Mauritania
West Africa
Mauritania regulates personal data through a comprehensive standalone statute, Law No. 2017-020 of 22 July 2017. Built on the ECOWAS regional model and influenced by Council of Europe Convention 108, the law governs automated processing and non-automated processing in structured filing systems, covering controllers established in Mauritania and those outside the country that use equipment or resources located in its territory. It codifies the standard data-quality principles, purpose limitation, adequacy and relevance, accuracy, and storage limitation, and requires appropriate technical and organisational security measures. The statute runs a prior notification and authorisation regime: ordinary processing is declared to the supervisory authority before it begins, while sensitive categories (health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sexual life) require prior authorisation. Data subjects have rights of access, rectification, erasure, and opposition, and are entitled to receive information about processing in an accessible and intelligible form. Cross-border transfers to countries that do not ensure adequate protection are prohibited unless specific conditions are met, including the data subject's consent or contractual safeguards approved by the authority. Criminal penalties apply for processing without required authorisation, breaches of security obligations, and obstruction of investigations. Enforcement rests with the Autorité de Protection des Données (APD), the independent supervisory authority designated under the law. The APD's operational status is confirmed through bilateral cooperation, including a Memorandum of Understanding signed with Algeria's ANPDP in October 2024. As a single-statute regime with a functioning regulator, Mauritania's framework is broadly comparable to its francophone Sahelian peers, though ATLPF's record flags some uncertainty over the law's phased commencement and the status of any implementing regulations.
| Topic | Instruments | Cases | Coverage |
|---|---|---|---|
| Data Protection | 1 | 0 | ◐ |
| AI Governance | 1 | 0 | ◐ |
| Fintech | 1 | 0 | ◐ |
| Cybercrime | 1 | 0 | ◐ |
| Digital Rights | 1 | 0 | ◐ |
| Platform Liability | 0 | 0 | ○ |
| Telecoms | 0 | 0 | ○ |
● Covered ◐ Partially covered ○ Not yet covered
Loi n° 2016-007 du 20 janvier 2016 relative à la cybercriminalité (Law on Cybercrime) (Mauritania)
Enacted 20 Jan 2016
Loi n° 2021-14 relative aux services et moyens de paiement électronique (Law No. 2021-14 on Electronic Payment Services and Instruments) (Mauritania)
Enacted 1 Jan 2021
Stratégie Nationale d'Intelligence Artificielle 2025-2029 (Mauritania National Artificial Intelligence Strategy 2025-2029)
Enacted 1 Jan 2025
Loi N° 2017-020 du 22 juillet 2017 sur la protection des données à caractère personnel (Mauritania Personal Data Protection Act 2017)
Enacted 22 Jul 2017
Commencement details and the status of implementing regulations are unconfirmed on file, and the 2017 law does not adopt the full post-GDPR accountability toolkit (fixed breach-notification deadlines, mandatory DPOs, DPIAs). No subsidiary instruments are recorded.