Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
TunisiaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Waking up
In one paragraph
Tunisia has had a privacy law since 2004. Under it, personal data may only leave the country if the national privacy authority signs off first, case by case. Some industries are far stricter. Government systems must sit on Tunisian soil, and firms licensed to run credit reporting are banned from using cloud hosting at all.
The catch
The permission-first picture is only the general rule. It is wrong in four places. Government electronic systems must be hosted inside Tunisia by a locally approved provider. Operators of vital digital infrastructure must keep a main data centre and a backup in Tunisia. Licensed credit reporting firms may not use any cloud hosting. Banks carry extra contract, testing and audit duties on top.
Does this apply to me?
The 2004 privacy law is written for data handling that happens in Tunisia. We found no wording that reaches a foreign company with no office, staff or equipment in the country, so a purely offshore service is probably outside it. Checked 18 August 2026, medium confidence. The cybersecurity rules are the ones that bite locally: any company that handles its users' personal data over telecoms networks, plus telecoms and internet providers, hosting and cloud firms, and companies whose networks are linked over telecoms networks, must have their systems audited in Tunisia. There is no size or revenue threshold anywhere.Medium confidence
Can the data leave the country?
In general, only with permission. Personal data may leave Tunisia only if the national privacy authority has authorised that specific transfer, and it may not go to a country that does not protect data properly. Then there are harder walls. Government electronic systems must be hosted in Tunisia. Operators of vital digital infrastructure must hold a main data centre in Tunisia and a backup with an approved Tunisian cloud provider. Licensed credit reporting firms may not put their data in the cloud at all.Medium confidence
What do I have to do to send it abroad?
The model is permission, not paperwork you write yourself. There is no standard contract, no company-wide scheme and no self-certification. You first tell the privacy authority about the processing, then you ask it separately for permission to send the data abroad. Tunisia's central bank treats these permissions as real: since February 2025 a bank using an outside firm for remote customer sign-up must hand the central bank up-to-date privacy authority certificates covering personal and fingerprint or face data.Medium confidence
Who enforces this — and are they actually working?
Two very different regulators. The privacy authority still works, but almost invisibly: its own website did not resolve at all on 18 August 2026, it publishes no decisions we could find, and the best proof it is alive comes from other agencies quoting its opinions. The cybersecurity agency is the opposite. It runs an approval scheme for cloud providers, updated its public list on 23 July 2026, renewed some approvals and refused to renew others, and can fine, downgrade or cut off organisations. The central bank is also active and treats privacy paperwork as a licensing condition.Medium confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling, and the floor is set sector by sector. The operator of the national cheque platform must keep the data exchanged through it for at least ten years. Licensed credit reporting firms and crowdfunding platforms must archive their records for at least five years. Any organisation covered by the cybersecurity rules must send its audit report to the cybersecurity agency within ten days of the audit finishing. In the other direction, the 2004 privacy law limits how long personal data may be kept, but we could not open the wording on a government site.Medium confidence
What happens when something goes wrong?
Count three clocks, and note that none of them is the 72 hours people expect from Europe. First, if you are covered by the cybersecurity rules you must tell the national cyber emergency contact point or your emergency response centre immediately, and then follow the urgent measures they order. Second, once the agency warns you about a weakness you have 30 days to fix it, or the communications minister can cut your systems off. Third, banks must tell the central bank without delay about any major incident in remote customer sign-up.Medium confidence
What's the trap?
Five things that are not in the summary. One: nobody currently holds the governmental cloud approval, so the rule that government systems must sit with an approved governmental provider cannot be satisfied as written. Two: sending data abroad without permission is a crime, not a fine - one year in prison and 5,000 dinars, about 1,600 United States dollars. Three: the compulsory security audit catches ordinary online businesses, not just banks and telecoms firms. Four: you must carry out every recommendation in that audit report. Five: the privacy authority's own website was dead when we checked, so plan for slow paper processes.Medium confidence
What's about to change?
One dated change is already published. From 1 January 2027 anyone applying for or renewing a Tunisian cloud approval must include a business continuity plan and a disaster recovery plan, and must show they have started a recognised continuity certification. Beyond that, watch the powers the government already holds rather than new bills. A decree can name which bodies count as vital digital infrastructure, a ministerial order can change how organisations are ranked for digital trust, and the communications minister can order systems to be cut off.Medium confidence
Hardest industry wall
  • Government Arrete du ministre des technologies de la communication du 13 septembre 2023, fixant les procedures et les conditions d'octroi, de renouvellement et de retrait des labels G-Cloud et N-Cloud, revise par l'arrete du 8 avril 2024
AlgeriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
In one paragraph
Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
The catch
The national rule is already strict, and three areas are stricter still. Online shops must run their site on servers inside Algeria under a .com.dz address. Electronic trust services, such as digital signatures and electronic identity, must host all the data they collect inside Algeria. Public bodies must exchange data only over a state-run network that is deliberately kept separate from the internet. Banking, insurance and securities have no storage rule that we could find, but the central bank's own website could not be reached, so treat that as unchecked rather than settled.
Does this apply to me?
Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.High confidence
Can the data leave the country?
Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.High confidence
What do I have to do to send it abroad?
The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.High confidence
Who enforces this — and are they actually working?
The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.High confidence
What happens when something goes wrong?
There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.High confidence
What's the trap?
Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.High confidence
What's about to change?
Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.High confidence
Hardest industry wall
  • Telecoms Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique
  • E-commerce Loi n° 18-05 relative au commerce electronique
  • Government Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees