The Cybercrimes Act
This Act may be cited as the Cyber Crimes Act.
- Jurisdiction
- Tanzania
- Instrument
- Act or statute
- Citation
- The Cybercrimes Act
- Version
- Undated source snapshot
- Language
- en
- Official source
- View official record ↗
Statute overview
About this statute
This Act may be cited as the Cyber Crimes Act. This Act applies to Mainland Tanzania and Tanzania Zanzibar, except for section 50. This section defines key terms used in the Act, including access, computer system, child, and service provider. A person must not intentionally and unlawfully access, or cause access to, a computer system. A person must not intentionally and unlawfully stay in or keep using a computer system after the allowed access time ends.
Search within this statute
Search all stored provisions in this version.
Legal text
Provisions of The Cybercrimes Act
Showing 52 of 52
- 1 Verify source ↗
Short title
This Act may be cited as the Cyber Crimes Act.
1. This Act may be cited as the Cyber Crimes Act. Application - 2 Verify source ↗
Application
This Act applies to Mainland Tanzania and Tanzania Zanzibar, except for section 50.
2. Save for section 50, this Act shall apply to Mainland Tanzania as well as Tanzania Zanzibar. Interpretation - 3 Verify source ↗
Interpretation
This section defines key terms used in the Act, including access, computer system, child, and service provider.
3. In this Act, unless the context otherwise requires- “access” in relation to any computer system, means entry to, instruct, communicate with, store data in, retrieve data from or otherwise make use of any of the resources of the computer system or network or data storage medium; “access provider” means a person who provides electronic data transmission service by transmitting information provided by or to a user of the service in a communication network or providing access to a communication network; “caching provider” means a person who provides an electronic data transmission service by automatic, intermediate or temporary storing information, for the purpose of making more efficient the information’s onward transmission to other users of the service upon their request; 498 ©2025 Government of Tanzania. All rights reserved. No part of this book may be reproduced or distributed without permission of OAG. THE CYBERCRIMES ACT [CAP. 443 R.E. 2023] “child” means a person below the age of eighteen years; “child pornography” means pornographic material that depicts, presents or represents: (a) a child engaged in a sexually explicit conduct; (b) a person appearing to be a child engaged in a sexually explicit conduct; or (c) an image representing a child engaged in a sexually explicit conduct; “computer system” means a device or combination of devices, including network, input and output devices capable of being used in conjunction with external files which contain computer programmes, electronic instructions, input data and output data that performs logic, arithmetic data storage and retrieval communication control and other functions; “computer data” means any representation of facts, concepts, information or instructions, in a form suitable for processing in a computer system, including a program suitable to cause a computer system to perform a function; “data storage medium” means any device, article or material from which computer data or information is capable of being stored or reproduced, with or without the aid of any other device or material; “device” includes- (a) a computer program, code, software or application; (b) component of computer system such as graphic card, memory card, chip or processor; (c) computer storage component; and (d) input and output devices; “electronic communication” means any transfer of a sign, signal or computer data of any nature transmitted in whole or in part by a wire, radio, electromagnetic, photo electronic, photo optical system or in any other similar form; “forensic tool” means an investigative tool or device including software or hardware installed on or in relation 499 ©2025 Government of Tanzania. All rights reserved. No part of this book may be reproduced or distributed without permission of OAG. THE CYBERCRIMES ACT [CAP. 443 R.E. 2023] to a computer system or part of a computer system and used to perform tasks which includes keystroke logging or collection of investigation information about a use of a computer or computer system; “hinder” in relation to a computer system includes - (a) causing electromagnetic interference to a computer system; (b) corrupting a computer system by any means; or (c) inputting, transmitting, damaging, deleting, deteriorating, altering or suppressing computer data; “hosting provider” means a person who provides an electronic data transmission service by storing information provided by a user of the service; “hyperlink” means a symbol, word, phrase, sentence or image that contains path to another source that points to and causes to display another document when executed; “intellectual property rights” means the rights accrued or related to copyright, patent, trade mark and any other related matters; “interception” in relation to a function of computer, includes acquiring, viewing, listening or recording any computer data communication through any other means of electronic or other means, during transmission through the use of any technical device; “law enforcement officer” means a police officer of the rank of Assistant Inspector or above or an investigator of equivalent rank of inspector and above, member of Tanzania Intelligence Service, prosecutor or any authorised officer of the authority responsible for regulation of communication or any other person authorised in any written law; “Minister” means the Minister responsible for Information and Communication Technology; “publish” means distributing, transmitting, disseminating, circulating, delivering, exhibit, exchanging, barter, printing, copying, selling or offering for sale, letting on 500 ©2025 Government of Tanzania. All rights reserved. No part of this book may be reproduced or distributed without permission of OAG. THE CYBERCRIMES ACT [CAP. 443 R.E. 2023] hire or offering to let on hire, offering in any other way, or making available in any way; “property” means property of any kind, whether movable or immovable, tangible or intangible, and includes- (a) any currency either as a legal tender in the United Republic or not; (b) information, including an electronically produced program or data or copy thereof, human or computer- readable data; or (c) any right or interest in property; “racist and xenophobic material” means any material which advocates, promotes or incites hatred, discrimination or violence, against any person or group of persons based on race, colour, descent, national or ethnic origin or religion; and “service provider” means a person or party that makes information system services available to third parties. PART II PROVISIONS RELATING TO OFFENCES AND PENALTIES Illegal access Illegal remaining
Part
PART II
- 4
A person must not intentionally and unlawfully access, or cause access to, a computer system.
4.–(1) A person shall not intentionally and unlawfully access or cause a computer system to be accessed. (2) A person who contravenes subsection (1) commits an offence and on conviction, shall be liable to a fine of not less than three million shillings or three times the value of the undue advantage received, whichever is greater or to imprisonment for a term of not less than one year or to both. - 5
A person must not intentionally and unlawfully stay in or keep using a computer system after the allowed access time ends.
5.–(1) A person shall not intentionally and unlawfully remain in a computer system or continue to use a computer system after the expiration of time which he was allowed to access the computer system. (2) A person who contravenes subsection (1) commits an offence and on conviction, shall be liable to a fine of not less than one million shillings or to imprisonment for a term of not less than one year or to both. 501 ©2025 Government of Tanzania. All rights reserved. No part of this book may be reproduced or distributed without permission of OAG. THE CYBERCRIMES ACT [CAP. 443 R.E. 2023] Illegal interception - 6
A person must not intentionally and unlawfully intercept certain non-public communications or system-related emissions, or bypass protection measures for non-public transmissions.
6.–(1) A person shall not intentionally and unlawfully- (a) intercept by technical means or by any other means- (i) a non-public transmission to, from or within a Illegal data interference computer system; (ii) a non-public electromagnetic emission from a computer system; or (iii) a non-public computer system that is connected to another computer system; or (b) circumvent the protection measures implemented to prevent access to the content of non-public transmission. (2) A person who contravenes subsection (1) commits an offence and on conviction, shall be liable to a fine of not less than five million shillings or to imprisonment for a term of not less than one year or to both. - 7 Verify source ↗
8. Data espionage
It is an offence to intentionally and unlawfully damage, delete, alter, interfere with, or deny access to computer data, and related data-sharing or data-destruction conduct also carries criminal penalties.
7.–(1) A person who intentionally and unlawfully- (a) damages or deteriorates computer data; (b) deletes computer data; (c) alters computer data; (d) renders computer data meaningless, useless or ineffective; (e) obstructs, interrupts or interferes with the lawful use of computer data; (f) obstructs, interrupts or interferes with any person in the lawful use of computer data; or (g) denies access to computer data to any person authorised to access it, commits an offence and on conviction, shall be liable to a fine of not less than ten million shillings or three times the value of undue advantage received, whichever is greater, or to imprisonment for a term of not less than three years or to both. (2) A person who- (a) communicates, discloses or transmits any computer data, program, access code or command to an unauthorised person; or 502 ©2025 Government of Tanzania. All rights reserved. No part of this book may be reproduced or distributed without permission of OAG. THE CYBERCRIMES ACT [CAP. 443 R.E. 2023] (b) internationally and unlawfully receives unauthorised computer data, commits an offence and on conviction, shall be liable to a fine of not less than two million shillings or three times the value of the undue advantage received, whichever is greater, or to imprisonment for a term of not less than one year or to both. (3) A person who intentionally and unlawfully destroys or alters any computer data, where such data is required to be maintained by law or is an evidence in any proceeding under this Act by- (a) mutilating, removing or modifying the data, program or any other form of information existing within or outside a computer system; (b) activating, installing or downloading a program that is designed to mutilate, remove or modify data, program or any other form of information existing within or outside a computer system; or (c) creating, altering or destroying a password, personal identification number, code or method used to access a computer system, commits an offence and on conviction, shall be liable to a fine of not less than twenty million shillings or three times the value of undue advantage received, whichever is greater, or to imprisonment for a term of not less than one year or to both. - 8 Verify source ↗
Data espionage
A person must not obtain computer data protected against unauthorised access without permission.
8.–(1) Without prejudice to the National Security Act, a person shall not obtain computer data protected against unauthorised access without permission. (2) A person who contravenes subsection (1) commits an offence and on conviction, shall be liable to a fine of not less than twenty million shillings or three times the value of undue advantage received, whichever is greater, or to imprisonment for a term of not less than five years or to both. 503 Data espionage Cap. 47 ©2025 Government of Tanzania. All rights reserved. No part of this book may be reproduced or distributed without permission of OAG. THE CYBERCRIMES ACT [CAP. 443 R.E. 2023] Illegal system interference - 9
A person must not intentionally and unlawfully hinder or interfere with a computer system’s functioning, use, or operation.
9. A person who intentionally and unlawfully hinders or interferes with- (a) the functioning of a computer system; or (b) the usage or operation of a computer system, commits an offence and on conviction, shall be liable to a fine of not less than two million shillings or three times of value the undue advantage received, whichever is greater, or to imprisonment for a term of not less than one year or to both. Illegal device - 10 Verify source ↗
11. Computer-related forgery
A person must not unlawfully deal with or possess certain devices, programs, passwords, access codes, or similar data used for committing an offence.
10.–(1) A person shall not unlawfully deal with or possess- Computer-related forgery (a) a device, including a computer program, that is designed or adapted for the purpose of committing an offence; (b) a computer password, access code or similar data by which the whole or any part of a computer system is capable of being accessed with the intent that it be used by any person for the purpose of committing an offence. (2) A person who contravenes subsection (1) commits an offence and on conviction, shall be liable to a fine of not less than ten million shillings or three times the value of undue advantage received, whichever is greater, or to imprisonment for a term of not less than three years or to both. - 11 Verify source ↗
Computer-related forgery
A person must not intentionally and unlawfully tamper with computer data in a way that makes it unauthentic and intended to be treated as authentic.
11.–(1) A person shall not intentionally and unlawfully input, alter, delay transmission or delete computer data, resulting in unauthentic data, with the intent that it be acted upon as if it were authentic, regardless of whether or not the data is readable or intelligible. (2) A person who contravenes subsection (1) commits an offence and on conviction, shall be liable to a fine of not less than twenty million shillings or three times the value of undue advantage received, whichever is greater, or to imprisonment for a term of not less than seven years or to both. 504 ©2025 Government of Tanzania. All rights reserved. No part of this book may be reproduced or distributed without permission of OAG. THE CYBERCRIMES ACT [CAP. 443 R.E. 2023] Computer-related fraud - 12 Verify source ↗
Computer-related fraud
A person must not use computer data or a computer system in a fraudulent or dishonest way that causes loss of property to another person.
12.–(1) A person shall not cause a loss of property to another person by- (a) any input, alteration, deletion, delaying transmission or suppression of computer data; or (b) any interference with the functioning of a computer system, with fraudulent or dishonest intent. (2) A person who contravenes subsection (1) commits an offence and on conviction, shall be liable to a fine of not less than twenty million shillings or three times the value of undue advantage received, whichever is greater, or to imprisonment for a term of not less than seven years or to both. Child pornography - 13 Verify source ↗
Child pornography
A person must not publish child pornography or make it available or accessible through a computer system.
13.–(1) A person shall not- (a) publish child pornography, through a computer system; or (b) make available or facilitate the access of child pornography through a computer system. (2) A person who contravenes subsection (1) commits an offence and on conviction, shall be liable to a fine of not less than fifty million shillings or three times the value of undue advantage received, whichever is greater, or to imprisonment for a term of not less than seven years or to both. (3) A person who is convicted for an offence under this section may, in addition to any other punishment, be adjudged to compensate a person injured by the offence. Pornography - 14 Verify source ↗
Pornography
A person must not publish pornography, including lascivious or obscene pornography, through a computer system or other ICT.
14.–(1) A person shall not publish or cause to be published through a computer system or through any other information and communication technology: (a) pornography; or (b) pornography which is lascivious or obscene. 505 ©2025 Government of Tanzania. All rights reserved. No part of this book may be reproduced or distributed without permission of OAG. THE CYBERCRIMES ACT [CAP. 443 R.E. 2023] (2) A person who contravenes subsection (1) commits an offence and on conviction, shall be liable on in the case of publication of- (a) pornography, to a fine of not less than twenty million shillings or to imprisonment for a term of not less than seven years or to both; and (b) pornography which is lascivious or obscene, to a fine of not less than thirty million shillings or to imprisonment for a term of not less than ten years or to both. Identity related crimes - 15 Verify source ↗
16. Publication of false information
A person must not use a computer system to impersonate another person.
15.–(1) A person shall not, by using a computer system impersonate another person. Publication of false information Racist and xenophobic material (2) A person who contravenes subsection (1) commits an offence and on conviction, shall be liable to a fine of not less than five million shillings or three times the value of undue advantage received by that person, whichever is greater, or to imprisonment for a term of not less than seven years or to both. - 16 Verify source ↗
Publication of false information
A person who knowingly publishes false, deceptive, misleading, or inaccurate information or data in a computer system with intent to defame, threaten, abuse, insult, or mislead the public commits an offence.
16. A person who publishes information or data presented in a picture, text, symbol or any other form in a computer system knowing that such information or data is false, deceptive, misleading or inaccurate, and with intent to defame, threaten, abuse, insult, or otherwise deceive or mislead the public or counseling commission of an offence, commits an offence and on conviction, shall be liable to a fine of not less than five million shillings or to imprisonment for a term of not less than three years or to both. - 17 Verify source ↗
Racist and xenophobic material
A person must not use a computer system to produce, offer, make available, distribute, or transmit racist or xenophobic material.
17.–(1) A person shall not, through a computer system- (a) produce racist or xenophobic material for the purposes of distribution; (b) offer or make available racist or xenophobic material; or (c) distribute or transmit racist or xenophobic material. (2) A person who contravenes subsection (1) commits an offence and on conviction, shall be liable to a fine of not less than three million shillings or to imprisonment for a term of not less than one year or to both. 506 ©2025 Government of Tanzania. All rights reserved. No part of this book may be reproduced or distributed without permission of OAG. THE CYBERCRIMES ACT [CAP. 443 R.E. 2023] Racist and xenophobic motivated insult Genocide and crimes against humanity Unsolicited messages - 18 Verify source ↗
Racist and xenophobic motivated insult
A person must not insult another person through a computer system on discriminatory grounds such as race or religion.
18.–(1) A person shall not insult another person through a computer system on the basis of race, colour, descent, nationality, ethnic origin or religion. (2) A person who contravenes subsection (1) commits an offence and on conviction, shall be liable to a fine of not less than three million shillings or to imprisonment for a term of not less than one year or to both. - 19 Verify source ↗
Genocide and crimes against humanity
A person must not unlawfully publish or cause publication, through a computer system, of material that incites, denies, minimises, or justifies genocide or crimes against humanity.
19.–(1) A person shall not unlawfully publish or cause to be published, through a computer system, a material which incites, denies, minimises or justifies acts constituting genocide or crimes against humanity. (2) A person who contravenes subsection (1) commits an offence and on conviction, shall be liable to a fine of not less than ten million shillings or to imprisonment for a term of not less than three years or to both. (3) For the purposes of this section, “genocide” shall have a meaning ascribed to it under the Convention on the Prevention and Punishment of the Crime of Genocide, 1948. - 20 Verify source ↗
Unsolicited messages
A person must not intentionally initiate, relay, retransmit, or falsify header information in unsolicited messages.
20.–(1) A person shall not, with intent to commit an offence under this Act- (a) initiate the transmission of unsolicited messages; (b) relay or retransmit unsolicited messages; or (c) falsify header information in unsolicited messages; (2) A person who contravenes subsection (1) commits an offence and on conviction, shall be liable to a fine of not less than three million shillings or three times the value of undue advantage received, whichever is greater or to imprisonment for a term of not less than one year or to both. (3) For the purposes of this section, “unsolicited messages” means any electronic message which is not solicited by the recipient. Disclosure of details of investigation - 21 Verify source ↗
Disclosure of details of investigation
A person must not knowingly and unlawfully disclose details of a confidential criminal investigation.
21.–(1) A person shall not knowingly and unlawfully disclose details of a criminal investigation, which requires confidentiality. 507 ©2025 Government of Tanzania. All rights reserved. No part of this book may be reproduced or distributed without permission of OAG. THE CYBERCRIMES ACT [CAP. 443 R.E. 2023] Obstruction of investigation Cyber bullying Violation of intellectual property rights (2) A person who contravenes subsection (1) commits an offence and on conviction, shall be liable to a fine of not less than ten million shillings or to imprisonment for a term of not less than three years or to both. - 22 Verify source ↗
Obstruction of investigation
A person must not intentionally and unlawfully obstruct an investigation by damaging or hiding computer data, or by blocking or ignoring an order under the Act.
22.–(1) A person who intentionally and unlawfully destroys, deletes, alters, conceals, modifies, renders computer data meaningless, ineffective or useless with intent to obstruct or delay investigation commits an offence and on conviction, shall be liable to a fine of not less than three million shillings or to imprisonment for a term not less than one year or to both. (2) A person who intentionally and unlawfully prevents the execution or fails to comply with an order issued under this Act, commits an offence and on conviction, shall be liable to a fine of not less than three million shillings or to imprisonment for a term of not less than one year or to both. - 23 Verify source ↗
Cyber bullying
A person must not use a computer system to send electronic communications to another person if the intent is to coerce, intimidate, harass, or cause emotional distress.
23.–(1) A person shall not initiate or send any electronic communication using a computer system to another person with intent to coerce, intimidate, harass or cause emotional distress. (2) A person who contravenes subsection (1) commits an offence and on conviction, shall be liable to a fine of not less than five million shillings or to imprisonment for a term of not less than three years or to both. - 24 Verify source ↗
Violation of intellectual property rights
A person must not use a computer system with intent to violate intellectual property rights.
24.–(1) A person shall not use a computer system with intent to violate intellectual property rights protected under any written law. (2) A person who contravenes subsection (1) commits an offence and in case the infringement is on - (a) non-commercial basis, shall be liable to a fine of not less than five million shillings or to imprisonment for a term of not less than three years or to both; or 508 ©2025 Government of Tanzania. All rights reserved. No part of this book may be reproduced or distributed without permission of OAG. THE CYBERCRIMES ACT [CAP. 443 R.E. 2023] (b) commercial basis, shall be liable to a fine of not less than twenty million shillings or to imprisonment for a term of not less than five years or to both, in addition, be liable to pay compensation to the victim of the crime as the court may deem just. Principal offenders - 25 Verify source ↗
Principal offenders
A person who helps, encourages, or procures an offence is treated as having taken part in it and can be charged and punished like the main offender.
25.–(1) A person who- (a) does an act or makes an omission which constitutes an offence; (b) does or omits to do any act for the purpose of enabling or aiding another person to commit an offence; (c) aids or abets another person in committing an offence; or (d) counsels or procures any other person to commit an offence, is deemed to have taken part in committing the offence, and shall be charged as a person who committed an offence. (2) A person who procures another to do or omit to do any act of such a nature that, if he had himself done the act or made the omission, the act or omission would have constituted an offence on his part, commits an offence of the same kind and shall be liable to the same punishment as if he had himself had done the act or the omission. - 26 Verify source ↗
Attempt
A person who tries to commit an offence under this Act, but does not complete it, is treated as having attempted the offence.
26.–(1) Where a person, intends to commit an offence, puts his intention into execution by means adapted to its fulfilment, and manifests his intention by some overt act, but does not fulfil his intention to such extent as to commit the offence, he is deemed to have attempted to commit the offence. (2) For the purposes of this section, it is immaterial- (a) except so far as regards to punishment, whether- (i) (ii) the offender does all that is necessary on his part for completing the commission of the offence; or the complete fulfilment of his intention is prevented by circumstances independent of his will; or (iii) he desists of his own motion from further execution of his intention; or 509 Attempt ©2025 Government of Tanzania. All rights reserved. No part of this book may be reproduced or distributed without permission of OAG. THE CYBERCRIMES ACT [CAP. 443 R.E. 2023] (b) that by reason of circumstances not known to the offender, it is impossible to commit the offence. (3) A person who attempts to commit an offence under this Act is guilty of an offence and on conviction, shall be liable to a fine not less than one million shillings or to imprisonment for a term not less than six month or to both. Conspiracy to commit offence - 27 Verify source ↗
Conspiracy to commit offence
A person who conspires with another person to commit an offence under the Act commits an offence and may be fined at least one million shillings, imprisoned for at least one year, or both, on conviction.
27. A person who conspires with another person to commit an offence under this Act, commits an offence and on conviction, shall be liable to a fine of not less than one million shillings or to imprisonment for a term of not less than one year or to both. Protection of critical information infrastructure - 28 Verify source ↗
Protection of critical information infrastructure
The Minister may, by Gazette order, designate a computer system as critical information infrastructure and may set related guidelines or procedures.
28.–(1) The Minister may, by order published in the Gazette, designate a computer system as critical information infrastructure. (2) The order under subsection (1) may prescribe guidelines or procedures in respect of- (a) registration, protection or preservation of critical information infrastructure; (b) general management of critical information infrastructure; (c) access to, transfer and control of data in any critical information infrastructure; (d) integrity and authenticity of data or information contained in any critical information infrastructure; (e) methods to be used in the storage or archiving data or information in critical information infrastructure; (f) disaster recovery plans in the event of loss of the critical information infrastructure or any part of critical information infrastructure; (g) manner and procedure for carrying out audit and inspection on any critical information infrastructure; and (h) any other matter that is relevant for adequate protection, management and control of data and other resources in a critical information infrastructure. 510 ©2025 Government of Tanzania. All rights reserved. No part of this book may be reproduced or distributed without permission of OAG. THE CYBERCRIMES ACT [CAP. 443 R.E. 2023] (3) For the purposes of this section, “critical information infrastructure” includes assets, devices, computer system, or networks, whether physical or virtual so vital to the United Republic that their incapacitation affect national security or the economy and social well being of citizens. Offences relating to critical information infrastructure - 29 Verify source ↗
Offences relating to critical information infrastructure
A person who commits an offence under this Act or any other written law in relation to critical information infrastructure, and is convicted, faces a fine of at least 100 million shillings, or three times the loss caused, or imprisonment for at least five years, or both.
29. Where a person commits an offence under this Act or any written law in relation to critical information infrastructure, that person on conviction, shall be liable to a fine not less than one hundred million shillings or three times the loss occasioned or to imprisonment for a term not less than five years or to both. PART III JURISDICTION Jurisdiction
Part
PART III
- 30 Verify source ↗
Jurisdiction
The courts may try offences under this Act when the offence has a listed connection to the United Republic, including location, nationality, or certain computer-system links.
30.–(1) The courts shall have jurisdiction to try any offence under this Act where an act or omission constituting an offence is committed wholly or in part - (a) within the United Republic; (b) on a ship or aircraft registered in the United Republic; (c) by a national of the United Republic; (d) by a national of the United Republic who resides outside the United Republic, if the act or omission would equally constitute an offence under a law of that country; or (e) by any person, irrespective of his nationality or citizenship, or location, when the offence is: (i) committed using a computer system, device or data located within United Republic; or (ii) directed against computer system, device or data or person located in United Republic. (2) In this section, the term “court” means court of competent jurisdiction. 511 ©2025 Government of Tanzania. All rights reserved. No part of this book may be reproduced or distributed without permission of OAG. THE CYBERCRIMES ACT [CAP. 443 R.E. 2023] PART IV SEARCH AND SEIZURE Search and seizure
Part
PART IV
- 31 Verify source ↗
Search and seizure
Police and similar law enforcement officers may authorize and conduct computer-system searches and seizures when they have reasonable grounds tied to an offence, and they must later list seized items and give a copy to the person in control.
31.–(1) Police officer incharge of a police station or a law enforcement officer of a similar rank, upon being satisfied that there are reasonable grounds to suspect or believe that a computer system- (a) may be used as evidence in proving an offence; or (b) is acquired by any person as a result of an offence, may issue an order authorising a law enforcement officer to- (i) enter into any premise and search or seize a device or computer system; (ii) secure the computer data accessed; or (iii) extend the search or similar accessing to another system where a law enforcement officer conducting a search has grounds to believe that the data sought is stored in another computer system or part of it. (2) The search under this section shall be conducted in accordance with the relevant laws regulating the conduct of search and seizure. (3) Where a device or computer system is removed or rendered inaccessible following a search or a seizure, the law enforcement officer shall, at the time of the search or as soon as practicable after the search- (a) prepare a list of items seized or rendered inaccessible and the time of seizure; and (b) issue a copy of that list to the person having control of the computer system. (4) A person having custody or control of the computer system may request from a law enforcement officer a permission to access or copy computer data on the system after seizure. (5) Without prejudice to subsection (4), the law enforcement officer may refuse to give access or provide a copy of the information where he has reasonable grounds to believe that giving the access or providing the copy- (a) would constitute an offence; or 512 ©2025 Government of Tanzania. All rights reserved. No part of this book may be reproduced or distributed without permission of OAG. THE CYBERCRIMES ACT [CAP. 443 R.E. 2023] Disclosure of data Expedited preservation (b) would prejudice - investigation in connection with the search; (i) (ii) another ongoing investigation; or (iii) any criminal proceedings that are pending or that may be instituted in relation to any investigation. (6) In this section, “premise” includes land, buildings, vessel or aircraft. - 32 Verify source ↗
Disclosure of data
Police or law enforcement officers may order disclosure of data for a criminal investigation or offence prosecution, and may seek a court order if that route cannot be used.
32.–(1) Where the disclosure of data is required for the purposes of a criminal investigation or the prosecution of an offence, a police officer in charge of a police station or a law enforcement officer of a similar rank may issue an order to any person in possession of such data compelling him to disclose such data. (2) The order issued under subsection (1) shall be granted to a law enforcement officer who shall serve the order to the person in possession of the data. (3) Where the disclosure of data cannot be done under subsection (1), the law enforcement officer may apply to the court for an order compelling- (a) a person to submit specified data that is in that person’s possession or control; or (b) a service provider offering its services to submit subscriber information in relation to such services in that service provider’s possession or control. (4) Where any material to which an investigation relates consists of data stored in a computer system or device, the request shall be deemed to require the person to produce or give access to it in a form in which it is legible and can be taken away. - 33 Verify source ↗
Expedited preservation
Police or similar law-enforcement officers may order a person in control of data or a device to preserve it for up to 14 days when the data is needed for an investigation and may be lost or changed.
33.–(1) Where there is a reasonable ground to believe that a computer data that is required for the purpose of investigation is vulnerable to loss or modification, the police officer incharge of a police station or a law enforcement officer of a similar rank may issue an order requiring the person in control of a device or computer data to preserve the device or computer data for a period not exceeding fourteen days. 513 ©2025 Government of Tanzania. All rights reserved. No part of this book may be reproduced or distributed without permission of OAG. THE CYBERCRIMES ACT [CAP. 443 R.E. 2023] Disclosure and collection of traffic data Disclosure and collection of content data (2) The court may, on application, extend the order made under section 35 for such period as the court may deem necessary. - 34 Verify source ↗
Disclosure and collection of traffic data
A senior police or similar law-enforcement officer may order a person holding computer data to disclose, collect, record, or help collect traffic data when the data is reasonably needed for an investigation.
34.–(1) Where there is a reasonable ground that a computer data is required for the purpose of investigation, a police officer in charge of a police station or a law enforcement officer of a similar rank may issue an order to any person in possession of the data for- (a) disclosure, collection or recording of the traffic data associated with a specified communication during a specified period; or (b) permitting and assisting the law enforcement officer to collect or record that data. (2) For the purposes of this section, “traffic data” means- (a) information relating to communication by means of a computer system; (b) the information generated by computer system that is part of the chain of communication; and (c) information that shows the communication’s origin, destination, route, time, size, duration or the type of underlying service.
Part
part of the chain of communication; and
- 35 Verify source ↗
Disclosure and collection of content data
A police officer or similar law enforcement officer may issue an order to collect or record content data or computer data when there are reasonable grounds to suspect or believe it is needed for an investigation.
35. Where there is a reasonable ground to suspect or believe that the content of an electronic communication is required for the purposes of investigation, a police officer incharge of a police station or a law enforcement officer of a similar rank may issue an order to- (a) collect, record, permit or assist the relevant authority to collect or record content data associated with specified communications transmitted by means of a computer system; or (b) collect or record the computer data through technical means. 514 ©2025 Government of Tanzania. All rights reserved. No part of this book may be reproduced or distributed without permission of OAG. THE CYBERCRIMES ACT [CAP. 443 R.E. 2023] Court order Use of forensic tool - 36 Verify source ↗
Court order
A law enforcement officer may ask the court for an order to disclose or preserve data in the situations described.
36. Where the disclosure or preservation of data, under sections 31, 32, 33, 34 and 35, as the case may be, may not be done without the use of force or due to resistance from the part holding data or evidential value of data can be preserved through the order of the court, a law enforcement officer may apply to court for an order for the disclosure or preservation.
Part
part holding data or evidential value of data can be preserved
- 37 Verify source ↗
Use of forensic tool
A law enforcement officer may apply to court to use a forensic tool when essential evidence cannot otherwise be collected, and the officer must limit and log the investigation activity.
37.–(1) Where a law enforcement officer is satisfied that essential evidence cannot be collected under this Part, he may apply to the court for an order to authorise the use of a forensic tool. (2) The application under subsection (1) shall contain- (a) the name and address of the suspect; (b) a description of the targeted computer system; and (c) a description of the intended measures, purpose, extent and duration of the utilisation. (3) The law enforcement officer shall ensure that any modification made to the computer system or computer data of the suspect are limited to the investigation and that any changes reversed after the completion of the investigation is restored into the system. (4) During investigation, the law enforcement officer shall log- (a) the technical means used and time and date of the application; (b) the identification of the computer system and details of the modification undertaken within the investigation; and (c) any information obtained; (5) The information obtained under this section shall be protected against any modification, unauthorised deletion and unauthorised access. (6) The authorisation under this section shall be valid for a period of fourteen days. 515 ©2025 Government of Tanzania. All rights reserved. No part of this book may be reproduced or distributed without permission of OAG. THE CYBERCRIMES ACT [CAP. 443 R.E. 2023] (7) The court may, on application, extend the period under subsection (6) for a further period of fourteen days or to such other period as it deems necessary. (8) Where the installation process requires a site visit, the requirements of section 30 shall apply. (9) In addition to the order granted under subsection (1), the court may, on application, order the service provider to support the installation process of the forensic tool. (10) The Minister may, by notice published in the Gazette, prescribe offences under which the court may grant an order for utilisation of a forensic tool. Hearing of application - 38 Verify source ↗
Hearing of application
Applications under this part are heard ex parte and in camera.
38. The proceedings for hearing of an application under this part shall be ex parte and in camera. PART V LIABILITY OF SERVICE PROVIDERS Monitoring obligation
Part
PART V
- 39 Verify source ↗
Monitoring obligation
Service providers must not monitor stored or transmitted data or actively seek signs of unlawful activity, and they may have to report and act on illegal information once they know about it.
39.–(1) When providing services in accordance with the provisions of this Part, a service provider shall not - (a) monitor the data which the service provider transmits or stores; or (b) actively seek facts or circumstances indicating an unlawful activity. (2) The Minister may prescribe procedures for service providers to- (a) inform the competent authority of alleged illegal activities undertaken or information provided by recipients of their service; and (b) avail competent authorities, at their request, with information enabling the identification of recipients of their service. (3) A service provider shall not be liable for disclosure, by a third party, of data lawfully made available to the third party upon proving that- (a) the third party acted without the knowledge of the service provider; or 516 ©2025 Government of Tanzania. All rights reserved. No part of this book may be reproduced or distributed without permission of OAG. THE CYBERCRIMES ACT [CAP. 443 R.E. 2023] Access provider (b) the service provider exercised due care and skill to prevent the disclosure of such data. (4) Where a service provider has knowledge of illegal information, or activity he shall- (a) remove the information in the computer system within the service providers control; (b) suspend or terminate services in respect of that information or activity; and (c) notify appropriate law enforcement authority of the illegal activity or information, relevant facts and the identity of the person for whom the service provider is supplying services in respect of the information. - 40 Verify source ↗
Access provider
An access provider is not liable for merely providing access or operating a computer system for third-party electronic communications if it does not initiate, choose the receiver, or change the transmission.
40.–(1) An access provider shall not be liable for providing access, transmitting or operating computer system in respect of third-party material in the form of electronic communication to which he merely provides access to or for operating facilities via a computer system under his control, provided that he does not- (a) initiate the transmission; (b) select the receiver of the transmission; or (c) select or modify the information contained in the transmission. (2) The transmission and provision of access referred to in subsection (1) include the automatic, intermediate and transient storage of the information transmitted in so far as this takes place- (a) for the purpose of carrying out the transmission in the information system; (b) in a manner that makes it inaccessible to a person other than the anticipated recipient; and (c) for a period no longer than is reasonably necessary for the transmission. 517 ©2025 Government of Tanzania. All rights reserved. No part of this book may be reproduced or distributed without permission of OAG. THE CYBERCRIMES ACT [CAP. 443 R.E. 2023] Hosting provider - 41 Verify source ↗
Hosting provider
A hosting provider is generally not liable for user-stored information, but must remove or disable illegal content after an order and must notify the relevant authority when it learns of illegal content.
41.–(1) A hosting provider is not liable for information stored at the request of a user of the service, on condition that the hosting provider- (a) immediately removes or disables access to the information after receiving an order from any competent authority or court to remove specific illegal information stored; or (b) upon becoming aware of illegal information stored otherwise than by the competent authority, shall immediately inform the relevant authority. (2) The provision of subsection (1) shall not apply where the user of the service is acting under the authority or control of the hosting provider. Caching provider - 42 Verify source ↗
Caching provider
A caching provider is not liable for storing information if it meets listed conditions.
42. A caching provider shall not be liable for the storage of information provided that the caching provider: (a) does not modify the information; (b) complies with conditions of access to the information; (c) complies with rules regarding the updating of the information; (d) does not interfere with the lawful use of the technology widely recognised and used in the industry, to obtain data on the use of the information; and (e) acts immediately to remove or to disable access to the information it has stored upon obtaining actual knowledge of the fact that the information at the initial source of the transmission has been removed from the network, or access to it has been disabled, or that a court or the relevant authority has ordered the removal or disablement. Hyperlink provider - 43 Verify source ↗
Hyperlink provider
A hyperlink provider is not liable for linked information if it promptly removes or disables access after an order from the relevant authority and promptly informs that authority when it becomes aware of specific illegal information by other means.
43. A hyperlink provider is not liable for the information linked provided that the hyperlink provider- (a) immediately removes or disables access to the information after receiving an order to do so from the relevant authority; and 518 ©2025 Government of Tanzania. All rights reserved. No part of this book may be reproduced or distributed without permission of OAG. THE CYBERCRIMES ACT [CAP. 443 R.E. 2023] Search engine provider (b) upon becoming aware of the specific illegal information stored by other ways than an order from a public authority, immediately informs relevant authority. - 44 Verify source ↗
Search engine provider
A search engine provider is not liable for search results if it does not initiate the transmission, choose the receiver, or select or change the transmitted information.
44.–(1) A search engine provider is not liable for search results, on condition that the search engine provider- (a) does not initiate the transmission; (b) does not select the receiver of the transmission; and (c) does not select or modify the information contained in the transmission. (2) For the purposes of this section, “a search engine provider” is a person who makes or operates a search engine which creates an index of internet related content or makes available electronic tools to search for information provided by third party. Take-down notification - 45 Verify source ↗
Take-down notification
A person may send a take-down notification to a service provider about infringing, unlawful, or otherwise unlawful content or activity, and the notice must include specified details.
45.–(1) A person may, through a take-down notification, notify the service provider of- (a) any data or activity infringing the rights of the recipient or of a third party; (b) any unlawful material or activity; or (c) any other matter conducted or provided contrary to the provisions of any written law. (2) For purposes of this Part, a take-down notification shall be in a permanent medium addressed by the complainant to the service provider or its designated agent and shall include- (a) the full names and address of the complainant; (b) the signature of the complainant; (c) identification of the right that has allegedly been infringed; (d) identification of the material or activity that is claimed to be the subject of unlawful activity; (e) the remedial action required to be taken by the service provider in respect of the complaint; (f) a statement that the complainant is acting in good faith; and 519 ©2025 Government of Tanzania. All rights reserved. No part of this book may be reproduced or distributed without permission of OAG. THE CYBERCRIMES ACT [CAP. 443 R.E. 2023] (g) a statement by the complainant that the information in the take-down notification is to his knowledge true or correct (3) A person who lodges a notification of unlawful activity with a service provider knowing that it materially misrepresents the facts, commits an offence and on conviction, shall be liable to a fine of not less than five million shillings or to imprisonment of a term of not less than one year or to both. (4) A service provider who fails to take action on the take- down notification received under this section, shall be charged as a person who initiated the contents of subsection (1). (5) A person who communicates a take-down notification to a service provider and the service provider fails to act upon the notification, the person may notify a competent authority of the failure to take-down and the competent authority may take down or order the service provider to act on the take-down notification or take any other measures to resolve the matter. (6) A service provider shall not be liable for a take-down done in compliance to a notification under this Act. Other obligations not affected - 46 Verify source ↗
Other bligations not affected
This Part does not change a service provider’s obligations in the listed situations.
46. This Part shall not affect obligation of a service provider that- (a) has been formed by an agreement; (b) is acting as such under a licensing or other regulatory regime established under any written law; or (c) has been imposed by law or by order of a court to remove, block or deny access to any electronic communication or to terminate or prevent unlawful activity. PART VI GENERAL PROVISIONS Immunity
Part
PART VI
- 47 Verify source ↗
48. Forfeiture of property
A person is not liable for acts or omissions done in good faith, without negligence, and in accordance with this Act.
47.–(1) Notwithstanding any other law to the contrary, anything done by law enforcement officer in the execution of functions conferred upon such law enforcement officer under this Act, render such law enforcement officer personally liable for such matter or thing. 520 ©2025 Government of Tanzania. All rights reserved. No part of this book may be reproduced or distributed without permission of OAG. THE CYBERCRIMES ACT [CAP. 443 R.E. 2023] (2) A person shall not be liable in respect of the performance of any act or omission where such act or omission was done in good faith and without negligence in accordance with the provisions of this Act. Forfeiture of property - 48 Verify source ↗
Forfeiture of property
The court may order forfeiture of property connected to the offence and may also order the convicted person to pay compensation to the victim.
48.–(1) In addition to a penalty imposed under this Act, the court may order forfeiture of any- (a) property constituting traceable proceeds of such offence; and (b) device or property used or intended to be used to commit or to facilitate commission of the offence. (2) In addition to an order that may be made under subsection (1), the court may order the convicted person to pay the victim of the offence such compensation as the court may deem just. - 49 Verify source ↗
Offence by body corporate
If a corporate body is convicted of an offence under this Act, certain directors, officers, managers, or people who authorised or allowed the act may be treated as having committed the same offence unless they prove lack of consent or due diligence.
49. Where a corporate body is convicted of an offence under this Act, every person who, at the time of commission of the offence was- (a) a director, officer or is otherwise concerned with the management of, the corporate body; or (b) knowingly authorised or permitted the act or omission constituting the offence, is deemed to have committed the same offence unless every such person proves that the commission of the offence took place without his consent or that he exercised due diligence to prevent the commission of offence and may be proceeded against and punished accordingly. - 50 Verify source ↗
Compounding of offences
The Director of Public Prosecutions may compound an offence before court proceedings start if there is a voluntary admission, and may order payment of a sum up to the fine prescribed for that offence.
50.–(1) Without prejudice to any other law in force in Mainland Tanzania, the Director of Public Prosecutions may, at any time prior to the commencement of court proceedings and subject to a voluntary admission of the commission of offence under this Act, compound the offence and order that person to pay a sum of money specified by him but not exceeding the amount of fine prescribed for any of such offence. Offence by body corporate Compounding of offences 521 ©2025 Government of Tanzania. All rights reserved. No part of this book may be reproduced or distributed without permission of OAG. THE CYBERCRIMES ACT [CAP. 443 R.E. 2023] (2) The compounding order under subsection (1) shall be- (a) in writing, specifying the offence committed, the sum of money to be paid and the date for payment and have attached the written admission referred to in subsection (1); (b) final and not subject to any appeal; and (c) enforced in the same manner as an order of the High Court. Power to make regulations - 51 Verify source ↗
Power to make regulations
The Minister may make regulations on matters that this Act requires to be prescribed or that are needed to give effect to the Act.
51. The Minister may make regulations with respect to any matter which, by this Act, is required to be prescribed or which is necessary for giving effect to this Act. PART VII CONSEQUENTIAL AMENDMENTS Omitted
Part
PART VII
- 52 Verify source ↗
59. [Omitted.]
Sections 52–59 are omitted in this source text.
52.–59. [Omitted.] 522 ©2025 Government of Tanzania. All rights reserved. No part of this book may be reproduced or distributed without permission of OAG.
Provision text is displayed from LexChat’s stored statute record. Use the official source links to verify amendments, commencement, and current legal force.
Ask AI about this statute
The Cybercrimes Act
Sign in to ask AI about this statute
Sign in to start authenticated, citation-grounded statute research.
Sign inLexChat organizes source-backed legal information for research. Verify amendments, commencement, and current legal force with the official publisher before relying on it.