Law / Tanzania

Tanzania

12 of 13 named instruments researched to a stage, across five of the six areas of law we track: 12 in force. As of 6 September 2026.

When they take effect12 of 12 carry a date. Earlier is before 2014.
Before 2014: 2 instruments (2 in force) earlier 2014: 0 instruments 2015: 1 instrument (1 in force) ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 1 instrument (1 in force) ’20 2021: 0 instruments 2022: 0 instruments 2023: 7 instruments (7 in force) 2024: 1 instrument (1 in force) 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 6
  3. Scraping law 3
  4. Cybersecurity law none researched
  5. Age gating law 1
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (95 words)

Tanzania has not enacted a general AI-specific statute governing transparency, risk classification or governance duties.

The one AI-specific duty located in the researched text is a criminal prohibition: the Cybercrimes Act, 2015, as amended by the Child Protection Laws (Miscellaneous Amendments) Act, 2024, bans producing, offering, distributing or possessing child sexual abuse material through a computer system, and its amended definition expressly reaches computer-generated material, whether created, adopted or modified, that cannot be differentiated from a real child.

No other AI transparency, risk-obligation, training-data, governance or sector-specific duty has been located in primary Tanzanian legislation.

AI prohibited practices

Cybercrimes Act, 2015, child sexual abuse material including computer-generated content

Cybercrimes Act 2015 (Act No. 14 of 2015), s. 13, as substituted by the Child Protection Laws (Miscellaneous Amendments) Act, 2024 (Act No. 10 of 2024), s. 5 (child sexual abuse material)official Gazette Act Supplement text, Office of the Attorney General Management Information System (oagmis.oag.go.tz)

In force since 2 October 2024. Binds public and private bodies.

What this law does

The Child Protection Laws (Miscellaneous Amendments) Act, 2024 repealed and replaced section 13 of the Cybercrimes Act, and amended section 3's definitions to add 'child sexual abuse material' or 'child sexual exploitation material', defined to mean any image, video, audio or written content depicting sexual acts involving a child or portraying a child in a sexualised manner, and to include any image, video or computer-generated material, whether created, adopted or modified, which cannot be differentiated from a real child.

As substituted, section 13 prohibits producing, offering, distributing, transmitting, procuring or knowingly possessing such material through a computer system, and prohibits compelling, inviting or allowing a child to view pornography or such material.

A person convicted is liable to a fine of not less than TZS 50,000,000 or three times the undue advantage received, whichever is greater, or imprisonment for a term of not less than seven years, or both, and may additionally be ordered to compensate the victim.

What it requires

Privacy law6 instruments, 6 in force

Research summary (237 words)

Tanzania's comprehensive personal-data regime is the Personal Data Protection Act, 2022 (Act No. 11 of 2022), which came into force on 1 May 2023 and establishes the Personal Data Protection Commission, binding every data controller or processor that collects or processes personal data, whether by automated or non-automated means.

A controller or processor must register with the Commission before collecting or processing personal data, and the Act's application clause carries no carve-out for personal data that is otherwise publicly accessible. Biometric data and data related to children are expressly listed as sensitive personal data, which may not be processed without the data subject's prior written consent.

Data subjects hold rights of access, objection to automated decision-making, and correction or erasure, and a data subject who suffers damage from a contravention is entitled to compensation from the controller or processor. Cross-border transfer requires the Commission's satisfaction as to adequate safeguards or that an adequate level of protection exists in the recipient country.

A controller must notify the Commission without undue delay of a security breach affecting personal data, though the Act sets no fixed notification deadline and imposes no separate duty to notify the affected data subject. The Commission may impose an administrative penalty of up to TZS 100,000,000, alongside criminal offences carrying fines and imprisonment terms that scale with the conduct, up to a fine of TZS 5,000,000,000 for a corporation convicted of unlawfully selling personal data.

Breach notification

Personal Data Protection Act, 2022, security and breach notification

Personal Data Protection Act, 2022 (Act No. 11 of 2022), s. 27 (security of personal data)official consolidated Act text, Office of the Attorney General Management Information System (oagmis.oag.go.tz)

In force since 1 May 2023. Binds public and private bodies.

What this law does

A data controller must protect personal data with security safeguards reasonable in the circumstances, and must notify the Personal Data Protection Commission without undue delay of any security breach affecting personal data being processed by or on behalf of the controller. The Act sets no fixed notification deadline and imposes no separate statutory duty on the controller to notify the affected data subject directly.

What it requires

Comprehensive regime

Personal Data Protection Act, 2022

Personal Data Protection Act, 2022 (Act No. 11 of 2022), ss. 1-5, 14, 21-26 (principles, application and registration)official consolidated Act text, Office of the Attorney General Management Information System (oagmis.oag.go.tz)

In force since 1 May 2023. Binds public and private bodies.

What this law does

The Personal Data Protection Act, 2022 establishes the Personal Data Protection Commission and requires every data controller or processor to process personal data lawfully, fairly and transparently, collected for explicit, specified and legitimate purposes.

A person may not collect or process personal data without first registering as a data controller or data processor with the Commission, and public institutions that collect or process personal data are deemed registered from the Act's commencement. The Act applies to Mainland Tanzania and to Tanzania Zanzibar, except that in Zanzibar it does not reach non-union matters.

What it requires

Cross border transfer

Personal Data Protection Act, 2022, transborder data flow

Personal Data Protection Act 2022 (Act No. 11 of 2022), Part V (ss. 31-32, transfer of personal data to states with and without adequate data protection)official consolidated Act text, Office of the Attorney General Management Information System (oagmis.oag.go.tz)

In force since 1 May 2023. Binds public and private bodies.

What this law does

Personal data may be transferred to a country with an adequate personal-data-protection legal framework where the recipient establishes that the transfer is necessary and can subsequently verify that necessity, and the data controller ensures the recipient processes the data only for the purpose for which it was transferred.

A transfer to a country without such a framework is permitted only where an adequate level of protection is otherwise ensured and the data is transferred solely to permit authorised processing.

What it requires

Data subject rights

Personal Data Protection Act, 2022, rights of data subjects

Personal Data Protection Act 2022 (Act No. 11 of 2022), Part VI (ss. 33-38, rights of data subjects, including automated decision-making, s. 36, and compensation, s. 37)official consolidated Act text, Office of the Attorney General Management Information System (oagmis.oag.go.tz)

In force since 1 May 2023. Binds public and private bodies.

What this law does

A data subject is entitled to be informed whether a controller is processing their personal data and to a description of that processing. Section 36 gives a data subject the right to require a controller to ensure that a decision significantly affecting them is not based solely on automated processing, subject to exceptions for contract performance, statutory authorisation or the subject's explicit consent, and lets the subject require the controller to reconsider the decision.

Section 37 entitles a data subject who suffers damage from any contravention of the Act to compensation from the controller or processor, and the Commission may separately order payment of compensation as part of its enforcement powers.

What it requires

Enforcement supervision

Personal Data Protection Act, 2022, investigation, enforcement and offences

Personal Data Protection Act 2022 (Act No. 11 of 2022), Part VII (ss. 39-50, investigation and enforcement) and Part IX (ss. 60-64, offences and general penalty)official consolidated Act text, Office of the Attorney General Management Information System (oagmis.oag.go.tz)

In force since 1 May 2023. Binds public and private bodies.

What this law does

A person may complain to the Commission of a violation of the personal-data-protection principles, and the Commission may investigate, issue an enforcement notice, and impose an administrative penalty of up to TZS 100,000,000 for a contravention of the Act. A person aggrieved by the Commission's decision may appeal to the High Court.

Separate criminal offences attach to specific conduct: unlawfully selling or disclosing personal data, and unlawfully destroying, deleting, concealing or altering personal data, each carrying its own fine and imprisonment range, and any other contravention with no specifically stated penalty carries a general penalty.

What it requires

Sensitive categories

Personal Data Protection Act, 2022, sensitive personal data

Personal Data Protection Act, 2022 (Act No. 11 of 2022), s. 30 (prohibition on processing of sensitive personal data)official consolidated Act text, Office of the Attorney General Management Information System (oagmis.oag.go.tz)

In force since 1 May 2023. Binds public and private bodies.

What this law does

Sensitive personal data, defined to include genetic data, data related to children, data related to offences, financial transactions, security measures and biometric data, may not be processed without the data subject's prior written consent, which may be withdrawn at any time without explanation or charge.

The Minister may by regulation determine circumstances in which the prohibition cannot be removed even with the data subject's consent, and where the data subject is a minor, a person of unsound mind, or another person unable to consent, consent must instead be sought from a parent, guardian or other legal representative.

What it requires

Scraping law3 instruments, 3 in force

Research summary (241 words)

Tanzania has no scraping-specific statute, so general law governs each dimension separately.

The Cybercrimes Act, 2015 criminalises unauthorised access to a computer system, but section 4 requires the access itself to be intentional and unlawful; the Act does not require defeating a security measure for the illegal-access offence, so a person who accesses a public, unauthenticated page without authorisation is not obviously outside the offence's reach, and no reported case has tested the point for ordinary web crawling.

No Tanzanian court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper. The Copyright and Neighbouring Rights Act, 1999 permits free use for personal use, quotation, criticism or review, and reporting of current events, but Tanzania has not enacted a text-and-data-mining exception, so training a model on scraped copyrighted text is not addressed by any text and data mining (TDM)-specific rule.

The same Act protects a compilation of data or a database as an original work only where its selection or arrangement constitutes intellectual creation, so Tanzania recognises no separate sui generis database right.

The Personal Data Protection Act, 2022 applies to personal data without a general carve-out for information that is otherwise publicly accessible, so scraping personal data from a public Tanzanian website remains subject to the Act's registration, lawful-basis and cross-border-transfer duties.

No Tanzanian statute or reported case establishes a scraping-specific unfair-competition, misappropriation or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Cybercrimes Act, 2015, unauthorised access and interference offences

Cybercrimes Act 2015 (Act No. 14 of 2015), ss. 4-9 (illegal access, illegal remaining, illegal interception, illegal data interference, illegal system interference, data espionage)Cybercrimes Act text as republished by TanzLII

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived September 5, 2025. Publisher's page: https://tanzlii.org/akn/tz/act/2015/14/eng@2015-05-22

In force since 1 September 2015. Binds public and private bodies.

What this law does

Section 4 prohibits intentionally and unlawfully accessing or causing a computer system to be accessed, carrying a fine of not less than TZS 3,000,000 or three times the undue advantage received, or imprisonment of not less than one year, or both. Section 5 separately prohibits remaining in a computer system beyond authorised time. Section 6 prohibits illegal interception of non-public transmissions or electromagnetic emissions.

Section 7 prohibits illegal data interference, including damaging, deleting or altering computer data, carrying a fine of not less than TZS 10,000,000 or imprisonment of not less than three years, or both. Section 8 prohibits data espionage, obtaining computer data protected against unauthorised access, carrying imprisonment of not less than five years. Section 9 prohibits illegal system interference, hindering the functioning or usage of a computer system.

Unlike a statute that conditions the illegal-access offence on defeating a security measure, section 4's text requires only that the access be intentional and unlawful, without an express security-circumvention element, and no reported Tanzanian decision has addressed whether reading a public, unauthenticated page without authorisation from the site operator falls within the offence.

What it requires

Personal data

Personal Data Protection Act, 2022, application to processing of personal data

Personal Data Protection Act, 2022 (Act No. 11 of 2022), s. 22 (application: collection of personal data)official consolidated Act text, Office of the Attorney General Management Information System (oagmis.oag.go.tz)

In force since 1 May 2023. Binds public and private bodies.

What this law does

The Personal Data Protection Act, 2022 applies to any collection and processing of personal data performed wholly or partly by manual or automated means, by a controller domiciled in Tanzania or otherwise reached by the Act, with no carve-out for personal data that is otherwise publicly accessible.

Scraping personal data from a public Tanzanian website therefore remains subject to the Act's registration, lawful-basis, and cross-border-transfer duties, and biometric data is a sensitive personal data category carrying a heightened prior-written-consent requirement.

What it requires

Age gating law1 instrument, 1 in force

Research summary (109 words)

Tanzania has not enacted a law that specifically imposes age-verification duties on adult-content services, social media platforms or app stores, and has no age-appropriate design code enacted as a statute.

The Tanzania Communications Regulatory Authority has instead made the Electronic and Postal Communications (Online Content) Regulations, 2020 under the Electronic and Postal Communications Act, which direct every person who provides, has access to, hosts, or uses online content, or who operates an internet cafe, to take all possible measures to ensure that children do not register, access or contribute to prohibited content, and that users are given a content-filtering mechanism and parental control, without prescribing a particular age-verification method.

Age-appropriate design code

Electronic and Postal Communications (Online Content) Regulations, 2020, children protection

Electronic and Postal Communications (Online Content) Regulations, 2020 (GN No. 538 of 2020), reg. 18 (children protection)Electronic and Postal Communications (Online Content) Regulations

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived May 5, 2021. Publisher's page: https://www.tcra.go.tz/document/The%20Electronic%20and%20Postal%20Communications%20(Online%20Content)%20Regulations,%202020

In force since 17 July 2020. Binds private bodies.

What this law does

Made by the Tanzania Communications Regulatory Authority under section 103 of the Electronic and Postal Communications Act (Cap. 306), these Regulations apply to online content service providers, internet service providers, application service licensees, online content users and other related online content.

Regulation 18 requires any person who provides, has access to, hosts, uses online content, or operates an internet cafe to take all possible measures to ensure that children do not register, access or contribute to prohibited content, and that users are provided with a content-filtering mechanism and parental control.

The Regulations carry a general penalty for any contravention for which no specific punishment is provided, and were published in the Gazette on 17 July 2020, revoking the prior 2018 online content Regulations.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (139 words)

Tanzania has no press-publisher neighbouring right, no compelled platform-to-publisher bargaining regime, no recognised hot-news or misappropriation doctrine distinct from ordinary copyright law, and no located case law on hyperlinking or framed display.

The general exception available to a news aggregator is the Copyright and Neighbouring Rights Act, 1999's free-use provision, which permits reproduction in the press or communication to the public of an article on current economic, political or religious topics broadcast or published in the press, unless the source expressly prohibits such use and provided the source is clearly indicated, and separately permits reproduction, to the extent justified by an informatory purpose, of a work seen or heard in the course of a current event being reported.

Tanzania has not enacted a machine-readable text-and-data-mining opt-out, so an aggregator's indexing is not addressed by any text and data mining (TDM)-specific rule either way.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.