Skip to content

Evidence request lists

Tunisia Organic Law on Personal Data Protection (Law No. 2004-63)

Evidence request list. 23 controls, 23 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Data Quality, Retention and Security

TN-DPL-06
Data Quality and Accuracy

Maintain personal data that is accurate, complete and kept up to date, with mechanisms to allow data subjects to verify and correct their data.

Artefacts an auditor will ask for
  • Data quality monitoring reports
  • Self-service profile update functionality screenshots
  • Rectification workflow documentation
  • Data validation rules in source systems
  • Periodic data accuracy review records
Where this commonly fails
  • Stale customer records never refreshed
  • Duplicate records causing inconsistent data
  • No upstream propagation of corrections to downstream systems
  • Manual data entry without validation checks
TN-DPL-07
Retention and Destruction

Personal data must be retained no longer than necessary for the purpose for which it was collected, with destruction or anonymisation at the end of the retention period.

Artefacts an auditor will ask for
  • Retention schedule per data category and purpose
  • Automated deletion job logs
  • Certificates of destruction for paper records
  • Anonymisation procedure documentation
  • Backup expiration and overwrite records
Where this commonly fails
  • Indefinite retention as default in source systems
  • Backups holding data well beyond live retention
  • Anonymisation not actually irreversible
  • Email archives ignored in retention scheme
TN-DPL-08
Security of Processing

Implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction.

Artefacts an auditor will ask for
  • Encryption configuration for data at rest and in transit
  • Access control matrix per system
  • Vulnerability scan reports
  • Penetration test reports
  • Security policies and standards approved by management
Where this commonly fails
  • Legacy systems without encryption support
  • Shared accounts in production environments
  • No periodic access recertification
  • Test environments populated with real personal data
TN-DPL-09
Data Breach Notification

Notify the INPDP and affected data subjects of personal data breaches in line with applicable timelines and document the incident response, root cause and mitigation.

Artefacts an auditor will ask for
  • Incident response playbook with INPDP notification template
  • Breach register with severity classification
  • Sample breach notifications sent to INPDP
  • Data subject communication templates
  • Post-incident review reports
Where this commonly fails
  • No defined trigger criteria for INPDP notification
  • Detection delayed by lack of monitoring
  • Notification omits required content elements
  • No tabletop exercise involving privacy scenarios

Data Subject Rights and Transparency

TN-DPL-03
Data Subject Rights Handling

Operate procedures to handle access, rectification, opposition and erasure requests from data subjects within statutory deadlines and provide free of charge response channels.

Artefacts an auditor will ask for
  • Data subject request intake form
  • DSR register with received, response and closure dates
  • Identity verification procedure
  • Sample response letters in Arabic and French
  • Staff training records on DSR handling
Where this commonly fails
  • No deadline tracking against statutory response window
  • Identity verification missing or excessive
  • Fees charged to data subjects for standard requests
  • Opposition right not offered for direct marketing
TN-DPL-11
Privacy Notice and Transparency

Inform data subjects at the point of collection about the controller identity, purposes, recipients, rights and the existence of any automated decision making.

Artefacts an auditor will ask for
  • Layered privacy notice in Arabic and French
  • Just in time notices at collection points
  • Privacy notice version history with effective dates
  • Communication record of material changes to data subjects
  • Internal review log of notice accuracy
Where this commonly fails
  • Notice only available in one language
  • Stale notice not aligned with current processing
  • Recipients categories described too vaguely
  • No notice for back office data collection

Governance

TUNISIA-4
Registration, Governance, Breach

Per Tunisia Law: INPDP registration + governance + breach + enforcement.

Artefacts an auditor will ask for
  • Tunisia evidence for TUNISIA-4
Where this commonly fails
  • INPDP + registration partial

Governance, Records and Assurance

TN-DPL-16
Records of Processing Activities

Maintain an internal register of all processing activities including purpose, categories of data and recipients, available for inspection by INPDP on request.

Artefacts an auditor will ask for
  • Records of processing activities register
  • Annual review and update logs
  • Process owner attestations
  • Mapping of register entries to systems and contracts
  • INPDP inspection readiness documentation
Where this commonly fails
  • Register built once and never updated
  • Activities held by shadow IT not captured
  • Recipients listed only generically
  • No link between register and DSR or breach handling
TN-DPL-17
Privacy Governance and Accountability

Designate accountable management for personal data protection, allocate resources and report to senior leadership on privacy posture and incidents.

Artefacts an auditor will ask for
  • Privacy officer or DPO appointment letter
  • Privacy steering committee minutes
  • Annual privacy report to board
  • Budget allocation for privacy programme
  • Risk register entries on privacy
Where this commonly fails
  • No clear accountable owner above operational level
  • Privacy steering committee inactive
  • Reporting limited to incident counts
  • Budget split across departments with no overall view
TN-DPL-18
Training and Awareness

Train staff handling personal data on Tunisian data protection obligations, with role specific content for DPO, IT, HR and customer facing teams.

Artefacts an auditor will ask for
  • Annual privacy training completion reports
  • Role specific training modules
  • Phishing and awareness campaign metrics
  • Knowledge check quiz results
  • New joiner privacy induction records
Where this commonly fails
  • Same generic training for all staff regardless of role
  • Annual reset only, no continuous reinforcement
  • Contractors and temporary staff excluded
  • No measurement of training effectiveness
TN-DPL-19
Internal Audit and Compliance Monitoring

Operate a programme of internal audit and compliance monitoring to detect deviations from privacy obligations and drive remediation.

Artefacts an auditor will ask for
  • Annual privacy audit plan
  • Audit reports with findings and ratings
  • Management response and remediation plans
  • Follow up testing of closed findings
  • Compliance monitoring dashboards
Where this commonly fails
  • Audit scope limited to IT and excludes business processes
  • Findings remain open for multiple cycles
  • No independent assurance for high risk processing
  • Monitoring metrics not aligned with privacy obligations

Notification, Authorisation and Lawful Basis

TN-DPL-01
INPDP Notification and Authorisation

Notify the Instance Nationale de Protection des Donnees a Caractere Personnel (INPDP) before processing personal data and obtain prior authorisation for sensitive processing categories or international transfers as required by the Organic Law.

Artefacts an auditor will ask for
  • INPDP declaration filings with submission timestamps
  • Prior authorisation requests for sensitive data processing
  • Acknowledgement letters and reference numbers from INPDP
  • Internal log of processing activities subject to declaration
  • Renewal and amendment notifications for changed processing
Where this commonly fails
  • Processing started before INPDP acknowledgement received
  • No tracking of declaration scope vs actual processing
  • Sensitive category processing without prior authorisation
  • Stale declarations not updated after material changes
TN-DPL-02
Lawful Basis and Consent

Establish a lawful basis for each processing operation, with explicit, written consent of the data subject as the default basis under Tunisian law, and document the consent capture mechanism for each collection point.

Artefacts an auditor will ask for
  • Consent forms in Arabic and French
  • Consent capture logs with timestamps and IP addresses
  • Lawful basis register mapping each processing activity
  • Withdrawal of consent procedure documentation
  • Re-consent campaign records when scope changes
Where this commonly fails
  • Implicit consent assumed instead of explicit written consent
  • Consent bundled with terms and conditions
  • No mechanism to withdraw consent as easily as it was given
  • Lawful basis not documented per processing purpose
TN-DPL-05
Sensitive Data Processing

Processing of sensitive data including health, racial, religious, political and trade union information requires explicit consent and specific INPDP authorisation with enhanced safeguards.

Artefacts an auditor will ask for
  • Inventory of sensitive data categories processed
  • Specific consent forms for sensitive processing
  • INPDP authorisation for sensitive data activities
  • Enhanced access control list for sensitive data systems
  • Risk assessment for each sensitive processing purpose
Where this commonly fails
  • Health data collected through wellness programs without authorisation
  • Inferred sensitive data from analytics not recognised
  • Sensitive data fields in general databases without segregation
  • No additional logging for sensitive data access

Rights

TUNISIA-2
Consent, Rights

Per Tunisia Law: consent + data subject rights.

Artefacts an auditor will ask for
  • Tunisia evidence for TUNISIA-2
Where this commonly fails
  • INPDP + registration partial

Scope

TUNISIA-1
Scope, Lawful Basis (Tunisia)

Per Tunisia Organic Law 2004-63 on Protection of Personal Data: scope. Align with INPDP (Instance Nationale de Protection des Donnees Personnelles).

Artefacts an auditor will ask for
  • Tunisia evidence for TUNISIA-1
Where this commonly fails
  • INPDP + registration partial

Security

TUNISIA-3
Security and Cross-Border

Per Tunisia Law: security + cross-border with INPDP authorization.

Artefacts an auditor will ask for
  • Tunisia evidence for TUNISIA-3
Where this commonly fails
  • INPDP + registration partial

Specific Processing Contexts

TN-DPL-12
Direct Marketing and Cookies

Use of personal data for direct marketing and tracking technologies requires prior consent of the data subject with a simple opt out mechanism in every communication.

Artefacts an auditor will ask for
  • Cookie consent banner configuration
  • Marketing consent capture logs
  • Preference centre user interface
  • Unsubscribe link confirmation records
  • Cookie inventory with purpose and lifetime
Where this commonly fails
  • Implied consent from continued browsing
  • No granular control over cookie categories
  • Marketing emails sent to addresses obtained from purchase only
  • Tracking pixels deployed before consent decision
TN-DPL-13
Employee and HR Data

Processing of employee personal data including monitoring, performance and health information must respect proportionality, transparency and INPDP notification obligations.

Artefacts an auditor will ask for
  • Employee privacy notice
  • Monitoring policy with proportionality justification
  • Works council or staff representative consultation records
  • Access controls on HR information systems
  • Retention schedule for HR files post departure
Where this commonly fails
  • Covert monitoring without prior notification
  • Excessive collection at recruitment stage
  • HR records kept indefinitely after exit
  • Manager access to colleague data without need to know
TN-DPL-14
Video Surveillance

Video surveillance systems require INPDP notification, signage informing data subjects, purpose limitation and retention limits aligned with the original purpose.

Artefacts an auditor will ask for
  • INPDP notification for each surveillance installation
  • Photographs of installed signage
  • Camera location plan with field of view
  • Retention period configuration on recording systems
  • Access log of who viewed footage and why
Where this commonly fails
  • Cameras pointed at public street beyond premises
  • Retention exceeding declared period
  • Footage exported and stored outside controlled environment
  • No purpose limitation, footage reused for performance management
TN-DPL-15
Children and Minors

Collect personal data of minors only with consent of the holder of parental authority, with enhanced safeguards on profile and marketing communications.

Artefacts an auditor will ask for
  • Age verification mechanism at registration
  • Parental consent capture workflow
  • Audit of services accessible to minors
  • Marketing exclusions for minors
  • Re-consent procedure at age of majority
Where this commonly fails
  • Birth date collected but not used for age check
  • Parental consent obtained only by self declaration
  • Profiling of minors not separately analysed
  • Marketing campaigns without minor exclusion segment

Transfers and Processors

TN-DPL-04
International Data Transfers

Transfers of personal data outside Tunisia require prior INPDP authorisation and adequate protection in the recipient country, demonstrated through contractual safeguards or specific derogations.

Artefacts an auditor will ask for
  • Transfer impact assessment per destination country
  • INPDP authorisation letter for each transfer route
  • Inter-company data transfer agreements
  • Standard contractual clauses with processors abroad
  • Adequacy assessments of recipient legal regime
Where this commonly fails
  • Transfers to cloud providers without prior INPDP authorisation
  • No mapping of where personal data actually resides
  • Sub-processor chain extending beyond authorised geography
  • Group company transfers treated as internal and unmapped
TN-DPL-10
Processor Oversight

Engage processors only under written contracts that bind them to the same protection level required of the controller, with audit rights and security obligations.

Artefacts an auditor will ask for
  • Processor inventory with risk rating
  • Data processing agreements with privacy clauses
  • Vendor security questionnaires
  • Audit reports or SOC 2 reports collected from processors
  • Sub-processor approval records
Where this commonly fails
  • Processors operating under generic services contracts only
  • No reassessment after initial onboarding
  • Sub-processors added without notification
  • No exit plan to retrieve or destroy data on termination
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.