Breach notification
Loi n° 18-07 relative à la protection des personnes physiques, notification des violations de données
Loi n° 18-07 du 10 juin 2018, art. 43, telle que modifiée et complétée par la loi n° 25-11 du 24 juillet 2025, arts. 45 bis 8 et 45 bis 10Loi n° 18-07 du 10 juin 2018 and loi n° 25-11 du 24 juillet 2025, Journal officiel de la République algérienne
In force since 11 August 2023. Binds public and private bodies.
What this law does
Article 43 requires a service provider, defined at article 3 as any public or private entity offering its users the ability to communicate by computer or telecommunications system, or any other entity processing or storing computer data for that communication service or its users, to notify the ANPDP without delay when processing personal data on a public electronic communications network results in destruction, loss, alteration, disclosure of, or unauthorised access to that data, and to notify the affected individual without delay too where the breach may harm their private life, unless the ANPDP finds the provider had already implemented appropriate protective measures; every service provider must also keep an up-to-date inventory of personal data breaches and the measures taken to remedy them.
Loi n° 25-11 of 24 July 2025 inserted article 45 bis 8, which is confined, by article 45 bis's own opening line, to processing under the new Title V bis for the prevention or detection of offences, investigations, inquiries, criminal prosecutions, or the execution of sentences, carried out only by the judicial authority, a body legally empowered to investigate offences, a judicial auxiliary, or the prison administration: within that narrow scope, the controller must notify the ANPDP of a personal-data breach within five days of becoming aware of it, stating the reason for the delay if the notification is made later, and a processor must notify the controller of the breach as soon as the processor becomes aware of it.
Article 45 bis 10, in the same Title V bis, requires the controller to notify the affected individual of a breach, in clear and simple language describing its consequences, where the breach is likely to cause a high risk to their rights and freedoms.
Existing data controllers had one year from the installation of the Autorité nationale de protection des données à caractère personnel (ANPDP) to comply, which Algeria's state press agency reported took place on 11 August 2022, placing that compliance deadline on 11 August 2023.
What it requires