FEEDBACK & FAQs
MASWALI YANAYOULIZWA MARA KWA MARA
FAQ
FAQ
20 questionsThe main responsibility of the DPO is to ensure that his Institution/Company fully implements the requirements of the Personal Data Protection Act, Chapter 44 of the Year 2022(PDPA).
In order to ensure that this is done correctly, these are some of his legal responsibilities as set out in the Personal Data Protection Act:-
(a). Ensuring Compliance with Personal Data Protection Act and its Regulations in the processing of Personal Data carried out by the Data Collector/ Data Processor.
(b). Providing Information to the Commission when there is a violation of the provisions of the PDPA or its Regulations for the Protection of Personal Data in the Processing/Collection of Data at its Institution/Company.
(c). Prepare Report on the Implementation of the Personal Data Protection Act and submit it to the Commission every Quarter.
(d). To supervise the implementation of the Data Privacy Policy of the Institution/ Company.
(e). Requesting Data Transfer permit to export Personal Data outside of Tanzania.
(f). Attending the Specialized Training of Data Protection Officers provided by the Personal Data Protection Commission (PDPC).
(g). To provide Data protection education to their colleagues.
Through Article Fourteen (14) of the Personal Data Protection Act in the country, every Person, Institution/Office whether Public or Private that is involved in the Collection and Processing of Personal Data or one of them i.e. Only Collection/Only Processing should register with PDPC.
In short, all Institutions/Companies in the country should be registered and obtain relevant Certificates from PDPC because no Institution/Company can perform its duties without Collecting and Processing Personal Information. An example of such Personal Information is as follows:-
- Names of people.
- Phone numbers.
- Email (email).
- Identification Number. (NIDA, Zanzibar Resident, License)
- Health information.
- Biometric data.
- Employee records.
- Customer databases.
- CCTV recordings.
- Any personally identifiable information.
If your Institution/Company is involved in the Collection, Processing, Storage or Use of Personal Data without registering with PDPC, you may face legal, operational and even strategic consequences for your Office.
Here are some of the possible side effects:
(a). Fines and Penalties
- Given an official warning by the PDPC
- The PDPC may charge you a fine, imprisonment or both
- Lack of various Government Services (Systems not compatible)
- PDPC Prevents You from Collecting and Processing Personal Information
This depends on the severity of the violation and the harm caused.
(b). Loss of Customer Confidence
When customers discover that your establishment:
- Not registered,
- Does not protect their Data properly,
- or does not comply with the Personal Data Protection Act, Chapter 44 of the Year 2022.
They may lose confidence in your company.
Remember in the digital World, Customer Loyalty is a very valuable asset.
(c). Risk of Data Leakage (Data Breach)
Without PDPC management:
- Many organizations lack proper Personal Information Protection systems.
- Many organizations lack Privacy Policies or Cybersecurity Controls.
This can cause:
- Theft of Personal Information
- Misuse of Personal Information.
(d). Lack of Partnership Opportunities
Many international organizations, banks, telecoms and development stakeholders check compliance with the Personal Data Protection Act before co - operating with the Institute.
So unsubscribing can:
- Affect Partnerships.
- Bid.
- Investment.
Yes, there is a registration fee. In accordance with the Personal Data Protection Act, Chapter 44 of 2022, the cost of obtaining one PDPC Certificate ranges from TZS 100,000/= to TZS 1,000,000/= per Certificate so for two certificates, the applicable fee ranges from TZS 200,000/= to TZS 2,000,000/=
Please note: Every institution/company is required to obtain two separate certificates: • Data Controler Certificate
• Data Processer Certificate
There are three key factors that determine the variation in the cost of the respective certificates:
(a) The type of institution {whether it is a Government Institution, a Private Commercial Institution or a Private Non-Governmental Organization (NGO)}
(b) The number of employees {applicable to private commercial institutions}
(c) The Financial Audit Report {applicable to private commercial institutions}
If your institution/ company is involved in the collection / processing of personal data, you are required to have the following documents in order to complete registration with PDPC:
(a) An introduction letter appointing the institution’s Data Protection Officer (DPO), duly designated and signed by the Head of the Institution.
(b) A Business Registration Certificate and Business License.
(c) A Financial Statement Audit Report.
Please note: Requirements (b) and (c) apply only to private commercial institutions/companies.
Registration is conducted entirely online through our official website:
Once on the website, navigate to the section labeled “Our Services” and select the option marked “Registration” to begin the registration process.