Tunisia - Combating Cyber Offences (2022-54)

Decree-Law No. 2022-54 of 13 September 2022 on Combating Offences Relating to Information and Communication Systems

Décret-loi n° 2022-54 du 13 septembre 2022, relatif à la lutte contre les infractions se rapportant aux systèmes d'information et de communication

Tunisia

RAI-TN-NA-DN2COXX-2022
Effective: September 16, 2022
In Force(In Force)
DecreeData Protection and PrivacyEnforcement and PenaltiesGovernance and Oversight
Export PDF

Decree-Law No. 2022-54, enacted by the President of Tunisia in 2022, establishes criminal penalties for information system offences, mandates traffic data retention by service providers, and grants broad investigative powers to authorities. The decree took effect on 2022-09-16 and binds telecom operators, service providers, and users nationwide.

Summary

Decree‑Law No. 2022‑54 (13 September 2022) establishes a specialised criminal regime addressing offences involving information and communication systems, sets obligations for data retention and evidence collection, and grants investigative and interception powers to public authorities. The law includes broad offences (including provisions criminalising the dissemination of “false news”) and significant penalties; it has been published in the Journal Officiel (JORT) and attracted sustained criticism from international and domestic rights organisations over risks to freedom of expression and privacy.

Full article

Read full text ↗

Overview

Decree‑Law No. 2022‑54, promulgated on 13 September 2022 and published in JORT No. 103 (16 September 2022), is titled "relatif à la lutte contre les infractions se rapportant aux systèmes d'information et de communication" and creates a comprehensive statutory framework to prevent, investigate and penalise offences relating to information and communication systems in Tunisia. The decree establishes definitions, preservation of electronic evidence, data‑retention obligations for service providers, interception and seizure powers, a catalogue of criminal offences and associated penalties, and provisions on international cooperation. The decree entered into force upon publication subject to specific implementing joint ministerial orders for certain technical and retention modalities. The official publication reference is JORT No.103 (16 September 2022). The original reproduction of the decree text made available online is: Journal Officiel reproduction – Decree‑Law No.2022‑54 (PDF). Additional commentary and summaries have been published by legal and civil society organisations; selected references and commentary appear in other sources. (See also: JORT official site: https://www.jort.tn)

Definitions

Article 5 and related provisions provide statutory definitions for central terms used throughout the decree. These definitions establish the scope of obligations, investigatory powers and criminal offences. Key defined terms include:

- "System of information": a set of software, tools and equipment allowing automated processing of data (support informatique, programme, données informatiques).
- "Computer data": data stored, processed or transmitted in digital form within an information system.
- "Communication system": any metallic, optical, radio or other transmission medium enabling electronic communication.
- "Service provider": entities providing telecommunications and internet services to the public, including those obligated to retain and provide data under judicial order.
- "Traffic/access data": metadata such as source, destination, route, time, volume, duration and type of service that facilitate attribution and routing of communications.
- Supporting terms: "support informatique", "programme", and related technical notions that ground the application of obligations, interception, seizure and evidence preservation rules.

These statutory definitions are referenced repeatedly in the decree and determine which actors, data types and technical measures fall within the law's remit. For extended explanatory material and commentary referencing these definitions, see published summaries and legal analyses available from specialist organisations and official repositories such as the Journal Officiel (JORT).

Governance and Institutional Framework

Implementation and enforcement responsibilities are distributed among multiple institutions: judicial authorities (public prosecutors, investigating judges), designated police and military judicial officers, and specialised services within the Ministries of Interior and Defence which execute orders within their spheres of competence. The decree authorises prosecutors and authorised judicial officers to request and obtain access to traffic and access data, order seizure and real‑time collection of specified data, and to supervise preservation of electronic evidence. Joint ministerial orders (defence, interior, justice and telecommunications) are required to fix technical modalities, retention durations and operational procedures. The decree also references cooperation channels with foreign authorities under international conventions and on a reciprocity basis. The decree imposes non‑disclosure and professional secrecy obligations on executing officers and experts involved in evidence handling and technical operations.

Key Focus Areas

  • Data retention and service‑provider obligations: mandatory retention of specified categories of traffic/access and related data by telecommunications and internet service providers, with retention durations and technical modalities to be fixed by joint ministerial order (the decree sets a minimum retention period of not less than two years as a baseline for implementing orders).
  • Preservation and collection of electronic evidence: provisions for preservation, access, copying and seizure of stored data on judicial order, and technical and procedural rules for handling electronic evidence.
  • Interception and real‑time collection powers: authority for prosecutors and authorised judicial officers to order interception, real‑time collection of traffic data and targeted measures executed by competent services within their legal competence (including different arrangements for civilian and military domains).
  • Criminal offences catalogue: a broad range of offences including illegal access (Art. 16), unlawful interception (Arts. 18–20), data tampering, diversion and fraud (Arts. 22–23), dissemination of "rumeurs et fausses nouvelles" using information systems (Article 24), unlawful disclosure of professional secrets, and specific offences relating to children.
  • Penalties and corporate liability: graduated criminal penalties (custodial terms and fines), aggravations for public officials, and corporate remedies including pecuniary sanctions, suspension of activities or dissolution (Art. 32).
  • Jurisdiction and extraterritorial application: rules allowing the decree to reach offences beyond Tunisia's borders in specified circumstances (Tunisian offenders, where Tunisian interests are affected, or where the foreign offender resides habitually in Tunisia).

Implementation Framework

The decree requires subsequent implementing measures to operationalise its substantive duties. Key implementation elements include:

- Joint ministerial orders (Ministries of Defence, Interior, Justice and Telecommunications) to fix retention durations, technical specifications for data retention and modalities for interception and seizure.
- Obligations for service providers to prepare systems and procedures to retain specified data categories and to respond to judicial orders for access, copying or real‑time collection.
- Designation of competent services and officers authorised to execute orders within their competence (including military and interior security services for matters within their jurisdictions).
- Requirements that officers, experts and technical personnel executing orders respect non‑disclosure obligations and professional secrecy.
- Integration with existing criminal and procedural law to ensure that electronic evidence is admissible and that specialised procedural safeguards apply where specified.
The decree itself indicates that certain articles enter into force only once the requisite implementing joint ministerial orders and technical decrees are issued; this creates an operational dependence on executive rule‑making to realise retention and interception regimes. For detailed summaries of implementation requirements and operational modalities, consult the official text published in the Journal Officiel (JORT) and subsequent implementing joint ministerial orders when issued.

Monitoring and Evaluation

The decree has prompted calls for transparent monitoring and evaluation of its use in practice. Observers recommend tracking:

- The issuance and content of joint ministerial orders that fix retention durations and technical procedures.
- Usage statistics: number of preservation orders, interception orders, seizures, prosecutions and convictions under the decree, disaggregated by offence category (notably Article 24 prosecutions concerning "false news").
- Compliance actions against service providers and any administrative or criminal sanctions applied to officials for breaches of retention, disclosure or secrecy obligations.
- Judicial review and appeals raising proportionality, legality and human‑rights considerations in relation to freedom of expression and privacy.
The decree has already attracted sustained criticism from international and domestic rights organisations warning that vague terms—especially Article 24 criminalising dissemination of "rumeurs et fausses nouvelles"—risk arbitrary enforcement against journalists, activists and critics. Major rights organisations and press bodies have publicly urged reconsideration or repeal; transparent publication of statistical use data and judicial decisions has been recommended to enable monitoring and evaluation.

Penalties, Liability, and Appeals

The decree establishes a graduated penalty scheme for individuals and legal persons. Key penalty features include:

- Illegal access (Art. 16): custodial terms and fines (shorter terms compared with more serious offences).
- Interception and damage to data (Arts. 18–20): multi‑year custodial terms and significant fines where conduct results in substantial harm.
- Fraud, falsification and data diversion (Arts. 22–23): heavier custodial terms reflective of economic or systemic harm.
- Article 24 ("rumeurs et fausses nouvelles"): criminalisation of deliberate production or dissemination of false news using information systems, with penalties up to five years' imprisonment and a fine of 50,000 Tunisian dinars (doubled where public officials are targeted).
- Sanctions for service providers and officials: failure to respect retention obligations or to comply with lawful orders may attract imprisonment and higher fines; corporate liability measures under Article 32 allow pecuniary sanctions and possible suspension or dissolution of legal persons.
The decree cross‑references existing procedures for criminal appeals under Tunisia's penal and criminal‑procedure codes; affected parties retain rights of defence and procedural safeguards as provided under the applicable criminal procedure framework, subject to the specialised procedural rules the decree introduces for electronic evidence and interception measures.

Relationship to Other Instruments

The decree integrates with Tunisia's penal code, code of criminal procedure and military justice code where applicable. It expressly abrogates specified prior penal provisions (notably articles 199 bis and 199 ter of the penal code). The text references international conventions and provides for cross‑border cooperation mechanisms and extraterritorial jurisdiction in specified cases. The decree also includes language requiring respect for constitutional guarantees, international treaties and human rights law in its application, although critics question how these safeguards will be operationalised in practice and subject to judicial oversight.

International Alignment

The decree provides for cooperation channels with foreign authorities based on international conventions and reciprocity, allowing mutual legal assistance and cross‑border evidence exchange in cyber‑related investigations. It also asserts extraterritorial jurisdiction in specified circumstances (Tunisian nationals, protection of Tunisian interests, or habitual residence in Tunisia). While the decree references international cooperation, observers note that alignment with international human rights standards (notably freedom of expression and privacy obligations under treaty law) will depend heavily on implementation practices, judicial oversight and transparency of orders and prosecutions.

Implementation Timeline

DateEvent
2022-09-13Decree‑Law signed (date on text)
2022-09-16Published in Journal Officiel (JORT No.103)
2023-12-11Reported first high-profile prosecutions under the decree (media/NGO reports)
2023-12-13Reported sentencing of two activists (media/NGO reports)
2025-09-30Significant international media report citing application of Decree 54 (death sentence reported in press)

Sources and References

SourceURL
Journal Officiel de la République Tunisienne (JORT No.103, 16 September 2022) — official publication reference for Decree‑Law No. 2022‑54https://www.jort.tn

Requirements for a company

What an organisation has to do under Tunisia - Combating Cyber Offences (2022-54), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

3
  • Retain specified categories of traffic and access data for a minimum baseline period of two years.Telecommunications and internet service providers
  • Comply with judicial orders for access, copying, seizure, or real-time collection of electronic data.Telecommunications and internet service providers
  • Maintain strict confidentiality and professional secrecy when executing data preservation or judicial interception orders.Technical personnel and experts executing judicial orders

Must not do

3
  • Do not produce or disseminate false news or rumors using information and communication systems.All users and operators of information systems
  • Do not perform unlawful interception of communications, data tampering, data diversion, or electronic fraud.All users and operators of information systems
  • Do not gain unauthorized access to any information system or digital support structure.All users and operators of information systems

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Tunisia - Combating Cyber Offences (2022-54), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1All users and operators of information systemsDo not produce or disseminate false news or rumors using information and communication systems.
deliberate production or dissemination of false news using information systems
Sep 16, 2022Article 24Critical
2Telecommunications and internet service providersRetain specified categories of traffic and access data for a minimum baseline period of two years.
mandatory retention of specified categories of traffic/access and related data by telecommunications and internet service providers
Sep 16, 2022Critical
3Telecommunications and internet service providersComply with judicial orders for access, copying, seizure, or real-time collection of electronic data.
prepare systems and procedures to retain specified data categories and to respond to judicial orders for access, copying or real‑time collection.
Upon judicial orderCritical
4All users and operators of information systemsDo not perform unlawful interception of communications, data tampering, data diversion, or electronic fraud.
unlawful interception (Arts. 18–20), data tampering, diversion and fraud (Arts. 22–23)
Sep 16, 2022Articles 18–23Critical
5All users and operators of information systemsDo not gain unauthorized access to any information system or digital support structure.
Illegal access (Art. 16): custodial terms and fines
Sep 16, 2022Article 16Critical
6Technical personnel and experts executing judicial ordersMaintain strict confidentiality and professional secrecy when executing data preservation or judicial interception orders.
Requirements that officers, experts and technical personnel executing orders respect non‑disclosure obligations and professional secrecy.
Sep 16, 2022Important

© Regulations.AI · updated on 13-Jun-2026 · reviewed against official sources on 07-Sep-2026 using Gemini 3.6 Flash