporting deadline for the communications industry. Only the 2025 amending regulations (GN No. 56) are published on the communications regulator's own site. We could not retrieve the main Computer Emergency Response Team Regulations 2018 (GN No. 60 of 2018) from a government website. If you hold a communications licence, ask the Authority.
Whether any country has been recognised as having adequate data protection, or any destination banned
We could not confirm that there is no approved-country list. We found no list and no ban notice on the Commission's site. The permit procedure suggests each application is judged on its own, which fits the 39 permits reported. But we cannot fully prove that no list exists.
Whether the transfer permit is legally required where a statutory exception such as consent or contract necessity applies
We could not confirm whether the Act's exceptions remove the need for a permit. The Act's exceptions and the Regulations' permit procedure are not reconciled in the text. We found no regulator guidance or court decision settling the overlap. Treat the permit as required.
Sector storage rules in health, education, insurance, securities, mapping and defence
We found no rule about where data must be stored in these industries. On 18 August 2026 we checked four sources. The insurance regulator's published guidelines. The capital markets authority's publications. The health ministry site. And the lands ministry's survey and mapping pages. Several of those sites are hard to search automatically. Treat this as a rule we could not find, not proof that none exists.
General tax and company record-keeping minimum periods
We could not confirm a tax record-keeping period. We could not reach a published Tax Administration Act record-keeping rule on the revenue authority's site. The ten-year minimums we cite come from the money-laundering and payment-systems rules, and those are verified. Ask the revenue authority if tax records matter to you.
How the law applies in Zanzibar for non-union matters, and whether Zanzibar has its own data protection instrument
We could not confirm what applies in Zanzibar for non-union matters. The Act says it does not apply there for those matters. We did not find a Zanzibar-specific data protection law or regulator on a government website. If you operate in Zanzibar, check locally.
Government notice number and exact commencement date of the Payment Systems (Licensing and Approval) Regulations 2015
We could not confirm the citation details of this document. The copy published on the central bank's own site has a blank government notice number and date line. The substance is verified. The citation details are not.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.