Decree 25-320: data governance in Algeria
Published in the Official Journal of 30 December 2025, it establishes a national data governance framework. Here is who it covers, what it requires, and what it does not.
Presidential decree no. 25-320 of 30 December 2025 establishes a national data governance framework. It does not apply to every Algerian company: it covers public institutions and administrations, together with bodies and companies — public or private — charged with delivering a public service. For those, it requires data to be classified and catalogued before any exchange with another administration.
Published in the Journal officiel de la République algérienne no. 87 of 2025, page 4. Decree no. 25-321, dated the same day and published on page 6, separately approves the national information systems security strategy for 2025-2029.
Who is covered, and who is not?
This is the first thing to settle, and much of the commentary casts it too widely. Article 2 sets the scope: public institutions and administrations, and bodies and companies charged with a public service.
Article 3 defines the latter without ambiguity:
"Bodies and companies charged with a public service: all bodies and companies, public or private, charged by virtue of their activities with providing a public service."
In other words, private status is no exemption. The activity decides. A private company carrying out a public service mission falls within scope; an ordinary private company does not.
What does the framework consist of?
Article 5 sets out three components:
- A data classification reference — it defines sensitivity levels, fields of use, types of protection and the security measures applying to each category (article 6).
- A data source cataloguing reference — it groups and identifies sources in a unified model, to ease access and reduce duplication of the same data (article 7).
- A national interoperability system — the secure exchange framework between the entities covered (article 9).
Neither reference appears in the decree itself: both are to be published by decision of the High Commissioner for Digitisation (article 8). That is the document to read for the exact classification levels.
What has to be done in practice?
Article 12 is the most operational provision. To access the national interoperability system, every covered entity must classify the data held in its information system, then catalogue it.
Article 13 adds a rule on circulation: the data user must obtain the issuer's agreement, through the system, for the purpose that justified the request. Data obtained for one use cannot be repurposed for another.
Three bodies supervise: the national information systems security council rules on the operation of the framework (article 14), the national authority for the protection of personal data checks that the cataloguing and classification of personal data comply with the law (article 15), and the information systems security agency rules on security-level classification (article 16).
What the decree says, and what it does not
| The decree requires | The decree does not require |
|---|---|
| Classification of data by sensitivity level | A general obligation on all private companies |
| Cataloguing of sources in a unified model | A compliance timetable — this text sets none |
| The issuer's agreement before use | Penalties — this text provides for none |
| Use of the national interoperability system between administrations | A ban on hosting abroad |
Staying in the left-hand column is the only way to discuss this text without overstating it. Personal data remains governed by law 18-07, which article 4 explicitly restates.
What does it change when choosing software?
One technical point deserves close reading. Article 11 provides that the High Commission for Digitisation shall put in place the secure national interconnection infrastructure "separately from the internet network".
The consequence is concrete. An information system whose core functions depend on a foreign online service becomes hard to connect to an infrastructure that, by design, is not on the internet. A system whose processing runs on its own servers raises no such problem.
The same logic applies to classification. Software that enforces the access boundary before reading the data, and not merely at display time, maps directly onto a sensitivity-level reference. Software that knows only an "administrator" role and a "user" role will have to be reworked.
What to watch now
- The High Commissioner's decision publishing the two references: it will carry the exact levels and procedures.
- Your own status under article 3. If your activity amounts to a public service mission, the question arises — and it is one for legal counsel, not for a software supplier.
- The state of your information system: do you know today what data you hold, where it came from and who may read it? Cataloguing starts there, and that work pays off whether or not the decree covers you.
Our deployments run on the client's own servers, with no outbound network call and access boundaries enforced at engine level. How a local deployment works, and what AI genuinely changes in an Algerian company.
Updated Sept. 9, 2026