Tunisia Organic Law on Personal Data Protection (Law No. 2004-63)
Evidence request list. 23 controls, 23 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Data Quality, Retention and Security
Maintain personal data that is accurate, complete and kept up to date, with mechanisms to allow data subjects to verify and correct their data.
- Data quality monitoring reports
- Self-service profile update functionality screenshots
- Rectification workflow documentation
- Data validation rules in source systems
- Periodic data accuracy review records
- Stale customer records never refreshed
- Duplicate records causing inconsistent data
- No upstream propagation of corrections to downstream systems
- Manual data entry without validation checks
Personal data must be retained no longer than necessary for the purpose for which it was collected, with destruction or anonymisation at the end of the retention period.
- Retention schedule per data category and purpose
- Automated deletion job logs
- Certificates of destruction for paper records
- Anonymisation procedure documentation
- Backup expiration and overwrite records
- Indefinite retention as default in source systems
- Backups holding data well beyond live retention
- Anonymisation not actually irreversible
- Email archives ignored in retention scheme
Implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction.
- Encryption configuration for data at rest and in transit
- Access control matrix per system
- Vulnerability scan reports
- Penetration test reports
- Security policies and standards approved by management
- Legacy systems without encryption support
- Shared accounts in production environments
- No periodic access recertification
- Test environments populated with real personal data
Notify the INPDP and affected data subjects of personal data breaches in line with applicable timelines and document the incident response, root cause and mitigation.
- Incident response playbook with INPDP notification template
- Breach register with severity classification
- Sample breach notifications sent to INPDP
- Data subject communication templates
- Post-incident review reports
- No defined trigger criteria for INPDP notification
- Detection delayed by lack of monitoring
- Notification omits required content elements
- No tabletop exercise involving privacy scenarios
Data Subject Rights and Transparency
Operate procedures to handle access, rectification, opposition and erasure requests from data subjects within statutory deadlines and provide free of charge response channels.
- Data subject request intake form
- DSR register with received, response and closure dates
- Identity verification procedure
- Sample response letters in Arabic and French
- Staff training records on DSR handling
- No deadline tracking against statutory response window
- Identity verification missing or excessive
- Fees charged to data subjects for standard requests
- Opposition right not offered for direct marketing
Inform data subjects at the point of collection about the controller identity, purposes, recipients, rights and the existence of any automated decision making.
- Layered privacy notice in Arabic and French
- Just in time notices at collection points
- Privacy notice version history with effective dates
- Communication record of material changes to data subjects
- Internal review log of notice accuracy
- Notice only available in one language
- Stale notice not aligned with current processing
- Recipients categories described too vaguely
- No notice for back office data collection
Governance
Per Tunisia Law: INPDP registration + governance + breach + enforcement.
- Tunisia evidence for TUNISIA-4
- INPDP + registration partial
Governance, Records and Assurance
Maintain an internal register of all processing activities including purpose, categories of data and recipients, available for inspection by INPDP on request.
- Records of processing activities register
- Annual review and update logs
- Process owner attestations
- Mapping of register entries to systems and contracts
- INPDP inspection readiness documentation
- Register built once and never updated
- Activities held by shadow IT not captured
- Recipients listed only generically
- No link between register and DSR or breach handling
Designate accountable management for personal data protection, allocate resources and report to senior leadership on privacy posture and incidents.
- Privacy officer or DPO appointment letter
- Privacy steering committee minutes
- Annual privacy report to board
- Budget allocation for privacy programme
- Risk register entries on privacy
- No clear accountable owner above operational level
- Privacy steering committee inactive
- Reporting limited to incident counts
- Budget split across departments with no overall view
Train staff handling personal data on Tunisian data protection obligations, with role specific content for DPO, IT, HR and customer facing teams.
- Annual privacy training completion reports
- Role specific training modules
- Phishing and awareness campaign metrics
- Knowledge check quiz results
- New joiner privacy induction records
- Same generic training for all staff regardless of role
- Annual reset only, no continuous reinforcement
- Contractors and temporary staff excluded
- No measurement of training effectiveness
Operate a programme of internal audit and compliance monitoring to detect deviations from privacy obligations and drive remediation.
- Annual privacy audit plan
- Audit reports with findings and ratings
- Management response and remediation plans
- Follow up testing of closed findings
- Compliance monitoring dashboards
- Audit scope limited to IT and excludes business processes
- Findings remain open for multiple cycles
- No independent assurance for high risk processing
- Monitoring metrics not aligned with privacy obligations
Notification, Authorisation and Lawful Basis
Notify the Instance Nationale de Protection des Donnees a Caractere Personnel (INPDP) before processing personal data and obtain prior authorisation for sensitive processing categories or international transfers as required by the Organic Law.
- INPDP declaration filings with submission timestamps
- Prior authorisation requests for sensitive data processing
- Acknowledgement letters and reference numbers from INPDP
- Internal log of processing activities subject to declaration
- Renewal and amendment notifications for changed processing
- Processing started before INPDP acknowledgement received
- No tracking of declaration scope vs actual processing
- Sensitive category processing without prior authorisation
- Stale declarations not updated after material changes
Establish a lawful basis for each processing operation, with explicit, written consent of the data subject as the default basis under Tunisian law, and document the consent capture mechanism for each collection point.
- Consent forms in Arabic and French
- Consent capture logs with timestamps and IP addresses
- Lawful basis register mapping each processing activity
- Withdrawal of consent procedure documentation
- Re-consent campaign records when scope changes
- Implicit consent assumed instead of explicit written consent
- Consent bundled with terms and conditions
- No mechanism to withdraw consent as easily as it was given
- Lawful basis not documented per processing purpose
Processing of sensitive data including health, racial, religious, political and trade union information requires explicit consent and specific INPDP authorisation with enhanced safeguards.
- Inventory of sensitive data categories processed
- Specific consent forms for sensitive processing
- INPDP authorisation for sensitive data activities
- Enhanced access control list for sensitive data systems
- Risk assessment for each sensitive processing purpose
- Health data collected through wellness programs without authorisation
- Inferred sensitive data from analytics not recognised
- Sensitive data fields in general databases without segregation
- No additional logging for sensitive data access
Rights
Per Tunisia Law: consent + data subject rights.
- Tunisia evidence for TUNISIA-2
- INPDP + registration partial
Scope
Per Tunisia Organic Law 2004-63 on Protection of Personal Data: scope. Align with INPDP (Instance Nationale de Protection des Donnees Personnelles).
- Tunisia evidence for TUNISIA-1
- INPDP + registration partial
Security
Per Tunisia Law: security + cross-border with INPDP authorization.
- Tunisia evidence for TUNISIA-3
- INPDP + registration partial
Specific Processing Contexts
Use of personal data for direct marketing and tracking technologies requires prior consent of the data subject with a simple opt out mechanism in every communication.
- Cookie consent banner configuration
- Marketing consent capture logs
- Preference centre user interface
- Unsubscribe link confirmation records
- Cookie inventory with purpose and lifetime
- Implied consent from continued browsing
- No granular control over cookie categories
- Marketing emails sent to addresses obtained from purchase only
- Tracking pixels deployed before consent decision
Processing of employee personal data including monitoring, performance and health information must respect proportionality, transparency and INPDP notification obligations.
- Employee privacy notice
- Monitoring policy with proportionality justification
- Works council or staff representative consultation records
- Access controls on HR information systems
- Retention schedule for HR files post departure
- Covert monitoring without prior notification
- Excessive collection at recruitment stage
- HR records kept indefinitely after exit
- Manager access to colleague data without need to know
Video surveillance systems require INPDP notification, signage informing data subjects, purpose limitation and retention limits aligned with the original purpose.
- INPDP notification for each surveillance installation
- Photographs of installed signage
- Camera location plan with field of view
- Retention period configuration on recording systems
- Access log of who viewed footage and why
- Cameras pointed at public street beyond premises
- Retention exceeding declared period
- Footage exported and stored outside controlled environment
- No purpose limitation, footage reused for performance management
Collect personal data of minors only with consent of the holder of parental authority, with enhanced safeguards on profile and marketing communications.
- Age verification mechanism at registration
- Parental consent capture workflow
- Audit of services accessible to minors
- Marketing exclusions for minors
- Re-consent procedure at age of majority
- Birth date collected but not used for age check
- Parental consent obtained only by self declaration
- Profiling of minors not separately analysed
- Marketing campaigns without minor exclusion segment
Transfers and Processors
Transfers of personal data outside Tunisia require prior INPDP authorisation and adequate protection in the recipient country, demonstrated through contractual safeguards or specific derogations.
- Transfer impact assessment per destination country
- INPDP authorisation letter for each transfer route
- Inter-company data transfer agreements
- Standard contractual clauses with processors abroad
- Adequacy assessments of recipient legal regime
- Transfers to cloud providers without prior INPDP authorisation
- No mapping of where personal data actually resides
- Sub-processor chain extending beyond authorised geography
- Group company transfers treated as internal and unmapped
Engage processors only under written contracts that bind them to the same protection level required of the controller, with audit rights and security obligations.
- Processor inventory with risk rating
- Data processing agreements with privacy clauses
- Vendor security questionnaires
- Audit reports or SOC 2 reports collected from processors
- Sub-processor approval records
- Processors operating under generic services contracts only
- No reassessment after initial onboarding
- Sub-processors added without notification
- No exit plan to retrieve or destroy data on termination
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.