Law / Tunisia

Tunisia

9 of 11 named instruments researched to a stage, across four of the six areas of law we track: 9 in force. As of 19 September 2026.

When they take effect9 of 9 carry a date. Earlier is before 2014.
Before 2014: 6 instruments (6 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 1 instrument (1 in force) 2023: 2 instruments (2 in force) 2024: 0 instruments 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 5
  3. Scraping law 1
  4. Cybersecurity law 2
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law5 instruments, 5 in force

Research summary (216 words)

Tunisia's comprehensive personal-data regime is Loi organique n° 2004-63 du 27 juillet 2004, portant sur la protection des données à caractère personnel, enforced by the Instance Nationale de Protection des Données à Caractère Personnel (INPDP).

The Act binds any natural or legal person carrying out automated or non-automated processing of personal data, requires a prior declaration to or authorization from the INPDP before processing, express written consent and advance notice before collection, and the INPDP's prior authorization for any transfer of personal data outside Tunisia.

It defines personal data broadly but excludes information tied to a person's public life from that definition, subjects data revealing racial or genetic origin, religious, political, philosophical or trade union views, or health to a heightened, generally consent-based restriction, and requires a child's data to be processed only with a guardian's consent and a family court judge's authorization.

The Act states no duty to notify the INPDP or an affected person of a personal data breach, and it holds no dedicated biometric-identifier statute, treating genetic data as one item within its special-category list rather than a category of its own. An organic bill to replace the 2004 Act, filed by 17 members of the Assembly of the Representatives of the People in July-August 2025, remains pending and has not been adopted.

Comprehensive regime

Organic Act on the Protection of Personal Data

Loi organique n° 2004-63 du 27 juillet 2004 portant sur la protection des données à caractère personnel, arts. 1-12, 16-26, 44-49, 53-61, 66-74, 104-105 (comprehensive regime)Full French text of Loi organique n° 2004-63

In force since 30 July 2004. Binds public and private bodies.

What this law does

Article premier declares personal data protection a fundamental, constitutionally guaranteed right, and articles 2 and 3 apply the Act to both automated and non-automated processing by a natural or legal person, exempting only processing for a strictly personal or family purpose not passed to a third party.

Article 7 requires a prior declaration to the INPDP before any processing, deemed accepted if the INPDP does not object within one month, and article 8 sets what an authorization request must contain wherever the Act requires one. Articles 9 to 12 require processing to respect human dignity and privacy, never to be used to harm a person's reputation, and to serve only the lawful, determined and explicit purpose it was collected for, kept accurate and current.

Article 17 bars conditioning a service or a benefit on accepting processing or reuse of personal data for another purpose, and articles 18 and 19 require the controller to take all necessary precautions against unauthorized access, modification or consultation, naming physical access controls, a log of who accessed the system and when, and secure backup copies.

Article 20 requires a controller delegating processing to choose its subcontractor with care and makes both civilly liable for a breach of the Act, and article 21 requires either to correct, complete or erase a file once its inaccuracy or insufficiency comes to light, notifying the person and any recipient within two months.

Article 22 confines the role of controller, subcontractor and their staff to Tunisian nationals resident in Tunisia with no criminal record, and article 23 binds them to confidentiality even after the processing ends.

Articles 24 to 26 require notice to the INPDP three months before ceasing a processing activity, or within three months of a controller's death, bankruptcy or dissolution, so the INPDP can authorize destruction or, in limited cases, communication of the data for historical or scientific use.

Articles 44 to 46 confine collection from third parties to cases where the person consents or a statutory exception applies, and require destruction once the declared retention period or purpose lapses, by a bailiff's report made with an INPDP-appointed expert.

Articles 47 to 49 bar communicating personal data to a third party without the person's express written consent, subject to public security, defense and criminal prosecution exceptions and to an INPDP-authorized override for vital interests, historical or scientific research, or contract performance.

Articles 53 to 61 exempt public authorities, local government and administrative public establishments acting for public security, defense, criminal prosecution or their statutory missions from the declaration, authorization, consent and several other duties above, while still requiring them to correct an inaccurate file and, for public bodies outside that narrower category, to answer a correction request.

Articles 66 to 68 confine data collected for scientific research to that purpose and bar disclosing an identified result unless the person consents or the disclosure concerns a phenomenon current at the time of presentation.

Articles 69 to 74 require the INPDP's prior authorization for video surveillance, confine its use to public places and their entrances, transport and parking facilities, and collective workplaces, bar pairing it with audio recording, and require clear, permanent public notice that it is in use. Articles 104 and 105 repeal the conflicting provisions of the 2000 electronic commerce law and gave existing processors one year from the Act's entry into force to comply.

The Act states no duty to notify the INPDP or an affected person of a personal data breach. An organic bill to replace the whole Act, filed by 17 members of the Assembly of the Representatives of the People in July-August 2025, remains pending and has not been adopted.

What it requires

Cross border transfer

Organic Act on the Protection of Personal Data, cross-border transfer

Loi organique n° 2004-63, arts. 50-52 (transfert des données à l'étranger)Full French text of Loi organique n° 2004-63

In force since 30 July 2004. Binds public and private bodies.

What this law does

Article 50 bars communicating or transferring personal data to a foreign country in any case capable of harming public security or Tunisia's vital interests, a bar no authorization can cure.

Article 51 permits transferring personal data undergoing or destined for processing only to a country that assures an adequate level of protection, assessed against the nature of the data, the purpose and duration of the processing, the destination country, and the safeguards in place, and requires every transfer to otherwise meet the Act's conditions.

Article 52 makes the INPDP's prior authorization mandatory for every transfer of personal data abroad, requires the INPDP to decide within one month of the request, and routes the request to the family court judge rather than the INPDP where the data to be transferred concern a child.

What it requires

Data subject rights

Organic Act on the Protection of Personal Data, rights of the data subject

Loi organique n° 2004-63, arts. 27, 29-43 (droits de la personne concernée)Full French text of Loi organique n° 2004-63

In force since 30 July 2004. Binds public and private bodies.

What this law does

Article 27 requires the person's express, written consent before processing their personal data, lets that consent be withdrawn at any time, and routes consent for an incapable person through the general rules of law.

Article 29 excuses consent only where processing manifestly serves the person's own interest and contacting them is impossible, obtaining consent would take disproportionate effort, or the processing rests on a law or a contract the person is party to, and article 30 confines a given consent to the form and purpose it was given for, barring use of personal data for advertising without the person's separate, express consent.

Article 31 requires written notice, given at least one month before the data are processed, of the data's nature, the processing's purpose, whether answering is mandatory or optional and the consequences of not answering, the recipient's and controller's identity and address, the person's rights of access, withdrawal and objection, the retention period, a summary of the security measures, and the destination country of any transfer.

Article 32 defines the right of access as the right to consult, correct, complete, rectify, update, clarify or erase data that prove inaccurate, ambiguous or unlawfully processed, and to obtain a copy in clear language and, for automated processing, an intelligible form; article 33 bars waiving that right in advance.

Articles 34 and 36 let the person exercise access at reasonable, non-excessive intervals, against each controller separately where there is more than one, and article 37 requires an automated controller to offer an electronic channel for a rectification, modification, correction or erasure request.

Article 38 gives the person one month to receive a requested copy, one month to bring a refusal or a delay to the INPDP, and the INPDP one month to decide, or seven days where the request is to stop the destruction or concealment of the data; article 39 requires the controller to flag data under dispute until the dispute is resolved.

Article 40 lets the person demand correction, completion, clarification, updating or erasure of data that prove inaccurate, incomplete or ambiguous, or its destruction where it was unlawfully collected or used, and a free copy within one month, escalating a refusal to the INPDP within a further month.

Article 42 gives the person the right to object at any time, for valid, legitimate and serious reasons, to processing of their data, and an unconditional right to object to its communication to third parties for advertising, with the objection suspending the processing immediately; a family court judge, not the INPDP, decides an objection dispute where the person is a child.

What it requires

Enforcement supervision

Organic Act on the Protection of Personal Data, enforcement and sanctions

Loi organique n° 2004-63, arts. 75-103 (l'Instance et les sanctions)Full French text of Loi organique n° 2004-63

In force since 30 July 2004. Binds public and private bodies.

What this law does

Article 75 establishes the Instance Nationale de Protection des Données à Caractère Personnel (INPDP) as a body with legal personality and financial autonomy, seated in Tunis and budgeted through the ministry responsible for human rights.

Article 76 charges the INPDP with granting authorizations, receiving declarations, withdrawing them where the Act allows, receiving complaints, setting the safeguards personal data protection requires, accessing processed data to verify compliance, advising on the Act's application, and issuing codes of conduct.

Article 77 lets the INPDP investigate by taking statements and inspecting the premises where processing took place, other than a private home, with the assistance of sworn communications ministry agents, judicial experts or others it finds useful, and requires it to report offences it learns of to the public prosecutor, with no claim of professional secrecy standing against it.

Articles 78 to 80 set the INPDP's composition and its members' three year appointment by decree, bar any member from holding an interest in a data-processing business, and impose a lifetime confidentiality duty over what they learn in that role.

Article 81 lets the INPDP withdraw an authorization or prohibit processing that has breached the Act, after hearing the controller or subcontractor, and article 82 makes its decisions appealable to the Tunis Court of Appeal within one month, executable despite an appeal unless the court's first president stays them to prevent irreversible harm. Article 85 requires the INPDP to report annually to the President of the Republic.

Chapter VII sets tiered criminal penalties: article 86 punishes a transfer or communication of personal data abroad capable of harming public security or Tunisia's vital interests with two to five years' imprisonment and a fine of five thousand to fifty thousand dinars, and punishes the attempt too.

Article 87 fixes two years and ten thousand dinars for violating the judicial record prohibition, the first paragraph of the special category, minors or health secrecy provisions, or the video surveillance rules, and for violating the basic consent, notice, third-party collection or research disclosure duties.

Articles 88 to 99 fix lower, mostly smaller and shorter penalties for coercing consent, profiting from or maliciously disclosing personal data, processing without declaration or authorization, disclosing health data despite an INPDP ban, transferring or communicating data unlawfully, ignoring an objection, obstructing access, breaching an INPDP-imposed safeguard, obstructing the INPDP's investigations or lying to it, and violating narrower notice or dispute-flagging duties.

Article 100 lets a court additionally withdraw a processing authorization or suspend the processing on top of any other penalty. Article 101 makes the penalties for a legal person's offence fall personally on its legal or de facto director, where that director's responsibility for the acts committed is established. Articles 102 and 103 route these offences through the ordinary criminal procedure code and allow penal mediation for the narrower offences it lists.

What it requires

Sensitive categories

Organic Act on the Protection of Personal Data, sensitive categories and minors

Loi organique n° 2004-63, arts. 13-15, 28, 62-65 (catégories particulières et mineurs)Full French text of Loi organique n° 2004-63

In force since 30 July 2004. Binds public and private bodies.

What this law does

Article 13 prohibits processing personal data about a person's criminal offences, their detection, prosecution, penalties, preventive measures or judicial record, with no exception stated in the Act.

Article 14 prohibits processing data revealing, directly or indirectly, racial or genetic origin, religious, political, philosophical or trade union opinions, or health, unless the person gives express consent in a form leaving a written trace, the data has become manifestly public, or the processing is necessary for historical or scientific purposes or to safeguard the person's vital interests; article 15 requires the INPDP's separate authorization for that processing, other than health data, which the INPDP must grant or refuse within thirty days, with silence counting as refusal.

Article 28 requires a child's personal data to be processed only with the guardian's consent and the family court judge's authorization, lets the judge order the processing even without the guardian's consent where the child's best interest requires it, and lets the judge withdraw that authorization at any time; the Act cross-references this same regime wherever the data subject is a child, including marketing consent, collection from third parties, communication to third parties, transfer abroad, disclosure of research results and video recording consent.

Article 62 permits processing health data beyond article 14's general exception where the person consents (subject to the article 28 regime for a child), the processing serves a purpose the law or regulations set, it serves public health protection or disease research, it benefits or is medically necessary for the person's own health, or it is scientific research in the health field.

Article 63 confines processing of health data to physicians or others bound by professional secrecy, and lets a physician share it with a research body only on the INPDP's authorization, decided within one month. Article 64 caps that processing at the time necessary for its purpose, and article 65 lets the INPDP set the precautions a health data authorization must carry and bar the data's dissemination outright.

What it requires

Scraping law1 instrument, 1 in force

Research summary (237 words)

Tunisia has no scraping-specific statute, so general law governs each dimension separately.

Décret-loi n° 2022-54 du 13 septembre 2022 criminalises knowingly accessing or remaining in a computer system without authorization, or exceeding the limits of a granted access right, but does not by its terms reach reading a public, unauthenticated page that defeats no access control, and no reported case has tested the point; the same decree-loi separately criminalises using an information system to access copyright-protected content without the rightholder's authorization for profit (art. 25), a distinct offence from unauthorized computer access.

No Tunisian court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper. Loi n° 94-36 du 24 février 1994 relative à la propriété littéraire et artistique excludes the news of the day and mere facts from copyright protection and permits quotations and press-review borrowings from a lawfully disclosed work, but Tunisia has not enacted a text-and-data-mining exception, and the Law confers no sui generis database right.

Loi organique n° 2004-63 du 27 juillet 2004 applies to personal data without a general carve-out for publicly accessible information beyond information tied to a person's public life, so scraping personal data from a public Tunisian website remains subject to that Act's consent, notice and cross-border-transfer duties.

No Tunisian statute or reported decision establishes a scraping-specific unfair-competition or misappropriation doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Decree-Law on Cybercrime, unauthorised access

Décret-loi n° 2022-54 du 13 septembre 2022 relatif à la lutte contre les infractions se rapportant aux systèmes d'information et de communication, art. 16Full French and Arabic text of Décret-loi n° 2022-54

In force since 16 September 2022. Binds public and private bodies.

What this law does

Article 16 punishes anyone who knowingly accesses or remains illegally in a computer system, in whole or in part, and imposes the same penalty on anyone who knowingly exceeds the limits of an access right they have been granted; an attempt is also punishable. The offence carries three months to one year of imprisonment and a fine of 10,000 dinars.

Because the offence's trigger is illegal access or exceeding a granted access right, reading a public, unauthenticated page that defeats no access control falls outside a plain reading of the provision. Article 37 repeals the former articles 199 bis and 199 ter of the Penal Code, which the decree-loi's Chapter III offences supersede.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (540 words)

Tunisia's cybersecurity framework is Décret-loi n° 2023-17 du 11 mars 2023, relatif à la cybersécurité, which repealed and replaced Loi n° 2004-5 du 3 février 2004 relative à la sécurité informatique (the earlier statute a WIPO-style lead pointed to; it is now abrogé), and created the Agence Nationale de la Cybersécurité in place of the Agence Nationale de la Sécurité Informatique.

The décret-loi's operative provisions entered into force six months after its 11 March 2023 publication, on 11 September 2023.

Its Article 6 subjects five categories of public and private organization to a mandatory, periodic audit: a public telecommunications network operator or telecommunications and internet service provider, an enterprise whose information networks are interconnected through telecommunications networks, a hosting or cloud-computing service provider, an enterprise that automatically processes its users' personal data while providing its service through telecommunications networks, and a vital digital infrastructure the state designates by decree.

The fourth of those, an enterprise automatically processing its users' personal data over telecommunications networks in the course of providing its service, reaches essentially any online or app-based service and is expressible against this vocabulary's activities, on the same footing as the EU's NIS2, Morocco's Loi 05-20, Serbia's, Ghana's and Côte d'Ivoire's equivalent audited populations; the telecommunications-operator, hosting-provider and vital-infrastructure categories name roles no activity in this vocabulary independently expresses, and are recorded rather than flagged.

Chapter IV creates a 'Sécurisé' label for software and electronic devices, but Article 10 makes requesting it optional, so it is a voluntary certification mark rather than a mandatory product-security requirement, and is not filed as a duty.

Chapter VIII (Arts. 21-22) layers extra security measures, labelled software and equipment, dual hosting, an approved procedures manual, onto organizations managing a 'vital digital infrastructure', but that class is itself a state-designated list fixed by decree under Article 21, a role this vocabulary cannot independently express, so those extra duties are recorded here rather than filed as a separate instrument.

The regional central bank's analogue, Banque Centrale de Tunisie, is understood to hold banking-supervision powers reaching IT risk at a licensed credit establishment, a role this vocabulary cannot express regardless; direct navigation within this visit's search budget did not locate a specific, citable BCT cybersecurity circular, so this is recorded as a deferred, unconfirmed lead rather than an instrument, on the same footing as Côte d'Ivoire's BCEAO lead in this jurisdiction's own regional peer document.

Décret-loi n° 2022-54 du 13 septembre 2022 (the cybercrime statute filed under the scraping topic) carries a telecommunications-provider data-retention duty (art. 6) and confidentiality duties running to judicial-investigation personnel (art. 7), neither of which is an operator-facing security-posture or vulnerability-reporting duty, so nothing there is re-filed here.

Loi organique n° 2004-63 du 27 juillet 2004's own security-of-processing duty, arts. 18 and 19's requirement that a data controller take every precaution necessary to secure personal data against unauthorized modification, alteration or consultation, stays filed under the privacy topic rather than here, consistent with this topic's seam against a comprehensive data-protection act's own security article.

This visit could not locate the ministerial arrêtés Articles 6 and 15 each leave the technical audit criteria and the classification procedure to, which is recorded as an open question on the instruments below rather than assumed either way.

Sector security regimes

Mandatory Security Audit and Digital-Trust Classification

Décret-loi n° 2023-17 du 11 mars 2023, relatif à la cybersécurité, Arts. 6-9, 14-16, 24-25Full French text of Décret-loi n° 2023-17

In force since 11 September 2023. Binds public and private bodies.

What this law does

Article 6 subjects every public and private organization in five categories to a mandatory, periodic information-systems security audit: a public telecommunications network operator or telecommunications and internet service provider, an enterprise whose information networks are interconnected through telecommunications networks, a hosting or cloud-computing service provider, an enterprise that automatically processes its users' personal data while providing its service through telecommunications networks, and a vital digital infrastructure the state designates by decree.

Article 7 requires that audit to run at least once every twelve months, performed by an expert the Agency lists as authorized to practice cybersecurity auditing. Article 8 requires the audited organization to submit a protected electronic copy of the audit report to the Agency within ten days of the audit's completion, and to implement every recommendation the report contains.

Article 14 requires the same organizations to host any governmental electronic system or service only with a cloud-computing or hosting provider that holds the Article 12 government-cloud or national-cloud label. Article 15 subjects the same organizations to a mandatory, periodic classification into three digital-trust levels, set from their audit compliance, their use of approved equipment and solutions, and whether they host their systems with a labeled provider.

Article 16 gives an organization classified at the lowest, unclassified third level up to one year, after a formal notice, to meet the classification standard. Article 24 lets the minister of communication technologies downgrade an organization classified at the first or second level, rather than fine it, for failing to audit, to submit its audit report on time, to implement the report's recommendations, or to honor the Article 14 hosting duty.

Article 25 fines an organization classified at the third level 50,000 to 100,000 dinars for failing to audit or to implement the report's recommendations.

What it requires

Vulnerability and incident reporting

Cybersecurity Incident Reporting and Emergency Response

Décret-loi n° 2023-17 du 11 mars 2023, relatif à la cybersécurité, Arts. 17-20, 24-25Full French text of Décret-loi n° 2023-17

In force since 11 September 2023. Binds public and private bodies.

What this law does

Article 19 requires the same Article 6 population, telecommunications and internet operators, interconnected enterprises, hosting and cloud providers, enterprises that automatically process their users' personal data over telecommunications networks, and vital digital infrastructure, to create its own cybersecurity emergency response center or to join a public, sectoral or private one, and to coordinate that center with the national emergency-response contact point Article 18 has the Agency designate.

Article 20 requires those organizations to immediately inform the national contact point or their emergency response center of any cybersecurity incident or attack, and to comply with the emergency measures either one orders.

Article 17 lets the Agency warn an organization whose incident or attack has disrupted its information system or communications network, or endangered the national cyberspace's security, to remedy the failure within thirty days, and lets the minister of communication technologies order the temporary isolation of its systems on the Agency's own reasoned report.

Article 24 lets the minister downgrade an organization classified at the first or second level, rather than fine it, for failing to comply with an emergency measure, to remedy a failure within the Article 17 deadline, or to create or join an emergency response center. Article 25 fines an organization classified at the third level 50,000 to 100,000 dinars for the same failures.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (199 words)

Tunisia has no press-publisher neighbouring right, no mandatory platform-to-publisher bargaining code, no recognized hot-news misappropriation doctrine distinct from ordinary copyright law, and no located statute or case law addressing hyperlinking or framing liability specifically; each of those dimensions is a sourced absence rather than an unresolved question.

The relevant instrument is Loi n° 94-36 du 24 février 1994 relative à la propriété littéraire et artistique, which excludes the news of the day and mere facts of a press-information character from copyright protection outright, so a bare fact or news item is never protectable regardless of who first reported it.

The same Law lets a person make quotations and borrowings from a lawfully disclosed work, including quotations and borrowings from articles in the form of press reviews, provided they conform to fair practice and are justified by a scientific, educational or informational purpose, with the source and author named; nothing limits that exception to short extracts by a length threshold, and no located Tunisian decision applies it to a systematic news aggregator as opposed to a traditional press review.

The Law predates the concept of a machine-readable text-and-data-mining reservation and confers no sui generis database right, so neither exists here.

Snippet reproduction

Copyright Act, Facts Exclusion and Quotation and Press-Review Exception

Loi n° 94-36 du 24 février 1994 relative à la propriété littéraire et artistique, telle que modifiée et complétée par la loi n° 2009-33 du 23 juin 2009, arts. 1er et 11Loi n° 94-36, French consolidated text as amended to 2009, reproduced on the WIPO Lex record page for the Law

In force since 1 March 1994. Binds public and private bodies.

What this law does

Article premier extends copyright to every original literary, scientific or artistic work but states that protection covers expressions and does not extend to official legislative, administrative or judicial texts and their official translations, or to the news of the day or miscellaneous facts that have the character of simple press information; a bare fact or news item is therefore never a protected work under Tunisian law, whichever outlet reports it first.

Article 11 separately authorises quotations and borrowings taken from a work already lawfully made accessible to the public, including quotations and borrowings from articles in the form of press reviews, on condition that they conform to fair practice and are justified by a scientific, educational or informational purpose, used in their original version or in translation, and accompanied by mention of the source and the author's name where it appears in the source.

The exception is not capped at a headline-length or short-extract threshold and is not confined to the press industry; whether it reaches a systematic aggregator's reproduction of headlines and snippets, as opposed to a traditional press review, has not been tested in a located Tunisian decision.

Article 51 arms a rightholder with civil damages for a breach of copyright or related rights, and article 52 sets a criminal fine of 1,000 to 50,000 dinars, doubled on repeat offence with up to twelve months' imprisonment added, for exploiting a protected work without the required authorization.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.