Law / Mauritania

Mauritania

2 of 5 named instruments researched to a stage, across two of the six areas of law we track: 2 in force. As of 5 September 2026.

  1. AI law none researched
  2. Privacy law 1
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law none researched

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law1 instrument, 1 in force

Research summary (138 words)

Mauritania's general data-protection statute is Loi n° 2017-020 du 22 juillet 2017 relative à la protection des données à caractère personnel, which sets a normative and institutional framework for processing personal data and creates the Autorité de Protection des Données à caractère personnel as the sector's supervisory authority, with power to authorise or refuse treatments, order corrective measures, and impose administrative pecuniary sanctions, alongside a separate chapter of criminal offences for unlawful processing.

The law's consent, lawful-basis, and data-subject-access provisions are not read and so are not described here. Mauritania signed the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention) on 26 February 2015, ratified it on 19 April 2023, and deposited its instrument of ratification on 9 May 2023, the fifteenth ratification recorded by the African Union, which brought the Convention into force.

Comprehensive regime

Loi n° 2017-020, protection des données à caractère personnel

Loi n° 2017-020 du 22 juillet 2017 relative à la protection des données à caractère personnelText of Loi n° 2017-020, published in the Journal Officiel de la République Islamique de Mauritanie, hosted by the ILO's NATLEX database

In force since 22 July 2017. Binds public and private bodies.

What this law does

Article premier sets the law's object as establishing a normative and institutional framework for processing personal data, so that any processing of personal data, in whatever form, respects citizens' fundamental freedoms and rights.

Article 25 lets the Authority authorise a transfer of personal data to a country that does not ensure an adequate level of protection, on a duly motivated request, where the controller offers sufficient guarantees, which may take the form of appropriate contractual clauses.

Article 72 binds ministers, public authorities, and public or private company directors alike to take all measures to facilitate the Authority's work, so the law's institutional obligations reach both public bodies and private controllers.

Articles 65 through 73 establish the Authority's composition, a four-year renewable-once mandate for its members, their professional-secrecy duty, and its missions, including receiving prior formalities, receiving complaints, ordering verifications, and authorising cross-border transfers.

Articles 74 through 79 give the Authority's agents inspection powers over premises used for personal-data processing, subject to judicial authorisation on the responsible party's objection, and let the Authority issue a warning, a formal notice, or, after that notice is not complied with, a temporary or definitive withdrawal of an authorisation or a pecuniary sanction.

Article 80 caps that pecuniary sanction at 10,000,000 ouguiya for a first breach, rising to 50,000,000 ouguiya, or, for a company, 5% of the last closed financial year's turnover excluding tax, for a repeated breach within five years of a prior final sanction.

Articles 84 through 98 set criminal offences and penalties, including for processing personal data without completing the law's prior formalities, collecting personal data by fraudulent or unlawful means, and processing a person's data despite their valid objection, notably to commercial prospecting. Article 101 ties the law's execution to publication in the Official Gazette, immediately above the promulgation dateline of 22 July 2017.

What it requires

Scraping law1 instrument, 1 in force

Research summary (339 words)

Mauritania has no scraping-specific statute, so general law governs each dimension separately.

Loi n° 2016-007 relative à la cybercriminalité criminalises accessing or attempting to access all or part of a computer system, intentionally and without right (art. 6), and remaining connected to it after such access (art. 7), without requiring that the actor defeat a technical security measure to gain access; no reported Mauritanian decision has tested whether reading a public, unauthenticated page falls inside or outside that 'without right' standard, so open-web crawling of a public page is unsettled rather than settled either way, while accessing a page behind a login without authorisation, or after defeating a technical control, fits the offence squarely.

No Mauritanian statute or reported case addresses the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

A text titled Loi relative à la propriété littéraire et artistique, dated 2012 and attributed to the Ministry of Culture, Youth and Sports, is hosted by the African Intellectual Property Organization (OAPI), of which Mauritania is a member; it would permit short quotations and excerpts with attribution and treats a database as protectable only where its selection or arrangement is an original creation, giving no sui generis database right, but its enactment date, official citation, and Journal Officiel reference could not be confirmed from the located text or by search, so it is not catalogued as an instrument here.

Mauritania has not enacted a text-and-data-mining exception. The Data Protection Authority created by Loi n° 2017-020 relative à la protection des données à caractère personnel (documented under the privacy topic) reaches personal data generally, but whether the law carves out publicly accessible personal data could not be confirmed from the located, partly illegible text.

No Mauritanian statute or reported case establishes a scraping-specific unfair-competition or misappropriation doctrine, though the cybercrime law separately criminalises copying computer data to another's prejudice (art. 28) and receiving personal, confidential, or professionally secret data obtained by fraudulent means (art. 29); neither assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Loi n° 2016-007, accès non autorisé à un système informatique

Loi n° 2016-007 du 20 janvier 2016 relative à la cybercriminalité, arts. 6-7 (accès non autorisé)Official French text of Loi n° 2016-007

In force since 20 January 2016. Binds public and private bodies.

What this law does

Article 6 punishes anyone who accesses or attempts to access, intentionally and without right, all or part of a computer system, with one to three years' imprisonment and a fine of 100,000 to 2,000,000 ouguiya, or either penalty alone. Article 7 punishes remaining, or attempting to remain, connected to all or part of a computer system in the same conditions with a heavier penalty of two to four years' imprisonment and a fine of 200,000 to 3,000,000 ouguiya, or either penalty alone.

Neither article states that the offence requires defeating a technical security measure to gain access, unlike some comparable statutes elsewhere; the standard is only that the access be intentional and without right, so a plain reading leaves open whether reading a public, unauthenticated page without any technical control to defeat counts as access without right, and no reported Mauritanian decision has construed the phrase.

Article 2 confines the statute to offences linked to the use of information and communication technologies and excludes sound and television broadcasting services from its scope. Article 52 ties the law's execution to publication in the Official Gazette, immediately after the President's promulgation dateline of 20 January 2016.

What it requires

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.