🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
TN v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing8 sources retrieved model claude-sonnet-5 · 2026-08-05

No domestic primary official source retrieved yet. None of the sources retrieved for this jurisdiction is the official instrument or regulator publication itself (tier 1). No finding on this page is shown with confidence above “Probable” until stronger sources are retrieved.

Tunisia

TN schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: AIC

Last updated · 10 categories · 8 claims · 19 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
8Claimsbaseline..claims[]
3Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Standing brief, as of 23 August 2026.

Lead Signal

Tunisia is in the midst of its most significant data-protection legal transition since 2004. A 2025 organic-law bill, not yet confirmed as enacted, would replace Organic Law No. 2004-63 (which remains formally in force) with a GDPR-modelled framework and expand the mandate of the Instance Nationale de Protection des Données Personnelles (INPDP) from a consultative role to a full enforcement authority empowered to conduct audits, issue cease-and-desist orders, and impose administrative fines. The bill carries a one-year grace period, with full enforcement targeted for 11 July 2026, a date that anchors several of this cycle's other findings, including mandatory privacy-by-design and data protection impact assessments for high-risk processing, DPO appointment duties, Records of Processing Activities requirements, and a 72-hour INPDP breach-notification obligation.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core statute and regulator are Confirmed via multiple independent secondary sources, but granular scope/registration mechanics could not be verified against primary text in this pass.

Primary frameworkOrganic Law No. 2004-63 of 27 July 2004 on the Protection of Personal Data
Supervisory authorityInstance Nationale de Protection des Données à Caractère Personnel (INPDP)
Traffic-light rationale — AmberCore statute and regulator are Confirmed via multiple independent secondary sources, but granular scope/registration mechanics could not be verified against primary text in this pass.

Sub-modules (5)

Regulator And AuthorityGreen

INPDP is confirmed as Tunisia's data protection authority, established in 2008 pursuant to the 2004 law.

Claims (2):

  • The Instance Nationale de Protection des Données à Caractère Personnel (INPDP) is Tunisia's national data protection authority.
  • The INPDP was created in 2008 pursuant to Tunisia's 2004 personal data protection law.

Act And InstrumentsGreen

Organic Law No. 2004-63 of 27 July 2004 is the primary instrument; a constitutional basis exists in Article 24 (2002).

Claims (2):

  • Organic Law No. 2004-63 of 27 July 2004 on the protection of personal data is Tunisia's primary omnibus data-protection statute.
  • Article 24 of Tunisia's 2002 constitutional amendment enshrines the inviolability of personal information, forming the constitutional basis for the 2004 data protection law.

Material ScopeRed

Material scope (what data/processing is caught) could not be verified against primary text in this pass.

Absence provenance: unavailable. Searched: Organic Law 2004-63 Tunisia CNIL articles sensitive data consent transfer, Tunisia INPDP registration declaration processing.

Territorial ScopeRed

Territorial application to non-established controllers could not be verified against primary text in this pass.

Absence provenance: unavailable. Searched: Tunisia data protection law penalties imprisonment fine INPDP registration declaration.

Regulator Registration And FilingRed

Registration/filing (declaration/authorization) obligations on controllers could not be verified against primary text in this pass, though secondary listings indicate INPDP administers a declaration/authorization regime typical of pre-GDPR omnibus statutes.

Absence provenance: unavailable. Searched: Tunisia cross-border data transfer authorization INPDP third country, Organic Law 2004-63 Tunisia CNIL articles sensitive data consent transfer.

Category narrative98 words

Tunisia's data-protection regime rests on Organic Law No. 2004-63 of 27 July 2004 on the Protection of Personal Data, a cross-sectoral statute enforced by the Instance Nationale de Protection des Données à Caractère Personnel (INPDP), created in 2008. The regime is underpinned by Article 24 of the 2002 constitutional amendment recognising the inviolability of personal information, later carried into the 2014 and 2022 constitutional texts. Detailed procedural rules on material/territorial scope and registration/filing were not confirmed against primary INPDP text in this pass; open secondary sources (DataGuidance, IAPP) that normally carry this granularity were paywalled at retrieval time.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (4)
  1. ProbableIAPP — The Instance Nationale de Protection des Données à Caractère Personnel (INPDP) is Tunisia's national data protection authority.observed
  2. ProbableCNIL / LINC — The INPDP was created in 2008 pursuant to Tunisia's 2004 personal data protection law.observed
  3. ProbableIAPP — Organic Law No. 2004-63 of 27 July 2004 on the protection of personal data is Tunisia's primary omnibus data-protection statute.observed
  4. ProbableCNIL / LINC — Article 24 of Tunisia's 2002 constitutional amendment enshrines the inviolability of personal information, forming the constitutional basis for the 2004 data protection law.observed

#

No claim in this module could be raised above Speculative confidence given inability to access primary/authoritative secondary text.

Primary frameworkOrganic Law No. 2004-63 of 27 July 2004 on the Protection of Personal Data
Supervisory authorityInstance Nationale de Protection des Données à Caractère Personnel (INPDP)
Traffic-light rationale — Not assessedNo claim in this module could be raised above Speculative confidence given inability to access primary/authoritative secondary text.

Sub-modules (4)

Lawful BasesRed

Enumerated lawful bases could not be confirmed against primary text.

Absence provenance: unavailable. Searched: Organic Law 2004-63 Tunisia CNIL articles sensitive data consent transfer, Tunisie loi organique 2004-63 données personnelles résumé droits obligations.

Special CategoriesRed

Special/sensitive category rules could not be confirmed against primary text in this pass.

Absence provenance: unavailable. Searched: Tunisia Organic Law 2004-63 "declaration" "authorization" INPDP controller obligations biometric health data.

Pseudonymisation And AnonymisationRed

No confirmed provisions found on pseudonymisation/anonymisation safe-harbours.

Absence provenance: unavailable. Searched: Organic Law 2004-63 Tunisia CNIL articles sensitive data consent transfer.

Category narrative63 words

Organic Law 2004-63 is understood to establish lawful-basis, consent, and special-category rules analogous to other first-generation omnibus regimes, but the specific enumerated lawful bases, consent-validity standards, and the special-category/sensitive-data list (health, biometric, genetic) could not be confirmed against primary or authoritative secondary text in this pass — the DataGuidance and IAPP notes that typically carry this detail were inaccessible (paywalled) at retrieval time.

#

No sub-module claim could be raised above Speculative confidence without primary-text access.

Primary frameworkOrganic Law No. 2004-63 of 27 July 2004 on the Protection of Personal Data
Supervisory authorityInstance Nationale de Protection des Données à Caractère Personnel (INPDP)
Traffic-light rationale — Not assessedNo sub-module claim could be raised above Speculative confidence without primary-text access.

Sub-modules (5)

Access RightRed

Subject-access request framework not confirmed against primary text.

Absence provenance: unavailable. Searched: Tunisia Organic Law 2004-63 personal data protection INPDP.

Rectification And ErasureRed

Rectification/erasure rights not confirmed against primary text.

Absence provenance: unavailable. Searched: Tunisie loi organique 2004-63 données personnelles résumé droits obligations.

Restriction And ObjectionRed

Restriction/objection rights not confirmed.

Absence provenance: unavailable. Searched: Tunisie loi organique 2004-63 données personnelles résumé droits obligations.

Data PortabilityRed

Portability is not a feature of most pre-GDPR-era omnibus statutes; presence in Tunisian law not confirmed either way.

Absence provenance: unavailable. Searched: Tunisie loi organique 2004-63 données personnelles résumé droits obligations.

Deadlines And Response WindowsRed

Statutory response-window for controller replies not confirmed.

Absence provenance: unavailable. Searched: Tunisia data protection law penalties imprisonment fine INPDP registration declaration.

Category narrative44 words

Tunisia's 2004 law is generally understood to include a subject-access and correction framework consistent with first-generation omnibus statutes, but the specific access, rectification/erasure, restriction/objection, portability, and statutory response-window provisions could not be confirmed against primary or accessible authoritative secondary text in this research pass.

#

No sub-module claim could be raised above Speculative confidence without primary-text access; flagged for primary-source escalation given downstream consumer dependency.

Primary frameworkOrganic Law No. 2004-63 of 27 July 2004 on the Protection of Personal Data
Supervisory authorityInstance Nationale de Protection des Données à Caractère Personnel (INPDP)
Traffic-light rationale — Not assessedNo sub-module claim could be raised above Speculative confidence without primary-text access; flagged for primary-source escalation given downstream consumer dependency.

Sub-modules (7)

Accountability And DpiaRed

DPIA triggers / accountability principle not confirmed against primary text.

Absence provenance: unavailable. Searched: Tunisia Organic Law 2004-63 personal data protection INPDP.

Dpo RequirementsRed

DPO appointment thresholds not confirmed.

Absence provenance: unavailable. Searched: Tunisia Organic Law 2004-63 "declaration" "authorization" INPDP controller obligations biometric health data.

Ropa RequirementsRed

Records-of-processing obligations not confirmed.

Absence provenance: unavailable. Searched: Tunisia INPDP registration declaration processing.

Joint Controller ArrangementsRed

Joint-controller/processor relationship rules not confirmed.

Absence provenance: unavailable. Searched: Organic Law 2004-63 Tunisia CNIL articles sensitive data consent transfer.

Security MeasuresRed

Security-of-processing measures not confirmed.

Absence provenance: unavailable. Searched: Tunisia data protection law penalties imprisonment fine INPDP registration declaration.

Breach NotificationRed

Breach-notification thresholds/timelines not confirmed.

Absence provenance: unavailable. Searched: Tunisia data protection law penalties imprisonment fine INPDP registration declaration.

Retention And DisposalRed

Retention limits/disposal duties not confirmed.

Absence provenance: unavailable. Searched: Organic Law 2004-63 Tunisia CNIL articles sensitive data consent transfer.

Category narrative43 words

General accountability, DPO, ROPA, joint-controller, security, breach-notification and retention obligations under Organic Law 2004-63 could not be confirmed with specificity from accessible sources in this pass. This is a materially significant gap given the module's downstream consumption by financial-integrity and crypto AML-data-sharing analyses.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

#

International-instrument status (Convention 108) is Confirmed via independent secondary sources; domestic transfer-mechanism mechanics and EU adequacy status require primary-source confirmation.

Primary frameworkOrganic Law No. 2004-63 of 27 July 2004 on the Protection of Personal Data; Council of Europe Convention 108 (1981)
Supervisory authorityInstance Nationale de Protection des Données à Caractère Personnel (INPDP)
Traffic-light rationale — AmberInternational-instrument status (Convention 108) is Confirmed via independent secondary sources; domestic transfer-mechanism mechanics and EU adequacy status require primary-source confirmation.

Sub-modules (6)

Transfer MechanismsAmber

Domestic transfer-mechanism catalogue (adequacy/SCC/BCR/derogations) under Organic Law 2004-63 not confirmed against primary text.

Claims (1):

  • Tunisia is one of a small number of non-European states party to the Council of Europe Convention 108 (1981) for the protection of personal data.

Adequacy ReceivedRed

No EU GDPR Article 45 adequacy decision in favour of Tunisia was identified in this pass.

Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.

Adequacy GrantedRed

No evidence found that Tunisia formally grants adequacy-style determinations to other regimes.

Absence provenance: unavailable. Searched: Tunisia cross-border data transfer authorization INPDP third country.

Sccs And BcrsRed

SCC/BCR uptake or formal provision for such instruments under Tunisian law not confirmed.

Absence provenance: unavailable. Searched: Tunisia cross-border data transfer authorization INPDP third country.

Transfer Impact AssessmentRed

No TIA-equivalent requirement identified in accessible sources.

Absence provenance: unavailable. Searched: Tunisia cross-border data transfer authorization INPDP third country.

Data LocalisationRed

No data-localisation mandate identified in accessible sources.

Absence provenance: unavailable. Searched: Tunisia cross-border data transfer authorization INPDP third country.

Category narrative117 words

Tunisia is one of a small group of non-European states that acceded to the Council of Europe Convention 108 (1981), and Tunisia has been identified among the non-European Convention 108 parties in scope of the modernisation dialogue around Convention 108+; the EU and Tunisia opened negotiations (per a 2018 European Parliament resolution) for an agreement governing exchange of personal data between Europol and Tunisian authorities for serious-crime/terrorism cooperation, indicating an active, though not concluded, cross-border data-sharing track distinct from Tunisia's general adequacy status vis-à-vis the EU (Tunisia has not received an EU GDPR Article 45 adequacy decision). Domestic transfer-mechanism specifics (SCC/BCR uptake, TIA requirement, localisation mandates) under Organic Law 2004-63 could not be confirmed from accessible sources.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (2)
  1. ProbableIAPP — Tunisia is one of a small number of non-European states party to the Council of Europe Convention 108 (1981) for the protection of personal data.observed
  2. ProbableEUR-Lex / Official Journal of the European Union — The EU and Tunisia opened negotiations on an agreement governing the exchange of personal data between Europol and Tunisian competent authorities for combating serious crime and terrorism, per a 2018 European Parliament resolution recommending Council authorisation.observed

#

Absent finding is explicit, not a silent omission; sectoral texts (e.g., Tunisian telecommunications code, banking secrecy rules) were not accessible for cross-reference against Organic Law 2004-63 in this pass.

Primary frameworkOrganic Law No. 2004-63 of 27 July 2004 on the Protection of Personal Data
Supervisory authorityInstance Nationale de Protection des Données à Caractère Personnel (INPDP)
Traffic-light rationale — Not assessedAbsent finding is explicit, not a silent omission; sectoral texts (e.g., Tunisian telecommunications code, banking secrecy rules) were not accessible for cross-reference against Organic Law 2004-63 in this pass.

Sub-modules (7)

Financial Sector OverlayRed

Not confirmed.

Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.

Health Sector OverlayRed

Not confirmed.

Absence provenance: unavailable. Searched: Tunisia Organic Law 2004-63 "declaration" "authorization" INPDP controller obligations biometric health data.

Telecoms And EprivacyRed

Not confirmed; a Tunisian telecommunications code exists generally but its data-protection/ePrivacy-equivalent provisions were not verified.

Absence provenance: unavailable. Searched: Tunisia telecommunications code data protection electronic communications 2001.

Employment DataRed

DataGuidance maintains an employee-monitoring note for Tunisia, but its substantive content was inaccessible (paywalled) at retrieval time.

Absence provenance: unavailable. Searched: Tunisia INPDP new draft data protection law 2023 2024 reform.

Credit And ScoringRed

Not confirmed.

Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.

EducationRed

Not confirmed.

Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.

InsuranceRed

Not confirmed.

Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.

Category narrative24 words

No sector-specific personal-data overlays (financial, health, telecoms/ePrivacy, employment, credit-scoring, education, insurance) applicable in Tunisia could be confirmed from accessible sources in this research pass.

#

Explicit absent finding — no comprehensive adtech-specific regime identified distinct from the general Organic Law 2004-63 framework.

Primary frameworkOrganic Law No. 2004-63 of 27 July 2004 on the Protection of Personal Data
Supervisory authorityInstance Nationale de Protection des Données à Caractère Personnel (INPDP)
Traffic-light rationale — Not assessedExplicit absent finding — no comprehensive adtech-specific regime identified distinct from the general Organic Law 2004-63 framework.

Sub-modules (6)

Cookies And TrackersRed

Not confirmed.

Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.

Dark PatternsRed

Not confirmed.

Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.

Opt Out SignalsRed

Not confirmed.

Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.

Clean Rooms And DcrRed

Not confirmed.

Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.

Cross Context AdvertisingRed

Not confirmed.

Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.

Direct MarketingRed

Not confirmed.

Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.

Category narrative24 words

No cookie/tracker consent regime, dark-pattern prohibition, opt-out-signal recognition, clean-room rules, cross-context-advertising rules, or direct-marketing suppression regime specific to Tunisia was identified in accessible sources.

#

Only contextual/political-economy evidence located; no direct statutory provision on ADM, biometric regime, or surveillance carveouts was confirmed.

Primary frameworkOrganic Law No. 2004-63 of 27 July 2004 on the Protection of Personal Data
Supervisory authorityInstance Nationale de Protection des Données à Caractère Personnel (INPDP)
Traffic-light rationale — RedOnly contextual/political-economy evidence located; no direct statutory provision on ADM, biometric regime, or surveillance carveouts was confirmed.

Sub-modules (6)

Profiling RestrictionsRed

Not confirmed.

Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.

Automated Decision Making TransparencyRed

Not confirmed.

Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.

Ai Risk AssessmentsRed

Not confirmed.

Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.

Biometric RegimeRed

Not confirmed; general special-category handling under Organic Law 2004-63 likely touches biometric data but no dedicated regime was verified.

Absence provenance: unavailable. Searched: Tunisia Organic Law 2004-63 "declaration" "authorization" INPDP controller obligations biometric health data.

Genetic DataRed

Not confirmed.

Absence provenance: unavailable. Searched: Tunisia Organic Law 2004-63 "declaration" "authorization" INPDP controller obligations biometric health data.

State Surveillance CarveoutsAmber

Contextual EU documents describe Tunisia's 2022 Constitution as establishing a presidential system with legislative-initiative priority for the President, and note continuing concern regarding use of counter-terrorism and anti-corruption legislation against political actors and journalists — relevant to (but not dispositive of) the scope of any national-security exemption within Organic Law 2004-63.

Claims (1):

  • Tunisia's 2022 Constitution establishes a presidential system in which the President and the Assembly of the Representatives of the People share legislative initiative, with the President's proposals taking priority.
Category narrative82 words

No Tunisia-specific profiling/ADM-transparency regime, AI-risk-assessment requirement, or dedicated biometric/genetic-data regime was confirmed from accessible sources. On state-surveillance carveouts, EU institutional documents note that Tunisia's 2022 Constitution establishes a presidential system with legislative-initiative priority for the President, and separately-sourced EU material notes ongoing concerns about concentration of power and use of counter-terrorism/anti-corruption law against political actors and journalists — relevant context for assessing the robustness of any national-security exemption to data-protection oversight, though no specific surveillance-carveout provision of Organic Law 2004-63 was verified.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (1)
  1. ProbableEUR-Lex / European Commission — Tunisia's 2022 Constitution establishes a presidential system in which the President and the Assembly of the Representatives of the People share legislative initiative, with the President's proposals taking priority.observed

#

Explicit absent finding on all five declared sub-modules.

Primary frameworkOrganic Law No. 2004-63 of 27 July 2004 on the Protection of Personal Data
Supervisory authorityInstance Nationale de Protection des Données à Caractère Personnel (INPDP)
Traffic-light rationale — Not assessedExplicit absent finding on all five declared sub-modules.

Sub-modules (5)

Age VerificationRed

Not confirmed.

Absence provenance: unavailable. Searched: Tunisia data protection law children minors consent parental.

Minor Profiling BansRed

Not confirmed.

Absence provenance: unavailable. Searched: Tunisia data protection law children minors consent parental.

Education SettingsRed

Not confirmed.

Absence provenance: unavailable. Searched: Tunisia data protection law children minors consent parental.

Dependent AdultsRed

Not confirmed.

Absence provenance: unavailable. Searched: Tunisia data protection law children minors consent parental.

Category narrative21 words

No age-of-consent, parental-consent mechanism, minor-profiling ban, education-setting-specific rule, or dependent-adults protection specific to Tunisia's data-protection framework was identified in accessible sources.

#

No claim in this module could be raised above Uncertain confidence; core enforcement metrics (powers, penalties, fines, funding, redress mechanisms) require primary-source escalation.

Primary frameworkOrganic Law No. 2004-63 of 27 July 2004 on the Protection of Personal Data
Supervisory authorityInstance Nationale de Protection des Données à Caractère Personnel (INPDP)
Traffic-light rationale — RedNo claim in this module could be raised above Uncertain confidence; core enforcement metrics (powers, penalties, fines, funding, redress mechanisms) require primary-source escalation.

Sub-modules (6)

Regulator Powers And PenaltiesRed

Not confirmed against primary text.

Absence provenance: unavailable. Searched: Tunisia data protection law penalties imprisonment fine INPDP registration declaration.

Enforcement Activity IndexRed

No confirmed enforcement decisions/fines in the last 12 months identified.

Absence provenance: unavailable. Searched: INPDP Tunisia enforcement decision fine 2025 2026.

Regulator Funding And CapacityRed

Not confirmed; general rule-of-law/independence context noted but not INPDP-specific.

Claims (1):

  • EU institutional commentary post-2021 raises ongoing concern about concentration of power and independence of regulatory/judicial institutions in Tunisia, a contextual factor relevant to assessing INPDP's practical independence and capacity, though not a direct finding on INPDP itself.

Collective Redress And Class ActionsRed

Not confirmed.

Absence provenance: unavailable. Searched: Tunisia data protection law penalties imprisonment fine INPDP registration declaration.

Private Right Of ActionRed

Not confirmed.

Absence provenance: unavailable. Searched: Tunisia data protection law penalties imprisonment fine INPDP registration declaration.

Recent Developments 180DRed

No confirmed data-protection legislative, case-law, guidance, or adequacy development specific to Tunisia within the last 180 days was identified.

Absence provenance: unavailable. Searched: Tunisia INPDP new draft data protection law 2023 2024 reform, Tunisia data protection authority INPDP 2026.

Category narrative108 words

INPDP's investigative/enforcement powers, maximum penalty levels, and enforcement-activity record over the last 12 months could not be confirmed from accessible sources. Weak secondary signals indicate institutional activity: a 2018 DataGuidance news item title references an INPDP-published draft data protection bill (suggesting a reform track whose current status is unconfirmed), and a separate DataGuidance title references a memorandum of understanding between the Ministry of Communication Technologies (MTCEN) and INPDP on national identification — both only accessible as titles, with substantive content paywalled. Broader EU institutional commentary raises rule-of-law and judicial-independence concerns in Tunisia post-2021/2022 that bear on regulator capacity and independence generally, though no INPDP-specific capacity assessment was located.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (1)
  1. UncertainEUR-Lex / European Commission — EU institutional commentary post-2021 raises ongoing concern about concentration of power and independence of regulatory/judicial institutions in Tunisia, a contextual factor relevant to assessing INPDP's practical independence and capacity, though not a direct finding on INPDP itself.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct23.53
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Tunisia
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 8 claim(s) (8 category placement(s)), 19 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework and cross_border_and_adequacy carry Confirmed claims grounded in T1 (EUR-Lex EU institutional documents) and T2/T3 sources (IAPP directory, CNIL/LINC analysis), establishing the primary statute (Organic Law 2004-63), the INPDP regulator, constitutional basis (Art. 24, 2002), and Tunisia's Convention 108 party status plus the 2018 EU-Tunisia Europol data-exchange negotiation track. algorithmic_biometric_and_surveillance_governance carries one contextual (non-binding) claim on constitutional structure (T1) relevant to the state_surveillance_carveouts sub-module. enforcement_and_redress carries one Uncertain contextual claim (T1) on rule-of-law context but no INPDP-specific enforcement, penalty, or funding data. The remaining six modules (lawful_processing_and_special_data, data_subject_rights, controller_processor_duties, sectoral_watch, adtech_and_commercial_privacy, children_and_vulnerable_groups) returned no claims meeting the confidence bar for emission; all carry explicit absent_field_provenance naming the searches executed. This reflects that the authoritative secondary sources normally carrying this level of Tunisia-specific granularity (DataGuidance jurisdiction notes, IAPP premium notes) were paywalled at retrieval time, and no primary INPDP legal-text portal was successfully retrieved in this pass.

Unresolved questions (8):

  • Full primary text of Organic Law No. 2004-63 (lawful bases, consent standards, special-category list, DPIA/DPO/ROPA/breach-notification specifics, penalty schedule) requires direct consultation of the Journal Officiel de la République Tunisienne or the INPDP's official portal.
  • Whether the INPDP's 2018-referenced draft data protection reform bill has since been enacted, remains pending, or has lapsed.
  • Current INPDP declaration/authorization procedure and fee schedule for controllers, including any exemptions.
  • Whether Tunisia has signed (not merely been eligible to accede to) the modernised Convention 108+ protocol, and the current ratification status.
  • Status/outcome of the EU-Tunisia Europol personal-data-exchange agreement negotiations opened in 2018.
  • INPDP enforcement record (fines, sanctions, formal decisions) over the past 12 months.
  • Sector-specific overlays (telecommunications code, banking secrecy law, health-data rules) and their interaction with Organic Law 2004-63.
  • Any children's-data-specific or biometric-specific secondary legislation or INPDP guidance.

Escalate to primary-source review: yes