Practical Guide to Cross-Border Transfers of Personal Data from Tanzania

By Equilex Law Group

The Personal Data Protection Act, Chapter 44, Revised Edition 2023 (PDPA), together with the Personal Data Protection (Personal Data Collection and Processing) Regulations, Government Notice No. 449C of 2023, regulates the transfer of personal data outside Tanzania.

Although the PDPA distinguishes between transfers to countries with an adequate legal framework and those without one, the practical position is that all cross-border transfers of personal data require prior approval from the Personal Data Protection Commission (PDPC) before the transfer takes place.

Step 1: Determine the Destination Country
The first consideration is whether the recipient country has an adequate legal framework for the protection of personal data.

• Countries with an adequate legal framework – Transfers are governed primarily by section 31 of the PDPA.

• Countries without an adequate legal framework – Transfers are governed by section 32 of the PDPA, provided the data controller demonstrates that appropriate safeguards are in place.

Step 2: Identify the Legal Basis for the Transfer
The data controller should identify the legal basis that justifies the proposed transfer.

Where section 31 applies, the controller should demonstrate that the transfer is necessary for lawful functions or otherwise satisfies the statutory requirements.

Where section 32 applies, the controller must establish that appropriate safeguards exist to protect the rights and freedoms of data subjects. These safeguards may include contractual protections, technical and organisational security measures, or other mechanisms capable of ensuring an adequate level of protection.

In addition, section 32(4) provides several independent grounds that may permit a transfer even where the recipient country does not provide an adequate level of protection. These include, among others, transfers based on the data subject’s consent, contractual necessity, legal obligations, protection of vital interests, public interest, or legal proceedings.

Step 3: Apply for PDPC Approval
Before any personal data leaves Tanzania, the data controller or processor must submit an application to the PDPC using Form No. 7 prescribed under Regulation 20 of the Personal Data Protection Regulations.

The application should clearly explain:
• the purpose of the transfer;
• the categories of personal data involved;
• the recipient and destination country;
• the legal basis for the transfer;
• the safeguards implemented to protect the data; and
• any other supporting documentation requested by the PDPC.

Step 4: PDPC Assessment
The PDPC reviews each application individually.
Its assessment is based on:
• the nature and sensitivity of the personal data;
• the purpose and scope of the transfer;
• the legal basis relied upon;
• the adequacy of the recipient country’s legal framework (where applicable); and
• the technical, organisational and contractual safeguards implemented by the applicant.

The Commission may also conduct its own independent verification before granting approval.
Practical Points
• Prior PDPC approval is required for every cross-border transfer of personal data from Tanzania.
• The application requirements are not identical in every case. The PDPC assesses each application according to its specific facts and circumstances.
• Data subject consent is not always required. Where another lawful ground under section 32(4) applies, approval may still be granted without consent.
• Section 32(5) should not be interpreted as the exclusive legal basis for international transfers. Rather, it provides flexibility for transfers to jurisdictions lacking adequate data protection laws, provided the PDPC is satisfied that appropriate safeguards exist.
• The PDPC is the authority responsible for determining whether a recipient jurisdiction provides an adequate level of protection and whether the proposed safeguards comply with the PDPA.

Key Takeaway
From both the legislative framework and current regulatory practice, organizations intending to transfer personal data outside Tanzania should treat PDPC approval as a mandatory first step. Early planning, proper documentation and clearly demonstrating the legal basis and safeguards for the transfer will significantly improve the likelihood of obtaining approval.

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *