Law / Algeria

Loi n° 18-07 relative à la protection des personnes physiques dans le traitement des données à caractère personnel, modifiée et complétée par la loi n° 25-11

Loi n° 18-07 du 10 juin 2018 Journal officiel n° 34, telle que modifiée et complétée par la loi n° 25-11 du 24 juillet 2025, Journal officiel n° 48

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 11 August 2023.

A comprehensive regime rule binding public and private bodies.

As of 4 September 2026.

What it requires

  • Obtain a lawful basis before processing the personal data of a person in Algeria, whether or not the processing is automated.
  • Do not process racial or ethnic origin, political opinions, religious or philosophical convictions, trade-union membership, or health data including genetic data, unless a listed exception applies, such as the data subject's express consent or data the person has manifestly made public.
  • Put in place technical and organizational security measures adequate to the risk, with heightened measures for sensitive and biometric data.
  • Designate a data protection officer, who may serve more than one controller depending on their organizational structure and size.
  • Before processing likely to create a high risk to a person's rights and freedoms, carry out a data protection impact assessment.
  • Do not base a judicial decision, or any other decision producing legal effects against a person, solely on automated processing that evaluates aspects of that person's personality.
  • Notify the ANPDP of a personal-data breach within five days of becoming aware of it; state the reason for the delay if notification is later.
  • Before transferring personal data to a foreign state, obtain the ANPDP's prior authorization, and never transfer data where the transfer could harm public security or the State's vital interests.
  • Respond to a data subject's request for information, access, rectification, or opposition to processing.
  • Where processing concerns a child, obtain the consent of the child's legal representative, or the authorization of the competent judge.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Loi n° 18-07 arts. 54 to 74 set a tiered set of criminal offences rather than one penalty: unlawful processing of sensitive data or processing that breaches the law's dignity and privacy principles carries two to five years' imprisonment and a fine of 200,000 to 500,000 DA (art. 54, art. 57); processing without a lawful basis or against a data subject's objection carries one to three years and 100,000 to 300,000 DA (art. 55); processing without complying with the prior-declaration or authorization conditions of art. 12 carries two to five years and 200,000 to 500,000 DA (art. 56); processing for a purpose other than the one declared or authorized carries six months to one year and 60,000 to 100,000 DA (art. 58); fraudulent collection carries one to three years and 100,000 to 300,000 DA (art. 59); letting an unauthorized person access personal data carries two to five years and 200,000 to 500,000 DA (art. 60); obstructing the ANPDP carries six months to two years and 60,000 to 200,000 DA (art. 61); revealing information protected under the law, by a person bound by professional secrecy under arts. 23 and 27, carries the penalty set by Penal Code art. 301 (art. 62); unauthorized access to the national register of art. 28 carries one to three years and 100,000 to 300,000 DA (art. 63); a controller's unjustified refusal of a data subject's information, access, rectification, or opposition rights carries two months to two years and 20,000 to 200,000 DA (art. 64); a breach of the security duties of arts. 38-39, or retaining data beyond its authorized duration, carries a fine of 200,000 to 500,000 DA (art. 65); a service provider's failure to notify a breach carries one to three years and 100,000 to 300,000 DA (art. 66); an unauthorized foreign transfer carries one to five years and 500,000 to 1,000,000 DA (art. 67); unauthorized retention of offence or conviction data carries six months to three years and 60,000 to 300,000 DA (art. 68); and negligently facilitating misuse or unauthorized disclosure of processed data carries one to five years and 100,000 to 500,000 DA (art. 69). Penalties double on recidivism (art. 74). A legal person is punished with a fine under the Penal Code's rules for legal persons (art. 70).

Penalty structure

The highest criminal fine on the tiered scale set by arts. 54 to 74 is the 500,000 to 1,000,000 DA range for an unauthorized foreign transfer (art. 67); most other offences carry a lower fine within a 20,000 to 500,000 DA range depending on the provision breached (art. 64's refusal-of-rights offence sets the floor) (see criminal_exposure_note for the full table). Separately, art. 47 lets the ANPDP itself impose a direct administrative fine of 500,000 DA on a controller that refuses a data subject's rights or fails to make a required notification. All figures double on recidivism under art. 74.

Rule
Fixed only
As of
4 September 2026
Currency
DZD
Fixed cap
1,000,000

Who enforces it

Enforcement body

Autorité nationale de protection des données à caractère personnel (ANPDP)

What it reaches

Obligation class

Consent, Data subject rights, Biometric, Transfer, Breach notice, Governance, DPIA, Security

Who checks it

Audit expectation

continuous

Who audits it

Regulator

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Loi n° 18-07 sets Algeria's general rules for processing personal data of a natural person, binding both public bodies and private persons, whether the processing is automated or held in a manual filing system, and reaching a controller established outside Algeria that uses processing means located in Algeria.

Existing data controllers had one year from the installation of the Autorité nationale de protection des données à caractère personnel (ANPDP) to comply, which Algeria's state press agency reported took place on 11 August 2022, placing that compliance deadline on 11 August 2023.

Processing sensitive data (racial or ethnic origin, political opinions, religious or philosophical convictions, trade-union membership, or health data including genetic data) is prohibited unless a listed exception applies, such as the data subject's express consent or data the data subject has manifestly made public. A data subject has rights to information, access, rectification, and opposition, and a transfer of personal data to a foreign state needs the ANPDP's prior authorization.

Loi n° 25-11 of 24 July 2025 adds a mandatory data protection officer, a right against a judicial or other legally significant decision based solely on automated processing evaluating aspects of a person's personality, a data protection impact assessment duty for processing likely to create a high risk, a five-day breach notification deadline to the ANPDP, heightened security duties specifically for sensitive and biometric data, and a defined biometric-data category.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors

Read the law

Loi n° 18-07 du 10 juin 2018 and loi n° 25-11 du 24 juillet 2025, Journal officiel de la République algérienne

Back to the example  ·  Lint your app