No personal data processing starts without a prior formality

In short: The rule fits in one sentence. In Algeria, every processing of personal data — customers, employees, prospects, cameras — must be covered either by a prior declaration with the National Personal Data Protection Authority or by an authorisation where the processing is risky (art. 12, Law 18-07). A declaration entitles you to a receipt within forty-eight hours and lets you start upon receipt; an authorisation takes two months, and silence equals rejection, not approval.

Keywords in this article

prior declaration ANPDP filing receipt law 18-07 prior authorisation sensitive data transfer abroad file interconnection national register

1. No processing starts without a prior formality

It is Article 12 of Law No. 18-07 of 10 June 2018, and it carries no size-based exception: "any processing operation of personal data" — whatever the size of the organisation behind it — "is subject to a prior declaration to the national authority or to its authorisation". A customer spreadsheet falls within scope just as much as an e-commerce platform or a CCTV system.

Three regimes therefore coexist, and the first task is to place your processing in the right one:

Prior declarationPrior authorisation
Starting pointThe default rule of common law under this statute (art. 12)The processing presents manifest dangers to privacy and fundamental freedoms upon examination of the declaration (art. 17)
Cases imposed by lawSensitive data (art. 18); interconnection of files (art. 19); health research and studies (art. 21)
Authority's response timeReceipt immediately or within 48 hours (art. 13)Two months, extendable once for the same period (art. 20)
What can you do meanwhile?Start the processing upon receipt of the receipt slip (art. 13)Wait: the authority's silence equals rejection, not approval (art. 20)

The scope deserves verification before anything else: the law covers automated processing even partially, and manual files too; it also reaches a controller established abroad who uses means located on Algerian territory (art. 4).

2. The declaration: file, receive the receipt, start

The declaration is simple in form, demanding in substance. Filed with the national authority — electronic filing is expressly provided for by Article 13 — it amounts to an undertaking that the processing will be conducted in accordance with the law, and a filing receipt is issued immediately or at the latest within forty-eight hours. From that moment, the controller may start operating the processing, under their own responsibility.

Article 14 sets nine mandatory elements, which map exactly what you must know about your own processing before declaring it:

1
The name and address of the controller — and of its representative where applicable.
2
The nature, characteristics and purpose(s) of the intended processing.
3
The categories of data subjects and of data processed.
4
The recipients, or categories of recipients, to whom data may be disclosed.
5
The nature of data whose transfer to foreign countries is envisaged.
6
The retention period of the data.
7
The service through which each person can exercise their rights, and the measures facilitating that exercise.
8
A general description of the measures taken to ensure confidentiality and security.
9
Interconnections, disclosures to third parties and subcontracting, in any form, free of charge or against payment.

Two logistical complements close the loop. Processings run by the same controller with identical or related purposes may be covered by a single declaration (art. 13) — no need to stack files. And any change to the declared information, as well as any deletion of a processing operation, must be notified without delay (art. 14): a declaration is not archived paperwork, it is a living record that follows the life of the processing. When a data file is sold, the acquirer completes the formalities anew.

3. When a declaration switches to authorisation

Prior authorisation comes into play in two configurations. Either the processing falls from the outset into a category the law subjects to it; or the authority, examining the filed declaration, finds manifest dangers to privacy and freedoms and decides to subject the processing to that regime — a reasoned decision notified within ten days of filing (art. 17).

The three blocks imposed by law:

BlockContentArticle
Sensitive dataRacial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, health including genetic data: processing is prohibited by principle and admitted only in the exhaustively listed cases — indispensable public interest tied to the controller's legal functions, express consent, statutory provision, or authorisation by the authority, plus specific cases (vital interests, data made public, defending a legal claim)Arts. 3 and 18
Interconnection of filesLinking files held by legal persons managing a public service pursuing different public interests, as well as private files with different main purposes, requires authorisationArt. 19
Research and healthProcessings for research, study or evaluation in the field of health serving a public interest are authorised by the authority, which may group several processings under a single decisionArt. 21

To these add the case many companies discover too late: transferring data to a foreign country. Article 44 makes it subject to the authority's authorisation and to an adequate level of protection ensured by the destination state — and Article 14 already requires the declaration itself to flag data whose transfer is envisaged. Hosting your customer files with a foreign provider, running your management on a platform hosted outside Algeria, sending consolidated files to a parent company: each of these circuits raises the question.

The silence trap. On an authorisation request, the authority has two months, extendable once for the same period. But if it has not ruled when that period expires, the request "is deemed rejected" (art. 20) — the opposite of many administrative procedures where silence means approval. Never launch risky processing counting on the authority's non-response.

4. The rare exemptions — and a list still to be published

Not everything is declared. Three families fall outside:

  • The law's own exclusions (art. 6): data processed by a natural person in the exclusively personal or domestic sphere without dissemination; data collected for national defence and security; data processed for the prevention, investigation and prosecution of offences, which follow their own texts.
  • Public registers (art. 16): keeping a register open to public consultation — or to anyone demonstrating a legitimate interest — is exempt from declaration, provided a controller is designated whose identity is made public and notified to the authority, and who answers requests about purposes, identity, data and recipients.
  • Simple processings (art. 15): the authority fixes the list of categories of processings posing no risk to rights and freedoms, which benefit from a simplified declaration limited to six of the nine elements of Article 14 — and may extend that regime to non-automated processing.

On this third family, a dated caveat applies: as at our verification date (22 August 2026), we have not found this list published on the authority's official channels. The law entrusts the list to the authority; nothing consultable says today which categories it covers. Until it becomes accessible, the safe reflex is to treat every professional file as falling under ordinary declaration — and to use consultation, which is among the authority's core missions (art. 25), whenever in doubt.

5. What missing the declaration costs

The law punishes clandestine processing severely. The heart of the scheme is Article 56: carrying out processing without complying with Article 12 — i.e. without a filed declaration or an obtained authorisation — exposes you to two to five years' imprisonment and a fine of DZD 200,000 to 500,000. The same penalties apply to anyone making false declarations or continuing to process after withdrawal of the receipt or of the authorisation.

The full escalation, as fixed by the criminal chapter:

ConductPenaltyArticle
Processing without declaration or authorisation; false declarations; continuing after withdrawal2-5 years + DZD 200,000-500,000Art. 56
Sensitive data processed outside permitted cases2-5 years + DZD 200,000-500,000Art. 57
Data used for purposes other than those declared or authorised6 months-1 year + DZD 60,000-100,000Art. 58
Collection by fraudulent, unfair or unlawful means1-3 years + DZD 100,000-300,000Art. 59
Refusal, without legitimate reason, of information, access, rectification or objection rights2 months-2 years + DZD 20,000-200,000Art. 64
Unlawful transfer to a foreign state1-5 years + DZD 500,000-1,000,000Art. 67
RecidivismPenalties doubledArt. 74

In parallel, the authority has a graduated administrative arm (art. 46): warning, formal notice, temporary withdrawal — capped at one year — or definitive withdrawal of the receipt or authorisation, and fines. One administrative fine is quantified by the statute itself: DZD 500,000 against a controller refusing rights without legitimate reason or failing the notifications required by Articles 4, 14 and 16 (art. 47), switching to criminal liability upon recidivism. Its decisions are appealable before the Council of State.

A deadline already run. Article 75 gave existing processings a maximum one-year period — counted from the installation of the national authority — to comply, failing which Article 56 penalties apply. The authority has been operational since 2023 (internal rules adopted as early as July 2023, online services active): for a file created before that period, regularisation is no longer a project to schedule, it is a situation to fix.

Map your processings and file your dossiers without guesswork

Inventory of processings to regularise, choosing between declaration and authorisation, preparing the dossiers on the authority's portal and tracking them to receipt: we frame the compliance effort with you.

Frame my compliance

6. How the process runs today

The statute describes the formality; the authority describes how it actually runs. Its official compliance procedures document (published April 2025) and its portal guides organise the following circuit:

1
Designate a qualified representative. Legal, technical or administrative, versed in Law 18-07, they carry the effort. The authority also recommends an internal committee mapping every processing operation.
2
Create an account on the authority's portal (portail.anpdp.dz) in the name of that representation, then complete the electronic declaration form — one form per processing, unless purposes are identical or linked.
3
Have it signed by the top manager. The printed form bears their signature; if someone else signs, a delegation accompanies the file.
4
Book an appointment and file the dossier. The portal assigns an appointment; the physical file is handed over to the authority, which issues a filing receipt if no observation has been raised.
5
Track review online. The file status is visible from the declarant's workspace: recorded, scheduled, under review, then decision — validated, corrections to resubmit, or switch to the authorisation regime.

This service snapshot is dated: it describes the circuit as documented by the authority at our verification date, and it can change without any text moving. What it clearly shows, however, fits in one sentence: the formality is not a checkbox but a small project — mapping, form, signature, filing — where each step produces a document you keep.

FAQ — Frequently asked questions

Sources and references

BENSAID Farouk ProfitPilot

BENSAID Farouk

Financial & Economic Research Consultant — ProfitPilot NextGen Consulting

Certified sole trader and expert in financial studies, risk analysis and market research for SMEs, startups and investors in Algeria. View full profile