The accelerating digitalisation of society has heightened the urgency of protecting personal data as both a human rights obligation and a regulatory priority. In response, Tanzania enacted the Personal Data Protection Act (PDPA) 2023, establishing the Personal Data Protection Commission (PDPC) to oversee compliance and safeguard citizens’ data rights. This study critically examines the PDPC’s effectiveness in fulfilling its statutory mandate, situating Tanzania’s data protection framework within regional and international standards, including the EU’s General Data Protection Regulation (GDPR), the African Union’s Malabo Convention, and comparable regimes in Kenya, South Africa, and Nigeria. Using doctrinal and comparative legal analysis, the study evaluates the PDPC’s institutional design, independence, and enforcement capacity. It finds that limited operational autonomy, inadequate technical expertise, and financial dependence undermine the Commission’s ability to ensure compliance and uphold data rights. While the PDPA marks significant progress in recognising privacy as a legal right, persistent institutional constraints weaken its implementation. The article concludes that achieving an effective data protection regime in Tanzania requires reforms enhancing the PDPC’s independence, resources, and alignment with international best practices. The study contributes to the discourse on digital governance in developing economies, offering policy insights for strengthening accountability and data rights protection in Tanzania’s evolving information society.