BlackTree Security · Infrastructure · Automation · AI

Tanzania’s Privacy Law Has Moved From Paper to Registration and Enforcement

Tanzania’s Personal Data Protection Act came into force in 2023, but its operational turning point arrived after that. The commission was formally inaugurated in April 2024, registration became real and statutory enforcement has now begun.

The Personal Data Protection Commission supervises the Act, registers controllers and processors, investigates complaints and breaches, issues guidance and controls international transfers. Its public service now states plainly that a person may not collect or process personal data without registration.

This is what makes the post-2023 development important. A law can sit on a compliance roadmap for years. A functioning registration portal, regulator and enforcement notice turns it into an operating dependency.

Registration is not optional inventory

Controllers and processors must register with the Commission under the statutory framework. The process requires organisational records and information about processing, and it is carried out through the Commission’s online system.

Registration should be treated as a continuing statement about the organisation. Changes in processing, contact details, DPO arrangements or data flows need governance so the regulator record does not drift away from reality.

The DPO is part of the filing

The registration process asks the organisation to designate a person acting as data protection officer and to introduce that person formally. The role sits between legal interpretation, operational evidence and regulator contact.

A DPO without access to system owners, vendor records and incident teams cannot keep the registration accurate or make a credible breach decision. The appointment should be backed by authority, information access and a clear escalation path.

Security is an explicit controller duty

The Act requires reasonable safeguards against negligent loss, unauthorised destruction, alteration, access or processing. The appropriate level depends on technology, implementation cost, data nature and risk to the individual.

That is a risk-based standard, not permission to adopt the cheapest control. The organisation should be able to explain why identity, access, encryption, logging, backup, vendor and incident controls are appropriate for the processing it registered.

Transfers have their own regulatory path

The Commission’s systems and regulations provide for international-transfer permissions and records. A cloud deployment may need more than a contractual data-protection clause if the statutory transfer process applies.

Teams should map support access, email, collaboration, identity, analytics, backups and security telemetry. Those services often create transfers that are absent from the main application diagram.

Enforcement changes the priority

The Commission moved from voluntary registration support toward enforcement after the announced registration period. Organisations that deferred because the regulator was new should now reassess that assumption.

The first enforcement risk may be administrative rather than a dramatic breach. An absent registration, outdated filing or unexplained transfer can reveal that basic accountability was never established.

What organisations should do now

  1. Confirm controller and processor registration status.
  2. Reconcile the regulator filing with current systems and processing.
  3. Give the DPO access, authority and a documented escalation route.
  4. Validate security measures against the sensitivity and scale of data.
  5. Map international transfers and required permissions.
  6. Prepare evidence for a complaint, audit or breach investigation.

Operational maturity is the real milestone

Tanzania’s privacy regime illustrates the gap between commencement and operational enforcement. The statute is not new, but the regulator’s capacity, registration system and enforcement posture are the developments that change what organisations must do today.

Official sources

This article provides general information and is not legal advice.

Continue the series: Africa Cyber & Digital Law Series index

Leave a Reply

Your email address will not be published. Required fields are marked *