TANZANIA WILDLIFE MANAGEMENT AUTHORITY
Government of the United Republic of Tanzania
TANZANIA WILDLIFE MANAGEMENT AUTHORITY (“the Institution”, “we”, “our” or “us”) is a Government institution responsible for the conservation and sustainable management of wildlife resources and the provision and promotion of tourism and related services within areas under its mandate.
This Privacy Policy explains how the Institution collects, uses, processes, stores, protects and discloses personal information when you use our mobile application (“the App”), website, online services or other digital platforms through which our services are accessed.
The Institution is committed to protecting the privacy and personal data of visitors, tourists, customers, service users and other individuals who interact with its digital services.
This Privacy Policy is intended to provide transparency regarding the handling of personal data and to inform users of their rights in accordance with applicable laws of the United Republic of Tanzania, including the Personal Data Protection Act, 2022 (Cap. 44) and applicable regulations and directives.
The Institution applies the principles of lawful, fair and transparent processing, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability in the processing of personal data.
Data Controller:
TANZANIA WILDLIFE MANAGEMENT AUTHORITY
Physical Address:
TAFORI Building, Dar es Salaam Road, Kingolwira Area
e
Postal Address:
P.O. BOX 2658 Morogoro
Telephone:
+255 ( 0) 23-2934204-11
Email:
cc@tawa.go.tz
DPO Email:
dpo@tawa.go.tz
The Institution may engage authorised third-party service providers to process personal data on its behalf. Where such processing takes place, the Institution will require appropriate contractual, technical and organisational safeguards.
Under Tanzania's data protection framework, a data controller is responsible for determining the purposes and means of processing personal data, while a data processor processes personal data on behalf of the controller and under the controller's instructions.
This Privacy Policy applies to personal data collected through:
This Policy applies to users including:
Depending on the service you request, the Institution may collect only the information necessary to provide that service.
This may include:
We may collect information relating to the service requested, including:
When you use the App, certain technical information may be collected automatically, where applicable, including:
Such information may be used primarily for security, troubleshooting, system administration and service improvement.
The Institution collects and processes personal data for specific and legitimate purposes, including:
The Institution will not collect personal data for purposes that are incompatible with the purpose for which the data was originally collected unless permitted or required by applicable law.
Depending on the circumstances, personal data may be processed on one or more lawful grounds recognised under applicable Tanzanian law.
These may include:
Because the Institution is a Government institution, certain processing activities may be necessary for the performance of statutory functions and public services and therefore may not depend solely on user consent.
Some personal information is necessary for the Institution to provide particular services.
For example, where a visitor requests an electronic permit or entry authorisation, information such as the visitor's name, age group, contact details and visit information may be required to:
User information → Service request → Fee calculation → Bill generation → Payment verification → Permit/entry document generation
Where information required for a particular statutory or operational service is not provided, the Institution may be unable to process the requested service.
Where information is optional, the App will indicate that it is optional where reasonably practicable.
When a user requests a service that attracts a fee, the personal information provided may be used to:
Payment processing may involve authorised Government payment platforms, financial institutions, payment service providers or other authorised service providers.
The Institution will not use payment information for purposes unrelated to the authorised transaction except where permitted or required by law.
The Institution will seek to collect only personal data that is adequate, relevant and reasonably necessary for the particular service or statutory purpose.
For example, where an age group is sufficient to determine an applicable tourism tariff, the Institution will seek to avoid collecting a full date of birth unless there is a legitimate operational, legal or service requirement for doing so.
Similarly, the Institution will not require a user to provide information that is unrelated to the service being requested.
Personal data may be collected:
For example, when you:
Certain technical information may be collected automatically when you use our digital services, particularly information required for security, system administration and performance monitoring.
Where permitted by law, the Institution may receive information from:
The Institution may disclose or share personal data where such disclosure is lawful, necessary and proportionate.
This may include sharing information with:
Where third-party processors are used, they will be required to process personal data only for authorised purposes and to implement appropriate security and confidentiality measures.
The Institution will not sell users' personal data.
The App may integrate with or exchange information with authorised Government or institutional systems for purposes such as:
Such integrations will be implemented subject to applicable laws, information security requirements, data-sharing arrangements and institutional controls.
The Institution will retain personal data only for as long as necessary to fulfil the purpose for which it was collected or as required by:
Different categories of information may therefore be retained for different periods.
For example, transaction, billing and permit records may need to be retained for longer periods than temporary application or technical information because they form part of official Government records.
When personal data is no longer required, it will be securely deleted, destroyed, anonymised or otherwise disposed of in accordance with applicable requirements.
The Institution implements appropriate technical and organisational measures designed to protect personal data against:
Security measures may include:
Access to personal data will be limited to authorised persons who require access for legitimate institutional duties.
The Institution seeks to maintain accurate and up-to-date personal data.
Users are encouraged to provide accurate information and to notify the Institution where information used in providing a service is incorrect.
Where appropriate, users may request correction or updating of their personal information.
Subject to applicable law and any lawful limitations, individuals have rights concerning their personal data.
These include the right to:
These rights are subject to legal and regulatory limitations. For example, a request to delete information may not be granted where the Institution is legally required to retain the information as part of an official Government record or for another lawful purpose.
The PDPC currently identifies these rights among the rights available to data subjects under Tanzania's data protection framework.
A user wishing to exercise a data protection right may contact the Institution's Data Protection Officer using the contact details provided in this Privacy Policy.
The request should, where necessary, provide sufficient information to enable the Institution to:
The Institution may take reasonable steps to verify the identity of the person making a request before releasing or modifying personal information.
Certain tourism and conservation services may be accessed by families and persons below the age of 18.
Where services involve children or minors, the Institution will process their personal data in accordance with applicable legal requirements and appropriate safeguards.
Where parental or guardian involvement or authorisation is required by law or by the particular service, the Institution may require information or confirmation from the parent or lawful guardian.
The App should not request unnecessary personal information about children.
Where the App or associated websites use cookies, analytics tools, device identifiers or similar technologies, such technologies may be used for purposes such as:
Where required, additional information concerning cookies and similar technologies will be provided through a separate Cookie Policy or appropriate notice.
Some conservation and tourism services may involve location-related functionality.
Where location information is required, the Institution will provide appropriate notice and will process such information only for legitimate and authorised purposes.
Where location information is not necessary for a particular service, the App should not require continuous access to the user's location.
The Institution may use contact information to communicate with users regarding:
Where promotional or marketing communications are undertaken, the Institution will comply with applicable legal requirements concerning such communications.
Personal data may only be transferred outside Tanzania where permitted by applicable law and subject to appropriate safeguards and requirements.
Where a service provider, cloud platform or other technology arrangement involves processing personal data outside Tanzania, the Institution will assess and manage the arrangement in accordance with applicable data protection requirements.
The App may contain links to or integrate with third-party services.
These services may have their own privacy policies and terms of use.
The Institution is responsible for personal data processing under its control but may not be responsible for the privacy practices of independent third-party services operating outside the Institution's control.
Users should review the privacy information provided by third-party services before submitting personal information to them.
The Institution maintains procedures for identifying, assessing, managing and responding to personal data breaches and other security incidents.
Where required by applicable law, the Institution will notify the relevant regulatory authority and/or affected data subjects within the applicable requirements.
Users who believe that their personal information may have been compromised should promptly contact the Institution using the contact details provided in this Privacy Policy.
The Institution may use automated systems to perform administrative functions such as:
Where applicable, users will be provided with information concerning significant automated decision-making and the rights available to them under applicable law.
The Institution may use personal data to produce official statistics, management reports, tourism reports, conservation reports, financial reports and other institutional reports.
Where practical and appropriate, statistical reporting will use aggregated, anonymised or de-identified information so that individual users are not unnecessarily identifiable.
Personal data will not be used for unrelated statistical purposes merely because it has already been collected.
The Institution treats personal data as confidential information and requires personnel and authorised service providers who have access to personal data to observe applicable confidentiality and data protection obligations.
Unauthorised access, use or disclosure of personal data may result in administrative, contractual or legal action as applicable.
If you believe that your personal data has been handled in a manner inconsistent with this Privacy Policy or applicable data protection law, you may first contact the Institution through its Data Protection Officer.
The Institution will receive, assess and respond to complaints in accordance with applicable procedures.
Where a data subject remains dissatisfied or where applicable law provides for direct regulatory recourse, a complaint may also be submitted to the Personal Data Protection Commission (PDPC).
The PDPC identifies complaint handling as part of its regulatory functions and provides mechanisms for individuals to raise concerns regarding personal data protection.
The Institution may periodically review and update this Privacy Policy to reflect:
When significant changes are made, the Institution will provide an appropriate notice through the App, website or other suitable communication channel.
The effective date and version of the Privacy Policy will be updated accordingly.
This Privacy Policy shall be interpreted and implemented in accordance with the laws of the United Republic of Tanzania.
Nothing in this Privacy Policy limits or excludes any rights, duties or obligations provided under applicable legislation.
For questions, requests or concerns relating to personal data and privacy, please contact:
Data Protection Officer
Tanzania Wildlife Management Authority
Physical Address:
TAFORI Building, Dar es Salaam Road, Kingolwira Area
Postal Address:
P.O.Box 2658 <progorp
Telephone:
+255 ( 0) 23-2934204-11
Email:
dpo@tawa.go.tz
Website:
https://tawa.go.tz
By using the Institution's digital services, you acknowledge that you have had an opportunity to read this Privacy Policy and understand how your personal data may be collected and processed for the purposes described herein.
Where processing requires consent under applicable law, the Institution will obtain consent through an appropriate mechanism.
Your use of a service does not constitute consent where another lawful basis is applicable or where consent is not legally required.