Loi n° 2017-020, protection des données à caractère personnel
Loi n° 2017-020 du 22 juillet 2017 relative à la protection des données à caractère personnel
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 22 July 2017.
A comprehensive regime rule binding public and private bodies.
As of 5 September 2026.
What it requires
- Do not process a person's personal data once they have validly objected, including where the processing serves commercial prospecting.
- Before transferring personal data to a country that does not ensure an adequate level of protection, obtain the Personal Data Protection Authority's authorisation on a motivated request, backed by sufficient guarantees such as appropriate contractual clauses.
- Do not collect personal data by fraudulent, unfair, or unlawful means.
- Complete the Personal Data Protection Authority's prior formalities before processing personal data; failing to do so, even negligently, is a criminal offence.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
One to two months' imprisonment and a fine of 50,000 to 500,000 ouguiya, or either penalty alone, for processing personal data, even negligently, without completing the prior formalities this law requires (art. 85).
Penalty structure
Article 80 caps a repeated breach, within five years of a prior final sanction, at 50,000,000 ouguiya or, for a company, 5% of the last closed financial year's turnover excluding tax; the text does not state in terms whether the higher or the applicable one of the two governs a corporate violator, coded here as the higher of the two. A first breach is capped separately, and lower, at 10,000,000 ouguiya under the same article. Amounts are stated in ouguiya as denominated in the statute's 2017 text, before Mauritania's 2018 currency redenomination (ten old ouguiya became one new ouguiya).
- Rule
- Higher of
- As of
- 5 September 2026
- Currency
- MRO
- Fixed cap
- 50,000,000
- Turnover percentage cap
- 5
Who enforces it
Enforcement body
Autorité de Protection des Données à caractère personnel
Settledness
- As of
- 5 September 2026
- Open questions
- Does article 80's 5%-of-turnover ceiling for a corporate violator replace the 50,000,000 ouguiya cap, or does the higher (or the lower) of the two govern?
What it reaches
Obligation class
Governance, Transfer, Consent
Who checks it
Audit expectation
on_request
Who audits it
Regulator
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article premier sets the law's object as establishing a normative and institutional framework for processing personal data, so that any processing of personal data, in whatever form, respects citizens' fundamental freedoms and rights.
Article 25 lets the Authority authorise a transfer of personal data to a country that does not ensure an adequate level of protection, on a duly motivated request, where the controller offers sufficient guarantees, which may take the form of appropriate contractual clauses.
Article 72 binds ministers, public authorities, and public or private company directors alike to take all measures to facilitate the Authority's work, so the law's institutional obligations reach both public bodies and private controllers.
Articles 65 through 73 establish the Authority's composition, a four-year renewable-once mandate for its members, their professional-secrecy duty, and its missions, including receiving prior formalities, receiving complaints, ordering verifications, and authorising cross-border transfers.
Articles 74 through 79 give the Authority's agents inspection powers over premises used for personal-data processing, subject to judicial authorisation on the responsible party's objection, and let the Authority issue a warning, a formal notice, or, after that notice is not complied with, a temporary or definitive withdrawal of an authorisation or a pecuniary sanction.
Article 80 caps that pecuniary sanction at 10,000,000 ouguiya for a first breach, rising to 50,000,000 ouguiya, or, for a company, 5% of the last closed financial year's turnover excluding tax, for a repeated breach within five years of a prior final sanction.
Articles 84 through 98 set criminal offences and penalties, including for processing personal data without completing the law's prior formalities, collecting personal data by fraudulent or unlawful means, and processing a person's data despite their valid objection, notably to commercial prospecting. Article 101 ties the law's execution to publication in the Official Gazette, immediately above the promulgation dateline of 22 July 2017.
When LexLint raises it
crawls_webtrains_modelsautomated_outreach