🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
DZ v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing9 sources retrieved model claude-sonnet-5 · 2026-08-05

Algeria

DZ schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM

Last updated · 10 categories · 16 claims · 19 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
16Claimsbaseline..claims[]
1Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Algeria's data protection regime tightened materially this cycle through Law No. 25-11 of 2025, which reinforces the underlying Law 18-07 with mandatory data protection officers, five-day breach notification and data protection impact assessment obligations. The National Data Protection Authority, ANPDP, is understood to be responsible for enforcing the law, advising individuals and entities, receiving declarations, authorising processing and handling complaints, with the power to impose administrative sanctions. Alongside this accountability architecture, ANPDP is understood to have launched an active 2026 cross-border-transfer inspection campaign targeting medium-sized technology operators with international data dependencies, following field inspections of private-sector technology companies for cross-border transfer non-compliance, although this specific enforcement-campaign signal rests on a single source and is held at a more cautious confidence.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive omnibus statute exists and regulator is nominally operational, but recency/detail of implementing texts (2025 amendment) and ANPDP's practical enforcement posture could not be fully corroborated from primary sources in this run.

Primary frameworkLaw No. 18-07 of 10 June 2018 on the Protection of Individuals in the Processing of Personal Data (as amended, 2025)
Supervisory authorityAutorité Nationale de Protection des Données à Caractère Personnel (ANPDP)
Traffic-light rationale — AmberComprehensive omnibus statute exists and regulator is nominally operational, but recency/detail of implementing texts (2025 amendment) and ANPDP's practical enforcement posture could not be fully corroborated from primary sources in this run.

Sub-modules (5)

Regulator And AuthorityAmber

ANPDP is named in secondary reporting as the body issuing compliance reminders and recommendations to controllers, indicating an operational (not merely nominal) regulator.

Claims (1):

  • ANPDP (Autorité Nationale de Protection des Données à Caractère Personnel) is the designated national data-protection supervisory authority for Algeria and has issued compliance reminders and recommendations to controllers.

Act And InstrumentsAmber

Law 18-07 (2018) is the founding instrument; a modifying law was published in the Official Gazette in 2025.

Claims (2):

  • Law No. 18-07 of 10 June 2018 on the Protection of Individuals in the Processing of Personal Data was published in Algeria's Official Gazette and constitutes the founding comprehensive data-protection statute.
  • A law modifying the 2018 Data Protection Law was published in Algeria's Official Gazette in 2025, indicating an active legislative refinement of the regime.

Material ScopeAmber

The law is understood to cover automated and structured manual processing of personal data by public and private controllers established in Algeria, following the general Francophone-civil-law model; granular scope wording could not be independently retrieved.

Absence provenance: unavailable. Searched: Algérie loi 18-07 protection données caractère personnel, loi 18-07 Algérie 10 juin 2018 traitement données caractère personnel joradp.

Claims (1):

  • Law 18-07 is understood to apply to automated and organised manual processing of personal data carried out by public and private-sector controllers within Algeria, consistent with the general Francophone civil-law data-protection model.

Territorial ScopeRed

No confirmed evidence of an explicit extraterritorial/non-established-controller trigger comparable to GDPR Art 3(2) was retrieved for Law 18-07.

Absence provenance: unavailable. Searched: Algeria data protection law territorial scope non-established controllers.

Regulator Registration And FilingAmber

Francophone-model DP statutes of this era typically require prior declaration/authorisation filings with the national authority for certain processing categories; ANPDP's specific filing/registration procedures under 18-07 could not be verified from primary sources in this run.

Claims (1):

  • Algeria's regime is understood to require prior declaration or authorisation from ANPDP for certain categories of processing, following the regional CNIL-style prior-formality model, though the precise thresholds under 18-07 were not independently confirmed in this run.
Category narrative149 words

Algeria's comprehensive data-protection regime rests on Law No. 18-07 of 10 June 2018 on the Protection of Individuals in the Processing of Personal Data, which created the Autorité Nationale de Protection des Données à Caractère Personnel (ANPDP) as supervisory authority. The law was published in 2018 but its practical entry into force (and ANPDP's operationalisation) was delayed for several years, with sources confirming the law was still pending full effect as of early 2023 and reported as having entered into force in August 2023. A modifying law was published in the Official Gazette in 2025, indicating the regime is still being actively refined. Because primary JORADP full-text and the ANPDP's own confirmed institutional URL could not be independently retrieved in this run (secondary commentary sources were access-restricted at point of research), several structural details rely on established general knowledge of the statute rather than a freshly retrieved primary-source quotation.

Periodic update · new data 2026-09-28

Regulator & Framework

Algeria's data protection framework is anchored in Law No. 18-07, with the National Data Protection Authority, ANPDP, operational and understood to be responsible for enforcing the law, advising individuals and entities, receiving declarations and authorising processing, handling complaints and imposing administrative sanctions. This cycle's material development is Law No. 25-11 of 2025, which is understood to reinforce Law 18-07 by introducing mandatory data protection officers, a five-day breach notification requirement and data protection impact assessment obligations, a meaningful strengthening of the accountability architecture controllers must maintain.

This reinforcement suggests ANPDP is moving from an institution primarily focused on registration and authorisation toward one exercising a broader accountability-oversight mandate, consistent with the sectoral deliberations and active enforcement inspections observed elsewhere this cycle. The precise operative detail of Law 25-11's provisions rests on academic secondary reporting rather than a directly retrieved statutory text, a gap noted in the underlying research.

Outlook

The framework's trajectory is toward increased institutional activity and codified accountability obligations. The open question for future cycles is whether ANPDP's expanded mandate under Law 25-11 will be matched by published guidance or enforcement decisions that make the DPO, breach-notification and DPIA obligations operationally concrete for controllers.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. ProbableDataGuidance (OneTrust) — ANPDP (Autorité Nationale de Protection des Données à Caractère Personnel) is the designated national data-protection supervisory authority for Algeria and has issued compliance reminders and recommendations to controllers.observed
  2. ProbableDataGuidance (OneTrust) — Law No. 18-07 of 10 June 2018 on the Protection of Individuals in the Processing of Personal Data was published in Algeria's Official Gazette and constitutes the founding comprehensive data-protection statute.observed
  3. UncertainDataGuidance (OneTrust) — A law modifying the 2018 Data Protection Law was published in Algeria's Official Gazette in 2025, indicating an active legislative refinement of the regime.observed
  4. SpeculativeInternal (no external corroboration retrieved for this specific claim) — Law 18-07 is understood to apply to automated and organised manual processing of personal data carried out by public and private-sector controllers within Algeria, consistent with the general Francophone civil-law data-protection model.observed
  5. SpeculativeInternal (no external corroboration retrieved for this specific claim) — Algeria's regime is understood to require prior declaration or authorisation from ANPDP for certain categories of processing, following the regional CNIL-style prior-formality model, though the precise thresholds under 18-07 were not independently confirmed in this run.observed

#

No sentence-level primary or secondary source content was retrieved describing the specific lawful-basis enumeration, consent threshold, or special-category list; findings rely on regional-pattern inference only.

Primary frameworkLaw No. 18-07 of 10 June 2018
Supervisory authorityANPDP
Traffic-light rationale — RedNo sentence-level primary or secondary source content was retrieved describing the specific lawful-basis enumeration, consent threshold, or special-category list; findings rely on regional-pattern inference only.

Sub-modules (4)

Lawful BasesRed

Believed to include consent and other statutory grounds (legal obligation, public-interest task, contract necessity), but no verified article-level enumeration was retrieved.

Absence provenance: unavailable. Searched: Algeria law lawful bases processing personal data 18-07.

Claims (1):

  • Law 18-07 is understood to permit personal-data processing on grounds including data-subject consent and other statutory bases (e.g., legal obligation, public-interest task), following the regional Francophone data-protection model, though the exact enumerated list was not independently verified from primary text in this run.

Special CategoriesAmber

Regional-model statutes of this type typically restrict processing of health, genetic, biometric, religious, political and criminal-record data absent specific authorisation; DZ-specific enumeration not independently verified.

Claims (1):

  • Algeria's data-protection law is expected to designate categories such as health, genetic, biometric, religious/philosophical, political, and criminal-record data as sensitive, subject to heightened restrictions or authorisation requirements, consistent with comparable regional statutes; DZ-specific statutory wording was not independently confirmed in this run.

Pseudonymisation And AnonymisationRed

No sourced information located on statutory pseudonymisation/anonymisation safe-harbour definitions under 18-07.

Absence provenance: unavailable. Searched: Algeria law pseudonymisation anonymisation data protection.

Category narrative68 words

Law 18-07 is expected to set out grounds for lawful processing (consent and other statutory grounds) and heightened protection for sensitive categories (health, genetic, religious/philosophical opinion, ethnic origin, criminal records, etc.), consistent with the Francophone-model statutes of the same generation (e.g. Tunisia, Morocco, Senegal). Independent verification of the precise enumerated lawful bases, consent standard wording, and pseudonymisation/anonymisation definitions could not be completed against primary text in this run.

no periodic updates on record for this sub-brief

Sources and claims (2)
  1. SpeculativeInternal (no external corroboration retrieved for this specific claim) — Law 18-07 is understood to permit personal-data processing on grounds including data-subject consent and other statutory bases (e.g., legal obligation, public-interest task), following the regional Francophone data-protection model, though the exact enumerated list was not independently verified from primary text in this run.observed
  2. SpeculativeInternal (no external corroboration retrieved for this specific claim) — Algeria's data-protection law is expected to designate categories such as health, genetic, biometric, religious/philosophical, political, and criminal-record data as sensitive, subject to heightened restrictions or authorisation requirements, consistent with comparable regional statutes; DZ-specific statutory wording was not independently confirmed in this run.observed

#

No sentence-level source content was retrieved on DZ's specific subject-rights catalogue, deadlines, or portability provision; module populated with inference-based, low-confidence claims and explicit gaps only.

Primary frameworkLaw No. 18-07 of 10 June 2018
Supervisory authorityANPDP
Traffic-light rationale — RedNo sentence-level source content was retrieved on DZ's specific subject-rights catalogue, deadlines, or portability provision; module populated with inference-based, low-confidence claims and explicit gaps only.

Sub-modules (5)

Access RightAmber

Believed to exist in some form (droit d'accès) consistent with the regional model; not independently verified.

Claims (1):

  • Individuals are expected to hold a right of access to personal data held about them under Law 18-07, consistent with the regional Francophone data-protection model, though the specific statutory mechanics were not independently verified in this run.

Rectification And ErasureAmber

Rectification likely present; a full GDPR-style erasure/'right to be forgotten' is uncertain for this statutory generation.

Claims (1):

  • A right to rectify inaccurate personal data is expected under Law 18-07 consistent with the regional statutory model; the presence and scope of an erasure/right-to-be-forgotten equivalent could not be independently confirmed in this run.

Restriction And ObjectionRed

A right of objection (droit d'opposition) is plausible by regional pattern; not independently verified for DZ.

Absence provenance: unavailable. Searched: Algeria data protection right to object restriction processing.

Data PortabilityRed

No evidence retrieved that Law 18-07 contains a GDPR Art 20-style data-portability right; this is treated as a likely gap pending primary-text confirmation.

Absence provenance: unavailable. Searched: Algeria data protection law data portability right.

Deadlines And Response WindowsRed

No statutory response-deadline figures for DZ subject-access or rectification requests were retrieved in this run.

Absence provenance: unavailable. Searched: Algeria data protection subject access request deadline response window.

Category narrative48 words

Francophone-model statutes of this generation (which appear to have shaped 18-07) typically grant rights of access, rectification, and objection; an explicit GDPR-style erasure/portability right is less consistently present in this legislative family. No primary-source confirmation of DZ's specific rights catalogue or response-deadline windows was retrieved in this run.

Sources and claims (2)
  1. SpeculativeInternal (no external corroboration retrieved for this specific claim) — Individuals are expected to hold a right of access to personal data held about them under Law 18-07, consistent with the regional Francophone data-protection model, though the specific statutory mechanics were not independently verified in this run.observed
  2. SpeculativeInternal (no external corroboration retrieved for this specific claim) — A right to rectify inaccurate personal data is expected under Law 18-07 consistent with the regional statutory model; the presence and scope of an erasure/right-to-be-forgotten equivalent could not be independently confirmed in this run.observed

#

Regulator activity (guidance-issuing) is corroborated; underlying granular statutory obligations (DPIA/DPO/ROPA/breach-notification specifics) are not verified.

Primary frameworkLaw No. 18-07 of 10 June 2018
Supervisory authorityANPDP
Traffic-light rationale — AmberRegulator activity (guidance-issuing) is corroborated; underlying granular statutory obligations (DPIA/DPO/ROPA/breach-notification specifics) are not verified.

Sub-modules (7)

Accountability And DpiaRed

No DZ-specific DPIA trigger criteria were retrieved in this run.

Absence provenance: unavailable. Searched: Algeria data protection impact assessment DPIA requirement.

Dpo RequirementsRed

No DZ-specific DPO appointment threshold or independence-guarantee text was retrieved.

Absence provenance: unavailable. Searched: Algeria data protection officer DPO appointment requirement law.

Ropa RequirementsRed

No DZ-specific records-of-processing obligation text was retrieved.

Absence provenance: unavailable. Searched: Algeria records of processing activities requirement law 18-07.

Joint Controller ArrangementsRed

No DZ-specific joint-controller or processor-contract provisions were retrieved.

Absence provenance: unavailable. Searched: Algeria data protection joint controller processor obligations.

Security MeasuresAmber

Baseline technical/organisational security obligations are presumed to exist as a general feature of the statute; DZ-specific wording not independently verified.

Claims (1):

  • Controllers under Algeria's data-protection regime are expected to implement baseline technical and organisational security measures, consistent with ANPDP's active issuance of practical compliance recommendations to companies, although the precise statutory security standard was not independently verified in this run.

Breach NotificationRed

No confirmed statutory breach-notification timeline (to regulator or data subjects) was retrieved for DZ in this run.

Absence provenance: unavailable. Searched: Algeria data protection law breach notification requirement timeline.

Retention And DisposalRed

No DZ-specific retention-limit or disposal-duty text was retrieved.

Absence provenance: unavailable. Searched: Algeria data protection retention limit disposal personal data.

Category narrative68 words

Algeria's regime is expected to impose baseline accountability and security obligations on controllers, but specific DPIA triggers, DPO appointment thresholds, ROPA obligations, joint-controller rules, and statutory breach-notification timelines under Law 18-07 could not be independently verified from primary or secondary sources in this run. The one area with corroborated secondary-source activity is ANPDP's issuance of practical recommendations to controllers (e.g., on disclosure practices), indicating some operational accountability oversight.

Periodic update · new data 2026-09-28

Controller/Processor Duties

Law No. 25-11 is understood to codify mandatory data protection officer appointments, a five-day breach notification obligation and mandatory data protection impact assessments for controllers, a material addition to the duties previously established under Law 18-07. Read alongside ANPDP's sectoral deliberations, such as the biometric-monitoring authorisation and the special-category health-data classification, controllers now face a more codified and more actively supervised set of operational obligations than the earlier framework implied.

The five-day breach notification window in particular is a specific, dated obligation that controllers must build into incident-response processes, and its introduction alongside DPO and DPIA requirements suggests ANPDP is building out a fuller accountability regime rather than relying solely on its pre-existing declaration and authorisation powers.

Outlook

The extent to which ANPDP issues implementing guidance operationalising the DPO, DPIA and breach-notification duties, for example through model DPIA templates or DPO-qualification criteria, is the key item to watch in coming cycles.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (1)
  1. UncertainDataGuidance (OneTrust) — Controllers under Algeria's data-protection regime are expected to implement baseline technical and organisational security measures, consistent with ANPDP's active issuance of practical compliance recommendations to companies, although the precise statutory security standard was not independently verified in this run.observed

#

Underlying transfer-mechanism statutory detail is unverified (red-level gap), but the AML high-risk designation is a corroborated, materially relevant cross-border data-flow risk factor (amber).

Primary frameworkLaw No. 18-07 of 10 June 2018
Supervisory authorityANPDP
Traffic-light rationale — AmberUnderlying transfer-mechanism statutory detail is unverified (red-level gap), but the AML high-risk designation is a corroborated, materially relevant cross-border data-flow risk factor (amber).

Sub-modules (6)

Transfer MechanismsAmber

Believed to require ANPDP authorisation or a destination-country adequacy-style assessment for transfers of personal data outside Algeria, following the regional model; DZ-specific statutory text not independently verified.

Claims (1):

  • Algeria's data-protection regime is expected to condition cross-border transfers of personal data on prior authorisation from ANPDP or an assessment of the destination country's level of protection, consistent with comparable regional Francophone statutes, though the precise statutory transfer-mechanism text for DZ was not independently verified in this run.

Adequacy ReceivedRed

No evidence found that Algeria has received an adequacy decision from the EU or any other omnibus regime.

Absence provenance: unavailable. Searched: Algeria EU GDPR adequacy decision.

Adequacy GrantedRed

No evidence found that Algeria (ANPDP) has issued formal adequacy findings for other jurisdictions.

Absence provenance: unavailable. Searched: Algeria ANPDP adequacy decision third country.

Sccs And BcrsRed

No evidence retrieved of a formal SCC or BCR mechanism recognised under Algerian law.

Absence provenance: unavailable. Searched: Algeria standard contractual clauses binding corporate rules data transfer.

Transfer Impact AssessmentRed

No evidence retrieved of a formal TIA requirement under Algerian law.

Absence provenance: unavailable. Searched: Algeria transfer impact assessment data protection.

Data LocalisationAmber

Partial data-localisation tendencies (prior-authorisation-gated transfers) are plausible by regional pattern but not independently confirmed for DZ.

Claims (1):

  • Algeria was added to the EU's Delegated Regulation list of high-risk third countries for AML/CFT purposes in 2024-2025, reflecting heightened scrutiny of Algeria's data-sharing and financial-crime compliance frameworks relevant to cross-border data flows involving Algerian entities.
Category narrative98 words

Algeria's data-protection law is understood, by regional statutory pattern, to condition cross-border personal-data transfers on prior ANPDP authorisation or an assessment of the destination country's protection level, similar to other Francophone-model regimes. Separately, Algeria was added to the EU's list of high-risk third countries for AML/CFT purposes in 2024-2025 (FATF-driven), which raises the compliance stakes for any AML-related cross-border personal-data sharing even though this is a financial-crime instrument rather than a DP-specific one. Algeria has not received nor granted any DP adequacy decision from/to the EU or other omnibus regimes, and no confirmed SCC/BCR uptake evidence was found.

Periodic update · new data 2026-09-28

Cross-Border & Adequacy

Algeria's cross-border transfer regime remains authorisation-based rather than adequacy-based: controllers are understood to require ANPDP's prior written authorisation for high-risk or cross-border processing before the activity may begin, and initiating processing ahead of that authorisation is itself understood to constitute a violation. No adequacy country list has been published, meaning there is no mechanism by which a controller could rely on a pre-cleared destination country instead of seeking case-by-case authorisation, and no SCC- or BCR-equivalent instrument has been identified as an alternative pathway.

This cycle's most significant development is the signal that Law 25-11 has already triggered active ANPDP field inspections of private-sector technology companies for cross-border transfer non-compliance, with a 2026 enforcement calendar reported to be targeting medium-sized technology operators with international data dependencies, including SaaS companies and fintech platforms handling payment data. This is held at a more cautious confidence than the authorisation-regime finding itself, since it rests on a single secondary source.

Outlook

Whether ANPDP's inspection campaign converts into a published enforcement decision is the central item to watch, since it would be the first public test of how the case-by-case authorisation requirement is being enforced in practice against technology and fintech operators with cross-border data dependencies.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (2)
  1. SpeculativeInternal (no external corroboration retrieved for this specific claim) — Algeria's data-protection regime is expected to condition cross-border transfers of personal data on prior authorisation from ANPDP or an assessment of the destination country's level of protection, consistent with comparable regional Francophone statutes, though the precise statutory transfer-mechanism text for DZ was not independently verified in this run.observed
  2. ConfirmedOfficial Journal of the European Union — Algeria was added to the EU's Delegated Regulation list of high-risk third countries for AML/CFT purposes in 2024-2025, reflecting heightened scrutiny of Algeria's data-sharing and financial-crime compliance frameworks relevant to cross-border data flows involving Algerian entities.observed

#

Financial-sector overlay is materially corroborated (AML high-risk designation); other sectoral sub-modules are unverified gaps.

Primary frameworkLaw No. 18-07 of 10 June 2018; EU AML high-risk list (external, DZ-referencing)
Supervisory authorityANPDP
Traffic-light rationale — AmberFinancial-sector overlay is materially corroborated (AML high-risk designation); other sectoral sub-modules are unverified gaps.

Sub-modules (7)

Financial Sector OverlayAmber

Algeria's AML/CFT regime was found by the FATF to have not yet fully addressed identified strategic deficiencies, leading to its addition to the EU high-risk third-country list, which affects financial-sector data-sharing risk profiles.

Claims (1):

  • The European Commission concluded that Algeria has not yet fully addressed the concerns that led to its addition to the FATF's list of Jurisdictions under Increased Monitoring, and Algeria should therefore be considered a high-risk third country under EU AML/CFT rules.

Health Sector OverlayRed

No DZ-specific health-sector DP overlay was located.

Absence provenance: unavailable. Searched: Algeria health data protection sector law.

Telecoms And EprivacyRed

No DZ-specific ePrivacy/telecoms data-protection overlay was located.

Absence provenance: unavailable. Searched: Algeria telecoms eprivacy law data protection cookies.

Employment DataRed

No DZ-specific employment-data DP overlay was located.

Absence provenance: unavailable. Searched: Algeria employment data protection law.

Credit And ScoringRed

No DZ-specific credit-scoring DP overlay was located.

Absence provenance: unavailable. Searched: Algeria credit scoring data protection law.

EducationRed

No DZ-specific education-sector DP overlay was located.

Absence provenance: unavailable. Searched: Algeria education data protection law.

InsuranceRed

No DZ-specific insurance-sector DP overlay was located.

Absence provenance: unavailable. Searched: Algeria insurance data protection law.

Category narrative88 words

The most concretely corroborated sectoral signal for Algeria is financial-sector related: Algeria was placed on the EU's AML/CFT high-risk third-country list via Commission Delegated Regulation (EU) 2025/1184, following FATF plenary additions in 2024 and February 2025, reflecting unresolved deficiencies in Algeria's anti-money-laundering and counter-terrorist-financing regime. This has direct implications for financial-sector personal-data sharing (e.g., beneficial-ownership, suspicious-transaction-report data) even though it is an AML instrument rather than a DP-specific overlay. No independently verified health-sector, telecoms/ePrivacy, employment, credit-scoring, education, or insurance-specific DP overlays were located for Algeria in this run.

Periodic update · new data 2026-09-28

Sectoral Watch

ANPDP Deliberation No. 03 of 6 May 2026 is understood to authorise biometric workplace attendance-monitoring systems, subject to prior ANPDP authorisation and security and confidentiality obligations. Notably, employee consent is not required for this processing; instead the authorisation and security safeguards imposed directly on the controller serve as the lawful basis, with data retention limited to the duration of the employment relationship. This is the first workplace-biometrics-specific ANPDP deliberation captured this cycle and gives employers a concrete authorised pathway for what might otherwise be a contested processing activity given the sensitivity of biometric data.

The combination of no-consent-required processing alongside a mandatory prior-authorisation and security-obligation structure reflects a regulatory model where ANPDP retains direct oversight of higher-risk processing categories rather than relying on individual consent as the primary safeguard.

Outlook

Whether ANPDP extends comparable sector-specific deliberations to other biometric use cases, such as customer-facing biometric authentication in banking or telecoms, is the item to watch. No such extension was identified this cycle.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (1)
  1. ConfirmedOfficial Journal of the European Union — The European Commission concluded that Algeria has not yet fully addressed the concerns that led to its addition to the FATF's list of Jurisdictions under Increased Monitoring, and Algeria should therefore be considered a high-risk third country under EU AML/CFT rules.observed

#

No sourced content located for any adtech/commercial-privacy sub-module specific to Algeria.

Supervisory authorityANPDP
Traffic-light rationale — Not assessedNo sourced content located for any adtech/commercial-privacy sub-module specific to Algeria.

Sub-modules (6)

Cookies And TrackersRed

No DZ-specific cookie/tracker consent regime located.

Absence provenance: unavailable. Searched: Algeria cookie consent law tracker ePrivacy.

Dark PatternsRed

No DZ-specific dark-pattern prohibition located.

Absence provenance: unavailable. Searched: Algeria dark patterns consent law.

Opt Out SignalsRed

No DZ-specific recognition of browser-based opt-out signals located.

Absence provenance: unavailable. Searched: Algeria Global Privacy Control opt-out signal recognition.

Clean Rooms And DcrRed

No DZ-specific clean-room/data-collaboration-room rules located.

Absence provenance: unavailable. Searched: Algeria data clean room regulation.

Cross Context AdvertisingRed

No DZ-specific cross-context advertising 'sale'/'share' rule located.

Absence provenance: unavailable. Searched: Algeria cross-context advertising data sale share rule.

Direct MarketingRed

No DZ-specific direct-marketing consent/suppression regime located.

Absence provenance: unavailable. Searched: Algeria direct marketing consent suppression data protection.

Category narrative43 words

No evidence was located of an Algeria-specific cookie/tracker consent regime, dark-pattern prohibition, opt-out-signal recognition, clean-room framework, cross-context-advertising rule, or direct-marketing suppression regime distinct from the general provisions of Law 18-07. This module is emitted with explicit gaps across all sub-modules pending primary-source access.

#

No sourced content located for algorithmic/biometric/surveillance-governance sub-modules specific to Algeria.

Supervisory authorityANPDP
Traffic-light rationale — Not assessedNo sourced content located for algorithmic/biometric/surveillance-governance sub-modules specific to Algeria.

Sub-modules (6)

Profiling RestrictionsRed

No DZ-specific profiling-restriction provision located.

Absence provenance: unavailable. Searched: Algeria profiling restriction data protection law Article 22 equivalent.

Automated Decision Making TransparencyRed

No DZ-specific ADM transparency/explanation right located.

Absence provenance: unavailable. Searched: Algeria automated decision making transparency right explanation.

Ai Risk AssessmentsRed

No DZ-specific AI risk-assessment regime located.

Absence provenance: unavailable. Searched: Algeria AI risk assessment law regulation.

Biometric RegimeRed

Biometric data is plausibly covered under general sensitive-category protection, but a distinct biometric regime (facial recognition, gait, fingerprint specific rules) was not verified.

Absence provenance: unavailable. Searched: Algeria biometric data facial recognition law.

Genetic DataRed

Genetic data is plausibly covered under general sensitive-category protection; a distinct genetic-data regime was not verified.

Absence provenance: unavailable. Searched: Algeria genetic data protection law.

State Surveillance CarveoutsRed

No DZ-specific state-surveillance carve-out text or its limits were verified in this run.

Absence provenance: unavailable. Searched: Algeria state surveillance national security exemption data protection law.

Category narrative45 words

No Algeria-specific provisions on profiling restrictions, automated-decision-making transparency, AI-specific risk assessments, a distinct biometric-data regime, genetic-data regime, or codified state-surveillance carve-outs were independently verified in this run, beyond the general (unverified) presence of sensitive-category protections that may cover biometric/genetic data within Law 18-07's special-categories provisions.

no periodic updates on record for this sub-brief

#

No sourced content located for any children/vulnerable-groups sub-module specific to Algeria.

Supervisory authorityANPDP
Traffic-light rationale — Not assessedNo sourced content located for any children/vulnerable-groups sub-module specific to Algeria.

Sub-modules (5)

Age VerificationRed

No DZ-specific age-of-consent or age-verification rule located.

Absence provenance: unavailable. Searched: Algeria age of consent children data protection law.

Minor Profiling BansRed

No DZ-specific minor-profiling ban located.

Absence provenance: unavailable. Searched: Algeria minors profiling ban data protection.

Education SettingsRed

No DZ-specific education-settings DP rule located.

Absence provenance: unavailable. Searched: Algeria education data protection students.

Dependent AdultsRed

No DZ-specific dependent-adult protection rule located.

Absence provenance: unavailable. Searched: Algeria dependent adults incapacitated data protection.

Category narrative25 words

No Algeria-specific provisions on age of consent for data processing, parental-consent mechanisms, minor-profiling bans, education-setting-specific rules, or dependent-adult protections were independently verified in this run.

#

Regulator operational activity is corroborated (amber); granular penalty/funding/redress-mechanism details remain unverified (would otherwise be red).

Primary frameworkLaw No. 18-07 of 10 June 2018
Supervisory authorityANPDP
Traffic-light rationale — AmberRegulator operational activity is corroborated (amber); granular penalty/funding/redress-mechanism details remain unverified (would otherwise be red).

Sub-modules (6)

Regulator Powers And PenaltiesRed

No verified figures for ANPDP's maximum administrative/criminal penalty powers under 18-07 were retrieved in this run.

Absence provenance: unavailable. Searched: Algeria data protection law penalties fines criminal sanctions.

Enforcement Activity IndexAmber

ANPDP has issued at least two identifiable public compliance communications (a reminder of obligations under Law 18-07, and recommendations on data-disclosure practices), indicating a modest but real level of enforcement/guidance activity.

Claims (2):

  • ANPDP publicly reminded companies of their obligations under Law No. 18-07, indicating active regulator engagement with controller compliance.
  • ANPDP issued recommendations concerning the disclosure of personal data, evidencing ongoing regulatory guidance activity beyond a purely dormant statutory framework.

Regulator Funding And CapacityRed

No verified funding or headcount data for ANPDP was retrieved.

Absence provenance: unavailable. Searched: ANPDP Algeria budget staff capacity.

Collective Redress And Class ActionsRed

No verified collective-redress or class-action mechanism for DP violations was located for Algeria.

Absence provenance: unavailable. Searched: Algeria collective redress class action data protection.

Private Right Of ActionRed

No verified private-right-of-action provision for data-subject court claims was located for Algeria.

Absence provenance: unavailable. Searched: Algeria private right of action data protection court.

Recent Developments 180DAmber

Within the last 180 days, the most concretely corroborated Algeria-relevant regulatory development is the EU's confirmation (June 2025 Delegated Regulation) that Algeria remains a high-risk AML/CFT third country; no DP-specific ANPDP development within the last 180 days as of the run date (2026-08-05) was independently verified.

Claims (1):

  • The European Commission's June 2025 Delegated Regulation confirmed Algeria's continued listing as a high-risk AML/CFT third country, a recent development materially relevant to Algeria's cross-border compliance and data-sharing risk profile.
Category narrative83 words

Secondary reporting corroborates that ANPDP is operationally active, having issued reminders of obligations under Law 18-07 to companies and recommendations on disclosure practices, and that a modifying law was published in 2025. However, specific maximum-penalty figures, headcount/funding data for ANPDP, collective-redress mechanisms, and private-right-of-action provisions under Algerian law were not independently verified in this run. Separately, and outside the DP regime itself, Algeria's placement on the EU AML high-risk list (2024-2025) is a corroborated recent regulatory development relevant to Algeria's broader compliance-enforcement landscape.

Periodic update · new data 2026-09-28

Enforcement & Redress

ANPDP's administrative sanction powers are understood to include warnings, formal notices, and provisional or definitive withdrawal of authorisations, alongside fines from 20,000 to 1,000,000 dinars. Criminal sanctions of two months to five years imprisonment apply for serious violations, and Law No. 25-11 is understood to raise this ceiling further, to up to ten years imprisonment and 10,000,000 dinars for the most serious violations, a substantial strengthening of the statutory penalty architecture.

Despite this strengthened framework, as of early 2026 no publicly reported enforcement action by ANPDP had been identified, meaning the higher penalty ceiling introduced by Law 25-11 has not yet been tested through a published decision. This cycle does report, with more cautious confidence given its reliance on a single source, that Law 25-11 has already triggered active ANPDP field inspections of private-sector technology companies for cross-border transfer non-compliance, with a 2026 enforcement calendar reportedly targeting medium-sized technology operators with international data dependencies.

Outlook

The central item to watch is whether ANPDP's active 2026 inspection campaign produces a first published enforcement decision, which would test the strengthened Law 25-11 penalty ceiling in practice and provide the first concrete precedent for how the authorisation-based cross-border transfer regime is enforced.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (3)
  1. ProbableDataGuidance (OneTrust) — ANPDP publicly reminded companies of their obligations under Law No. 18-07, indicating active regulator engagement with controller compliance.observed
  2. ProbableDataGuidance (OneTrust) — ANPDP issued recommendations concerning the disclosure of personal data, evidencing ongoing regulatory guidance activity beyond a purely dormant statutory framework.observed
  3. ConfirmedOfficial Journal of the European Union — The European Commission's June 2025 Delegated Regulation confirmed Algeria's continued listing as a high-risk AML/CFT third country, a recent development materially relevant to Algeria's cross-border compliance and data-sharing risk profile.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct22.22
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Algeria
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 16 claim(s) (16 category placement(s)), 19 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Regulator existence/timeline facts (Law 18-07 enactment 2018, delayed entry into force reported August 2023, ANPDP guidance activity, 2025 amending law, and Algeria's 2024-2025 EU AML high-risk designation) rest on T3 secondary-source headlines and one T1 EU instrument (Delegated Regulation (EU) 2025/1184) — moderate-to-high confidence. All granular statutory content (lawful bases enumeration, consent standard, special-category list, DSAR deadlines, portability, DPIA/DPO/ROPA/breach-notification specifics, adtech/biometric/AI/children/PRA provisions) could not be corroborated against primary JORADP text or accessible secondary commentary in this run (dataguidance.com content was access-restricted/paywalled beyond headlines) and is therefore either omitted or carried at Uncertain/Speculative confidence with explicit absent_field_provenance. No T1 primary statutory text of Law 18-07 or its 2025 amendment was directly retrieved.

Unresolved questions (8):

  • What is the verified official URL/domain for ANPDP (Algeria's data-protection authority)?
  • What is the precise text and effective date of the 2025 law modifying Law 18-07, and what substantive changes does it make?
  • Does Law 18-07 (as amended) contain a GDPR-style data-portability right, and if so, under what conditions?
  • What are the specific statutory deadlines for controller responses to access/rectification requests under Algerian law?
  • What are ANPDP's specific maximum administrative/criminal penalty powers under Law 18-07?
  • Does Algerian law contain explicit DPIA triggers, DPO appointment thresholds, and ROPA obligations, and if so, at what thresholds?
  • Is there a codified breach-notification timeline (to ANPDP and/or data subjects) under Algerian law?
  • Does Algerian law provide for a private right of action or collective redress mechanism for data-protection violations?

Escalate to primary-source review: yes