Skip to content

DZ Privacy Compass v1.0.0

Latest

Choose a tag to compare

@MrTaherAmine MrTaherAmine released this 24 Aug 07:00
0a592db

DZ Privacy Compass v1.0.0

The first public release of DZ Privacy Compass is now available.

DZ Privacy Compass is an open-source Algerian Data Protection Governance & Compliance Toolkit designed to help organisations operationalise privacy governance, legal requirements, accountability, evidence, assurance, and day-to-day compliance activities around Law 18-07 and Law 25-11.

This release brings together legal mapping, processing activities, DPO operations, data-subject rights, vendors, international transfers, privacy-by-design, risks, controls, evidence, incidents, audits, reporting, and executive visibility in one self-hostable workspace.

Highlights

🇩🇿 Algerian privacy governance

v1.0.0 includes a structured legal corpus covering:

  • 104 legal provision records
  • 58 source-verified operational requirements
  • all 76 articles of Law 18-07
  • all 8 amending articles of Law 25-11
  • 359/359 mechanically source-matched extracted clauses
  • 358 independently approved interpretations
  • 1 explicitly quarantined interpretation where legal uncertainty remains

The platform deliberately separates statutory source material from operational guidance and avoids silently turning uncertain interpretation into mandatory compliance requirements.

📊 Executive dashboard

A redesigned operational dashboard provides useful visibility for DPOs, CISOs, privacy leaders, auditors, and governance teams, including:

  • compliance posture
  • assessment progress
  • open and overdue actions
  • risk distribution
  • evidence health
  • incidents
  • rights-request workload
  • vendor and transfer review status
  • privacy-by-design workload
  • recent activity and priorities

Metrics are derived from actual workspace data.

🧭 Privacy operations

DZ Privacy Compass supports:

  • processing activity registers
  • legal entities and organisational mapping
  • departments and systems
  • data assets
  • processors and subprocessors
  • vendors
  • international transfers
  • rights requests
  • incidents
  • DPO activities
  • privacy-by-design reviews
  • impact assessments
  • special-processing reviews
  • formalities and ANPDP readiness
  • risks
  • controls
  • findings
  • corrective actions
  • audits
  • evidence management

📁 Evidence Vault

Evidence handling includes:

  • controlled upload and retrieval
  • authenticated access
  • SHA-256 integrity verification
  • workspace isolation
  • permission-aware access
  • protected download workflows

Archive uploads remain intentionally restricted until hostile-archive protections are considered sufficient for broader support.

📄 Reports and exports

v1.0.0 supports reporting and portability across multiple formats, including:

  • PDF
  • HTML
  • CSV
  • JSON
  • XLSX

Representative outputs include:

  • Executive Privacy Report
  • DPO Annual Report
  • ANPDP Preparation Pack
  • Article dossiers
  • operational datasets and registers

Human-readable outputs include persistent project attribution, while machine-readable formats remain parser-safe.

🌐 Multilingual interface

DZ Privacy Compass supports:

  • 🇫🇷 French
  • 🇩🇿 Arabic
  • 🇬🇧 English

Arabic includes full RTL support.

The interface also supports:

  • Dark mode
  • Light mode
  • System theme
  • responsive desktop and laptop layouts

🔐 Secure by default

Security controls include:

  • Argon2id password hashing
  • deployment pepper
  • opaque revocable sessions
  • optional TOTP MFA
  • encrypted MFA secrets
  • one-use recovery codes
  • RBAC
  • workspace / tenant isolation
  • exact-origin CSRF enforcement
  • login throttling and lockout
  • secure response headers
  • authenticated Evidence Vault access
  • evidence integrity verification
  • permission-aware reporting and exports
  • tamper-evident operational logging
  • fail-closed runtime configuration

v1.0.0 validation

The final release passed:

  • clean locked dependency installation
  • ESLint
  • TypeScript validation
  • automated regression suite
  • production build
  • Prisma validation and generation
  • committed PostgreSQL migration deployment
  • clean PostgreSQL initialization
  • legal corpus verification
  • authentication and MFA testing
  • RBAC validation
  • tenant/workspace isolation
  • representative CRUD workflows
  • Evidence Vault upload/download integrity
  • reports and exports
  • destructive database + Evidence Vault restore
  • FR / AR / EN browser validation
  • RTL validation
  • responsive browser QA
  • Docker clean-start validation
  • dependency audit
  • SBOM generation
  • container security scanning
  • reproducible source artifact generation

A completely fresh installation was also tested from the final release ZIP on macOS using a new directory, fresh PostgreSQL instance, locked dependencies, committed migration, new administrator bootstrap, npm run local:verify, and live browser login.

Release artifact

File

dz-privacy-compass-1.0.0-source.zip

SHA-256

b6fc5c1d05dc696dcff7dcb41bd01d699c6130fc18d80d7d05d8d7d6cf797216

Verify the archive against the accompanying checksum information before deployment where integrity verification is required.

Deployment

DZ Privacy Compass is designed to be self-hosted.

The packaged architecture uses:

  • Next.js
  • React
  • TypeScript
  • Prisma
  • PostgreSQL 17
  • Docker

For production use, review the repository's deployment, security, backup, and operational documentation before exposing the application beyond localhost.

Important notice

DZ Privacy Compass is an independent open-source project.

It is:

  • not affiliated with ANPDP
  • not an Algerian Government application
  • not a certification authority
  • not a guarantee of regulatory compliance
  • not a substitute for qualified legal, privacy, cybersecurity, or regulatory advice

Organisations remain responsible for evaluating their own legal and operational circumstances.

License

DZ Privacy Compass is released under the Apache License 2.0.

See LICENSE, NOTICE, and CITATION.cff in the repository.

Created & maintained by

Taher Amine ELHOUARI

Independent vCISO · Senior Advisor · Accredited Auditor · Certified Trainer

🌐 https://www.taheramine.org/

GitHub: MrTaherAmine


Built for organisations. Designed for trust. Open for all.