Comprehensive regime
Loi n° 2017-020, protection des données à caractère personnel
Loi n° 2017-020 du 22 juillet 2017 relative à la protection des données à caractère personnel arts. 1, 3-11, 17, 26-49 (principes généraux, formalités préalables et obligations du responsable)Text of Loi n° 2017-020, published in the Journal Officiel de la République Islamique de Mauritanie, hosted by the ILO's NATLEX database
In force since 22 July 2017. Binds public and private bodies.
What this law does
Article premier sets the law's object as establishing a normative and institutional framework for processing personal data, so that any processing of personal data, in whatever form, respects citizens' fundamental freedoms and rights.
Article 3 applies the law to processing by a natural person, the State, local authorities, or a public or private legal person, to any structured file, and to a controller operating in Mauritania or using processing means located there, and article 4 exempts only a person's exclusive personal or domestic processing and transient technical transmission copies.
Article 5 makes a data subject's consent the general basis for lawful processing, with derogations similar to the omnibus consent article, and articles 6 through 9 require collection to be lawful, fair and non fraudulent, limited to determined and legitimate purposes, kept accurate and updated, and carried out under a duty of transparency toward the data subject.
Article 10 requires processing to be confidential and protected under article 47, and article 11 requires a written act binding a sub-processor to the controller's own instructions, extending confidentiality to anyone taking part in that sub-processing. Article 17 admits processing for journalism, research or artistic or literary expression carried out under the professional, legislative or regulatory rules of those activities.
Articles 26 through 31 require the Authority's authorization before interconnecting files held by different public bodies or by private bodies with different purposes, on a request stating the data, purpose, and safeguards involved.
Outside the exemptions article 32 lists, article 33 requires a controller to declare its processing to the Authority, and articles 37 through 45 require the Authority's prior authorization for the categories article 37 lists, including an interconnection of files, a national identification number or other general purpose identifier, or a public interest historical, statistical or scientific treatment.
Article 46 requires processing to stay strictly confidential and carried out only by persons the controller has vetted for technical, legal and personal integrity guarantees, article 47 requires precautions appropriate to the nature of the data, article 48 bars keeping data longer than its purpose needs except for historical, statistical or scientific treatment, and article 49 requires a controller to keep data usable and, where needed, converted for durable storage.
What it requires