Comprehensive regime
Organic Act on the Protection of Personal Data
Loi organique n° 2004-63 du 27 juillet 2004, portant sur la protection des données à caractère personnelFull French text of Loi organique n° 2004-63
In force since 30 July 2004. Binds public and private bodies.
What this law does
Article premier declares the protection of personal data a fundamental, constitutionally guaranteed right, and article 2 applies the Act to both automated and non-automated processing carried out by a natural or legal person, with article 3 exempting processing for a strictly personal or family purpose not communicated to a third party.
Article 7 requires a prior declaration to the INPDP before any processing, deemed accepted if the INPDP does not object within one month, and article 8 requires the INPDP's prior authorization for the processing listed elsewhere in the Act.
Article 14 prohibits processing data revealing racial or genetic origin, religious, political, philosophical or trade-union views, or health, unless the person gives express consent in a form leaving a written trace, the data has become manifestly public, or the processing is necessary for historical or scientific purposes or to safeguard the person's vital interests, with article 15 requiring the INPDP's separate authorization for that processing (except health data).
Article 27 requires the person's express, written consent before processing, and article 31 requires advance written notice of the processing's purpose, its recipients, the person's access and objection rights, the retention period, and the destination country of any transfer.
Articles 32 to 43 give the data subject a right of access, rectification, and objection, enforceable before the INPDP, and articles 51 and 52 require the INPDP's prior authorization before any transfer of personal data abroad, conditioned on the destination country assuring an adequate level of protection. Article 50 separately bars any transfer of personal data abroad capable of harming public security or Tunisia's vital interests, regardless of that authorization. Article 20 makes the data controller and processor civilly liable for a breach of the Act's provisions.
What it requires