Written by the Kopesha team · Published 29 September 2026 · 14 min read · No lender pays for these guides · How we write and check them
The app has texted your family about your loan. Is that allowed?
Three days after an app loan of TZS 60,000 fell due, your sister, your pastor and a regular customer at your shop each get a text calling you a thief who refuses to pay. The app itself rings you every hour.
If the Bank of Tanzania has cleared the lender to lend through an app, the texts to your contacts break the Bank's rules, and so do calls whose effect is to harass you. Two Acts of Parliament also reach whoever sends such messages, cleared or not: the Personal Data Protection Act 2022 and the Cybercrimes Act. Below is what each one forbids, the evidence (ushahidi) to save, and where to take a complaint (lalamiko) first.
The loan does not disappear. What you received, and the lawful charges written in your agreement, are still owed; fees a lender may not charge lists the ones that are banned even when written in. A complaint deals with how the lender collects, and the last section covers the debt itself.
What an approved app lender may not do
The rules are in the Bank's Guidance Note on Digital Lenders, issued in August 2024 for Tier 2 microfinance service providers. Those are the companies and individual money lenders licensed by the Bank to lend without taking deposits. A covering circular applies the note from 27 August 2024 to Tier 2 lenders operating in Mainland Tanzania (paragraph 3 of the circular). The note's list of prohibited activities, paragraph 5.1, binds every lender that holds the Bank's no-objection letter for an app.
Paragraph 5.1(b) bars the lender from using its app to get at your contacts, call logs, SMS, photos, storage, social media, email or other installed apps, whether for identity checks or for handling arrears. Paragraph 5.1(f) lists what the lender's officers, employees and agents may not do while collecting, whether the target is you or "any other person":
- use threats, violence or other means to harm a person, their reputation or their property if the loan is not settled (i)
- send obscene or profane language to you, your references or your contacts in order to shame you (ii)
- go into your phone book or other phone records to send people messages because a payment is late or missing (iii)
- post your personal or sensitive information online, or in any other forum, to shame you (iv)
- make unauthorised or unsolicited calls or send such messages to your phone contacts and other contacts (v)
- use any improper or unconscionable collection tactic (vi)
- do anything else whose result is to harass, oppress or abuse any person over the debt (vii)
Two more items in the same paragraph matter here. Under 5.1(c), the lender's directors, officers, employees and agents may not divulge customer information, while they work there or after they leave. And 5.1(q) says a digital loan may not be handed to a debt collector, outsourced call centre or agent unless you are informed before they get in touch.
An app may point to a box you ticked when you installed it. The bans in 5.1(b) and 5.1(f)(iii) contain no exception for a borrower who agreed.
Match what happened to the rule it breaks
Every Tier 2 lender, with an app or without one, is also bound by regulation 56 of the 2019 Tier 2 regulations (Government Notice 679). Regulation 56(2) forbids harassing, abusing or oppressing a borrower, a guarantor (mdhamini) or anyone else over a debt.
The Bank's 2019 consumer protection regulations list abusive debt recovery as an unfair practice (regulation 11(2)(b)). The same regulations define abusive debt recovery to include harassment and coercion (regulation 3, repeated in regulation 11(3) by the 2025 amendment).
| What happened | Bank of Tanzania rules | Acts of Parliament |
|---|---|---|
| Texts or calls to people in your phone book about your loan | Note 5.1(b), 5.1(f)(iii) and (v) | PDPA sections 25, 26 and 60(1): data used or disclosed outside the purpose it was collected for |
| Insults such as "thief" or "fraud", obscene words, or calls at all hours, to you or your contacts | Note 5.1(f)(ii) and (vii); Reg 56(2)(b) and (d) | Cybercrimes Act section 23, where the intent is to intimidate, harass or cause distress |
| Threats of harm to you, your family, your home or your name | Note 5.1(f)(i); Reg 56(2)(c) | Cybercrimes Act section 23 |
| Your photo or ID card posted in a WhatsApp group or on social media | Note 5.1(f)(iv) | PDPA sections 26 and 60(1) |
| Threats of arrest or a court case that cannot legally follow, or that the lender does not intend | Reg 56(2)(e)(iii) | Cybercrimes Act section 23, where the intent is to coerce or intimidate |
| A caller who falsely says he is a lawyer, or a message falsely said to come from one | Reg 56(2)(e)(ii) | Cybercrimes Act section 15, where the message impersonates a named person |
| A collector you were never told about | Note 5.1(q); Reg 56(4)(a) requires any collector to be licensed | No specific section |
| New charges that are not in your agreement | Reg 56(3) | No specific section |
If the app is not on the Bank's approved list
Paragraph 5.1 binds lenders the Bank has cleared. The Bank's separate list of apps it has not approved, dated 28 February 2026, names 116. Its web page for that list states that lending through such an app breaks section 16 of the Microfinance Act 2018, and warns that a person who deals with one risks losing the protection of the Bank's consumer protection regulations. So the Bank's complaint desk may decline your case.
The same page asks the public to report such apps to the Bank straight away, without naming a channel. For unlicensed providers, the Bank's public notices page asks for reports by email to complaints-desk@bot.go.tz; the footer of its website adds info@bot.go.tz. Is this loan app approved? shows how to check an app against both of the Bank's lists.
The two Acts do not depend on a licence. The Personal Data Protection Act's rules on collecting, using and disclosing data cover a controller based outside Tanzania when the processing happens in Tanzania (section 22(1)(c)). Section 23 of the Cybercrimes Act applies to "a person". So the data protection commission and the police stay open to you whoever runs the app.
Zanzibar is treated differently. Section 2 of the Microfinance Act limits that Act to Mainland Tanzania, and the circular limits the guidance note in the same way; GN 679 is made under section 60 of that Act. The Personal Data Protection Act applies to Mainland Tanzania and to Tanzania Zanzibar, except for non-union matters in Zanzibar (section 2). The Cybercrimes Act applies to both, apart from its section 50 (section 2).
Save the evidence before you block anyone
Save these before you delete a message or uninstall the app:
- Screenshots of every message, showing the sender's number or name, the date and the time.
- Screenshots from the people who were contacted, with the date showing, and a note of their names and numbers.
- Your call log for the days of the calls, showing each number and how often it rang.
- The app's landing page: its name, the company it says owns it, and the complaint contacts. A cleared app must name its owner there in a sentence beginning "This App … is owned or operated by" (Guidance Note 3.1(d)) and give working complaint contacts (3.1(h)).
- The loan: the amount received, the charges shown, the due date, and each repayment's transaction ID with the e-receipt or message that 5.1(g) requires.
- The app's permissions page in your phone's settings, showing what it can reach.
- A written log: date, time, number, what was said, and who else received it.
Keep two copies, one on the phone and one printed or emailed to yourself, and attach copies, never your only set, to a complaint. Then switch off the app's access to your contacts, messages and files. That stops further reading of your phone but does not delete what the app has already copied.
Tell the people who were messaged that the texts come from a lender breaking the rules, and ask them to keep the messages and not reply. Any person may complain to the Personal Data Protection Commission under section 39 of the data protection Act, so a relative whose number was taken can complain in their own right.
Where to complain, and in what order
If a message threatens violence (vitisho) against you or your family, report it at a police station first. The complaint routes below can take weeks.
- The lender's complaints desk. Write to the contacts on the app's landing page. Say what happened and which paragraph it breaks. Ask in writing that all contact with third parties stop, that the lender tell you what data it holds on you, why, and who has received it (section 33 of the Personal Data Protection Act), and that it delete the contact list it took. Ask for a complaint reference number, which clause 17 of the Bank's 2025 complaint-handling guidelines obliges the lender to give you.
- Sema na BoT. If the lender does not resolve the complaint in time, or you do not accept its answer, take it to the Bank through the Sema na BoT website, app, toll-free line or chatbot (clause 25). The time limits at each stage are in your rights as a borrower.
- The Personal Data Protection Commission. For the use of your phone data and the messages to your contacts. The next section explains the form and the timetable.
- The police, for the criminal offences described below, even when no violence was threatened.
One caution. The Bank will only take a complaint that "has not been subject to legal proceedings before a Court or Tribunal or any other competent authority" (clause 25(3)(d)). The Commission may reject one that is pending before a court, tribunal, arbitration or quasi-judicial body (regulation 5(1)(c) of its complaint regulations). Neither text says whether the other body counts. Keep the collection conduct and the data misuse as separate complaints, tell each body about the other, and ask a lawyer if you are unsure.
Complaining to the data protection commission
The Personal Data Protection Act requires personal data to be collected for explicit, specified and legitimate purposes and not processed further in ways incompatible with them (section 5). Details of your loan are personal data, and so is every name and number in your phone book.
A company may use data for a new purpose, or disclose it to anyone other than the person it is about, only in the cases section 25 lists, such as your own authorisation or a legal requirement (sections 25 and 26). Where a breach of the Act causes you damage, section 37 makes the company liable to compensate you.
The procedure is in the Personal Data Protection (Complaints Settlement Procedures) Regulations, 2023 (GN 449B). You complain on Form No. 1, printed in the Schedule at the end of the regulations (regulation 4(1)), in Kiswahili or English (4(4)). If writing is hard for you, you may complain orally and the Commission fills in the form for you to sign (4(2)). People wronged by the same app can file one group complaint, attaching a list of their names with signatures or thumbprints and the minutes of the meeting where they agreed to file (4(3)).
The form asks for your details, the company's name and address, what happened and the relief you want, such as the messages stopped, your contacts' data erased, or compensation. It also asks whether you tried to settle it with the company or went to another institution, and for a list of documents attached.
| Stage | Time limit | Rule |
|---|---|---|
| The Commission checks your complaint; a rejection comes in writing with reasons | Within 7 days of the decision to reject | Regulation 5(2) |
| The company is summoned to answer | Within 7 days after the check | Regulation 6(1) |
| The company files its defence | Within 21 days of the summons, or the Commission hears the case without it | Regulation 7(1) and (3) |
| A Commission officer tries mediation; an agreed settlement becomes the award | Within 30 days of filing | Regulation 14(1) |
| Mediation fails and a three-member committee hears the case | Hearing summons within 7 days of referral | Regulations 16(2) and 17(2) |
| The whole complaint is concluded | 90 days from receipt, extendable by up to 90 more: 180 days at most | Act section 39(3) and (4) |
| Either side asks the Commission to review its award | Apply within 21 days; review decided within 14 days | Regulation 25 |
| Either side appeals to the High Court | Within 21 days of delivery of the award | Regulation 26 |
An enforcement notice may direct the company to stop collecting or processing data, or to erase or destroy it (regulation 22(2)). A person who then fails to comply can be given a penalty notice with a fine of up to TZS 100 million (sections 46 and 47). The Commission may also order compensation, and section 50(4) says damage includes harm that is not financial. Once registered at the High Court, an award is enforceable as that court's order (regulation 24).
On 28 September 2026 the Commission's website, pdpc.go.tz, gave its address as P.O. Box 1105, 1 Moshi Street, Viwandani, 41102 Dodoma, with the email helpdesk@pdpc.go.tz and office hours of Monday to Friday, 08:00 to 16:00. The regulations containing Form No. 1 are published there as a PDF (see the sources below). The site's "File a complaint here" link also opens the form online, at dataprotection.pdpc.go.tz.
Cyber bullying and unlawful disclosure are crimes
Section 23 of the Cybercrimes Act (Cap. 443) is headed "Cyber bullying". It forbids anyone to start or send an electronic communication through a computer system to another person "with intent to coerce, intimidate, harass or cause emotional distress". On conviction the penalty is a fine of not less than TZS 5 million, imprisonment of not less than three years, or both.
The data protection law carries its own offence. A data controller that, without lawful excuse, discloses personal data in a way incompatible with the purpose it was collected for commits an offence (section 60(1)). Section 60(6) sets the penalty: for an individual, a fine from TZS 100,000 to TZS 20 million, prison of up to ten years, or both; for a company, a fine from TZS 1 million to TZS 5 billion. Where a company offends, section 62 also makes liable every officer who knowingly and wilfully authorised or permitted it.
The police investigate, and only a court can convict. The Tanzania Communications Regulatory Authority's consumer questions say criminal matters, including being insulted online, are for the police. Report at a station to get an RB number and an investigator, and take printed copies of your evidence. If you meet an obstacle, the same page says to speak to the officer in charge of the station and then the levels above. Write the RB number on your complaints to the lender, the Bank and the Commission.
The loan is still yours to settle
Nothing in the Guidance Note, the data protection law or the Cybercrimes Act reduces what you owe under your agreement. What the rules limit is collection. Regulation 56(2)(a) of GN 679 requires 14 days' written notice before collection begins. Under regulation 56(3), interest, fees, charges or expenses that the loan agreement does not prescribe may not be collected, so a new "penalty" announced in a threatening text is owed only if the agreement provides for it.
Pay through the app or the lender's own published numbers, never a personal number a collector sends you, keep every e-receipt, and ask in writing for a statement of your balance. If the charges seem far out of line with what you borrowed, the guide to phone and app loan costs converts a fee over days into monthly and yearly rates.
If you cannot pay on time, the guide to a missed payment covers the notices and credit bureau reporting that follow a late installment (rejesho). Getting out of debt you already have helps you plan repayments across several loans.
Sources
- Guidance Note on Digital Lenders under Tier 2 Microfinance Service Providers, 2024 — Bank of Tanzania
- Circular on publication of the Guidance Note on Digital Lenders, 27 August 2024 — Bank of Tanzania
- Microfinance (Non-Deposit Taking Microfinance Service Providers) Regulations, 2019, GN 679 — Bank of Tanzania
- Microfinance Act, 2018 — Bank of Tanzania
- Bank of Tanzania (Financial Consumer Protection) Regulations, 2019, GN 884
- Bank of Tanzania (Financial Consumer Protection) (Amendment) Regulations, 2025, GN 298
- Guidelines for Handling Financial Consumer Complaints, 2025 — Bank of Tanzania
- List of unapproved digital lending platforms (page) — Bank of Tanzania
- List of unapproved digital lending platforms and apps, up to 28 February 2026 — Bank of Tanzania
- Taarifa kwa umma: Watoa Huduma za Fedha wasiosajiliwa (reporting unlicensed providers) — Bank of Tanzania
- Personal Data Protection Act, 2022 (Cap. 44) — Personal Data Protection Commission
- Personal Data Protection (Complaints Settlement Procedures) Regulations, 2023, GN 449B, with Form No. 1 — Personal Data Protection Commission
- Form No. 1, online complaint form — Personal Data Protection Commission
- Personal Data Protection Commission, contact details
- Cybercrimes Act, Cap. 443 R.E. 2023 — National Prosecutions Service
- Frequently asked questions on customer and consumer affairs — Tanzania Communications Regulatory Authority
- Sema na BoT complaints portal — Bank of Tanzania
What changed
- 29 September 2026: First published.
Found a mistake? Tell us through the contact page and name this guide. We check it against the source and correct the page.
This guide is general information about borrowing in Tanzania. It is not legal or financial advice about your situation or about any particular lender, and the worked examples are examples, not a quote or an offer from anybody.