Law / Algeria

Loi n° 18-07 relative à la protection des personnes physiques, contrôle, sanctions et voies de recours

Loi n° 18-07 du 10 juin 2018, arts. 47, 52 et 54-74, telle que modifiée et complétée par la loi n° 25-11 du 24 juillet 2025, art. 27 bis

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 11 August 2023.

An enforcement supervision rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Expect a person in Algeria harmed by an infringement of this law to be able to seek protective measures or reparation from the competent court.
  • Expect the ANPDP to fine you 500,000 DA for refusing a data subject's information, access, rectification or objection rights without legitimate reason, or for not making a required notification, doubling on a repeat violation.
  • Answer the ANPDP's own inspections and audits, and expect the tiered criminal penalties this law sets, from a fine alone up to five years' imprisonment, for the specific duty you breach.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Loi n° 18-07 arts. 54 to 74 set a tiered set of criminal offences rather than one penalty: unlawful processing of sensitive data or processing that breaches the law's dignity and privacy principles carries two to five years' imprisonment and a fine of 200,000 to 500,000 DA (art. 54, art. 57); processing without a lawful basis or against a data subject's objection carries one to three years and 100,000 to 300,000 DA (art. 55); processing without complying with the prior-declaration or authorization conditions of art. 12 carries two to five years and 200,000 to 500,000 DA (art. 56); processing for a purpose other than the one declared or authorized carries six months to one year and 60,000 to 100,000 DA (art. 58); fraudulent collection carries one to three years and 100,000 to 300,000 DA (art. 59); letting an unauthorized person access personal data carries two to five years and 200,000 to 500,000 DA (art. 60); obstructing the ANPDP carries six months to two years and 60,000 to 200,000 DA (art. 61); revealing information protected under the law, by a person bound by professional secrecy under arts. 23 and 27, carries the penalty set by Penal Code art. 301 (art. 62); unauthorized access to the national register of art. 28 carries one to three years and 100,000 to 300,000 DA (art. 63); a controller's unjustified refusal of a data subject's information, access, rectification, or opposition rights carries two months to two years and 20,000 to 200,000 DA (art. 64); a breach of the security duties of arts. 38-39, or retaining data beyond its authorized duration, carries a fine of 200,000 to 500,000 DA (art. 65); a service provider's failure to notify a breach carries one to three years and 100,000 to 300,000 DA (art. 66); an unauthorized foreign transfer carries one to five years and 500,000 to 1,000,000 DA (art. 67); unauthorized retention of offence or conviction data carries six months to three years and 60,000 to 300,000 DA (art. 68); and negligently facilitating misuse or unauthorized disclosure of processed data carries one to five years and 100,000 to 500,000 DA (art. 69). Penalties double on recidivism (art. 74). A legal person is punished with a fine under the Penal Code's rules for legal persons (art. 70).

Penalty structure

The highest criminal fine on the tiered scale set by arts. 54 to 74 is the 500,000 to 1,000,000 DA range for an unauthorized foreign transfer (art. 67); most other offences carry a lower fine within a 20,000 to 500,000 DA range depending on the provision breached (art. 64's refusal-of-rights offence sets the floor) (see criminal_exposure_note for the full table). Separately, art. 47 lets the ANPDP itself impose a direct administrative fine of 500,000 DA on a controller that refuses a data subject's rights or fails to make a required notification. All figures double on recidivism under art. 74.

Rule
Fixed only
As of
4 September 2026
Currency
DZD
Fixed cap
1,000,000

Who enforces it

Enforcement body

Autorité nationale de protection des données à caractère personnel (ANPDP)

What it reaches

Obligation class

Governance, Reporting

Who checks it

Audit expectation

continuous

Who audits it

Regulator

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 27 bis, inserted by loi n° 25-11 of 24 July 2025, gives the ANPDP regional units in charge of oversight and audit of the institutions and persons that process personal data.

Article 47 lets the ANPDP itself fine a controller 500,000 DA for refusing, without legitimate reason, the information, access, rectification or objection rights of articles 32, 34, 35 and 36, or for not making the notifications required by articles 4, 14 and 16, doubling on recidivism to the penalties article 64 sets. Article 52 lets the holder of a right under the law who claims to be harmed by its infringement seek protective measures or reparation from the competent court.

Articles 54 to 74 set a tiered set of criminal offences: unlawful processing that breaches the law's dignity and privacy principles under article 2 carries two to five years' imprisonment and a fine of 200,000 to 500,000 DA (art. 54); processing without a lawful basis or against a data subject's objection carries one to three years and 100,000 to 300,000 DA (art. 55); processing without the prior declaration or authorisation article 12 requires carries two to five years and 200,000 to 500,000 DA (art. 56); unauthorised access to the national register of article 28 carries one to three years and 100,000 to 300,000 DA (art. 63); a controller's unjustified refusal of a data subject's information, access, rectification or objection rights carries two months to two years and 20,000 to 200,000 DA (art. 64); breaching the security duties of articles 38 and 39, or retaining data beyond its authorised duration, carries a fine of 200,000 to 500,000 DA (art. 65); a service provider's failure to notify a breach under article 43 carries one to three years and 100,000 to 300,000 DA (art. 66); an unauthorised foreign transfer carries one to five years and 500,000 to 1,000,000 DA (art. 67); and obstructing the ANPDP's own inspections carries six months to two years and 60,000 to 200,000 DA (art. 61).

Penalties double on recidivism (art. 74), and a legal person is punished with a fine under the Penal Code's own rules for legal persons (art. 70). Existing data controllers had one year from the installation of the Autorité nationale de protection des données à caractère personnel (ANPDP) to comply, which Algeria's state press agency reported took place on 11 August 2022, placing that compliance deadline on 11 August 2023.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot

Read the law

Loi n° 18-07 du 10 juin 2018 and loi n° 25-11 du 24 juillet 2025, Journal officiel de la République algérienne

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app