Skip to the content
Global Data RulesData governance rules, country by country

Algeria

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Algeria — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: HighEnforcement: Waking up

Data can leave Algeria, but not freely. Every transfer abroad needs permission from the national data protection authority, unless a listed exception applies. Breaking that rule is a crime that carries prison. Since July 2025 every organisation must have a data protection officer. You must also keep a written register of what you do with data, and an automatic log of every operation. The regulator is staffed but has issued no known decisions.

Data governance in Algeria

The eight things that decide how you handle data about people in Algeria. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes, it can reach a company with no office in Algeria. But the trigger is equipment, not customers. You are covered if you are set up in Algeria. You are also covered if you use any equipment in Algeria to handle data, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria. That person takes on your rights and duties. There is no size or revenue threshold to fall below.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Yes, with permission or a listed excuse. The starting rule is simple. You may only send personal data to another country if the national data protection authority allows it. The destination country must also protect privacy well enough. There is a short list of exceptions that most businesses rely on instead. Those include the person's express consent, or a transfer needed to carry out their contract. Two things are banned outright. You cannot make a transfer that could harm public safety or the state's vital interests. And you cannot use or store sensitive data at all, unless a narrow exception applies. Sensitive data means things like health, religion, politics or trade union membership.

What to do: Plan for a database inside Algeria: this data is not allowed to leave.

Sending data out of the country

It is decided case by case. Before data goes abroad you need the national data protection authority to authorise it. The destination country must also protect privacy well enough, in the authority's judgement. There is no published list of approved countries. There is no official standard contract you can sign instead. So most companies rely on the written exceptions. Those are the person's express consent, a transfer needed for their contract, a court claim, or saving someone's life. The rest are an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.

Ways to send data out:
Government sign-off needed · Official 'this country is safe' decision · Explicit consent · Needed for a contract · Legal claims · To save someone’s life · Important public interest

What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.

The regulator, and whether it actually acts

The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years. A new president was appointed in October 2023. The authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement. In four years the official gazette shows only housekeeping texts from the authority. No fine, no order, no filing procedure. Treat it as awake, but not yet acting against companies.

How long you must keep it — and when to delete it

There is a minimum and a maximum, and people miss the minimum. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The maximum is this. Do not keep personal data in a form that identifies people for longer than the purpose needs. Keeping it too long is a crime.

What you have to do here:
Keep data for a minimum period · Delete data after a period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

There is no seventy-two hour clock here. The five-day deadline people quote is not for ordinary businesses. Do you provide a service over a public electronic communications network? Then if data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away. There is no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services. It does not apply to a normal company.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things cost people their weekend. One: breaking these rules is a crime. Sending data abroad against the rule brings one to five years in prison. There is also a fine of up to one million dinars. That is roughly seven thousand seven hundred US dollars. Individuals can go to prison, not just companies. Two: since 24 July 2025 every organisation must appoint a data protection officer. You must keep a written register of what you do with data. You must also keep an automatic log of every collection, consultation, disclosure and deletion. There is no exemption for small companies. Three: sensitive data is banned by default, and consent must be express. Silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law. So there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified government documents. It reaches acts committed outside Algeria against the Algerian state. It can also force any person to hand over stored data.

What you have to do here:
Appoint a data protection officer · Keep records of how you use data · Keep logs · Get a parent's consent for children
What it costs if you get it wrong:
Criminal liability · Order to stop

What's changing next

Three things to watch in the next twelve months. First, the five-year terms of the data protection authority's members run out in May 2027. They were appointed on 18 May 2022, so new appointments are due. Second, the regional inspection and audit units created for the authority in July 2025 still need a regulation. Until it appears, inspectors cannot turn up at your door. Third, the new government data rules need two reference documents to switch on. Those cover classifying data and cataloguing data sources. The High Commission for Digitalisation can publish them with a single decision. From that day, every public body and every company running a public service must classify and catalogue its data.

What you have to do here:
Keep the data in the country

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Telecoms

Telecoms data needs a copy kept in the country

Official name: Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique · Loi n° 26-02 du 17 fevrier 2026 (JO n° 14 du 18 fevrier 2026) · Act of parliament

Partly in forceA copy must stay

Do you offer digital signatures, electronic seals, timestamps or electronic identity in Algeria? Then you must host every piece of data you collect on servers inside the country. You must also be an Algerian company or an Algerian national. Data can still be copied abroad for the business itself. Foreign providers count only where a mutual recognition agreement exists.

In force since 18 February 2026

Enforced by Ministry of Post and Telecommunications

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed

E-commerce

E-commerce data needs a copy kept in the country

Official name: Loi n° 18-05 relative au commerce electronique · Loi n° 18-05 du 10 mai 2018 (JO n° 28 du 16 mai 2018) · Act of parliament

In forceA copy must stay

Do you sell online to people in Algeria? You must run the storefront on hosting located in Algeria, under a .com.dz address. You must register the domain with the national trade register centre. And you must keep records of every transaction for it. Customer data can still travel abroad, but only under the general privacy law.

In force since 16 May 2018

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Government

Internet and platform rules

Official name: Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees · Decret presidentiel n° 25-320 du 30 decembre 2025 (JO n° 87 du 30 decembre 2025) · Directly binding regulation

Partly in forceNo — it stays put

Since the end of December 2025, public bodies may exchange digital data only through a state interoperability platform. That platform runs on a network deliberately separated from the internet. The rule also covers private companies entrusted with a public service, once they are brought into the system. The duties to classify and catalogue data do not start until two reference documents are published. That can happen by a single decision, with no consultation.

In force since 30 December 2025

Enforced by National Authority for the Protection of Personal Data

How this country controls where data goes: Not allowed

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

State and security data rules

Official name: Loi n° 18-07 relative a la protection des personnes physiques dans le traitement des donnees a caractere personnel, modifiee et completee par la loi n° 25-11 · Loi n° 18-07 du 10 juin 2018 (JO n° 34), amended by Loi n° 25-11 du 24 juillet 2025 (JO n° 48) · Act of parliament

In forceYes, with paperwork

Algeria's general privacy law. Everything you do with personal data must be filed with the national authority first. Sending data abroad needs the authority's permission, unless a listed exception applies. The penalties are criminal, not just fines from a regulator. The July 2025 amendment added three things for every organisation. A compulsory data protection officer. A written register of what you do with data. And an automatic log of operations. It also removed national defence and security data from the law's reach entirely.

In force since 10 June 2018Enforced from 18 May 2023

Enforced by National Authority for the Protection of Personal Data

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed, Official 'this country is safe' decision, Explicit consent, Needed for a contract, Legal claims, To save someone’s life, Important public interest

Telecoms

Telecoms rules

Official name: Loi n° 09-04 portant regles particulieres relatives a la prevention et a la lutte contre les infractions liees aux technologies de l'information et de la communication · Loi n° 09-04 du 5 aout 2009 (JO n° 47 du 16 aout 2009) · Act of parliament

In forceYes, with paperwork

Do you offer a service that lets users communicate over a computer or telecoms system? Or do you store data for such a service? Then you must keep connection and identification records for one year, and hand them to investigators on demand. Internet access providers must also take down illegal content without delay. The law does not say where the records must be stored.

In force since 16 August 2009

Enforced by Post and Electronic Communications Regulatory Authority

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Who you would hear from

  • Autorite nationale de protection des donnees a caractere personnel

    General privacy law: filings, authorisations, transfers abroad, inspections, administrative sanctions

    Real and staffed. Fifteen members were appointed on 18 May 2022 for five years. A new president was appointed in October 2023. It has an executive secretariat, a staff corps, and its own official bulletin since 2024. Its president signed a decision in August 2025 setting up a technical committee. But no fine, order, filing form or procedure has appeared in the official gazette in four years. Enforcement is awake, but it has not yet acted against companies.

  • Autorite de regulation de la poste et des communications electroniques

    Telecoms and postal licensing, operator obligations, equipment approval

    Clearly active: it ran the 5G licence tender in 2025, launched a satellite licence process in 2026 and publishes numbered decisions regularly.

  • Ministere de la poste et des telecommunications

    Policy on digital trust, electronic certification and sector cyber security

    Opened a sector cyber incident detection and response centre in June 2026.

  • Banque d'Algerie

    Banks, financial institutions, payment service providers

    Active. It issued rules on payment service providers and customer protection in April 2025. It issued rules on the national payments committee in May 2026. All were published in the official gazette. We could not open its own website on 18 August 2026, because of a certificate problem. So anything published only there is unchecked.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The exact date the national data protection authority was 'installed', which is what starts the one-year compliance deadline in article 75 of the 2018 law

    The gazette records the appointment of the president and members on 18 May 2022. No text records a formal installation date. We have used 18 May 2023 as the date the law started to apply. If installation happened later, the deadline moved with it. Check the gazette if the exact date matters to you.

  • Whether the authority has issued any filing forms, guidance, official “this country is safe” decision or sanctions outside the official gazette

    The authority created its own official bulletin in September 2024. We could not reach its website on 18 August 2026. Anything published only there is invisible to us. Contact the authority directly if you need forms or guidance.

  • Whether any list of countries with an adequate or equivalent level of protection exists

    We found nothing in the official gazette. The law refers to countries 'whose legislation is recognised as equivalent'. We found no text naming one. Assume no such list exists until the gazette shows otherwise.

  • Whether banking, payments, insurance or securities rules impose data storage inside Algeria

    The 2023 monetary and banking law and the April 2025 payment service provider rules contain no such rule. But we could not reach the Bank of Algeria's website, or the insurance and securities regulators' sites. Anything issued outside the gazette is unchecked. If you work in finance, ask your supervisor directly.

  • The age at which a person stops being a child for consent purposes

    The data protection law requires the legal representative's consent for a child, but does not define the age. Algeria's child protection law treats anyone under 18 as a child. We could not check that against the law's own text. Confirm the age before you build an age gate.

  • Whether any modern rule restricts mapping, survey or high-resolution location data

    The only texts we found run from 1967 to 1994. They concern the national cartographic institute's monopoly under defence ministry supervision. We could not find a current rule, and no defence ministry source was reachable. If you handle Algerian mapping or location data, check before you rely on this.

  • Dinar to US dollar conversions used in the penalty figures

    We converted at roughly 130 Algerian dinars to the dollar, which is an approximation. We could not check the official rate, because the central bank website was unreachable.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.