No personal data processing starts without a prior formality
In short: The rule fits in one sentence. In Algeria, every processing of personal data — customers, employees, prospects, cameras — must be covered either by a prior declaration with the National Personal Data Protection Authority or by an authorisation where the processing is risky (art. 12, Law 18-07). A declaration entitles you to a receipt within forty-eight hours and lets you start upon receipt; an authorisation takes two months, and silence equals rejection, not approval.
Keywords in this article
1. No processing starts without a prior formality
It is Article 12 of Law No. 18-07 of 10 June 2018, and it carries no size-based exception: "any processing operation of personal data" — whatever the size of the organisation behind it — "is subject to a prior declaration to the national authority or to its authorisation". A customer spreadsheet falls within scope just as much as an e-commerce platform or a CCTV system.
Three regimes therefore coexist, and the first task is to place your processing in the right one:
| Prior declaration | Prior authorisation | |
|---|---|---|
| Starting point | The default rule of common law under this statute (art. 12) | The processing presents manifest dangers to privacy and fundamental freedoms upon examination of the declaration (art. 17) |
| Cases imposed by law | — | Sensitive data (art. 18); interconnection of files (art. 19); health research and studies (art. 21) |
| Authority's response time | Receipt immediately or within 48 hours (art. 13) | Two months, extendable once for the same period (art. 20) |
| What can you do meanwhile? | Start the processing upon receipt of the receipt slip (art. 13) | Wait: the authority's silence equals rejection, not approval (art. 20) |
The scope deserves verification before anything else: the law covers automated processing even partially, and manual files too; it also reaches a controller established abroad who uses means located on Algerian territory (art. 4).
2. The declaration: file, receive the receipt, start
The declaration is simple in form, demanding in substance. Filed with the national authority — electronic filing is expressly provided for by Article 13 — it amounts to an undertaking that the processing will be conducted in accordance with the law, and a filing receipt is issued immediately or at the latest within forty-eight hours. From that moment, the controller may start operating the processing, under their own responsibility.
Article 14 sets nine mandatory elements, which map exactly what you must know about your own processing before declaring it:
Two logistical complements close the loop. Processings run by the same controller with identical or related purposes may be covered by a single declaration (art. 13) — no need to stack files. And any change to the declared information, as well as any deletion of a processing operation, must be notified without delay (art. 14): a declaration is not archived paperwork, it is a living record that follows the life of the processing. When a data file is sold, the acquirer completes the formalities anew.
3. When a declaration switches to authorisation
Prior authorisation comes into play in two configurations. Either the processing falls from the outset into a category the law subjects to it; or the authority, examining the filed declaration, finds manifest dangers to privacy and freedoms and decides to subject the processing to that regime — a reasoned decision notified within ten days of filing (art. 17).
The three blocks imposed by law:
| Block | Content | Article |
|---|---|---|
| Sensitive data | Racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, health including genetic data: processing is prohibited by principle and admitted only in the exhaustively listed cases — indispensable public interest tied to the controller's legal functions, express consent, statutory provision, or authorisation by the authority, plus specific cases (vital interests, data made public, defending a legal claim) | Arts. 3 and 18 |
| Interconnection of files | Linking files held by legal persons managing a public service pursuing different public interests, as well as private files with different main purposes, requires authorisation | Art. 19 |
| Research and health | Processings for research, study or evaluation in the field of health serving a public interest are authorised by the authority, which may group several processings under a single decision | Art. 21 |
To these add the case many companies discover too late: transferring data to a foreign country. Article 44 makes it subject to the authority's authorisation and to an adequate level of protection ensured by the destination state — and Article 14 already requires the declaration itself to flag data whose transfer is envisaged. Hosting your customer files with a foreign provider, running your management on a platform hosted outside Algeria, sending consolidated files to a parent company: each of these circuits raises the question.
4. The rare exemptions — and a list still to be published
Not everything is declared. Three families fall outside:
- The law's own exclusions (art. 6): data processed by a natural person in the exclusively personal or domestic sphere without dissemination; data collected for national defence and security; data processed for the prevention, investigation and prosecution of offences, which follow their own texts.
- Public registers (art. 16): keeping a register open to public consultation — or to anyone demonstrating a legitimate interest — is exempt from declaration, provided a controller is designated whose identity is made public and notified to the authority, and who answers requests about purposes, identity, data and recipients.
- Simple processings (art. 15): the authority fixes the list of categories of processings posing no risk to rights and freedoms, which benefit from a simplified declaration limited to six of the nine elements of Article 14 — and may extend that regime to non-automated processing.
On this third family, a dated caveat applies: as at our verification date (22 August 2026), we have not found this list published on the authority's official channels. The law entrusts the list to the authority; nothing consultable says today which categories it covers. Until it becomes accessible, the safe reflex is to treat every professional file as falling under ordinary declaration — and to use consultation, which is among the authority's core missions (art. 25), whenever in doubt.
5. What missing the declaration costs
The law punishes clandestine processing severely. The heart of the scheme is Article 56: carrying out processing without complying with Article 12 — i.e. without a filed declaration or an obtained authorisation — exposes you to two to five years' imprisonment and a fine of DZD 200,000 to 500,000. The same penalties apply to anyone making false declarations or continuing to process after withdrawal of the receipt or of the authorisation.
The full escalation, as fixed by the criminal chapter:
| Conduct | Penalty | Article |
|---|---|---|
| Processing without declaration or authorisation; false declarations; continuing after withdrawal | 2-5 years + DZD 200,000-500,000 | Art. 56 |
| Sensitive data processed outside permitted cases | 2-5 years + DZD 200,000-500,000 | Art. 57 |
| Data used for purposes other than those declared or authorised | 6 months-1 year + DZD 60,000-100,000 | Art. 58 |
| Collection by fraudulent, unfair or unlawful means | 1-3 years + DZD 100,000-300,000 | Art. 59 |
| Refusal, without legitimate reason, of information, access, rectification or objection rights | 2 months-2 years + DZD 20,000-200,000 | Art. 64 |
| Unlawful transfer to a foreign state | 1-5 years + DZD 500,000-1,000,000 | Art. 67 |
| Recidivism | Penalties doubled | Art. 74 |
In parallel, the authority has a graduated administrative arm (art. 46): warning, formal notice, temporary withdrawal — capped at one year — or definitive withdrawal of the receipt or authorisation, and fines. One administrative fine is quantified by the statute itself: DZD 500,000 against a controller refusing rights without legitimate reason or failing the notifications required by Articles 4, 14 and 16 (art. 47), switching to criminal liability upon recidivism. Its decisions are appealable before the Council of State.
Map your processings and file your dossiers without guesswork
Inventory of processings to regularise, choosing between declaration and authorisation, preparing the dossiers on the authority's portal and tracking them to receipt: we frame the compliance effort with you.
Frame my compliance6. How the process runs today
The statute describes the formality; the authority describes how it actually runs. Its official compliance procedures document (published April 2025) and its portal guides organise the following circuit:
This service snapshot is dated: it describes the circuit as documented by the authority at our verification date, and it can change without any text moving. What it clearly shows, however, fits in one sentence: the formality is not a checkbox but a small project — mapping, form, signature, filing — where each step produces a document you keep.
FAQ — Frequently asked questions
Yes. Article 12 subjects every processing operation to a formality, with no headcount or volume threshold. Size changes the effort of preparing the file, not the obligation itself. Only the exclusions of Article 6 — strictly personal use, national defence and security, judicial handling of offences — and the exemption for public registers escape the formality.
The statute gives two reference points. The filing receipt must be issued immediately or at the latest within forty-eight hours (art. 13), and the controller may start upon receipt. On the authority's side, its procedures document announces review of declarations within ten days, with notification within that window if a switch to authorisation is needed. Actual duration depends mostly on how complete your file is.
No — and this is the most counter-intuitive point of the scheme. After two months, extendable once, without a decision, the request is deemed rejected (art. 20). Silence releases nothing; it prohibits. Processing anyway exposes you to Article 56 penalties.
Your processing moves onto the authorisation track: transferring data to a foreign state requires the authority's approval and presupposes an adequate level of protection in the destination country (art. 44), and breach exposes you to penalties of up to five years and one million dinars (art. 67). The authority's compliance procedures document expressly cites foreign hosting among the cases requiring the authorisation regime.
Yes: footage identifying people is personal data, and capturing it is processing subject to the prior formality. Article 29 further allows the authority to issue CCTV-specific rules — a point to monitor, since such regulations are awaited; keep your retention periods short and justified from now on.
Sources and references
- Law No. 18-07 of 10 June 2018 on the protection of natural persons in the processing of personal data — Official Gazette No. 34 of 10/06/2018, pp. 11-21 (full text read) — Official Journal of the Algerian Republic (JORADP) · Verified on 22/08/2026
- Official compliance-procedures document: filing route, mandatory authorisation cases, dossier contents and deadlines observed by the authority — National Personal Data Protection Authority (ANPDP), April 2025 · Verified on 22/08/2026
- Official guide to declaring a processing on the authority's electronic portal (guide_declaration_traitement V1.0) — National Personal Data Protection Authority (ANPDP) · Verified on 22/08/2026
- Official portals: declarations and authorisation requests (portail.anpdp.dz), complaints and appeals (plaintes.anpdp.dz), presentation of the institution — National Personal Data Protection Authority (ANPDP) · Verified on 22/08/2026
