§ Dossier · NORTH AFRICA · updated 22 July 2026
in force
DP law status
Organic Law No. 2004-63 on the Protection of Personal Data (replacement bill tabled 2025)
Yes
enforcement activity
as of the last landscape verification
Yes
decisions published
collection under way
The law
Organic Law No. 2004-63 of 27 July 2004 on the Protection of Personal Data IN FORCE
commenced 2004-07-27 · Official full text ↗
- Scope
- All information, regardless of origin or form, that directly or indirectly identifies or makes identifiable a natural person: except information related to public life or considered as such by law (art. 4).
- Key obligations
- Prior declaration to the INPDP for any processing, filed at its headquarters or by any written means; the INPDP may object within one month (art. 7; procedures per Decree 2007-3004); Prior INPDP authorisation for sensitive-data processing and transfers abroad; Prohibition on processing data on criminal history, proceedings and penalties, and on data concerning racial/genetic origins, beliefs, opinions, philosophical or union activism, and health outside the authorised channels; Health-data regime under INPDP Decision No. 4 of 5 September 2018, incl. mandatory DPO for healthcare establishments
- DPO required
- Not generally: no DPO in the 2004 law; healthcare establishments must appoint one under INPDP Decision No. 4 of 2018, and one is recommended practice for other sensitive-data processors.
- Registration
- Yes: prior declaration to the INPDP, with prior authorisation for sensitive data, transfers abroad, or where required by law (art. 7; Decree 2007-3004).
- Cross-border transfers
- Transfers abroad only to countries ensuring adequate protection (art. 51) and INPDP authorisation is MANDATORY in all cases, decided within one month (art. 52); transfers likely to harm public security or Tunisia's vital interests are prohibited outright (art. 50); a child's data transfer goes before the family judge. No safeguards catalogue and no transfer-specific consent derogation; unauthorised transfer abroad is a criminal offence. (Verified from the archived INS text 2026-07-11, S27.)
- Breach notification
- No breach-notification duty under the 2004 law; the INPDP refers detected offences to the public prosecutor, and telecoms-mediated service providers must report cyberattacks to the National Cybersecurity Agency under Decree-Law 2023-17.
- Penalties
- Criminal sanctions (imprisonment and fines) under the 2004 law, enforced through the courts on INPDP referral: a 2018 Tunis First Instance Court case held a controller liable for unauthorised video surveillance; Decree-Law 2022-54 adds harsh criminal penalties (up to five years and TND 50,000, doubled against officials' victims) for harmful dissemination of personal data online.
- Authority
- Instance Nationale de Protection des Données Personnelles (INPDP)
Verified 2026-07-10
Access to information
Organic Law No. 2016-22 on the Right of Access to Information IN FORCE
Enforcement record
The authority publishes enforcement outcomes (publication venue ↗). Published decisions are being collected and verified for the tracker; this dossier will carry them as they pass verification.
Related reading
Analysis is at lawlab.africa/analysis;
method, inclusion rules and the correction policy are on the
methodology page.
Track Tunisia
Get decision alerts by email
Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.