One law, one authority, zero excuses. Law No. 18-07 has framed every processing of personal data in Algeria since 2018: express consent, defined purposes, bounded retention, a prior formality with the national authority. Long without teeth, the machinery is now complete: the authority receives declarations on its portal, investigates complaints, audits and sanctions. This guide walks through the law as it applies — and the workstreams it opens.

Key points

Applicable textLaw No. 18-07 of 10 June 2018 (Official Gazette No. 34 of 10/06/2018) — all 76 articles read for this guide
Competent authorityNational Personal Data Protection Authority (ANPDP) — operational since 2023, declaration and complaints portals active
Prior formalityDeclaration (receipt within 48 h) or authorisation (2 months, silence = rejection) — arts. 12-21
Substantive ruleExpress consent except narrow exceptions; specified purposes; minimisation; bounded duration — arts. 7 and 9
Transfers abroadAuthorisation required + adequate level of protection — arts. 44-45; dedicated criminal offence art. 67
Maximum sanctionsUp to 5 years and DZD 1,000,000 (unlawful transfer); administrative fine DZD 500,000; recidivism × 2

Chapter 01

Personal data, processing, controller: what exactly are we talking about?

Law No. 18-07 of 10 June 2018 builds its entire edifice on a handful of definitions set out in its Article 3. They deserve to be read one by one, because each decides whether your practices fall within scope.

ConceptLegal definitionWhat it covers in practice
Personal dataAny information relating to an identified or identifiable person, directly or indirectly — in particular by reference to an identification number or to elements of physical, physiological, genetic, biometric, psychic, economic, cultural or social identityName, phone, address, email, photo, IP address, employee number… whatever the medium
ProcessingAny operation applied to data, automated or not: collection, recording, storage, consultation, use, transmission, interconnection, locking, erasure, destructionA paper address book as much as a CRM; mere consultation already counts
Data controllerThe natural or legal person, public or private, that determines the purposes and means of processingYour company, from the moment it decides why and how data is used
Subcontractor / processorWhoever processes data on behalf of the controllerHosting provider, payroll software publisher, agency managing your customer base
Sensitive dataData revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, or relating to health including genetic dataA regime of prohibition by principle with narrow exceptions (art. 18)
Data subjectAny natural person whose data is processedCustomer, prospect, employee, individual supplier, website visitor

Two useful clarifications. First, the law protects natural persons: a company's own data is not personal data — but its CEO's, as a natural person, is. Second, "processing" does not begin when you actively exploit data: merely keeping an old file is already processing under the law.

Chapter 02

Scope: who is concerned, who is not

The perimeter reads across three articles.

Article 4 — the territorial test. The law covers automated processing, even partial, and manual processing contained or intended for files. It targets controllers established on Algerian territory — any activity exercised on the territory suffices, whatever the legal form — as well as controllers established abroad who use means located in Algeria; in the latter case they must notify the authority of their representative established in Algeria.

Articles 5 and 21 — health. Research or study processings in the health field are subject to the law, with exceptions carved for ordinary medical practice (individual therapeutic follow-up, internal studies by care staff, reimbursement); what remains in scope requires authorisation.

Article 6 — exclusions. Three families fall outside: data processed by a natural person in the exclusively personal or domestic sphere without dissemination; data collected for national defence and security; data processed to prevent, investigate and prosecute offences, governed by their own texts.

The resulting finding. An ordinary Algerian SME never escapes scope: customer and prospect files, payroll and HR records, mailing lists, CCTV, the website contact form — every professional file is a processing, and every processing calls for the prior formality developed below.

Chapter 03

Before collecting: consent and quality principles

Before the declarative formality even arises, the law imposes substantive rules. They come in four blocks.

1. Express consent as the starting rule (art. 7). Processing may only be carried out with the express consent of the data subject, who may withdraw it at any time. Disclosing data to a third party also requires that prior consent — unless processing is necessary under Article 7's list: complying with a legal obligation, safeguarding life, performing a contract the person is party to, a public-interest mission, or pursuing the controller's legitimate interest subject to the person's fundamental rights and freedoms.

2. Children (art. 8). Processing a child's data requires parental or legal-representative consent — even a judge's authorisation, and the judge may also order processing where the child's best interest demands it.

3. Data quality (art. 9). Five cumulative requirements: lawful and fair processing; specified, explicit and legitimate purposes without incompatible reuse; adequate, relevant and non-excessive data; accuracy and updating; retention limited to the necessary period. This is the article that condemns customer bases never cleaned: keeping indefinitely is not neutral — it is an offence.

4. No standalone automated decision (art. 11). No decision producing legal effects may rest solely on automated profiling — except in contract performance, provided the person could present observations. A scoring system rejecting a customer with no human review possible sits squarely in this crosshair.

Add the often-overlooked Article 10: data on offences, sentences and security measures may only be processed by judicial authorities, certain public bodies and court officers. A private company has no business keeping a "record" of troublesome customers.

Free, on request

The personal data workbook

Seven worksheets that turn Law 18-07 into dated decisions: your processing map, each file's legal basis, the notices to publish, the breaches register and the review calendar.

  • Your complete processing map, file by file
  • The 'declaration or authorisation?' test for every processing
  • The information-notice template and the model breaches register
  • The annual compliance-review calendar
Request the free workbook

Chapter 04

The prior formality: declaration or authorisation

Once principles are secured remains the formality gating every start: Article 12 subjects every processing operation to a prior declaration with the national authority, or to its authorisation where the processing presents manifest dangers to privacy and freedoms. Three points structure the regime:

  • The declaration entitles you to a receipt within forty-eight hours and allows implementation upon receipt (art. 13). Its content follows nine mandatory elements (art. 14): purposes through security measures, including recipients, retention periods and envisaged transfers.
  • Authorisation applies to sensitive data (art. 18), file interconnection (art. 19) and health research (art. 21) — or when the authority switches your declaration to that regime after examination (art. 17). Two months, extendable; and silence equals rejection, not approval (art. 20).
  • Transfer abroad itself falls under authorisation, with its own conditions (art. 44).

The detailed route — dossier contents, exemptions, actual filing on the authority's portal, penalties — has its own article: declaring a processing with the ANPDP. This guide picks up where that article stops: what must be true inside the declared processing.

Chapter 05

Data subjects' rights: information, access, rectification, objection

The law devotes Title IV to data subjects' rights. They form a coherent package your organisation must be able to serve — not in theory but with a designated service, procedures and deadlines.

RightContentVigilance point
Information (art. 32)Before collection: controller identity, purposes, recipients, whether replies are mandatory and their consequences, rights, transfers abroadIndirect collection: notice due before recording or disclosure; open-network collection: inform unless the person already knows
Access (art. 34)Confirmation of processing, purposes, categories, recipients; intelligible communication including originThe controller may push back on manifestly abusive requests — but bears the burden of proving abusiveness
Rectification (art. 35)Updating, rectification, erasure or locking of non-compliant data, free of chargeTen days to rectify at no cost; refusal or silence → the authority investigates; notification of third-party recipients; right transmissible to heirs
Objection (art. 36)For legitimate reasons, against processing; absolute objection to commercial prospecting useInoperative against a legal obligation or what the authorisation expressly excluded
No prospecting without consent (art. 37)Direct prospection banned via calling machines, fax, email absent prior consent"Sale or similar service" exception with free opt-out offered at each message; valid contact details mandatory; sender identity non-concealable

Refusing these rights without legitimate reason is not rudeness: it is an administrative fine of DZD 500,000 (art. 47) and a criminal offence carrying two months to two years' imprisonment (art. 64). The authority's official procedures document recommends designating explicitly the service receiving these requests — a dedicated functional mailbox suffices — and stating it in the declaration itself, as Article 14 requires.

Chapter 06

The controller's continuing obligations

Title V places continuing obligations on the controller. Four structure internal governance.

1
Secure (art. 38). Implement appropriate technical and organisational measures against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access — at a level matched to the processing's risks and the nature of the data. The authority's procedures document translates this into practice: a security-and-confidentiality charter signed by everyone granted access.
2
Frame your processors (art. 39). Choose only those offering sufficient guarantees, bound by contract to act solely on the controller's instructions and to meet the same security requirements. Hosting entrusted without data-protection clauses is the controller's fault, not just the provider's.
3
Enforce confidentiality (arts. 40-41). Professional secrecy binds everyone who accessed the data, even after their duties end; and no one may process data reached through work other than on the controller's instructions.
4
Document breaches (art. 43). Where processing over public electronic-communications networks results in destruction, loss, alteration, unauthorised disclosure or access, the service provider must notify the authority and the data subject without delay where privacy may be affected — and keep an inventory of breaches and remedies. The text targets service providers; the authority nevertheless recommends every controller keep this register, the centrepiece of your defence when an incident occurs.

A sector-specific obligation completes the picture: electronic certification providers may only process data collected for certificate issuance for those very purposes (art. 42) — the natural bridge to our guide on electronic signatures in business.

Chapter 07

Sending data to a foreign country

This is probably the provision with the heaviest consequences for a digital economy: Article 44 prohibits transferring personal data to a foreign state without the national authority's authorisation, and only if that state ensures an adequate level of protection of privacy and freedoms. Adequacy is assessed by the authority: the country's laws, applicable security measures, characteristics of the processing, nature, origin and destination of the data. In all cases, transfer likely to harm public security or the state's vital interests is prohibited.

Article 45 opens precise derogations:

  • the data subject's express consent to the transfer;
  • necessity: saving life, public interest, establishing or defending a legal claim, performance of a contract with the data subject, concluding a contract in their interest, international judicial assistance, medical prevention, diagnosis or care;
  • a bilateral or multilateral agreement to which Algeria is party;
  • authorisation by the authority where the processing complies with Article 2.

Translated into business situations: an e-commerce site hosted outside Algeria, HR management running on a foreign tool, consolidated files sent to a parent company, a storage service replicating data abroad — each circuit crosses Article 44 and calls either for an Article 45 derogation or for authorisation. The offence is costly: one to five years' imprisonment and a fine of DZD 500,000 to 1,000,000 (art. 67).

Where the picture stays open. Neither the statute as read nor the official documents consulted at our verification date (22 August 2026) publish a list of "adequate" states or model agreements: every transfer dossier is assessed case by case before the authority. Do not build an IT architecture on an equivalence presumption that does not exist.

Chapter 08

The authority that audits, the penalties that bite

The authority. The law creates, under the President of the Republic, an independent administrative authority with legal personality and financial autonomy (art. 22), composed of sixteen members appointed by presidential decree for five-year renewable terms (art. 23). Its missions cover the whole life cycle (art. 25): issuing authorisations and receiving declarations; informing and advising; handling complaints and appeals; authorising cross-border transfers; ordering modifications, locking, withdrawal or destruction of data; imposing administrative sanctions; drafting standards and codes of conduct. It keeps the national register of processings (art. 28), conducts on-site investigations outside dwellings against which professional secrecy cannot be raised (art. 49), and immediately informs the prosecutor general of criminal facts. The institution is no longer theoretical: internal rules adopted as early as July 2023, an active declaration portal, a separate complaints portal, annual reports published — the machinery runs.

Administrative sanctions (arts. 46-48). A graduated ladder: warning, formal notice, temporary withdrawal — capped at one year — or definitive withdrawal of the receipt or authorisation, and fines. The fine quantified by the statute is DZD 500,000 for refusing rights or missing notifications; withdrawal can be immediate where processing harms national security or public morals. Decisions are appealable before the Council of State.

Criminal sanctions (arts. 54-69). The criminal chapter lists thirteen offences:

OffencePenaltyArticle
Breach of dignity, privacy, public freedoms (violating art. 2)2-5 years + DZD 200,000-500,000Art. 54
Processing without consent, or despite legitimate objection1-3 years + DZD 100,000-300,000Art. 55
Processing without declaration or authorisation; false declarations; continuing after withdrawal2-5 years + DZD 200,000-500,000Art. 56
Sensitive data outside permitted cases2-5 years + DZD 200,000-500,000Art. 57
Purpose diversion6 months-1 year + DZD 60,000-100,000Art. 58
Fraudulent, unfair or unlawful collection1-3 years + DZD 100,000-300,000Art. 59
Access left to unauthorised persons2-5 years + DZD 200,000-500,000Art. 60
Obstructing the authority's controls6 months-2 years + DZD 60,000-200,000Art. 61
Refusal of information, access, rectification, objection rights2 months-2 years + DZD 20,000-200,000Art. 64
Breach of security obligations; excessive retentionFine DZD 200,000-500,000Art. 65
Failure to notify a data breach1-3 years + DZD 100,000-300,000Art. 66
Unlawful transfer abroad1-5 years + DZD 500,000-1,000,000Art. 67
Abusive or fraudulent use, even by negligence1-5 years + DZD 100,000-500,000Art. 69

Three general multipliers complete the set: attempt punished like the completed offence (art. 73), recidivism doubling penalties (art. 74), and legal entities liable under the criminal code with supplementary penalties up to ordered erasure of data (arts. 70-72).

And compliance? Article 75 set the framework: existing processings had one maximum year — counted from installation of the authority — to comply, failing which Article 56 penalties apply. With an authority operational since 2023 and online services active, that countdown lies behind us. The useful question is no longer "when must we start?" but "which workstream do we launch this week?" — processing mapping, formalities filed, information notices, subcontractor contracts, violations register. That is precisely the agenda of a compliance engagement.

Bring your company into compliance without guesswork

Processing mapping, information notices, declaration and authorisation dossiers, subcontractor clauses, breaches register: we run compliance end to end. First consultation free.

Frequently asked questions

Sources and references