Skip to the content
Global Data RulesData governance rules, country by country

Tunisia

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Tunisia — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Waking up

Tunisia has had a privacy law since 2004. Under it, personal data may only leave the country if the national privacy authority signs off first, case by case. Some industries are far stricter. Government systems must be hosted inside Tunisia. And firms licensed to run credit reporting are banned from using cloud hosting at all.

Data governance in Tunisia

The eight things that decide how you handle data about people in Tunisia. Same eight on every country page, so you can compare.

Who has to follow these rules

The 2004 privacy law is written for data handling that happens in Tunisia. We found no wording that reaches a foreign company with no office, staff or equipment in the country. So a purely offshore service is probably outside it. Checked 18 August 2026, medium confidence. The cybersecurity rules are the ones that reach you locally. Any company that handles its users' personal data over telecoms networks must have its systems audited in Tunisia. So must telecoms and internet providers, hosting and cloud firms, and companies whose networks are linked over telecoms networks. There is no size or revenue threshold anywhere.

Not fully verified — see “What we're not sure about” below.

Where the data is allowed to live

In general, only with permission. Personal data may leave Tunisia only if the national privacy authority has approved that specific transfer. It may not go to a country that does not protect data properly. Then there are stricter rules. Government electronic systems must be hosted in Tunisia. Operators of vital digital infrastructure must hold a main data centre in Tunisia and a backup with an approved Tunisian cloud provider. Licensed credit reporting firms may not put their data in the cloud at all.

What to do: Check your own industry against the restricted list before you pick a hosting region.

Not fully verified — see “What we're not sure about” below.

Sending data out of the country

The model is permission, not paperwork you write yourself. There is no standard contract, no company-wide scheme and no self-certification. First you tell the privacy authority how you use the data. Then you ask it separately for permission to send that data abroad. Tunisia's central bank treats these permissions as real. Since February 2025 a bank using an outside firm for remote customer sign-up must hand the central bank up-to-date privacy authority certificates. Those must cover personal data and fingerprint or face data.

Ways to send data out:
Government sign-off needed · Explicit consent

What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.

Not fully verified — see “What we're not sure about” below.

The regulator, and whether it actually acts

Two very different regulators. The privacy authority still works, but almost invisibly. Its own website did not load at all on 18 August 2026. It publishes no decisions we could find. The best proof it is alive comes from other agencies quoting its opinions. The cybersecurity agency is the opposite. It runs an approval scheme for cloud providers and updated its public list on 23 July 2026. It renewed some approvals and refused to renew others. It can fine, downgrade or cut off organisations. The central bank is also active, and treats privacy paperwork as a licensing condition.

Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

There is a minimum and a maximum, and the minimum is set industry by industry. The operator of the national cheque platform must keep the data exchanged through it for at least ten years. Licensed credit reporting firms and crowdfunding platforms must archive their records for at least five years. Any organisation covered by the cybersecurity rules must send its audit report to the cybersecurity agency within ten days of the audit finishing. Going the other way, the 2004 privacy law limits how long personal data may be kept. We could not open that wording on a government site.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Independent audit

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

Count three deadlines. None of them is the 72 hours people expect from Europe. First, if the cybersecurity rules cover you, tell the national cyber emergency contact point or your emergency response centre immediately. Then follow the urgent measures they order. Second, once the agency warns you about a weakness, you have 30 days to fix it. If you do not, the communications minister can cut your systems off. Third, banks must tell the central bank without delay about any major incident in remote customer sign-up.

What you have to do here:
Report cyber incidents · Report breaches to the regulator

What to do: Your breach process has to reach Tunisia's regulator inside the deadline above.

Not fully verified — see “What we're not sure about” below.

What catches people out

Five things are not in the summary. One: nobody currently holds the governmental cloud approval. So the rule that government systems must sit with an approved governmental provider cannot be met as written. Two: sending data abroad without permission is a crime, not a fine. That is one year in prison and 5,000 dinars, about 1,600 United States dollars. Three: the compulsory security audit catches ordinary online businesses, not just banks and telecoms firms. Four: you must carry out every recommendation in that audit report. Five: the privacy authority's own website was dead when we checked, so plan for slow paper processes.

What you have to do here:
Independent audit · Written vendor contract
What it costs if you get it wrong:
Criminal liability
Not fully verified — see “What we're not sure about” below.

What's changing next

One dated change is already published. From 1 January 2027 anyone applying for or renewing a Tunisian cloud approval must include two plans. A business continuity plan and a disaster recovery plan. They must also show they have started a recognised continuity certification. Beyond that, watch the powers the government already holds rather than new bills. A decree can name which bodies count as vital digital infrastructure. A ministerial order can change how organisations are ranked for digital trust. And the communications minister can order systems cut off.

What to do: Diarise 1 January 2027 — that is the date this changes.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Government data must stay in the country

Official name: Arrete du ministre des technologies de la communication du 13 septembre 2023, fixant les procedures et les conditions d'octroi, de renouvellement et de retrait des labels G-Cloud et N-Cloud, revise par l'arrete du 8 avril 2024 · Arrete of 13 September 2023, JORT n° 106; revised by the arrete of 8 April 2024; implementing Articles 12 to 14 of Decret-loi n° 2023-17 · Directly binding regulation

In forceNo — it stays put

Government electronic systems and services must be hosted with a cloud provider holding a Tunisian national or governmental cloud label. Those labels only go to Tunisian providers whose main and backup data centres are inside Tunisia. As of 23 July 2026 no provider held the governmental label.

In force since 15 September 2023

Enforced by National Cybersecurity Agency

How this country controls where data goes: Not allowed

Finance

Cloud and outsourcing rules

Official name: Circulaire de la Banque Centrale de Tunisie n° 2022-09 du 25 octobre 2022 · Circulaire BCT n° 2022-09, made under Decret-loi n° 2022-2 du 4 janvier 2022 on credit information activity · Regulator directive

In forceYes, with paperwork

A firm applying to run credit reporting in Tunisia must describe where its data will be hosted, and cloud hosting is expressly forbidden. Records must be archived for five years. The central bank issued this rule after taking the privacy authority's opinion.

In force since 25 October 2022

Enforced by Central Bank of Tunisia

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Banking

Banking rules

Official name: Circulaire aux banques n° 2025-06 du 28 fevrier 2025, relative aux regles minimales regissant l'enrolement electronique des clients · Circulaire BCT n° 2025-06; related archiving duty in Circulaire BCT n° 2025-03 du 31 janvier 2025 · Regulator directive

In forceYes, with paperwork

Banks doing remote customer sign-up must protect the identity data with strong encryption. They must test the technology through an approved cyber auditor. They must also hold privacy authority certificates for fingerprint and face data. Outside providers face contract terms far heavier than a normal supplier agreement.

In force since 28 February 2025

Enforced by Central Bank of Tunisia

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Rules for sending data abroad

Official name: Loi organique n° 2004-63 du 27 juillet 2004, portant sur la protection des donnees a caractere personnel · Loi organique n° 2004-63 du 27 juillet 2004; procedures in Decret n° 2007-3004 du 27 novembre 2007 · Act of parliament

In forceYes, with paperwork

Tunisia's general privacy law. You must declare to the national privacy authority how you use personal data. Data may only be sent abroad if that authority approves the specific transfer. The destination must also protect data properly. Breaking the transfer rule is a crime, not just a fine.

In force since 27 July 2004

Enforced by National Authority for the Protection of Personal Data

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Explicit consent

Not fully verified — see “What we're not sure about” below.

Cyber security rules

Official name: Decret-loi n° 2023-17 du 11 mars 2023, relatif a la cybersecurite · Decret-loi n° 2023-17, JORT n° 26 of 11 March 2023 · Act of parliament

In forceYes, with paperwork

Tunisia's cybersecurity law. It forces a yearly security audit on a wide list of public and private bodies. That includes ordinary companies that handle their users' personal data over telecoms networks. It also makes you report incidents immediately. Vital digital infrastructure must be hosted in Tunisia with a Tunisian backup.

In force since 11 September 2023

Enforced by National Cybersecurity Agency

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Who you would hear from

  • Instance Nationale de Protection des Donnees a Caractere Personnel

    General privacy law: declarations, authorisations, transfers abroad

    Working, but close to invisible. Its own website did not load on 18 August 2026. The name server returned a failure. We found no public register of its decisions. The proof that it works comes from other regulators. The central bank cites its opinion of 15 August 2022 and its opinion of 31 August 2023. Since February 2025 the central bank has made banks produce its certificates for personal and biometric data.

  • Agence Nationale de la Cybersecurite

    Compulsory security audits, incident response, cloud provider labelling, digital trust classification

    Clearly active. It maintains and versions a public list of labelled cloud providers, last updated 23 July 2026. It has renewed some labels and refused to renew others. It publishes audit reference documents and runs an incident reporting channel.

  • Banque Centrale de Tunisie

    Banking, payments, credit reporting, crowdfunding: hosting, archiving, outsourcing and onboarding rules

    Active and current. It issued circulars through 2025 and 2026 and treats privacy authority paperwork as a licensing condition.

  • Instance Nationale des Telecommunications

    Telecommunications regulation, operator disputes and decisions

    Site live and publishing decisions and tenders in 2026. No telecoms data storage-location rule was found on its own site.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The full text of the 2004 privacy law, including its exact transfer, retention and penalty wording

    We could not confirm the full text of the 2004 privacy law, including its exact wording on transfers, keeping periods and penalties. The privacy authority's website did not load on 18 August 2026. The national legal database at legislation.tn returned a service unavailable error every time. The official gazette site needs a session and could not be searched. So the article-level detail here rests on a professional source. Check the wording before you rely on it.

  • The 2018 decision of the privacy authority listing countries considered to offer sufficient protection, and whether it is still in force

    We could not confirm the 2018 decision listing countries that offer sufficient protection. A professional source reports it exists. We could not open it on any Tunisian government site. So we cannot tell you which countries are on it, or whether it has since been changed. Ask the privacy authority before you plan a transfer.

  • Whether the privacy authority currently has appointed members and is issuing new authorisations in 2026

    We could not confirm that the privacy authority currently has appointed members and is issuing new permissions in 2026. The last activity we can point to is indirect: a central bank rule of February 2025 that assumes it issues certificates. We found no 2026 decision, annual report or appointment notice on a government site. Allow extra time if you need a permission from it.

  • Whether a modernised, Europe-style privacy law has been adopted since the 2018 draft

    We found no sign that a modernised, Europe-style privacy law has been adopted since the 2018 draft. Parliament's own site shows no trace of adoption. We treat it as a bill with no legal effect. Check before you plan around a new law.

  • The text of central bank circular 2006-01 of 28 March 2006 on outsourcing, and whether it restricts outsourcing outside Tunisia

    We could not confirm what central bank circular 2006-01 of 28 March 2006 on outsourcing says, or whether it limits outsourcing outside Tunisia. We know it exists, because later central bank circulars cite it. But the document itself is not published at any address we could reach on the central bank site. If you are a bank, ask the central bank for the text.

  • Whether sector rules on storage location exist for insurance, securities, health, education, gambling or mapping

    We found no storage-location rule for insurance, securities, health, education, gambling or mapping. We checked the insurance, securities and telecoms regulators' own sites, and the health ministry site was unreachable. That is a gap in what we could check, not proof that no rule exists. If you work in one of these industries, check with your regulator.

  • General company and tax record-keeping periods

    We could not confirm the general company and tax record-keeping periods. They are widely reported as ten years. We could not verify that on a Tunisian government site. Check with your accountant or the tax authority before you set a keeping period.

  • Whether the decree naming vital digital infrastructure operators and the ministerial order on digital trust classification have been issued

    We could not confirm whether two documents have been issued. One is the decree naming vital digital infrastructure operators. The other is the ministerial order on digital trust classification. Both are required by the 2023 cybersecurity law. Neither was published on the cybersecurity agency's site. Ask the agency whether your organisation has been named.

  • The retention and cooperation duties said to sit in the 2022 cybercrime decree-law

    We could not confirm the keeping and cooperation duties said to sit in the 2022 cybercrime decree-law. We could not get the official text from any Tunisian government source we could reach. So this record does not state them as rules. Check the text before you rely on their absence.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.