GRC & Compliance

Law 18-07: personal data protection in Algeria

Enacted on 10 June 2018, Law 18-07 is Algeria's first framework dedicated to protecting personal data. What it protects, who it binds, the rights it grants, and the compliance path to the ANPDP.

Intervalle Technologies 8 min read

Law 18-07 of 10 June 2018 is Algeria's first statute wholly dedicated to protecting natural persons in the processing of their personal data. It applies to any organisation, public or private, established in Algeria or directly targeting Algerian residents. For those organisations it is not administrative housekeeping : it is a substantive obligation, backed by criminal penalties. Understanding its architecture means understanding what the regulator actually expects from any body that collects, stores or uses personal data.

What Law 18-07 protects, and who it binds

Personal data is any information relating to an identified or identifiable natural person — directly, through a name and surname, or indirectly, by combining several elements. It can take the form of text, an image, a sound or code, on any medium : a name, a photo, an email address, a phone number, a CV or a payslip are all covered. The law grants reinforced protection to sensitive data, such as information touching on health or on social and ethnic origin.

The scope is broad. It covers automated and non-automated processing alike, including manual files. It reaches the data controller established in Algeria, or in a State whose legislation is recognised as equivalent. And where a controller not established in Algeria uses means located on national territory, it must notify the national authority of the identity of its representative in the country. A few operations fall outside the text : purely personal or domestic activities that are not disclosed to third parties, those relating to national defence and security, judicial databases, and certain health-related processing — individual therapeutic follow-up, insurance control, and studies carried out by medical personnel.

For an Algerian organisation, Law 18-07 is not a box to tick : it is a substantive obligation, backed by criminal penalties.

The actors in processing, and the principles that govern them

The law organises protection around three roles. The data controller decides the purposes and the means : it collects, retains, updates and deletes data, declares its processing, obtains consent, informs individuals of their rights and handles their requests. The data protection officer (DPO), independent and equipped with specific skills, advises the organisation, monitors compliance and acts as the point of contact with the authorities. The processor, finally, acts on the controller's behalf and on its instructions ; it carries its own obligations of confidentiality, security, transparency and accountability.

These actors share a common foundation of principles. Processing must be legitimate, fair and transparent. It is bound by purpose limitation and by a principle of proportionality : only the data strictly necessary to the stated objectives is processed. Data minimisation requires data that is adequate, relevant and not excessive (Art. 9), accurate and kept for a reasonable period. The data subject's express consent is, in principle, required (Art. 7), save for exceptions — legal obligation, safeguarding life, performance of a contract, public interest or legitimate interest. To these requirements the law adds a duty of security and confidentiality, delivered through technical and organisational measures such as encryption, strong authentication and access management. This is where data protection meets the organisation's wider governance, risk and compliance posture.

The rights of data subjects

Against these obligations, the law opens four rights that shape the relationship with the data controller. The right to information requires that the person be told, before collection, of the controller's identity, the purposes and any other useful information — except for processing carried out for statistical, historical or scientific purposes. The right of access lets a person confirm that processing exists, learn its purposes, the categories of data and the recipients, and receive their data in an intelligible form together with information on its origin ; the controller may set reasonable response times and refuse abusive requests.

The right of rectification opens the free update, rectification, erasure or blocking of data where processing is not compliant. The controller must act within ten days ; failing that, the person may refer the matter to the national authority, and rectifications must be notified to the third parties to whom the data was disclosed. The right to object, finally, allows a person to refuse processing on legitimate grounds, and to object without condition to the use of their data for commercial marketing.

Becoming compliant : declaration, authorisation and the ANPDP

The law created the National Authority for the Protection of Personal Data (ANPDP), an independent authority tasked with enforcing the text and safeguarding individuals' rights. Before any processing, the controller files a prior declaration setting out its identity and that of its representative, the nature and purposes of the processing, the categories of persons and data concerned, the recipients, the retention period, the service where rights are exercised, the security measures and any interconnections or transfers of data to third parties. Structured support, such as a Law 18-07 compliance audit, helps assemble these files without gaps.

The system distinguishes three types of request. A declaration applies to standard processing, with an instruction time of around ten days. An authorisation is required for sensitive data, interconnections and transfers ; its review takes two months, extendable to four. A consultation, finally, lets an organisation seek an opinion on a project. The steps are handled on the ANPDP portal, completed by a physical filing of the case and the issue of a receipt. Cross-border transfers of data require prior authorisation ; they are prohibited where they would compromise public security or the vital interests of the State, and allow only strict exceptions — explicit consent, safeguarding life, legal obligations. To enforce this regime, the ANPDP can conduct investigations, inspections and audits, and access data and documents on any medium.

Key takeaways

  • Scope: any public or private body established in Algeria or targeting Algerian residents, across automated and manual processing.
  • Three actors: data controller, DPO and processor, each with its own obligations.
  • Four rights: information, access, rectification (within ten days) and objection.
  • ANPDP: prior declaration or authorisation ; cross-border transfers subject to authorisation.
  • Penalties: fines from 20,000 to 1,000,000 DA and imprisonment from two months to five years.

Breaches, penalties and alignment with other frameworks

The law requires the data controller to document data breaches, keep a register of them and take corrective measures to limit their effects. Non-compliance has a price : infringements of the personal data protection regime expose the controller to fines from 20,000 to 1,000,000 dinars and to imprisonment from two months to five years, with legal persons also liable to criminal penalties under the rules of the penal code. In the event of a breach, the ANPDP can refer the matter to the competent judicial authorities.

Law 18-07 does not stand alone. It aligns with the National Reference Framework for Information Systems Security (RNSI-2020), a baseline of measures that public bodies must implement, and with the ISO 27001 standard, which structures an information security management system. The two reinforce each other : the first sets the legal obligation, the second equips its implementation. The framework has since widened with Law 25-11, which introduces the notion of data sovereignty. For an Algerian organisation the point is unchanged : treat compliance as a continuous effort — governance, security, training — and not as a file closed once and for all.

A Law 18-07 compliance programme to run?

We help Algerian organisations comply with Law 18-07, from diagnosis through to assembling ANPDP filings. Tell us where you are and an expert will get back to you.