As stipulated by the Tanzania Communications Regulatory Authority (TCRA), enterprises sending SMS messages to local users must simultaneously comply with regulations on personal data protection, consumer rights, and carrier messaging services. A2P SMS operations collect user data including mobile phone numbers, account information, delivery logs, delivery status, and marketing preferences. Before sending OTPs, transaction notifications, customer service messages, or marketing SMS, enterprises must clearly define the purposes of data processing and implement mechanisms for user authorization, information security, and complaint handling.
The Bulk SMS Privacy Addendum of Vodacom Tanzania specifies that information processed for enterprise SMS services includes personal and enterprise account details, payment records, customer service tickets, SMS delivery and fault data, among others. The legal bases for data processing include contract performance, compliance with statutory tax, security and anti-fraud requirements, or user consent. Enterprises shall not collect or share user information beyond the scope of their business operations. With regard to marketing SMS, even if users have consented to receiving promotional content, they reserve the right to unsubscribe from marketing messages at any time, and unsubscribing will not affect their receipt of transactional notifications such as bills, account security alerts, and order status updates. Enterprises shall provide a convenient unsubscribe entry and retain records of user authorization and unsubscription.
In terms of data retention, service providers shall set a reasonable retention period based on business objectives and legal constraints. According to Vodacom Tanzania’s rules, network operation data is generally anonymized or deleted after 90 days; user personal data is typically erased 12 months after service cancellation, except where otherwise required by law. Meanwhile, regulators prioritize cracking down on non-compliant SMS activities such as identity spoofing, telecom fraud, and personal information theft. Enterprises shall use verifiable sender identities and must not use fake numbers, misleading copy, or illegal number databases. Different carriers have differentiated technical specifications for Sender ID registration, content review, and SMS links, which must be confirmed in advance before service launch.
In addition, users enjoy statutory rights to access, correct, and delete their personal data, as well as to refuse marketing pushes. Enterprises engaging in A2P SMS business are required to establish management systems for data protection, anti-fraud, user complaints, and third-party service provider oversight, so as to mitigate risks such as data leaks, SMS interception, regulatory penalties, and brand damage.
