PRIVACY POLICY

TANZANIA WILDLIFE MANAGEMENT AUTHORITY
Government of the United Republic of Tanzania

 

1. INTRODUCTION

TANZANIA WILDLIFE MANAGEMENT AUTHORITY (“the Institution”, “we”, “our” or “us”) is a Government institution responsible for the conservation and sustainable management of wildlife resources and the provision and promotion of tourism and related services within areas under its mandate.

This Privacy Policy explains how the Institution collects, uses, processes, stores, protects and discloses personal information when you use our mobile application (“the App”), website, online services or other digital platforms through which our services are accessed.

The Institution is committed to protecting the privacy and personal data of visitors, tourists, customers, service users and other individuals who interact with its digital services.

This Privacy Policy is intended to provide transparency regarding the handling of personal data and to inform users of their rights in accordance with applicable laws of the United Republic of Tanzania, including the Personal Data Protection Act, 2022 (Cap. 44) and applicable regulations and directives.

The Institution applies the principles of lawful, fair and transparent processing, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability in the processing of personal data.

 

2. WHO WE ARE

Data Controller:
TANZANIA WILDLIFE MANAGEMENT AUTHORITY

Physical Address:
TAFORI Building, Dar es Salaam Road, Kingolwira Area

e

Postal Address:
P.O. BOX 2658 Morogoro

Telephone:
+255 ( 0) 23-2934204-11

Email:
cc@tawa.go.tz

DPO Email:
dpo@tawa.go.tz

The Institution may engage authorised third-party service providers to process personal data on its behalf. Where such processing takes place, the Institution will require appropriate contractual, technical and organisational safeguards.

Under Tanzania's data protection framework, a data controller is responsible for determining the purposes and means of processing personal data, while a data processor processes personal data on behalf of the controller and under the controller's instructions.

 

3. SCOPE OF THIS PRIVACY POLICY

This Privacy Policy applies to personal data collected through:

  • The Institution's mobile application;
  • The Institution's websites and online portals;
  • Online tourism and conservation service applications;
  • Electronic booking and permit services;
  • Electronic billing and payment processes;
  • Customer enquiries and communications;
  • Digital visitor registration processes; and
  • Other digital services operated or authorised by the Institution.

This Policy applies to users including:

  • Domestic visitors;
  • International visitors;
  • Tourists;
  • Customers;
  • Applicants for permits;
  • Tour operators and their representatives;
  • Researchers and other authorised users; and
  • Other members of the public accessing the Institution's digital services.

 

4. PERSONAL DATA WE MAY COLLECT

Depending on the service you request, the Institution may collect only the information necessary to provide that service.

This may include:

4.1 Identification and Personal Information

  • Full name;
  • Age or age group;
  • Nationality, where required for determining applicable service charges;
  • Identification information where legally or operationally required; and
  • Other information necessary to identify or distinguish a service applicant.

4.2 Contact Information

  • Mobile telephone number;
  • Email address;
  • Postal or other contact information where required.

4.3 Service and Transaction Information

We may collect information relating to the service requested, including:

  • Attraction or conservation area to be visited;
  • Date of visit;
  • Number of visitors;
  • Type of service requested;
  • Permit or booking information;
  • Bill or invoice information;
  • Payment status;
  • Control number or transaction reference;
  • Permit number; and
  • Other information required to provide or administer the requested service.

4.4 Technical Information

When you use the App, certain technical information may be collected automatically, where applicable, including:

  • Device type;
  • Operating system;
  • Application version;
  • IP address;
  • Device identifiers;
  • Date and time of access;
  • System logs;
  • Network information; and
  • Information relating to application performance and security.

Such information may be used primarily for security, troubleshooting, system administration and service improvement.

 

5. WHY WE COLLECT YOUR PERSONAL DATA

The Institution collects and processes personal data for specific and legitimate purposes, including:

  1. To provide conservation and tourism services requested by users;
  2. To register visitors and customers;
  3. To process bookings and applications;
  4. To determine applicable fees and charges;
  5. To generate bills, invoices and payment references;
  6. To issue permits, tickets, entry documents or other authorisations;
  7. To verify transactions and service eligibility;
  8. To communicate with users concerning their applications or services;
  9. To provide customer support;
  10. To maintain accurate institutional records;
  11. To administer and improve digital services;
  12. To prevent fraud, misuse and unauthorised access;
  13. To maintain the security and integrity of our systems;
  14. To fulfil statutory, regulatory and public-service obligations;
  15. To prepare official statistical and management reports;
  16. To support conservation and tourism planning where legally permitted; and
  17. To comply with lawful requests from competent Government authorities.

The Institution will not collect personal data for purposes that are incompatible with the purpose for which the data was originally collected unless permitted or required by applicable law.

 

6. LEGAL BASIS FOR PROCESSING PERSONAL DATA

Depending on the circumstances, personal data may be processed on one or more lawful grounds recognised under applicable Tanzanian law.

These may include:

  • Performance of a statutory or public function;
  • Compliance with a legal or regulatory obligation;
  • Provision of a service requested by the user;
  • Performance of an agreement or transaction;
  • Consent, where consent is legally required;
  • Protection of the rights, safety or security of individuals; and
  • Other lawful grounds provided under applicable legislation.

Because the Institution is a Government institution, certain processing activities may be necessary for the performance of statutory functions and public services and therefore may not depend solely on user consent.

 

7. INFORMATION REQUIRED TO PROVIDE OUR SERVICES

Some personal information is necessary for the Institution to provide particular services.

For example, where a visitor requests an electronic permit or entry authorisation, information such as the visitor's name, age group, contact details and visit information may be required to:

User information → Service request → Fee calculation → Bill generation → Payment verification → Permit/entry document generation

Where information required for a particular statutory or operational service is not provided, the Institution may be unable to process the requested service.

Where information is optional, the App will indicate that it is optional where reasonably practicable.

 

8. BILLING, PAYMENT AND PERMIT PROCESSING

When a user requests a service that attracts a fee, the personal information provided may be used to:

  • Determine the applicable tariff;
  • Calculate the amount payable;
  • Generate a Government bill or control number;
  • Associate the payment with the requested service;
  • Verify payment status;
  • Generate a permit, ticket or entry authorisation; and
  • Maintain the official transaction record.

Payment processing may involve authorised Government payment platforms, financial institutions, payment service providers or other authorised service providers.

The Institution will not use payment information for purposes unrelated to the authorised transaction except where permitted or required by law.

 

9. DATA MINIMISATION

The Institution will seek to collect only personal data that is adequate, relevant and reasonably necessary for the particular service or statutory purpose.

For example, where an age group is sufficient to determine an applicable tourism tariff, the Institution will seek to avoid collecting a full date of birth unless there is a legitimate operational, legal or service requirement for doing so.

Similarly, the Institution will not require a user to provide information that is unrelated to the service being requested.

 

10. HOW WE COLLECT PERSONAL DATA

Personal data may be collected:

Directly from you

For example, when you:

  • Register on the App;
  • Submit a booking;
  • Apply for a permit;
  • Request a tourism service;
  • Enter visitor information;
  • Contact customer support; or
  • Complete an online form.

Automatically

Certain technical information may be collected automatically when you use our digital services, particularly information required for security, system administration and performance monitoring.

From authorised sources

Where permitted by law, the Institution may receive information from:

  • Government institutions;
  • Authorised payment platforms;
  • Authorised tourism stakeholders;
  • Service providers;
  • Regulatory authorities; and
  • Other lawful sources.

 

 

11. SHARING OF PERSONAL DATA

The Institution may disclose or share personal data where such disclosure is lawful, necessary and proportionate.

This may include sharing information with:

  • Authorised Government institutions;
  • Government payment and revenue systems;
  • Authorised service providers and technology partners;
  • Payment service providers;
  • Financial institutions involved in authorised transactions;
  • Auditors and authorised oversight bodies;
  • Law enforcement agencies where legally required;
  • Courts or other competent authorities; and
  • Other parties where disclosure is authorised or required by law.

Where third-party processors are used, they will be required to process personal data only for authorised purposes and to implement appropriate security and confidentiality measures.

The Institution will not sell users' personal data.

 

12. GOVERNMENT SYSTEMS AND INTEGRATIONS

The App may integrate with or exchange information with authorised Government or institutional systems for purposes such as:

  • Revenue collection;
  • Payment verification;
  • Permit processing;
  • Visitor management;
  • Service delivery;
  • Reporting;
  • Audit;
  • Compliance; and
  • Other legitimate Government functions.

Such integrations will be implemented subject to applicable laws, information security requirements, data-sharing arrangements and institutional controls.

 

13. DATA RETENTION

The Institution will retain personal data only for as long as necessary to fulfil the purpose for which it was collected or as required by:

  • Applicable legislation;
  • Government records-management requirements;
  • Financial and audit requirements;
  • Conservation and tourism regulations;
  • Institutional records-retention schedules; or
  • Other lawful obligations.

Different categories of information may therefore be retained for different periods.

For example, transaction, billing and permit records may need to be retained for longer periods than temporary application or technical information because they form part of official Government records.

When personal data is no longer required, it will be securely deleted, destroyed, anonymised or otherwise disposed of in accordance with applicable requirements.

 

14. SECURITY OF PERSONAL DATA

The Institution implements appropriate technical and organisational measures designed to protect personal data against:

  • Unauthorised access;
  • Unauthorised disclosure;
  • Loss;
  • Destruction;
  • Alteration;
  • Misuse;
  • Unauthorised processing; and
  • Other security threats.

Security measures may include:

  • User authentication and access controls;
  • Role-based access;
  • Encryption where appropriate;
  • Secure application and database architecture;
  • Network security controls;
  • System monitoring and logging;
  • Backup and recovery controls;
  • Security testing;
  • Staff confidentiality obligations; and
  • Incident-response procedures.

Access to personal data will be limited to authorised persons who require access for legitimate institutional duties.

 

15. DATA ACCURACY

The Institution seeks to maintain accurate and up-to-date personal data.

Users are encouraged to provide accurate information and to notify the Institution where information used in providing a service is incorrect.

Where appropriate, users may request correction or updating of their personal information.

 

16. YOUR RIGHTS AS A DATA SUBJECT

Subject to applicable law and any lawful limitations, individuals have rights concerning their personal data.

These include the right to:

  1. Be informed about the processing of personal data;
  2. Access personal data held about them;
  3. Request correction of inaccurate or incomplete personal data;
  4. Request erasure or destruction where legally applicable;
  5. Request restriction of processing in applicable circumstances;
  6. Object to certain processing;
  7. Request data portability where applicable;
  8. Withdraw consent where processing is based on consent;
  9. Object to applicable forms of direct marketing;
  10. Raise concerns regarding automated decision-making where applicable;
  11. Lodge a complaint concerning the handling of personal data; and
  12. Seek other remedies available under applicable law.

These rights are subject to legal and regulatory limitations. For example, a request to delete information may not be granted where the Institution is legally required to retain the information as part of an official Government record or for another lawful purpose.

The PDPC currently identifies these rights among the rights available to data subjects under Tanzania's data protection framework.

 

17. HOW TO EXERCISE YOUR RIGHTS

A user wishing to exercise a data protection right may contact the Institution's Data Protection Officer using the contact details provided in this Privacy Policy.

The request should, where necessary, provide sufficient information to enable the Institution to:

  • Identify the applicant;
  • Understand the request;
  • Locate the relevant personal data; and
  • Respond appropriately.

The Institution may take reasonable steps to verify the identity of the person making a request before releasing or modifying personal information.

 

18. CHILDREN AND MINORS

Certain tourism and conservation services may be accessed by families and persons below the age of 18.

Where services involve children or minors, the Institution will process their personal data in accordance with applicable legal requirements and appropriate safeguards.

Where parental or guardian involvement or authorisation is required by law or by the particular service, the Institution may require information or confirmation from the parent or lawful guardian.

The App should not request unnecessary personal information about children.

 

19. COOKIES AND SIMILAR TECHNOLOGIES

Where the App or associated websites use cookies, analytics tools, device identifiers or similar technologies, such technologies may be used for purposes such as:

  • Authentication;
  • Security;
  • Session management;
  • Application functionality;
  • Performance monitoring; and
  • Improving digital services.

Where required, additional information concerning cookies and similar technologies will be provided through a separate Cookie Policy or appropriate notice.

 

20. LOCATION INFORMATION

Some conservation and tourism services may involve location-related functionality.

Where location information is required, the Institution will provide appropriate notice and will process such information only for legitimate and authorised purposes.

Where location information is not necessary for a particular service, the App should not require continuous access to the user's location.

 

21. MARKETING AND COMMUNICATIONS

The Institution may use contact information to communicate with users regarding:

  • Their requested services;
  • Bookings and permits;
  • Payment or billing matters;
  • Service interruptions;
  • Important operational information;
  • Customer support; and
  • Other official communications.

Where promotional or marketing communications are undertaken, the Institution will comply with applicable legal requirements concerning such communications.

 

22. CROSS-BORDER DATA TRANSFERS

Personal data may only be transferred outside Tanzania where permitted by applicable law and subject to appropriate safeguards and requirements.

Where a service provider, cloud platform or other technology arrangement involves processing personal data outside Tanzania, the Institution will assess and manage the arrangement in accordance with applicable data protection requirements.

 

23. THIRD-PARTY SERVICES AND LINKS

The App may contain links to or integrate with third-party services.

These services may have their own privacy policies and terms of use.

The Institution is responsible for personal data processing under its control but may not be responsible for the privacy practices of independent third-party services operating outside the Institution's control.

Users should review the privacy information provided by third-party services before submitting personal information to them.

 

24. DATA BREACHES AND SECURITY INCIDENTS

The Institution maintains procedures for identifying, assessing, managing and responding to personal data breaches and other security incidents.

Where required by applicable law, the Institution will notify the relevant regulatory authority and/or affected data subjects within the applicable requirements.

Users who believe that their personal information may have been compromised should promptly contact the Institution using the contact details provided in this Privacy Policy.

 

25. AUTOMATED PROCESSING

The Institution may use automated systems to perform administrative functions such as:

  • Calculating applicable charges;
  • Generating bills;
  • Checking payment status;
  • Generating permits or tickets;
  • Processing service applications; and
  • Producing operational reports.

Where applicable, users will be provided with information concerning significant automated decision-making and the rights available to them under applicable law.

 

26. STATISTICAL AND REPORTING USE

The Institution may use personal data to produce official statistics, management reports, tourism reports, conservation reports, financial reports and other institutional reports.

Where practical and appropriate, statistical reporting will use aggregated, anonymised or de-identified information so that individual users are not unnecessarily identifiable.

Personal data will not be used for unrelated statistical purposes merely because it has already been collected.

 

 

 

 

 

27. CONFIDENTIALITY

The Institution treats personal data as confidential information and requires personnel and authorised service providers who have access to personal data to observe applicable confidentiality and data protection obligations.

Unauthorised access, use or disclosure of personal data may result in administrative, contractual or legal action as applicable.

 

28. COMPLAINTS

If you believe that your personal data has been handled in a manner inconsistent with this Privacy Policy or applicable data protection law, you may first contact the Institution through its Data Protection Officer.

The Institution will receive, assess and respond to complaints in accordance with applicable procedures.

Where a data subject remains dissatisfied or where applicable law provides for direct regulatory recourse, a complaint may also be submitted to the Personal Data Protection Commission (PDPC).

The PDPC identifies complaint handling as part of its regulatory functions and provides mechanisms for individuals to raise concerns regarding personal data protection.

 

29. CHANGES TO THIS PRIVACY POLICY

The Institution may periodically review and update this Privacy Policy to reflect:

  • Changes in legislation;
  • Changes in Government policies;
  • Changes in digital services;
  • Changes in application functionality;
  • Changes in data-processing arrangements;
  • Changes in security practices; or
  • Other operational or regulatory requirements.

When significant changes are made, the Institution will provide an appropriate notice through the App, website or other suitable communication channel.

The effective date and version of the Privacy Policy will be updated accordingly.

30. GOVERNING LAW

This Privacy Policy shall be interpreted and implemented in accordance with the laws of the United Republic of Tanzania.

Nothing in this Privacy Policy limits or excludes any rights, duties or obligations provided under applicable legislation.

 

31. CONTACT INFORMATION

For questions, requests or concerns relating to personal data and privacy, please contact:

Data Protection Officer
Tanzania Wildlife Management Authority

Physical Address:
TAFORI Building, Dar es Salaam Road, Kingolwira Area

Postal Address:
P.O.Box 2658 <progorp

Telephone:
+255 ( 0) 23-2934204-11

Email:
dpo@tawa.go.tz

Website:
https://tawa.go.tz

 

 

 

 

32. USER ACKNOWLEDGEMENT

By using the Institution's digital services, you acknowledge that you have had an opportunity to read this Privacy Policy and understand how your personal data may be collected and processed for the purposes described herein.

Where processing requires consent under applicable law, the Institution will obtain consent through an appropriate mechanism.

Your use of a service does not constitute consent where another lawful basis is applicable or where consent is not legally required.