[codicts-css-switcher id=”346″]

Global Law Experts Logo
tunisia moves replace its twentyyearold data

Tunisia Moves to Replace Its Twenty‑year‑old Data Protection Law, What Businesses Must Do Now

By Global Law Experts
– posted 2 hours ago

Last reviewed: August 13, 2026

Tunisia moves to replace its twenty‑year‑old data protection framework with a sweeping organic bill that overhauls every major obligation businesses face when collecting, storing or transferring personal data in or out of the country. The draft bill, filed with the Assemblée des Représentants du Peuple (ARP) as project PLO 095/2025, proposes to repeal Organic Law No. 2004‑63 and introduce modern requirements for Data Protection Officers, mandatory breach notification, controls on AI‑driven profiling, and significantly higher sanctions. For companies that have treated Tunisia’s data‑protection regime as a low‑enforcement formality, the Tunisia data protection bill now before parliament demands an immediate reassessment of internal compliance programmes.

This guide explains the key changes, maps each one to a concrete compliance decision, and provides a step‑by‑step checklist that legal, IT and HR teams can act on today.

Executive Summary: What Changed and the Single Compliance Decision

The core question every business operating in Tunisia must answer is straightforward: are your current data‑handling practices built for a 2004 law that is about to be replaced, or are they ready for a regime modelled on modern international standards? The draft bill filed with the ARP introduces obligations that did not exist under the outgoing framework, including the formal role of the Data Protection Officer in Tunisia, mandatory incident reporting to the INPDP (Instance Nationale de Protection des Données Personnelles), and explicit restrictions on automated decision‑making and profiling AI in Tunisia.

For in‑house counsel and compliance officers, the practical effect is a single strategic decision with multiple operational components: treat the draft as effectively final for planning purposes, conduct a gap analysis against its reported provisions, and begin closing the gaps now, before the transition window opens and competitors scramble for the same limited pool of local advisory resources.

The legislative process is live and moving. Parliamentary committees have already begun hearings on the bill’s provisions, with press coverage confirming that debates have focused on AI risk controls and the supervisory powers of the INPDP. Waiting for final enactment before acting is a compliance risk in itself, given that many of the required measures, processing inventories, cross‑border transfer authorisations, breach‑response plans, take months to implement properly.

At a Glance: Top 6 Takeaways

  • Full repeal of Law 2004‑63. The draft bill replaces the entire existing framework rather than amending it piecemeal.
  • Data Protection Officer role created. The bill introduces a DPO function, with mandatory appointment expected for public bodies and high‑risk processors.
  • Mandatory breach notification. Organisations will be required to notify the INPDP, and potentially affected data subjects, following qualifying personal data breaches.
  • AI and automated decision‑making controls. New provisions address profiling, algorithmic risk and individuals’ rights to contest automated decisions.
  • Cross‑border transfer rules tightened. The INPDP authorisation regime is expected to continue, with additional safeguards for offshore processing and hosting.
  • Higher sanctions. The draft significantly increases fines and introduces broader enforcement powers for the INPDP.

Background: Tunisia’s Current Framework (Law 2004‑63) and Why Reform Is Happening

Tunisia was an early mover on data protection in Africa and the Arab world. Organic Law No. 2004‑63 of 27 July 2004 established a comprehensive, for its time, regime governing the collection, processing and storage of personal data. It created the INPDP as the national supervisory authority, introduced a system of prior declarations and authorisations, and set out data‑subject rights including access, rectification and objection.

Key Features of Law 2004‑63

The 2004 law applied broadly to any processing of personal data carried out wholly or partly in Tunisia. It required data controllers to file declarations with the INPDP before commencing most processing activities and to obtain prior authorisation for sensitive data processing and cross‑border data transfers. Criminal penalties were available for non‑compliance, and individuals could exercise rights of access and correction directly against controllers. The INPDP was charged with receiving complaints, conducting inspections and issuing opinions.

Practical Limitations That Prompted the Bill

Despite its pioneering status, Law 2004‑63 was designed before cloud computing, big‑data analytics, social‑media platforms and AI‑driven profiling became routine business operations. The law contained no specific provisions on breach notification, no formal DPO role, and limited guidance on automated decision‑making. Its enforcement architecture relied heavily on criminal sanctions rather than the graduated administrative fines that have proved more effective in other jurisdictions. Industry observers note that the INPDP’s practical capacity to process the volume of declarations and authorisations generated by a modern digital economy has been stretched, and that businesses increasingly required clearer rules for cross‑border data transfer to Tunisia’s trading partners. These structural gaps made comprehensive reform, rather than incremental amendment, the logical path forward.

What the Tunisia Data Protection Bill Proposes: Detailed Breakdown

The draft bill filed with the ARP as PLO 095/2025 is a substantial piece of legislation. Local press has reported varying article counts, some sources referencing approximately 123 articles and others citing 132 articles. The definitive structure will be confirmed by the ARP dossier once committee review concludes. What follows is a synthesis drawn from the parliamentary filings and regulatory summaries published by Regulations.ai and African Manager.

Scope and New Definitions

The bill broadens the material and territorial scope of Tunisia’s personal data regime. It updates core definitions, including “personal data,” “processing,” “controller” and “processor”, to align more closely with international standards. Significantly, the draft extends its reach to processors established outside Tunisia where their processing relates to individuals located in the country. This extraterritorial element mirrors approaches taken by the EU’s GDPR and several African peer frameworks, and the likely practical effect will be to bring offshore service providers and cloud platforms squarely within the INPDP’s regulatory perimeter.

DPO, Declarations and Authorisations

One of the most operationally significant changes is the creation of a formal Data Protection Officer role. As reported by African Manager, the draft makes DPO appointment obligatory for certain categories of organisation, public bodies and entities whose core activities involve large‑scale or systematic monitoring of individuals. The bill also modernises the existing declaration and authorisation system administered by the INPDP Tunisia authority, streamlining certain low‑risk declarations while reinforcing prior‑authorisation requirements for high‑risk processing activities including the processing of sensitive data categories.

AI, Profiling and ADM Controls

The draft bill includes dedicated provisions on profiling AI in Tunisia and automated decision‑making (ADM). These provisions grant individuals the right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significant impacts. Organisations deploying AI systems that make or materially influence decisions about individuals, credit scoring, recruitment filtering, insurance underwriting, will need to conduct impact assessments, provide meaningful information about the logic involved, and offer a mechanism for human review. Regulatory summaries indicate that the bill also empowers the INPDP to issue sector‑specific guidance on algorithmic transparency and to investigate complaints related to ADM.

Compliance Decisions Businesses Must Make Now as Tunisia Moves to Replace Its Twenty‑Year‑Old Data Framework

The gap between current practice under Law 2004‑63 and the obligations in the draft bill is wide enough that early action delivers a clear competitive and legal advantage. The following checklist is organised into two phases: urgent items that should be addressed within 30 days, and medium‑term tasks for a 90‑day roadmap.

30‑Day Implementation Checklist for Urgent Matters

  1. Conduct a processing inventory. Map every category of personal data your organisation collects, the legal basis relied upon, where it is stored and to whom it is transferred. This is the foundation for every other compliance action.
  2. Identify cross‑border data flows. List all transfers of personal data outside Tunisia, including to cloud service providers, group companies and third‑party processors. Check whether each transfer is covered by a current INPDP authorisation. If not, begin the application process immediately via the INPDP notice portal.
  3. Assess DPO readiness. Determine whether your organisation falls within the categories likely to require a mandatory Data Protection Officer under the draft bill (public body, large‑scale systematic monitoring, sensitive‑data processing at scale). If so, identify internal candidates or external service options and begin budget allocation.
  4. Review breach‑response capability. Confirm that your incident‑response plan includes a data‑breach classification process, internal escalation flow and draft notification templates. Under the new regime, breach notification Tunisia obligations will require rapid action, delays will be costly.
  5. Audit privacy notices and consent mechanisms. Review all customer‑facing and employee‑facing privacy notices for accuracy, completeness and alignment with the broader data‑subject rights introduced by the draft.

90‑Day Roadmap for Medium‑Term Tasks

  1. Data Protection Impact Assessments (DPIAs). Prioritise DPIAs for high‑risk processing activities, particularly any use of AI, automated scoring or profiling. Document the assessment process and remedial actions taken.
  2. Vendor and processor contracts. Review all data‑processing agreements with third‑party vendors. Ensure contracts include mandatory clauses on data security, sub‑processing, breach notification, audit rights and cross‑border transfer safeguards consistent with the draft bill’s requirements.
  3. Training programme. Develop and schedule mandatory data‑protection training for staff who handle personal data, particularly HR, marketing, IT and customer‑service teams.
  4. Record‑keeping systems. Implement or upgrade a register of processing activities that can be produced on request to the INPDP.
  5. Insurance review. Assess whether your organisation’s professional‑indemnity or cyber‑insurance policies adequately cover regulatory‑investigation costs, fines (where insurable) and data‑breach remediation expenses under the enhanced enforcement regime.
  6. Governance structure. Formalise reporting lines between the DPO (or designated privacy lead), the board and operational teams. Document decision‑making authority for breach escalation, DPIA sign‑off and cross‑border transfer approvals.

Cross‑Border Transfers and INPDP Authorisations

Cross‑border data transfer from Tunisia has long required prior authorisation from the INPDP for transfers to countries that do not provide an adequate level of personal data protection. The draft bill is expected to retain this authorisation‑based model while introducing additional safeguards, including recognition of contractual mechanisms analogous to standard contractual clauses. The table below summarises the main transfer routes and practical steps under both the current and expected regimes.

Transfer Route When Usable Practical Steps
INPDP prior authorisation Required for transfers to non‑adequate countries (current law and expected under draft) File application via INPDP notice portal; allow processing time; maintain documentation of authorisation
Transfer to adequate‑protection country Where INPDP has recognised the destination country’s framework as adequate Verify adequacy status on INPDP published list; document reliance; monitor for changes
Contractual safeguards (expected under draft) Where the bill introduces contractual mechanisms akin to SCCs Prepare template clauses now; align with INPDP guidance once published; incorporate into vendor agreements
Derogations (consent, contract necessity) Limited circumstances, explicit data‑subject consent or contractual necessity Document the specific derogation relied upon; do not treat as a routine transfer basis

When to Start INPDP Authorisation

Organisations that have not yet obtained INPDP authorisation for existing cross‑border transfers should begin the process immediately. The authorisation procedure involves submitting detailed information about the nature of the data, the identity and location of the recipient, and the safeguards in place. Processing times can be lengthy, and early indications suggest that demand for authorisations will increase as the new law approaches enactment. Starting now avoids a bottleneck that could disrupt business‑critical data flows.

Breach Notification in Tunisia: Thresholds, Timelines and Example Template

Law 2004‑63 did not include a mandatory breach‑notification obligation. The draft bill changes this fundamentally. Regulatory summaries indicate that the bill requires controllers to notify the INPDP of qualifying personal data breaches and, where the breach poses a high risk to data subjects, to notify the affected individuals as well. The precise notification timeline is expected to be confirmed in the final text or implementing regulations; industry observers expect it to be measured in days rather than weeks, consistent with international practice.

Organisations should prepare now by establishing the following internal framework:

  • Detection and classification. Define what constitutes a personal data breach and establish classification criteria (severity, volume of data, categories of data subjects affected).
  • Internal escalation flow. Set a clear chain: incident reporter → IT security lead → DPO / privacy lead → legal counsel → senior management. Document maximum response times at each stage.
  • Notification template. Prepare a draft notification to the INPDP that includes: (a) description of the breach, (b) categories and approximate number of data subjects affected, (c) likely consequences, (d) measures taken or proposed to address the breach and mitigate harm.
  • Data‑subject communication. Prepare a separate template for notifying individuals in clear, plain language where the breach is assessed as high‑risk.
  • Post‑incident review. Require a documented lessons‑learned review within 30 days of every qualifying breach.

Enforcement, Sanctions and Litigation Risk

The draft bill significantly strengthens the INPDP’s enforcement toolkit. Under the current framework, sanctions are primarily criminal in nature. The proposed regime introduces graduated administrative fines that can be imposed directly by the INPDP, reserving criminal penalties for the most serious violations. Parliamentary materials confirm that the bill expands the authority’s investigative powers, including the ability to conduct on‑site inspections, compel the production of documents and issue binding corrective orders.

The practical implication is a shift from a regime where enforcement was rare to one where administrative action becomes a realistic and routine possibility. Organisations should factor this into their risk registers and consider whether existing cyber‑insurance and professional‑indemnity policies need updating. Civil liability for damages caused by unlawful processing is also addressed in the draft, creating an additional litigation risk from data subjects and representative bodies. Early compliance investment is the most cost‑effective form of mitigation.

Comparison: Draft Tunisia Bill vs EU GDPR

The following table compares the key reported provisions of the Tunisia data protection bill with the corresponding GDPR baseline. This comparison helps international businesses already familiar with GDPR to calibrate their Tunisia‑specific compliance effort.

Issue Draft Tunisia Bill (Reported) GDPR (Baseline)
Legal bases for processing Multiple legal bases expected (consent, contractual necessity, legal obligation, legitimate interests framework details pending final text) Six legal bases under Article 6; legitimate‑interests balancing test well established
DPO requirement Mandatory for public bodies and likely for high‑risk processors; thresholds to be confirmed Required for public authorities and organisations whose core activities involve large‑scale systematic monitoring (Art. 37)
Breach notification timeline Mandatory notification to INPDP and to high‑risk data subjects; specific timeline pending final text 72 hours to supervisory authority where feasible (Art. 33); without undue delay to data subjects for high‑risk breaches (Art. 34)
Cross‑border transfers INPDP prior‑authorisation model retained; contractual safeguards expected to be introduced Adequacy decisions, SCCs, BCRs, derogations (Chapter V)
AI / automated decisions Right not to be subject to solely automated decisions with legal or significant effects; DPIA obligations Art. 22 right to contest automated decisions; DPIA required for high‑risk processing (Art. 35)
Sanctions Graduated administrative fines introduced alongside criminal penalties; quantum details pending Administrative fines up to €20 million or 4% of global annual turnover (Art. 83)

The structural alignment is clear: the Tunisia data protection bill draws heavily on GDPR principles while retaining elements, notably the INPDP authorisation model for transfers, that reflect Tunisia’s existing regulatory architecture. Businesses already GDPR‑compliant will have a significant head start, but should not assume that GDPR compliance automatically satisfies Tunisian requirements. Local nuances in the authorisation process, the DPO obligation thresholds, and the enforcement approach will require jurisdiction‑specific attention.

Next Steps: Preparing for Personal Data Compliance in Tunisia 2026

Tunisia moves to replace its twenty‑year‑old data protection regime at a moment when personal data obligations are intensifying across every jurisdiction in which businesses operate. The draft bill before the ARP is not a minor amendment, it is a fundamental overhaul that will reshape how organisations collect, process, transfer and secure personal data in Tunisia. Compliance is not optional, and early movers will face lower costs, less disruption and reduced regulatory risk.

The practical steps are clear: complete your processing inventory, assess your DPO requirements, secure INPDP transfer authorisations, build your breach‑response capability and conduct DPIAs on any AI or automated decision‑making systems. For organisations that need jurisdiction‑specific guidance, engaging a Tunisian‑licensed data‑protection lawyer is the single most effective step to ensure your compliance programme meets the requirements of the new law from day one.

Global Law Experts connects businesses with experienced data‑protection practitioners in Tunisia and across the MENA region. For tailored advice on the Tunisia data protection bill and its impact on your operations, consult a qualified privacy specialist through the Global Law Experts network.

Sources

  1. ARP (Tunisian Parliament), Project PLO 095/2025
  2. INPDP, Instance Nationale de Protection des Données Personnelles
  3. Organic Law No. 2004‑63 of 27 July 2004 (legislation‑securite.tn)
  4. Regulations.ai, Tunisia data protection draft summary
  5. African Manager, Personal data protection: Tunisian parliament moves to curb AI and algorithm risks
  6. INPDP notice and authorisation portal
  7. Tunisie Numérique, draft bill coverage (Arabic)

FAQs

What law is being replaced?
Tunisia’s Organic Act No. 2004‑63 of 27 July 2004 on the protection of personal data is being replaced by a comprehensive organic bill currently before the ARP.
The draft bill creates a formal DPO role. Mandatory appointment is expected for public bodies and organisations conducting high‑risk or large‑scale data processing. Start assessing your organisation’s position now, as final thresholds will be confirmed upon enactment.
Under current law, most cross‑border transfers require prior INPDP authorisation. The draft bill retains this model and may add contractual‑safeguard options. Begin mapping your international data flows and filing applications immediately.
Conduct a processing inventory, initiate DPIAs for AI and high‑risk activities, prepare a breach‑response plan, review cross‑border transfer authorisations, and update privacy notices. The 30‑day and 90‑day checklists in this article provide a structured approach.
The legislative process is active; the bill is in committee review at the ARP. Monitor the parliamentary docket and INPDP announcements for final publication and any transition period. Do not wait for enactment to begin compliance work.
The bill introduces a right not to be subject to solely automated decisions with legal or significant effects, requires impact assessments for AI‑driven processing, and empowers the INPDP to issue guidance on algorithmic transparency.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Tunisia Moves to Replace Its Twenty‑year‑old Data Protection Law, What Businesses Must Do Now

Send welcome message

Custom Message