Skip to content
Client login

Free Audit

Artificial intelligence

The processing register, filled in on a real case

A twelve-person firm loses a tender on a document it had never heard named. Here are the six columns, filled in on a real assistant.

Published on 19 August 2026 — Algeria Agency

A twelve-person company in Algiers answers a foreign group’s tender. Everything goes well until the line “provide your register of processing activities”. Nobody in the room knows what that is; the file goes in without it, and is set aside on a missing document rather than on its price.

The register has become the entry document of Algerian compliance, and it is also what makes an artificial intelligence project describable: as long as a business cannot say where its data is, it cannot decide what it is entitled to do with it.

This article gives the six columns and fills them end to end on one case — a support assistant connected to a shop’s messaging. It does not cover the decision to send that data abroad or not: what is allowed to leave your servers is a separate question, and it comes after this one.

What the law asks, and since what date

Law 18-07 of 10 June 2018, amended and completed by law 25-11 of 24 July 2025 published in Journal officiel no. 48, turns principles into documents you have to produce. The register of processing activities is the first: it describes, activity by activity, the purpose, the categories of people and data, the recipients, the retention periods, the security measures and what leaves the country.

Two further obligations accompany it and are better understood beside it. A ledger tracing operations carried out on the files — who consulted, modified or deleted what, and when. And notification to the supervisory authority within five days of becoming aware of a breach.

The register is not public. It is kept by the business and shown to the authority when asked for, which completely changes its useful form: it is not a communication document, it is a working document that has to be accurate rather than elegant.

The above describes the state of a regulation as at 21 August 2026 and does not replace a lawyer’s advice. The exact scope of each obligation is read in the text, article by article, and a borderline case is settled with a lawyer rather than with an IT supplier.

A register is a map, not a formality

The way it is presented — an obligation, a document to supply — misses what it is actually for. A register answers a question a twelve-person business can almost never settle from memory: where is our customers’ data, and who has access to it.

That is why it is filled in with the teams rather than on their behalf. The salesperson knows they export the prospect list into a spreadsheet before every trade fair; the bookkeeper knows the statements arrive by email and stay in the mailbox; the storekeeper knows there is a notebook. None of those three lines is findable from a server.

The format matters less than everything else. A spreadsheet is enough for a very long time, and it is what we leave in most cases; a dedicated tool earns its place when processing activities run into the dozens and change often. Below that it adds a subscription and a skill to maintain for a document of a few pages.

The right measure of the work is the number of rows, not the number of pages. A business of this size has between eight and twenty real processing activities, and most of the effort goes into naming them rather than describing them.

Column 1 — the purpose, in a sentence the team recognises

Take the case and keep it to the end: an assistant connected to a shop’s messaging, answering delivery questions and passing the rest to a person. The purpose is written like this: “answering customers’ questions about the status and timing of their order, and passing anything that is not a delivery question to a salesperson”.

What to avoid is a statement of intent. “Improving the customer experience” is not a purpose: it is a commercial objective, and it lets nobody decide whether a specific piece of data belongs in the activity. The test is simple — the purpose must let you answer yes or no to “do we need this field”.

One purpose per activity, and one activity per purpose. If the same database also sends promotions, that is two activities and two rows, even if it is one tool. This is the point where a register starts describing the business rather than its IT.

The column is filled by asking the person who uses the tool every day, not the person who bought it. The two answers differ regularly, and the first is the true one.

Column 2 — the people, and the data about them

Two sub-columns, not one. On one side, the categories of people concerned: customers, prospects, employees, applicants, suppliers, patients, pupils. On the other, the categories of data held about them.

For our assistant, the people are customers who wrote in on the messaging channel. The data is: the identity given in the message, phone number or messaging handle, delivery address, message content, and the order history the system matches to it.

That last line is the one registers forget, because the customer did not enter it: the business added it before handling the message. A useful assistant receives a great deal of it, and everything it receives belongs in this column.

Some categories are treated separately by the law and should be spotted here rather than later: health, opinions, biometric data. In a law or accountancy practice, the question does not arise conditionally — the nature of the files makes it a sensitive activity from the first row.

Column 3 — the recipients, including the ones you did not choose

A recipient is any entity that receives the data, inside or outside. For the assistant: the sales team, the carrier when an address is passed to it, the site’s host, and the model provider that processes the message content.

The last is the one missing everywhere, and it is missing for a reason of vocabulary: nobody thinks “recipient” while writing “we use this tool”. Yet the tool receives exactly what a subcontractor receives, and responsibility for what it does with it stays with the business that collected the data.

Writing a recipient means writing a company name and not a product name. Many tools sold as complete solutions call a third party’s model, and the data then crosses two companies. The question to put to the supplier fits in a sentence: what is the name of the company that runs the model.

This column has a useful side effect: it makes visible what happens when a tool is replaced. A business that has written its recipients knows, on the day of the change, exactly which rows of the register move.

Column 4 — retention, and why “indefinitely” fails

A retention period is a number and a starting point. “Three years after the last order” is a period; “as long as necessary” is not one, and “indefinitely” is the answer that signals no decision was taken.

For the assistant, the periods are plural and that is normal: conversation content does not need keeping as long as the order history it refers to. Writing two different periods on two rows is more accurate, and easier to apply, than one period chosen to cover both.

The expensive part is not writing the period, it is getting it applied. A period written and never executed is worse than none, because it describes a business that deletes while nothing is deleted. Deciding who executes the deletion, and how often, is part of the row.

It is also the column that does the most good. Most useful compliance corrections begin with a deletion, and the retention period is what triggers one without a meeting being needed.

Column 5 — security measures, described and not promised

This column calls for verifiable facts and not adjectives. “Data is secured” says nothing; “access by named accounts, two authorised people, passwords held in a manager, daily backup tested in January” describes something somebody can go and check.

The useful content fits in four points: who has access, how that access is removed when the person leaves, where the backups are, and what is encrypted. The second point reveals the most, and it often reveals an account still open in a former employee’s name.

Consistency matters more than level. A business that writes modest measures and applies them is in a better position than one describing a complete setup nobody knows how to operate — the gap between what is in place and what is believed to be in place is exactly what gets discovered too late.

Writing this column produces a list of corrections, and that is the sign it was written well. A register whose six columns fill in without revealing anything was probably filled from a template rather than from the business.

Column 6 — what leaves the country

The column is simple to describe and it decides the most: for each activity, does the data leave Algeria, to which country, and to which company. For the assistant the answer is nearly always yes, because the model runs elsewhere.

Transfer outside the country is subject to prior authorisation from the authority, and law 25-11 adds an assessment of the level of protection offered by the destination country. The column is therefore half the file that request will require, which is the best reason to fill it carefully the first time.

An honest answer is sometimes “we do not know”. Many online tools do not announce where they host, and the question goes to the supplier rather than to the register. Writing “unknown, asked on the 12th” is more useful than a blank cell, because a blank cell will be read as a no.

This column is also the most unstable: a supplier changes hosting region without telling a customer, and nothing at the business flags it. It is one of the few rows in the register that deserves re-checking on a fixed date rather than on the occasion of a change.

The row nobody writes

On every register we see, one row is missing more often than the others: the processing carried out by the model provider itself. The business writes the activity “answering customers” and stops there, as if the tool were software installed on a machine.

What makes the row necessary is simple: the provider keeps the exchanges for a certain time, often to monitor abusive use, and that copy is accessible at their end. Their stating that they do not train their models on your data does not remove that retention, which is a separate thing.

What to note before signing fits in three items and is in the provider’s documentation: the default retention period, whether a setting exists to shorten it, and the exact name of that setting. The third is most often missing, because the feature exists and sits three screens away.

The same row applies to what employees use with no project at all. What leaves the business through a browser window is a processing activity, it has neither a contract nor a written recipient, and it belongs in the register as much as the official assistant does.

The ledger, beside the register

The register says what the business does; the ledger says what was done, row by row. It traces operations on the files — consultation, modification, deletion — with the date, the time, the person and the reason.

The good news is that most tools know how to produce it; the bad news is that almost nobody switches it on. It is a setting, not a development, and it can be checked in half an hour across every tool holding data about people.

The real difficulty is how long those logs are kept, which is often short by default. A log going back only seven days is of no use on the day a question arises about a file from last year, and extending it is generally a box to tick.

The ledger has a use that has nothing to do with an inspection: it is the only way to answer a customer asking who has looked at their file. Without it, the honest answer is that you do not know, and that answer costs more than an inspection.

The ten-minute check, to run this week

Get three people from three different trades together and ask one question: name me the data processing you do in your job. Give no definition and do not explain what an activity is — that is the point of the exercise.

Write everything down, including what sounds trivial: the spreadsheet exported before a trade fair, the messaging group where orders circulate, the shared mailbox, the notebook at reception. Do not discuss, do not sort, do not interrupt.

Then count the rows you got and compare them with what you would have answered alone before the meeting. The gap is the exact measure of what your register will not contain if you write it from your desk, and it is generally half.

The exercise takes ten minutes per person and it produces column 1 of the register — the longest to obtain and the only one nobody can sell you. The rest fills in from it, and it fills in quickly.

What we do, and what we refuse

We run the inventory with your teams and write the first rows in front of them, in your working vocabulary. The file stays with you, in a format any provider or lawyer can pick up — including a competitor of ours — and we show how a row is added, because the next one will be written without us.

We do not keep your register for you. A register kept by a supplier is a register nobody at the business re-reads, and it stops being true at the first change of tool without anybody noticing. That is a limit of method, not of means: we could do it, and it would leave you with an accurate and unusable document.

We issue no compliance certificate. There is no such thing and nobody can supply you one; what we can say is that the register exists, that it describes your real processing, and that your teams know how to update it.

And we are not your data protection officer. The role requires independence from whoever built the system, and we are that party. We train the person you designate; we do not take their place, and a supplier who accepts both roles sells you the second by cancelling the first.

Frequently asked questions

How many processing activities does a small business have?

Between eight and twenty in what we see, for an organisation of ten to fifteen people, and the number always surprises upwards. The reason is that payroll, recruitment, video surveillance and the mailing list are processing activities just as much as the customer file, and none of the four comes to mind when people think “data”.

Do we need a register if we use no artificial intelligence?

Yes: the obligation attaches to processing personal data and not to the technology used. AI does not create the obligation, it makes it visible — an assistant project is often the first occasion on which somebody asks where the data is, which is why the two subjects arrive together.

Can we start from a template found online?

As a column structure, yes, and it saves an hour. As content, no: a filled-in template describes an imaginary business, and the only serious risk with a register is that it is wrong rather than absent. A missing register is a missing document; a wrong one is an inaccurate statement.

How often does it need updating?

At every change — new tool, new activity, supplier replaced — and a full re-read once a year. The transfers column deserves separate treatment, because a host can change region with nothing at your end flagging it; it is the one row we advise re-checking on a fixed date.

Who should keep the register in a twelve-person business?

One person designated by name, who does not need to be technical: whoever handles administration does very well, because the register is a job of description and follow-up. What does not work is assigning it to a function rather than to a name, because the next row is then written by nobody.

Does the register have to be in French?

It first has to be understood by the people keeping it and readable by the authority that asks for it. We write it in the business’s working language, most often French here, and we keep the column headings stable rather than translated differently from one version to the next.

Where we come in

The three people you asked named twice as many activities as you would have listed alone. It is that gap, not the number, that says where the work starts.

  • We run the inventory interview with each trade and name the activities that come out of it.
  • We fill the six columns in front of your teams on the first three, then watch you do the fourth.
  • We check which of your tools can produce an access log, and which one was left switched off.

The register stays in your hands, and the officer’s post cannot fall to us: it assumes being able to contradict the supplier, and the supplier here is us.

Read next

Let us talk about your project

A free audit, no commitment: we look at your online presence and tell you what is holding it back.

We measure how this site is used with Google Analytics, to learn which pages actually help. You can stop that measurement at any time from the footer. Cookie policy