Statutory Limitations on Data Subject Rights under Tanzania's Personal Data Protection Act.

  • Insight Article 2026年8月20日 2026年8月20日
  • 非洲

  • Regulatory movement

The Personal Data Protection Act, Chapter 44, Revised Edition 2023 (the PDP Act) and the Personal Data Protection (Personal Data Collection and Processing) Regulations, Government Notice No. 449C of 2023 (the Collection and Processing Regulations) establish a comprehensive framework for the protection of personal data in Tanzania.

Among other things, the PDP Act grants data subjects several rights, including the right of access to personal data, the right to prevent certain processing activities, the right to prevent processing of personal data for direct marketing purposes, the right in relation to automated decision-making, and the right to seek rectification, blocking, erasure or destruction of personal data.

However, the rights conferred on data subjects under the PDP Act and the Collection and Processing Regulations are not absolute. The PDP Act recognises that, in certain circumstances, the exercise of these rights may need to be limited or restricted to protect competing interests, including compliance with legal obligations, the administration of justice, law enforcement objectives, and the rights of data subjects, data controllers and data processors. In particular, certain provisions of the PDP Act set out statutory limitations and exceptions to the exercise of data subject rights.

This legal update examines the key statutory limitations on data subject rights under the PDP Act and their practical implications for entities involved in the collection and processing of personal data in Tanzania.

Exceptions and limitations on data subject rights under the PDP Act

While the PDP Act grants data subjects several rights in relation to their personal data, the exercise of those rights is subject to certain statutory exceptions and limitations. These limitations include:

(a)    Limitations on the right of access to personal data

Pursuant to section 33(2) of the PDP Act, a data controller is not required to inform a data subject about the collection or processing of their personal data where the personal data:

(i) is inaccurate;

(ii) is the subject of an investigation conducted in accordance with applicable law; or

(iii) is subject to a court order prohibiting disclosure.

For example: a bank may decline a customer's request for access to information where that information forms part of an ongoing financial crime investigation. Similarly, a data controller may refuse disclosure where it is prohibited by a court order, or where the information requested is inaccurate and remains subject to verification or correction.

(b)    Limitations on rights in relation to automated decision-making

Under section 36(3) of the PDP Act, the protections relating to automated decision-making do not apply where the decision is:

(i) necessary for entering into, or performing, a contract between the data subject and the data controller;

(ii) authorised by written law; or

(iii) made with the data subject’s explicit consent.

For example: where a customer applies online for a mobile phone service, the service provider may use an automated system to verify the customer’s details and assess eligibility for the service. Although the decision is made solely through automated processing, the customer may not object to that automated decision-making where it is necessary for entering into, or performing, the service agreement requested by the customer.

Practical considerations for entities

Although the PDP Act recognises circumstances in which data subject rights may be restricted, entities should rely on these limitations cautiously and on a case-by-case basis. In particular, entities should:

(a)    assess each request on its own facts to determine whether the relevant exemption or limitation applies;

(b)    keep clear records of the request, the assessment undertaken and the legal basis for refusing or limiting the exercise of the data subject’s rights;

(c)    avoid blanket reliance on exemptions, as their application will depend on the circumstances of each case;

(d)    seek guidance from their Data Protection Officer or legal advisers where the interpretation or application of an exemption is unclear; and

(e)   ensure internal policies and procedures clearly address the handling of data subject requests and the circumstances in which rights may lawfully be restricted.

These steps will help entities demonstrate compliance with the PDP Act while promoting transparency and accountability in the handling of personal data.

Conclusion

The statutory limitations and exceptions under the PDP Act recognise that data protection rights must, in certain circumstances, be balanced against other legitimate interests, including legal compliance, law enforcement, the administration of justice and  public interest. Although data subjects enjoy important rights under the PDP Act, those rights are not absolute. Entities should therefore understand when such rights may lawfully be restricted and ensure that any reliance on an exemption is supported by a clear legal basis. A careful, proportionate and well-documented approach to data subject requests will help organisations demonstrate compliance with the PDP Act while maintaining trust and accountability in their processing of personal data.

结束

Clyde.Insights.Areas:

  • Legal Development

掌握其礼的最新消息

注册您的邮箱,获取其礼最新消息!