Data Protection
MDF’s data-protection framework is designed around the Tanzania Personal Data Protection Act, 2022 and applicable regulations, supported by internationally recognised principles of fairness, purpose limitation, minimisation, accuracy, security and accountability.
Know who is responsible
Material datasets should have an identified owner, purpose, lawful basis, classification, access rule, retention period and review process.
Provide usable request channels
Requests for access, correction, deletion or other rights should be authenticated, logged, reviewed and answered within applicable legal requirements.
Prepare before an incident
MDF should protect records according to risk, restrict privileged access, maintain backups and logs, assess suspected breaches promptly and make legally required notifications.
Control external handling
Contracts or formal arrangements should define permitted processing, confidentiality, security, retention, incident reporting, return or deletion, audit rights and cross-border transfer responsibilities.
Protect people and sensitive ecosystems
GPS evidence, participant records, research data and community information require consent or another valid basis, safe devices, controlled synchronisation and disclosure rules that protect people and ecologically sensitive locations.
Local impact grows through long-term relationships.
Return for field updates, approved reports, learning opportunities and new ways to participate in MDF programmes.
