Egypt
Egypt Data Privacy Laws: PDPL Law 151/2020 and the 2025 Executive Regulations
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 16 primary sources cited on this page. How we verify our legal content

Egypt's data privacy framework is governed by Law No. 151 of 2020 on the Protection of Personal Data, the country's first comprehensive data protection statute. Ministerial Decree No. 816 of 2025 activated the law's full requirements. It was issued on 1 November 2025 and took effect the following day, and it started a one-year compliance period that ends on 1 November 2026.
Quick Answer
Egypt's data protection regime is built on Law No. 151 of 2020 on the Protection of Personal Data (the PDPL), the country's first dedicated personal data protection statute. It was issued on 13 July 2020, published in Official Gazette No. 28 bis (e) on 15 July 2020, and entered into force three months from the day after publication, in mid-October 2020. It then sat largely dormant for five years, because the executive regulations needed to operationalize key provisions were never issued.
That changed on 1 November 2025, when the Minister of Communications and Information Technology issued Ministerial Decree No. 816 of 2025, promulgating the PDPL's Executive Regulations. The Regulations were published in the Official Gazette and took effect the day after publication. They introduced a mandatory licensing regime, detailed data subject rights mechanisms, cross-border transfer procedures, breach notification timelines, and Data Protection Officer requirements.
Organizations have a one-year compliance period. Article 6 of the Law's issuing articles runs it from the issuance of the Executive Regulations, which were issued on 1 November 2025, so it ends on 1 November 2026. The Decree itself took effect the following day, 2 November 2025. The PDPC has published no launch announcement for its online application portal, and as of 10 September 2026 its public site carries no application route.
Constitutional Basis for Privacy
Egypt's 2014 Constitution establishes privacy as a fundamental right. Article 57 states that private life is inviolable, safeguarded, and may not be infringed upon. The provision protects individuals from unauthorized surveillance, searches, and interference with personal communications.
Critically for data protection, Article 57 also declares that all forms of communication (including postal correspondence, electronic messages, phone calls, and telegraph communications) are inviolable and their confidentiality is guaranteed. Interception or monitoring may only occur by judicial order for a limited period under circumstances defined by law.
These constitutional protections provided the normative foundation for Law No. 151 of 2020. The PDPL translates the constitutional right to privacy into specific statutory obligations binding on public and private sector entities alike, subject to the exemptions in Article 3 of its issuing articles.
Law No. 151 of 2020: Core Framework
Scope and Territorial Reach
The PDPL applies to personal data of natural persons that is processed electronically, in whole or in part. That is the opening line of Article 1 of the issuing articles, and the Article 1 definition of processing is confined to electronic or technical operations carried out through electronic or technical media or devices. Purely manual or paper-based filing sits outside the law. The reach beyond Egypt's borders comes from Article 2 of the issuing articles, which is a criminal jurisdiction rule rather than a general scope rule. It applies the law to an Egyptian offender whether inside or outside the Republic, to a non-Egyptian resident inside it, and to a non-Egyptian outside it where the act is punishable in the country where it was committed and the data belong to Egyptians or to foreigners resident in Egypt.
That hook brings foreign companies operating digital platforms and services into scope where they process data belonging to Egyptians or to foreigners resident in Egypt.
Personal data is defined as any information relating to an identified or identifiable natural person. The law separately recognizes a category of sensitive personal data, which receives heightened protection. Sensitive categories include:
- Mental, psychological, physical, or genetic health data
- Financial data and banking details
- Religious and ideological beliefs
- Political opinions
- Security status, including criminal and judicial records
- Biometric data used for identification
Children's data is sensitive personal data in every case under the Article 1 definition, whatever the data itself contains.
Data Outside the Law's Reach
Article 3 of the issuing articles carves six categories out of the law altogether:
- Personal data kept by natural persons and processed for personal use
- Data processed to obtain official statistics, or in application of a legal provision
- Data processed exclusively for media purposes, provided it is accurate and is not used for other purposes
- Data relating to judicial seizure records, investigations and lawsuits
- Data held by the national security bodies, defined as the Presidency of the Republic, the Ministry of Defence, the Ministry of Interior, the General Intelligence Service and the Administrative Control Authority. Those bodies may also require a controller or processor to amend, erase, withhold or stop circulating personal data on national security grounds within a set time, and the direction must be carried out
- Data held by the Central Bank of Egypt and the entities under its supervision, other than money transfer and exchange companies, which instead follow the Central Bank's own rules on personal data
Legal Bases for Processing
The PDPL recognizes several lawful bases that justify the processing of personal data:
Consent is the primary basis and is subject to strict requirements. Consent must be explicit, specific to the stated purpose, freely given, informed, and documented. Controllers must inform data subjects of the purpose of collection, the categories of data being processed, the identity of the controller, and the rights available to them. Consent may be withdrawn at any time. Once withdrawn, the controller must cease processing.
The Executive Regulations draw a distinction between explicit consent (required for most processing, sensitive data, and direct marketing) and a narrow category of implied consent, which applies only where processing is strictly necessary to deliver a lawful service or transaction expressly requested by the data subject.
Article 6 of the PDPL sets out four grounds, and only four, on which electronic processing is lawful:
- The data subject's consent to the processing for one or more specified purposes
- Necessity to perform a contractual obligation or legal act, to conclude a contract in the data subject's favour, or to bring or defend a legal claim
- Implementation of an obligation regulated by law, an order of a competent investigating body, or a judicial ruling
- Enabling the controller to discharge his obligations or exercise his legitimate rights, unless that conflicts with the data subject's fundamental rights and freedoms
Egypt has no equivalent of the GDPR's vital interests ground or its public interest task ground. Neither appears in Article 6.
Secondary use of data collected for one purpose for a different purpose requires renewed consent.
Sensitive Data Processing
Article 12 of the PDPL does more than tighten the consent rule. It prohibits a controller or processor from collecting, transferring, storing, keeping, processing or making available sensitive personal data except under a licence from the PDPC. On top of that licence, written and explicit consent from the data subject is required unless the case is one the law itself authorizes, and where the data belongs to a child the guardian's consent is required as well.
Egypt does not carry over the GDPR's exemptions for employment law obligations, vital interests, public health or legal proceedings. There is no route to processing health, biometric, financial, religious, political or children's data without the PDPC licence.
Sensitive data processing must still comply with the data minimization, purpose limitation, and security requirements of the PDPL.
Data Subject Rights
Article 2 of the PDPL grants data subjects six rights: to know of and access or obtain their data; to withdraw a prior consent to its retention or processing; to correct, amend, erase, add to or update it; to restrict processing to a defined scope; to know of any breach of their data; and to object to the processing or its results where it conflicts with their fundamental rights and freedoms. Related routes sit elsewhere in the Law, including complaints to the PDPC under Article 33 and compensation under Article 35.
Two limits have no GDPR counterpart. Egypt gives no right to data portability. And apart from breach notification, the data subject pays the cost of the service the controller or processor provides in exercising a right, at an amount the PDPC fixes by decision and capped at EGP 20,000 (Article 2, final paragraph).
Controllers must establish PDPC-approved mechanisms for exercising these rights, and Article 32 requires the holder, controller or processor to reply to a rights request within six working days. Article 10(3) applies the same six working days to a request to make personal data available, and there silence counts as a refusal. In practice the rights work out as follows:
Right to be informed: Controllers must provide clear, transparent notice at the point of collection, including the identity of the controller, purpose of processing, categories of data collected, retention periods, the rights available, and whether data will be transferred internationally.
Right of access: Data subjects may request confirmation of whether their data is being processed and may obtain a copy.
Right to rectification: Individuals may request correction of inaccurate or incomplete personal data.
Right to erasure: Data subjects may request deletion of their data upon expiry of the processing purpose, withdrawal of consent, or where processing lacks a legal basis.
Right to restrict processing: Individuals may request that processing be suspended pending resolution of an accuracy dispute or a legal rights determination.
Right to object: Data subjects may object to processing not based on consent or contract, and may object to processing for direct marketing purposes at any time.
Right to withdraw consent: Consent may be revoked at any time; controllers must cease processing upon receiving a withdrawal request.
Right to lodge a complaint: Data subjects may file complaints with the PDPC, which must resolve them within 30 working days.
Right to compensation: Individuals who suffer material or moral harm from violations of the PDPL may seek civil compensation through the courts.
The Personal Data Protection Centre (PDPC)
Establishment and Authority

The Personal Data Protection Centre (PDPC) was established by Article 19 of the PDPL as an economic public authority with its own legal personality, following the Minister of Communications and Information Technology, and seated in Cairo Governorate or a neighbouring one. The statute does not describe it as independent, and Article 20 places that same Minister in the chair of its board, alongside representatives of the Ministry of Defence, the Ministry of Interior, the General Intelligence Service, the Administrative Control Authority, ITIDA and the NTRA, the Centre's chief executive, and three ministerial appointees, all for renewable three-year terms.
The Executive Regulations issued in November 2025 formally operationalized the PDPC and defined its regulatory framework.
The PDPC's powers include:
- Setting national data protection policies and technical standards
- Issuing, suspending, and revoking processing licences and permits
- Receiving and investigating data subject complaints (30 working days to decide)
- Conducting inspections of controller and processor operations
- Referring criminal violations for prosecution through the judicial officers among its staff
- Maintaining the registry of licensed Data Protection Officers
- Publishing the Executive Regulations and guidance on its official website
The PDPC website carries the Gazette text of the Law and of the Regulations, ten guidelines all dated 26 January 2026, templates and a glossary. Both the Regulations and the PDPC's Licenses and Permits Guideline describe an electronic portal through which applications, renewals and breach reports are to be filed, including a Company Journey questionnaire that works out which licence a data user needs. As of 10 September 2026 that application route is not reachable from the PDPC's public site and the PDPC has published no launch announcement for it. Its Media Center's most recent entry is dated 29 March 2026.
Licensing Regime
One of the most significant and distinctive features of Egypt's data protection framework is its mandatory pre-authorization licensing regime. Unlike the self-assessment or registration approach used in the EU, UK, or United States, Egypt requires most data controllers and data processors to obtain a PDPC licence or permit before commencing processing activities.
The Executive Regulations establish a tiered fee structure based on the volume of personal data records processed:
| Data Volume (Records) | Annual Licence Fee |
|---|---|
| 1 to 100,000 | Exempt |
| 101,000 to 200,000 | EGP 200 |
| 201,000 to 300,000 | EGP 300 |
| 301,000 to 1,000,000 | EGP 400 to EGP 1,000 (tiered) |
| 1,000,001 to 2,000,000 | EGP 5,000 to EGP 50,000 (tiered) |
| 2,000,001 to 5,000,000 | EGP 60,000 to EGP 500,000 (tiered) |
| Above 5,000,000 | EGP 666,666 per year, being the statutory maximum of EGP 2,000,000 across the three-year licence term |
Controller-only or processor-only licences receive a 50% fee reduction. A controller-processor combined licence is available for entities acting in both capacities.
Separate licences are required for:
- Cross-border data transfers (priced at 50% of the applicable controller/processor licence fee)
- Direct electronic marketing activities (10% of the controller/processor fee to market your own goods or services, 25% to market on behalf of third parties)
- Visual surveillance systems in public places (EGP 1,000 per licence every three years, or EGP 500 a year for a permit)
- Sensitive personal data, which Article 12 prohibits processing at all without a PDPC licence
A licence and a permit are different instruments, and the difference is what makes the fee ceiling readable. A licence is issued only to a juridical person and runs for three years, renewable, with the renewal application due at least three months before expiry. A permit is open to natural persons as well and runs for up to one year, renewable, with renewal due at least a month before expiry. Because a licence runs three years, the statutory EGP 2,000,000 ceiling is a three-year figure, not an annual one.
Licence applications must include detailed information about the data being processed, the security measures in place, retention periods, and the identity of the DPO.
Cross-Border Data Transfers
Prior Authorization Required
The PDPL prohibits the transfer of personal data outside Egypt without prior authorization from the PDPC. This is a hard rule: no self-certification, no standard contractual clauses alone, and no adequacy reliance without formal approval.
Before any international transfer, a controller or processor must:
- Obtain a PDPC cross-border transfer licence or permit, which the PDPC grants on its own assessment that the destination country's level of protection is adequate
- Obtain the consent of the data subject. Executive Regulations Article 16 requires it for every transfer abroad, including transfers to a destination the PDPC has already accepted as adequate
- Specify the destination country, foreign entity, data categories and volumes, security measures, storage locations, and retention periods
Adequacy Assessment
The PDPC assesses the destination country's protection level based on whether it has personal data protection legislation consistent with the principles of the PDPL, adequate technical and security measures, and legal mechanisms enabling compensation for data subjects who suffer harm.
The PDPC had published no adequacy list as of 10 September 2026. Organizations seeking transfer authorizations must address these criteria in their applications on a case-by-case basis. The PDPC has 90 days from a complete application to decide, and silence counts as a refusal.
Exceptions
Consent is never a substitute for the licence. Separately from the standing consent requirement above, Article 15 of the Law allows a transfer to a country that does not meet the required level of protection where the data subject gives explicit consent and the transfer falls within a defined statutory category:
- Medical necessity or protection of vital interests
- Performance of a contract at the data subject's request
- Defense of legal rights in judicial proceedings
- Compliance with international treaties to which Egypt is a party
All approved transfers must strictly follow the authorizations issued. Ongoing obligations require controllers to maintain equivalent protection levels throughout the data's lifecycle abroad.
Data Breach Notification
PDPC Notification
Data controllers and processors must report any personal data breach to the PDPC within 72 hours of becoming aware of it, through the PDPC's electronic portal or the hotline designated for that purpose, and must log it in a secured electronic register. Where the breach touches national security considerations, immediate reporting is required.
The breach notification must include:
- A description of the nature of the breach and the data affected
- The approximate number of records and data subjects involved
- The likely consequences of the breach
- The measures taken or proposed to address the breach
Individual Notification
There is no risk threshold. Article 7 of the Law and Article 5 of the Executive Regulations both say that in all cases the controller or processor must notify the data subject, and both start the clock at the same point: three working days from the date the breach was reported to the PDPC, not three days from the moment the organization learned of it.
Notice goes to the data subject by the contact method they nominated when their data was collected, meaning SMS, email or telephone call, and must describe the breach and the security measures taken. The PDPC publishes two templates for this notice, an initial communication and a detailed follow-up, and states that both must be provided in Arabic.
Data Protection Officer Requirements
Who Must Appoint a DPO
Under the PDPL and Executive Regulations, all legal entities processing personal data must appoint a Data Protection Officer. The DPO must be:
- Formally registered with the PDPC (in the PDPC's DPO registry)
- Publicly announced as the organization's DPO
- Independent from operational decision-making on data processing
Natural persons (sole traders and individual controllers/processors) may appoint a DPO voluntarily but are not required to do so under the same mandatory framework.
The DPO's responsibilities include monitoring compliance with the PDPL and its Regulations, handling data subject requests, advising the organization on data protection matters, acting as the primary point of contact with the PDPC, and reporting compliance issues to senior management.
DPO Qualifications
The Executive Regulations require DPOs to hold professional qualifications, relevant practical experience, and to pass exams approved by the PDPC. The PDPC has published a Data Protection Officer Guideline and a DPO Categories Guideline, both version 1.1 dated 26 January 2026, but as of 10 September 2026 it had published no examination schedule or accreditation procedure.
A foreign controller or processor with no branch or representative office in Egypt has a separate obligation under Articles 4 and 5 of the PDPL to appoint a PDPC-approved local representative, or an agent where the controller is a natural person. That representative is the PDPC's point of contact. It does not fulfil the DPO role, which Article 8 requires to be an employee inside the organization's own legal and job structure.
Failure to Appoint
Failure to appoint a registered DPO carries a fine of EGP 200,000 to EGP 2,000,000 under the PDPL's criminal penalty provisions.
Penalties and Enforcement
Criminal Penalties

Every penalty in the PDPL is criminal and is tried before the Economic Courts. They are tiered by the type and severity of the violation:
Unauthorized processing (collecting, processing, disclosing, making available or circulating electronically processed personal data outside the cases the law permits, or without the data subject's consent, Article 36 first paragraph): a fine of EGP 100,000 to EGP 1,000,000. The base offence carries no imprisonment.
Sensitive personal data violations (unauthorized collection, disclosure, circulation, or transfer of sensitive data without consent or legal basis): imprisonment of not less than three months, and/or a fine of EGP 500,000 to EGP 5,000,000.
Cross-border transfer violations (transferring personal data outside Egypt without PDPC authorization): imprisonment of not less than three months, and/or a fine of EGP 500,000 to EGP 5,000,000.
Aggravated unauthorized processing (the same act committed in exchange for a material or moral benefit, or with intent to expose the data subject to danger or harm, Article 36 second paragraph): imprisonment of not less than six months and a fine of EGP 200,000 to EGP 2,000,000, or one of those two penalties.
Processing without a licence, permit or accreditation (Article 45): a fine of EGP 500,000 to EGP 5,000,000. This is the penalty that backs the licensing regime described above.
Denial of data subject rights (refusing to honor data subject rights without lawful justification): a fine of EGP 100,000 to EGP 1,000,000.
DPO breach of duty (a data protection officer who fails the Article 9 duties): a fine of EGP 200,000 to EGP 2,000,000, reduced to EGP 50,000 to EGP 500,000 where the offence occurred as a result of the officer's negligence.
Failure of controller, processor or breach-reporting duties (Articles 4, 5 and 7, covering security measures, record-keeping, the licence requirement and the 72-hour report): fines of EGP 300,000 to EGP 3,000,000.
Marketing violations (unauthorized direct electronic marketing): fines of EGP 200,000 to EGP 2,000,000.
In all cases, the court must order publication of the sentence in two widely-circulated newspapers and on open information networks, at the convicted party's expense. Attempts to commit violations are punishable at half the prescribed penalty level, and Article 48 doubles both the minimum and the maximum of every penalty in the chapter on a repeat offence.
Civil Liability
Article 35 of the PDPL preserves the injured party's right to compensation alongside the criminal penalties, so a data subject who suffers material or moral harm from a violation may bring a civil claim. Article 47 adds two things that matter to companies: the person actually responsible for managing a juridical person is punished with the same penalties where their breach of management duties contributed to the offence and their knowledge of it is proved, and the juridical person is jointly liable for compensation adjudged where the violation was committed by one of its staff in its name and for its benefit.
What the PDPC Itself Can Do
The PDPC has no power to levy administrative fines. Every monetary penalty in the PDPL is a criminal fine imposed by a court, and Article 5 of the issuing articles gives the Economic Courts jurisdiction over offences under the law. PDPC staff designated by the Minister of Justice hold judicial officer status under Article 34 and refer offences for prosecution. Article 31 confirms the design by funding the Centre partly from a share of the fines a court adjudges.
The PDPC's own levers are regulatory rather than financial. On its own account of them, it may warn a data user and require it to stop and remedy a violation, suspend a licence or permit in whole or in part, revoke a licence or permit, publish proven violations at the violator's expense, and place a data user under technical supervision at that user's cost. Financial sanctions for breach of licence conditions are set in the licence itself under Executive Regulations Articles 21 and 41.
The PDPC had published no enforcement decisions as of 10 September 2026, and the decisions tab on its Regulations page is empty. The 1 November 2026 date marks the end of the one-year transitional compliance period.
Intersecting Laws
Anti-Cybercrime Law No. 175 of 2018
Egypt's Law No. 175 of 2018 on Anti-Cyber and Information Technology Crimes provides a complementary layer of criminal protection for personal data, operating alongside the PDPL rather than in place of it.
Article 25 of the Cybercrime Law criminalizes the unlawful disclosure or use of personal data and any conduct violating individuals' privacy without consent. Article 26 imposes enhanced penalties for using information technology to process personal data in a way that harms a person's reputation or dignity.
Service providers under the Cybercrime Law must retain system and communication logs for 180 days and cooperate with national security authorities in investigations. This intersects with the PDPL's data retention principles, requiring organizations to balance security-law retention mandates against data minimization obligations.
Telecommunications Law
Egypt's Telecommunications Law regulates the confidentiality of communications infrastructure and intersects with the PDPL where telecom service providers process subscriber personal data, including call records, location data, and billing information. Telecom sector obligations on data security, retention, and disclosure to authorities operate alongside PDPL requirements.
Children's Data
Children's data is sensitive personal data in every case, so a PDPC licence is required before any of it is processed. On top of that, the PDPL and its Executive Regulations set age-differentiated consent requirements:
Under 15 years old: Explicit written consent from the child's legal guardian is required before any personal data collection or processing. The participation of a child in a game, competition, or any other activity may not be made conditional on the submission of personal data beyond what is strictly necessary for that participation.
Ages 15 to 18: The guardian's consent is still the operative consent. Executive Regulations Article 15 requires the child or the guardian, as the case may be, to submit the guardian's consent to the collection and processing, through mechanisms the PDPC sets. Nothing in Egyptian law lets a 15 to 17 year old consent for themselves.
The Executive Regulations restrict behavioral profiling, tracking, and monitoring of children beyond what is strictly necessary for the stated purpose. Organizations developing apps, platforms, or services directed at or used by children in Egypt should implement age-verification mechanisms and build guardian-consent workflows before the 1 November 2026 deadline.
Direct Electronic Marketing
Separate Licence Required
Direct electronic marketing (including promotional emails, SMS, push notifications, and similar communications) requires a separate PDPC licence or permit on top of the standard controller/processor licence. Executive Regulations Article 29 splits it into two categories priced differently: marketing your own goods or services costs 10% of the controller/processor licence or permit fee, and marketing on behalf of third parties costs 25%. The 50% rate belongs to cross-border transfer licences under Article 27, not to marketing.
The licensing application must demonstrate that explicit, purpose-specific consent was obtained for marketing communications and that such consent is demonstrably linked to direct electronic marketing rather than bundled with other consents.
Consent and Purpose Limitation
The Executive Regulations impose strict purpose limitation on marketing data: personal data collected for direct electronic marketing purposes may not be used for any other purpose unless new, explicit consent is obtained for that secondary use.
Mandatory erasure of marketing data is required upon consent withdrawal or upon expiry of the stated purpose. Withdrawal mechanisms must be accessible through any communication channel approved by the PDPC.
Marketing intermediaries, agencies and third-party platforms used to deliver marketing communications, bear independent obligations to verify that the original controller obtained valid, documented consent before the data was shared.
Visual Surveillance in Public Places
Executive Regulations Article 31 governs CCTV and other visual surveillance in public places, and it carries operating rules, not just a fee:
- A conspicuous notice must announce that visual surveillance is in operation
- What the cameras capture may not be transferred, made available, recorded or processed outside Egypt except for reasons the law prescribes
- No processing may identify a person from the image or video using face recognition or comparable techniques, except in cases the law prescribes or with the data subject's explicit consent
- Staff operating the systems must keep the footage confidential and may not circulate or disclose any image except for legally prescribed reasons
- Recordings must be secured under procedures the PDPC issues, and the PDPC must be able to inspect the systems
Surveillance of a person's own residence, kept within its boundaries, is exempt from prior approval. Fees are EGP 1,000 per licence every three years, or EGP 500 a year for a permit.
Data Security Requirements

Controllers and processors must implement appropriate technical and organizational measures to protect personal data against unauthorized access, accidental destruction, loss, alteration, or unlawful disclosure. The measures must be proportionate to the sensitivity of the data, the risks associated with the processing, and the state of the art in available security technologies.
The Executive Regulations require that security measures address:
- Encryption and pseudonymization where appropriate
- System access controls and authentication procedures
- Logging and audit trail capabilities
- Business continuity and disaster recovery procedures
- Regular testing and evaluation of security systems
Neither the Law nor the Executive Regulations imposes a language requirement on privacy notices. The PDPC's Privacy Notice Guideline does: it says the notice must be given in Arabic as the primary language, with other languages free to be added, and must be intelligible, transparent, concise, prominent, accessible and kept accurate. That guideline is regulator guidance rather than a binding decision, but it is the PDPC's stated expectation, and the same Arabic requirement appears on its breach-notification templates.
What the Regulations themselves require is that the data subject be clearly informed of the purpose of collection before consent is taken, and told of the rights Article 2 gives them. On timing, the PDPC's guideline asks for the notice at the moment of collection where the data comes from the data subject, and within 30 days where it comes from another source, or at the first communication or before the first disclosure if that comes sooner.
AI and Emerging Technologies
Egypt's Second National AI Strategy (2025-2030), launched by President El-Sisi in January 2025, integrates data protection as a foundational requirement for responsible AI development. The strategy is built on six pillars (Governance, Technology, Data, Infrastructure, Ecosystem, and Talent) and operates alongside the PDPL's data governance framework.
The Executive Regulations include specific references to artificial intelligence and emerging technologies, requiring that AI-driven processing comply with recognized principles and that such processing not result in harm to data subjects. Controllers using AI for automated decision-making must be prepared to demonstrate that PDPC-approved mechanisms exist for data subjects to exercise their rights.
The strategy also envisions a dedicated Centre for Responsible AI as a specialized oversight body, which will likely interact with the PDPC on AI-specific data governance questions as the framework matures.
Recent Developments (2024-2026)
January 2025: National AI Strategy 2025-2030 launched. President El-Sisi launched Egypt's second National AI Strategy, emphasizing PDPL-aligned data governance as a prerequisite for responsible AI deployment across sectors.
November 2025: Executive Regulations issued. Ministerial Decree No. 816 of 2025, issued on 1 November 2025, brought the PDPL's operational framework into force after a five-year delay. The Regulations were published in the Official Gazette and entered into force the following day.
December 2025: Regulations publicly released. The full text of the Executive Regulations was published on the PDPC's website in December 2025, along with initial regulatory guidance documents.
January 2026: PDPC guidelines published. The PDPC published ten guidelines, all version 1.1 dated 26 January 2026, covering consent, lawful bases, direct electronic marketing, data protection officers and DPO categories, data users, data protection principles, records of processing activities, licences and permits, and privacy notices, together with breach notification templates.
1 November 2026: Compliance deadline. Article 6 of the Law's issuing articles runs the one-year compliance period from the issuance of the Executive Regulations on 1 November 2025, so it expires on 1 November 2026. From that date, processing without a valid PDPC licence or permit is itself an offence under Article 45, and organizations face the PDPL's criminal penalties, suspension or revocation of a licence, and civil claims for compensation.
Business Compliance Checklist
Organizations processing personal data of Egyptian residents should work through the following steps ahead of the 1 November 2026 deadline:
Data mapping: complete now
- Identify all personal data collected, stored, or shared
- Classify data by category (ordinary personal data vs. sensitive personal data)
- Document processing purposes, retention periods, and data flows
- Identify all international transfers involving Egyptian resident data
Licensing preparation
- Determine which licence categories apply (controller, processor, cross-border transfer, marketing, surveillance)
- Calculate applicable fee tiers based on record volumes
- Prepare application documentation including security measures, retention schedules, and DPO details
- Watch for the PDPC's portal launch announcement and file as soon as the application route opens
DPO appointment
- Identify and appoint a qualified DPO meeting PDPC qualification requirements
- Complete PDPC DPO registration
- Foreign controllers without local presence must appoint an approved local representative
Privacy notices and consent
- Update privacy notices to comply with PDPL requirements, in Arabic as the primary language per the PDPC's Privacy Notice Guideline
- Audit consent mechanisms to ensure consent is explicit, documented, and purpose-specific
- Build separate consent workflows for sensitive data, children's data, and direct marketing
- Implement consent withdrawal mechanisms
Breach response
- Establish a documented breach response procedure
- Ensure the 72-hour PDPC notification window can be met operationally
- Test individual notification workflows for every breach, since notice to affected data subjects is mandatory in all cases
Supplier management
- Map third-party data processors and review data processing agreements
- Confirm that marketing intermediaries hold valid consent records before sharing data
International transfers
- Identify all cross-border data flows involving Egyptian resident data
- Obtain separate PDPC cross-border transfer licences for each transfer, and capture the data subject's consent to the transfer itself
- Address destination country adequacy on a case-by-case basis in licence applications
Related Reading
For recording consent laws that intersect with privacy in Egypt, see our guide to Egypt Recording Laws.
Frequently Asked Questions
What is Egypt's main data protection law?
Egypt's primary data protection statute is Law No. 151 of 2020 on the Protection of Personal Data (PDPL). It was issued on 13 July 2020, published in Official Gazette No. 28 bis (e) on 15 July 2020, and entered into force three months from the day after publication, in mid-October 2020. It then sat largely inert until Ministerial Decree No. 816 of 2025 issued the Executive Regulations on 1 November 2025. The law covers personal data of natural persons that is processed electronically, in whole or in part, under Article 1 of the issuing articles, so purely manual or paper-based processing is outside its scope. It binds public and private entities except those Article 3 of the issuing articles excludes, notably the national security bodies and the Central Bank of Egypt and the entities under its supervision.
What are the Executive Regulations and when did they come into effect?
The Executive Regulations are the implementing rules issued under the PDPL that specify the operational details of the law, including the licensing regime, DPO requirements, breach notification timelines, cross-border transfer procedures, and fee structures. They were issued by the Minister of Communications and Information Technology under Ministerial Decree No. 816 of 2025 on 1 November 2025 and entered force the following day, ending a five-year implementation delay.
Do organizations need a licence to process personal data in Egypt?
Yes. The Executive Regulations require most data controllers and data processors to obtain a PDPC licence or permit before processing personal data. Entities processing 100,000 records or fewer are exempt from the licence fee but still need the licence or permit itself. Separate licences are required for cross-border data transfers, direct electronic marketing, and visual surveillance in public places. As of 10 September 2026 the PDPC has published no launch announcement for its licensing portal and its public site carries no application route.
What is the compliance deadline for Egypt's PDPL?
Article 6 of the Law's issuing articles gives addressees one year from the issuance of the Executive Regulations to bring their positions into line. The Regulations were issued on 1 November 2025, so the deadline is 1 November 2026. The Decree itself took effect the following day, 2 November 2025. The PDPC's Licenses and Permits Guideline confirms the one-year grace period and warns that processing after it without the required licence or permit is a violation. From that date, processing without the required licence or permit is itself an offence under Article 45, and organizations are exposed to criminal penalties before the Economic Courts, suspension or revocation of a licence, and civil claims for compensation.
What are the penalties for violating Egypt's PDPL?
Every penalty in the PDPL is criminal and is imposed by the Economic Courts, not as an administrative fine by the PDPC. Unauthorized processing of ordinary personal data carries a fine of EGP 100,000 to EGP 1,000,000, rising to imprisonment of at least six months and a fine of EGP 200,000 to EGP 2,000,000 where the act was done for a material or moral benefit or to expose the data subject to harm. Unauthorized processing of sensitive personal data and unlicensed cross-border transfers carry imprisonment of at least three months and fines of EGP 500,000 to EGP 5,000,000. Processing without a required licence, permit or accreditation carries a fine of EGP 500,000 to EGP 5,000,000. Denial of data subject rights carries EGP 100,000 to EGP 1,000,000, and failure to appoint a registered DPO EGP 200,000 to EGP 2,000,000. Both limits double on a repeat offence, and courts may order public disclosure of the conviction in newspapers and online.
Can personal data be transferred outside Egypt?
Yes, but every transfer needs two things: a separate PDPC cross-border transfer licence or permit, and the data subject's consent, which Executive Regulations Article 16 requires for all transfers abroad. The PDPC assesses whether the destination country provides adequate protection when it decides the licence. Where the destination does not meet that level, Article 15 of the Law still allows a transfer on the data subject's explicit consent for specific statutory purposes such as medical necessity, contract performance, or legal proceedings.
Who must appoint a Data Protection Officer under Egypt's PDPL?
All legal entities (companies, organizations, and public bodies) processing personal data must appoint a PDPC-registered Data Protection Officer. Article 8 requires that officer to be an employee inside the entity's own legal and job structure, entered in the PDPC's DPO register and publicly announced. A foreign controller or processor with no branch or representative office in Egypt has a separate obligation under Articles 4 and 5 to appoint a PDPC-approved local representative, or an agent if the controller is a natural person. That representative is a point of contact with the PDPC and does not fulfil the DPO role.
What is the breach notification requirement under Egypt's PDPL?
Data controllers must notify the PDPC of a personal data breach within 72 hours of becoming aware of it. Where national security considerations arise, immediate notification is required. In all cases, affected data subjects must also be notified within three working days of the date the breach was reported to the PDPC, by the contact method they nominated when their data was collected. Egyptian law sets no risk threshold for that notice. Notifications must describe the breach, the data and individuals affected, likely consequences, and the remedial steps taken.
How does Egypt's PDPL treat children's data?
Children's data is sensitive personal data in every case, so a PDPC licence is required before processing it. Children under 15 require explicit written consent from a legal guardian, on paper or electronically, before any collection or processing. For children aged 15 to 18 the guardian's consent is still what counts, and the child or the guardian may be the one to submit it, through mechanisms the PDPC sets. Processing for games, competitions, or other activities may not be conditioned on collecting more data than is strictly necessary. Behavioral profiling of children is restricted under the Executive Regulations.
Updates
Corrected against the Official Gazette texts of Law 151/2020 and Ministerial Decree 816/2025: breach notice to individuals is required in every case within three working days of the report to the PDPC, with no risk threshold; the base penalty for unauthorized processing is a fine of EGP 100,000 to EGP 1,000,000 with no imprisonment, and unlicensed processing carries EGP 500,000 to EGP 5,000,000; the PDPC has no administrative-fine power, since all fines are criminal and imposed by the Economic Courts; the licence fee above five million records is EGP 666,666 a year, not EGP 2,000,000; direct e-marketing licences cost 10 percent or 25 percent, not 50 percent; Egypt has four lawful bases and no vital-interests, public-interest or GDPR-style sensitive-data exemptions, and no right to data portability; sensitive data needs a PDPC licence; cross-border transfers need the data subject's consent as well as a licence; the law covers electronic processing only and exempts six categories including the national security bodies and the Central Bank; the compliance deadline is 1 November 2026; and an unverifiable court citation was removed. Corrected the first FAQ answer, which still said Egypt's Personal Data Protection Law was enacted in October 2020 and took effect in January 2021 and that it covered non-automated processing across all public and private bodies: the Law was issued on 13 July 2020, published in the Official Gazette on 15 July 2020 and in force in mid-October 2020, it reaches only electronically processed data, and Article 3 of its issuing articles excludes the national security bodies and the Central Bank of Egypt. Also attributed the deemed-refusal rule to Article 10(3) rather than Article 32, restated the extraterritorial reach as the Article 2 jurisdiction rule covering data of Egyptians and of foreigners resident in Egypt, derived the 1 November 2026 compliance deadline from the issuance of the Executive Regulations under issuing Article 6, put the recent-developments entries in date order, and removed a duplicate citation.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Full refresh: incorporated Ministerial Decree No. 816/2025 (the Executive Regulations), and updated the licensing fee tiers, compliance timeline, DPO registration requirements, children's data age thresholds, direct marketing licence rules, AI Strategy 2025-2030 alignment, and the penalty structure from Law 151/2020.
Reviewed and approved by an editor
Initial publication covering PDPL Law 151/2020, PDPC establishment, cross-border transfer framework, and Executive Decree 816 overview.
Sources and References
- Library of Congress - Egypt Law on Personal Data Implemented 2025(loc.gov).gov
- Library of Congress - Egypt Data Protection Law 2020(loc.gov).gov
- Law No. 151 of 2020 on the Protection of Personal Data, Official Gazette No. 28 bis (e), 15 July 2020 (PDPC copy of the Gazette text)(pdpc.gov.eg).gov
- Ministerial Decree No. 816 of 2025 issuing the Executive Regulations, al-Waqa'i al-Misriyya No. 244 supp. (A), 1 November 2025, in force 2 November 2025 (stamped Gazette scan)(pdpc.gov.eg).gov
- PDPC FAQs: commencement of the PDPL, entry into force of the Executive Regulations, the one-year compliance period, and the breach notification duties(pdpc.gov.eg).gov
- PDPC, Licenses and Permits Guidelines, version 1.1, 26 January 2026(pdpc.gov.eg).gov
- PDPC, Services: licences and permits, their types, eligibility and validity periods(pdpc.gov.eg).gov
- PDPC, Privacy Notice Guidelines, version 1.1, 26 January 2026(pdpc.gov.eg).gov
- PDPC, Personal data breach notification to data subjects: templates(pdpc.gov.eg).gov
- PDPC, Regulations: the Law, the Executive Regulations, ten published guidelines, templates and the decisions tab(pdpc.gov.eg).gov
- Official Gazette text of Law No. 151 of 2020, hosted by the Ministry of Communications and Information Technology(mcit.gov.eg).gov
- WIPO Lex Law No. 175 of 2018 Egypt Cybercrime Law(wipo.int).gov
- Digital Watch Observatory Egypt National AI Strategy 2025-2030(dig.watch)
- PDPC, Lawful Bases of Processing Guidelines, version 1.1, 26 January 2026(pdpc.gov.eg).gov
- CADE Project Egypt Activates Data Protection Law with Implementing Regulations(cadeproject.org)
- PDPC, Data Protection Officer Guidelines, version 1.1, 26 January 2026(pdpc.gov.eg).gov
- PDPC, Electronic Direct Marketing Guidelines, version 1.1, 26 January 2026(pdpc.gov.eg).gov
- PDPC, Personal data breach notification to the PDPC: template(pdpc.gov.eg).gov