Between the 2000 Law on Electronic Transactions, the 2023 decree-law on cybersecurity, and the legislators’ persistent silence on the allocation of digital losses, Tunisian businesses move forward without a clear contractual safety net.
In 2025, the Tunisian electronic payments ecosystem crossed a new quantitative threshold. Monetary activity totaled 164.8 million transactions for a value of 29.5 billion dinars, up 12.3% in value, driven by a base of 5.85 million payment cards and 43,116 electronic payment terminals.
Mobile payments jumped 81% in the number of transactions, reaching 8.4 million transactions for 1.769 billion dinars, while e-payments on merchant sites rose by 31% in value, to 1.375 billion dinars, according to Central Bank of Tunisia Bulletin No. 15.
This acceleration is accompanied by increasing exposure to cyber risk. The National Cybersecurity Agency, which succeeded the former National Agency for Information Security, had already recorded more than 155,000 reported incidents in 2022, against 63,000 in 2021, a 146% increase in a single year.
Facing this critical mass of flows and incidents, one question remains unequivocally unanswered in Tunisian positive law: when an electronic payment operation is diverted, altered, or blocked by a cyber event, who ultimately bears the financial loss?
Legal framework and layering of texts
The Tunisian electronic payment law does not derive from a single text organizing the allocation of risk, but from a stacking of three layers adopted at different times and for distinct purposes.
Law No. 2000-83 of August 9, 2000 on electronic exchanges and commerce established the equivalence of electronic writing with paper writing and organized electronic certification, without addressing payments specifically.
Decree-law No. 2023-17 of March 11, 2023 relating to cybersecurity, which came into force on September 11, 2023, created the National Cybersecurity Agency and entrusted it with supervising the information system security of public and private entities, but without instituting a civil liability regime specific to payment incidents.
Central Bank of Tunisia Circular No. 2024-2 of January 29, 2024, concerning the conditions for marketing and pricing of financial products and services, governs the information provided to clients about monetary and remote operations, without, however, setting a clause for the allocation of the loss between bank, merchant, and cardholder.
Unlike the European framework of the Payment Services Directive, which generally imputes the loss to the issuer unless gross negligence by the customer is proven, Tunisian law does not contain any equivalent text dedicated to unauthorized payment operations.