Keywords for this page

law 18-07 compliance ANPDP declaration processing mapping sensitive data transfers abroad breaches register information notices
What this is. A Law 18-07 compliance engagement run in the order the law itself thinks — map, qualify, declare, document — because that is where mistakes cost: a dossier filed without prior mapping, a customer base treated as a mere sales tool, foreign hosting discovered after the fact. We issue no receipts and no authorisations: that is the national authority's monopoly. We make sure that what you file matches what you actually do — and that what follows filing withstands an audit.

Why improvised compliance costs more than managed compliance

Law 18-07 does not only punish clandestine processing; it mostly punishes approximate processing. The situations behind requests for help keep coming back to the same four decisions taken too fast:

  • A filing without mapping. 'Customer file' gets declared while the purchased prospect list, the shop camera and the online HR tool are forgotten — every undeclared processing is a standalone offence.
  • A decorative consent. A pre-ticked box is not express consent; and as soon as sensitive data enters — health, beliefs, opinions — the regime switches to authorisation.
  • Hosting discovered late. The server has been abroad for three years when the question arrives: the transfer required authorisation (art. 44), and the offence runs up to five years and one million dinars.
  • Zero written trace. No information notice, no subcontractor contract with data clauses, no breaches register: nothing proving good faith on audit day or when a complaint lands.

The authority, for its part, has organised its arsenal: an active declaration portal, a separate complaints portal, statutory audit powers, graduated sanctions up to definitive withdrawal. Compliance there is no longer a horizon — it is a verifiable state.

What the engagement covers

1
Processing mapping. File by file — customers, prospects, employees, suppliers, cameras, web forms, hosted tools: purposes, categories of people and data, recipients, retention periods, processors, actual data location. That map drives everything else.
2
Legal qualification. For every processing: ordinary declaration, single declaration for linked purposes, or authorisation request (sensitive data, interconnection, transfer abroad). The test runs article by article, not by intuition.
3
Upgrading the foundations. Legal bases corrected (express consent, legitimate interest, contractual necessity), Article 32 information notices drafted, retention periods set and a purge procedure for legacy bases.
4
Dossiers filed. Complete preparation on the authority's portal: electronic form, supporting documents, top manager's signature, appointment booking and physical filing, tracking to receipt — corrections resubmitted if review requires.
5
Contracts and access control. Data-protection clauses inserted in your hosting, payroll, maintenance and marketing contracts (art. 39), confidentiality charter signed by authorised staff, designation of the rights-exercise service required by Article 14.
6
Compliance life. Breaches register kept and fed, internal procedure answering access and rectification requests within the ten-day deadline, annual review calendar — because an unguarded scheme slides back into breach silently.

What this engagement is not. We issue neither receipts nor authorisations. That competence belongs exclusively to the national authority. Nor do we install technical security solutions; our deliverable is the legal and documentary framework that makes your setup defensible. No engagement carries any commitment as to a decision of the authority.

What timeline should you expect?

PhaseIndicative durationInterim result
Mapping and qualification1-2 weeks depending on number of filesMaster table: one processing = one row = one regime
Documentary upgrade2-3 weeks, in parallel with filingsNotices, clauses, signed charters, rights procedures
Portal filingsA few days per dossier + authority reviewDeclaration receipts; authorisations tracked to decision
Closing review1 weekBreaches register operational, annual calendar set

The authority's own timelines add on top: declaration review announced within ten days, authorisation within two months extendable to four. They depend on the authority, not on us. Our deliverables are calibrated so nothing is missing from its files.

Where to start if everything cannot be done at once?

The whole company does not need to be compliant on day one. The order that yields the most per dinar invested:

  1. Sensitive data and transfers abroad come first. This is where penalties climb to five years and one million dinars, so qualify these processings in week one.
  2. Externally visible processings come second. The website, the prospecting list and the shop are what competitors, customers and journalists see, and therefore report.
  3. The internal core comes last. Payroll, HR records and archives are large volumes with contained incident risk; they come next.

A one-hour conversation is enough to lay out this prioritisation on your real case. It is free, and it often ends with a list of three actions you can launch without us.

Before filing your first dossiers

Compliance framing. First consultation free, reply within 24 hours.

Frequently asked questions

Sources and references

Passenger, or pilot?

ProfitPilot — profitpilot.dz