Algeria
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
Data governance in Algeria
The eight things that decide how you handle data about people in Algeria. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.
Article 4 of Law 18-07 borrows the older European test of 'means located on the territory', not the newer test of targeting people in the country. Pure transit through Algeria is expressly excluded. A foreign business that serves Algerian customers entirely from abroad, with no local equipment, is therefore not clearly caught by the wording, which is a real difference from Europe, India or Brazil. Article 4 also treats a controller established in a country whose law is recognised as equivalent to Algerian law as if it were established in Algeria, but no list of equivalent countries has been published in the official gazette. Separately, the Algerian courts can try offences under the data law committed outside Algeria by an Algerian, by a foreigner living in Algeria, or by an Algerian company (Article 53).
Sources
- Official sourceJournal officiel de la Republique algerienne n° 34Loi n° 18-07 du 10 juin 2018 relative a la protection des personnes physiques dans le traitement des donnees a caractere personnel, articles 4 and 53
joradp.dz
“lorsque le responsable n'est pas etabli sur le territoire algerien mais recourt, a des fins de traitement des donnees a caractere personnel, a des moyens automatises ou non, situes sur le territoire algerien, a l'exclusion des traitements qui ne sont utilises qu'a des fins de transit sur le territoire national.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 48Loi n° 25-11 du 24 juillet 2025 modifiant et completant la loi n° 18-07
joradp.dz
Link checked 18 August 2026
Where the data is allowed to live
Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.
Sector by sector, checked on 18 August 2026. E-COMMERCE: hard wall. An online seller must publish a site or page hosted in Algeria with a .com.dz address, and must deposit the domain name with the national trade register centre (Law 18-05, articles 8 and 9). ELECTRONIC TRUST SERVICES (digital signatures, seals, timestamps, electronic identity): hard wall with an exit. All data collected by a trust service provider must be hosted on national territory, and may then also be transferred abroad in the course of the business (Law 26-02 of 17 February 2026, article 27). Providers must also be Algerian legal persons or Algerian nationals. GOVERNMENT: closed channel. Since 30 December 2025 the national interoperability system is the exclusive route for digital data exchange between public bodies, running on a secured national interconnection network kept separate from the internet (Presidential Decree 25-320). TELECOMS: all international traffic other than satellite must be carried entirely over the international infrastructure of the historic operator (Law 18-04, article 126), and identification and traffic data must be kept for one year (Law 09-04, article 11). HEALTH: no storage rule found, but every public and private health facility must keep a single computerised patient record and must join the national health information system (Law 18-11, articles 292 and 321). BANKING, PAYMENTS, INSURANCE, SECURITIES: no storage or localisation rule found in the monetary and banking law of 2023 or in the April 2025 regulation on payment service providers, checked 18 August 2026; the central bank's own website was unreachable, so instructions published only there could not be checked. GAMBLING: not a licensed activity in Algeria, so no rule sought. MAPPING: the national cartographic institute has held a monopoly on mapping work since 1967 under defence ministry supervision, but we found no modern instrument on mapping data, so this is flagged as unconfirmed.
Sources
- Official sourceJournal officiel de la Republique algerienne n° 34Loi n° 18-07, articles 44 and 45 (transfert de donnees vers un pays etranger)
joradp.dz
“Le responsable d'un traitement ne peut transferer, les donnees a caractere personnel vers un Etat etranger, que sur autorisation de l'autorite nationale ... Il est interdit, dans tous les cas, de communiquer ou de transferer des donnees a caractere personnel vers un pays etranger, lorsque ce transfert est susceptible de porter atteinte a la securite publique ou aux interets vitaux de l'Etat.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 14Loi n° 26-02 du 17 fevrier 2026 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique, article 27
joradp.dz
“Toutes les donnees recueillies par les fournisseurs de services de confiance doivent etre hebergees sur le territoire national et peuvent etre transferees en dehors de celui-ci, dans le cadre de leur activite, sans prejudice des dispositions legislatives et reglementaires en vigueur.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 28Loi n° 18-05 du 10 mai 2018 relative au commerce electronique, article 8
joradp.dz
“L'activite de commerce electronique est soumise a inscription, selon le cas, au registre du commerce ou au registre de l'artisanat et des metiers, et a la publication d'un site ou d'une page web heberge en Algerie avec une extension " .com.dz ".”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 87Decret presidentiel n° 25-320 du 30 decembre 2025 portant mise en place d'un dispositif national de gouvernance des donnees, articles 10 to 12
joradp.dz
“Le systeme national d'interoperabilite est le cadre exclusif pour l'echange de donnees numeriques entre les institutions et les administrations publiques, a travers l'infrastructure du reseau d'interconnexion national securise, dedie a cet effet.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 27Loi n° 18-04 du 10 mai 2018 fixant les regles generales relatives a la poste et aux communications electroniques, article 126
joradp.dz
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 28Reglement de la Banque d'Algerie n° 25-02 du 14 avril 2025 fixant les conditions d'autorisation, d'agrement et d'exercice des prestataires de services de paiement
joradp.dz
Link checked 18 August 2026
Sending data out of the country
The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.
Article 44 of Law 18-07 sets the authorisation rule and the test of a sufficient level of protection, judged by the authority on the law of the destination country, the security measures in place there, and the purpose, duration, nature, origin and destination of the data. Article 45 lists the exceptions that allow a transfer even to a country that fails that test. There is one absolute bar: no transfer at all where it could harm public security or the vital interests of the state. Nothing in the official gazette sets out how to apply, what the form looks like or how long a decision takes, and the authority's own website could not be reached from our checker on 18 August 2026, so the practical route to an authorisation is unverified. A separate and narrower transfer regime for police and justice bodies was added in July 2025 and requires the competent authority to assess the destination itself, with the option of asking the national authority for an opinion first.
Sources
- Official sourceJournal officiel de la Republique algerienne n° 34Loi n° 18-07, articles 44 and 45
joradp.dz
“Par derogation aux dispositions de l'article 44 de la presente loi, le responsable d'un traitement, peut transferer des donnees a caractere personnel vers un Etat ne repondant pas aux conditions prevues par ledit article : 1° si la personne concernee a consenti expressement a leur transfert”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 48Loi n° 25-11, new article 45 bis 13 (transfers by police and justice bodies)
joradp.dz
Link checked 18 August 2026
- Official sourceLink may be brokenANPDPAutorite nationale de protection des donnees a caractere personnel - official website
anpdp.dz
Link checked 18 August 2026
The regulator, and whether it actually acts
The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.
Evidence trail from the official gazette: Presidential Decree 22-187 of 18 May 2022 appointed the president and members for five years; Presidential Decree 23-73 of 14 February 2023 organised the executive secretariat; Presidential Decree 23-147 of 5 April 2023 created the staff corps; an interministerial order of 17 September 2024 created the authority's own official bulletin; a decision of 31 August 2025 set up an internal technical committee and is signed by the president, Samir Bourehil. The July 2025 amendment gave the authority regional units for inspection and audit, but their conditions of operation still have to be set by regulation. Two caveats. First, the authority publishes its own bulletin, which we could not open, so decisions may exist outside the gazette. Second, criminal offences under the law are prosecuted by the ordinary courts on the report of judicial police officers, so a case can proceed without the authority acting at all. Sector regulators are separate and functioning: the telecoms and post regulator issues decisions regularly, and the telecoms ministry launched a sector cyber incident response centre in June 2026.
Sources
- Official sourceJournal officiel de la Republique algerienne n° 35Decret presidentiel n° 22-187 du 18 mai 2022 portant nomination du president et des membres de l'autorite nationale de protection des donnees a caractere personnel
joradp.dz
“Sont nommes membres de l'autorite nationale de protection des donnees a caractere personnel, pour une duree de cinq (5) annees”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 63Decision du 31 aout 2025 portant constitution d'un comite technique aupres de l'autorite nationale de protection des donnees a caractere personnel, signed by the authority's president
joradp.dz
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 67Arrete interministeriel du 17 septembre 2024 portant creation d'un bulletin officiel de l'autorite nationale de protection des donnees a caractere personnel
joradp.dz
Link checked 18 August 2026
- Official sourceMinistere de la poste et des telecommunicationsMinistere de la poste et des telecommunications - launch of the sector cyber incident detection and response centre, June 2026
mpt.gov.dz
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.
The ten-year accounting rule comes from the financial accounting law of 2007, articles 20 and 22, and covers both full and simplified bookkeeping. The one-year telecom rule comes from the 2009 cybercrime law, article 11, and covers user identification data, terminal equipment data, the time and duration of each communication, the services used, the recipients and the addresses of sites visited. Conflicts are resolved in favour of the specific keeping rule: article 65 of the data law makes it an offence to keep personal data beyond the period fixed by the legislation in force, or the period stated in your own filing, which means the filing you make becomes your own binding deadline. Article 9 also lets the authority approve longer keeping for historical, statistical or scientific purposes if you ask and can show a legitimate interest.
Sources
- Official sourceJournal officiel de la Republique algerienne n° 74Loi n° 07-11 du 25 novembre 2007 portant systeme comptable financier, articles 20 and 22
joradp.dz
“Les livres comptables ou les supports qui en tiennent lieu ainsi que les pieces justificatives sont conserves pendant dix (10) ans a compter de la date de cloture de chaque exercice comptable.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 47Loi n° 09-04 du 5 aout 2009, article 11 (conservation des donnees relatives au trafic)
joradp.dz
“La duree de conservation des donnees citees au present article est fixee a une (1) annee a compter du jour de l'enregistrement.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 34Loi n° 18-07, articles 9 and 65
joradp.dz
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 28Loi n° 18-05, article 25 (registres des transactions commerciales)
joradp.dz
Link checked 18 August 2026
If something goes wrong
There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.
Article 43 of Law 18-07 is the operative rule for providers on public electronic communications networks and uses the words 'sans delai', without delay. Telling the individual is not required if the authority finds that the provider had appropriate protection measures in place. Article 66 makes failure to notify either the authority or the person a criminal offence. The July 2025 amendment created a separate Title V bis for processing to prevent, investigate and prosecute crime and to enforce sentences; inside that title, article 45 bis 8 sets a five-day deadline to inform the authority and article 45 bis 10 requires telling the individual where the risk is high, with the option to delay that where an investigation would be harmed. No general duty was found for ordinary businesses to report a cyber incident to a national agency: the national information systems security framework of January 2020, amended in November 2025, sets up a council and an agency under the Ministry of National Defence rather than a reporting deadline, and the telecoms ministry's sector incident response centre opened in June 2026 as a channel rather than a legal duty. Checked 18 August 2026.
Sources
- Official sourceJournal officiel de la Republique algerienne n° 34Loi n° 18-07, articles 43 and 66
joradp.dz
“le fournisseur de services avertit, sans delai, l'autorite nationale et la personne concernee lorsque cette violation peut porter atteinte a sa vie privee.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 48Loi n° 25-11, new articles 45 bis 8 to 45 bis 10 (five-day notification, criminal justice processing only)
joradp.dz
“En cas de violation de donnees a caractere personnel, le responsable du traitement doit en informer l'autorite nationale, au plus tard, cinq (5) jours apres en avoir pris connaissance.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 4Decret presidentiel n° 20-05 du 20 janvier 2020 portant mise en place d'un dispositif national de la securite des systemes d'information
joradp.dz
Link checked 18 August 2026
- Official sourceMinistere de la poste et des telecommunicationsMinistere de la poste et des telecommunications - sector cyber incident detection and response centre, June 2026
mpt.gov.dz
Link checked 18 August 2026
What catches people out
Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.
On the criminal exposure: the maximum administrative fine the authority itself can impose is 500,000 dinars, about 3,800 US dollars, so the deterrent is not the money but the prison sentence and the power to withdraw your filing receipt or authorisation, which stops the processing. Article 48 lets the authority withdraw a filing without delay where the processing turns out to harm national security or offend public morals, a ground with no equivalent in European law. On children: processing a child's data needs the consent of the legal representative or the authorisation of a judge, and a judge can order processing without the parent's consent where the child's best interests require it, and can withdraw that at any time; the data law does not itself state the age at which someone stops being a child. On sensitive data: the categories include racial or ethnic origin, political opinions, religious or philosophical belief, trade union membership and health, including genetic data. On trust services and online selling: the provider must be an Algerian legal person or an Algerian national, and an online shop must run on Algerian hosting under a .com.dz address, which rules out a plain foreign cloud front end.
Sources
- Official sourceJournal officiel de la Republique algerienne n° 34Loi n° 18-07, articles 7, 8, 18, 46, 47, 48 and 67
joradp.dz
“Est puni d'un emprisonnement d'un (1) an a cinq (5) ans et d'une amende de 500.000 DA a 1.000.000 DA, quiconque effectue un transfert de donnees a caractere personnel vers un Etat etranger, en violation des dispositions de l'article 44 de la presente loi.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 48Loi n° 25-11, new articles 41 bis, 41 bis 2 and 41 bis 3, and amended article 6
joradp.dz
“Le responsable du traitement ainsi que le sous-traitant tiennent chacun un carnet automatise des operations de traitement des donnees a caractere personnel”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 45Ordonnance n° 21-09 du 8 juin 2021 relative a la protection des informations et des documents administratifs, articles 21 to 24 and 28 to 31
joradp.dz
Link checked 18 August 2026
What's changing next
Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.
Dormant switches, in order of how quickly they could change the picture. First, the two reference frameworks under the December 2025 decree: article 19 says public bodies must begin classifying and cataloguing from the date those documents are published, and they are published by a decision of the High Commissioner for Digitalisation with no consultation step. Second, the data protection authority can decide on its own that a filing you have made should instead be put under prior authorisation, and it has ten days from your filing to say so. Third, article 15 of the data law lets the authority publish a list of low-risk processing that qualifies for a simplified filing; no such list has appeared, so today everything follows the full route. Fourth, the trust services law of February 2026 needs its implementing texts and a new national electronic certification authority; until that authority is actually set up, the existing certification bodies carry on, and the old 2015 implementing texts stay in force. Fifth, the national information systems security strategy for 2025 to 2029 was approved on 30 December 2025 and may produce further obligations.
Sources
- Official sourceJournal officiel de la Republique algerienne n° 87Decret presidentiel n° 25-320, articles 8 and 19; Decret presidentiel n° 25-321 approving the national information systems security strategy 2025-2029
joradp.dz
“Les instituions et les administrations publiques s'engagent a proceder a la classification de leurs donnees ainsi qu'au catalogage des sources de leurs donnees, conformement aux dispositions du present decret, a compter de la date de publication des deux referentiels cites a l'article 8 ci-dessus.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 48Loi n° 25-11, new article 27 bis (regional control and audit units, conditions to be set by regulation)
joradp.dz
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 14Loi n° 26-02, articles 112 to 115 (transition to the new certification authority)
joradp.dz
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 35Decret presidentiel n° 22-187 (five-year terms from 18 May 2022)
joradp.dz
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique
Act of parliament · Loi n° 26-02 du 17 fevrier 2026 (JO n° 14 du 18 fevrier 2026)
Anyone offering digital signatures, electronic seals, timestamps or electronic identity in Algeria must host every piece of data they collect on servers inside the country, and must be an Algerian company or an Algerian national. Data may still be copied abroad for the business itself. Foreign providers count only where a mutual recognition agreement exists.
Enforced by Ministry of Post and Telecommunications
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the country — from 18 February 2026All data collected by a trust service provider must be hosted on national territory. Transfers out are allowed in the course of the business, subject to the general data law.
- Register or notifyProviders need an eligibility certificate, then an authorisation, and cannot even register at the trade register before holding the eligibility certificate.
- Independent auditAuthorisation depends on a successful evaluation audit by the authority or the national information systems security body, plus periodic audits.
- Hold a security certificate
What it costs if you get it wrong
- Criminal liability: 1 to 3 years imprisonment and 1,000,000 to 5,000,000 DZD — about $38 thousandProviding trust services to the public without authorisation, or continuing after it is withdrawn
Sources
- Official sourceJournal officiel de la Republique algerienne n° 14Loi n° 26-02 du 17 fevrier 2026, articles 25, 27, 34 and 112 to 115
joradp.dz
“Toutes les donnees recueillies par les fournisseurs de services de confiance doivent etre hebergees sur le territoire national”
Link checked 18 August 2026
Loi n° 18-05 relative au commerce electronique
Act of parliament · Loi n° 18-05 du 10 mai 2018 (JO n° 28 du 16 mai 2018)
If you sell online to people in Algeria you must run the storefront on hosting located in Algeria under a .com.dz address, register the domain with the national trade register centre and keep records of every transaction for it. Customer data may still travel abroad, but only under the general privacy law.
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryThe selling site or page must be hosted in Algeria under a .com.dz address.
- Register or notifyEntry in the commercial register or the craft register, and deposit of the domain name with the national trade register centre, which publishes a national list of online sellers.
- Keep records of processingRegisters of every transaction and its date must be kept and transmitted electronically to the national trade register centre.
- Get consentAn online seller may collect only the data needed for the transaction and must respect the general data law.
What it costs if you get it wrong
- Order to stopPrecautionary suspension of the seller's domain name, for up to thirty days
Sources
- Official sourceJournal officiel de la Republique algerienne n° 28Loi n° 18-05 du 10 mai 2018, articles 8, 9, 25 and 26
joradp.dz
“la publication d'un site ou d'une page web heberge en Algerie avec une extension " .com.dz "”
Link checked 18 August 2026
Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees
Directly binding regulation · Decret presidentiel n° 25-320 du 30 decembre 2025 (JO n° 87 du 30 decembre 2025)
Since the end of December 2025 public bodies, and private companies entrusted with a public service that are brought into the system, may exchange digital data only through a state interoperability platform running on a network deliberately separated from the internet. The duties to classify and catalogue data do not start until two reference documents are published, which can happen by a single decision with no consultation.
Enforced by National Authority for the Protection of Personal Data
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryDigital data exchange between public bodies may take place only over the national interoperability system, carried on a secured national interconnection network kept separate from the internet.
- Keep records of processingEach body must classify the data in its information system and catalogue its data sources. This starts on the day the two reference frameworks are published by decision of the High Commissioner for Digitalisation.
- Secure the data
Sources
- Official sourceJournal officiel de la Republique algerienne n° 87Decret presidentiel n° 25-320 du 30 decembre 2025, articles 4 to 19
joradp.dz
“Le haut commissariat a la numerisation met en place l'infrastructure du reseau d'interconnexion national securise ... et ce, de maniere separee du reseau internet.”
Link checked 18 August 2026
Loi n° 18-11 relative a la sante
Act of parliament · Loi n° 18-11 du 2 juillet 2018 (JO n° 46 du 29 juillet 2018)
Every hospital and clinic, public or private, must keep a single computerised record for each patient and must plug into the national health information system. There is no rule found that says health data must stay in Algeria, but health data is sensitive data, so processing it needs an express consent or a narrow exception and sending it abroad needs the regulator's permission.
Transfer model: Approval each time · Accepted routes: Government sign-off needed, Someone's life is at risk
What it makes you do
- Keep records of processingEvery public and private health facility must create and keep up to date a single computerised medical record for each patient, and must manage and preserve medical archives.
- Secure the dataConfidentiality, availability and integrity of the national health information system are the responsibility of its managers and of the people who use the data.
- Keep data for a minimum periodRecords opened before the single medical record was introduced must be preserved. The classification, archiving, retention period and destruction rules are still to be set by regulation.
Sources
- Official sourceJournal officiel de la Republique algerienne n° 46Loi n° 18-11 du 2 juillet 2018, articles 292, 320 to 323 and 444 to 445
joradp.dz
“Les structures et les etablissements de sante, publics et prives, sont dans l'obligation d'integrer le systeme national d'information sanitaire.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 34Loi n° 18-07, articles 3 and 18 (health data is sensitive data; processing sensitive data is prohibited by default)
joradp.dz
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Loi n° 18-07 relative a la protection des personnes physiques dans le traitement des donnees a caractere personnel, modifiee et completee par la loi n° 25-11
Act of parliament · Loi n° 18-07 du 10 juin 2018 (JO n° 34), amended by Loi n° 25-11 du 24 juillet 2025 (JO n° 48)
Algeria's general privacy law. Every processing operation must be filed with the national authority first, sending data abroad needs the authority's permission unless a listed exception applies, and the penalties are criminal rather than administrative. The July 2025 amendment added a compulsory data protection officer, a processing register and an automatic operations log for every organisation, and removed national defence and security data from the law's reach entirely.
Enforced by National Authority for the Protection of Personal Data
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed, Official 'this country is safe' decision, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk, Important public interest
What it makes you do
- Register or notifyEvery processing operation must be filed with the authority before it starts, or authorised by it. A receipt is issued within 48 hours and you may start on receipt.
- Get consentExpress consent is the default basis. Exceptions include a legal obligation, saving a life, a public interest task, performing a contract and a legitimate interest.
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people object
- Limit automated decisionsNo decision with legal effects may rest solely on automated profiling.
- Secure the data
- Written vendor contractA written contract with the processor is required, and the data protection terms must be recorded in writing for evidence.
- Appoint a local representative — from 10 June 2018Required where the controller is not established in Algeria but uses means located there.
- Appoint a data protection officer — from 24 July 2025Added by the 2025 amendment. No size threshold. One officer may serve several controllers depending on their structure and size.
- Keep records of processing — from 24 July 2025
- Keep logs — from 24 July 2025Automated 'carnet' logging every collection, consultation, disclosure, encryption, erasure and destruction, with time and, where possible, the identity of the user and the recipients.
- Report breaches to the regulatorWithout delay, for providers of services on public electronic communications networks. No fixed hours.
- Tell affected people
- Put a transfer safeguard in place
- Delete data after a periodNo longer than the purpose requires. Longer keeping for historical, statistical or scientific purposes needs the authority's permission.
- Get a parent's consent for childrenConsent of the legal representative, or authorisation of the competent judge, who may also override the representative in the child's best interests.
- Assess high-risk projects — from 24 July 2025Written into the new criminal justice title; the data protection officer advises on impact assessments generally.
What it costs if you get it wrong
- Criminal liability: 1 to 5 years imprisonment and 500,000 to 1,000,000 DZD — about $8 thousandTransferring personal data abroad in breach of the transfer rule
- Criminal liability: 2 to 5 years imprisonment and 200,000 to 500,000 DZD — about $4 thousandProcessing without the required filing or authorisation, false filing, or continuing after withdrawal
- Criminal liability: 2 to 5 years imprisonment and 200,000 to 500,000 DZD — about $4 thousandProcessing sensitive data without express consent, or letting unauthorised people reach personal data
- Criminal liability: 1 to 3 years imprisonment and 100,000 to 300,000 DZD — about $2 thousandFailure to notify a personal data breach to the authority or the individual
- Fixed maximum fine: 500,000 DZD — about $4 thousandAdministrative fine by the authority, for refusing individuals' rights or failing to make required notifications
- Order to stopTemporary withdrawal of the filing receipt or authorisation for up to one year, or permanent withdrawal, including where the processing harms national security or public morals
Sources
- Official sourceJournal officiel de la Republique algerienne n° 34Loi n° 18-07 du 10 juin 2018 - full text
joradp.dz
“Nonobstant toute disposition legislative contraire, toute operation de traitement des donnees a caractere personnel, est soumise a une declaration prealable a l'autorite nationale ou a son autorisation conformement aux dispositions prevues par la presente loi.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 48Loi n° 25-11 du 24 juillet 2025 - full text of the amendment
joradp.dz
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 35Decret presidentiel n° 22-187 - appointment of the authority, which starts the one-year compliance clock in article 75
joradp.dz
Link checked 18 August 2026
Loi n° 09-04 portant regles particulieres relatives a la prevention et a la lutte contre les infractions liees aux technologies de l'information et de la communication
Act of parliament · Loi n° 09-04 du 5 aout 2009 (JO n° 47 du 16 aout 2009)
Anyone offering a service that lets users communicate over a computer or telecoms system, and anyone storing data for such a service, must keep connection and identification records for one year and hand them to investigators on demand. Internet access providers must also take down illegal content without delay. The law does not say where the records must be stored.
Enforced by Post and Electronic Communications Regulatory Authority
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep logs — 1 yearUser identification data, terminal equipment data, time and duration of each communication, services used, recipients and addresses of sites visited. Telephone operators must also keep data identifying and locating the origin of a call.
- Keep data for a minimum period — 1 year
What it costs if you get it wrong
- Criminal liability: 6 months to 5 years imprisonment and 50,000 to 500,000 DZD — about $4 thousandFailure to keep the data where this obstructs a judicial investigation. Companies are fined under the criminal code.
Sources
- Official sourceJournal officiel de la Republique algerienne n° 47Loi n° 09-04 du 5 aout 2009, articles 10 to 12
joradp.dz
“La duree de conservation des donnees citees au present article est fixee a une (1) annee a compter du jour de l'enregistrement.”
Link checked 18 August 2026
- Official sourceJournal officiel de la Republique algerienne n° 27Loi n° 18-04 du 10 mai 2018, article 126 (international traffic routed through the historic operator)
joradp.dz
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The exact date the national data protection authority was 'installed', which is what starts the one-year compliance deadline in article 75 of the 2018 law
The gazette records the appointment of the president and members on 18 May 2022, but no text records a formal installation. We have used 18 May 2023 as the date the law began to bite. If installation happened later, the deadline moved with it.
Whether the authority has issued any filing forms, guidance, adequacy findings or sanctions outside the official gazette
The authority created its own official bulletin in September 2024 and its website could not be reached from this environment on 18 August 2026. Anything published only there is invisible to us.
Whether any list of countries with an adequate or equivalent level of protection exists
Nothing in the official gazette. The law refers to countries 'whose legislation is recognised as equivalent', but we found no instrument naming one.
Whether banking, payments, insurance or securities rules impose data storage inside Algeria
The 2023 monetary and banking law and the April 2025 payment service provider regulation contain no such rule, but the Bank of Algeria website is unreachable from here and the insurance and securities regulators could not be opened either, so instructions issued outside the gazette are unchecked.
The age at which a person stops being a child for consent purposes
The data protection law requires the legal representative's consent for a child but does not define the age. Algeria's child protection law treats anyone under 18 as a child, which we could not verify against its own text during this run.
Whether any modern rule restricts mapping, survey or high-resolution location data
The only instruments found are from 1967 to 1994 and concern the national cartographic institute's monopoly under defence ministry supervision. We could not find a current instrument, and no defence ministry source was reachable.
Dinar to US dollar conversions used in the penalty figures
Converted at roughly 130 Algerian dinars to the dollar, an approximation. The official rate could not be checked because the central bank website was unreachable.
60-day cadence. Three switches can flip without consultation: publication of the data classification and cataloguing reference frameworks by the High Commissioner for Digitalisation, which starts real duties for public bodies and public service companies; the implementing regulation for the data protection authority's regional inspection and audit units; and the implementing texts and new certification authority under the February 2026 trust services law. The authority's members were appointed for five years from 18 May 2022, so a reappointment round is due before May 2027.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
Algeria versus
Compare