Law / Algeria

Loi n° 18-07 relative à la protection des personnes physiques, notification des violations de données

Loi n° 18-07 du 10 juin 2018, art. 43, telle que modifiée et complétée par la loi n° 25-11 du 24 juillet 2025, arts. 45 bis 8 et 45 bis 10

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 11 August 2023.

A breach notification rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • As a service provider, that is any public or private entity offering users the ability to communicate over a computer or telecommunications system, or any entity processing or storing data for that communication service, notify the ANPDP without delay of a personal-data breach occurring on a public electronic communications network.
  • Notify the affected individual without delay of that same breach where it may harm their private life, unless the ANPDP finds you had already implemented appropriate protective measures.
  • Keep an up-to-date inventory of personal-data breaches and the measures you took to remedy them.
  • If you are the judicial authority, a body legally empowered to investigate offences, a judicial auxiliary or the prison administration processing personal data under Title V bis for the prevention or detection of offences, investigations, inquiries, criminal prosecutions or the execution of sentences, notify the ANPDP of a personal-data breach within five days of becoming aware of it, stating the reason for the delay if the notification is made later.
  • As a processor engaged in that same Title V bis processing, notify the controller of a personal-data breach as soon as you become aware of it.
  • Within that same Title V bis processing, notify the affected individual of a breach, in clear and simple language describing its consequences, where the breach is likely to cause a high risk to their rights and freedoms.

What it reaches

Obligation class

Breach notice, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 43 requires a service provider, defined at article 3 as any public or private entity offering its users the ability to communicate by computer or telecommunications system, or any other entity processing or storing computer data for that communication service or its users, to notify the ANPDP without delay when processing personal data on a public electronic communications network results in destruction, loss, alteration, disclosure of, or unauthorised access to that data, and to notify the affected individual without delay too where the breach may harm their private life, unless the ANPDP finds the provider had already implemented appropriate protective measures; every service provider must also keep an up-to-date inventory of personal data breaches and the measures taken to remedy them.

Loi n° 25-11 of 24 July 2025 inserted article 45 bis 8, which is confined, by article 45 bis's own opening line, to processing under the new Title V bis for the prevention or detection of offences, investigations, inquiries, criminal prosecutions, or the execution of sentences, carried out only by the judicial authority, a body legally empowered to investigate offences, a judicial auxiliary, or the prison administration: within that narrow scope, the controller must notify the ANPDP of a personal-data breach within five days of becoming aware of it, stating the reason for the delay if the notification is made later, and a processor must notify the controller of the breach as soon as the processor becomes aware of it.

Article 45 bis 10, in the same Title V bis, requires the controller to notify the affected individual of a breach, in clear and simple language describing its consequences, where the breach is likely to cause a high risk to their rights and freedoms.

Existing data controllers had one year from the installation of the Autorité nationale de protection des données à caractère personnel (ANPDP) to comply, which Algeria's state press agency reported took place on 11 August 2022, placing that compliance deadline on 11 August 2023.

When LexLint raises it

  • provides_telecom_services
  • deploys_chatbot
  • automated_outreach

Read the law

Loi n° 18-07 du 10 juin 2018 and loi n° 25-11 du 24 juillet 2025, Journal officiel de la République algérienne

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app