Skip to content

Evidence request lists

Tanzania Personal Data Protection Act (Draft)

Evidence request list. 23 controls, 23 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Consent

TANZANIA-2
Consent, Notice, Sensitive

Per TZ PDPA: consent + notice + Collection Without Consent exceptions + sensitive data.

Artefacts an auditor will ask for
  • TZ PDPA evidence for TANZANIA-2
Where this commonly fails
  • registration + PDPC partial

Governance

TANZANIA-5
DPO, Governance, Breach

Per TZ PDPA: DPO + PDPC notification + breach notification + enforcement.

Artefacts an auditor will ask for
  • TZ PDPA evidence for TANZANIA-5
Where this commonly fails
  • registration + PDPC partial

Governance, Assessment and Records

TZ-PDPA-05
Data Protection Officer Appointment

Organisations meeting the threshold criteria must appoint a Data Protection Officer with documented independence, suitable expertise, and direct reporting to senior management.

Artefacts an auditor will ask for
  • Board minute appointing the DPO
  • Position description with reporting line
  • DPO contact details published internally and externally
  • Conflict of interest declaration
  • Annual DPO report to executive management
Where this commonly fails
  • DPO role bundled with CISO without independence safeguards
  • DPO contact not registered with the Commission
  • No annual report evidencing oversight
TZ-PDPA-09
Records of Processing Activities

Controllers must maintain a current record of processing activities covering purposes, categories of data and subjects, recipients, transfers, retention, and security measures.

Artefacts an auditor will ask for
  • Centralised RoPA spreadsheet or tooling export
  • Quarterly attestation by business owners
  • Change log showing additions and retirements
  • Mapping of RoPA entries to systems and vendors
  • RoPA extract submitted to the Commission on request
Where this commonly fails
  • RoPA last updated more than a year prior
  • Owners not aware of their RoPA entries
  • Marketing automation flows missing from inventory
TZ-PDPA-10
Data Protection Impact Assessment

High risk processing requires a documented impact assessment covering necessity, proportionality, risks to data subjects, and mitigating measures, with Commission consultation when residual risk remains high.

Artefacts an auditor will ask for
  • DPIA template anchored to Tanzanian context
  • Library of completed DPIAs with sign off
  • Risk register entries linked to DPIA outputs
  • Commission consultation submissions
  • Annual review schedule
Where this commonly fails
  • No trigger criteria documented for when DPIA is required
  • DPIA produced after launch
  • Residual risk not escalated to executive sponsor
TZ-PDPA-15
Staff Training and Awareness

Personnel handling personal data must receive role appropriate training on the Act, the controller's privacy programme, and incident reporting.

Artefacts an auditor will ask for
  • Annual privacy training deck
  • LMS completion reports by team
  • Role based deep dive modules for high risk teams
  • Knowledge check results
  • Awareness campaign evidence such as posters and newsletters
Where this commonly fails
  • Training not refreshed when regulations change
  • Contractor population excluded
  • No effectiveness measurement beyond attendance

Marketing and Complaints

TZ-PDPA-14
Direct Marketing Controls

Direct marketing communications require a lawful basis with clear opt out mechanisms, suppression lists, and respect for consumer preference signals.

Artefacts an auditor will ask for
  • Marketing consent flags in CRM
  • Unsubscribe link audit
  • Suppression list extract and synchronisation evidence
  • Channel level opt out workflow design
  • Sample marketing message archive
Where this commonly fails
  • Cross brand marketing sending without renewed consent
  • SMS suppression list not synced to email platform
  • No double opt in for newly acquired lists
TZ-PDPA-16
Complaints Handling and Commission Cooperation

Controllers must operate an accessible complaints channel, log complaints centrally, and cooperate with Commission investigations and directives.

Artefacts an auditor will ask for
  • Complaint policy with escalation steps
  • Centralised complaint register
  • Sample case files showing investigation steps
  • Commission correspondence archive
  • Director attestation of cooperation
Where this commonly fails
  • Multiple inboxes with no central register
  • No log of Commission engagement
  • Cases closed without root cause analysis

Notice and Data Subject Rights

TZ-PDPA-03
Data Subject Rights Handling

Controllers must operate a documented process to respond to access, correction, deletion, objection, and restriction requests within the statutory response window.

Artefacts an auditor will ask for
  • Documented rights handling procedure
  • Ticketing system extract with request type and closure dates
  • Identity verification workflow
  • Response letter templates in Swahili and English
  • Quarterly metrics on response timeliness
Where this commonly fails
  • No identity verification step before disclosure
  • Rights inbox not monitored on weekends
  • Refusal reasons not logged with statutory citation
TZ-PDPA-06
Privacy Notice Content

Privacy notices must disclose identity of the controller, purposes, lawful basis, retention, recipients, transfer destinations, rights, and Commission complaint route in plain language.

Artefacts an auditor will ask for
  • Master privacy notice with section mapping to statutory requirements
  • Layered notices for mobile and call centre channels
  • Version control log
  • Translation review of Swahili notice
  • Customer facing point of capture screenshots
Where this commonly fails
  • Notice not provided at point of mobile sign up
  • Swahili version trailing English by multiple versions
  • Recipients listed only as categories with no examples
TZ-PDPA-17
Automated Decision Making

Decisions made solely by automated processing with significant effects on data subjects require safeguards, human review options, and explanations.

Artefacts an auditor will ask for
  • Inventory of automated decision systems with personal data inputs
  • Documented human review pathway
  • Explanation templates for adverse decisions
  • Model risk assessments
  • Audit logs of overrides
Where this commonly fails
  • No record of model decisions affecting consumers
  • Human review path not staffed adequately
  • Explanations limited to generic phrasing

Rights

TANZANIA-3
Data Subject Rights

Per TZ PDPA: data subject rights including access + correction + erasure + portability.

Artefacts an auditor will ask for
  • TZ PDPA evidence for TANZANIA-3
Where this commonly fails
  • registration + PDPC partial

Scope

TANZANIA-1
Scope, Registration, Lawful Basis

Per Tanzania Personal Data Protection Act: scope + Duty to Register + Registration Application + lawful basis. Align with PDPC Tanzania.

Artefacts an auditor will ask for
  • TZ PDPA evidence for TANZANIA-1
Where this commonly fails
  • registration + PDPC partial

Scope, Registration and Lawful Basis

TZ-PDPA-01
Lawful Basis for Processing

Controllers must establish and document a lawful basis under the Act for every category of personal data processed, with consent, contract, legal obligation, vital interest, public function, or legitimate interest each requiring distinct evidence.

Artefacts an auditor will ask for
  • Record of processing activities mapped to lawful basis
  • Consent capture logs with timestamp and version
  • Legal obligation register citing Tanzanian statutes
  • Legitimate interest assessments
  • Annual review minutes of lawful basis register
Where this commonly fails
  • Default reliance on consent for activities better grounded on contract or legal obligation
  • No version history for consent text
  • Legitimate interest balancing tests not documented
TZ-PDPA-02
Registration with the Personal Data Protection Commission

Data controllers and processors operating in Tanzania must register with the Personal Data Protection Commission, maintain a current registration certificate, and renew on schedule.

Artefacts an auditor will ask for
  • Registration application package
  • Issued registration certificate
  • Renewal receipts and acknowledgements
  • Internal calendar entries for renewal milestones
  • Updates to registered processing scope filed with the Commission
Where this commonly fails
  • Subsidiaries processing data without separate registration
  • Renewal lapses past the regulatory window
  • Scope changes not refiled when new processing activities are launched
TZ-PDPA-18
Data Localisation Considerations

Certain categories of personal data may be subject to local storage expectations or sector specific localisation rules, requiring inventory of storage locations and mitigation plans.

Artefacts an auditor will ask for
  • Storage location map by system
  • Sector regulator correspondence on localisation
  • Mitigation roadmap when storage is offshore
  • Cloud region selection rationale
  • Annual review of localisation status
Where this commonly fails
  • Cloud workloads in regions never reviewed against Tanzanian rules
  • No mapping of sector specific localisation requirements
  • Mitigation plans treated as one off rather than living documents

Security

TANZANIA-4
Security and Cross-Border

Per TZ PDPA: security + cross-border with PDPC approval.

Artefacts an auditor will ask for
  • TZ PDPA evidence for TANZANIA-4
Where this commonly fails
  • registration + PDPC partial

Security and Breach Notification

TZ-PDPA-07
Security Safeguards

Controllers and processors must apply technical and organisational measures proportionate to the risk, with documented standards covering access control, encryption, logging, and incident detection.

Artefacts an auditor will ask for
  • Information security policy approved by the board
  • Access control matrix mapped to systems holding personal data
  • Encryption inventory for data at rest and in transit
  • Log retention configuration and SIEM use case catalogue
  • Penetration test reports and remediation tracker
Where this commonly fails
  • Encryption not applied to historical backups
  • SIEM lacks use cases for personal data exfiltration
  • Pen tests scoped to public sites only, missing internal systems
TZ-PDPA-08
Breach Notification to the Commission

Notifiable personal data breaches must be reported to the Personal Data Protection Commission within the statutory window with a defined content set, and to affected data subjects when material harm is likely.

Artefacts an auditor will ask for
  • Incident response plan with Tanzanian regulatory annex
  • Breach register with severity scoring
  • Submitted Commission notifications and acknowledgements
  • Customer communications archive
  • Post incident reviews
Where this commonly fails
  • No clear trigger for Commission notification clock
  • Severity scoring relies on subjective judgement
  • Customer notice not translated to Swahili

Sensitive and Children Data

TZ-PDPA-12
Children and Sensitive Data

Processing of children's data and sensitive personal data requires heightened safeguards, parental consent or specific legal basis, and tighter access controls.

Artefacts an auditor will ask for
  • Inventory of sensitive data flows including health, biometric, and political views
  • Parental consent workflow evidence
  • Age gating screenshots
  • Role based access reports for sensitive datasets
  • Annual review of sensitive data necessity
Where this commonly fails
  • No process to detect minors signing up for adult services
  • Sensitive data accessible to broad analyst pools
  • Health data combined with marketing data without justification

Transfers, Processors and Retention

TZ-PDPA-04
Cross-Border Transfer Controls

Personal data transfers outside Tanzania require evidence that the recipient jurisdiction provides adequate protection, or that contractual safeguards and Commission authorisation are in place.

Artefacts an auditor will ask for
  • Transfer impact assessment library
  • Inter company data transfer agreements
  • Standard contractual clauses with addenda for Tanzanian law
  • Commission authorisation letters for specific corridors
  • Map of data flows by recipient country
Where this commonly fails
  • SaaS subprocessors in unassessed jurisdictions
  • No localisation analysis for cloud regions
  • Authorisations not refreshed when vendor footprint changes
TZ-PDPA-11
Processor Contracts and Oversight

Controllers must bind processors with contracts addressing scope, security, subprocessing, audit rights, and breach notification, and must monitor compliance throughout the engagement.

Artefacts an auditor will ask for
  • Master processor agreement template aligned to the Act
  • Vendor risk assessment file
  • Subprocessor approval log
  • Audit reports or attestations from processors
  • Annual vendor review minutes
Where this commonly fails
  • Legacy vendors operating under pre Act contracts
  • No record of subprocessor approvals
  • Audit rights never exercised even on high risk vendors
TZ-PDPA-13
Retention and Disposal

Personal data must be retained no longer than necessary for the documented purpose, with secure disposal evidenced when retention expires.

Artefacts an auditor will ask for
  • Retention schedule by record type
  • Automated deletion job logs
  • Certificates of destruction for physical media
  • Backup expiry policies
  • Annual disposal attestation
Where this commonly fails
  • Indefinite retention defaults in operational systems
  • Backups outlive primary copies without controls
  • No physical media disposal log for legacy storage
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Tanzania Personal Data Protection Act (Draft) framework page.