Loi organique n° 2004-63 du 27 juillet 2004 portant sur la protection des données à caractère personnel (Organic Law No. 2004-63 of 27 July 2004 on the Protection of Personal Data)
tn-dp-2004 · Act
Organic Law No. 2004-63 of 27 July 2004 on the Protection of Personal Data (Loi organique n° 2004-63) is Tunisia’s foundational and current data protection statute. As an organic law, it carries elevated constitutional status in the Tunisian legal order. Its adoption made Tunisia the first country in Africa and the Arab world to enact a dedicated personal data protection law, and the Instance Nationale de Protection des Données Personnelles (INPDP) established under it is the oldest data protection authority on the African continent. The law’s origins lie in the 2002 amendment to Tunisia’s 1959 Constitution, which incorporated the protection of private life and personal data among constitutionally guaranteed rights. The protection was further entrenched by Article 24 of the 2014 Constitution and reaffirmed by Article 30 of the 2022 Constitution. The law is supplemented by implementing Decrees No. 2007-3003 and No. 2007-3004 of 27 November 2007, governing respectively the INPDP’s operating procedures and the conditions for declarations and authorisations. Tunisia ratified Council of Europe Convention 108 and its Additional Protocol on 1 November 2017. A comprehensive Organic Bill to modernise the framework in line with the GDPR is before Parliament as at June 2026 but has not been enacted; Organic Law No. 2004-63 remains the governing instrument. The law applies to all automated processing of personal data and to manual processing in structured filing systems, where the controller is established in Tunisia or processing takes place on Tunisian territory. Article 1 enshrines the right of every individual to protection of personal data relating to their private life as a fundamental right guaranteed by the Constitution. Personal data must be collected directly from the data subject, for lawful and explicit purposes, and only to the extent necessary for those purposes. The data subject’s informed, express, and written consent is the general basis for lawful processing, and consent to one purpose does not extend to processing for another purpose. Children’s data may only be processed with the consent of a legal representative and, in specified circumstances, judicial authorisation. Sensitive data, including racial or genetic origin, religious and political beliefs, trade union activities, health data, and criminal history, is subject to heightened restrictions or prohibition. Processing of criminal history data is reserved for authorities specifically empowered by law. Controllers must file a mandatory prior declaration with the INPDP before commencing any processing. Prior INPDP authorisation, which must be granted or refused within one month, is required for sensitive data processing and cross-border transfers. Cross-border transfers are prohibited to countries lacking an adequate level of protection and are absolutely barred where they may endanger public security or Tunisia’s vital interests. Data subjects enjoy rights of access, rectification, updating, deletion, and objection; the right to object immediately suspends the relevant processing. Enforcement is through the INPDP, which may file criminal complaints with the public prosecutor. Penalties include imprisonment of up to one year and fines of up to 5,000 dinars for specific offences. Decree-Law No. 2023-17 of 11 March 2023 on cybersecurity adds mandatory annual IT system audits and cyberattack notification obligations for entities processing personal data via telecommunications networks.
- Prior mandatory declaration to INPDP required for all processing; prior INPDP authorisation required for sensitive data processing and cross-border transfers, with decision issued within one month
- Data subjects’ informed, express, and written consent is the general basis for lawful processing; children’s data requires legal representative consent and may require judicial authorisation
- Sensitive data (racial/genetic origin, health, religious and political beliefs, criminal history) subject to heightened restrictions or prohibition
- Cross-border transfers prohibited to countries lacking adequate protection; all transfers require INPDP authorisation; transfers endangering public security or vital State interests absolutely barred
- Data subject rights include access, rectification, updating, deletion, and objection; exercise of the right to object immediately suspends processing
- INPDP may refer detected offences to the public prosecutor; criminal penalties include imprisonment up to one year and fines up to 5,000 dinars
- Decree-Law No. 2023-17 (2023) mandates annual IT system audits for entities processing personal data via telecommunications networks and requires cyberattack notification to the National Cybersecurity Agency