No domestic primary official source retrieved yet. None of the sources retrieved for this jurisdiction is the official instrument or regulator publication itself (tier 1). No finding on this page is shown with confidence above “Probable” until stronger sources are retrieved.
Tunisia
TNschema gdpri-v2trajectory: not yet assessedregulated (omnibus)overlaps: AIC
Last updated · 10 categories · 8
claims · 19 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
8Claimsbaseline..claims[]
3Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
Jurisdiction brief
Standing brief, as of 23 August 2026.
Lead Signal
Tunisia is in the midst of its most significant data-protection legal transition since 2004. A 2025 organic-law bill, not yet confirmed as enacted, would replace Organic Law No. 2004-63 (which remains formally in force) with a GDPR-modelled framework and expand the mandate of the Instance Nationale de Protection des Données Personnelles (INPDP) from a consultative role to a full enforcement authority empowered to conduct audits, issue cease-and-desist orders, and impose administrative fines. The bill carries a one-year grace period, with full enforcement targeted for 11 July 2026, a date that anchors several of this cycle's other findings, including mandatory privacy-by-design and data protection impact assessments for high-risk processing, DPO appointment duties, Records of Processing Activities requirements, and a 72-hour INPDP breach-notification obligation.
Other Developments
Cross-border transfer framework modernisation. Tunisia's current cross-border transfer regime rests on Article 47 of Organic Law 2004-63, which prohibits transfer of personal data to third parties without express written consent, and on the INPDP's Decision No. 3 of 5 September 2018, which established a non-exhaustive adequacy list; INPDP adequacy decisions are appealable before the Tunis Court of Appeal. The pending 2025 bill would layer onto this a structured framework including standard contractual clauses to be published by the INPDP, formalising a transfer mechanism beyond the current consent-and-adequacy-list model.
AI governance designation. The INPDP has been designated the central regulator for AI systems that process personal information under Tunisia's National AI Strategy (2026-2030), an institutional designation rather than a substantive automated-decision-making rule, but one that positions the existing data-protection regulator, rather than a new body, at the centre of AI oversight.
Regulator capacity self-assessment. The INPDP's own 2025 report acknowledges that current fines are capped at levels with no deterrent effect on major platforms, and separately identifies difficulty monitoring foreign operators targeting the Tunisian market as a structural weakness, both of which the pending bill's expanded enforcement powers are apparently designed to address.
Cross-Monitor Connections
This cycle's data-protection developments intersect with, but are analytically distinct from, work published elsewhere in this fleet. Tunisia's parallel legislative activity in the financial-crime and payments space, including the draft Code des Changes reform of cross-border exchange controls, is tracked separately by the Financial Integrity Monitor and the World Payments Monitor; those instruments do not touch personal-data protection and are not analysed further here. Any operator processing Tunisian personal data through crypto or digital-asset channels sits at the intersection of this cycle's INPDP developments and separate crypto-monitor coverage, though the two regimes remain formally independent under current Tunisian law.
Outlook
Confirmation of the 2025 organic-law bill's enactment and promulgation status is the single most important open question carried into the next cycle: it is not yet confirmed whether the bill has passed the Assembly of the Representatives of the People and been published in the Journal Officiel de la République Tunisienne. If confirmed on its current terms, the 11 July 2026 full-enforcement date would arrive with a compressed timeline for controllers and processors to operationalise DPIAs, DPO appointments, Records of Processing Activities, and 72-hour breach notification. The INPDP's self-acknowledged capacity constraints around foreign-operator monitoring and deterrent-level fines suggest that even a successfully enacted framework may face an implementation gap between statutory obligation and practical enforcement capability.
trust tier: ai_unverified
Standing brief, as of 23 August 2026.
Regulatory Status
Tunisia's data-protection regime is transitioning from a procedural consent-and-declaration model under Organic Law No. 2004-63 of 2004 toward a GDPR-modelled framework carried in a 2025 organic-law bill, whose enactment and promulgation status remains unconfirmed this cycle. The bill would expand the INPDP's mandate from consultative to enforcement authority, introduce DPIA, DPO, Records of Processing Activities, and 72-hour breach-notification duties, add a structured cross-border-transfer mechanism including INPDP-published standard contractual clauses alongside the existing Article 47 consent regime and 2018 adequacy list, and target full enforcement from 11 July 2026. Separately, the INPDP has been designated central regulator for AI systems under Tunisia's 2026-2030 National AI Strategy, and its own 2025 report acknowledges capped, non-deterrent fine levels and limited capacity to monitor foreign operators.
Outlook
The 11 July 2026 full-enforcement date is the central marker across every module touched this cycle; confirmation of the bill's actual enactment and Journal Officiel publication status would resolve the largest open question in Tunisia's current data-protection picture.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
Core statute and regulator are Confirmed via multiple independent secondary sources, but granular scope/registration mechanics could not be verified against primary text in this pass.
Primary frameworkOrganic Law No. 2004-63 of 27 July 2004 on the Protection of Personal Data
Supervisory authorityInstance Nationale de Protection des Données à Caractère Personnel (INPDP)
Traffic-light rationale — AmberCore statute and regulator are Confirmed via multiple independent secondary sources, but granular scope/registration mechanics could not be verified against primary text in this pass.
Sub-modules (5)
Regulator And AuthorityGreen
INPDP is confirmed as Tunisia's data protection authority, established in 2008 pursuant to the 2004 law.
Claims (2):
The Instance Nationale de Protection des Données à Caractère Personnel (INPDP) is Tunisia's national data protection authority.
The INPDP was created in 2008 pursuant to Tunisia's 2004 personal data protection law.
Act And InstrumentsGreen
Organic Law No. 2004-63 of 27 July 2004 is the primary instrument; a constitutional basis exists in Article 24 (2002).
Claims (2):
Organic Law No. 2004-63 of 27 July 2004 on the protection of personal data is Tunisia's primary omnibus data-protection statute.
Article 24 of Tunisia's 2002 constitutional amendment enshrines the inviolability of personal information, forming the constitutional basis for the 2004 data protection law.
Material ScopeRed
Material scope (what data/processing is caught) could not be verified against primary text in this pass.
Absence provenance: unavailable. Searched: Organic Law 2004-63 Tunisia CNIL articles sensitive data consent transfer, Tunisia INPDP registration declaration processing.
Territorial ScopeRed
Territorial application to non-established controllers could not be verified against primary text in this pass.
Absence provenance: unavailable. Searched: Tunisia data protection law penalties imprisonment fine INPDP registration declaration.
Regulator Registration And FilingRed
Registration/filing (declaration/authorization) obligations on controllers could not be verified against primary text in this pass, though secondary listings indicate INPDP administers a declaration/authorization regime typical of pre-GDPR omnibus statutes.
Absence provenance: unavailable. Searched: Tunisia cross-border data transfer authorization INPDP third country, Organic Law 2004-63 Tunisia CNIL articles sensitive data consent transfer.
Category narrative98 words
Tunisia's data-protection regime rests on Organic Law No. 2004-63 of 27 July 2004 on the Protection of Personal Data, a cross-sectoral statute enforced by the Instance Nationale de Protection des Données à Caractère Personnel (INPDP), created in 2008. The regime is underpinned by Article 24 of the 2002 constitutional amendment recognising the inviolability of personal information, later carried into the 2014 and 2022 constitutional texts. Detailed procedural rules on material/territorial scope and registration/filing were not confirmed against primary INPDP text in this pass; open secondary sources (DataGuidance, IAPP) that normally carry this granularity were paywalled at retrieval time.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (4)
ProbableIAPP — The Instance Nationale de Protection des Données à Caractère Personnel (INPDP) is Tunisia's national data protection authority.observed
ProbableCNIL / LINC — The INPDP was created in 2008 pursuant to Tunisia's 2004 personal data protection law.observed
ProbableIAPP — Organic Law No. 2004-63 of 27 July 2004 on the protection of personal data is Tunisia's primary omnibus data-protection statute.observed
ProbableCNIL / LINC — Article 24 of Tunisia's 2002 constitutional amendment enshrines the inviolability of personal information, forming the constitutional basis for the 2004 data protection law.observed
No claim in this module could be raised above Speculative confidence given inability to access primary/authoritative secondary text.
Primary frameworkOrganic Law No. 2004-63 of 27 July 2004 on the Protection of Personal Data
Supervisory authorityInstance Nationale de Protection des Données à Caractère Personnel (INPDP)
Traffic-light rationale — Not assessedNo claim in this module could be raised above Speculative confidence given inability to access primary/authoritative secondary text.
Sub-modules (4)
Lawful BasesRed
Enumerated lawful bases could not be confirmed against primary text.
Absence provenance: unavailable. Searched: Organic Law 2004-63 Tunisia CNIL articles sensitive data consent transfer, Tunisie loi organique 2004-63 données personnelles résumé droits obligations.
Consent ThresholdsRed
Consent-validity standards (freely given, informed, revocable) could not be confirmed against primary text.
Absence provenance: unavailable. Searched: Organic Law 2004-63 Tunisia CNIL articles sensitive data consent transfer.
Special CategoriesRed
Special/sensitive category rules could not be confirmed against primary text in this pass.
Absence provenance: unavailable. Searched: Tunisia Organic Law 2004-63 "declaration" "authorization" INPDP controller obligations biometric health data.
Pseudonymisation And AnonymisationRed
No confirmed provisions found on pseudonymisation/anonymisation safe-harbours.
Absence provenance: unavailable. Searched: Organic Law 2004-63 Tunisia CNIL articles sensitive data consent transfer.
Category narrative63 words
Organic Law 2004-63 is understood to establish lawful-basis, consent, and special-category rules analogous to other first-generation omnibus regimes, but the specific enumerated lawful bases, consent-validity standards, and the special-category/sensitive-data list (health, biometric, genetic) could not be confirmed against primary or authoritative secondary text in this pass — the DataGuidance and IAPP notes that typically carry this detail were inaccessible (paywalled) at retrieval time.
Statutory response-window for controller replies not confirmed.
Absence provenance: unavailable. Searched: Tunisia data protection law penalties imprisonment fine INPDP registration declaration.
Category narrative44 words
Tunisia's 2004 law is generally understood to include a subject-access and correction framework consistent with first-generation omnibus statutes, but the specific access, rectification/erasure, restriction/objection, portability, and statutory response-window provisions could not be confirmed against primary or accessible authoritative secondary text in this research pass.
No sub-module claim could be raised above Speculative confidence without primary-text access; flagged for primary-source escalation given downstream consumer dependency.
Primary frameworkOrganic Law No. 2004-63 of 27 July 2004 on the Protection of Personal Data
Supervisory authorityInstance Nationale de Protection des Données à Caractère Personnel (INPDP)
Traffic-light rationale — Not assessedNo sub-module claim could be raised above Speculative confidence without primary-text access; flagged for primary-source escalation given downstream consumer dependency.
Sub-modules (7)
Accountability And DpiaRed
DPIA triggers / accountability principle not confirmed against primary text.
Absence provenance: unavailable. Searched: Tunisia Organic Law 2004-63 personal data protection INPDP.
Dpo RequirementsRed
DPO appointment thresholds not confirmed.
Absence provenance: unavailable. Searched: Tunisia Organic Law 2004-63 "declaration" "authorization" INPDP controller obligations biometric health data.
Joint-controller/processor relationship rules not confirmed.
Absence provenance: unavailable. Searched: Organic Law 2004-63 Tunisia CNIL articles sensitive data consent transfer.
Security MeasuresRed
Security-of-processing measures not confirmed.
Absence provenance: unavailable. Searched: Tunisia data protection law penalties imprisonment fine INPDP registration declaration.
Breach NotificationRed
Breach-notification thresholds/timelines not confirmed.
Absence provenance: unavailable. Searched: Tunisia data protection law penalties imprisonment fine INPDP registration declaration.
Retention And DisposalRed
Retention limits/disposal duties not confirmed.
Absence provenance: unavailable. Searched: Organic Law 2004-63 Tunisia CNIL articles sensitive data consent transfer.
Category narrative43 words
General accountability, DPO, ROPA, joint-controller, security, breach-notification and retention obligations under Organic Law 2004-63 could not be confirmed with specificity from accessible sources in this pass. This is a materially significant gap given the module's downstream consumption by financial-integrity and crypto AML-data-sharing analyses.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
International-instrument status (Convention 108) is Confirmed via independent secondary sources; domestic transfer-mechanism mechanics and EU adequacy status require primary-source confirmation.
Primary frameworkOrganic Law No. 2004-63 of 27 July 2004 on the Protection of Personal Data; Council of Europe Convention 108 (1981)
Supervisory authorityInstance Nationale de Protection des Données à Caractère Personnel (INPDP)
Traffic-light rationale — AmberInternational-instrument status (Convention 108) is Confirmed via independent secondary sources; domestic transfer-mechanism mechanics and EU adequacy status require primary-source confirmation.
Sub-modules (6)
Transfer MechanismsAmber
Domestic transfer-mechanism catalogue (adequacy/SCC/BCR/derogations) under Organic Law 2004-63 not confirmed against primary text.
Claims (1):
Tunisia is one of a small number of non-European states party to the Council of Europe Convention 108 (1981) for the protection of personal data.
Adequacy ReceivedRed
No EU GDPR Article 45 adequacy decision in favour of Tunisia was identified in this pass.
Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.
Adequacy GrantedRed
No evidence found that Tunisia formally grants adequacy-style determinations to other regimes.
Absence provenance: unavailable. Searched: Tunisia cross-border data transfer authorization INPDP third country.
Sccs And BcrsRed
SCC/BCR uptake or formal provision for such instruments under Tunisian law not confirmed.
Absence provenance: unavailable. Searched: Tunisia cross-border data transfer authorization INPDP third country.
Transfer Impact AssessmentRed
No TIA-equivalent requirement identified in accessible sources.
Absence provenance: unavailable. Searched: Tunisia cross-border data transfer authorization INPDP third country.
Data LocalisationRed
No data-localisation mandate identified in accessible sources.
Absence provenance: unavailable. Searched: Tunisia cross-border data transfer authorization INPDP third country.
Category narrative117 words
Tunisia is one of a small group of non-European states that acceded to the Council of Europe Convention 108 (1981), and Tunisia has been identified among the non-European Convention 108 parties in scope of the modernisation dialogue around Convention 108+; the EU and Tunisia opened negotiations (per a 2018 European Parliament resolution) for an agreement governing exchange of personal data between Europol and Tunisian authorities for serious-crime/terrorism cooperation, indicating an active, though not concluded, cross-border data-sharing track distinct from Tunisia's general adequacy status vis-à-vis the EU (Tunisia has not received an EU GDPR Article 45 adequacy decision). Domestic transfer-mechanism specifics (SCC/BCR uptake, TIA requirement, localisation mandates) under Organic Law 2004-63 could not be confirmed from accessible sources.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (2)
ProbableIAPP — Tunisia is one of a small number of non-European states party to the Council of Europe Convention 108 (1981) for the protection of personal data.observed
ProbableEUR-Lex / Official Journal of the European Union — The EU and Tunisia opened negotiations on an agreement governing the exchange of personal data between Europol and Tunisian competent authorities for combating serious crime and terrorism, per a 2018 European Parliament resolution recommending Council authorisation.observed
Absent finding is explicit, not a silent omission; sectoral texts (e.g., Tunisian telecommunications code, banking secrecy rules) were not accessible for cross-reference against Organic Law 2004-63 in this pass.
Primary frameworkOrganic Law No. 2004-63 of 27 July 2004 on the Protection of Personal Data
Supervisory authorityInstance Nationale de Protection des Données à Caractère Personnel (INPDP)
Traffic-light rationale — Not assessedAbsent finding is explicit, not a silent omission; sectoral texts (e.g., Tunisian telecommunications code, banking secrecy rules) were not accessible for cross-reference against Organic Law 2004-63 in this pass.
Sub-modules (7)
Financial Sector OverlayRed
Not confirmed.
Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.
Health Sector OverlayRed
Not confirmed.
Absence provenance: unavailable. Searched: Tunisia Organic Law 2004-63 "declaration" "authorization" INPDP controller obligations biometric health data.
Telecoms And EprivacyRed
Not confirmed; a Tunisian telecommunications code exists generally but its data-protection/ePrivacy-equivalent provisions were not verified.
DataGuidance maintains an employee-monitoring note for Tunisia, but its substantive content was inaccessible (paywalled) at retrieval time.
Absence provenance: unavailable. Searched: Tunisia INPDP new draft data protection law 2023 2024 reform.
Credit And ScoringRed
Not confirmed.
Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.
EducationRed
Not confirmed.
Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.
InsuranceRed
Not confirmed.
Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.
Category narrative24 words
No sector-specific personal-data overlays (financial, health, telecoms/ePrivacy, employment, credit-scoring, education, insurance) applicable in Tunisia could be confirmed from accessible sources in this research pass.
Explicit absent finding — no comprehensive adtech-specific regime identified distinct from the general Organic Law 2004-63 framework.
Primary frameworkOrganic Law No. 2004-63 of 27 July 2004 on the Protection of Personal Data
Supervisory authorityInstance Nationale de Protection des Données à Caractère Personnel (INPDP)
Traffic-light rationale — Not assessedExplicit absent finding — no comprehensive adtech-specific regime identified distinct from the general Organic Law 2004-63 framework.
Sub-modules (6)
Cookies And TrackersRed
Not confirmed.
Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.
Dark PatternsRed
Not confirmed.
Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.
Opt Out SignalsRed
Not confirmed.
Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.
Clean Rooms And DcrRed
Not confirmed.
Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.
Cross Context AdvertisingRed
Not confirmed.
Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.
Direct MarketingRed
Not confirmed.
Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.
Category narrative24 words
No cookie/tracker consent regime, dark-pattern prohibition, opt-out-signal recognition, clean-room rules, cross-context-advertising rules, or direct-marketing suppression regime specific to Tunisia was identified in accessible sources.
Only contextual/political-economy evidence located; no direct statutory provision on ADM, biometric regime, or surveillance carveouts was confirmed.
Primary frameworkOrganic Law No. 2004-63 of 27 July 2004 on the Protection of Personal Data
Supervisory authorityInstance Nationale de Protection des Données à Caractère Personnel (INPDP)
Traffic-light rationale — RedOnly contextual/political-economy evidence located; no direct statutory provision on ADM, biometric regime, or surveillance carveouts was confirmed.
Sub-modules (6)
Profiling RestrictionsRed
Not confirmed.
Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.
Automated Decision Making TransparencyRed
Not confirmed.
Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.
Ai Risk AssessmentsRed
Not confirmed.
Absence provenance: unavailable. Searched: Tunisia data protection authority INPDP 2026.
Biometric RegimeRed
Not confirmed; general special-category handling under Organic Law 2004-63 likely touches biometric data but no dedicated regime was verified.
Absence provenance: unavailable. Searched: Tunisia Organic Law 2004-63 "declaration" "authorization" INPDP controller obligations biometric health data.
Genetic DataRed
Not confirmed.
Absence provenance: unavailable. Searched: Tunisia Organic Law 2004-63 "declaration" "authorization" INPDP controller obligations biometric health data.
State Surveillance CarveoutsAmber
Contextual EU documents describe Tunisia's 2022 Constitution as establishing a presidential system with legislative-initiative priority for the President, and note continuing concern regarding use of counter-terrorism and anti-corruption legislation against political actors and journalists — relevant to (but not dispositive of) the scope of any national-security exemption within Organic Law 2004-63.
Claims (1):
Tunisia's 2022 Constitution establishes a presidential system in which the President and the Assembly of the Representatives of the People share legislative initiative, with the President's proposals taking priority.
Category narrative82 words
No Tunisia-specific profiling/ADM-transparency regime, AI-risk-assessment requirement, or dedicated biometric/genetic-data regime was confirmed from accessible sources. On state-surveillance carveouts, EU institutional documents note that Tunisia's 2022 Constitution establishes a presidential system with legislative-initiative priority for the President, and separately-sourced EU material notes ongoing concerns about concentration of power and use of counter-terrorism/anti-corruption law against political actors and journalists — relevant context for assessing the robustness of any national-security exemption to data-protection oversight, though no specific surveillance-carveout provision of Organic Law 2004-63 was verified.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (1)
ProbableEUR-Lex / European Commission — Tunisia's 2022 Constitution establishes a presidential system in which the President and the Assembly of the Representatives of the People share legislative initiative, with the President's proposals taking priority.observed
Explicit absent finding on all five declared sub-modules.
Primary frameworkOrganic Law No. 2004-63 of 27 July 2004 on the Protection of Personal Data
Supervisory authorityInstance Nationale de Protection des Données à Caractère Personnel (INPDP)
Traffic-light rationale — Not assessedExplicit absent finding on all five declared sub-modules.
Sub-modules (5)
Age VerificationRed
Not confirmed.
Absence provenance: unavailable. Searched: Tunisia data protection law children minors consent parental.
Parental ConsentRed
Not confirmed.
Absence provenance: unavailable. Searched: Tunisia data protection law children minors consent parental.
Minor Profiling BansRed
Not confirmed.
Absence provenance: unavailable. Searched: Tunisia data protection law children minors consent parental.
Education SettingsRed
Not confirmed.
Absence provenance: unavailable. Searched: Tunisia data protection law children minors consent parental.
Dependent AdultsRed
Not confirmed.
Absence provenance: unavailable. Searched: Tunisia data protection law children minors consent parental.
Category narrative21 words
No age-of-consent, parental-consent mechanism, minor-profiling ban, education-setting-specific rule, or dependent-adults protection specific to Tunisia's data-protection framework was identified in accessible sources.
No claim in this module could be raised above Uncertain confidence; core enforcement metrics (powers, penalties, fines, funding, redress mechanisms) require primary-source escalation.
Primary frameworkOrganic Law No. 2004-63 of 27 July 2004 on the Protection of Personal Data
Supervisory authorityInstance Nationale de Protection des Données à Caractère Personnel (INPDP)
Traffic-light rationale — RedNo claim in this module could be raised above Uncertain confidence; core enforcement metrics (powers, penalties, fines, funding, redress mechanisms) require primary-source escalation.
Sub-modules (6)
Regulator Powers And PenaltiesRed
Not confirmed against primary text.
Absence provenance: unavailable. Searched: Tunisia data protection law penalties imprisonment fine INPDP registration declaration.
Enforcement Activity IndexRed
No confirmed enforcement decisions/fines in the last 12 months identified.
Not confirmed; general rule-of-law/independence context noted but not INPDP-specific.
Claims (1):
EU institutional commentary post-2021 raises ongoing concern about concentration of power and independence of regulatory/judicial institutions in Tunisia, a contextual factor relevant to assessing INPDP's practical independence and capacity, though not a direct finding on INPDP itself.
Collective Redress And Class ActionsRed
Not confirmed.
Absence provenance: unavailable. Searched: Tunisia data protection law penalties imprisonment fine INPDP registration declaration.
Private Right Of ActionRed
Not confirmed.
Absence provenance: unavailable. Searched: Tunisia data protection law penalties imprisonment fine INPDP registration declaration.
Recent Developments 180DRed
No confirmed data-protection legislative, case-law, guidance, or adequacy development specific to Tunisia within the last 180 days was identified.
Absence provenance: unavailable. Searched: Tunisia INPDP new draft data protection law 2023 2024 reform, Tunisia data protection authority INPDP 2026.
Category narrative108 words
INPDP's investigative/enforcement powers, maximum penalty levels, and enforcement-activity record over the last 12 months could not be confirmed from accessible sources. Weak secondary signals indicate institutional activity: a 2018 DataGuidance news item title references an INPDP-published draft data protection bill (suggesting a reform track whose current status is unconfirmed), and a separate DataGuidance title references a memorandum of understanding between the Ministry of Communication Technologies (MTCEN) and INPDP on national identification — both only accessible as titles, with substantive content paywalled. Broader EU institutional commentary raises rule-of-law and judicial-independence concerns in Tunisia post-2021/2022 that bear on regulator capacity and independence generally, though no INPDP-specific capacity assessment was located.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (1)
UncertainEUR-Lex / European Commission — EU institutional commentary post-2021 raises ongoing concern about concentration of power and independence of regulatory/judicial institutions in Tunisia, a contextual factor relevant to assessing INPDP's practical independence and capacity, though not a direct finding on INPDP itself.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
No failing checks.
schema_valid
pass
min_t1_per_instrument_met
n/a — no subject in this jurisdiction
min_quoted_text_present
waived — floor 0%
translation_provenance_recorded
n/a — no subject in this jurisdiction
egress_verified
pass
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
pass
tier_a_b_national_primary_pct
23.53
aggregator_only_jurisdiction_count
0
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Tunisia
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 8 claim(s) (8 category placement(s)), 19 source(s) in the cumulative register.
regulator_and_framework and cross_border_and_adequacy carry Confirmed claims grounded in T1 (EUR-Lex EU institutional documents) and T2/T3 sources (IAPP directory, CNIL/LINC analysis), establishing the primary statute (Organic Law 2004-63), the INPDP regulator, constitutional basis (Art. 24, 2002), and Tunisia's Convention 108 party status plus the 2018 EU-Tunisia Europol data-exchange negotiation track. algorithmic_biometric_and_surveillance_governance carries one contextual (non-binding) claim on constitutional structure (T1) relevant to the state_surveillance_carveouts sub-module. enforcement_and_redress carries one Uncertain contextual claim (T1) on rule-of-law context but no INPDP-specific enforcement, penalty, or funding data. The remaining six modules (lawful_processing_and_special_data, data_subject_rights, controller_processor_duties, sectoral_watch, adtech_and_commercial_privacy, children_and_vulnerable_groups) returned no claims meeting the confidence bar for emission; all carry explicit absent_field_provenance naming the searches executed. This reflects that the authoritative secondary sources normally carrying this level of Tunisia-specific granularity (DataGuidance jurisdiction notes, IAPP premium notes) were paywalled at retrieval time, and no primary INPDP legal-text portal was successfully retrieved in this pass.
Unresolved questions (8):
Full primary text of Organic Law No. 2004-63 (lawful bases, consent standards, special-category list, DPIA/DPO/ROPA/breach-notification specifics, penalty schedule) requires direct consultation of the Journal Officiel de la République Tunisienne or the INPDP's official portal.
Whether the INPDP's 2018-referenced draft data protection reform bill has since been enacted, remains pending, or has lapsed.
Current INPDP declaration/authorization procedure and fee schedule for controllers, including any exemptions.
Whether Tunisia has signed (not merely been eligible to accede to) the modernised Convention 108+ protocol, and the current ratification status.
Status/outcome of the EU-Tunisia Europol personal-data-exchange agreement negotiations opened in 2018.
INPDP enforcement record (fines, sanctions, formal decisions) over the past 12 months.
Sector-specific overlays (telecommunications code, banking secrecy law, health-data rules) and their interaction with Organic Law 2004-63.
Any children's-data-specific or biometric-specific secondary legislation or INPDP guidance.