Law / Mauritania

Loi n° 2017-020, Autorité de Protection des Données et sanctions

Loi n° 2017-020 du 22 juillet 2017, arts. 64-98 (Autorité de Protection des Données et sanctions)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 22 July 2017.

An enforcement supervision rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Cooperate with the Authority's on-site inspections, and take all measures needed to facilitate its work rather than opposing its action.
  • Comply with an Authority warning or formal notice within the period it sets, or face suspension or definitive withdrawal of your processing authorization and a pecuniary fine of up to ten million ouguiya for a first breach, or up to fifty million ouguiya or five percent of turnover for a repeat breach within five years.
  • Expect the Authority to interrupt your processing, lock the data, or ban the processing without prior formal notice where it creates an urgent risk to rights and freedoms.
  • Expect a sanction the Authority imposes to be published, at your own expense, on the Authority's president's decision.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

One to two months' imprisonment and a fine of 50,000 to 500,000 ouguiya, or either penalty alone, for processing personal data, even negligently, without completing the prior formalities this law requires (art. 85). Separate criminal tiers punish obstructing the Authority's own inspections, one to three months and 100,000 to 1,000,000 ouguiya (art. 84), and unlawfully recording or keeping sensitive personal data without the person's express consent, fifteen days to one month and 50,000 to 500,000 ouguiya (art. 90). Prosecution of an unlawful-disclosure offence under art. 94 requires the victim's own complaint.

Penalty structure

Article 80 caps a repeated breach, within five years of a prior final sanction, at 50,000,000 ouguiya or, for a company, 5% of the last closed financial year's turnover excluding tax; the text does not state in terms whether the higher or the applicable one of the two governs a corporate violator, coded here as the higher of the two. A first breach is capped separately, and lower, at 10,000,000 ouguiya under the same article. This is the Authority's own administrative pecuniary sanction; the criminal fine tiers under arts. 84, 85 and 90 run far lower, from 50,000 to 1,000,000 ouguiya. Amounts are stated in ouguiya as denominated in the statute's 2017 text, before Mauritania's 2018 currency redenomination (ten old ouguiya became one new ouguiya).

Rule
Higher of
As of
19 September 2026
Currency
MRO
Fixed cap
50,000,000
Turnover percentage cap
5

Who enforces it

Enforcement body

Autorité de Protection des Données à caractère personnel

Settledness

As of
19 September 2026
Open questions
Does article 80's 5%-of-turnover ceiling for a corporate violator replace the 50,000,000 ouguiya cap, or does the higher (or the lower) of the two govern?

What it reaches

Obligation class

Governance, Reporting

Who checks it

Audit expectation

on_request

Who audits it

Regulator

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 64 creates the Autorité de Protection des Données à caractère personnel as an independent public legal person with financial and management autonomy, attached to the Prime Minister, charged with ensuring processing complies with the law and checking that information and communication technologies do not threaten public freedoms or privacy.

Articles 65 through 69 fix the Authority's composition and member appointment by decree, its staff, a four year once renewable mandate, incompatibility with government membership or business leadership, and replacement rules, and articles 70 and 71 bind members to an oath and give them full immunity for opinions expressed in office, free from any authority's instructions.

Article 72 requires ministers, public authorities, and public or private company directors alike to take all measures to facilitate the Authority's work and bars them from opposing its action except where the law provides otherwise.

Article 73 lists the Authority's missions, including receiving prior formalities and complaints, notifying the public prosecutor of offences and suing to enforce the law, ordering verifications, sanctioning a controller under articles 77 and following, answering opinion requests, approving codes of conduct, keeping a public register of processing, advising controllers, setting the conditions for and authorizing cross border transfers, proposing legislative improvements, cooperating internationally, publishing its authorizations, and reporting annually to the Prime Minister, Parliament, and the Minister for electronic communications.

Articles 74 through 76 let the Authority's agents and sworn officers inspect premises used for processing, with the territorially competent prosecutor informed beforehand, and demand and copy any document useful to their mission.

Article 77 lets the Authority warn a controller and give formal notice to end a breach within a set period, and article 78 lets it, after a contradictory procedure, provisionally or definitively withdraw an authorization or impose a pecuniary fine under article 80 where the controller does not comply.

Article 79 lets the Authority, in an emergency threatening rights and freedoms, order the interruption of a processing operation, the locking of data, or a temporary or definitive ban on a processing that violates the law, and article 83 lets any Authority sanction or decision be appealed to the Supreme Court.

Article 80 caps a pecuniary sanction at ten million ouguiya for a first breach, rising to fifty million ouguiya, or, for a company, five percent of the last closed financial year's turnover excluding tax, for a repeated breach within five years of a prior final sanction. Article 82 lets the Authority's president order a sanction published at the sanctioned party's own expense.

Articles 84 through 94 set criminal offences and penalties, including for obstructing the Authority's own inspections, processing personal data without completing the law's prior formalities, collecting personal data by fraudulent or unlawful means, and processing a person's data despite their valid objection, notably to commercial prospecting, and articles 96 through 98 extend criminal liability to a legal person and require the public prosecutor to notify the Authority's president of every prosecution.

When LexLint raises it

  • crawls_web
  • trains_models
  • automated_outreach

Read the law

Text of Loi n° 2017-020, published in the Journal Officiel de la République Islamique de Mauritanie, hosted by the ILO's NATLEX database

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app