Loading...
Loading...
Copyright © 2026 Anove International B.V.
All product names, logos, and brands are property of their respective owners. Use of these names does not imply affiliation, endorsement, or partnership.
Law 18-07
Algeria's GDPR-inspired data protection law requires express consent, prior declaration or authorisation of processing and ANPDP authorisation of international transfers; the 2025 amendment (Law No. 25-11) added accountability, risk-based and governance obligations.
Law No. 18-07 of 10 June 2018 protects natural persons in the processing of personal data and applies to any public or private entity that receives, stores or processes personal data, whether digital or not. Its supervisory authority, the ANPDP, became operational in August 2023 and announced its first field inspections of private-sector companies on 28 February 2024. Processing generally requires the data subject's express consent, subject to listed exemptions (legal obligation, contract, vital interests, public interest, legitimate interest). International transfers require ANPDP authorisation and an adequate level of protection in the destination State; transfers likely to affect public security or the vital interests of the State are prohibited.
Law No. 25-11 of 24 July 2025 amended and supplemented the framework, aligning it further with the GDPR. The amendment modernised key definitions (biometric data, profiling, pseudonymisation, data breach), introduced mandatory records of processing activities for controllers and processors including automated logs of operations, required data protection impact assessments before high-risk processing, and equipped the ANPDP with regional branches dedicated to inspections and audits across the national territory. Data breaches on electronic communications networks must be notified to the ANPDP and the data subject within a maximum of five days. Non-compliance carries fines of DZD 20,000 to 1,000,000 and imprisonment of two months to five years, alongside ANPDP administrative measures up to definitive withdrawal of authorisation.
Controllers must file a prior declaration with the ANPDP before processing, and obtain prior authorisation for sensitive processing, communication of data to third parties, data interconnection and transfers abroad.
Personal data may only be processed with the data subject's express consent unless a statutory exemption applies (legal obligation, contract, vital interests, public interest, legitimate interest).
Since Law 25-11, controllers and processors must keep detailed records of processing activities available to the ANPDP, including automated operation logs, and conduct impact assessments before high-risk processing.
Transfers to a foreign State require ANPDP authorisation and an adequate level of protection; transfers affecting public security or vital State interests are prohibited.
Read more
Anove scans your stack against Law 18-07 and 260+ other frameworks in minutes.
Providers processing data over electronic communications networks must notify the ANPDP and the data subject within a maximum of five days of becoming aware of a breach.