Loi n° 18-07 du 10 juin 2018 relative à la protection des personnes physiques dans le traitement des données à caractère personnel (Law No. 18-07 of 10 June 2018 on the Protection of Natural Persons in the Processing of Personal Data)
dz-dp-2018 · Act
Law No. 18-07 of 10 June 2018 on the Protection of Natural Persons in the Processing of Personal Data (Loi n° 18-07) is Algeria’s primary legislative framework for personal data protection. Published in the Journal Officiel de la République Algérienne No. 34 of 10 June 2018, it is modelled on European data protection principles. Its entry into force was contingent on the establishment of the National Authority for the Protection of Personal Data (ANPDP): the Authority was formally installed on 11 August 2022, and by operation of Article 75 the law became applicable one year later, on 11 August 2023. The law has since been amended and supplemented by Law No. 25-11 of 24 July 2025, which introduced mandatory Data Protection Officer (DPO) designation, records of processing activities, Data Protection Impact Assessments (DPIAs), and a breach notification regime. The law applies to any processing of personal data by a controller established in Algeria or using processing means located on Algerian territory. It covers both automated and non-automated processing and applies to public and private entities alike. Personal data is defined broadly as any information, in any form and on any medium, that identifies or makes identifiable a natural person directly or indirectly. Controllers must file a prior declaration with the ANPDP before commencing any processing operation. Where processing presents clear risks to privacy or fundamental rights, including sensitive data processing, interconnection of public-interest databases, or cross-border transfers, prior ANPDP authorisation is required. The fundamental data quality principles apply: data must be processed lawfully and fairly, collected for specified and legitimate purposes, be adequate and not excessive, remain accurate and up to date, and be kept no longer than necessary. Sensitive data, covering racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, and genetic data, is subject to a general prohibition with narrow statutory exceptions, including vital interests of the data subject, specific associational processing, and scientific or medical research purposes. Data subjects enjoy rights of prior information, access to their data, rectification or erasure of non-compliant data within ten days of referral, and objection for legitimate reasons including direct marketing. Cross-border transfers require ANPDP authorisation and are permitted only to countries providing adequate protection; absolute prohibition applies where the transfer could endanger public security or vital State interests. Enforcement includes administrative sanctions (warnings, formal notices, suspension or withdrawal of authorisation, fines up to 6 million DZD) and criminal penalties ranging from two months to five years’ imprisonment, doubled for repeat offences. Law No. 25-11 (2025) additionally introduced a mandatory obligation to notify the ANPDP of personal data breaches within five days of becoming aware, with processors required to notify the controller without delay.
- Prior declaration to ANPDP required for all personal data processing; prior ANPDP authorisation required for sensitive data processing, cross-border transfers, and interconnection of public-interest databases
- Processing of sensitive data (racial/ethnic origin, health, genetic data, political and religious beliefs) prohibited in principle, with narrow statutory exceptions
- Data subjects hold rights of information, access, rectification within ten days, and objection, including to direct marketing
- Cross-border transfers require ANPDP authorisation and are permitted only to countries offering adequate protection; absolute bar where transfer endangers public security or vital State interests
- Controllers must implement appropriate technical and organisational security measures commensurate with risk and data sensitivity
- Law No. 25-11 (2025) introduces mandatory DPO designation, processing records, automated logbooks, DPIAs for high-risk operations, and five-day breach notification to ANPDP
- Administrative sanctions include warnings and fines up to 6 million DZD; criminal penalties range from two months to five years’ imprisonment, doubled for repeat offences