Skip to the content
Global Data RulesData governance rules, country by country

Tunisia

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.

The answer

Depends on your industryWork: HighEnforcement: Waking up

Tunisia has had a privacy law since 2004. Under it, personal data may only leave the country if the national privacy authority signs off first, case by case. Some industries are far stricter. Government systems must sit on Tunisian soil, and firms licensed to run credit reporting are banned from using cloud hosting at all.

Data governance in Tunisia

The eight things that decide how you handle data about people in Tunisia. Same eight on every country page, so you can compare.

Who has to follow these rules

The 2004 privacy law is written for data handling that happens in Tunisia. We found no wording that reaches a foreign company with no office, staff or equipment in the country, so a purely offshore service is probably outside it. Checked 18 August 2026, medium confidence. The cybersecurity rules are the ones that bite locally: any company that handles its users' personal data over telecoms networks, plus telecoms and internet providers, hosting and cloud firms, and companies whose networks are linked over telecoms networks, must have their systems audited in Tunisia. There is no size or revenue threshold anywhere.

Medium confidenceNational rulesIndustry rules

Where the data is allowed to live

In general, only with permission. Personal data may leave Tunisia only if the national privacy authority has authorised that specific transfer, and it may not go to a country that does not protect data properly. Then there are harder walls. Government electronic systems must be hosted in Tunisia. Operators of vital digital infrastructure must hold a main data centre in Tunisia and a backup with an approved Tunisian cloud provider. Licensed credit reporting firms may not put their data in the cloud at all.

Medium confidenceDepends on your industryApproval each time

Sending data out of the country

The model is permission, not paperwork you write yourself. There is no standard contract, no company-wide scheme and no self-certification. You first tell the privacy authority about the processing, then you ask it separately for permission to send the data abroad. Tunisia's central bank treats these permissions as real: since February 2025 a bank using an outside firm for remote customer sign-up must hand the central bank up-to-date privacy authority certificates covering personal and fingerprint or face data.

Medium confidenceApproval each timeGovernment sign-off neededExplicit consent

The regulator, and whether it actually acts

Two very different regulators. The privacy authority still works, but almost invisibly: its own website did not resolve at all on 18 August 2026, it publishes no decisions we could find, and the best proof it is alive comes from other agencies quoting its opinions. The cybersecurity agency is the opposite. It runs an approval scheme for cloud providers, updated its public list on 23 July 2026, renewed some approvals and refused to renew others, and can fine, downgrade or cut off organisations. The central bank is also active and treats privacy paperwork as a licensing condition.

Medium confidenceWaking up

How long you must keep it — and when to delete it

There is a floor and a ceiling, and the floor is set sector by sector. The operator of the national cheque platform must keep the data exchanged through it for at least ten years. Licensed credit reporting firms and crowdfunding platforms must archive their records for at least five years. Any organisation covered by the cybersecurity rules must send its audit report to the cybersecurity agency within ten days of the audit finishing. In the other direction, the 2004 privacy law limits how long personal data may be kept, but we could not open the wording on a government site.

Medium confidenceKeep data for a minimum periodDelete data after a periodIndependent audit

If something goes wrong

Count three clocks, and note that none of them is the 72 hours people expect from Europe. First, if you are covered by the cybersecurity rules you must tell the national cyber emergency contact point or your emergency response centre immediately, and then follow the urgent measures they order. Second, once the agency warns you about a weakness you have 30 days to fix it, or the communications minister can cut your systems off. Third, banks must tell the central bank without delay about any major incident in remote customer sign-up.

Medium confidenceReport cyber incidentsReport breaches to the regulator

What catches people out

Five things that are not in the summary. One: nobody currently holds the governmental cloud approval, so the rule that government systems must sit with an approved governmental provider cannot be satisfied as written. Two: sending data abroad without permission is a crime, not a fine - one year in prison and 5,000 dinars, about 1,600 United States dollars. Three: the compulsory security audit catches ordinary online businesses, not just banks and telecoms firms. Four: you must carry out every recommendation in that audit report. Five: the privacy authority's own website was dead when we checked, so plan for slow paper processes.

Medium confidenceCriminal liabilityIndependent auditKeep the data in the countryWritten vendor contract

What's changing next

One dated change is already published. From 1 January 2027 anyone applying for or renewing a Tunisian cloud approval must include a business continuity plan and a disaster recovery plan, and must show they have started a recognised continuity certification. Beyond that, watch the powers the government already holds rather than new bills. A decree can name which bodies count as vital digital infrastructure, a ministerial order can change how organisations are ranked for digital trust, and the communications minister can order systems to be cut off.

Medium confidenceProposed

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Arrete du ministre des technologies de la communication du 13 septembre 2023, fixant les procedures et les conditions d'octroi, de renouvellement et de retrait des labels G-Cloud et N-Cloud, revise par l'arrete du 8 avril 2024

Directly binding regulation · Arrete of 13 September 2023, JORT n° 106; revised by the arrete of 8 April 2024; implementing Articles 12 to 14 of Decret-loi n° 2023-17

In forceNo — it stays put

Government electronic systems and services must be hosted with a cloud provider holding a Tunisian national or governmental cloud label, and those labels are only given to Tunisian providers whose main and backup data centres are inside Tunisia. As of 23 July 2026 no provider held the governmental label.

In force since 15 September 2023

Enforced by National Cybersecurity Agency

Transfer model: Not allowed

High confidence
Finance

Circulaire de la Banque Centrale de Tunisie n° 2022-09 du 25 octobre 2022

Regulator directive · Circulaire BCT n° 2022-09, made under Decret-loi n° 2022-2 du 4 janvier 2022 on credit information activity

In forceYes, with paperwork

A firm applying to run credit reporting in Tunisia must describe where its data will be hosted, and cloud hosting is expressly forbidden. Records must be archived for five years. The central bank issued this rule after taking the privacy authority's opinion.

In force since 25 October 2022

Enforced by Central Bank of Tunisia

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence
Banking

Circulaire aux banques n° 2025-06 du 28 fevrier 2025, relative aux regles minimales regissant l'enrolement electronique des clients

Regulator directive · Circulaire BCT n° 2025-06; related archiving duty in Circulaire BCT n° 2025-03 du 31 janvier 2025

In forceYes, with paperwork

Banks doing remote customer sign-up must protect the identity data with strong encryption, test the technology through an approved cyber auditor, and hold privacy authority certificates for fingerprint and face data. Outside providers face contract terms far heavier than a normal supplier agreement.

In force since 28 February 2025

Enforced by Central Bank of Tunisia

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Loi organique n° 2004-63 du 27 juillet 2004, portant sur la protection des donnees a caractere personnel

Act of parliament · Loi organique n° 2004-63 du 27 juillet 2004; procedures in Decret n° 2007-3004 du 27 novembre 2007

In forceYes, with paperwork

Tunisia's general privacy law. Processing must be declared to the national privacy authority, and personal data may only be sent abroad if that authority authorises the specific transfer and the destination protects data properly. Breaking the transfer rule is a crime, not just a fine.

In force since 27 July 2004

Enforced by National Authority for the Protection of Personal Data

Transfer model: Approval each time · Accepted routes: Government sign-off needed, Explicit consent

Medium confidence

Decret-loi n° 2023-17 du 11 mars 2023, relatif a la cybersecurite

Act of parliament · Decret-loi n° 2023-17, JORT n° 26 of 11 March 2023

In forceYes, with paperwork

Tunisia's cybersecurity law. It forces a yearly security audit on a wide list of public and private bodies, including ordinary companies that handle their users' personal data over telecoms networks, and it requires immediate incident reporting. Vital digital infrastructure must be hosted in Tunisia with a Tunisian backup.

In force since 11 September 2023

Enforced by National Cybersecurity Agency

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Who you would hear from

  • Instance Nationale de Protection des Donnees a Caractere Personnel

    General privacy law: declarations, authorisations, transfers abroad

    Functioning but close to invisible. Its own website did not resolve on 18 August 2026 - the name server returned a failure - and we found no public register of its decisions. Proof that it works comes from other regulators: the central bank cites its opinion of 15 August 2022 and its opinion of 31 August 2023, and since February 2025 requires banks to produce its certificates for personal and biometric data.

  • Agence Nationale de la Cybersecurite

    Compulsory security audits, incident response, cloud provider labelling, digital trust classification

    Clearly active. It maintains and versions a public list of labelled cloud providers, last updated 23 July 2026, has renewed some labels and refused to renew others, publishes audit reference documents and runs an incident reporting channel.

  • Banque Centrale de Tunisie

    Banking, payments, credit reporting, crowdfunding: hosting, archiving, outsourcing and onboarding rules

    Active and current. It issued circulars through 2025 and 2026 and treats privacy authority paperwork as a licensing condition.

  • Instance Nationale des Telecommunications

    Telecommunications regulation, operator disputes and decisions

    Site live and publishing decisions and tenders in 2026. No telecoms data storage-location rule was found on its own site.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The full text of the 2004 privacy law, including its exact transfer, retention and penalty wording

    The privacy authority's website did not resolve on 18 August 2026 and the national legal database at legislation.tn returned a service unavailable error on every attempt. The official gazette site is a session-based application that could not be queried. Article-level detail therefore rests on a professional source, and confidence is reduced accordingly.

  • The 2018 decision of the privacy authority listing countries considered to offer sufficient protection, and whether it is still in force

    Reported by a professional source. We could not open the decision on any Tunisian government site, so we cannot confirm which countries are on it or whether it has been revised.

  • Whether the privacy authority currently has appointed members and is issuing new authorisations in 2026

    The last verifiable activity is indirect: a central bank rule of February 2025 that assumes it issues certificates. We found no 2026 decision, annual report or appointment notice on a government site.

  • Whether a modernised, Europe-style privacy law has been adopted since the 2018 draft

    No trace of adoption was found on parliament's own site. It is treated as a bill with no legal effect.

  • The text of central bank circular 2006-01 of 28 March 2006 on outsourcing, and whether it restricts outsourcing outside Tunisia

    Its existence is confirmed because later central bank circulars cite it, but the document itself is not published under a reachable address on the central bank site.

  • Whether sector rules on storage location exist for insurance, securities, health, education, gambling or mapping

    No such rule was found on the insurance, securities or telecoms regulators' own sites, and the health ministry site was unreachable. This is an absence of evidence, not proof of absence.

  • General company and tax record-keeping periods

    Widely reported as ten years, but we could not verify them on a Tunisian government site during this research.

  • Whether the decree naming vital digital infrastructure operators and the ministerial order on digital trust classification have been issued

    Both are required by the 2023 cybersecurity law but neither was found published on the cybersecurity agency's site.

  • The retention and cooperation duties said to sit in the 2022 cybercrime decree-law

    We could not obtain the official text of that instrument from a reachable Tunisian government source, so it is not stated as a rule in this record.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Tunisia versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.