Skip to the content
Global Data RulesData governance rules, country by country

Algeria

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.

The answer

Yes, with paperworkWork: HighEnforcement: Waking up

Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.

Data governance in Algeria

The eight things that decide how you handle data about people in Algeria. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.

High confidenceNational rulesAppoint a local representative

Where the data is allowed to live

Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.

High confidenceYes, with paperworkApproval each timeA copy must stayNo — it stays put

Sending data out of the country

The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.

High confidenceApproval each timeGovernment sign-off neededOfficial 'this country is safe' decisionExplicit consentNeeded for a contractLegal claimsSomeone's life is at riskImportant public interest

The regulator, and whether it actually acts

The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.

High confidenceWaking up

How long you must keep it — and when to delete it

There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logs

If something goes wrong

There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What catches people out

Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.

High confidenceCriminal liabilityAppoint a data protection officerKeep records of processingKeep logsGet a parent's consent for childrenOrder to stop

What's changing next

Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.

High confidenceIn forceKeep the data in the countryRegister or notify

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Telecoms

Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique

Act of parliament · Loi n° 26-02 du 17 fevrier 2026 (JO n° 14 du 18 fevrier 2026)

Partly in forceA copy must stay

Anyone offering digital signatures, electronic seals, timestamps or electronic identity in Algeria must host every piece of data they collect on servers inside the country, and must be an Algerian company or an Algerian national. Data may still be copied abroad for the business itself. Foreign providers count only where a mutual recognition agreement exists.

In force since 18 February 2026

Enforced by Ministry of Post and Telecommunications

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed

High confidence
E-commerce

Loi n° 18-05 relative au commerce electronique

Act of parliament · Loi n° 18-05 du 10 mai 2018 (JO n° 28 du 16 mai 2018)

In forceA copy must stay

If you sell online to people in Algeria you must run the storefront on hosting located in Algeria under a .com.dz address, register the domain with the national trade register centre and keep records of every transaction for it. Customer data may still travel abroad, but only under the general privacy law.

In force since 16 May 2018

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence
Government

Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees

Directly binding regulation · Decret presidentiel n° 25-320 du 30 decembre 2025 (JO n° 87 du 30 decembre 2025)

Partly in forceNo — it stays put

Since the end of December 2025 public bodies, and private companies entrusted with a public service that are brought into the system, may exchange digital data only through a state interoperability platform running on a network deliberately separated from the internet. The duties to classify and catalogue data do not start until two reference documents are published, which can happen by a single decision with no consultation.

In force since 30 December 2025

Enforced by National Authority for the Protection of Personal Data

Transfer model: Not allowed

High confidence

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Loi n° 18-07 relative a la protection des personnes physiques dans le traitement des donnees a caractere personnel, modifiee et completee par la loi n° 25-11

Act of parliament · Loi n° 18-07 du 10 juin 2018 (JO n° 34), amended by Loi n° 25-11 du 24 juillet 2025 (JO n° 48)

In forceYes, with paperwork

Algeria's general privacy law. Every processing operation must be filed with the national authority first, sending data abroad needs the authority's permission unless a listed exception applies, and the penalties are criminal rather than administrative. The July 2025 amendment added a compulsory data protection officer, a processing register and an automatic operations log for every organisation, and removed national defence and security data from the law's reach entirely.

In force since 10 June 2018But only enforceable from 18 May 2023

Enforced by National Authority for the Protection of Personal Data

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed, Official 'this country is safe' decision, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk, Important public interest

High confidence
Telecoms

Loi n° 09-04 portant regles particulieres relatives a la prevention et a la lutte contre les infractions liees aux technologies de l'information et de la communication

Act of parliament · Loi n° 09-04 du 5 aout 2009 (JO n° 47 du 16 aout 2009)

In forceYes, with paperwork

Anyone offering a service that lets users communicate over a computer or telecoms system, and anyone storing data for such a service, must keep connection and identification records for one year and hand them to investigators on demand. Internet access providers must also take down illegal content without delay. The law does not say where the records must be stored.

In force since 16 August 2009

Enforced by Post and Electronic Communications Regulatory Authority

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Who you would hear from

  • Autorite nationale de protection des donnees a caractere personnel

    General privacy law: filings, authorisations, transfers abroad, inspections, administrative sanctions

    Real and staffed. Fifteen members appointed on 18 May 2022 for five years, a new president appointed in October 2023, an executive secretariat, a staff corps, its own official bulletin since 2024 and a technical committee set up by a decision signed by its president in August 2025. But no fine, order, filing form or procedure has appeared in the official gazette in four years, and its website could not be reached from our checker on 18 August 2026. Enforcement is best described as awake but not yet biting.

  • Autorite de regulation de la poste et des communications electroniques

    Telecoms and postal licensing, operator obligations, equipment approval

    Clearly active: it ran the 5G licence tender in 2025, launched a satellite licence process in 2026 and publishes numbered decisions regularly.

  • Ministere de la poste et des telecommunications

    Policy on digital trust, electronic certification and sector cyber security

    Opened a sector cyber incident detection and response centre in June 2026.

  • Banque d'Algerie

    Banks, financial institutions, payment service providers

    Active: it issued regulations on payment service providers and customer protection in April 2025 and on the national payments committee in May 2026, all published in the official gazette. Its own website could not be opened from our checker on 18 August 2026 because of a certificate problem, so any instruction published only there is unchecked.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The exact date the national data protection authority was 'installed', which is what starts the one-year compliance deadline in article 75 of the 2018 law

    The gazette records the appointment of the president and members on 18 May 2022, but no text records a formal installation. We have used 18 May 2023 as the date the law began to bite. If installation happened later, the deadline moved with it.

  • Whether the authority has issued any filing forms, guidance, adequacy findings or sanctions outside the official gazette

    The authority created its own official bulletin in September 2024 and its website could not be reached from this environment on 18 August 2026. Anything published only there is invisible to us.

  • Whether any list of countries with an adequate or equivalent level of protection exists

    Nothing in the official gazette. The law refers to countries 'whose legislation is recognised as equivalent', but we found no instrument naming one.

  • Whether banking, payments, insurance or securities rules impose data storage inside Algeria

    The 2023 monetary and banking law and the April 2025 payment service provider regulation contain no such rule, but the Bank of Algeria website is unreachable from here and the insurance and securities regulators could not be opened either, so instructions issued outside the gazette are unchecked.

  • The age at which a person stops being a child for consent purposes

    The data protection law requires the legal representative's consent for a child but does not define the age. Algeria's child protection law treats anyone under 18 as a child, which we could not verify against its own text during this run.

  • Whether any modern rule restricts mapping, survey or high-resolution location data

    The only instruments found are from 1967 to 1994 and concern the national cartographic institute's monopoly under defence ministry supervision. We could not find a current instrument, and no defence ministry source was reachable.

  • Dinar to US dollar conversions used in the penalty figures

    Converted at roughly 130 Algerian dinars to the dollar, an approximation. The official rate could not be checked because the central bank website was unreachable.

60-day cadence. Three switches can flip without consultation: publication of the data classification and cataloguing reference frameworks by the High Commissioner for Digitalisation, which starts real duties for public bodies and public service companies; the implementing regulation for the data protection authority's regional inspection and audit units; and the implementing texts and new certification authority under the February 2026 trust services law. The authority's members were appointed for five years from 18 May 2022, so a reappointment round is due before May 2027.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Algeria versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.