Personal Data: Responsibilities of Tunisian Business Owners

Written by: Adel Khelifi on August 19, 2026

Between the Organic Law of 2004 and the 2025 reform project, the Tunisian leader sees his personal liability weighing more heavily in relation to the processing of data of his clients, employees and partners.

In Tunisia, personal data has become an asset that every leader handles without always measuring the legal weight that accompanies it. Customer files, biometric badge, HR files, online payment form: every stream of nominative information places the business leader, whether he knows it or not, in the position of data controller within the meaning of Organic Law No. 2004-63 of July 27, 2004.

Twenty-two years after the entry into force of this pioneering text in the Arab world, the accelerated digitization of the Tunisian economy, driven by e-commerce, electronic invoicing and artificial intelligence, has made this responsibility both more frequent and more consequential.

A foundational framework weighing on the leader

The 2004 law, complemented by Decrees No. 2007-3003 and No. 2007-3004 of November 27, 2007, established the National Authority for the Protection of Personal Data, endowed with legal personality and financial autonomy, based in Tunis.

This framework rests on a strict procedural logic. Indeed, any collection of identifying data, from name to identity card number through IP address, must be the subject of a prior declaration to the Authority, while the processing of sensitive data, health, biometrics, criminal records, requires explicit authorization. It is the legal representative of the company who signs these forms, and thus bears personal responsibility in case of non-compliance.

The text provides criminal penalties directly attributable to the leader. Up to one year in prison and a fine of 5,000 dinars for failure to declare or lack of authorization, notably for data exports outside the national territory, governed by Article 47, which prohibits any disclosure to a third party without explicit written consent, and by Article 50, which prohibits any transfer likely to endanger public security.

The Authority has moreover transferred, as early as July 2023, about thirty cases to the public prosecutor for non-compliance with the declarative obligation of Article 7, while several hundred cases remain pending before Tunisian courts, a volume that reflects a widespread lack of compliance in the entrepreneurial fabric.

The obligation to secure systems

To this baseline was added a second pillar: Decree-Law No. 2022-54 relating to combating offenses related to information and communication systems, followed by Decree-Law No. 2023-17 of March 11, 2023 relating to cybersecurity, which came into force on September 11, 2023.

This latter text imposes on public and private structures managing critical information infrastructure precise obligations of securing, incident notification and digital risk management, obligations whose implementation ultimately falls to the business leader, guarantor of the compliance of his structures.

The juxtaposition of these two regimes, data protection and cybersecurity, means that a single data breach today can engage the leader’s responsibility on two distinct and cumulative legal grounds.

 

 

 

MAP OF THE THREE REGIMES OF THE LEADER’S LIABILITY

Personal data in business – a comparative reading 2004 · 2023 · 2025 project

REGIME I · 2004

Organic Law No. 2004-63

REGIME II · 2023

Cybersecurity Decree-Law No. 2023-17

REGIME III · PROJECT 2025

Organic Law No. 095/2025

Status: in force

Authority: INPDP

Key obligation: declaration/ prior authorization

Status: in force since 11/09/2023

Authority: National Cybersecurity Authority

Key obligation: securing information systems

Status: in parliamentary committee

Authority: new independent authority

Key obligation: DPO + register + notification

Sanction for leader: up to 1 year in prison

and 5,000 TND fine

Sanction for leader: compliance responsibility

on critical infrastructures

Sanction for leader: up to 200,000 TND

(≈ 60,000 €) + prison + % of turnover

Basis: art. 7, 47 and 50 Basis: Decree-Law 2022-54 and 2023-17 132 articles · 17 MPs · July 2025

Comment: the three regimes are cumulative – a single data incident today can engage the Tunisian leader’s responsibility on several simultaneous legal bases.

Toward a regime close to the GDPR

Aware of the inadequacy of the 2004 framework in the face of contemporary digital practices, e-commerce platforms, cloud, connected devices, artificial intelligence, a parliamentary initiative submitted in July 2025 the Organic Law No. 095/2025, backed by seventeen deputies from the Libres bloc.

This text, which comprises 132 articles and goes beyond simply amending the existing law by proposing a complete overhaul, aligned with the standards of the European General Data Protection Regulation (GDPR).

Three structural innovations define this project. First, the creation of an independent public authority replacing the current Authority, endowed with a division dedicated to offenses and sanctions and subject to the obligation to publish an annual report detailing complaints, investigations and sanctions, transmitted to the President of the Republic and the President of the Assembly.

Next, the establishment of a Data Protection Officer position, mandatory within public structures and strongly recommended, or even required, in private companies processing significant volumes of data.

Finally, a regime of financial penalties that is significantly tougher, potentially reaching 200,000 dinars, equivalent to about 60,000 euros, accumulable with custodial penalties for the gravest offenses. For the most serious breaches, illicit processing of sensitive data or failure to comply with an order from the authority, the text even provides fines indexed to the annual turnover of the offending company, thus mirroring the proportional logic of the European GDPR in Tunisian law.

Numerical barometer of the reform

2004

year of the foundational law

30

cases transferred to the prosecutor (July 2023)

132

articles of the 2025 bill

200 000

TND maximum penalty envisaged

 

What this concretely changes for the leader

While awaiting the final adoption of this text, currently under review by the General Legislation Committee of the Assembly of the Representatives of the People, Tunisian business leaders are advised to anticipate rather than endure.

This entails, first, precisely mapping the data collected and their purposes, secondly verifying the validity of declarations and authorizations filed with the Authority, notably for cross-border flows, which remain subject to a principle of prohibition unless express authorization based on the adequacy of the recipient country’s legal framework.

This implies, third, formalizing the written consent collection of the data subjects, central requirement of Article 1 of the 2004 law, and designating, even in the absence of a strict obligation at this stage, an internal data protection delegate, a governance signal increasingly expected by banking partners, investors and international contracting authorities.

Foreign companies operating in Tunisia are not spared. In fact, Tunisian law applies without exception to nationality or the legal status of the entity, as soon as the processing occurs on national territory or targets Tunisian residents.

Anticipating data governance

The Tunisian legislative trajectory, from the 2004 foundational law to the 2025 reform project, sketches an embraced convergence toward the most demanding international standards. For the business leader, the challenge now goes beyond mere administrative compliance. It is a question of strategic governance, where mastery of personal data conditions client trust, the bankability of projects and access to export markets to the European Union.

Leaders who structure their data protection policy today, beyond the strict legal minimum, will be ahead of the curve when the new sanctions regime comes into force, rather than discovering, at the time of an audit or a complaint, the extent of a responsibility they were already bearing without knowing it.

References

  • Organic Law No. 2004-63 of July 27, 2004, relating to the protection of personal data, Official Journal of the Tunisian Republic.
  • Decree No. 2007-3004 of November 27, 2007, setting the conditions and procedures for the declaration and authorization for the processing of personal data.
  • Decree-Law No. 2022-54 of September 13, 2022, relating to the fight against offenses related to information and communication systems.
  • Decree-Law No. 2023-17 of March 11, 2023, relating to cybersecurity, came into force on September 11, 2023.
  • Organic Bill No. 095/2025, filed in July 2025 by seventeen deputies, relating to the protection of personal data.
  • Organic Law No. 2017-42 of May 30, 2017, approving Tunisia’s accession to Council of Europe Convention 108 and its Additional Protocol.

 

 




Adel Khelifi

Adel Khelifi

My name is Adel Khelifi, and I’m a journalist based in Tunis with a passion for telling local stories to a global audience. I cover current affairs, culture, and social issues with a focus on clarity and context. I believe journalism should connect people, not just inform them.