Tunisia
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Tunisia — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Tunisia has had a privacy law since 2004. Under it, personal data may only leave the country if the national privacy authority signs off first, case by case. Some industries are far stricter. Government systems must be hosted inside Tunisia. And firms licensed to run credit reporting are banned from using cloud hosting at all.
Data governance in Tunisia
The eight things that decide how you handle data about people in Tunisia. Same eight on every country page, so you can compare.
Who has to follow these rules
The 2004 privacy law is written for data handling that happens in Tunisia. We found no wording that reaches a foreign company with no office, staff or equipment in the country. So a purely offshore service is probably outside it. Checked 18 August 2026, medium confidence. The cybersecurity rules are the ones that reach you locally. Any company that handles its users' personal data over telecoms networks must have its systems audited in Tunisia. So must telecoms and internet providers, hosting and cloud firms, and companies whose networks are linked over telecoms networks. There is no size or revenue threshold anywhere.
The cybersecurity decree-law of 11 March 2023 lists, in its Article 6, the bodies that must be audited regularly. Public bodies. Public telecoms network operators, and telecoms and internet service providers. Companies whose computer networks are linked through telecoms networks. Hosting and cloud service providers. Companies that automatically handle their users' personal data when delivering services over telecoms networks. And vital digital infrastructure. That list captures most online businesses with a Tunisian operation. We found no general duty under the privacy law to appoint a local representative. You do need a Tunisian company to become an approved cloud host, because both cloud labels are reserved to Tunisian hosting providers.
Sources
- Official sourceAgence Nationale de la CybersecuriteDecret-loi n° 2023-17 du 11 mars 2023, relatif a la cybersecurite (official gazette text, JORT n° 26)
ancs.tn
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteAudit reglementaire - cadre juridique et reglementaire de la mission d'audit
ancs.tn
Link checked 18 August 2026
- Secondary sourceDLA PiperData Protection Laws of the World - Tunisia: law
dlapiperdataprotection.com
Link checked 18 August 2026
Where the data is allowed to live
In general, only with permission. Personal data may leave Tunisia only if the national privacy authority has approved that specific transfer. It may not go to a country that does not protect data properly. Then there are stricter rules. Government electronic systems must be hosted in Tunisia. Operators of vital digital infrastructure must hold a main data centre in Tunisia and a backup with an approved Tunisian cloud provider. Licensed credit reporting firms may not put their data in the cloud at all.
Industry by industry, as verified on 18 August 2026. GOVERNMENT: closed. The 2023 cybersecurity decree-law makes the bodies it covers host government electronic systems and services with an approved provider. That provider must hold a national or governmental cloud label. The ministerial order that sets the label conditions requires the provider to be Tunisian. It also requires the main and backup data centres to be on Tunisian territory. VITAL DIGITAL INFRASTRUCTURE: closed. Those operators must run their own main hosting centre plus a backup at a labelled provider. CREDIT REPORTING: no cloud allowed. Records must be archived for five years. BANKING AND PAYMENTS: we found no rule about where data must be stored. But outsourcing is regulated, and remote customer sign-up carries heavy conditions. TELECOMS, INSURANCE, SECURITIES, HEALTH, EDUCATION, GAMBLING, MAPPING: we found no storage-location rule on the regulators' own sites, checked 18 August 2026. Confidence is medium. Several Tunisian official sites were unreachable, including the privacy authority's own site and the national legal database.
Sources
- Official sourceMinistere des technologies de la communication / ANCSArrete du ministre des technologies de la communication du 13 septembre 2023 fixant les conditions d'octroi des labels G-Cloud et N-Cloud (JORT n° 106)
ancs.tn
“Doit fournir et utiliser des centres de donnees primaires et de secours situes sur le territoire tunisien”
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteDecret-loi n° 2023-17 du 11 mars 2023, relatif a la cybersecurite (official gazette text, JORT n° 26)
ancs.tn
Link checked 18 August 2026
- Official sourceBanque Centrale de TunisieCirculaire de la Banque Centrale de Tunisie n° 2022-09 du 25 octobre 2022 (agrement pour l'activite de renseignement de credit)
bct.gov.tn
“L'hebergement des donnees (avec interdiction d'hebergement dans le cloud) ; L'archivage obligatoire pour une periode de 5 ans.”
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteLabelisation - labels N-Cloud et G-Cloud
ancs.tn
Link checked 18 August 2026
- Secondary sourceDLA PiperData Protection Laws of the World - Tunisia: transfer
dlapiperdataprotection.com
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Not fully verified — see “What we're not sure about” below.Sending data out of the country
The model is permission, not paperwork you write yourself. There is no standard contract, no company-wide scheme and no self-certification. First you tell the privacy authority how you use the data. Then you ask it separately for permission to send that data abroad. Tunisia's central bank treats these permissions as real. Since February 2025 a bank using an outside firm for remote customer sign-up must hand the central bank up-to-date privacy authority certificates. Those must cover personal data and fingerprint or face data.
- Ways to send data out:
- Government sign-off needed · Explicit consent
The declaration and permission procedure sits in a government decree of 27 November 2007. The central bank cites that decree in its own rules. Professional sources report three things. The authority has one month to decide. Transfers to countries that do not protect data are forbidden. And a 2018 decision of the authority lists countries considered to offer sufficient protection. We could not open that decision on a Tunisian government site, so treat the list as reported rather than verified. The person concerned must also consent to a transfer. Transfers involving children are reported to need a family judge. Tunisia joined the Council of Europe's data protection convention in 2017. That is often cited as support for transfers. But it is a treaty duty, and it does not replace the permission you need.
Sources
- Official sourceBanque Centrale de TunisieCirculaire de la Banque Centrale de Tunisie n° 2022-09 du 25 octobre 2022 (agrement pour l'activite de renseignement de credit)
bct.gov.tn
“L'hebergement des donnees (avec interdiction d'hebergement dans le cloud) ; L'archivage obligatoire pour une periode de 5 ans.”
Link checked 18 August 2026
- Official sourceBanque Centrale de TunisieCirculaire aux banques n° 2025-06 du 28 fevrier 2025 - regles minimales regissant l'enrolement electronique des clients
bct.gov.tn
“des attestations actualisees du tiers pour le traitement des donnees personnelles et biometriques delivrees par l'Instance Nationale de Protection des Donnees Personnelles”
Link checked 18 August 2026
- Secondary sourceDLA PiperData Protection Laws of the World - Tunisia: transfer
dlapiperdataprotection.com
Link checked 18 August 2026
What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.
Not fully verified — see “What we're not sure about” below.The regulator, and whether it actually acts
Two very different regulators. The privacy authority still works, but almost invisibly. Its own website did not load at all on 18 August 2026. It publishes no decisions we could find. The best proof it is alive comes from other agencies quoting its opinions. The cybersecurity agency is the opposite. It runs an approval scheme for cloud providers and updated its public list on 23 July 2026. It renewed some approvals and refused to renew others. It can fine, downgrade or cut off organisations. The central bank is also active, and treats privacy paperwork as a licensing condition.
Evidence that the privacy authority works. The central bank's credit reporting rules of October 2022 cite its opinion number 22/03-333 of 15 August 2022. The crowdfunding rules of November 2023 cite its opinion of 31 August 2023. And the February 2025 remote sign-up rules make banks produce its certificates for personal and biometric data. Evidence that the cybersecurity agency works. It publishes and versions a list of labelled cloud providers. Entries show labels renewed, applications pending, and two labels not renewed in November 2025. Its fines under the law run from 50,000 to 100,000 Tunisian dinars, roughly 16,000 to 32,000 United States dollars. The communications minister can also order an organisation's systems cut off temporarily, on a reasoned report from the agency. We found no public register of privacy fines or privacy court decisions.
Sources
- Official sourceBanque Centrale de TunisieCirculaire de la Banque Centrale de Tunisie n° 2023-06 du 2 novembre 2023 (crowdfunding en prets)
bct.gov.tn
“Vu l'avis de l'Instance Nationale de Protection des Donnees a caractere Personnel en date du 31 aout 2023”
Link checked 18 August 2026
- Official sourceBanque Centrale de TunisieCirculaire aux banques n° 2025-06 du 28 fevrier 2025 - regles minimales regissant l'enrolement electronique des clients
bct.gov.tn
“des attestations actualisees du tiers pour le traitement des donnees personnelles et biometriques delivrees par l'Instance Nationale de Protection des Donnees Personnelles”
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteListe des fournisseurs Cloud labelises, version 5.2 du 23 juillet 2026
ancs.tn
“Nouvelle Exigence : Il est a noter qu'a partir du 1er Janvier 2027, les dossiers d'octroi ou de renouvellement doivent contenir un Plan de Continuite d'Activites (PCA) et un Plan de reprise d'activites (PRA)”
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteDecret-loi n° 2023-17 du 11 mars 2023, relatif a la cybersecurite (official gazette text, JORT n° 26)
ancs.tn
Link checked 18 August 2026
- Official sourceLink may be brokenINPDPInstance Nationale de Protection des Donnees a Caractere Personnel - official website (name server returned SERVFAIL on 18 August 2026)
inpdp.nat.tn
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a minimum and a maximum, and the minimum is set industry by industry. The operator of the national cheque platform must keep the data exchanged through it for at least ten years. Licensed credit reporting firms and crowdfunding platforms must archive their records for at least five years. Any organisation covered by the cybersecurity rules must send its audit report to the cybersecurity agency within ten days of the audit finishing. Going the other way, the 2004 privacy law limits how long personal data may be kept. We could not open that wording on a government site.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Independent audit
Verified minimums. Ten years for data exchanged through the single electronic cheque platform, under central bank rules of 31 January 2025. Five years of compulsory archiving for credit reporting licence applicants, under central bank rules of 25 October 2022. At least five years for crowdfunding platforms, under central bank rules of 2 November 2023. General company and tax record-keeping periods are widely reported as ten years. We could not verify them on a Tunisian government site, so they are listed as unconfirmed. Where a keep-it rule and a delete-it rule collide, the industry rule is the one a Tunisian regulator will inspect. And the privacy law expressly allows keeping data where another law requires it.
Sources
- Official sourceBanque Centrale de TunisieCirculaire de la Banque Centrale de Tunisie n° 2025-03 du 31 janvier 2025 - Plateforme Electronique Unique des Cheques
bct.gov.tn
“Le gestionnaire doit assurer un archivage securise des donnees echangees via la plateforme et les conserver pendant une duree minimale de dix ans”
Link checked 18 August 2026
- Official sourceBanque Centrale de TunisieCirculaire de la Banque Centrale de Tunisie n° 2022-09 du 25 octobre 2022 (agrement pour l'activite de renseignement de credit)
bct.gov.tn
“L'hebergement des donnees (avec interdiction d'hebergement dans le cloud) ; L'archivage obligatoire pour une periode de 5 ans.”
Link checked 18 August 2026
- Official sourceBanque Centrale de TunisieCirculaire de la Banque Centrale de Tunisie n° 2023-06 du 2 novembre 2023 (crowdfunding en prets)
bct.gov.tn
“Vu l'avis de l'Instance Nationale de Protection des Donnees a caractere Personnel en date du 31 aout 2023”
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteDecret-loi n° 2023-17 du 11 mars 2023, relatif a la cybersecurite (official gazette text, JORT n° 26)
ancs.tn
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
Count three deadlines. None of them is the 72 hours people expect from Europe. First, if the cybersecurity rules cover you, tell the national cyber emergency contact point or your emergency response centre immediately. Then follow the urgent measures they order. Second, once the agency warns you about a weakness, you have 30 days to fix it. If you do not, the communications minister can cut your systems off. Third, banks must tell the central bank without delay about any major incident in remote customer sign-up.
- What you have to do here:
- Report cyber incidents · Report breaches to the regulator
The 2023 cybersecurity decree-law requires immediate notice to the national contact point for cyber emergencies. You may instead tell a public, sector or private emergency response centre. You must then follow the urgent measures those bodies set. The same law gives you a 30-day window to fix failings after a warning. Behind that sits a power to isolate the systems and networks concerned. That is done by ministerial decision on a reasoned report. Covered organisations must also either set up their own cyber emergency response centre or join one. Three things are grounds for both a downgrade and a fine. Failing to obey urgent measures. Failing to fix problems within the deadline. And having no emergency response centre. We found no general duty in the 2004 privacy law to report a personal data breach. That is true both for telling the privacy authority and for telling the people affected. Checked 18 August 2026, medium confidence.
Sources
- Official sourceAgence Nationale de la CybersecuriteDecret-loi n° 2023-17 du 11 mars 2023, relatif a la cybersecurite (official gazette text, JORT n° 26)
ancs.tn
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteProcedure de declarations des incidents cybernetiques
ancs.tn
Link checked 18 August 2026
- Official sourceBanque Centrale de TunisieCirculaire aux banques n° 2025-06 du 28 fevrier 2025 - regles minimales regissant l'enrolement electronique des clients
bct.gov.tn
“des attestations actualisees du tiers pour le traitement des donnees personnelles et biometriques delivrees par l'Instance Nationale de Protection des Donnees Personnelles”
Link checked 18 August 2026
What to do: Your breach process has to reach Tunisia's regulator inside the deadline above.
Not fully verified — see “What we're not sure about” below.What catches people out
Five things are not in the summary. One: nobody currently holds the governmental cloud approval. So the rule that government systems must sit with an approved governmental provider cannot be met as written. Two: sending data abroad without permission is a crime, not a fine. That is one year in prison and 5,000 dinars, about 1,600 United States dollars. Three: the compulsory security audit catches ordinary online businesses, not just banks and telecoms firms. Four: you must carry out every recommendation in that audit report. Five: the privacy authority's own website was dead when we checked, so plan for slow paper processes.
- What you have to do here:
- Independent audit · Written vendor contract
- What it costs if you get it wrong:
- Criminal liability
On the first trap. The cybersecurity agency's list of labelled providers, version 5.2 of 23 July 2026, contains only national cloud labels. There is no governmental cloud label on it, and several national labels were pending renewal. On the third trap. The audit duty covers any company that automatically handles its users' personal data while delivering services over telecoms networks. The audit must happen at least once every twelve months. Only auditors certified by the agency may do it. On the fourth trap. The report goes to the agency within ten days, and all its security recommendations must be carried out. Doing only part of them within a year is itself a ground for a fine. That fine is 50,000 to 100,000 dinars for unclassified organisations. Two more to watch. Credit reporting firms are flatly banned from cloud hosting. And banks using an outside firm for remote sign-up must impose contract terms well beyond a normal supplier agreement. Those include a ban on that firm subcontracting, and a right for the central bank to inspect the firm's own premises.
Sources
- Official sourceAgence Nationale de la CybersecuriteListe des fournisseurs Cloud labelises, version 5.2 du 23 juillet 2026
ancs.tn
“Nouvelle Exigence : Il est a noter qu'a partir du 1er Janvier 2027, les dossiers d'octroi ou de renouvellement doivent contenir un Plan de Continuite d'Activites (PCA) et un Plan de reprise d'activites (PRA)”
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteDecret-loi n° 2023-17 du 11 mars 2023, relatif a la cybersecurite (official gazette text, JORT n° 26)
ancs.tn
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteAudit reglementaire - cadre juridique et reglementaire de la mission d'audit
ancs.tn
Link checked 18 August 2026
- Official sourceBanque Centrale de TunisieCirculaire de la Banque Centrale de Tunisie n° 2022-09 du 25 octobre 2022 (agrement pour l'activite de renseignement de credit)
bct.gov.tn
“L'hebergement des donnees (avec interdiction d'hebergement dans le cloud) ; L'archivage obligatoire pour une periode de 5 ans.”
Link checked 18 August 2026
- Official sourceBanque Centrale de TunisieCirculaire aux banques n° 2025-06 du 28 fevrier 2025 - regles minimales regissant l'enrolement electronique des clients
bct.gov.tn
“des attestations actualisees du tiers pour le traitement des donnees personnelles et biometriques delivrees par l'Instance Nationale de Protection des Donnees Personnelles”
Link checked 18 August 2026
- Secondary sourceDLA PiperData Protection Laws of the World - Tunisia: transfer
dlapiperdataprotection.com
Link checked 18 August 2026
What's changing next
One dated change is already published. From 1 January 2027 anyone applying for or renewing a Tunisian cloud approval must include two plans. A business continuity plan and a disaster recovery plan. They must also show they have started a recognised continuity certification. Beyond that, watch the powers the government already holds rather than new bills. A decree can name which bodies count as vital digital infrastructure. A ministerial order can change how organisations are ranked for digital trust. And the communications minister can order systems cut off.
The 1 January 2027 requirement appears in version 4.3 of the cybersecurity agency's labelled provider list, dated 8 July 2026. It is carried into the current version 5.2 of 23 July 2026. Powers already held, roughly in order of how fast they could change things. First, the decree fixing the list of vital digital infrastructure operators. That pulls named organisations into the Tunisian hosting and backup duty. Second, the ministerial order setting the classification procedure. Being left unclassified is what exposes an organisation to the 50,000 to 100,000 dinar fines. Third, the ministerial order on technical audit criteria. Fourth, the privacy authority's power to change which countries it treats as offering sufficient protection. A modernised, Europe-style privacy bill has been reported as pending since 2018. We found no evidence it has been adopted. Do not treat it as binding.
Sources
- Official sourceAgence Nationale de la CybersecuriteListe des fournisseurs Cloud labelises, version 5.2 du 23 juillet 2026
ancs.tn
“Nouvelle Exigence : Il est a noter qu'a partir du 1er Janvier 2027, les dossiers d'octroi ou de renouvellement doivent contenir un Plan de Continuite d'Activites (PCA) et un Plan de reprise d'activites (PRA)”
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteDecret-loi n° 2023-17 du 11 mars 2023, relatif a la cybersecurite (official gazette text, JORT n° 26)
ancs.tn
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteLabelisation - labels N-Cloud et G-Cloud
ancs.tn
Link checked 18 August 2026
What to do: Diarise 1 January 2027 — that is the date this changes.
Not fully verified — see “What we're not sure about” below.The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Government data must stay in the country
Official name: Arrete du ministre des technologies de la communication du 13 septembre 2023, fixant les procedures et les conditions d'octroi, de renouvellement et de retrait des labels G-Cloud et N-Cloud, revise par l'arrete du 8 avril 2024 · Arrete of 13 September 2023, JORT n° 106; revised by the arrete of 8 April 2024; implementing Articles 12 to 14 of Decret-loi n° 2023-17 · Directly binding regulation
Government electronic systems and services must be hosted with a cloud provider holding a Tunisian national or governmental cloud label. Those labels only go to Tunisian providers whose main and backup data centres are inside Tunisia. As of 23 July 2026 no provider held the governmental label.
Enforced by National Cybersecurity Agency
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryApproved providers must be Tunisian. Their main and backup data centres must be on Tunisian territory. Governmental cloud providers must also connect to the national administration network and the national interoperability platform.
- Prove the data stays under local controlLabels are granted after the opinion of the ministers of national defence and of the interior.
- Hold a security certificate — 1 yearLabels are renewed every year and can be withdrawn early if a technical condition stops being met.
What it costs if you get it wrong
- Loss of your licence: Withdrawal of the cloud labelFailure to keep to the technical conditions of the label
Sources
- Official sourceMinistere des technologies de la communication / ANCSArrete du ministre des technologies de la communication du 13 septembre 2023 fixant les conditions d'octroi des labels G-Cloud et N-Cloud (JORT n° 106)
ancs.tn
“Doit fournir et utiliser des centres de donnees primaires et de secours situes sur le territoire tunisien”
Link checked 18 August 2026
- Official sourceMinistere des technologies de la communication / ANCSArrete du ministre des technologies de la communication du 8 avril 2024 revisant les conditions des labels G-Cloud et N-Cloud
ancs.tn
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteLabelisation - labels N-Cloud et G-Cloud
ancs.tn
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteListe des fournisseurs Cloud labelises, version 5.2 du 23 juillet 2026
ancs.tn
“Nouvelle Exigence : Il est a noter qu'a partir du 1er Janvier 2027, les dossiers d'octroi ou de renouvellement doivent contenir un Plan de Continuite d'Activites (PCA) et un Plan de reprise d'activites (PRA)”
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteDecret-loi n° 2023-17 du 11 mars 2023, relatif a la cybersecurite (official gazette text, JORT n° 26)
ancs.tn
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Circulaire de la Banque Centrale de Tunisie n° 2022-09 du 25 octobre 2022 · Circulaire BCT n° 2022-09, made under Decret-loi n° 2022-2 du 4 janvier 2022 on credit information activity · Regulator directive
A firm applying to run credit reporting in Tunisia must describe where its data will be hosted, and cloud hosting is expressly forbidden. Records must be archived for five years. The central bank issued this rule after taking the privacy authority's opinion.
Enforced by Central Bank of Tunisia
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryCloud hosting of the data is prohibited outright for licence applicants.
- Keep data for a minimum period — 5 yearsCompulsory archiving for five years.
- Secure the dataThe licence file must describe data and system access tools, network security, audit trails, backup and hosting arrangements.
Sources
- Official sourceBanque Centrale de TunisieCirculaire de la Banque Centrale de Tunisie n° 2022-09 du 25 octobre 2022 (agrement pour l'activite de renseignement de credit)
bct.gov.tn
“L'hebergement des donnees (avec interdiction d'hebergement dans le cloud) ; L'archivage obligatoire pour une periode de 5 ans.”
Link checked 18 August 2026
Banking rules
Official name: Circulaire aux banques n° 2025-06 du 28 fevrier 2025, relative aux regles minimales regissant l'enrolement electronique des clients · Circulaire BCT n° 2025-06; related archiving duty in Circulaire BCT n° 2025-03 du 31 janvier 2025 · Regulator directive
Banks doing remote customer sign-up must protect the identity data with strong encryption. They must test the technology through an approved cyber auditor. They must also hold privacy authority certificates for fingerprint and face data. Outside providers face contract terms far heavier than a normal supplier agreement.
Enforced by Central Bank of Tunisia
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Written vendor contractContracts with an outside sign-up provider must ban subcontracting and ban disclosure. They must give the bank timely access to all data. They must also let the central bank inspect the provider's own premises.
- Put a transfer safeguard in placeThe bank must give the central bank up-to-date privacy authority certificates. Those cover how the provider handles personal and biometric data.
- Independent audit — 2 yearsThe sign-up process and technology must be audited every two years, and outsourced activity audited yearly.
- Hold a security certificatePenetration testing by an auditor approved by the cybersecurity agency before go-live.
- Report cyber incidentsThe central bank must be told without delay of any major technical or functional incident in electronic customer sign-up.
- Keep data for a minimum period — 10 yearsUnder the January 2025 cheque platform rules, the platform operator must archive exchanged data for at least ten years.
Sources
- Official sourceBanque Centrale de TunisieCirculaire aux banques n° 2025-06 du 28 fevrier 2025 - regles minimales regissant l'enrolement electronique des clients
bct.gov.tn
“des attestations actualisees du tiers pour le traitement des donnees personnelles et biometriques delivrees par l'Instance Nationale de Protection des Donnees Personnelles”
Link checked 18 August 2026
- Official sourceBanque Centrale de TunisieCirculaire de la Banque Centrale de Tunisie n° 2025-03 du 31 janvier 2025 - Plateforme Electronique Unique des Cheques
bct.gov.tn
“Le gestionnaire doit assurer un archivage securise des donnees echangees via la plateforme et les conserver pendant une duree minimale de dix ans”
Link checked 18 August 2026
- Official sourceBanque Centrale de TunisieCirculaire aux etablissements de credit n° 2006-19 du 28 novembre 2006 relative au controle interne (cites the 2006-01 outsourcing circular)
bct.gov.tn
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Rules for sending data abroad
Official name: Loi organique n° 2004-63 du 27 juillet 2004, portant sur la protection des donnees a caractere personnel · Loi organique n° 2004-63 du 27 juillet 2004; procedures in Decret n° 2007-3004 du 27 novembre 2007 · Act of parliament
Tunisia's general privacy law. You must declare to the national privacy authority how you use personal data. Data may only be sent abroad if that authority approves the specific transfer. The destination must also protect data properly. Breaking the transfer rule is a crime, not just a fine.
Enforced by National Authority for the Protection of Personal Data
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Explicit consent
What you have to do
- Register or notifyYou must declare to the privacy authority how you use personal data. Sensitive uses and transfers abroad need separate permission.
- Put a transfer safeguard in placeYou need the privacy authority's permission before each transfer out of Tunisia.
- Get consent
- Secure the data
- Delete data after a periodYou may not keep data longer than you need it for the purpose. We did not verify this wording on a government site.
What it costs if you get it wrong
- Criminal liability: 1 year imprisonment and TND 5,000 — about $2 thousandTransferring personal data abroad without the authority's authorisation (reported by a professional source; statute text not opened on a government site)
Sources
- Official sourceAgence Nationale de la CybersecuritePolitique de traitement des donnees a caractere personnel
ancs.tn
“Dans le strict respect des dispositions de la loi organique relative a la protection des donnees a caractere personnel (n° 63-2004)”
Link checked 18 August 2026
- Official sourceBanque Centrale de TunisieCirculaire de la Banque Centrale de Tunisie n° 2022-09 du 25 octobre 2022 (agrement pour l'activite de renseignement de credit)
bct.gov.tn
“L'hebergement des donnees (avec interdiction d'hebergement dans le cloud) ; L'archivage obligatoire pour une periode de 5 ans.”
Link checked 18 August 2026
- Official sourceBanque Centrale de TunisieCirculaire aux banques n° 2025-06 du 28 fevrier 2025 - regles minimales regissant l'enrolement electronique des clients
bct.gov.tn
“des attestations actualisees du tiers pour le traitement des donnees personnelles et biometriques delivrees par l'Instance Nationale de Protection des Donnees Personnelles”
Link checked 18 August 2026
- Secondary sourceDLA PiperData Protection Laws of the World - Tunisia: transfer
dlapiperdataprotection.com
Link checked 18 August 2026
- Secondary sourceDLA PiperData Protection Laws of the World - Tunisia: law
dlapiperdataprotection.com
Link checked 18 August 2026
Cyber security rules
Official name: Decret-loi n° 2023-17 du 11 mars 2023, relatif a la cybersecurite · Decret-loi n° 2023-17, JORT n° 26 of 11 March 2023 · Act of parliament
Tunisia's cybersecurity law. It forces a yearly security audit on a wide list of public and private bodies. That includes ordinary companies that handle their users' personal data over telecoms networks. It also makes you report incidents immediately. Vital digital infrastructure must be hosted in Tunisia with a Tunisian backup.
Enforced by National Cybersecurity Agency
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Independent audit — 1 yearCompulsory security audit at least once every twelve months, by an auditor certified by the cybersecurity agency.
- Keep records of how you use dataA protected electronic copy of the audit report must reach the agency within ten days of the audit ending. Every recommendation in it must be carried out.
- Report cyber incidentsReport incidents and attacks immediately to the national cyber emergency contact point, or to an emergency response centre. Then follow the urgent measures they set.
- Hold a security certificateOrganisations are ranked into three digital trust levels; being left unclassified exposes them to fines.
- Keep the data in the countryVital digital infrastructure operators must have their own main hosting centre and a backup at a labelled Tunisian cloud provider.
What it costs if you get it wrong
- Fixed maximum fine: TND 50,000 to TND 100,000 — about $32 thousandUnclassified organisations that skip the compulsory audit, ignore audit recommendations, ignore urgent incident measures, miss the 30-day fix window, or have no cyber emergency response centre
- Order to stop: Temporary isolation of information systems and networksFailure to remove failings within 30 days after an incident or attack, by ministerial decision on a reasoned report of the agency
Sources
- Official sourceAgence Nationale de la CybersecuriteDecret-loi n° 2023-17 du 11 mars 2023, relatif a la cybersecurite (official gazette text, JORT n° 26)
ancs.tn
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteAudit reglementaire - cadre juridique et reglementaire de la mission d'audit
ancs.tn
Link checked 18 August 2026
- Official sourceAgence Nationale de la CybersecuriteProcedure de declarations des incidents cybernetiques
ancs.tn
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The full text of the 2004 privacy law, including its exact transfer, retention and penalty wording
We could not confirm the full text of the 2004 privacy law, including its exact wording on transfers, keeping periods and penalties. The privacy authority's website did not load on 18 August 2026. The national legal database at legislation.tn returned a service unavailable error every time. The official gazette site needs a session and could not be searched. So the article-level detail here rests on a professional source. Check the wording before you rely on it.
The 2018 decision of the privacy authority listing countries considered to offer sufficient protection, and whether it is still in force
We could not confirm the 2018 decision listing countries that offer sufficient protection. A professional source reports it exists. We could not open it on any Tunisian government site. So we cannot tell you which countries are on it, or whether it has since been changed. Ask the privacy authority before you plan a transfer.
Whether the privacy authority currently has appointed members and is issuing new authorisations in 2026
We could not confirm that the privacy authority currently has appointed members and is issuing new permissions in 2026. The last activity we can point to is indirect: a central bank rule of February 2025 that assumes it issues certificates. We found no 2026 decision, annual report or appointment notice on a government site. Allow extra time if you need a permission from it.
Whether a modernised, Europe-style privacy law has been adopted since the 2018 draft
We found no sign that a modernised, Europe-style privacy law has been adopted since the 2018 draft. Parliament's own site shows no trace of adoption. We treat it as a bill with no legal effect. Check before you plan around a new law.
The text of central bank circular 2006-01 of 28 March 2006 on outsourcing, and whether it restricts outsourcing outside Tunisia
We could not confirm what central bank circular 2006-01 of 28 March 2006 on outsourcing says, or whether it limits outsourcing outside Tunisia. We know it exists, because later central bank circulars cite it. But the document itself is not published at any address we could reach on the central bank site. If you are a bank, ask the central bank for the text.
Whether sector rules on storage location exist for insurance, securities, health, education, gambling or mapping
We found no storage-location rule for insurance, securities, health, education, gambling or mapping. We checked the insurance, securities and telecoms regulators' own sites, and the health ministry site was unreachable. That is a gap in what we could check, not proof that no rule exists. If you work in one of these industries, check with your regulator.
General company and tax record-keeping periods
We could not confirm the general company and tax record-keeping periods. They are widely reported as ten years. We could not verify that on a Tunisian government site. Check with your accountant or the tax authority before you set a keeping period.
Whether the decree naming vital digital infrastructure operators and the ministerial order on digital trust classification have been issued
We could not confirm whether two documents have been issued. One is the decree naming vital digital infrastructure operators. The other is the ministerial order on digital trust classification. Both are required by the 2023 cybersecurity law. Neither was published on the cybersecurity agency's site. Ask the agency whether your organisation has been named.
The retention and cooperation duties said to sit in the 2022 cybercrime decree-law
We could not confirm the keeping and cooperation duties said to sit in the 2022 cybercrime decree-law. We could not get the official text from any Tunisian government source we could reach. So this record does not state them as rules. Check the text before you rely on their absence.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.