Tunisia
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
Tunisia has had a privacy law since 2004. Under it, personal data may only leave the country if the national privacy authority signs off first, case by case. Some industries are far stricter. Government systems must sit on Tunisian soil, and firms licensed to run credit reporting are banned from using cloud hosting at all.
Data governance in Tunisia
The eight things that decide how you handle data about people in Tunisia. Same eight on every country page, so you can compare.
Who has to follow these rules
The 2004 privacy law is written for data handling that happens in Tunisia. We found no wording that reaches a foreign company with no office, staff or equipment in the country, so a purely offshore service is probably outside it. Checked 18 August 2026, medium confidence. The cybersecurity rules are the ones that bite locally: any company that handles its users' personal data over telecoms networks, plus telecoms and internet providers, hosting and cloud firms, and companies whose networks are linked over telecoms networks, must have their systems audited in Tunisia. There is no size or revenue threshold anywhere.
The cybersecurity decree-law of 11 March 2023 lists, in its Article 6, the bodies subject to compulsory periodic audit: public bodies, public telecoms network operators and telecoms and internet service providers, companies whose computer networks are interconnected through telecoms networks, hosting and cloud service providers, companies that carry out automated processing of their users' personal data when delivering services over telecoms networks, and vital digital infrastructure. That list captures most online businesses with a Tunisian operation. No general obligation to appoint a local representative was found for the privacy law. In practice a local vehicle is needed to be an approved cloud host, because both cloud labels are reserved to Tunisian hosting providers.
Sources
- Official sourceAgence Nationale de la CybersecuriteDecret-loi n° 2023-17 du 11 mars 2023, relatif a la cybersecurite (official gazette text, JORT n° 26)
ancs.tn
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteAudit reglementaire - cadre juridique et reglementaire de la mission d'audit
ancs.tn
Link checked 18 August 2026
- Secondary sourceDLA PiperData Protection Laws of the World - Tunisia: law
dlapiperdataprotection.com
Link checked 18 August 2026
Where the data is allowed to live
In general, only with permission. Personal data may leave Tunisia only if the national privacy authority has authorised that specific transfer, and it may not go to a country that does not protect data properly. Then there are harder walls. Government electronic systems must be hosted in Tunisia. Operators of vital digital infrastructure must hold a main data centre in Tunisia and a backup with an approved Tunisian cloud provider. Licensed credit reporting firms may not put their data in the cloud at all.
Sector by sector, as verified on 18 August 2026. GOVERNMENT: closed. The 2023 cybersecurity decree-law requires the bodies it covers to host government electronic systems and services with providers holding a national or governmental cloud label, and the ministerial order that sets the label conditions requires the provider to be Tunisian and to use primary and backup data centres located on Tunisian territory. VITAL DIGITAL INFRASTRUCTURE: closed. Those operators must run their own main hosting centre plus a backup at a labelled provider. CREDIT REPORTING: no cloud permitted, and records must be archived for five years. BANKING AND PAYMENTS: no residency rule found, but outsourcing is regulated and remote customer onboarding carries heavy conditions. TELECOMS, INSURANCE, SECURITIES, HEALTH, EDUCATION, GAMBLING, MAPPING: no storage-location rule found on the regulators' own sites, checked 18 August 2026, medium confidence - several Tunisian official sites, including the privacy authority's own site and the national legal database, were unreachable during this research.
Sources
- Official sourceMinistere des technologies de la communication / ANCSArrete du ministre des technologies de la communication du 13 septembre 2023 fixant les conditions d'octroi des labels G-Cloud et N-Cloud (JORT n° 106)
ancs.tn
“Doit fournir et utiliser des centres de donnees primaires et de secours situes sur le territoire tunisien”
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteDecret-loi n° 2023-17 du 11 mars 2023, relatif a la cybersecurite (official gazette text, JORT n° 26)
ancs.tn
Link checked 18 August 2026
- Official sourceBanque Centrale de TunisieCirculaire de la Banque Centrale de Tunisie n° 2022-09 du 25 octobre 2022 (agrement pour l'activite de renseignement de credit)
bct.gov.tn
“L'hebergement des donnees (avec interdiction d'hebergement dans le cloud) ; L'archivage obligatoire pour une periode de 5 ans.”
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteLabelisation - labels N-Cloud et G-Cloud
ancs.tn
Link checked 18 August 2026
- Secondary sourceDLA PiperData Protection Laws of the World - Tunisia: transfer
dlapiperdataprotection.com
Link checked 18 August 2026
Sending data out of the country
The model is permission, not paperwork you write yourself. There is no standard contract, no company-wide scheme and no self-certification. You first tell the privacy authority about the processing, then you ask it separately for permission to send the data abroad. Tunisia's central bank treats these permissions as real: since February 2025 a bank using an outside firm for remote customer sign-up must hand the central bank up-to-date privacy authority certificates covering personal and fingerprint or face data.
The declaration and authorisation procedure sits in a government decree of 27 November 2007, which the central bank cites in its own rules. Secondary legal sources report that the authority has one month to decide, that transfers to countries that do not protect data are forbidden, and that a 2018 decision of the authority lists countries considered to offer sufficient protection. We could not open that decision on a Tunisian government site during this research, so treat the list as reported rather than verified. Consent of the person concerned is also required for a transfer, and transfers involving children are reported to need a family judge. Tunisia joined the Council of Europe's data protection convention in 2017, which is often cited as support for transfers, but that is a treaty obligation and not a substitute for the authorisation.
Sources
- Official sourceBanque Centrale de TunisieCirculaire de la Banque Centrale de Tunisie n° 2022-09 du 25 octobre 2022 (agrement pour l'activite de renseignement de credit)
bct.gov.tn
“L'hebergement des donnees (avec interdiction d'hebergement dans le cloud) ; L'archivage obligatoire pour une periode de 5 ans.”
Link checked 18 August 2026
- Official sourceBanque Centrale de TunisieCirculaire aux banques n° 2025-06 du 28 fevrier 2025 - regles minimales regissant l'enrolement electronique des clients
bct.gov.tn
“des attestations actualisees du tiers pour le traitement des donnees personnelles et biometriques delivrees par l'Instance Nationale de Protection des Donnees Personnelles”
Link checked 18 August 2026
- Secondary sourceDLA PiperData Protection Laws of the World - Tunisia: transfer
dlapiperdataprotection.com
Link checked 18 August 2026
The regulator, and whether it actually acts
Two very different regulators. The privacy authority still works, but almost invisibly: its own website did not resolve at all on 18 August 2026, it publishes no decisions we could find, and the best proof it is alive comes from other agencies quoting its opinions. The cybersecurity agency is the opposite. It runs an approval scheme for cloud providers, updated its public list on 23 July 2026, renewed some approvals and refused to renew others, and can fine, downgrade or cut off organisations. The central bank is also active and treats privacy paperwork as a licensing condition.
Evidence of the privacy authority working: the central bank's credit reporting rules of October 2022 cite its opinion number 22/03-333 of 15 August 2022; the crowdfunding rules of November 2023 cite its opinion of 31 August 2023; and the February 2025 remote onboarding rules require banks to produce its certificates for personal and biometric data. Evidence of the cybersecurity agency working: it publishes and versions a list of labelled cloud providers, with entries showing labels renewed, applications pending and two labels not renewed in November 2025. Its statutory fines run from 50,000 to 100,000 Tunisian dinars, roughly 16,000 to 32,000 United States dollars. The communications minister can also order an organisation's systems to be temporarily cut off on a reasoned report from the agency. We found no public register of privacy fines or privacy court decisions.
Sources
- Official sourceBanque Centrale de TunisieCirculaire de la Banque Centrale de Tunisie n° 2023-06 du 2 novembre 2023 (crowdfunding en prets)
bct.gov.tn
“Vu l'avis de l'Instance Nationale de Protection des Donnees a caractere Personnel en date du 31 aout 2023”
Link checked 18 August 2026
- Official sourceBanque Centrale de TunisieCirculaire aux banques n° 2025-06 du 28 fevrier 2025 - regles minimales regissant l'enrolement electronique des clients
bct.gov.tn
“des attestations actualisees du tiers pour le traitement des donnees personnelles et biometriques delivrees par l'Instance Nationale de Protection des Donnees Personnelles”
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteListe des fournisseurs Cloud labelises, version 5.2 du 23 juillet 2026
ancs.tn
“Nouvelle Exigence : Il est a noter qu'a partir du 1er Janvier 2027, les dossiers d'octroi ou de renouvellement doivent contenir un Plan de Continuite d'Activites (PCA) et un Plan de reprise d'activites (PRA)”
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteDecret-loi n° 2023-17 du 11 mars 2023, relatif a la cybersecurite (official gazette text, JORT n° 26)
ancs.tn
Link checked 18 August 2026
- Official sourceLink may be brokenINPDPInstance Nationale de Protection des Donnees a Caractere Personnel - official website (name server returned SERVFAIL on 18 August 2026)
inpdp.nat.tn
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a floor and a ceiling, and the floor is set sector by sector. The operator of the national cheque platform must keep the data exchanged through it for at least ten years. Licensed credit reporting firms and crowdfunding platforms must archive their records for at least five years. Any organisation covered by the cybersecurity rules must send its audit report to the cybersecurity agency within ten days of the audit finishing. In the other direction, the 2004 privacy law limits how long personal data may be kept, but we could not open the wording on a government site.
Verified floors: ten years for data exchanged through the single electronic cheque platform, under central bank rules of 31 January 2025; five years of compulsory archiving for credit reporting licence applicants under central bank rules of 25 October 2022; at least five years for crowdfunding platforms under central bank rules of 2 November 2023. General company and tax record-keeping periods are widely reported as ten years but we could not verify them on a Tunisian government site during this research, so they are listed as unconfirmed. Where a keep-it rule and a delete-it rule collide, the sector rule is the one a Tunisian regulator will inspect, and the privacy law expressly allows keeping data where another law requires it.
Sources
- Official sourceBanque Centrale de TunisieCirculaire de la Banque Centrale de Tunisie n° 2025-03 du 31 janvier 2025 - Plateforme Electronique Unique des Cheques
bct.gov.tn
“Le gestionnaire doit assurer un archivage securise des donnees echangees via la plateforme et les conserver pendant une duree minimale de dix ans”
Link checked 18 August 2026
- Official sourceBanque Centrale de TunisieCirculaire de la Banque Centrale de Tunisie n° 2022-09 du 25 octobre 2022 (agrement pour l'activite de renseignement de credit)
bct.gov.tn
“L'hebergement des donnees (avec interdiction d'hebergement dans le cloud) ; L'archivage obligatoire pour une periode de 5 ans.”
Link checked 18 August 2026
- Official sourceBanque Centrale de TunisieCirculaire de la Banque Centrale de Tunisie n° 2023-06 du 2 novembre 2023 (crowdfunding en prets)
bct.gov.tn
“Vu l'avis de l'Instance Nationale de Protection des Donnees a caractere Personnel en date du 31 aout 2023”
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteDecret-loi n° 2023-17 du 11 mars 2023, relatif a la cybersecurite (official gazette text, JORT n° 26)
ancs.tn
Link checked 18 August 2026
If something goes wrong
Count three clocks, and note that none of them is the 72 hours people expect from Europe. First, if you are covered by the cybersecurity rules you must tell the national cyber emergency contact point or your emergency response centre immediately, and then follow the urgent measures they order. Second, once the agency warns you about a weakness you have 30 days to fix it, or the communications minister can cut your systems off. Third, banks must tell the central bank without delay about any major incident in remote customer sign-up.
The 2023 cybersecurity decree-law requires immediate notification to the national contact point for cyber emergencies or to a public, sector or private emergency response centre, and compliance with the urgent measures those bodies set. The same law gives a 30-day window to remove failings after a warning, backed by a power to isolate the systems and networks concerned by ministerial decision on a reasoned report. Covered organisations must also either create their own cyber emergency response centre or join one. Failure to obey urgent measures, to fix within the deadline or to have an emergency response centre is one of the grounds for both downgrading and fines. We found no general duty in the 2004 privacy law to report a personal data breach to the privacy authority or to affected people, checked 18 August 2026, medium confidence.
Sources
- Official sourceAgence Nationale de la CybersecuriteDecret-loi n° 2023-17 du 11 mars 2023, relatif a la cybersecurite (official gazette text, JORT n° 26)
ancs.tn
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteProcedure de declarations des incidents cybernetiques
ancs.tn
Link checked 18 August 2026
- Official sourceBanque Centrale de TunisieCirculaire aux banques n° 2025-06 du 28 fevrier 2025 - regles minimales regissant l'enrolement electronique des clients
bct.gov.tn
“des attestations actualisees du tiers pour le traitement des donnees personnelles et biometriques delivrees par l'Instance Nationale de Protection des Donnees Personnelles”
Link checked 18 August 2026
What catches people out
Five things that are not in the summary. One: nobody currently holds the governmental cloud approval, so the rule that government systems must sit with an approved governmental provider cannot be satisfied as written. Two: sending data abroad without permission is a crime, not a fine - one year in prison and 5,000 dinars, about 1,600 United States dollars. Three: the compulsory security audit catches ordinary online businesses, not just banks and telecoms firms. Four: you must carry out every recommendation in that audit report. Five: the privacy authority's own website was dead when we checked, so plan for slow paper processes.
On the first trap: the cybersecurity agency's list of labelled providers, version 5.2 of 23 July 2026, contains only national cloud labels and no governmental cloud label, and several national labels were pending renewal. On the third: the audit duty covers any company doing automated processing of its users' personal data while delivering services over telecoms networks, must be done at least once every twelve months, and only auditors certified by the agency may do it. On the fourth: the report goes to the agency within ten days and all its security recommendations must be implemented; partial implementation within a year is itself a ground for a fine of 50,000 to 100,000 dinars for unclassified organisations. Two more to watch: credit reporting firms are flatly banned from cloud hosting, and banks using an outside firm for remote sign-up must impose contract terms that go well beyond a normal supplier agreement, including a ban on that firm subcontracting and a right for the central bank to inspect the firm's own premises.
Sources
- Official sourceAgence Nationale de la CybersecuriteListe des fournisseurs Cloud labelises, version 5.2 du 23 juillet 2026
ancs.tn
“Nouvelle Exigence : Il est a noter qu'a partir du 1er Janvier 2027, les dossiers d'octroi ou de renouvellement doivent contenir un Plan de Continuite d'Activites (PCA) et un Plan de reprise d'activites (PRA)”
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteDecret-loi n° 2023-17 du 11 mars 2023, relatif a la cybersecurite (official gazette text, JORT n° 26)
ancs.tn
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteAudit reglementaire - cadre juridique et reglementaire de la mission d'audit
ancs.tn
Link checked 18 August 2026
- Official sourceBanque Centrale de TunisieCirculaire de la Banque Centrale de Tunisie n° 2022-09 du 25 octobre 2022 (agrement pour l'activite de renseignement de credit)
bct.gov.tn
“L'hebergement des donnees (avec interdiction d'hebergement dans le cloud) ; L'archivage obligatoire pour une periode de 5 ans.”
Link checked 18 August 2026
- Official sourceBanque Centrale de TunisieCirculaire aux banques n° 2025-06 du 28 fevrier 2025 - regles minimales regissant l'enrolement electronique des clients
bct.gov.tn
“des attestations actualisees du tiers pour le traitement des donnees personnelles et biometriques delivrees par l'Instance Nationale de Protection des Donnees Personnelles”
Link checked 18 August 2026
- Secondary sourceDLA PiperData Protection Laws of the World - Tunisia: transfer
dlapiperdataprotection.com
Link checked 18 August 2026
What's changing next
One dated change is already published. From 1 January 2027 anyone applying for or renewing a Tunisian cloud approval must include a business continuity plan and a disaster recovery plan, and must show they have started a recognised continuity certification. Beyond that, watch the powers the government already holds rather than new bills. A decree can name which bodies count as vital digital infrastructure, a ministerial order can change how organisations are ranked for digital trust, and the communications minister can order systems to be cut off.
The 1 January 2027 requirement appears in version 4.3 of the cybersecurity agency's labelled provider list, dated 8 July 2026, and is carried in the current version 5.2 of 23 July 2026. Dormant switches, in rough order of how fast they could change the picture: the decree fixing the list of vital digital infrastructure operators, which pulls named organisations into the in-country hosting and backup duty; the ministerial order setting the classification procedure, since being left unclassified is what exposes an organisation to the 50,000 to 100,000 dinar fines; the ministerial order on technical audit criteria; and the privacy authority's power to revise which countries it treats as offering sufficient protection. A modernised, Europe-style privacy bill has been reported as pending since 2018; we found no evidence it has been adopted, and it must not be treated as binding.
Sources
- Official sourceAgence Nationale de la CybersecuriteListe des fournisseurs Cloud labelises, version 5.2 du 23 juillet 2026
ancs.tn
“Nouvelle Exigence : Il est a noter qu'a partir du 1er Janvier 2027, les dossiers d'octroi ou de renouvellement doivent contenir un Plan de Continuite d'Activites (PCA) et un Plan de reprise d'activites (PRA)”
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteDecret-loi n° 2023-17 du 11 mars 2023, relatif a la cybersecurite (official gazette text, JORT n° 26)
ancs.tn
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteLabelisation - labels N-Cloud et G-Cloud
ancs.tn
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Arrete du ministre des technologies de la communication du 13 septembre 2023, fixant les procedures et les conditions d'octroi, de renouvellement et de retrait des labels G-Cloud et N-Cloud, revise par l'arrete du 8 avril 2024
Directly binding regulation · Arrete of 13 September 2023, JORT n° 106; revised by the arrete of 8 April 2024; implementing Articles 12 to 14 of Decret-loi n° 2023-17
Government electronic systems and services must be hosted with a cloud provider holding a Tunisian national or governmental cloud label, and those labels are only given to Tunisian providers whose main and backup data centres are inside Tunisia. As of 23 July 2026 no provider held the governmental label.
Enforced by National Cybersecurity Agency
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryApproved providers must be Tunisian and must use primary and backup data centres located on Tunisian territory; governmental cloud providers must also connect to the national administration network and the national interoperability platform.
- Prove the data stays under local controlLabels are granted after the opinion of the ministers of national defence and of the interior.
- Hold a security certificate — 1 yearLabels are renewed every year and can be withdrawn early if a technical condition stops being met.
What it costs if you get it wrong
- Loss of your licence: Withdrawal of the cloud labelFailure to keep to the technical conditions of the label
Sources
- Official sourceMinistere des technologies de la communication / ANCSArrete du ministre des technologies de la communication du 13 septembre 2023 fixant les conditions d'octroi des labels G-Cloud et N-Cloud (JORT n° 106)
ancs.tn
“Doit fournir et utiliser des centres de donnees primaires et de secours situes sur le territoire tunisien”
Link checked 18 August 2026
- Official sourceMinistere des technologies de la communication / ANCSArrete du ministre des technologies de la communication du 8 avril 2024 revisant les conditions des labels G-Cloud et N-Cloud
ancs.tn
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteLabelisation - labels N-Cloud et G-Cloud
ancs.tn
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteListe des fournisseurs Cloud labelises, version 5.2 du 23 juillet 2026
ancs.tn
“Nouvelle Exigence : Il est a noter qu'a partir du 1er Janvier 2027, les dossiers d'octroi ou de renouvellement doivent contenir un Plan de Continuite d'Activites (PCA) et un Plan de reprise d'activites (PRA)”
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteDecret-loi n° 2023-17 du 11 mars 2023, relatif a la cybersecurite (official gazette text, JORT n° 26)
ancs.tn
Link checked 18 August 2026
Circulaire de la Banque Centrale de Tunisie n° 2022-09 du 25 octobre 2022
Regulator directive · Circulaire BCT n° 2022-09, made under Decret-loi n° 2022-2 du 4 janvier 2022 on credit information activity
A firm applying to run credit reporting in Tunisia must describe where its data will be hosted, and cloud hosting is expressly forbidden. Records must be archived for five years. The central bank issued this rule after taking the privacy authority's opinion.
Enforced by Central Bank of Tunisia
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryCloud hosting of the data is prohibited outright for licence applicants.
- Keep data for a minimum period — 5 yearsCompulsory archiving for five years.
- Secure the dataThe licence file must describe data and system access tools, network security, audit trails, backup and hosting arrangements.
Sources
- Official sourceBanque Centrale de TunisieCirculaire de la Banque Centrale de Tunisie n° 2022-09 du 25 octobre 2022 (agrement pour l'activite de renseignement de credit)
bct.gov.tn
“L'hebergement des donnees (avec interdiction d'hebergement dans le cloud) ; L'archivage obligatoire pour une periode de 5 ans.”
Link checked 18 August 2026
Circulaire aux banques n° 2025-06 du 28 fevrier 2025, relative aux regles minimales regissant l'enrolement electronique des clients
Regulator directive · Circulaire BCT n° 2025-06; related archiving duty in Circulaire BCT n° 2025-03 du 31 janvier 2025
Banks doing remote customer sign-up must protect the identity data with strong encryption, test the technology through an approved cyber auditor, and hold privacy authority certificates for fingerprint and face data. Outside providers face contract terms far heavier than a normal supplier agreement.
Enforced by Central Bank of Tunisia
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Written vendor contractContracts with an outside sign-up provider must ban subcontracting, ban disclosure, give the bank timely access to all data, and let the central bank inspect the provider's own premises.
- Put a transfer safeguard in placeThe bank must give the central bank up-to-date privacy authority certificates covering the provider's processing of personal and biometric data.
- Independent audit — 2 yearsThe sign-up process and technology must be audited every two years, and outsourced activity audited yearly.
- Hold a security certificatePenetration testing by an auditor approved by the cybersecurity agency before go-live.
- Report cyber incidentsThe central bank must be told without delay of any major technical or functional incident in electronic customer sign-up.
- Keep data for a minimum period — 10 yearsUnder the January 2025 cheque platform rules, the platform operator must archive exchanged data for at least ten years.
Sources
- Official sourceBanque Centrale de TunisieCirculaire aux banques n° 2025-06 du 28 fevrier 2025 - regles minimales regissant l'enrolement electronique des clients
bct.gov.tn
“des attestations actualisees du tiers pour le traitement des donnees personnelles et biometriques delivrees par l'Instance Nationale de Protection des Donnees Personnelles”
Link checked 18 August 2026
- Official sourceBanque Centrale de TunisieCirculaire de la Banque Centrale de Tunisie n° 2025-03 du 31 janvier 2025 - Plateforme Electronique Unique des Cheques
bct.gov.tn
“Le gestionnaire doit assurer un archivage securise des donnees echangees via la plateforme et les conserver pendant une duree minimale de dix ans”
Link checked 18 August 2026
- Official sourceBanque Centrale de TunisieCirculaire aux etablissements de credit n° 2006-19 du 28 novembre 2006 relative au controle interne (cites the 2006-01 outsourcing circular)
bct.gov.tn
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Loi organique n° 2004-63 du 27 juillet 2004, portant sur la protection des donnees a caractere personnel
Act of parliament · Loi organique n° 2004-63 du 27 juillet 2004; procedures in Decret n° 2007-3004 du 27 novembre 2007
Tunisia's general privacy law. Processing must be declared to the national privacy authority, and personal data may only be sent abroad if that authority authorises the specific transfer and the destination protects data properly. Breaking the transfer rule is a crime, not just a fine.
Enforced by National Authority for the Protection of Personal Data
Transfer model: Approval each time · Accepted routes: Government sign-off needed, Explicit consent
What it makes you do
- Register or notifyProcessing must be declared to the privacy authority; sensitive processing and transfers abroad need a separate authorisation.
- Put a transfer safeguard in placePrior authorisation of the privacy authority for each transfer out of Tunisia.
- Get consent
- Secure the data
- Delete data after a periodData may not be kept beyond the period needed for the purpose; wording not verified on a government site.
What it costs if you get it wrong
- Criminal liability: 1 year imprisonment and TND 5,000 — about $2 thousandTransferring personal data abroad without the authority's authorisation (reported by a professional source; statute text not opened on a government site)
Sources
- Official sourceAgence Nationale de la CybersecuritePolitique de traitement des donnees a caractere personnel
ancs.tn
“Dans le strict respect des dispositions de la loi organique relative a la protection des donnees a caractere personnel (n° 63-2004)”
Link checked 18 August 2026
- Official sourceBanque Centrale de TunisieCirculaire de la Banque Centrale de Tunisie n° 2022-09 du 25 octobre 2022 (agrement pour l'activite de renseignement de credit)
bct.gov.tn
“L'hebergement des donnees (avec interdiction d'hebergement dans le cloud) ; L'archivage obligatoire pour une periode de 5 ans.”
Link checked 18 August 2026
- Official sourceBanque Centrale de TunisieCirculaire aux banques n° 2025-06 du 28 fevrier 2025 - regles minimales regissant l'enrolement electronique des clients
bct.gov.tn
“des attestations actualisees du tiers pour le traitement des donnees personnelles et biometriques delivrees par l'Instance Nationale de Protection des Donnees Personnelles”
Link checked 18 August 2026
- Secondary sourceDLA PiperData Protection Laws of the World - Tunisia: transfer
dlapiperdataprotection.com
Link checked 18 August 2026
- Secondary sourceDLA PiperData Protection Laws of the World - Tunisia: law
dlapiperdataprotection.com
Link checked 18 August 2026
Decret-loi n° 2023-17 du 11 mars 2023, relatif a la cybersecurite
Act of parliament · Decret-loi n° 2023-17, JORT n° 26 of 11 March 2023
Tunisia's cybersecurity law. It forces a yearly security audit on a wide list of public and private bodies, including ordinary companies that handle their users' personal data over telecoms networks, and it requires immediate incident reporting. Vital digital infrastructure must be hosted in Tunisia with a Tunisian backup.
Enforced by National Cybersecurity Agency
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Independent audit — 1 yearCompulsory security audit at least once every twelve months, by an auditor certified by the cybersecurity agency.
- Keep records of processingA protected electronic copy of the audit report must reach the agency within ten days of the audit ending, and every recommendation in it must be implemented.
- Report cyber incidentsImmediate notification of incidents and attacks to the national cyber emergency contact point or an emergency response centre, and compliance with the urgent measures they set.
- Hold a security certificateOrganisations are ranked into three digital trust levels; being left unclassified exposes them to fines.
- Keep the data in the countryVital digital infrastructure operators must have their own main hosting centre and a backup at a labelled Tunisian cloud provider.
What it costs if you get it wrong
- Fixed maximum fine: TND 50,000 to TND 100,000 — about $32 thousandUnclassified organisations that skip the compulsory audit, ignore audit recommendations, ignore urgent incident measures, miss the 30-day fix window, or have no cyber emergency response centre
- Order to stop: Temporary isolation of information systems and networksFailure to remove failings within 30 days after an incident or attack, by ministerial decision on a reasoned report of the agency
Sources
- Official sourceAgence Nationale de la CybersecuriteDecret-loi n° 2023-17 du 11 mars 2023, relatif a la cybersecurite (official gazette text, JORT n° 26)
ancs.tn
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteAudit reglementaire - cadre juridique et reglementaire de la mission d'audit
ancs.tn
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteProcedure de declarations des incidents cybernetiques
ancs.tn
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The full text of the 2004 privacy law, including its exact transfer, retention and penalty wording
The privacy authority's website did not resolve on 18 August 2026 and the national legal database at legislation.tn returned a service unavailable error on every attempt. The official gazette site is a session-based application that could not be queried. Article-level detail therefore rests on a professional source, and confidence is reduced accordingly.
The 2018 decision of the privacy authority listing countries considered to offer sufficient protection, and whether it is still in force
Reported by a professional source. We could not open the decision on any Tunisian government site, so we cannot confirm which countries are on it or whether it has been revised.
Whether the privacy authority currently has appointed members and is issuing new authorisations in 2026
The last verifiable activity is indirect: a central bank rule of February 2025 that assumes it issues certificates. We found no 2026 decision, annual report or appointment notice on a government site.
Whether a modernised, Europe-style privacy law has been adopted since the 2018 draft
No trace of adoption was found on parliament's own site. It is treated as a bill with no legal effect.
The text of central bank circular 2006-01 of 28 March 2006 on outsourcing, and whether it restricts outsourcing outside Tunisia
Its existence is confirmed because later central bank circulars cite it, but the document itself is not published under a reachable address on the central bank site.
Whether sector rules on storage location exist for insurance, securities, health, education, gambling or mapping
No such rule was found on the insurance, securities or telecoms regulators' own sites, and the health ministry site was unreachable. This is an absence of evidence, not proof of absence.
General company and tax record-keeping periods
Widely reported as ten years, but we could not verify them on a Tunisian government site during this research.
Whether the decree naming vital digital infrastructure operators and the ministerial order on digital trust classification have been issued
Both are required by the 2023 cybersecurity law but neither was found published on the cybersecurity agency's site.
The retention and cooperation duties said to sit in the 2022 cybercrime decree-law
We could not obtain the official text of that instrument from a reachable Tunisian government source, so it is not stated as a rule in this record.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
Tunisia versus
Compare