Algeria's Law 18-07: designing biometric KYC around evidence, not a consent screen
A practical map of purpose, biometric artifacts, formalities, vendors, transfers, retention and the 2025 amendments for Algerian KYC.
“The selfie is deleted after one month” does not make biometric KYC lawful. First the organisation has to explain why it captures the image, what it derives from it, which basis and formality apply, who receives each result and why it cannot reach the goal with less data. Retention is one line in a much larger evidence file.
In Algeria, that file must use Law No. 18-07 together with the amending Law No. 25-11 of 24 July 2025. The amendment added an explicit biometric-data definition and governance elements including processing records, a data-protection delegate and impact assessment for likely high-risk uses of new technologies.
Seven questions before the first biometric session

Question | Evidence to retain |
|---|---|
Purpose | Defined action and prohibited secondary uses |
Data | Images, templates, scores, metadata and logs |
Basis | Statutory basis, consent or another applicable condition |
Formality | Declaration, authorisation or documented exception |
Parties | Controller, processor, recipients and access roles |
Lifecycle | Retention, deletion trigger, backups and proof |
Transfer | Country, recipient, basis and ANPDP decision where required |
Unlike a generic “compliant” status, this map ties every conclusion to an actual data flow and product version.
A face image and biometric data are not always the same object
Law No. 25-11 added a definition of biometric data to Article 3: personal data resulting from specific technical processing of physical, physiological or behavioural characteristics that allows or confirms unique identification.
Inventory every object the system produces: the original selfie or video frames, the aligned face image, the computed representation or template, the similarity score, liveness and attack signals, the final decision and technical logs. Each can have its own purpose, recipient and deletion trigger. If you delete the selfie but keep a template and diagnostic frames indefinitely, you have not deleted the biometric set.
“Biometric” and “sensitive” require careful legal qualification
The original Article 3 of Law No. 18-07 includes biometric characteristics in the broad definition of personal data. Its separate list of données sensibles names racial or ethnic origin, political opinions, beliefs, union membership, health and genetic data. The 2025 amendment adds a standalone biometric definition. That alone does not justify rewriting every rule as if the two labels were automatically identical.
A narrower conclusion is safer. Biometric data fall within the personal-data framework, and the basis, formality and authorisation for a particular operation depend on the actual use and the current ANPDP position. This article does not claim that every face frame always follows one universal regime.
Purpose constrains reuse
Article 7 of Law No. 18-07 states the general express-consent rule and lists circumstances in which consent is not required. You cannot bolt consent onto every flow mechanically, and it does not authorise every later use either.
One session may bind a presenter to a document, detect a presentation attack, prevent duplicate enrolment, authenticate an existing customer and produce data that look attractive for model training. Training does not automatically inherit the KYC basis. It needs its own analysis of purpose, dataset, minimisation, formality, notice, retention and opt-out.
Declaration, authorisation and exception are different outcomes
The law sets prior formalities and lets the national authority place a processing operation under prior authorisation when the declared operation presents manifest dangers to privacy or fundamental rights and freedoms. The name of the technology alone does not tell you which route applies.
Before launch, retain the flow description, data and subject categories, recipients and processors, notice and basis evidence, selected formality or reasoned exception, and the number, date and scope of an ANPDP decision where applicable. Any change in model, vendor, purpose or processing country can require a new assessment.
The 2025 amendment raises the governance standard
Law No. 25-11 added a record of processing activities containing purposes and legal basis, subject and data categories, recipients, intended erasure periods where possible and general security measures. It also added the data-protection delegate and advisory, monitoring and authority-contact duties.
New Article 45 bis 6 requires an impact study before processing likely to create high risks to rights and freedoms, particularly through new technologies. The study describes operations, assesses risk and records measures, safeguards and mechanisms for demonstrating compliance.
Do not assign every biometric KYC deployment to one outcome by default. Run a threshold assessment and keep it on file. It should explain why an impact study is required, or why the actual operation does not reach the statutory high-risk criterion.
A processor does not absorb the controller's responsibility
Articles 38–39 of Law No. 18-07 require technical and organisational measures appropriate to risk and data nature, sufficient processor guarantees and a written instrument binding the processor to the controller's instructions.
The contract and technical annex should identify data objects and purposes, active-processing and backup locations, subprocessors, privileged access, deletion and return, incident evidence and audit, and any prohibition on provider training without separate approval.
Biometric.Vision security information can support vendor assessment. The customer still needs its own assessment, contract and deployed architecture. Orchestrator can record versioned workflow steps; the controller selects the legal purpose and ANPDP route.
International transfer starts before the cloud region is selected
Article 44 of Law No. 18-07 ties foreign transfer to national-authority authorisation and sufficient protection, subject to the law's detailed conditions. “Hosted in region X” is where the analysis begins.
Map the core service, support access, telemetry, backups, ticketing and subprocessors. Remote access to the data or its metadata can amount to a transfer even when the primary file stays in Algeria.
Pre-launch control list
Verify the current consolidated law and applicable ANPDP decisions.
Give each artifact a purpose, owner, recipient and deletion trigger.
Do not use consent where the actual basis is different, or omit it where required.
Disable model-training reuse or assess and document it separately.
Provide a controlled exception and manual-review route.
Test deletion across active storage, diagnostics, logs and backups.
Include support and subprocessors in the transfer map.
Reassess the flow after a model, vendor, purpose or country change.
Before launch, you should be able to show why the face comparison was necessary, which data objects the system created, who could see them, which decision they affected and when the whole set stopped being needed.
Sources
Ready to strengthen your customer checks?
500 checks free every month · no card · no contract · no sales call.


