Data Protection in Tanzania’s Digital Jungle

by Jens Ambrock//

The European concept of data protection is steadily spreading across the world. In the current decade, it has reached Africa and is being incorporated widely into the legislations across the continent. Only Eritrea, Gambia, Guinea, Sierra Leone, Liberia and Eritrea are exceptions; all other African states have adopted relatively recent data protection legislation (as of 2025). The majority of countries have already established a data protection authority to enforce legal standards, while the remaining ones are still working towards full implementation but are on a clear and consistent path. It is readily apparent that national data protection laws have been more than merely inspired by the European Union’s General Data Protection Regulation. Even though these are not one-to-one adaptations of the EU model, the principles and structure of the GDPR have largely been adopted. This is evident, for example, in the Personal Data Protection Act of the United Republic of Tanzania, which has been applicable since 2023. Consequently, the Tanzanian High Court also regularly refers to EU case law when interpreting national data protection law.

Straight into the smartphone age

Tanzania is not repeating the mistake made, for example, by many Balkan states of adopting the entire catalogue of GDPR obligations in one go. The country is moving rapidly, but gradually, towards the European level of data protection. This is wise given its different starting conditions. Data protection is a new idea there, not a historically evolved legal position. The digitalisation of society has also emerged rather abruptly. The fibre-optic age was skipped altogether. Internet access in Tanzania is entirely mobile-network based. Good reception is available even in remote corners of the savannah. Computers are not widely used, whereas almost everyone has a smartphone. SIM-card sellers in corrugated-iron shacks line the roads even in places where, apart from local foodstuffs, there is little else to buy.

The consequence of smartphone-based communication is that apps dominate social life. WhatsApp is the preferred tool of exchange, displacing all other forms of communication even within public authorities and government circles. Payments are made via transaction apps. Vodacom M-Pesa and Airtel Money are the common payment and transfer services. Taxis do not exist; app-based services such as Bolt and Uber perform this function and arrange rides on motorcycles, in three-wheeled bajajis or in cars. This has given rise to functioning, flourishing app-based business models that are largely beyond state regulation. The government is increasingly endeavouring to get this digital jungle under control through reforms, including in banking regulation.

Personal data protection principles

Data protection has constitutional status in Tanzania (Article 16 CURT). Since May 2023, statutory obligations have followed from the Personal Data Protection Act (PDPA). The basic principle is enshrined in Article 22(2)–(3): the collection of personal data is permissible only if it is necessary, serves a lawful purpose and does not involve collection by unlawful means. There is therefore no legal principle like the general prohibition subject to legal authorisation as in Article 6 GDPR. However, Article 22 PDPA has a partly similar effect in practice. If both the purpose and the conduct of data collection must be lawful, these indeterminate legal concepts necessarily imply a balancing of interests. Consent, by contrast, plays a minor role; it is relevant only in relation to sensitive categories of data. Sensitive data are protected in a manner similar to Article 9 GDPR, although the catalogue also includes children’s data and financial transactions. A counterweight to the relatively broad provision to collect data is the strongly developed purpose-limitation principle. It is reinforced by a principle of direct collection, according to which data should primarily be collected from the data subject itself and may then generally be used only for the purpose for which they were collected.

Data subject rights are comparatively weak. The right to information covers only a few items of metadata, such as the purposes of processing and the recipients of the data. In addition, the PDPA contains an individual right to object to processing operations that are likely substantially to harm data subjects or third parties.

Transfers to third countries are regulated, although data exporters are not provided with adequacy decisions. The requirements differ depending on whether the recipient state has an adequate or inadequate level of data protection. Exporters must assess for themselves whether adequacy exists. Contracts similar to the EU’s Standard Contractual Clauses would certainly suggest themselves as a means of increasing the level of protection in individual cases; the Act itself provides no real guidance.

The High Court does its job

The High Court has swiftly trimmed back essential parts of the new data protection legislation. In the constitutional petition in Magoti v Attorney General (Case No. 18 OF 2023), key provisions were declared inapplicable. In particular, the High Court found that the PDPA’s most important constituent element, “unlawful means” as a limitation on data collection, is not defined and is also too vague for a criminally sanctioned provision. The Court recognises that where consent is given, there are no unlawful means. Where consent is not given, however, the Court raises the question of who is to determine which purposes are unlawful. It assigns the task of defining this unequivocally to the legislature.

The High Court gave the legislature a period of one year in which to amend the Act. Following the judgment of 8 May 2024, that period has expired without result. In the event that the PDPA was not supplemented in time, the High Court provided in its judgment: “Failure to do so these provisions will be struck out of the statute book.” The result is curious. Tanzania currently has a highly differentiated data protection regime whose core provision is, for the time being, inapplicable.

Bureaucracy first

In the East African states, there is a discernible tendency to design new legislative initiatives in such a way that regulatory authorities gain an overview of the market. This is understandable against the background of the relatively unregulated digital jungle described above. While deregulation and the reduction of bureaucracy are currently en vogue in Europe, Tanzania has therefore arrived at some surprising rules. For example, the PDPA contains a prohibition on any processing of personal data without prior registration with the data protection authority as a controller or processor. The obligation contains no exceptions, no de minimis threshold and also applies to natural persons. Depending on the size of the undertaking, an annual fee equivalent to between EUR 32 and EUR 322 is payable. The documents to be submitted are the certificate of incorporation or extract from the register, or, in the case of natural persons, the identity card. In addition, the intended data processing operations must be specified in the form. After five years, re-registration is required at half the fee. The registration obligation is accompanied by a quarterly reporting obligation to the data protection authority concerning compliance. Every controller and processor must designate their own data protection officer; there are no exceptions.

Why Tanzania matters to Europe

Why is all this relevant to us in Europe? Because East Africa matters. First, as a market with enormous future potential. If countries such as Tanzania align their digital law with Western standards, this makes market entry easier for European companies and more difficult for companies from the Far East. Moreover, any engagement in the region is a sound investment. Since the United States has withdrawn from development aid and Russia is running out of resources, it makes sense in several respects to support Tanzania’s position as an anchor of stability in Africa. At a time when, regrettably, migration restrictions have become the overriding rationale of the state in many European countries, countries such as Tanzania are taking in large numbers of refugees and exerting a positive influence on their neighbours. Economic growth through a digitalisation that respects the population’s fundamental rights is also very much in Europe’s own interest.

Dr Jens Ambrock is Head of Department at the Office of the Hamburg Commissioner for Data Protection and Freedom of Information. In addition, he is Junior Project Leader of the EU Twinning Project Digital for Tanzania. This article reflects the author’s personal opinion and was not written in any official capacity.