Your DPO and your compliance with Algerian law
Since Law 25-11 of July 24, 2025, which amends and supplements Law 18-07 on the protection of personal data, companies must appoint a data protection officer, keep a register of their processing activities, log operations on data and notify breaches to the ANPDP. We take on this work, from the first audit to day-to-day follow-up.
From the audit to an outsourced DPO
Compliance audit
Inventory of your processing activities, your processors and your data flows, gaps against the law and a prioritized action plan.
Outsourced DPO
We take on the role of data protection officer, or we support the one you appoint internally. Their contact details are communicated to the ANPDP.
Register of processing activities
A register kept up to date: purposes, categories of data, recipients, retention periods and security measures.
Declarations and authorizations
Preparation and follow-up of declarations and authorization requests with the National Authority for the Protection of Personal Data.
Impact assessments
Impact assessment before launching high-risk processing, and consultation of the ANPDP when the residual risk calls for it.
Data breaches
A ready-to-use procedure to notify the ANPDP within five days and inform the data subjects, with an incident register.
Access and objection requests
Response templates and an internal workflow to handle access, rectification, erasure and objection requests.
Policies and consent
Privacy policy, information notices, consent collection and a compliant cookie banner, in French and Arabic.
Awareness training
Training your teams in the right reflexes: minimal collection, file sharing, passwords, responding to an incident.
Compliance also lives in the infrastructure
Law 25-11 requires automated logging of operations on data: who viewed, modified or deleted what, and when. It is as much a technical subject as a legal one. Because we build and operate ISOGrid, we put these measures in place in your systems, not just on paper.
How we work
- Audit: interviews, inventory of processing activities and gap report.
- Compliance: register, procedures, documents, declarations and technical measures.
- Follow-up: outsourced DPO or support for your DPO, review of new processing activities, handling of requests and incidents.
Every engagement is priced on quote, according to the size of your organization and the number of processing activities.
Data protection in Algeria
Does my company have to appoint a DPO?
Since Law 25-11 of July 24, 2025, which amends and supplements Law 18-07, data controllers must appoint a data protection officer and communicate their contact details to the ANPDP. We check with you what the law requires for your business.
Can you be our DPO?
Yes. We can take on the role of outsourced DPO, or support the person you appoint internally: method, document templates, review of processing activities and assistance in exchanges with the ANPDP.
What happens in the event of a data leak?
Law 25-11 requires notifying the ANPDP within five days of discovering a breach, and informing the data subjects without delay when the risk to them is high. We prepare the procedure in advance and help you run it when the day comes.
Does the data have to be hosted in Algeria?
Transfers of personal data abroad are strictly regulated by law. Hosting your processing in Algeria, for example on ISOGrid, avoids most of these formalities. We map your data flows to spot those that leave the country.
Complementary to this one
Let's talk about your project
Write to us or call us. We answer in French, Arabic and English.