
DODOMA: THE Personal Data Protection Commission (PDPC) will from Monday begin physical compliance audits of institutions and businesses collecting and processing personal data, with noncompliant entities facing legal action, including fines. PDPC Director General Dr Emmanuel Mkilia said yesterday in Dodoma that the exercise would assess compliance with the Personal Data Protection Act, including how … The post Operation targets rogue data collectors appeared first on Daily News .
DODOMA: THE Personal Data Protection Commission (PDPC) will from Monday begin physical compliance audits of institutions and businesses collecting and processing personal data, with noncompliant entities facing legal action, including fines.
PDPC Director General Dr Emmanuel Mkilia said yesterday in Dodoma that the exercise would assess compliance with the Personal Data Protection Act, including how personal information is collected, processed, stored, secured and transferred outside the country. He said the Commission had already conducted preliminary compliance checks through its systems and identified several areas requiring corrective action before physical inspections begin.
“We found that there was not enough understanding among some data collectors and processors regarding personal data protection. We therefore used the initial stage to identify areas that needed to be corrected before we begin visiting them physically,” Dr Mkilia said.
He said the preliminary assessment had identified inaccuracies in registration information submitted by some data collectors and processors, inadequate observance of data subjects’ rights and cases where personal data was transferred outside the country without following procedures required by law.
ALSO READ: Agriculture sector leads government’s 8.5 million jobs plan in next five years
Dr Mkilia said physical audits would verify whether institutions were properly registered and whether information submitted during registration was accurate. The exercise will also examine the roles of Data Protection Officers (DPOs), procedures for collecting and processing personal information, data security measures and compliance with requirements governing cross-border data transfers.
He said the Commission would take measures depending on the nature and seriousness of violations, including issuing directives, warning letters and fines as provided for under the law.
“We have different penalties depending on the level of the offence. We can issue directives on what needs to be corrected and we can also issue warning letters. We expect to impose fines as provided for under the law,” he said.
Dr Mkilia said enforcement measures were aimed not only at penalising violations but also at creating a secure environment for the digital economy and protecting citizens whose personal information is handled by institutions.
He urged all data collectors and processors to register with the Commission, comply with the Act and its regulations, respect data subjects’ rights and collect personal information only for lawful and specific purposes.
He also called on institutions to prepare and submit quarterly compliance reports, maintain approved personal data protection policies and ensure personal information is not transferred outside Tanzania contrary to the law.
The post Operation targets rogue data collectors appeared first on Daily News.