Law / Mauritania

Mauritania

6 of 9 named instruments researched to a stage, across two of the six areas of law we track: 6 in force. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law 5
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law none researched

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law5 instruments, 5 in force

Research summary (138 words)

Mauritania's general data-protection statute is Loi n° 2017-020 du 22 juillet 2017 relative à la protection des données à caractère personnel, which sets a normative and institutional framework for processing personal data and creates the Autorité de Protection des Données à caractère personnel as the sector's supervisory authority, with power to authorise or refuse treatments, order corrective measures, and impose administrative pecuniary sanctions, alongside a separate chapter of criminal offences for unlawful processing.

The law's consent, lawful-basis, and data-subject-access provisions are not read and so are not described here. Mauritania signed the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention) on 26 February 2015, ratified it on 19 April 2023, and deposited its instrument of ratification on 9 May 2023, the fifteenth ratification recorded by the African Union, which brought the Convention into force.

Comprehensive regime

Loi n° 2017-020, protection des données à caractère personnel

Loi n° 2017-020 du 22 juillet 2017 relative à la protection des données à caractère personnel arts. 1, 3-11, 17, 26-49 (principes généraux, formalités préalables et obligations du responsable)Text of Loi n° 2017-020, published in the Journal Officiel de la République Islamique de Mauritanie, hosted by the ILO's NATLEX database

In force since 22 July 2017. Binds public and private bodies.

What this law does

Article premier sets the law's object as establishing a normative and institutional framework for processing personal data, so that any processing of personal data, in whatever form, respects citizens' fundamental freedoms and rights.

Article 3 applies the law to processing by a natural person, the State, local authorities, or a public or private legal person, to any structured file, and to a controller operating in Mauritania or using processing means located there, and article 4 exempts only a person's exclusive personal or domestic processing and transient technical transmission copies.

Article 5 makes a data subject's consent the general basis for lawful processing, with derogations similar to the omnibus consent article, and articles 6 through 9 require collection to be lawful, fair and non fraudulent, limited to determined and legitimate purposes, kept accurate and updated, and carried out under a duty of transparency toward the data subject.

Article 10 requires processing to be confidential and protected under article 47, and article 11 requires a written act binding a sub-processor to the controller's own instructions, extending confidentiality to anyone taking part in that sub-processing. Article 17 admits processing for journalism, research or artistic or literary expression carried out under the professional, legislative or regulatory rules of those activities.

Articles 26 through 31 require the Authority's authorization before interconnecting files held by different public bodies or by private bodies with different purposes, on a request stating the data, purpose, and safeguards involved.

Outside the exemptions article 32 lists, article 33 requires a controller to declare its processing to the Authority, and articles 37 through 45 require the Authority's prior authorization for the categories article 37 lists, including an interconnection of files, a national identification number or other general purpose identifier, or a public interest historical, statistical or scientific treatment.

Article 46 requires processing to stay strictly confidential and carried out only by persons the controller has vetted for technical, legal and personal integrity guarantees, article 47 requires precautions appropriate to the nature of the data, article 48 bars keeping data longer than its purpose needs except for historical, statistical or scientific treatment, and article 49 requires a controller to keep data usable and, where needed, converted for durable storage.

What it requires

Cross border transfer

Loi n° 2017-020, transferts vers un pays tiers

Loi n° 2017-020 du 22 juillet 2017, arts. 20-25 (transferts vers un pays tiers)Text of Loi n° 2017-020, published in the Journal Officiel de la République Islamique de Mauritanie, hosted by the ILO's NATLEX database

In force since 22 July 2017. Binds public and private bodies.

What this law does

Article 20 bars transferring personal data to a country that does not ensure a sufficient level of protection for privacy and fundamental rights and freedoms, and article 21 requires the Authority to publish and keep up to date the list of countries it considers to offer that sufficient level. Article 22 requires the controller to notify the Authority before any transfer to a country not on that list, with the transfer following the conditions and procedural rules the Authority sets.

Article 23 judges the sufficiency of a country's protection by its security measures, and by the processing's purpose, duration, and the nature, origin and destination of the data. Article 24 lets a controller transfer data to a country that does not meet that standard where the transfer is a one off, non massive transfer made with the person's express consent, or is necessary to protect the person's life, the public interest, a legal claim, or a contract.

Article 25 lets the Authority authorize a transfer or set of transfers to an inadequate country on a duly motivated request where the controller offers sufficient guarantees, which may take the form of appropriate contractual clauses.

What it requires

Data subject rights

Loi n° 2017-020, droits de la personne concernée

Loi n° 2017-020 du 22 juillet 2017, arts. 18-19, 50-63 (droits de la personne concernée)Text of Loi n° 2017-020, published in the Journal Officiel de la République Islamique de Mauritanie, hosted by the ILO's NATLEX database

In force since 22 July 2017. Binds public and private bodies.

What this law does

Article 50 requires a controller collecting data directly from the person to tell them, at the latest when collecting it, who is responsible for the processing, its purpose, the categories of data, the recipients, whether a reply is mandatory or optional and the consequences of not replying, their access, rectification and objection rights, the retention period, any transfer abroad, and their right to be removed from the file, subject to exemptions for state security, defence, public security, criminal enforcement, and major economic or financial interests of the State.

Article 51 requires that same information to be given, when data is not collected from the person, at the time it is recorded or, if disclosure is planned, no later than the first disclosure.

Article 52 requires a controller accessing or writing information on a user's terminal equipment to tell the user its purpose and how to object, bars conditioning access to a service on accepting that processing, unless the access only enables the communication or is strictly necessary for a service the user expressly requested.

Articles 53 and 54 give a person a written right to access their data in an accessible and intelligible form, its origin, and a copy on payment of no more than the reproduction cost, and article 55 lets them refer a suspected mismatch between the data disclosed and the data actually processed to the Authority for verification.

Article 56 lets a patient's access right be exercised through a physician they designate, article 57 lets a controller resist manifestly abusive requests while carrying the burden of proving abuse, and article 58 routes access to a state security, defence or public security processing through an Authority member who investigates and decides what can be disclosed.

Article 59 gives a person the right to object, without cost, to processing of their data, to be told before their data is first disclosed to or used by a third party for prospecting, and to object to that disclosure or use free of charge, unless the processing meets a legal obligation, and article 60 gives a right to object to the lifting of professional secrecy concerning them, subject to the legal exceptions, while article 18 separately bars sending a person direct marketing communications by any means before they have expressed prior consent to receive them.

Articles 61 through 63 let a person demand that inaccurate, incomplete, ambiguous, outdated, or unlawfully processed data about them be corrected, completed, updated, blocked, or deleted, require the controller to prove compliance within one month at no cost and to notify any third party the data was disclosed to, and let an heir make the same demand to reflect the person's death.

Article 19 bars a judicial decision assessing a person's conduct from resting on automated processing that evaluates aspects of their personality, and bars any decision producing legal effects from resting solely on automated profiling.

What it requires

Enforcement supervision

Loi n° 2017-020, Autorité de Protection des Données et sanctions

Loi n° 2017-020 du 22 juillet 2017, arts. 64-98 (Autorité de Protection des Données et sanctions)Text of Loi n° 2017-020, published in the Journal Officiel de la République Islamique de Mauritanie, hosted by the ILO's NATLEX database

In force since 22 July 2017. Binds public and private bodies.

What this law does

Article 64 creates the Autorité de Protection des Données à caractère personnel as an independent public legal person with financial and management autonomy, attached to the Prime Minister, charged with ensuring processing complies with the law and checking that information and communication technologies do not threaten public freedoms or privacy.

Articles 65 through 69 fix the Authority's composition and member appointment by decree, its staff, a four year once renewable mandate, incompatibility with government membership or business leadership, and replacement rules, and articles 70 and 71 bind members to an oath and give them full immunity for opinions expressed in office, free from any authority's instructions.

Article 72 requires ministers, public authorities, and public or private company directors alike to take all measures to facilitate the Authority's work and bars them from opposing its action except where the law provides otherwise.

Article 73 lists the Authority's missions, including receiving prior formalities and complaints, notifying the public prosecutor of offences and suing to enforce the law, ordering verifications, sanctioning a controller under articles 77 and following, answering opinion requests, approving codes of conduct, keeping a public register of processing, advising controllers, setting the conditions for and authorizing cross border transfers, proposing legislative improvements, cooperating internationally, publishing its authorizations, and reporting annually to the Prime Minister, Parliament, and the Minister for electronic communications.

Articles 74 through 76 let the Authority's agents and sworn officers inspect premises used for processing, with the territorially competent prosecutor informed beforehand, and demand and copy any document useful to their mission.

Article 77 lets the Authority warn a controller and give formal notice to end a breach within a set period, and article 78 lets it, after a contradictory procedure, provisionally or definitively withdraw an authorization or impose a pecuniary fine under article 80 where the controller does not comply.

Article 79 lets the Authority, in an emergency threatening rights and freedoms, order the interruption of a processing operation, the locking of data, or a temporary or definitive ban on a processing that violates the law, and article 83 lets any Authority sanction or decision be appealed to the Supreme Court.

Article 80 caps a pecuniary sanction at ten million ouguiya for a first breach, rising to fifty million ouguiya, or, for a company, five percent of the last closed financial year's turnover excluding tax, for a repeated breach within five years of a prior final sanction. Article 82 lets the Authority's president order a sanction published at the sanctioned party's own expense.

Articles 84 through 94 set criminal offences and penalties, including for obstructing the Authority's own inspections, processing personal data without completing the law's prior formalities, collecting personal data by fraudulent or unlawful means, and processing a person's data despite their valid objection, notably to commercial prospecting, and articles 96 through 98 extend criminal liability to a legal person and require the public prosecutor to notify the Authority's president of every prosecution.

What it requires

Sensitive categories

Loi n° 2017-020, catégories sensibles de données

Loi n° 2017-020 du 22 juillet 2017, arts. 12-16, 37 (catégories sensibles de données)Text of Loi n° 2017-020, published in the Journal Officiel de la République Islamique de Mauritanie, hosted by the ILO's NATLEX database

In force since 22 July 2017. Binds public and private bodies.

What this law does

Article 12 prohibits collecting or processing data revealing racial, ethnic, linguistic or regional origin, filiation, political opinion, religious or philosophical belief, trade union membership, sexual life, genetic data, or health, and article 13 lifts that prohibition only on the ten grounds it lists, including data the person has made public, their written consent, a vital interest they cannot otherwise consent to, a legal claim, an open judicial or criminal proceeding, a public interest historical, statistical or scientific motive, a contract, a legal obligation, a public mission, or the internal activity of a nonprofit body with a political, philosophical, religious or trade union purpose.

Article 14 restricts processing data on offences, criminal convictions or security measures to courts, public authorities and public service bodies acting within their legal remit, and to legal auxiliaries strictly for the missions the law assigns them.

Article 15 makes processing health data lawful only on one of eight listed grounds, including the person's consent, data they have made public, protecting vital interests, a legal purpose, public health promotion such as screening, preventing a certain danger or a specific offence, a legal claim, or preventive medicine and care.

Article 16 requires health data to be collected from the person themselves unless collecting it elsewhere is necessary for the processing or the person cannot supply it themselves. Article 37 also requires the Authority's prior authorization before processing genetic data or health related research data, data on offences, convictions or security measures, or biometric data, so these categories carry a registration burden on top of article 12's prohibition and article 14's restriction.

What it requires

Scraping law1 instrument, 1 in force

Research summary (339 words)

Mauritania has no scraping-specific statute, so general law governs each dimension separately.

Loi n° 2016-007 relative à la cybercriminalité criminalises accessing or attempting to access all or part of a computer system, intentionally and without right (art. 6), and remaining connected to it after such access (art. 7), without requiring that the actor defeat a technical security measure to gain access; no reported Mauritanian decision has tested whether reading a public, unauthenticated page falls inside or outside that 'without right' standard, so open-web crawling of a public page is unsettled rather than settled either way, while accessing a page behind a login without authorisation, or after defeating a technical control, fits the offence squarely.

No Mauritanian statute or reported case addresses the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

A text titled Loi relative à la propriété littéraire et artistique, dated 2012 and attributed to the Ministry of Culture, Youth and Sports, is hosted by the African Intellectual Property Organization (OAPI), of which Mauritania is a member; it would permit short quotations and excerpts with attribution and treats a database as protectable only where its selection or arrangement is an original creation, giving no sui generis database right, but its enactment date, official citation, and Journal Officiel reference could not be confirmed from the located text or by search, so it is not catalogued as an instrument here.

Mauritania has not enacted a text-and-data-mining exception. The Data Protection Authority created by Loi n° 2017-020 relative à la protection des données à caractère personnel (documented under the privacy topic) reaches personal data generally, but whether the law carves out publicly accessible personal data could not be confirmed from the located, partly illegible text.

No Mauritanian statute or reported case establishes a scraping-specific unfair-competition or misappropriation doctrine, though the cybercrime law separately criminalises copying computer data to another's prejudice (art. 28) and receiving personal, confidential, or professionally secret data obtained by fraudulent means (art. 29); neither assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Loi n° 2016-007, accès non autorisé à un système informatique

Loi n° 2016-007 du 20 janvier 2016 relative à la cybercriminalité, arts. 6-7 (accès non autorisé)Official French text of Loi n° 2016-007

In force since 20 January 2016. Binds public and private bodies.

What this law does

Article 6 punishes anyone who accesses or attempts to access, intentionally and without right, all or part of a computer system, with one to three years' imprisonment and a fine of 100,000 to 2,000,000 ouguiya, or either penalty alone. Article 7 punishes remaining, or attempting to remain, connected to all or part of a computer system in the same conditions with a heavier penalty of two to four years' imprisonment and a fine of 200,000 to 3,000,000 ouguiya, or either penalty alone.

Neither article states that the offence requires defeating a technical security measure to gain access, unlike some comparable statutes elsewhere; the standard is only that the access be intentional and without right, so a plain reading leaves open whether reading a public, unauthenticated page without any technical control to defeat counts as access without right, and no reported Mauritanian decision has construed the phrase.

Article 2 confines the statute to offences linked to the use of information and communication technologies and excludes sound and television broadcasting services from its scope. Article 52 ties the law's execution to publication in the Official Gazette, immediately after the President's promulgation dateline of 20 January 2016.

What it requires

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.