Artificial intelligence
The regional audit divisions: what an inspection asks for, in what order
An inspection begins with a list of documents, not with a visit. There are four, they are known, and nothing stops you producing them first.
The manager of a private clinic receives a letter from the authority. It mentions neither a fine nor an offence: it asks for four documents and sets a date. She has one of them, partly. The other three exist somewhere in the business, in a form nobody has ever assembled.
That is the commonest shape of an inspection, and it is also the one that prepares best, because the list does not change from one business to another. For a business that has connected an assistant or an automation to customer data, those four documents are exactly what the project should have produced along the way.
This article describes what is asked for, in what order, what each document has to contain to survive being opened, and what the regional divisions do besides inspecting. It does not give the amount of any fine, and section 9 explains why.
An inspection starts with a list, not with a visit
The image of an inspection is people arriving unannounced. That is not its usual form: the first stage is a documentary check, that is, a written request for documents with a deadline. The visit, when there is one, comes afterwards and covers what the documents left open.
That distinction changes everything you prepare. You do not prepare to answer questions put out loud; you prepare to produce documents that already exist and stand up without commentary. A document that needs a spoken explanation alongside it is an incomplete document.
It also changes who has to be ready. A documentary check is handled from a desk, by whoever keeps the documents, and not by senior management. If your business has designated a data protection officer, they are the one who handles the request, answers the authority and accompanies an on-site check if there is one.
Finally, it gives the right preparation exercise, and it is nothing like a simulation: produce the four documents on an ordinary day, without warning anybody, and time it.
What the law created on 24 July 2025
Law 25-11 of 24 July 2025, which amends and completes law 18-07 of 10 June 2018, introduces an article 27 bis creating regional divisions within the national data protection authority. The text provides for their deployment at wilaya level.
Their mandate is dual, and that is the part that goes unnoticed: inspection and audit of public and private bodies processing personal data, and support for those bodies towards compliance. The second half is a service, and almost nobody uses it.
What the deployment concretely changes is distance. An investigation run from Algiers for a business in Sétif or Tlemcen was slow and rare; divisions spread across the country bring investigation closer to the businesses covered, which makes an inspection more likely without a single substantive rule having moved.
The above describes the state of a regulation as at 21 August 2026 and does not replace a lawyer’s advice. The exact scope of the powers is read in the text, article by article, and the practical arrangements fall to implementing regulations — see section 8.
The four documents, and the order they are asked for in
There are four and they follow logically. The register of processing activities, which says what you do. The automated logs, which say what was done. The impact assessments, which say what you examined before doing it. And the breach notifications, which say what you declared when it went wrong.
The order is not administrative, it is logical, and it explains why there is no point preparing the fourth if the first is missing: each document is read in the light of the previous one. A breach notification about an activity absent from the register raises one more question than it settles.
The practical consequence is a work order. A business with three weeks ahead of it writes the register first, even incomplete, because it is the table of contents of the other three. A business that starts with the logs produces a mass of data that nothing organises.
These four documents are also the exact list of what an AI project should have produced along the way. It is the only reassuring aspect of the subject: a business that ran its project properly has nothing to prepare, it has things to gather.
The first: the register, and what makes it fail on opening
The register of processing activities describes, activity by activity, the purpose, the categories of people and data, the recipients, the retention periods, the security measures and what leaves the country. The six columns, filled in on a real case are a separate subject and a whole article; what matters here is what makes it fail on first reading.
Three things do, and none of them is a lack of detail. The first is a register that describes tools instead of activities: “CRM”, “website”, “messaging” are software, not purposes, and a register written that way does not allow a single obligation to be verified.
The second is a retention period written “as needed”. It signals that no decision was taken, and it makes the simplest check an inspection can run impossible, which is comparing a stated period against a real database.
The third is a register dated two years ago. A register is a living document; the date it was last updated is the first thing looked at, because it says whether the document describes today’s business or the one from a past audit.
The second: the logs, and the window that makes them useless
Automated logs trace operations carried out on the files: consultation, modification, deletion, with the date, the time and the person’s identity. Most tools can produce them; the inspection’s question is almost never “can you” but “since when”.
It is the retention period that decides their usefulness, and it is short by default at nearly every vendor. A log going back seven days answers no question about a file from last year, and extending it is generally a box nobody ticked.
The second point is coverage. A business switches logs on for its main application and leaves them off on the shared mailbox, the spreadsheet on the common drive, and the tool the sales team bought on its own. Those three often hold more personal data than the main application.
The check takes half an hour and needs nobody from outside: list the tools holding data about people, open the log screen on each, and note the date of the oldest line. You get coverage and window in the same pass.
The third: the impact assessment, and the date that counts
An impact assessment is carried out before a sensitive activity goes live, and it is the date that makes it an impact assessment rather than a report. One dated after the service opened describes a risk that has already either materialised or not; it can no longer do what it exists for, which is to cancel a project.
That is also what makes it uncomfortable to produce retrospectively. You cannot honestly backdate one, and the only defensible answer for an activity already running is to do it now, date it today, and accept that it is late. A late assessment honestly dated beats an absent one; a backdated one is a forgery.
The expected content amounts to few things: what the activity does, the risks to the people concerned, the measures that reduce them, and the risk that remains. That last line is almost always missing, and it is the only one that makes the document useful — a residual risk that stays high is what has to go up to management.
For an AI project it is done at the moment the architecture is decided and not after the prototype. It is also the moment it is cheapest to write, because the answers are fresh.
The fourth: incidents, including when there were none
The fourth document is the trace of data breaches and of what was done: what happened, when you knew, what you notified and when. Notification to the authority runs in days from the moment you become aware, which rules out writing the procedure on the day it is needed. In a clinic or a medical practice, where the content of a file reveals a state of health, it is the document whose absence is noticed most.
An empty incident register is not a problem, on one condition: that it exists. “Nothing has happened to us” said out loud and “here is our incident register, empty since it was opened in March” are two different statements, and only one is verifiable.
What matters more for the future than for the past is the procedure itself. It fits on a page — who calls whom, in what order, with what wording — and its value lies entirely in its being written beforehand. Improvised, it spends half the deadline deciding who decides.
One point businesses miss: the clock starts at knowledge, not at certainty. A team that spends six days establishing whether the incident is real has let the deadline run while it investigated, and investigating does not suspend it.
The division does something else too, and almost nobody uses it
The regional divisions’ mandate includes supporting bodies towards compliance, alongside inspection. That means a business can ask a question before it has a problem, and that the question is not in itself an admission.
It is counter-intuitive and it is nonetheless the simplest reading of the text: an authority whose mandate includes support has an interest in businesses asking. The opposite instinct — above all do not draw attention — produces businesses that discover their obligations during an inspection.
Declarations and authorisation requests go through the authority’s online portal, which makes the process traceable on both sides. A trace of the process is also evidence of diligence, and it beats having no file at all.
We do not claim to know each division’s practice: they are recent and their arrangements fall to implementing regulations. What we say is that the route exists, that it is written into the law, and that a business hesitating between asking and waiting is better off asking.
The implementing regulations are not out, and what that changes
At the time this article is written, the practical arrangements of the regional divisions — where they sit, on what timetable, how a mission proceeds — fall to implementing regulations that have not been published. That is a dated fact, and it is usable rather than awkward.
What it changes: there is no choreography to learn. You cannot prepare for a procedure that has not been published, and any detailed description of how a mission proceeds read somewhere today is a supposition. What is certain is the list of documents, because it follows from the substantive obligations and not from the arrangements.
What it does not change: the obligations themselves are in force. A missing implementing regulation is not a reprieve, and a business waiting for its publication before writing its register is waiting for something that suspends nothing.
The same distinction applies to a text that is not an obligation at all yet: the national artificial intelligence strategy sets a direction for the state and imposes nothing on a business, which is a different situation and one often confused with this one.
The practical consequence is to prepare the substance and ignore the form. The four documents, kept current, answer whatever procedure is published, because no procedure will ask for less than the law already requires.
The fine is not the subject, and we do not give its amount
Penalties were reinforced and graded by severity under law 25-11. We publish no scale, and the absence is deliberate: the amounts found online are those of the previous text, and carrying over a superseded ceiling would be wrong in the direction that reassures. That is the worse of the two directions.
There is a substantive reason on top of that one. An article that opens on the amount of a fine produces an avoidance decision — what do we risk, is it likely — and that decision is taken badly because it rests on an estimate nobody can make. The four documents justify themselves without it.
They justify themselves because they are asked for by parties other than the authority, and far more often. A client, a foreign partner, a tender: the register has become a commercial file document, and that demand is certain where an inspection is a probability.
If you want the scale in force, it is read in the text and discussed with a lawyer. We will tell you when a question leaves our trade, and estimating a penalty risk leaves it.
The rehearsal to run this week: forty-eight hours
Pick an ordinary day and give yourself forty-eight hours to produce the four documents, in whatever state they are in, without writing anything new. The aim is not to succeed: the aim is to measure where the time goes.
Note three things for each document. How many minutes to find where it is. How many minutes to get it out. And whether you would send it as it stands to somebody outside — the third question is the only one that counts, and it answers yes or no without discussion.
The commonest result we see is this: the first takes a day because it does not exist in that form, the second reveals that logs are off on half the tools, the third does not exist, and the fourth is a conversation somebody remembers. That is an ordinary starting point and not a failure.
The exercise has a property few compliance exercises have: it needs nobody from outside, it costs only time, and its result is directly the list of things to do, in order. If you do only one thing after this article, do that one.
What we do, and what we refuse
We run the rehearsal above with you and produce the list of gaps, document by document, with what each one needs and in what order. We switch the logs on where they are off and extend the retention window, which is a morning’s configuration work rather than a project — the gap between what is in place and what is believed to be in place often closes in the same pass.
We support you during an investigation on the technical questions: describing an architecture, explaining a flow, producing a readable log extract. That is the part where a business needs somebody who knows what the expected answer looks like.
We do not represent your business before the authority and we draft no response in your name. An answer to an inspection commits whoever signs it to the accuracy of what it describes, and it is your management or your counsel who has to answer for it. A technical supplier who drafts on your behalf puts you in the position of defending a text you did not write.
And we backdate nothing, ever, including when it is asked for and the request is understandable. A late impact assessment openly dated is an honest file with a weak point; the same one backdated is a forgery, and it turns a non-compliance into something else. If that is what is expected of us, better to know now.
Frequently asked questions
Is an inspection announced in advance?
The first stage is generally a documentary check, that is, a written request with a deadline, which is by definition announced. The arrangements for on-site missions fall to implementing regulations that were not published at the date of this article, so any precise description of how one proceeds would be a supposition. What can be prepared is the list of documents, which does not depend on the procedure.
We have never declared anything. Should we start there?
No: start with the register, because it is the table of contents of everything else and because a declaration written without it describes an activity nobody can verify. The authority’s portal is useful afterwards, and it is more useful when you know what you are declaring.
What if a document does not exist at all?
Better to say so than to produce one manufactured for the occasion. A missing document is a non-compliance that can be corrected and dated; a backdated one is something else, and it turns an administrative failing into a question of good faith. The correction timetable is what gets discussed; whether a document exists does not.
Do we need a data protection officer to answer an inspection?
The officer is the natural point of contact and is the one who handles this kind of request where there is one. Whether your business must designate one depends on the nature, volume and sensitivity of your processing rather than on your headcount, and that is a question for a lawyer with the list of your activities in front of them.
Do the regional divisions change anything for a small business?
They change no substantive obligation; they change distance and therefore frequency. An investigation run from the capital for a business inland was rare by construction, and divisions spread across the country make an inspection more likely without a single rule having moved.
Can we ask the authority for advice without drawing attention?
The divisions’ mandate includes support towards compliance alongside inspection, so the route exists and it is written into the text. We do not know each division’s practice and will not describe it on their behalf; what we observe is that the businesses discovering their obligations during an inspection are almost all the ones that never asked anything.
Where we come in
The forty-eight-hour rehearsal nearly always ends the same way: one document out, one half out, two that do not exist in that form. That is the work order, not a verdict.
- We rerun the rehearsal beside you, stopwatch in hand, and record what stalls at each step.
- We start the logging wherever it is asleep and raise its retention to a useful length.
- We hold the technical side during an investigation, down to the log extract somebody can actually read.
Nothing leaves under our signature towards the authority, and no date is moved back to tidy a file — even when the request is understandable.
Read next
The national AI strategy, translated for a small business
A strategy sets a direction; it imposes nothing on a business. Where it stands on 6 September 2026, what concerns you, and what already obliges you.What you are allowed to send to a model hosted abroad
A chatbot connected to your mailbox exports your customer file, one line at a time. Nobody around the table described it that way.The processing register, filled in on a real case
A twelve-person firm loses a tender on a document it had never heard named. Here are the six columns, filled in on a real assistant.
Let us talk about your project
A free audit, no commitment: we look at your online presence and tell you what is holding it back.