Law No. 25-11 of 24 July 2025 amending Law No. 18-07 on Personal Data Protection (Algeria)
dz-law-25-11-2025 · Act
Law No. 25-11 of 24 July 2025 is an amending statute that significantly strengthens Algeria's primary data protection framework, Law No. 18-07 of 10 June 2018 on the protection of natural persons in the processing of personal data. It modernises the 2018 regime, which had only become applicable in August 2023 (one year after the supervisory authority was installed), by importing several accountability-based obligations characteristic of the GDPR generation. The key changes introduced by Law No. 25-11 include: mandatory designation of a Data Protection Officer; an obligation to maintain records of processing activities; a requirement to conduct Data Protection Impact Assessments (DPIAs) for high-risk operations; and a breach-notification regime under which controllers must notify the National Authority for the Protection of Personal Data (ANPDP) of a personal data breach within five days of becoming aware, with processors required to notify the controller without delay. These additions move Algeria's framework closer to an accountability model, supplementing the declaration-and-authorisation architecture of the original 2018 law. This instrument is recorded to complement ATLPF's existing Algeria entry (Law No. 18-07), where the 2025 amendments had previously only been noted within the primary law's record. Capturing it as a separate instrument reflects Algeria's legislative history more accurately and supports the jurisdiction's documentation completeness. The ANPDP remains the supervisory authority. This entry was created during a June 2026 documentation pass. Reviewer should confirm the full scope of the amendments against the Journal Officiel and add the primary-source URL. Source language: French/Arabic.
- Amending statute strengthening Algeria's primary data protection law (Law No. 18-07 of 2018).
- Introduces mandatory Data Protection Officer designation.
- Requires records of processing activities and DPIAs for high-risk operations.
- Introduces a five-day breach-notification duty to the ANPDP, with processors required to notify controllers without delay.
- Moves Algeria's framework toward a GDPR-style accountability model.
- ANPDP remains the supervisory authority.
- Reviewer action: confirm the full scope of the amendments against the Journal Officiel and add a primary-source URL.