Law / Algeria

Algeria

All 10 named instruments researched to a stage, across three of the six areas of law we track: 10 in force. As of 19 September 2026.

When they take effect10 of 10 carry a date. Earlier is before 2014.
Before 2014: 4 instruments (4 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 6 instruments (6 in force) 2024: 0 instruments 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 3
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (253 words)

Algeria's comprehensive personal-data statute is Loi n° 18-07 du 10 juin 2018 relative à la protection des personnes physiques dans le traitement des données à caractère personnel, published in the Journal officiel n° 34 of 10 June 2018 and amended and supplemented by Loi n° 25-11 du 24 juillet 2025, published in Journal officiel n° 48.

The 2018 law's own transitional clause ties full applicability to the installation of the Autorité nationale de protection des données à caractère personnel (ANPDP), which existing data controllers had one year to comply with from that date; Algeria's official state news agency reported the ANPDP's president and members installed on 11 August 2022, which would place the compliance deadline at 11 August 2023; the installation date is as reported by the state press agency.

The 2025 amendment adds a mandatory data protection officer, a restriction on decisions based solely on automated processing, a formal data protection impact assessment duty for high-risk processing, a five-day breach notification deadline to the ANPDP, and a defined category of biometric data carrying heightened security duties, while leaving the 2018 law's sensitive-data category (racial or ethnic origin, political opinions, religious or philosophical convictions, trade-union membership, and health data including genetic data) unchanged.

Enforcement combines administrative measures and fines set by the ANPDP with criminal offences carrying imprisonment and fines that vary by the provision breached, and the holder of a right under the law who claims to be harmed by its infringement may seek protective measures or reparation from the competent court.

Breach notification

Loi n° 18-07 relative à la protection des personnes physiques, notification des violations de données

Loi n° 18-07 du 10 juin 2018, art. 43, telle que modifiée et complétée par la loi n° 25-11 du 24 juillet 2025, arts. 45 bis 8 et 45 bis 10Loi n° 18-07 du 10 juin 2018 and loi n° 25-11 du 24 juillet 2025, Journal officiel de la République algérienne

In force since 11 August 2023. Binds public and private bodies.

What this law does

Article 43 requires a service provider, defined at article 3 as any public or private entity offering its users the ability to communicate by computer or telecommunications system, or any other entity processing or storing computer data for that communication service or its users, to notify the ANPDP without delay when processing personal data on a public electronic communications network results in destruction, loss, alteration, disclosure of, or unauthorised access to that data, and to notify the affected individual without delay too where the breach may harm their private life, unless the ANPDP finds the provider had already implemented appropriate protective measures; every service provider must also keep an up-to-date inventory of personal data breaches and the measures taken to remedy them.

Loi n° 25-11 of 24 July 2025 inserted article 45 bis 8, which is confined, by article 45 bis's own opening line, to processing under the new Title V bis for the prevention or detection of offences, investigations, inquiries, criminal prosecutions, or the execution of sentences, carried out only by the judicial authority, a body legally empowered to investigate offences, a judicial auxiliary, or the prison administration: within that narrow scope, the controller must notify the ANPDP of a personal-data breach within five days of becoming aware of it, stating the reason for the delay if the notification is made later, and a processor must notify the controller of the breach as soon as the processor becomes aware of it.

Article 45 bis 10, in the same Title V bis, requires the controller to notify the affected individual of a breach, in clear and simple language describing its consequences, where the breach is likely to cause a high risk to their rights and freedoms.

Existing data controllers had one year from the installation of the Autorité nationale de protection des données à caractère personnel (ANPDP) to comply, which Algeria's state press agency reported took place on 11 August 2022, placing that compliance deadline on 11 August 2023.

What it requires

Comprehensive regime

Loi n° 18-07 relative à la protection des personnes physiques dans le traitement des données à caractère personnel, modifiée et complétée par la loi n° 25-11

Loi n° 18-07 du 10 juin 2018 Journal officiel n° 34, arts. 4, 7-9 et 12, telle que modifiée et complétée par la loi n° 25-11 du 24 juillet 2025, arts. 38-39 et 41 bis à 41 bis 3Loi n° 18-07 du 10 juin 2018 and loi n° 25-11 du 24 juillet 2025, Journal officiel de la République algérienne

In force since 11 August 2023. Binds public and private bodies.

What this law does

Article 4 applies the law to automated and manual processing of personal data by public bodies and private persons, reaching a controller established outside Algeria that uses automated or non-automated means located in Algerian territory, in which case that controller must notify the ANPDP of the identity of its Algeria-based representative.

Article 7 requires the express consent of the data subject before processing, or one of a listed set of grounds when consent is not required: a legal obligation, safeguarding the data subject's vital interests, performing a contract to which they are party, a task carried out in the public interest or in the exercise of official authority, or a legitimate interest pursued by the controller or the recipient.

Article 8 conditions the processing of a child's personal data on the consent of their legal representative or the authorisation of the competent judge. Article 9 requires personal data to be processed lawfully and fairly, collected for determined, explicit and legitimate purposes, adequate, relevant and not excessive, accurate and kept up to date, and kept in a form permitting identification of the data subject no longer than the purposes for which it was collected require.

Article 12 subjects every personal-data processing operation to a prior declaration to the ANPDP or its authorisation. Article 38 requires the controller to implement technical and organisational measures appropriate to the risk presented by the processing and the nature of the data, and article 39 requires a processor to be chosen for the sufficiency of its own security guarantees, governed by a contract or legal act.

Loi n° 25-11 of 24 July 2025 inserted articles 41 bis and 41 bis 1, requiring the controller and, separately, the competent authority under Title V bis, each to designate a data protection officer chosen for their professional qualifications, who may serve more than one controller or authority given their organisational structure and size; a court is exempted from this duty when exercising its judicial functions.

Loi n° 25-11 also inserted articles 41 bis 2 and 41 bis 3, requiring the controller and the processor each to keep, respectively, a written or electronic record of processing activities and an automated log of processing operations, both to be made available to the ANPDP on request.

Loi n° 25-11 also inserted article 45 bis 6, a data protection impact assessment duty, but that article sits inside the new Title V bis, which article 45 bis confines to personal-data processing for the prevention or detection of offences, investigations, inquiries, criminal prosecutions, or the execution of sentences, carried out only by the judicial authority, a body legally empowered to investigate offences, a judicial auxiliary, or the prison administration, so it is not a general duty on an ordinary controller.

Existing data controllers had one year from the installation of the Autorité nationale de protection des données à caractère personnel (ANPDP) to comply, which Algeria's state press agency reported took place on 11 August 2022, placing that compliance deadline on 11 August 2023.

What it requires

Cross border transfer

Loi n° 18-07 relative à la protection des personnes physiques, transfert de données vers un pays étranger

Loi n° 18-07 du 10 juin 2018, arts. 44-45Loi n° 18-07 du 10 juin 2018 and loi n° 25-11 du 24 juillet 2025, Journal officiel de la République algérienne

In force since 11 August 2023. Binds public and private bodies.

What this law does

Article 44 conditions a transfer of personal data to a foreign state on the ANPDP's prior authorisation, granted only where that state ensures a sufficient level of protection for privacy and fundamental rights and freedoms with respect to the processing the data may undergo, a sufficiency the ANPDP assesses against that state's legal provisions, its applicable security measures and the processing's own characteristics, and prohibits any communication or transfer abroad that could harm public security or the State's vital interests.

Article 45 lists narrow derogations that permit a transfer to a state that does not meet those conditions: the data subject's express consent, safeguarding their life, preserving the public interest, establishing or defending a legal right, performing a contract with the data subject or pre-contractual measures at their request, a contract concluded in the data subject's interest between the controller and a third party, executing a measure of international judicial assistance, preventing, diagnosing or treating a medical condition, a bilateral or multilateral agreement to which Algeria is party, or the ANPDP's own authorisation where the processing meets article 2's conditions.

Existing data controllers had one year from the installation of the Autorité nationale de protection des données à caractère personnel (ANPDP) to comply, which Algeria's state press agency reported took place on 11 August 2022, placing that compliance deadline on 11 August 2023.

What it requires

Data subject rights

Loi n° 18-07 relative à la protection des personnes physiques, droits de la personne concernée

Loi n° 18-07 du 10 juin 2018 arts. 34-36, telle que modifiée et complétée par la loi n° 25-11 du 24 juillet 2025, art. 7 (abrogation de l'art. 11) et art. 45 bis 1Loi n° 18-07 du 10 juin 2018 and loi n° 25-11 du 24 juillet 2025, Journal officiel de la République algérienne

In force since 11 August 2023. Binds public and private bodies.

What this law does

Article 34 gives a data subject the right to obtain from the controller confirmation of whether their personal data is processed and, if so, its purposes, categories and recipients, and communication in an intelligible form of that data and of any available information on its origin.

Article 35 gives a free right to have inaccurate, incomplete or unlawfully processed data updated, rectified, erased or locked, which the controller must action within ten days of the request, and article 36 gives a right to object on legitimate grounds to processing, and specifically to processing for direct marketing purposes, though that objection right does not apply where the processing meets a legal obligation or the authorisation for the processing expressly excluded it.

Loi n° 18-07 originally gave a data subject a right, at article 11, that no judicial decision assessing their behaviour and no other decision producing legal effects against them could rest solely on automated processing evaluating aspects of their personality; article 7 of loi n° 25-11 of 24 July 2025 repealed that article, along with article 10, without enacting a replacement of general application.

The only automated-decision protection loi n° 25-11 enacted is article 45 bis 1, which restates the same rule but only for personal data processed under the new Title V bis, which article 45 bis confines to processing for the prevention or detection of offences, investigations, inquiries, criminal prosecutions, or the execution of sentences, carried out by the judicial authority, a body legally empowered to investigate offences, a judicial auxiliary, or the prison administration.

Existing data controllers had one year from the installation of the Autorité nationale de protection des données à caractère personnel (ANPDP) to comply, which Algeria's state press agency reported took place on 11 August 2022, placing that compliance deadline on 11 August 2023.

What it requires

Enforcement supervision

Loi n° 18-07 relative à la protection des personnes physiques, contrôle, sanctions et voies de recours

Loi n° 18-07 du 10 juin 2018, arts. 47, 52 et 54-74, telle que modifiée et complétée par la loi n° 25-11 du 24 juillet 2025, art. 27 bisLoi n° 18-07 du 10 juin 2018 and loi n° 25-11 du 24 juillet 2025, Journal officiel de la République algérienne

In force since 11 August 2023. Binds public and private bodies.

What this law does

Article 27 bis, inserted by loi n° 25-11 of 24 July 2025, gives the ANPDP regional units in charge of oversight and audit of the institutions and persons that process personal data.

Article 47 lets the ANPDP itself fine a controller 500,000 DA for refusing, without legitimate reason, the information, access, rectification or objection rights of articles 32, 34, 35 and 36, or for not making the notifications required by articles 4, 14 and 16, doubling on recidivism to the penalties article 64 sets. Article 52 lets the holder of a right under the law who claims to be harmed by its infringement seek protective measures or reparation from the competent court.

Articles 54 to 74 set a tiered set of criminal offences: unlawful processing that breaches the law's dignity and privacy principles under article 2 carries two to five years' imprisonment and a fine of 200,000 to 500,000 DA (art. 54); processing without a lawful basis or against a data subject's objection carries one to three years and 100,000 to 300,000 DA (art. 55); processing without the prior declaration or authorisation article 12 requires carries two to five years and 200,000 to 500,000 DA (art. 56); unauthorised access to the national register of article 28 carries one to three years and 100,000 to 300,000 DA (art. 63); a controller's unjustified refusal of a data subject's information, access, rectification or objection rights carries two months to two years and 20,000 to 200,000 DA (art. 64); breaching the security duties of articles 38 and 39, or retaining data beyond its authorised duration, carries a fine of 200,000 to 500,000 DA (art. 65); a service provider's failure to notify a breach under article 43 carries one to three years and 100,000 to 300,000 DA (art. 66); an unauthorised foreign transfer carries one to five years and 500,000 to 1,000,000 DA (art. 67); and obstructing the ANPDP's own inspections carries six months to two years and 60,000 to 200,000 DA (art. 61).

Penalties double on recidivism (art. 74), and a legal person is punished with a fine under the Penal Code's own rules for legal persons (art. 70). Existing data controllers had one year from the installation of the Autorité nationale de protection des données à caractère personnel (ANPDP) to comply, which Algeria's state press agency reported took place on 11 August 2022, placing that compliance deadline on 11 August 2023.

What it requires

Sensitive categories

Loi n° 18-07 relative à la protection des personnes physiques, catégories de données sensibles et biométriques

Loi n° 18-07 du 10 juin 2018, art. 18, telle que modifiée et complétée par la loi n° 25-11 du 24 juillet 2025, arts. 3 et 45 bis 7Loi n° 18-07 du 10 juin 2018 and loi n° 25-11 du 24 juillet 2025, Journal officiel de la République algérienne

In force since 11 August 2023. Binds public and private bodies.

What this law does

Article 18 prohibits processing sensitive data, defined at article 3 as data revealing racial or ethnic origin, political opinions, religious or philosophical convictions or trade-union membership, or relating to health including genetic data; that list was left unchanged by loi n° 25-11.

The prohibition lifts only for a public-interest reason indispensable to the controller's legal or statutory functions, the data subject's express consent, a legal provision authorising it, or the ANPDP's own authorisation, and article 18 separately authorises the processing of sensitive data to defend a person's vital interests where they cannot consent, by a non-profit political, philosophical, religious or trade-union body confined to its own members, over data manifestly made public by the data subject, to establish or defend a legal claim, or of genetic data by a doctor or biologist for preventive medicine, diagnosis or care.

Loi n° 25-11 of 24 July 2025 defined biometric data at article 3 as personal data resulting from specific technical processing relating to a natural person's physical, physiological or behavioural characteristics that allow or confirm their unique identification, but did not add biometric data to article 18's sensitive-data list.

The only operative duty loi n° 25-11 attaches to biometric data is article 45 bis 7, which requires the controller or processor to put in place technical and organisational measures giving an appropriate level of protection for processing of sensitive and biometric data.

That article sits inside the new Title V bis Chapter 4, which article 45 bis confines to personal-data processing for the prevention or detection of offences, investigations, inquiries, criminal prosecutions, or the execution of sentences, carried out only by the judicial authority, a body legally empowered to investigate offences, a judicial auxiliary, or the prison administration.

Existing data controllers had one year from the installation of the Autorité nationale de protection des données à caractère personnel (ANPDP) to comply, which Algeria's state press agency reported took place on 11 August 2022, placing that compliance deadline on 11 August 2023.

What it requires

Scraping law3 instruments, 3 in force

Research summary (245 words)

Algeria's computer-misuse authority sits in the Penal Code (ordonnance n° 66-156 du 8 juin 1966), articles 394 bis to 394 noniès, inserted by loi n° 04-15 du 10 novembre 2004: fraudulently accessing or remaining in an automated data-processing system is an offence whether or not the system is behind a technical protection measure, so a public, unauthenticated page is not carved out by the text.

Loi n° 09-04 du 5 août 2009 supplies the investigative and procedural framework around the same offences, including obligations on internet service providers to remove or block illicit content and to cooperate with judicial authorities, with its own penalty for a provider's non-compliance. No statute or reported case addresses terms-of-service enforceability, or whether login or acceptance of terms changes the legal picture; this is unsettled rather than a specific regime.

Copyright protects a database only as a compilation, never through a separate sui generis right: ordonnance n° 03-05 du 19 juillet 2003 protects a collection of works or data as an original creation only where the choice or arrangement of its contents is itself original, and its private-use exception expressly excludes the digital-form reproduction of a database.

The same ordinance's quotation exception permits a citation or borrowing from a work in another work where it conforms to loyal use for information or demonstration and names the author and source. No text-and-data-mining exception, and no AI-training-specific rule, is in force, and robots.txt carries no statutory weight one way or the other.

Computer misuse

Code pénal, atteintes aux systèmes de traitement automatisé de données

Ordonnance n° 66-156 du 8 juin 1966 portant code pénal articles 394 bis à 394 noniès, insérés par la loi n° 04-15 du 10 novembre 2004 (JO n° 71)Code pénal (ordonnance n° 66-156 du 8 juin 1966), consolidated text through loi n° 14-01 du 4 février 2014, WIPO Lex

In force since 10 November 2004. Binds public and private bodies.

What this law does

Articles 394 bis to 394 noniès of the Penal Code punish fraudulently accessing or remaining in all or part of an automated data-processing system with three months to one year of imprisonment and a fine of 50,000 to 100,000 DA, doubled where data is suppressed or modified, and raised to six months to two years and 50,000 to 150,000 DA where the system's operation is altered (art. 394 bis).

Fraudulently introducing, deleting, or modifying data in such a system carries six months to three years and 500,000 to 2,000,000 DA (art. 394 ter). Creating, researching, assembling, distributing, or marketing tools or data by which these offences can be committed, or possessing, revealing, or using data obtained through them, carries two months to three years and 1,000,000 to 5,000,000 DA (art. 394 quater).

Penalties double where the offence harms national defense or a public-law body (art. 394 quinquiès), a legal person is fined up to five times the maximum fine for a natural person (art. 394 sixiès), and participating in a group or agreement formed to prepare one or more of these offences is punished the same as the completed offence (art. 394 septiès), attempt likewise (art. 394 noniès), and art. 394 octiès provides for confiscation of the instruments and data used and closure of the site or premises involved.

What it requires

Loi n° 09-04 relative à la prévention et à la lutte contre les infractions liées aux technologies de l'information et de la communication

Loi n° 09-04 du 5 août 2009 portant règles particulières relatives à la prévention et à la lutte contre les infractions liées aux… technologies de l'information et de la communication, Journal officiel n° 47Loi n° 09-04 du 5 août 2009, Journal officiel de la République algérienne n° 47

In force since 5 August 2009. Binds public and private bodies.

What this law does

Loi n° 09-04 defines an ICT-related offence by reference to the Penal Code's automated-data-processing-system offences and any other offence committed or facilitated through a computer or electronic communications system, and sets the procedure for judicially-authorized electronic surveillance of communications in terrorism, state security, and serious computer-system-threat investigations.

Internet access providers must remove or block access to illicit content as soon as they become aware of it, directly or indirectly, and assist the competent judicial authorities; a provider's failure to comply carries six months to five years' imprisonment and a fine of 50,000 to 500,000 DA for the natural person responsible. Data gathered through surveillance may be used only for the investigation it was gathered for.

This law's obligations bind service and access providers, not a web crawler generally: art. 2(d) defines a 'fournisseur de services' as an entity offering users the means to communicate over a computer or telecommunications system, or an entity processing or storing data for that communication service or its users, which does not on its own reach an operator that only collects data from public pages it does not own.

What it requires

Database right

Ordonnance n° 03-05, protection des bases de données

Ordonnance n° 03-05 du 19 juillet 2003, art. 5 (bases de données)Ordonnance n° 03-05 du 19 juillet 2003 relative aux droits d'auteur et aux droits voisins

In force since 19 July 2003. Binds public and private bodies.

What this law does

Ordonnance n° 03-05 relative aux droits d'auteur et aux droits voisins protects a database as an original composite work only where the choice or arrangement of its contents constitutes an original creation, the same standard it applies to a collection or anthology of works; Algeria has no separate sui generis database right. Its private-use exception, which otherwise allows a single copy for personal or family use, expressly excludes the digital-form reproduction of a database. Reproducing or communicating a protected work or database without authorization is punishable as contrefaçon.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (149 words)

Algeria has no press-publisher neighbouring right and no compelled platform-to-publisher bargaining regime; the general copyright framework of ordonnance n° 03-05 du 19 juillet 2003 relative aux droits d'auteur et aux droits voisins is the only law reaching an aggregator's reproduction of news content.

Its quotation exception permits citing or borrowing from a work in another work where the use conforms to loyal use for information or demonstration and the author and source are named, which reaches a short excerpt or headline used this way but not a systematic or wholesale reproduction. No reported case or statute addresses hyperlinking or framing specifically, and no text-and-data-mining exception or machine-readable opt-out mechanism is in force; the ordinance predates that concept.

A database of headlines or articles is protected only as an original compilation, never through a separate sui generis right, so an unoriginal, purely factual aggregation is not itself protected against reproduction.

Snippet reproduction

Ordonnance n° 03-05, exception de citation

Ordonnance n° 03-05 du 19 juillet 2003, art. 41-42 (citations)Ordonnance n° 03-05 du 19 juillet 2003 relative aux droits d'auteur et aux droits voisins

In force since 19 July 2003. Binds public and private bodies.

What this law does

A citation or borrowing from a published work in another work is licit under ordonnance n° 03-05 where it conforms to loyal use for information or demonstration purposes, provided the author's name and the source are always given. A single-copy private reproduction of a work is otherwise licit for personal or family use, but that exception does not cover a digital-form database reproduction.

Reproducing or communicating a protected work without authorization outside these exceptions is punishable as contrefaçon.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.