The Use of Artificial Intelligence (AI) in Tanzania: What Entities Need to Know About Data Protection Compliance
-
Insight Article 20 July 2026 20 July 2026
-
Africa
-
Tech & AI evolution
-
Cyber Risk
Artificial Intelligence (AI) is rapidly transforming the way businesses, financial institutions, healthcare providers, insurers, telecommunications companies, government agencies and generally how most entities operate. AI-powered technologies such as chatbots, virtual assistants, facial recognition systems, automated recruitment platforms, fraud detection tools, predictive analytics and generative AI are increasingly being used to improve efficiency, decision-making and service delivery.
While Tanzania has not yet enacted a specific legislation regulating the use of AI, entities deploying AI technologies are not operating in a legal vacuum. In particular, the Personal Data Protection Act, Chapter 44 Revised Edition 2023 (the PDP Act) and the Personal Data Protection (Personal Data Collection and Processing) Regulations, GN No. 449C of 2023 (the Collection and Processing Regulations), impose general obligations on entities that process personal data through automated means including AI systems.
Although the PDP Act and the Collection and Processing Regulations constitute the primary legal framework governing AI-driven processing of personal data, the deployment and use of AI may also be subject to other laws depending on the nature of the AI system and the activities it performs. These include:
- the Electronic and Postal Communications Act, Chapter 306 Revised Edition 2023;
- the Electronic Transactions Act, Chapter 255 Revised Edition 2023;
- the Cybercrimes Act, Chapter 443 Revised Edition 2023; and
- institutional or sector-specific legislation and guidelines governing the use of AI in sectors such as education, healthcare, telecommunications and financial services
This legal update examines the current legal framework relevant to AI in Tanzania and highlights the key data protection considerations arising from the development, procurement and deployment of AI technologies, including lawful processing, transparency, security, and general AI governance.
Why AI raises data protection concerns on entities
Most AI systems function by collecting, analysing and learning from data. Where such data relates to an identifiable individual, it constitutes personal data within the meaning of section 3 of the PDP Act. AI systems that commonly process personal data include:
- customer profiling and targeted advertising;
- employee recruitment and performance assessment;
- fraud detection and credit scoring;
- facial recognition and biometric authentication;
- healthcare diagnostics and predictive analytics; and
- generative AI systems trained using personal data.
It is worth noting that, given the reliance of AI systems on large datasets and automated decision-making processes, their use may give rise to a range of data protection concerns, including:
- unauthorised access to personal data;
- personal data breaches; and
- cybersecurity risks that may compromise the confidentiality, integrity and security of personal data.
Data protection obligations for entities deploying AI systems: Key take aways
Entities deploying AI systems that process personal data should ensure compliance with the PDP Act, the Collection and Processing Regulations and other relevant governing laws throughout the AI lifecycle. Key considerations may include:
- determining whether the AI system processes personal data within the meaning of section 3 of the PDP Act;
- identifying a lawful basis for processing personal data through the AI system and ensuring that such processing complies with regulation 25 of the Collection and Processing Regulations;
- ensuring compliance with the fundamental principles of data protection under section 5 of the PDP Act and regulations 23 to 30 of the Collection and Processing Regulations, including:
- lawfulness, fairness and transparency;
- purpose limitation;
- data minimisation;
- accuracy;
- storage limitation;
- integrity and confidentiality; and
- accountability;
- maintaining transparency by complying with the notification requirements under section 23 of the PDP Act and informing data subjects where personal data is processed through AI systems, including where automated decision-making is involved under regulation 19(3) of the Collection and Processing Regulations;
- implementing appropriate technical and organisational security measures to safeguard personal data in accordance with section 25 of the PDP Act and regulation 27 of the Collection and Processing Regulations;
- conducting due diligence on third-party AI service providers and ensuring compliance with the requirements applicable to data processors under section 27(4) of the PDP Act;
- complying with the cross-border data transfer requirements under sections 31 and 32 of the PDP Act and regulations 20 to 22 of the Collection and Processing Regulations; and
- Adopting appropriate AI governance measures, including:
- conducting AI and privacy risk assessments;
- maintaining meaningful human oversight over high-impact decisions;
- testing for bias and discriminatory outcomes;
- maintaining adequate documentation and audit trails; and
- periodically reviewing AI systems to ensure ongoing legal and ethical compliance.
Emerging best practices
Although Tanzania has not yet enacted a specific legislation regulating AI, unlike jurisdictions such as the European Union (EU), which has adopted a comprehensive legal framework governing AI system, organisations should, nevertheless, consider implementing appropriate AI governance measures to promote accountability, transparency and the responsible use of AI. These measures may include:
- adopting internal AI governance policies and procedures;
- conducting AI and data protection impact assessments (DPIAs) prior to deployment;
- maintaining meaningful human oversight over high-impact or automated decisions;
- documenting AI development, testing and deployment processes;
- maintaining appropriate records and audit trails for AI-assisted decisions; and
- periodically reviewing AI systems to ensure ongoing legal, ethical and operational compliance.
Conclusion
Although AI presents significant opportunities for organisations through increased efficiency, enhanced decision-making and improved service delivery, its adoption must be accompanied by compliance with applicable legal and regulatory requirements. While Tanzania has not yet enacted specific legislation regulating AI, organisations deploying AI systems that process personal data must ensure compliance with the PDP Act, the Collection and Processing Regulations and other applicable laws, and adopt appropriate governance measures to support the responsible use of AI.
End

