PRIVACY POLICY

CREG WEBSITE
Last updated: 31/12/2025

This Privacy Policy explains how the Electricity and Gas Regulatory Commission (CREG) processes your personal data when you use its website creg.gov.dz and its online services (forms, contact emails, etc.).

The data controller is: Electricity and Gas Regulatory Commission (CREG), established pursuant to Law No. 02-01 of 5 February 2002.
Registered office: Section No. 04, Block No. 788, Amara Activity Zone, Cheraga, Algiers, Algeria.
Telephone: +213 28 91 03 01 / Fax: +213 28 91 03 02.

Depending on the channel, you may contact CREG via:
• General information: contact@creg.gov.dz
• Consumer information: ecoute-conso@creg.gov.dz
• Consumer appeals: recours@creg.gov.dz
Important: when you write to us, your message and contact details are processed in order to handle your request (see the “Purposes” section).

CREG processes personal data in accordance with Law No. 18-07 on the protection of natural persons in the processing of personal data, as amended and supplemented, notably by Law No. 25-11 of 24 July 2025.

4.1 Contact form (website)

When you complete a contact form, CREG may process:
• Last name
• First name
• Email
• Telephone
• Subject / message content
Source: directly from you (entered in the form).

4.2 Recruitment form (CV)

When you apply via the recruitment form (online application), CREG may process:
• Full name (last name and first name)
• Email
• Telephone
• Cover letter (to be entered)
• CV (attachment)
The “call for applications” page refers to the use of an online form to submit an application.
Warning (recommendation): avoid including unnecessary data in your CV (e.g. highly sensitive information). If you provide such data, it may be processed as part of the recruitment process.

4.3 Email contacts (general / consumer / appeals)

When you write to the published addresses, CREG may process:
• your contact details (email, last name/first name, telephone number if provided),
• the content of your message,
• any attachments, in order to respond to you and/or process your request (including consumer appeals).

4.4 Technical data (browsing and security)

When you browse the website, certain technical data may be processed (depending on the configuration):
• connection logs: IP address, date/time, pages viewed, user-agent, security events, etc. These data are used for security, diagnostics, and the proper functioning of the website.

CREG processes your data for the following purposes:
1. To respond to requests received via the contact form and ensure follow-up of exchanges.
2. To manage applications (receipt, review, exchanges, organization of interviews, creation of a talent pool where applicable).
3. To process consumer requests (listening, information, guidance) via the dedicated channel.
4. To examine consumer appeals and manage exchanges related to the procedure (including via form/electronic means).
5. To secure the website, prevent fraud/attacks, detect incidents and ensure service continuity.
6. Technical administration of the website (maintenance, support, anomaly resolution).

Depending on the nature of your action, processing may be based on:
• the performance of a task carried out in the public interest / exercise of public authority (according to CREG’s institutional role),
• the processing of your request (management of the user/consumer relationship),
• your consent (e.g. when you initiate a spontaneous application via a form, or for certain non-essential cookies if used),
• a legal obligation (e.g. retention/traceability where required),
• legitimate interest (e.g. website security, prevention of abuse), in compliance with applicable law.

Your data may be disclosed, on a need-to-know basis, to:
• the relevant internal CREG departments (reception/communication, human resources, consumer/appeals services, relevant directorate, IT),
• technical service providers (hosting, maintenance, security, messaging), acting on CREG’s instructions,
• authorized authorities/bodies where required or permitted by law (supervision, litigation, official requests).

As a matter of principle, CREG favors processing and hosting that comply with applicable legal requirements. If a transfer abroad were to occur (e.g. a technical service provider), it would be carried out in accordance with the requirements set out by the applicable regulations and, where applicable, the required formalities/guarantees.

CREG retains your data for a period proportionate to the purposes:
1. Requests via contact form / “general information” emails:
o Retention for the duration of the request processing, followed by limited archiving for up to 12 months after the last interaction (reference: “user service” – adjustable according to internal needs).
2. Consumer requests (ecoute-conso):
o Retention during examination and follow-up, followed by limited archiving for up to 24 months after closure, unless there is a specific need (litigation, traceability).
3. Consumer appeals (recours@ / appeals form):
o Retention during examination of the appeal, followed by archiving for the period necessary for traceability and the management of any litigation, which may extend beyond this if required by the applicable archiving rules or the defense of rights.
4. Applications (recruitment – CV):
o If the application is not accepted: retention for up to 12 months from the last contact, in order to be able to contact the candidate again if appropriate (unless the candidate objects).
o If the application is accepted: the relevant data are transferred to the HR file and follow the applicable HR retention periods.
5. Technical and security logs:
o Retention generally for 6 to 12 months (or longer in the event of a security incident requiring evidentiary retention), according to security and audit needs.
These periods are indicative and may be adapted according to legal/archival obligations and litigation management.

CREG implements appropriate technical and organizational measures to protect your data, including:
• access control (authorizations),
• traceability,
• network and application security measures,
• backup and restoration procedures,
• awareness/confidentiality of authorized persons, in order to reduce the risks of unauthorized access, disclosure, alteration or loss.

The website uses only cookies that are strictly necessary for its operation, security and language management. These cookies do not require the user’s consent to be collected.

In accordance with applicable law, you may exercise (subject to the conditions provided) the following rights:
• right to information,
• right of access,
• right to rectification, updating, erasure or blocking of your data (within legal limits),
• right to object (where applicable),

For any request relating to your data (rights, questions, complaints), you may write to CREG via the email address dpo@creg.gov.dz, specifying:
• subject: “Data Protection – Exercise of Rights”,
• your contact details,
• and any information enabling identification of the processing concerned (e.g. “contact form”, “application”, “appeal”).
CREG may request proof of identity only if necessary to prevent unauthorized access to your data.

The website may contain links to external websites. CREG is not responsible for the privacy practices of these websites. We invite you to consult their privacy policies.

This Policy may be updated to reflect changes to the website, services, or legal framework. The “Last updated” date indicates the version in force.