Algeria
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Algeria — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Data can leave Algeria, but not freely. Every transfer abroad needs permission from the national data protection authority, unless a listed exception applies. Breaking that rule is a crime that carries prison. Since July 2025 every organisation must have a data protection officer. You must also keep a written register of what you do with data, and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
Data governance in Algeria
The eight things that decide how you handle data about people in Algeria. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes, it can reach a company with no office in Algeria. But the trigger is equipment, not customers. You are covered if you are set up in Algeria. You are also covered if you use any equipment in Algeria to handle data, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria. That person takes on your rights and duties. There is no size or revenue threshold to fall below.
- What you have to do here:
- Appoint a representative
Law 18-07 borrows the older European test of 'means located on the territory'. It does not use the newer test of targeting people in the country. Data that only passes through Algeria is expressly left out. So a foreign business that serves Algerian customers entirely from abroad, with no local equipment, is not clearly caught by the wording. That is a real difference from Europe, India or Brazil. The law also treats a company based in a country whose law counts as equivalent to Algerian law as if it were based in Algeria. But no list of equivalent countries has been published in the official gazette. Separately, Algerian courts can try offences under this law committed outside Algeria. That covers an Algerian, a foreigner living in Algeria, or an Algerian company.
Sources
- Official sourceJournal officiel de la Republique algerienne n° 34Loi n° 18-07 du 10 juin 2018 relative a la protection des personnes physiques dans le traitement des donnees a caractere personnel, articles 4 and 53
joradp.dz
“lorsque le responsable n'est pas etabli sur le territoire algerien mais recourt, a des fins de traitement des donnees a caractere personnel, a des moyens automatises ou non, situes sur le territoire algerien, a l'exclusion des traitements qui ne sont utilises qu'a des fins de transit sur le territoire national.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 48Loi n° 25-11 du 24 juillet 2025 modifiant et completant la loi n° 18-07
joradp.dz
Link checked 18 August 2026
Where the data is allowed to live
Yes, with permission or a listed excuse. The starting rule is simple. You may only send personal data to another country if the national data protection authority allows it. The destination country must also protect privacy well enough. There is a short list of exceptions that most businesses rely on instead. Those include the person's express consent, or a transfer needed to carry out their contract. Two things are banned outright. You cannot make a transfer that could harm public safety or the state's vital interests. And you cannot use or store sensitive data at all, unless a narrow exception applies. Sensitive data means things like health, religion, politics or trade union membership.
Industry by industry, checked on 18 August 2026. E-COMMERCE: closed. An online seller must publish a site or page hosted in Algeria with a .com.dz address. It must also deposit the domain name with the national trade register centre (Law 18-05). ELECTRONIC TRUST SERVICES (digital signatures, seals, timestamps, electronic identity): closed, with an exit. All data collected by a trust service provider must be hosted on national territory. It may then also be sent abroad in the course of the business (Law 26-02 of 17 February 2026). Providers must also be Algerian companies or Algerian nationals. GOVERNMENT: closed channel. Since 30 December 2025 the national interoperability system is the only route for digital data exchange between public bodies. It runs on a secured national interconnection network kept separate from the internet (Presidential Decree 25-320). TELECOMS: all international traffic other than satellite must be carried entirely over the historic operator's international infrastructure (Law 18-04). Identification and traffic data must be kept for one year (Law 09-04). HEALTH: we found no storage rule. But every public and private health facility must keep a single computerised patient record, and must join the national health information system (Law 18-11). BANKING, PAYMENTS, INSURANCE, SECURITIES: we found no storage or location rule, checked 18 August 2026. We looked at the monetary and banking law of 2023 and the April 2025 rules on payment service providers. We could not reach the central bank's own website, so instructions published only there could not be checked. GAMBLING: not a licensed activity in Algeria, so we did not look. MAPPING: the national cartographic institute has held a monopoly on mapping work since 1967, under defence ministry supervision. We found no modern rule on mapping data, so this is flagged as unconfirmed.
Sources
- Official sourceJournal officiel de la Republique algerienne n° 34Loi n° 18-07, articles 44 and 45 (transfert de donnees vers un pays etranger)
joradp.dz
“Le responsable d'un traitement ne peut transferer, les donnees a caractere personnel vers un Etat etranger, que sur autorisation de l'autorite nationale ... Il est interdit, dans tous les cas, de communiquer ou de transferer des donnees a caractere personnel vers un pays etranger, lorsque ce transfert est susceptible de porter atteinte a la securite publique ou aux interets vitaux de l'Etat.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 14Loi n° 26-02 du 17 fevrier 2026 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique, article 27
joradp.dz
“Toutes les donnees recueillies par les fournisseurs de services de confiance doivent etre hebergees sur le territoire national et peuvent etre transferees en dehors de celui-ci, dans le cadre de leur activite, sans prejudice des dispositions legislatives et reglementaires en vigueur.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 28Loi n° 18-05 du 10 mai 2018 relative au commerce electronique, article 8
joradp.dz
“L'activite de commerce electronique est soumise a inscription, selon le cas, au registre du commerce ou au registre de l'artisanat et des metiers, et a la publication d'un site ou d'une page web heberge en Algerie avec une extension " .com.dz ".”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 87Decret presidentiel n° 25-320 du 30 decembre 2025 portant mise en place d'un dispositif national de gouvernance des donnees, articles 10 to 12
joradp.dz
“Le systeme national d'interoperabilite est le cadre exclusif pour l'echange de donnees numeriques entre les institutions et les administrations publiques, a travers l'infrastructure du reseau d'interconnexion national securise, dedie a cet effet.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 27Loi n° 18-04 du 10 mai 2018 fixant les regles generales relatives a la poste et aux communications electroniques, article 126
joradp.dz
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 28Reglement de la Banque d'Algerie n° 25-02 du 14 avril 2025 fixant les conditions d'autorisation, d'agrement et d'exercice des prestataires de services de paiement
joradp.dz
Link checked 18 August 2026
What to do: Plan for a database inside Algeria: this data is not allowed to leave.
Sending data out of the country
It is decided case by case. Before data goes abroad you need the national data protection authority to authorise it. The destination country must also protect privacy well enough, in the authority's judgement. There is no published list of approved countries. There is no official standard contract you can sign instead. So most companies rely on the written exceptions. Those are the person's express consent, a transfer needed for their contract, a court claim, or saving someone's life. The rest are an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.
- Ways to send data out:
- Government sign-off needed · Official 'this country is safe' decision · Explicit consent · Needed for a contract · Legal claims · To save someone’s life · Important public interest
Law 18-07 sets the authorisation rule and the test of a sufficient level of protection. The authority judges that on the law of the destination country and the security measures in place there. It also looks at the purpose, duration, nature, origin and destination of the data. The law then lists the exceptions that allow a transfer even to a country that fails that test. One bar is absolute. No transfer at all where it could harm public security or the vital interests of the state. Nothing in the official gazette says how to apply, what the form looks like, or how long a decision takes. We could not reach the authority's own website on 18 August 2026. So the practical route to an authorisation is unverified. A separate and narrower set of transfer rules for police and justice bodies was added in July 2025. It requires the relevant authority to assess the destination itself. It can ask the national authority for an opinion first.
Sources
- Official sourceJournal officiel de la Republique algerienne n° 34Loi n° 18-07, articles 44 and 45
joradp.dz
“Par derogation aux dispositions de l'article 44 de la presente loi, le responsable d'un traitement, peut transferer des donnees a caractere personnel vers un Etat ne repondant pas aux conditions prevues par ledit article : 1° si la personne concernee a consenti expressement a leur transfert”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 48Loi n° 25-11, new article 45 bis 13 (transfers by police and justice bodies)
joradp.dz
Link checked 18 August 2026
- Official sourceLink may be brokenANPDPAutorite nationale de protection des donnees a caractere personnel - official website
anpdp.dz
Link checked 18 August 2026
What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.
The regulator, and whether it actually acts
The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years. A new president was appointed in October 2023. The authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement. In four years the official gazette shows only housekeeping texts from the authority. No fine, no order, no filing procedure. Treat it as awake, but not yet acting against companies.
Here is the evidence trail from the official gazette. Presidential Decree 22-187 of 18 May 2022 appointed the president and members for five years. Presidential Decree 23-73 of 14 February 2023 organised the executive secretariat. Presidential Decree 23-147 of 5 April 2023 created the staff corps. An interministerial order of 17 September 2024 created the authority's own official bulletin. A decision of 31 August 2025 set up an internal technical committee, signed by the president, Samir Bourehil. The July 2025 amendment gave the authority regional units for inspection and audit. How those units will work still has to be set by regulation. Two warnings. First, the authority publishes its own bulletin, which we could not open. Decisions may exist outside the gazette. Second, crimes under the law are prosecuted by the ordinary courts, on a report from judicial police officers. So a case can proceed without the authority acting at all. Industry regulators are separate and working. The telecoms and post regulator issues decisions regularly. The telecoms ministry launched an industry cyber incident response centre in June 2026.
Sources
- Official sourceJournal officiel de la Republique algerienne n° 35Decret presidentiel n° 22-187 du 18 mai 2022 portant nomination du president et des membres de l'autorite nationale de protection des donnees a caractere personnel
joradp.dz
“Sont nommes membres de l'autorite nationale de protection des donnees a caractere personnel, pour une duree de cinq (5) annees”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 63Decision du 31 aout 2025 portant constitution d'un comite technique aupres de l'autorite nationale de protection des donnees a caractere personnel, signed by the authority's president
joradp.dz
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 67Arrete interministeriel du 17 septembre 2024 portant creation d'un bulletin officiel de l'autorite nationale de protection des donnees a caractere personnel
joradp.dz
Link checked 18 August 2026
- Official sourceMinistere de la poste et des telecommunicationsMinistere de la poste et des telecommunications - launch of the sector cyber incident detection and response centre, June 2026
mpt.gov.dz
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a minimum and a maximum, and people miss the minimum. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The maximum is this. Do not keep personal data in a form that identifies people for longer than the purpose needs. Keeping it too long is a crime.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period
The ten-year accounting rule comes from the financial accounting law of 2007. It covers both full and simplified bookkeeping. The one-year telecom rule comes from the 2009 cybercrime law. It covers user identification data, terminal equipment data, and the time and duration of each communication. It also covers the services used, the recipients, and the addresses of sites visited. Conflicts are settled in favour of the specific keeping rule. The data law makes it an offence to keep personal data beyond the period fixed by the law in force. It is also an offence to keep it beyond the period stated in your own filing. So the filing you make becomes your own binding deadline. The law also lets the authority approve longer keeping for historical, statistical or scientific purposes. You have to ask, and show a legitimate interest.
Sources
- Official sourceJournal officiel de la Republique algerienne n° 74Loi n° 07-11 du 25 novembre 2007 portant systeme comptable financier, articles 20 and 22
joradp.dz
“Les livres comptables ou les supports qui en tiennent lieu ainsi que les pieces justificatives sont conserves pendant dix (10) ans a compter de la date de cloture de chaque exercice comptable.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 47Loi n° 09-04 du 5 aout 2009, article 11 (conservation des donnees relatives au trafic)
joradp.dz
“La duree de conservation des donnees citees au present article est fixee a une (1) annee a compter du jour de l'enregistrement.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 34Loi n° 18-07, articles 9 and 65
joradp.dz
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 28Loi n° 18-05, article 25 (registres des transactions commerciales)
joradp.dz
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
There is no seventy-two hour clock here. The five-day deadline people quote is not for ordinary businesses. Do you provide a service over a public electronic communications network? Then if data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away. There is no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services. It does not apply to a normal company.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Law 18-07 sets the rule for providers on public electronic communications networks. It uses the words 'sans delai', without delay. You do not have to tell the individual if the authority finds you had appropriate protection measures in place. Failing to notify either the authority or the person is a crime. The July 2025 amendment created a separate part of the law for data used to prevent, investigate and prosecute crime, and to enforce sentences. Inside that part, there is a five-day deadline to inform the authority. There is also a duty to tell the individual where the risk is high. That can be delayed where an investigation would be harmed. We found no general duty for ordinary businesses to report a cyber incident to a national agency. The national information systems security rules of January 2020 were amended in November 2025. They set up a council and an agency under the Ministry of National Defence. They do not set a reporting deadline. The telecoms ministry's industry incident response centre opened in June 2026 as a channel, not a legal duty. Checked 18 August 2026.
Sources
- Official sourceJournal officiel de la Republique algerienne n° 34Loi n° 18-07, articles 43 and 66
joradp.dz
“le fournisseur de services avertit, sans delai, l'autorite nationale et la personne concernee lorsque cette violation peut porter atteinte a sa vie privee.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 48Loi n° 25-11, new articles 45 bis 8 to 45 bis 10 (five-day notification, criminal justice processing only)
joradp.dz
“En cas de violation de donnees a caractere personnel, le responsable du traitement doit en informer l'autorite nationale, au plus tard, cinq (5) jours apres en avoir pris connaissance.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 4Decret presidentiel n° 20-05 du 20 janvier 2020 portant mise en place d'un dispositif national de la securite des systemes d'information
joradp.dz
Link checked 18 August 2026
- Official sourceMinistere de la poste et des telecommunicationsMinistere de la poste et des telecommunications - sector cyber incident detection and response centre, June 2026
mpt.gov.dz
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things cost people their weekend. One: breaking these rules is a crime. Sending data abroad against the rule brings one to five years in prison. There is also a fine of up to one million dinars. That is roughly seven thousand seven hundred US dollars. Individuals can go to prison, not just companies. Two: since 24 July 2025 every organisation must appoint a data protection officer. You must keep a written register of what you do with data. You must also keep an automatic log of every collection, consultation, disclosure and deletion. There is no exemption for small companies. Three: sensitive data is banned by default, and consent must be express. Silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law. So there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified government documents. It reaches acts committed outside Algeria against the Algerian state. It can also force any person to hand over stored data.
- What you have to do here:
- Appoint a data protection officer · Keep records of how you use data · Keep logs · Get a parent's consent for children
- What it costs if you get it wrong:
- Criminal liability · Order to stop
On the criminal exposure. The largest fine the authority itself can impose is 500,000 dinars, about 3,800 US dollars. So the deterrent is not the money. It is the prison sentence, and the power to withdraw your filing receipt or authorisation. That stops you using the data at all. The authority can withdraw a filing without delay where your use of data turns out to harm national security or offend public morals. There is no equivalent ground in European law. On children. Using a child's data needs the consent of the legal representative, or the authorisation of a judge. A judge can also allow it without the parent's consent where the child's best interests require it, and can withdraw that at any time. The data law does not itself say the age at which someone stops being a child. On sensitive data. The categories are racial or ethnic origin, political opinions, religious or philosophical belief, trade union membership, and health, including genetic data. On trust services and online selling. The provider must be an Algerian company or an Algerian national. An online shop must run on Algerian hosting under a .com.dz address. That rules out a plain foreign cloud front end.
Sources
- Official sourceJournal officiel de la Republique algerienne n° 34Loi n° 18-07, articles 7, 8, 18, 46, 47, 48 and 67
joradp.dz
“Est puni d'un emprisonnement d'un (1) an a cinq (5) ans et d'une amende de 500.000 DA a 1.000.000 DA, quiconque effectue un transfert de donnees a caractere personnel vers un Etat etranger, en violation des dispositions de l'article 44 de la presente loi.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 48Loi n° 25-11, new articles 41 bis, 41 bis 2 and 41 bis 3, and amended article 6
joradp.dz
“Le responsable du traitement ainsi que le sous-traitant tiennent chacun un carnet automatise des operations de traitement des donnees a caractere personnel”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 45Ordonnance n° 21-09 du 8 juin 2021 relative a la protection des informations et des documents administratifs, articles 21 to 24 and 28 to 31
joradp.dz
Link checked 18 August 2026
What's changing next
Three things to watch in the next twelve months. First, the five-year terms of the data protection authority's members run out in May 2027. They were appointed on 18 May 2022, so new appointments are due. Second, the regional inspection and audit units created for the authority in July 2025 still need a regulation. Until it appears, inspectors cannot turn up at your door. Third, the new government data rules need two reference documents to switch on. Those cover classifying data and cataloguing data sources. The High Commission for Digitalisation can publish them with a single decision. From that day, every public body and every company running a public service must classify and catalogue its data.
- What you have to do here:
- Keep the data in the country
Switches that could flip, in order of how fast they could change things. First, the two reference documents under the December 2025 decree. Public bodies must begin classifying and cataloguing from the date those documents are published. The High Commissioner for Digitalisation publishes them by decision, with no consultation step. Second, the data protection authority can decide on its own that a filing you made should instead need prior authorisation. It has ten days from your filing to say so. Third, the data law lets the authority publish a list of low-risk uses of data that qualify for a simplified filing. No such list has appeared. So today everything follows the full route. Fourth, the trust services law of February 2026 needs its detailed rules and a new national electronic certification authority. Until that authority is actually set up, the existing certification bodies carry on, and the old 2015 rules stay in force. Fifth, the national information systems security strategy for 2025 to 2029 was approved on 30 December 2025, and it may produce further duties.
Sources
- Official sourceJournal officiel de la Republique algerienne n° 87Decret presidentiel n° 25-320, articles 8 and 19; Decret presidentiel n° 25-321 approving the national information systems security strategy 2025-2029
joradp.dz
“Les instituions et les administrations publiques s'engagent a proceder a la classification de leurs donnees ainsi qu'au catalogage des sources de leurs donnees, conformement aux dispositions du present decret, a compter de la date de publication des deux referentiels cites a l'article 8 ci-dessus.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 48Loi n° 25-11, new article 27 bis (regional control and audit units, conditions to be set by regulation)
joradp.dz
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 14Loi n° 26-02, articles 112 to 115 (transition to the new certification authority)
joradp.dz
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 35Decret presidentiel n° 22-187 (five-year terms from 18 May 2022)
joradp.dz
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Telecoms data needs a copy kept in the country
Official name: Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique · Loi n° 26-02 du 17 fevrier 2026 (JO n° 14 du 18 fevrier 2026) · Act of parliament
Do you offer digital signatures, electronic seals, timestamps or electronic identity in Algeria? Then you must host every piece of data you collect on servers inside the country. You must also be an Algerian company or an Algerian national. Data can still be copied abroad for the business itself. Foreign providers count only where a mutual recognition agreement exists.
Enforced by Ministry of Post and Telecommunications
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the country — from 18 February 2026All data collected by a trust service provider must be hosted on national territory. Transfers out are allowed in the course of the business, subject to the general data law.
- Register or notifyProviders need an eligibility certificate, then an authorisation, and cannot even register at the trade register before holding the eligibility certificate.
- Independent auditAuthorisation depends on a successful evaluation audit by the authority or the national information systems security body, plus periodic audits.
- Hold a security certificate
What it costs if you get it wrong
- Criminal liability: 1 to 3 years imprisonment and 1,000,000 to 5,000,000 DZD — about $38 thousandProviding trust services to the public without authorisation, or continuing after it is withdrawn
Sources
- Official sourceJournal officiel de la Republique algerienne n° 14Loi n° 26-02 du 17 fevrier 2026, articles 25, 27, 34 and 112 to 115
joradp.dz
“Toutes les donnees recueillies par les fournisseurs de services de confiance doivent etre hebergees sur le territoire national”
Link checked 18 August 2026
E-commerce data needs a copy kept in the country
Official name: Loi n° 18-05 relative au commerce electronique · Loi n° 18-05 du 10 mai 2018 (JO n° 28 du 16 mai 2018) · Act of parliament
Do you sell online to people in Algeria? You must run the storefront on hosting located in Algeria, under a .com.dz address. You must register the domain with the national trade register centre. And you must keep records of every transaction for it. Customer data can still travel abroad, but only under the general privacy law.
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryThe selling site or page must be hosted in Algeria under a .com.dz address.
- Register or notifyYou must enter the commercial register or the craft register. You must deposit the domain name with the national trade register centre. That centre publishes a national list of online sellers.
- Keep records of how you use dataRegisters of every transaction and its date must be kept and transmitted electronically to the national trade register centre.
- Get consentAn online seller may collect only the data needed for the transaction and must respect the general data law.
What it costs if you get it wrong
- Order to stopPrecautionary suspension of the seller's domain name, for up to thirty days
Sources
- Official sourceJournal officiel de la Republique algerienne n° 28Loi n° 18-05 du 10 mai 2018, articles 8, 9, 25 and 26
joradp.dz
“la publication d'un site ou d'une page web heberge en Algerie avec une extension " .com.dz "”
Link checked 18 August 2026
Internet and platform rules
Official name: Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees · Decret presidentiel n° 25-320 du 30 decembre 2025 (JO n° 87 du 30 decembre 2025) · Directly binding regulation
Since the end of December 2025, public bodies may exchange digital data only through a state interoperability platform. That platform runs on a network deliberately separated from the internet. The rule also covers private companies entrusted with a public service, once they are brought into the system. The duties to classify and catalogue data do not start until two reference documents are published. That can happen by a single decision, with no consultation.
Enforced by National Authority for the Protection of Personal Data
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryPublic bodies may exchange digital data only over the national interoperability system. It runs on a secured national interconnection network, kept separate from the internet.
- Keep records of how you use dataEach body must classify the data in its information system and catalogue its data sources. This starts on the day the two reference documents are published by decision of the High Commissioner for Digitalisation.
- Secure the data
Sources
- Official sourceJournal officiel de la Republique algerienne n° 87Decret presidentiel n° 25-320 du 30 decembre 2025, articles 4 to 19
joradp.dz
“Le haut commissariat a la numerisation met en place l'infrastructure du reseau d'interconnexion national securise ... et ce, de maniere separee du reseau internet.”
Link checked 18 August 2026
Health data rules
Official name: Loi n° 18-11 relative a la sante · Loi n° 18-11 du 2 juillet 2018 (JO n° 46 du 29 juillet 2018) · Act of parliament
Every hospital and clinic, public or private, must keep a single computerised record for each patient. Each must also plug into the national health information system. We found no rule saying health data must stay in Algeria. But health data is sensitive data. So you need express consent or a narrow exception to use it, and the regulator's permission to send it abroad.
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, To save someone’s life
What you have to do
- Keep records of how you use dataEvery public and private health facility must create a single computerised medical record for each patient, and keep it up to date. It must also manage and preserve medical archives.
- Secure the dataConfidentiality, availability and integrity of the national health information system are the responsibility of its managers and of the people who use the data.
- Keep data for a minimum periodRecords opened before the single medical record was introduced must be preserved. The classification, archiving, retention period and destruction rules are still to be set by regulation.
Sources
- Official sourceJournal officiel de la Republique algerienne n° 46Loi n° 18-11 du 2 juillet 2018, articles 292, 320 to 323 and 444 to 445
joradp.dz
“Les structures et les etablissements de sante, publics et prives, sont dans l'obligation d'integrer le systeme national d'information sanitaire.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 34Loi n° 18-07, articles 3 and 18 (health data is sensitive data; processing sensitive data is prohibited by default)
joradp.dz
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
State and security data rules
Official name: Loi n° 18-07 relative a la protection des personnes physiques dans le traitement des donnees a caractere personnel, modifiee et completee par la loi n° 25-11 · Loi n° 18-07 du 10 juin 2018 (JO n° 34), amended by Loi n° 25-11 du 24 juillet 2025 (JO n° 48) · Act of parliament
Algeria's general privacy law. Everything you do with personal data must be filed with the national authority first. Sending data abroad needs the authority's permission, unless a listed exception applies. The penalties are criminal, not just fines from a regulator. The July 2025 amendment added three things for every organisation. A compulsory data protection officer. A written register of what you do with data. And an automatic log of operations. It also removed national defence and security data from the law's reach entirely.
Enforced by National Authority for the Protection of Personal Data
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed, Official 'this country is safe' decision, Explicit consent, Needed for a contract, Legal claims, To save someone’s life, Important public interest
What you have to do
- Register or notifyEverything you do with personal data must be filed with the authority before it starts, or authorised by it. You get a receipt within 48 hours and may start on receipt.
- Get consentExpress consent is the default legal reason. Exceptions include a legal duty, saving a life, a public interest task, performing a contract, and a legitimate interest.
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people object
- Limit automated decisionsNo decision with legal effects may rest solely on automated profiling.
- Secure the data
- Written vendor contractYou need a written contract with any company that handles data for you. The data protection terms must be in writing as evidence.
- Appoint a representative — from 10 June 2018Required if you are not based in Algeria but use equipment located there.
- Appoint a data protection officer — from 24 July 2025Added by the 2025 amendment. There is no size threshold. One officer may serve several companies, depending on their structure and size.
- Keep records of how you use data — from 24 July 2025
- Keep logs — from 24 July 2025An automatic 'carnet' logging every collection, consultation, disclosure, encryption, erasure and destruction. It records the time and, where possible, who did it and who received the data.
- Report breaches to the regulatorWithout delay, for providers of services on public electronic communications networks. No fixed hours.
- Tell affected people
- Put a transfer safeguard in place
- Delete data after a periodNo longer than the purpose requires. Longer keeping for historical, statistical or scientific purposes needs the authority's permission.
- Get a parent's consent for childrenConsent of the legal representative, or authorisation of the competent judge, who may also override the representative in the child's best interests.
- Assess high-risk projects — from 24 July 2025Written into the new criminal justice part of the law. The data protection officer advises on impact assessments generally.
What it costs if you get it wrong
- Criminal liability: 1 to 5 years imprisonment and 500,000 to 1,000,000 DZD — about $8 thousandTransferring personal data abroad in breach of the transfer rule
- Criminal liability: 2 to 5 years imprisonment and 200,000 to 500,000 DZD — about $4 thousandProcessing without the required filing or authorisation, false filing, or continuing after withdrawal
- Criminal liability: 2 to 5 years imprisonment and 200,000 to 500,000 DZD — about $4 thousandProcessing sensitive data without express consent, or letting unauthorised people reach personal data
- Criminal liability: 1 to 3 years imprisonment and 100,000 to 300,000 DZD — about $2 thousandFailure to notify a personal data breach to the authority or the individual
- Fixed maximum fine: 500,000 DZD — about $4 thousandAdministrative fine by the authority, for refusing individuals' rights or failing to make required notifications
- Order to stopTemporary withdrawal of the filing receipt or authorisation for up to one year, or permanent withdrawal, including where the processing harms national security or public morals
Sources
- Official sourceJournal officiel de la Republique algerienne n° 34Loi n° 18-07 du 10 juin 2018 - full text
joradp.dz
“Nonobstant toute disposition legislative contraire, toute operation de traitement des donnees a caractere personnel, est soumise a une declaration prealable a l'autorite nationale ou a son autorisation conformement aux dispositions prevues par la presente loi.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 48Loi n° 25-11 du 24 juillet 2025 - full text of the amendment
joradp.dz
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 35Decret presidentiel n° 22-187 - appointment of the authority, which starts the one-year compliance clock in article 75
joradp.dz
Link checked 18 August 2026
Telecoms rules
Official name: Loi n° 09-04 portant regles particulieres relatives a la prevention et a la lutte contre les infractions liees aux technologies de l'information et de la communication · Loi n° 09-04 du 5 aout 2009 (JO n° 47 du 16 aout 2009) · Act of parliament
Do you offer a service that lets users communicate over a computer or telecoms system? Or do you store data for such a service? Then you must keep connection and identification records for one year, and hand them to investigators on demand. Internet access providers must also take down illegal content without delay. The law does not say where the records must be stored.
Enforced by Post and Electronic Communications Regulatory Authority
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep logs — 1 yearUser identification data, terminal equipment data, time and duration of each communication, services used, recipients and addresses of sites visited. Telephone operators must also keep data identifying and locating the origin of a call.
- Keep data for a minimum period — 1 year
What it costs if you get it wrong
- Criminal liability: 6 months to 5 years imprisonment and 50,000 to 500,000 DZD — about $4 thousandFailure to keep the data where this obstructs a judicial investigation. Companies are fined under the criminal code.
Sources
- Official sourceJournal officiel de la Republique algerienne n° 47Loi n° 09-04 du 5 aout 2009, articles 10 to 12
joradp.dz
“La duree de conservation des donnees citees au present article est fixee a une (1) annee a compter du jour de l'enregistrement.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 27Loi n° 18-04 du 10 mai 2018, article 126 (international traffic routed through the historic operator)
joradp.dz
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The exact date the national data protection authority was 'installed', which is what starts the one-year compliance deadline in article 75 of the 2018 law
The gazette records the appointment of the president and members on 18 May 2022. No text records a formal installation date. We have used 18 May 2023 as the date the law started to apply. If installation happened later, the deadline moved with it. Check the gazette if the exact date matters to you.
Whether the authority has issued any filing forms, guidance, official “this country is safe” decision or sanctions outside the official gazette
The authority created its own official bulletin in September 2024. We could not reach its website on 18 August 2026. Anything published only there is invisible to us. Contact the authority directly if you need forms or guidance.
Whether any list of countries with an adequate or equivalent level of protection exists
We found nothing in the official gazette. The law refers to countries 'whose legislation is recognised as equivalent'. We found no text naming one. Assume no such list exists until the gazette shows otherwise.
Whether banking, payments, insurance or securities rules impose data storage inside Algeria
The 2023 monetary and banking law and the April 2025 payment service provider rules contain no such rule. But we could not reach the Bank of Algeria's website, or the insurance and securities regulators' sites. Anything issued outside the gazette is unchecked. If you work in finance, ask your supervisor directly.
The age at which a person stops being a child for consent purposes
The data protection law requires the legal representative's consent for a child, but does not define the age. Algeria's child protection law treats anyone under 18 as a child. We could not check that against the law's own text. Confirm the age before you build an age gate.
Whether any modern rule restricts mapping, survey or high-resolution location data
The only texts we found run from 1967 to 1994. They concern the national cartographic institute's monopoly under defence ministry supervision. We could not find a current rule, and no defence ministry source was reachable. If you handle Algerian mapping or location data, check before you rely on this.
Dinar to US dollar conversions used in the penalty figures
We converted at roughly 130 Algerian dinars to the dollar, which is an approximation. We could not check the official rate, because the central bank website was unreachable.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.