Organic Act on the Protection of Personal Data
Loi organique n° 2004-63 du 27 juillet 2004 portant sur la protection des données à caractère personnel, arts. 1-12, 16-26, 44-49, 53-61, 66-74, 104-105 (comprehensive regime)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 30 July 2004.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- File a prior declaration with the National Authority for the Protection of Personal Data (INPDP) before processing personal data, or obtain its prior authorization where the Act requires one.
- Collect and process personal data only for a lawful, determined and explicit purpose, and keep it accurate, precise and up to date.
- Do not make providing a service or granting a benefit conditional on a person accepting that their data be processed or reused for a purpose other than the one it was collected for.
- Take all necessary precautions to secure personal data against unauthorized modification, alteration or consultation, including physical access controls, a log of who accessed the system and when, and secure backup copies.
- Choose a subcontractor with care before delegating any processing to it, hold it to the Act's own obligations, and correct, complete or erase a file once you learn it is inaccurate or insufficient, notifying the person and any recipient within two months.
- Preserve the confidentiality of personal data and the information you process, even after the processing ends or you leave your position, unless the person consented in writing to its disclosure or the law provides otherwise.
- Tell the INPDP at least three months before permanently ceasing your processing activity, or within three months of a controller's death, bankruptcy or dissolution, so it can authorize the data's destruction.
- Destroy personal data once its declared or authorized retention period expires, its purpose is achieved, or it is no longer useful to your activity, by a bailiff's report made with an INPDP-appointed expert.
- Do not communicate personal data to a third party without the person's express consent given in a form leaving a written trace, unless a listed public security, defense or criminal prosecution exception applies.
- Obtain the INPDP's prior authorization before using video surveillance, confine it to the listed categories of place, never pair it with audio recording, and post clear, permanent notice that it is in use.
What it reaches
Obligation class
Licensing, Governance, Security, Disclosure, Retention
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article premier declares personal data protection a fundamental, constitutionally guaranteed right, and articles 2 and 3 apply the Act to both automated and non-automated processing by a natural or legal person, exempting only processing for a strictly personal or family purpose not passed to a third party.
Article 7 requires a prior declaration to the INPDP before any processing, deemed accepted if the INPDP does not object within one month, and article 8 sets what an authorization request must contain wherever the Act requires one. Articles 9 to 12 require processing to respect human dignity and privacy, never to be used to harm a person's reputation, and to serve only the lawful, determined and explicit purpose it was collected for, kept accurate and current.
Article 17 bars conditioning a service or a benefit on accepting processing or reuse of personal data for another purpose, and articles 18 and 19 require the controller to take all necessary precautions against unauthorized access, modification or consultation, naming physical access controls, a log of who accessed the system and when, and secure backup copies.
Article 20 requires a controller delegating processing to choose its subcontractor with care and makes both civilly liable for a breach of the Act, and article 21 requires either to correct, complete or erase a file once its inaccuracy or insufficiency comes to light, notifying the person and any recipient within two months.
Article 22 confines the role of controller, subcontractor and their staff to Tunisian nationals resident in Tunisia with no criminal record, and article 23 binds them to confidentiality even after the processing ends.
Articles 24 to 26 require notice to the INPDP three months before ceasing a processing activity, or within three months of a controller's death, bankruptcy or dissolution, so the INPDP can authorize destruction or, in limited cases, communication of the data for historical or scientific use.
Articles 44 to 46 confine collection from third parties to cases where the person consents or a statutory exception applies, and require destruction once the declared retention period or purpose lapses, by a bailiff's report made with an INPDP-appointed expert.
Articles 47 to 49 bar communicating personal data to a third party without the person's express written consent, subject to public security, defense and criminal prosecution exceptions and to an INPDP-authorized override for vital interests, historical or scientific research, or contract performance.
Articles 53 to 61 exempt public authorities, local government and administrative public establishments acting for public security, defense, criminal prosecution or their statutory missions from the declaration, authorization, consent and several other duties above, while still requiring them to correct an inaccurate file and, for public bodies outside that narrower category, to answer a correction request.
Articles 66 to 68 confine data collected for scientific research to that purpose and bar disclosing an identified result unless the person consents or the disclosure concerns a phenomenon current at the time of presentation.
Articles 69 to 74 require the INPDP's prior authorization for video surveillance, confine its use to public places and their entrances, transport and parking facilities, and collective workplaces, bar pairing it with audio recording, and require clear, permanent public notice that it is in use. Articles 104 and 105 repeal the conflicting provisions of the 2000 electronic commerce law and gave existing processors one year from the Act's entry into force to comply.
The Act states no duty to notify the INPDP or an affected person of a personal data breach. An organic bill to replace the whole Act, filed by 17 members of the Assembly of the Representatives of the People in July-August 2025, remains pending and has not been adopted.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
Full French text of Loi organique n° 2004-63
hosted by the Agence Tunisienne de Certification Électronique (ATCT), a Tunisian public establishment the reproduced text carries the branding of the legislation-securite.tn consolidated-law database it was drawn from
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.