Without a dedicated law or unified legal definition, business secrecy in Tunisia rests on a patchwork of penal, civil, and contractual texts. With hundreds of thousands of cyberattacks, safeguarding strategic information is first and foremost a governance issue, before it becomes a matter for lawyers.
A well-informed but fragmented framework
The first surprise for managers is legal in nature. The Digital Trade Integration baseline of the European University Institute notes that Tunisia does not have a complete framework for protecting business secrets, with only a few partial measures in Articles 138 and 253 of the Penal Code. On the civil side, the manager relies on the general law of liability (Articles 82 and 83 of the Code of Obligations and Contracts) and on his own contractual commitments.
Article 39 of the WTO TRIPS Agreement, however, requires protection of undisclosed information against unfair practices. Directive 2016/943 provides the most widely used framework. A secret information, having commercial value by virtue of its secrecy, and protected by reasonable measures. This framework has no binding force in Tunisia, but it indicates the logic of proof to anticipate.
Practical consequence: the secret is proven more than proclaimed. What the company has put in place before the dispute becomes its main piece of evidence in the file.
A quantified and massive threat
The National Cybersecurity Agency recorded nearly 558,000 cyberattacks in 2025, including 168,000 phishing attempts. These indicators are not simply additive. The National Cybersecurity Agency had counted 57,430 attacks in the first half of 2025, and the counted attacks, the reported incidents and the blocked threats cover distinct realities.
The target is vast: the national directory lists more than 824,000 companies, mostly small and with limited financial margins. Institutionally, Decree-Law No. 17 of 2023 of March 11, 2023 created the National Cybersecurity Agency and entrusted it with supervising public and private information systems, without specifying who bears the financial loss of a payment incident. The company thus moves forward without a clear contractual safety net.
The cost of the leak: legitimate access at the forefront