ANPDP declaration: guide for merchants
Last updated: October 10, 2026
Law 18-07 requires prior declaration of personal data processing to the ANPDP, and authorisation for some processing, including transfers abroad. The merchant is the controller; Wafly is the processor.
1. Controller
- Business name, legal form, trade register number, NIF, address (wilaya), legal representative, contact person.
2. Processing
- Name: "Customer loyalty program".
- Purposes: points or stamps, rewards, tiers; card information; offers to consenting customers; birthday gift; anonymised statistics.
- Basis: the customer's consent (article 7); separate consent for offers.
- Data: first name, email (optional or from Google), birthday day and month (optional), loyalty history, consents, Wallet identifiers, sign-up IP.
3. Recipients and transfers
Authorised staff; Wafly as processor; Wafly's providers. Hosting: [Nom, forme juridique et adresse de l’hébergeur en Algérie], servers in Algeria. Providers abroad (Apple (Apple Wallet), Google (Google Wallet and Sign in with Google), Resend (email) and, where used, Meta (WhatsApp) and an SMS provider) require ANPDP authorisation (article 44): state the country, data, purpose and safeguards for each.
4. Retention and security
- During membership, then 3 years after the last visit. Logs: 13 months.
- Personal PINs, paired devices, encryption, per-business isolation, signed card QR, two credits per card per day.
5. Information and rights
Customers are informed at sign-up and exercise their rights of access, rectification and objection from their customer area or with the business. Counter notice: "Data collected is processed under ANPDP declaration no. [number] for the loyalty program of [business]. You have the right of access, rectification and objection: [contact]."