Law 25-11, now in force, amends and strengthens Law 18-07 of 2018 on the protection of natural persons in the processing of personal data. For Algerian organisations, this is not a routine update: the text creates new documentation obligations, defines concepts that had stayed vague, and gives the National Authority for the Protection of Personal Data (ANPDP) broader powers of control and audit. This guide separates what the law actually requires from what you need to put in place to meet it.
Why Law 25-11, and what it fixes
Algeria adopted its first dedicated personal data protection framework in 2018. Law 18-07 set the founding principles, but it was written for a digital landscape that the digitalisation of business — accelerated by the pandemic — has since transformed. By multiplying the points of contact with personal data, that shift exposed risks the 2018 text did not cover precisely enough.
Law 25-11 closes those blind spots. Several gaps are addressed head-on: the absence of a strict framework for biometric data, even as facial and fingerprint recognition become commonplace; the absence of a definition of profiling, which left personalised marketing and artificial intelligence largely outside the regulatory scope; the vagueness around documentation obligations for processing; and the imprecision over which authorities may process data in a judicial context. The overall message is clear: Algeria is moving from a framework of principles to a framework of control, backed by an authority now equipped to inspect and audit.
New definitions and the data protection officer's role
Law 25-11 first enriches the legal vocabulary, and these definitions are not cosmetic: they determine what falls under the law. It precisely frames biometric data — data that, resulting from specific technical processing, allows or confirms the unique identification of a person from their physical, physiological or behavioural characteristics. It defines profiling as the use of personal data to evaluate or predict aspects such as work performance, economic situation, health or a person's preferences. And it establishes pseudonymisation, the processing that makes data no longer attributable to a person without resorting to additional information kept separately.
The second innovation is organisational. The law requires data controllers and competent authorities — the public authorities responsible for the prevention and detection of offences, investigations, enquiries and prosecutions — to appoint a data protection officer. This obligation does not automatically apply to every private company: it concerns primarily the public sector and specific processing contexts, with courts exempt when exercising their judicial functions. The officer informs and advises on legal obligations, monitors compliance with the law and internal procedures, guides processing impact assessments, and acts as liaison with the national authority. To carry that oversight across the country, the law also equips the ANPDP with regional divisions responsible for audit and inspection.
Processing register and automated log: the new documentation duty
This is arguably the most concrete change for IT departments. Law 25-11 creates two distinct documentation obligations. The register of processing activities describes, processing by processing, who handles what and why: the contact details of the controller and their officer, the purposes and legal basis of operations, the categories of persons and data concerned, the recipients of the data, the planned deletion deadlines, and the security measures in place.
The automated log of operations goes further. It must trace every operation carried out on the data — from collection to destruction, including consultation, modification, communication, interconnection or encryption — recording the reason, the date, the time and the identity of the person who accessed it. In practice it is a permanent audit trail of personal data. It assumes logging capabilities that few existing architectures offer without a rebuild, and it shifts the burden of proof: it is no longer enough to assert that you protect data, you have to be able to show it, line by line.
Breaches, international transfers and the judicial framework
The law tightly governs breach management. The data controller must inform the National Authority within five days of becoming aware of a breach, describing its nature, its possible consequences, and the measures taken or proposed to mitigate its effects. Where the breach presents a high risk to the rights of the persons concerned, they too must be informed, "in simple and clear terms". This short deadline forces something many organisations do not yet have: a detection and notification procedure ready to trigger.
International transfers are subject to a prior assessment: the adequate level of protection in the destination country, respect for human rights and fundamental freedoms, the existence of a supervisory authority in that country, and the applicable security measures. Finally, an entire title — Title V bis — is devoted to processing for the prevention and detection of offences, clearly designating the authorised bodies: the judicial authority, the services legally empowered to investigate offences, judicial officers, and the prison administration.
What to take away
- Law 25-11 strengthens Law 18-07 and arms the ANPDP with powers of control and audit, relayed by regional divisions.
- It finally defines biometric data, profiling and pseudonymisation, and imposes a data protection officer on competent authorities.
- Two documentation obligations structure compliance: the processing register and the automated log of operations.
- Breaches must be notified within five days; transfers out of the country are subject to prior assessment.
Getting compliant: a risk-based roadmap
Compliance cannot be declared in one stroke. It starts with an audit of the existing estate — a precise mapping of current processing that reveals the gaps against the new requirements — then prioritises by risk: not all processing carries the same weight, and effort must go first to the most sensitive data and the breaches with the heaviest consequences. Next come appointing or training a qualified officer, keeping the registers, implementing the automated log, and formalising notification procedures.
Technically, the main obstacle is the log: it requires integrating advanced logging capabilities, often through a SIEM able to automate breach detection and access traceability. The registers, for their part, hold sensitive information that must be protected without being made inaccessible to oversight — a classic data protection challenge. Beyond tooling, it is the whole workforce, not only the officer, that must be made aware; this effort feeds directly into the organisation's governance, risk and compliance posture.
Taken this way, in phases and by risk, the constraint becomes an investment. By documenting its processing and demonstrating its control, an Algerian organisation does more than shield itself from penalties: it strengthens the trust of its customers and partners, and gains concrete ground in a digital economy where data protection has become a criterion of choice.
