MR

Mauritania

West Africa

4Instruments
0Cases
3Regulators
65%Coverage
Overview

Mauritania regulates personal data through a comprehensive standalone statute, Law No. 2017-020 of 22 July 2017. Built on the ECOWAS regional model and influenced by Council of Europe Convention 108, the law governs automated processing and non-automated processing in structured filing systems, covering controllers established in Mauritania and those outside the country that use equipment or resources located in its territory. It codifies the standard data-quality principles, purpose limitation, adequacy and relevance, accuracy, and storage limitation, and requires appropriate technical and organisational security measures. The statute runs a prior notification and authorisation regime: ordinary processing is declared to the supervisory authority before it begins, while sensitive categories (health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sexual life) require prior authorisation. Data subjects have rights of access, rectification, erasure, and opposition, and are entitled to receive information about processing in an accessible and intelligible form. Cross-border transfers to countries that do not ensure adequate protection are prohibited unless specific conditions are met, including the data subject's consent or contractual safeguards approved by the authority. Criminal penalties apply for processing without required authorisation, breaches of security obligations, and obstruction of investigations. Enforcement rests with the Autorité de Protection des Données (APD), the independent supervisory authority designated under the law. The APD's operational status is confirmed through bilateral cooperation, including a Memorandum of Understanding signed with Algeria's ANPDP in October 2024. As a single-statute regime with a functioning regulator, Mauritania's framework is broadly comparable to its francophone Sahelian peers, though ATLPF's record flags some uncertainty over the law's phased commencement and the status of any implementing regulations.

Topic coverage
TopicInstrumentsCasesCoverage
Data Protection10
AI Governance10
Fintech10
Cybercrime10
Digital Rights10
Platform Liability00
Telecoms00

● Covered  ◐ Partially covered  ○ Not yet covered

Instruments
mr-cyber-2016·Act

Loi n° 2016-007 du 20 janvier 2016 relative à la cybercriminalité (Law on Cybercrime) (Mauritania)

MauritaniaCybercrimeDigital RightsIn Force
Verified

Enacted 20 Jan 2016

mr-fintech-paymentservices-2021·Act

Loi n° 2021-14 relative aux services et moyens de paiement électronique (Law No. 2021-14 on Electronic Payment Services and Instruments) (Mauritania)

MauritaniaFintechIn Force
Verified

Enacted 1 Jan 2021

mr-ai-2025·Guidance

Stratégie Nationale d'Intelligence Artificielle 2025-2029 (Mauritania National Artificial Intelligence Strategy 2025-2029)

MauritaniaAI GovernanceProposed
Verified

Enacted 1 Jan 2025

mr-dp-2017·Act

Loi N° 2017-020 du 22 juillet 2017 sur la protection des données à caractère personnel (Mauritania Personal Data Protection Act 2017)

MauritaniaData ProtectionIn Force
Verified

Enacted 22 Jul 2017

Notable gaps

Commencement details and the status of implementing regulations are unconfirmed on file, and the 2017 law does not adopt the full post-GDPR accountability toolkit (fixed breach-notification deadlines, mandatory DPOs, DPIAs). No subsidiary instruments are recorded.