Tunisia Organic Law on Personal Data Protection (Law No. 2004-63)
Tunisia's Organic Law No. 2004-63 on the Protection of Personal Data (2004) was the first comprehensive data protection law in Africa and the Arab world. The National Authority for the Protection of Personal Data (INPDP) oversees compliance. The law establishes processing principles, individual rights, registration requirements, and cross-border transfer restrictions. A reform aligning with GDPR has been under consideration.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (26)
Accountability
| Code | Title |
|---|---|
| TN-DPL-16 | Records of Processing Activities |
Assurance
| Code | Title |
|---|---|
| TN-DPL-19 | Internal Audit and Compliance Monitoring |
Chapter I - General Provisions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 6 | Writing |
Chapter II - Conditions of Processing
| Code | Title |
|---|---|
| Art. 10 | Data and Data Governance |
| Art. 14 | Human Oversight |
| Art. 16 | Obligations of Providers of High-Risk AI Systems |
| Art. 18 | Documentation Keeping |
| Art. 7 | Minimum Standards |
Chapter III - Collection, Conservation, Deletion and Destruction
| Code | Title |
|---|---|
| Art. 22 | Authorised Representatives of Providers of High-Risk AI Systems |
| Art. 24 | Restrictions on Processing Unique Identification Information |
| Art. 26 | Obligations of Deployers of High-Risk AI Systems |
Chapter IV - Communication and Transfer
| Code | Title |
|---|---|
| Art. 47 | Existing Legal Procedures |
| Art. 50 | Transparency Obligations for Providers and Deployers of Certain AI Systems |
Chapter V - Specific Processing Categories
| Code | Title |
|---|---|
| Art. 52 | Procedure |
| Art. 55 | Obligations for Providers of General-Purpose AI Models with Systemic Risk |
| Art. 58 | Scientific Research Data |
| Art. 60 | Initiation of Proceedings |
Chapter VI - National Data Protection Authority (INPDP)
| Code | Title |
|---|---|
| Art. 75 | Administrative Fines |
| Art. 77 | Powers of the Commissioner |
Chapter VII - Sanctions
| Code | Title |
|---|---|
| Art. 90 | Establishment and Competences |
| Art. 94 | Enhanced Penalties |
| Art. 95 | Inspection Supervision |
Cross-Border Transfers
| Code | Title |
|---|---|
| TN-DPL-04 | International Data Transfers |
Data Management
| Code | Title |
|---|---|
| TN-DPL-06 | Data Quality and Accuracy |
Electronic Communications
| Code | Title |
|---|---|
| TN-DPL-12 | Direct Marketing and Cookies |
Governance
| Code | Title |
|---|---|
| TN-DPL-17 | Privacy Governance and Accountability |
Incident Response
| Code | Title |
|---|---|
| TN-DPL-09 | Data Breach Notification |
Information Security
| Code | Title |
|---|---|
| TN-DPL-08 | Security of Processing |
Lawfulness
| Code | Title |
|---|---|
| TN-DPL-02 | Lawful Basis and Consent |
Lifecycle Management
| Code | Title |
|---|---|
| TN-DPL-07 | Retention and Destruction |
People
| Code | Title |
|---|---|
| TN-DPL-18 | Training and Awareness |
Regulator Engagement
| Code | Title |
|---|---|
| TN-DPL-01 | INPDP Notification and Authorisation |
Rights Management
| Code | Title |
|---|---|
| TN-DPL-03 | Data Subject Rights Handling |
Special Categories
| Code | Title |
|---|---|
| TN-DPL-05 | Sensitive Data Processing |
Third Party Management
| Code | Title |
|---|---|
| TN-DPL-10 | Processor Oversight |
Transparency
| Code | Title |
|---|---|
| TN-DPL-11 | Privacy Notice and Transparency |
Vulnerable Subjects
| Code | Title |
|---|---|
| TN-DPL-15 | Children and Minors |
Workplace Privacy
| Code | Title |
|---|---|
| TN-DPL-13 | Employee and HR Data |
Workplace and Public Surveillance
| Code | Title |
|---|---|
| TN-DPL-14 | Video Surveillance |
Your Compliance Coverage
If you comply with Tunisia Organic Law on Personal Data Protection (Law No. 2004-63), you already cover:
EU AI Act
28%
12 controls mapped
Compare →Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data
28%
12 controls mapped
Compare →South Korea PIPA
28%
12 controls mapped
Compare →+ 605 more: LGPD (28%), Ethiopia Personal Data Protection Proclamation (No. 1321/2024) (26%)
See all 608 mapped frameworks ↓Maps to 608 other frameworks
Frequently Asked Questions
What is Tunisia Organic Law on Personal Data Protection (Law No. 2004-63)?
Tunisia Organic Law on Personal Data Protection (Law No. 2004-63) is a compliance framework from Tunisia with 26 domains and 43 controls. Tunisia's Organic Law No. 2004-63 on the Protection of Personal Data (2004) was the first comprehensive data protection law in Africa and the Arab world. The National Authority for the Protection of Personal Data (INPDP) oversees compliance. The law establishes processing principles, individual rights, registration requirements, and cross-border transfer restrictions. A reform aligning with GDPR has been under consideration. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Tunisia Organic Law on Personal Data Protection (Law No. 2004-63) have?
Tunisia Organic Law on Personal Data Protection (Law No. 2004-63) has 43 controls organised across 26 domains. The largest domains are Chapter I - General Provisions (5 controls), Chapter II - Conditions of Processing (5 controls), Chapter V - Specific Processing Categories (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Tunisia Organic Law on Personal Data Protection (Law No. 2004-63) map to?
Tunisia Organic Law on Personal Data Protection (Law No. 2004-63) maps to 608 other compliance frameworks. The top mapping partners are EU AI Act (28% coverage), Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data (28% coverage), South Korea PIPA (28% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Tunisia Organic Law on Personal Data Protection (Law No. 2004-63) compliance?
Start your Tunisia Organic Law on Personal Data Protection (Law No. 2004-63) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Tunisia Organic Law on Personal Data Protection (Law No. 2004-63) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 43 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required