Key points
Chapter 01
Personal data, processing, controller: what exactly are we talking about?
Law No. 18-07 of 10 June 2018 builds its entire edifice on a handful of definitions set out in its Article 3. They deserve to be read one by one, because each decides whether your practices fall within scope.
| Concept | Legal definition | What it covers in practice |
|---|---|---|
| Personal data | Any information relating to an identified or identifiable person, directly or indirectly — in particular by reference to an identification number or to elements of physical, physiological, genetic, biometric, psychic, economic, cultural or social identity | Name, phone, address, email, photo, IP address, employee number… whatever the medium |
| Processing | Any operation applied to data, automated or not: collection, recording, storage, consultation, use, transmission, interconnection, locking, erasure, destruction | A paper address book as much as a CRM; mere consultation already counts |
| Data controller | The natural or legal person, public or private, that determines the purposes and means of processing | Your company, from the moment it decides why and how data is used |
| Subcontractor / processor | Whoever processes data on behalf of the controller | Hosting provider, payroll software publisher, agency managing your customer base |
| Sensitive data | Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, or relating to health including genetic data | A regime of prohibition by principle with narrow exceptions (art. 18) |
| Data subject | Any natural person whose data is processed | Customer, prospect, employee, individual supplier, website visitor |
Two useful clarifications. First, the law protects natural persons: a company's own data is not personal data — but its CEO's, as a natural person, is. Second, "processing" does not begin when you actively exploit data: merely keeping an old file is already processing under the law.
Chapter 02
Scope: who is concerned, who is not
The perimeter reads across three articles.
Article 4 — the territorial test. The law covers automated processing, even partial, and manual processing contained or intended for files. It targets controllers established on Algerian territory — any activity exercised on the territory suffices, whatever the legal form — as well as controllers established abroad who use means located in Algeria; in the latter case they must notify the authority of their representative established in Algeria.
Articles 5 and 21 — health. Research or study processings in the health field are subject to the law, with exceptions carved for ordinary medical practice (individual therapeutic follow-up, internal studies by care staff, reimbursement); what remains in scope requires authorisation.
Article 6 — exclusions. Three families fall outside: data processed by a natural person in the exclusively personal or domestic sphere without dissemination; data collected for national defence and security; data processed to prevent, investigate and prosecute offences, governed by their own texts.
Chapter 03
Before collecting: consent and quality principles
Before the declarative formality even arises, the law imposes substantive rules. They come in four blocks.
1. Express consent as the starting rule (art. 7). Processing may only be carried out with the express consent of the data subject, who may withdraw it at any time. Disclosing data to a third party also requires that prior consent — unless processing is necessary under Article 7's list: complying with a legal obligation, safeguarding life, performing a contract the person is party to, a public-interest mission, or pursuing the controller's legitimate interest subject to the person's fundamental rights and freedoms.
2. Children (art. 8). Processing a child's data requires parental or legal-representative consent — even a judge's authorisation, and the judge may also order processing where the child's best interest demands it.
3. Data quality (art. 9). Five cumulative requirements: lawful and fair processing; specified, explicit and legitimate purposes without incompatible reuse; adequate, relevant and non-excessive data; accuracy and updating; retention limited to the necessary period. This is the article that condemns customer bases never cleaned: keeping indefinitely is not neutral — it is an offence.
4. No standalone automated decision (art. 11). No decision producing legal effects may rest solely on automated profiling — except in contract performance, provided the person could present observations. A scoring system rejecting a customer with no human review possible sits squarely in this crosshair.
Add the often-overlooked Article 10: data on offences, sentences and security measures may only be processed by judicial authorities, certain public bodies and court officers. A private company has no business keeping a "record" of troublesome customers.
The personal data workbook
Seven worksheets that turn Law 18-07 into dated decisions: your processing map, each file's legal basis, the notices to publish, the breaches register and the review calendar.
- Your complete processing map, file by file
- The 'declaration or authorisation?' test for every processing
- The information-notice template and the model breaches register
- The annual compliance-review calendar
Chapter 04
The prior formality: declaration or authorisation
Once principles are secured remains the formality gating every start: Article 12 subjects every processing operation to a prior declaration with the national authority, or to its authorisation where the processing presents manifest dangers to privacy and freedoms. Three points structure the regime:
- The declaration entitles you to a receipt within forty-eight hours and allows implementation upon receipt (art. 13). Its content follows nine mandatory elements (art. 14): purposes through security measures, including recipients, retention periods and envisaged transfers.
- Authorisation applies to sensitive data (art. 18), file interconnection (art. 19) and health research (art. 21) — or when the authority switches your declaration to that regime after examination (art. 17). Two months, extendable; and silence equals rejection, not approval (art. 20).
- Transfer abroad itself falls under authorisation, with its own conditions (art. 44).
The detailed route — dossier contents, exemptions, actual filing on the authority's portal, penalties — has its own article: declaring a processing with the ANPDP. This guide picks up where that article stops: what must be true inside the declared processing.
Chapter 05
Data subjects' rights: information, access, rectification, objection
The law devotes Title IV to data subjects' rights. They form a coherent package your organisation must be able to serve — not in theory but with a designated service, procedures and deadlines.
| Right | Content | Vigilance point |
|---|---|---|
| Information (art. 32) | Before collection: controller identity, purposes, recipients, whether replies are mandatory and their consequences, rights, transfers abroad | Indirect collection: notice due before recording or disclosure; open-network collection: inform unless the person already knows |
| Access (art. 34) | Confirmation of processing, purposes, categories, recipients; intelligible communication including origin | The controller may push back on manifestly abusive requests — but bears the burden of proving abusiveness |
| Rectification (art. 35) | Updating, rectification, erasure or locking of non-compliant data, free of charge | Ten days to rectify at no cost; refusal or silence → the authority investigates; notification of third-party recipients; right transmissible to heirs |
| Objection (art. 36) | For legitimate reasons, against processing; absolute objection to commercial prospecting use | Inoperative against a legal obligation or what the authorisation expressly excluded |
| No prospecting without consent (art. 37) | Direct prospection banned via calling machines, fax, email absent prior consent | "Sale or similar service" exception with free opt-out offered at each message; valid contact details mandatory; sender identity non-concealable |
Refusing these rights without legitimate reason is not rudeness: it is an administrative fine of DZD 500,000 (art. 47) and a criminal offence carrying two months to two years' imprisonment (art. 64). The authority's official procedures document recommends designating explicitly the service receiving these requests — a dedicated functional mailbox suffices — and stating it in the declaration itself, as Article 14 requires.
Chapter 06
The controller's continuing obligations
Title V places continuing obligations on the controller. Four structure internal governance.
A sector-specific obligation completes the picture: electronic certification providers may only process data collected for certificate issuance for those very purposes (art. 42) — the natural bridge to our guide on electronic signatures in business.
Chapter 07
Sending data to a foreign country
This is probably the provision with the heaviest consequences for a digital economy: Article 44 prohibits transferring personal data to a foreign state without the national authority's authorisation, and only if that state ensures an adequate level of protection of privacy and freedoms. Adequacy is assessed by the authority: the country's laws, applicable security measures, characteristics of the processing, nature, origin and destination of the data. In all cases, transfer likely to harm public security or the state's vital interests is prohibited.
Article 45 opens precise derogations:
- the data subject's express consent to the transfer;
- necessity: saving life, public interest, establishing or defending a legal claim, performance of a contract with the data subject, concluding a contract in their interest, international judicial assistance, medical prevention, diagnosis or care;
- a bilateral or multilateral agreement to which Algeria is party;
- authorisation by the authority where the processing complies with Article 2.
Translated into business situations: an e-commerce site hosted outside Algeria, HR management running on a foreign tool, consolidated files sent to a parent company, a storage service replicating data abroad — each circuit crosses Article 44 and calls either for an Article 45 derogation or for authorisation. The offence is costly: one to five years' imprisonment and a fine of DZD 500,000 to 1,000,000 (art. 67).
Chapter 08
The authority that audits, the penalties that bite
The authority. The law creates, under the President of the Republic, an independent administrative authority with legal personality and financial autonomy (art. 22), composed of sixteen members appointed by presidential decree for five-year renewable terms (art. 23). Its missions cover the whole life cycle (art. 25): issuing authorisations and receiving declarations; informing and advising; handling complaints and appeals; authorising cross-border transfers; ordering modifications, locking, withdrawal or destruction of data; imposing administrative sanctions; drafting standards and codes of conduct. It keeps the national register of processings (art. 28), conducts on-site investigations outside dwellings against which professional secrecy cannot be raised (art. 49), and immediately informs the prosecutor general of criminal facts. The institution is no longer theoretical: internal rules adopted as early as July 2023, an active declaration portal, a separate complaints portal, annual reports published — the machinery runs.
Administrative sanctions (arts. 46-48). A graduated ladder: warning, formal notice, temporary withdrawal — capped at one year — or definitive withdrawal of the receipt or authorisation, and fines. The fine quantified by the statute is DZD 500,000 for refusing rights or missing notifications; withdrawal can be immediate where processing harms national security or public morals. Decisions are appealable before the Council of State.
Criminal sanctions (arts. 54-69). The criminal chapter lists thirteen offences:
| Offence | Penalty | Article |
|---|---|---|
| Breach of dignity, privacy, public freedoms (violating art. 2) | 2-5 years + DZD 200,000-500,000 | Art. 54 |
| Processing without consent, or despite legitimate objection | 1-3 years + DZD 100,000-300,000 | Art. 55 |
| Processing without declaration or authorisation; false declarations; continuing after withdrawal | 2-5 years + DZD 200,000-500,000 | Art. 56 |
| Sensitive data outside permitted cases | 2-5 years + DZD 200,000-500,000 | Art. 57 |
| Purpose diversion | 6 months-1 year + DZD 60,000-100,000 | Art. 58 |
| Fraudulent, unfair or unlawful collection | 1-3 years + DZD 100,000-300,000 | Art. 59 |
| Access left to unauthorised persons | 2-5 years + DZD 200,000-500,000 | Art. 60 |
| Obstructing the authority's controls | 6 months-2 years + DZD 60,000-200,000 | Art. 61 |
| Refusal of information, access, rectification, objection rights | 2 months-2 years + DZD 20,000-200,000 | Art. 64 |
| Breach of security obligations; excessive retention | Fine DZD 200,000-500,000 | Art. 65 |
| Failure to notify a data breach | 1-3 years + DZD 100,000-300,000 | Art. 66 |
| Unlawful transfer abroad | 1-5 years + DZD 500,000-1,000,000 | Art. 67 |
| Abusive or fraudulent use, even by negligence | 1-5 years + DZD 100,000-500,000 | Art. 69 |
Three general multipliers complete the set: attempt punished like the completed offence (art. 73), recidivism doubling penalties (art. 74), and legal entities liable under the criminal code with supplementary penalties up to ordered erasure of data (arts. 70-72).
And compliance? Article 75 set the framework: existing processings had one maximum year — counted from installation of the authority — to comply, failing which Article 56 penalties apply. With an authority operational since 2023 and online services active, that countdown lies behind us. The useful question is no longer "when must we start?" but "which workstream do we launch this week?" — processing mapping, formalities filed, information notices, subcontractor contracts, violations register. That is precisely the agenda of a compliance engagement.
Bring your company into compliance without guesswork
Processing mapping, information notices, declaration and authorisation dossiers, subcontractor clauses, breaches register: we run compliance end to end. First consultation free.
Frequently asked questions
Yes: no headcount or volume threshold exists in the statute. A sole proprietor keeping a customer file falls in scope as much as a bank. What varies is the scale of the compliance effort — how many processings to map, dossiers to file — not the obligation itself.
No. Law 18-07 knows no mandatory DPO. Article 14 does require designating, in every declaration, the service through which people exercise their rights — and the authority's procedures document recommends appointing a qualified representative to carry compliance internally. The function exists, without the European title or obligation.
Verify the requester's identity, then answer properly: confirmation of processings, intelligible communication and, for rectification, free execution within ten days (art. 35). Past that deadline without response, the requester may seize the authority, which mandates one of its members to investigate. Document every request and reply: it is your best defence.
They follow the common regime: consent or contractual necessity at hiring, explicit purposes, bounded retention periods, adequate security, prior formality. No 'human resources' exemption exists in the law — and an employee's health data (medical certificates) is sensitive data under the reinforced regime of Article 18.
Prohibited, no — but framed, yes. Transfer to a foreign state requires the authority's authorisation or an Article 45 derogation such as express consent. Before choosing any tool, ask where the data actually resides: it has become a selection criterion on par with price.
The main risk is criminal: two to five years' imprisonment and a fine of DZD 200,000 to 500,000 for processing without the prior formality (art. 56), penalties doubled upon recidivism (art. 74), plus administrative withdrawal and possible ordered erasure of data. Add the commercial effect: a competitor or customer can report the situation to the authority through its complaints portal.
Yes: footage identifying people is personal data, and capturing it is processing subject to the prior formality. Article 29 further allows the authority to issue CCTV-specific rules — expect sector regulation there; keep retention short and justified from now.
Sources and references
- Law No. 18-07 of 10 June 2018 on the protection of natural persons in the processing of personal data — Official Gazette No. 34 of 10/06/2018, pp. 11-21 (full text read) — Official Journal of the Algerian Republic (JORADP) · Verified on 22/08/2026
- Compliance-procedures document: qualified representative, information notices, security charters, mandatory authorisation cases, filing route — National Personal Data Protection Authority (ANPDP), April 2025 · Verified on 22/08/2026
- ANPDP internal rules, adopted 26 July 2023 (Article 64 cited by the procedures document regarding the breaches register) — National Personal Data Protection Authority (ANPDP) · Verified on 22/08/2026
- Presidential decrees Nos. 23-147 and 23-148 of 5 April 2023 on the staff statute and secondment terms of the national authority — Official Gazette No. 24 of 09/04/2023 — Official Journal of the Algerian Republic (JORADP) · Verified on 22/08/2026
- Official portals: declarations and authorisation requests (portail.anpdp.dz), complaints and appeals (plaintes.anpdp.dz), institution presentation — National Personal Data Protection Authority (ANPDP) · Verified on 22/08/2026
- Official guide to declaring a processing on the electronic portal (guide_declaration_traitement V1.0, August 2023) — National Personal Data Protection Authority (ANPDP) · Verified on 22/08/2026
- Authority publications: annual activity reports 2023, 2024 and 2025, semi-official bulletins and the compendium of texts (2025 edition) — National Personal Data Protection Authority (ANPDP) · Verified on 22/08/2026