Keywords for this page
Why improvised compliance costs more than managed compliance
Law 18-07 does not only punish clandestine processing; it mostly punishes approximate processing. The situations behind requests for help keep coming back to the same four decisions taken too fast:
- A filing without mapping. 'Customer file' gets declared while the purchased prospect list, the shop camera and the online HR tool are forgotten — every undeclared processing is a standalone offence.
- A decorative consent. A pre-ticked box is not express consent; and as soon as sensitive data enters — health, beliefs, opinions — the regime switches to authorisation.
- Hosting discovered late. The server has been abroad for three years when the question arrives: the transfer required authorisation (art. 44), and the offence runs up to five years and one million dinars.
- Zero written trace. No information notice, no subcontractor contract with data clauses, no breaches register: nothing proving good faith on audit day or when a complaint lands.
The authority, for its part, has organised its arsenal: an active declaration portal, a separate complaints portal, statutory audit powers, graduated sanctions up to definitive withdrawal. Compliance there is no longer a horizon — it is a verifiable state.
What the engagement covers
What this engagement is not. We issue neither receipts nor authorisations. That competence belongs exclusively to the national authority. Nor do we install technical security solutions; our deliverable is the legal and documentary framework that makes your setup defensible. No engagement carries any commitment as to a decision of the authority.
What timeline should you expect?
| Phase | Indicative duration | Interim result |
|---|---|---|
| Mapping and qualification | 1-2 weeks depending on number of files | Master table: one processing = one row = one regime |
| Documentary upgrade | 2-3 weeks, in parallel with filings | Notices, clauses, signed charters, rights procedures |
| Portal filings | A few days per dossier + authority review | Declaration receipts; authorisations tracked to decision |
| Closing review | 1 week | Breaches register operational, annual calendar set |
The authority's own timelines add on top: declaration review announced within ten days, authorisation within two months extendable to four. They depend on the authority, not on us. Our deliverables are calibrated so nothing is missing from its files.
Where to start if everything cannot be done at once?
The whole company does not need to be compliant on day one. The order that yields the most per dinar invested:
- Sensitive data and transfers abroad come first. This is where penalties climb to five years and one million dinars, so qualify these processings in week one.
- Externally visible processings come second. The website, the prospecting list and the shop are what competitors, customers and journalists see, and therefore report.
- The internal core comes last. Payroll, HR records and archives are large volumes with contained incident risk; they come next.
A one-hour conversation is enough to lay out this prioritisation on your real case. It is free, and it often ends with a list of three actions you can launch without us.
Before filing your first dossiers
Compliance framing. First consultation free, reply within 24 hours.
Frequently asked questions
You must regularise. Article 75 has set the direction since the authority's installation, but not everything has to move at once. The useful sequence starts with mapping: qualify, fix legal bases and retention periods, then file by order of risk. Filing one clean dossier beats filing ten approximate ones that come back for corrections.
No, and nobody can, because the decision belongs exclusively to the national authority. What we guarantee is a dossier complete under the texts, a qualification argued article by article, and follow-up on any review observations with a corrected resubmission.
The same method applies there, with the same mapping, the same formalities and the same documents, since the law targets both public and private controllers. But certain public files follow their own rules (consultable registers, judicial databases). The first qualification phase exists to identify those special regimes before any filing.
Location settles the transfer question, not the subcontracting one. Your host processes data on your behalf, so they need sufficient guarantees and a contract with data-protection clauses (art. 39), and it remains to verify physically where backups and third-party services called by your solution reside.
Sources and references
- Law No. 18-07 of 10 June 2018 on the protection of natural persons in the processing of personal data — Official Gazette No. 34 of 10/06/2018 (full text read) — Official Journal of the Algerian Republic (JORADP) · Verified on 22/08/2026
- Compliance-procedures document: filing route, mandatory authorisation cases, dossier contents, document templates — National Personal Data Protection Authority (ANPDP), April 2025 · Verified on 22/08/2026
- Official portals: declarations and authorisation requests (portail.anpdp.dz), complaints and appeals (plaintes.anpdp.dz) — National Personal Data Protection Authority (ANPDP) · Verified on 22/08/2026