Code of ethics for data protection
I am a manager for a new company that deals with a lot of personal data. I understand that recently, there have been many regulatory developments concerning the protection of personal data in Tanzania. I believe these changes may necessitate the company having internal policies and codes of ethics. Are there any legal considerations we need to consider while preparing these documents?
FC, Dar es Salaam
It is good that as a manager you want to ensure your company complies with the law. According to section 65 of the Personal Data Protection Act No. 11 of 2022, every data controller shall draw and place a code of ethics or policy for personal data protection, which shall prescribe for ethics and conduct to be complied with during the collection or processing of personal data. It is important that the company goes through the Data Protection Act No. 11 of 2022 while preparing these documents to be aware of aspects such as having a designated data officer, rights of data subjects and offences, etc.
Once these documents are drafted, the law requires that the code or policy be submitted to the Personal Data Protection Commission for consideration and approval. In considering the codes of ethics or policies, the Commission shall ascertain, among other things, whether the drafts submitted to it have complied with the provisions of the Personal Data Protection Act and any other relevant sector laws and, where it considers necessary, seek the views of data subjects or their representatives and consult with the data controller concerned for the purposes of undertaking necessary amendments before the approval. You might benefit from consulting your lawyer to guide you further.