Tanzania Personal Data Protection Act, 2022

Know where you stand on data protection

DataGuard turns Tanzania's Personal Data Protection Act into plain-language questions, a clear picture of your gaps, and the tasks and evidence to close them — so any team can run a real programme, not just lawyers.

Coverage describes assessed and evidenced controls. It is not a statement of legal compliance.

app.dataguard.co.tz
Mazingira TrustDashboard

Your compliance health

Control coverageNot a legal opinion
61%
108 of 123 assessed
108/123
Assessed
88%
Assessment
48%
Implemented
Coverage by domainLive
Registration
10 controls
40%
Third party
4 controls
50%
Breach notification
2 controls
50%
Sensitive data
10 controls
55%
Retention
7 controls
57%
Security
11 controls
59%
Disclosure
5 controls
60%
Enforcement
19 controls
61%

The dashboard — live coverage across the 123 mapped controls, by domain.

123
Controls mapped
96
Requirements
9
Parts of the Act
1
Framework, versioned

Built for the people who do the work

Whether you hold the data, run the programme, or advise others, DataGuard meets you where you are.

Organisations handling personal data

NGOs, clinics, SACCOs, schools and businesses. See where you stand against the Act without needing a law degree — plain questions, clear next steps.

Data protection officers

Run the whole programme in one place: assessment, risks, tasks, evidence, rights requests and breach cases — each tied back to the Act.

Consultants and advisors

Manage many clients as separate, private tenants. Switch between them without anything leaking across organisations.

Plain language, always

Answer questions, not legalese

Each control becomes a question about how your organisation really operates. You choose an honest answer, add a note, and attach evidence. The statutory reference and why it matters ride along with every one — and a gap can become a remediation task in a click.

  • Five clear answers: from implemented to “I do not know”
  • The legal reference on every question
  • Progress saved per control, resumable any time
  • Gaps become owned, dated remediation tasks
app.dataguard.co.tz/assessment
Security · Section 27(1)8 of 11 in this domain
PDPA-027-005CRITICAL RISK

Are you protected against people seeing personal data when they have no business reason to see it?

Implemented
Partially implemented
Not implemented
Not applicable
I do not know

Everything a PDPA programme needs

One place for the assessment, the risks it raises, the tasks that close them, the records you keep and the evidence that proves it.

Guided assessment

Answer plain-language questions about your organisation. The legal reference travels with every answer and your progress saves as you go.

The Act as 123 controls

Every duty in the PDPA 2022 mapped to a practical control with its section, expected evidence and a default risk level.

Risks and tasks

Findings become risks scored on a transparent 5×5 method, and remediation tasks with an owner and due date.

Records of processing

Data inventory, sensitive-data register, retention schedule and a live data map of where personal data flows.

Rights and breaches

A time-boxed queue for data-subject requests and a guided breach intake whose timeline is the evidence of notification.

Evidence and reports

Attach the documents that prove each control operates, then export a report that names the framework and matrix version.

Three steps, start to proof

1

Assess

Work through the controls for your organisation, one domain at a time. Answers and notes save per user, per control.

2

Remediate

Turn gaps into risks and tasks with an owner and a reason, so the work to close each one is always in front of you.

3

Evidence and report

Attach evidence to controls, then export a dated report that states the framework version its figures were drawn from.

The source of truth

Grounded in the Act, honest about the gaps

Every control cites its provision and is labelled by how far it sits from the statutory text — directly stated, derived, or a practical interpretation. Where the Act leaves detail to regulations, DataGuard says so rather than inventing an answer. It supports compliance management; it does not constitute legal advice or certification.

Legal reference on every control
Source type: explicit / derived / interpretation
Regulatory-detail-pending flags
Versioned framework & audit trail

Questions, answered plainly

Do I need to be a lawyer to use it?

No. Every control is written as a plain-language question about how your organisation actually works. The legal wording is there if you want it, but you answer in ordinary terms.

Is this legal advice?

No. DataGuard is a compliance-management tool. It maps the Act into practical controls and tracks your work, but it does not constitute legal advice or certify compliance. Where the Act leaves detail to regulations, it says so.

Where does my data live and who can see it?

Each organisation is a separate tenant. Your answers, evidence and records are private to your workspace and protected by row-level security — other organisations cannot see them.

What does “coverage” actually mean?

It describes how many mapped controls you have assessed and evidenced — fully implemented controls count fully, partial ones by half. It is not a statement that you are legally compliant.

How long does it take to start?

About a minute. Create a workspace, name your organisation, and you are taken straight into the assessment.

Start your PDPA assessment today

Create a workspace in a minute. Your answers, evidence and tasks are private to your organisation.