Skip to content
Client login

Free Audit

IT consulting & support

Personal data compliance

What you hold about your customers, where it is written down, and what leaves the country without anyone deciding so.

Law 18-07 of 10 June 2018 has protected personal data in Algeria for eight years. What changed is law 25-11 of 24 July 2025, which amends and completes it: it turns principles into documents you have to produce. A processing register, a ledger tracing access, a designated officer, a notification within five days when something leaks.

The practical consequence is less dramatic than it sounds, and more demanding. Nobody will ask whether you protect your customers’ data well: you will be asked to show it, in writing, in a specific form. A careful business with nothing written down and a careless one look very much alike on paper.

Our work starts with an inventory, not with a legal text. Where the names, phone numbers, addresses, medical files and bank statements are — in which software, on which machine, in which mailbox, at which provider. Most businesses we audit discover at least one place nobody had thought of.

We will also often tell you that compliance is not an IT project. Much of what the law asks is settled by deleting data that should never have been kept, and that is not bought: it is decided. We say so at the start, and it is not the most profitable answer for us.

What we usually find

  • You were asked for your processing register during a tender, and did not know what it was.
  • Your customer data passes through an online tool hosted elsewhere, and nobody ever looked where.
  • A former employee still has access to the sales mailbox, and you are not certain either way.
  • You want to connect an AI to your customer conversations and do not know whether you are allowed to.

What changes

  • A register that describes your business

    Your real processing activities, not a template filled in at random: purposes, data categories, recipients, retention periods, security measures, and what leaves the country.

  • A map of what goes abroad

    Every tool sending data outside Algeria, named, with exactly what it receives. It is the line almost nobody has written and the first one an inspection asks for.

  • A breach procedure that fits on one page

    Who calls whom, in what order, with what wording. The notification deadline to the authority is counted in days, which rules out inventing the procedure on the day it is needed.

What you get

  • Inventory of the data you hold

    Software, spreadsheets, mailboxes, paper files, providers. We look where nobody thinks to: exports, backups, messaging groups.

  • Writing the processing register

    The first rows written with your teams, in your own vocabulary, then the rest by you — a register kept by a supplier is a register nobody re-reads.

  • Mapping transfers outside the country

    Every outbound flow identified and documented, including the ones produced by tools you did not buy with data in mind.

  • Access and ledger review

    Who can read what, since when, and what your tools are able to record about that access. Traceability is required; it is rarely switched on.

  • Impact assessment before a sensitive project

    Before connecting an assistant, a recruitment tool or a camera to personal data. It is done before go-live, which is the whole point of it.

  • Supplier and subcontracting clauses

    What your provider must commit to in writing, read contract by contract. The responsibility stays yours even when the fault is theirs.

Is this the right fit for you?

This is for you if

  • You hold data about customers, patients, pupils or job applicants.
  • You use online tools and do not know where they host.
  • You are starting a project — assistant, CRM, application — that will touch that data.

This is not for you if

  • You want a compliance certificate. There is no such thing, and nobody can issue you one.
  • You want the register filled in without your teams being disturbed. A register written without them describes an imaginary business.
  • You do not intend to delete anything. Most useful corrections begin with a deletion.

What we commit to

  • The register is yours and readable without us

    A spreadsheet or a document, in your working language, that any provider or lawyer can pick up — including a competitor of ours.

  • We are not your data protection officer

    The role requires independence from whoever built the system. We train the person you designate; we do not take their place.

  • No legal advice in disguise

    We describe what the text asks and tell you when the question is beyond our trade. Deciding a borderline case is a lawyer’s work.

What compliance runs into here

The supervisory authority is the ANPDP, and law 25-11 of 24 July 2025 gave it regional audit divisions — so inspection moves geographically closer to the businesses it covers. Its declarations and authorisation requests go through its online portal, which makes the process traceable on both sides.

Transferring data outside the country is where nearly every project stalls. It is subject to prior authorisation, and law 25-11 additionally requires an assessment of the destination country’s level of protection. A foreign online tool connected to a customer file is a transfer, even when nobody felt they were arranging one.

Finally, data circulates here largely by messaging. Customer lists in a WhatsApp group, an export sent as an attachment to a salesperson, a spreadsheet shared from a personal account: these are processing activities, they belong in the register, and they are invisible to an audit that only looks at servers.

Frequently asked questions

Who does law 25-11 apply to?

It amends and completes law 18-07 of 10 June 2018, which covers the processing of personal data whatever the sector. The exact scope of some obligations — the designation of an officer in particular — is read in the text article by article, and that is a question for a lawyer rather than an IT provider. What we establish is the list of your processing activities: that is what makes the question answerable at all.

Is the register software we have to buy?

No. A spreadsheet is enough for a very long time, and it is what we leave in most cases. A dedicated tool earns its place when processing activities run into the dozens and change often; below that it adds a subscription and a skill to maintain for a document of a few pages.

What if our data sits with a foreign provider?

That is a transfer outside the country, subject to prior authorisation, and it stays true when the provider is well known and serious. The question is not the provider’s quality but the existence of the flow and its documentation. It is also why we map flows before discussing any architecture.

How long does compliance take?

The inventory takes a few days for a small organisation and happens while you work. What takes time afterwards is not the writing: it is deciding what to delete and closing accesses, and that depends on you rather than on us.

Is an inspection likely?

We do not know, and nobody should sell you an answer to that question. What we observe is that the register is increasingly asked for outside any inspection: by clients, in tenders, by foreign partners. That is a more concrete reason than fear of one.

Can you guarantee compliance?

No, and be wary of anyone who does. Compliance is not a state you reach: it is a set of documents kept current and decisions taken. What we can guarantee is that the register exists, that it describes your real processing, and that your teams know how to update it.

How to start

Tell us which software holds data about people, and which of it is hosted outside Algeria.

We agree an inventory. You leave with a written register and the list of what goes abroad, usable without us.

What we have written on this subject

Let us talk about your project

A free audit, no commitment: we look at your online presence and tell you what is holding it back.

  • The register is yours and readable without us
  • We are not your data protection officer
  • No legal advice in disguise

We measure how this site is used with Google Analytics, to learn which pages actually help. You can stop that measurement at any time from the footer. Cookie policy