Egypt flag

Egypt

Egypt Data Privacy Laws: PDPL Law 151/2020 and the 2025 Executive Regulations

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 16 primary sources cited on this page. How we verify our legal content

Egypt Data Privacy Laws: PDPL Law 151/2020 and the 2025 Executive Regulations

Frequently Asked Questions

What is Egypt's main data protection law?

Egypt's primary data protection statute is Law No. 151 of 2020 on the Protection of Personal Data (PDPL). It was issued on 13 July 2020, published in Official Gazette No. 28 bis (e) on 15 July 2020, and entered into force three months from the day after publication, in mid-October 2020. It then sat largely inert until Ministerial Decree No. 816 of 2025 issued the Executive Regulations on 1 November 2025. The law covers personal data of natural persons that is processed electronically, in whole or in part, under Article 1 of the issuing articles, so purely manual or paper-based processing is outside its scope. It binds public and private entities except those Article 3 of the issuing articles excludes, notably the national security bodies and the Central Bank of Egypt and the entities under its supervision.

What are the Executive Regulations and when did they come into effect?

The Executive Regulations are the implementing rules issued under the PDPL that specify the operational details of the law, including the licensing regime, DPO requirements, breach notification timelines, cross-border transfer procedures, and fee structures. They were issued by the Minister of Communications and Information Technology under Ministerial Decree No. 816 of 2025 on 1 November 2025 and entered force the following day, ending a five-year implementation delay.

Do organizations need a licence to process personal data in Egypt?

Yes. The Executive Regulations require most data controllers and data processors to obtain a PDPC licence or permit before processing personal data. Entities processing 100,000 records or fewer are exempt from the licence fee but still need the licence or permit itself. Separate licences are required for cross-border data transfers, direct electronic marketing, and visual surveillance in public places. As of 10 September 2026 the PDPC has published no launch announcement for its licensing portal and its public site carries no application route.

What is the compliance deadline for Egypt's PDPL?

Article 6 of the Law's issuing articles gives addressees one year from the issuance of the Executive Regulations to bring their positions into line. The Regulations were issued on 1 November 2025, so the deadline is 1 November 2026. The Decree itself took effect the following day, 2 November 2025. The PDPC's Licenses and Permits Guideline confirms the one-year grace period and warns that processing after it without the required licence or permit is a violation. From that date, processing without the required licence or permit is itself an offence under Article 45, and organizations are exposed to criminal penalties before the Economic Courts, suspension or revocation of a licence, and civil claims for compensation.

What are the penalties for violating Egypt's PDPL?

Every penalty in the PDPL is criminal and is imposed by the Economic Courts, not as an administrative fine by the PDPC. Unauthorized processing of ordinary personal data carries a fine of EGP 100,000 to EGP 1,000,000, rising to imprisonment of at least six months and a fine of EGP 200,000 to EGP 2,000,000 where the act was done for a material or moral benefit or to expose the data subject to harm. Unauthorized processing of sensitive personal data and unlicensed cross-border transfers carry imprisonment of at least three months and fines of EGP 500,000 to EGP 5,000,000. Processing without a required licence, permit or accreditation carries a fine of EGP 500,000 to EGP 5,000,000. Denial of data subject rights carries EGP 100,000 to EGP 1,000,000, and failure to appoint a registered DPO EGP 200,000 to EGP 2,000,000. Both limits double on a repeat offence, and courts may order public disclosure of the conviction in newspapers and online.

Can personal data be transferred outside Egypt?

Yes, but every transfer needs two things: a separate PDPC cross-border transfer licence or permit, and the data subject's consent, which Executive Regulations Article 16 requires for all transfers abroad. The PDPC assesses whether the destination country provides adequate protection when it decides the licence. Where the destination does not meet that level, Article 15 of the Law still allows a transfer on the data subject's explicit consent for specific statutory purposes such as medical necessity, contract performance, or legal proceedings.

Who must appoint a Data Protection Officer under Egypt's PDPL?

All legal entities (companies, organizations, and public bodies) processing personal data must appoint a PDPC-registered Data Protection Officer. Article 8 requires that officer to be an employee inside the entity's own legal and job structure, entered in the PDPC's DPO register and publicly announced. A foreign controller or processor with no branch or representative office in Egypt has a separate obligation under Articles 4 and 5 to appoint a PDPC-approved local representative, or an agent if the controller is a natural person. That representative is a point of contact with the PDPC and does not fulfil the DPO role.

What is the breach notification requirement under Egypt's PDPL?

Data controllers must notify the PDPC of a personal data breach within 72 hours of becoming aware of it. Where national security considerations arise, immediate notification is required. In all cases, affected data subjects must also be notified within three working days of the date the breach was reported to the PDPC, by the contact method they nominated when their data was collected. Egyptian law sets no risk threshold for that notice. Notifications must describe the breach, the data and individuals affected, likely consequences, and the remedial steps taken.

How does Egypt's PDPL treat children's data?

Children's data is sensitive personal data in every case, so a PDPC licence is required before processing it. Children under 15 require explicit written consent from a legal guardian, on paper or electronically, before any collection or processing. For children aged 15 to 18 the guardian's consent is still what counts, and the child or the guardian may be the one to submit it, through mechanisms the PDPC sets. Processing for games, competitions, or other activities may not be conditioned on collecting more data than is strictly necessary. Behavioral profiling of children is restricted under the Executive Regulations.

Updates

Corrected against the Official Gazette texts of Law 151/2020 and Ministerial Decree 816/2025: breach notice to individuals is required in every case within three working days of the report to the PDPC, with no risk threshold; the base penalty for unauthorized processing is a fine of EGP 100,000 to EGP 1,000,000 with no imprisonment, and unlicensed processing carries EGP 500,000 to EGP 5,000,000; the PDPC has no administrative-fine power, since all fines are criminal and imposed by the Economic Courts; the licence fee above five million records is EGP 666,666 a year, not EGP 2,000,000; direct e-marketing licences cost 10 percent or 25 percent, not 50 percent; Egypt has four lawful bases and no vital-interests, public-interest or GDPR-style sensitive-data exemptions, and no right to data portability; sensitive data needs a PDPC licence; cross-border transfers need the data subject's consent as well as a licence; the law covers electronic processing only and exempts six categories including the national security bodies and the Central Bank; the compliance deadline is 1 November 2026; and an unverifiable court citation was removed. Corrected the first FAQ answer, which still said Egypt's Personal Data Protection Law was enacted in October 2020 and took effect in January 2021 and that it covered non-automated processing across all public and private bodies: the Law was issued on 13 July 2020, published in the Official Gazette on 15 July 2020 and in force in mid-October 2020, it reaches only electronically processed data, and Article 3 of its issuing articles excludes the national security bodies and the Central Bank of Egypt. Also attributed the deemed-refusal rule to Article 10(3) rather than Article 32, restated the extraterritorial reach as the Article 2 jurisdiction rule covering data of Egyptians and of foreigners resident in Egypt, derived the 1 November 2026 compliance deadline from the issuance of the Executive Regulations under issuing Article 6, put the recent-developments entries in date order, and removed a duplicate citation.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Full refresh: incorporated Ministerial Decree No. 816/2025 (the Executive Regulations), and updated the licensing fee tiers, compliance timeline, DPO registration requirements, children's data age thresholds, direct marketing licence rules, AI Strategy 2025-2030 alignment, and the penalty structure from Law 151/2020.

Reviewed and approved by an editor

Initial publication covering PDPL Law 151/2020, PDPC establishment, cross-border transfer framework, and Executive Decree 816 overview.

Sources and References

  1. Library of Congress - Egypt Law on Personal Data Implemented 2025(loc.gov).gov
  2. Library of Congress - Egypt Data Protection Law 2020(loc.gov).gov
  3. Law No. 151 of 2020 on the Protection of Personal Data, Official Gazette No. 28 bis (e), 15 July 2020 (PDPC copy of the Gazette text)(pdpc.gov.eg).gov
  4. Ministerial Decree No. 816 of 2025 issuing the Executive Regulations, al-Waqa'i al-Misriyya No. 244 supp. (A), 1 November 2025, in force 2 November 2025 (stamped Gazette scan)(pdpc.gov.eg).gov
  5. PDPC FAQs: commencement of the PDPL, entry into force of the Executive Regulations, the one-year compliance period, and the breach notification duties(pdpc.gov.eg).gov
  6. PDPC, Licenses and Permits Guidelines, version 1.1, 26 January 2026(pdpc.gov.eg).gov
  7. PDPC, Services: licences and permits, their types, eligibility and validity periods(pdpc.gov.eg).gov
  8. PDPC, Privacy Notice Guidelines, version 1.1, 26 January 2026(pdpc.gov.eg).gov
  9. PDPC, Personal data breach notification to data subjects: templates(pdpc.gov.eg).gov
  10. PDPC, Regulations: the Law, the Executive Regulations, ten published guidelines, templates and the decisions tab(pdpc.gov.eg).gov
  11. Official Gazette text of Law No. 151 of 2020, hosted by the Ministry of Communications and Information Technology(mcit.gov.eg).gov
  12. WIPO Lex Law No. 175 of 2018 Egypt Cybercrime Law(wipo.int).gov
  13. Digital Watch Observatory Egypt National AI Strategy 2025-2030(dig.watch)
  14. PDPC, Lawful Bases of Processing Guidelines, version 1.1, 26 January 2026(pdpc.gov.eg).gov
  15. CADE Project Egypt Activates Data Protection Law with Implementing Regulations(cadeproject.org)
  16. PDPC, Data Protection Officer Guidelines, version 1.1, 26 January 2026(pdpc.gov.eg).gov
  17. PDPC, Electronic Direct Marketing Guidelines, version 1.1, 26 January 2026(pdpc.gov.eg).gov
  18. PDPC, Personal data breach notification to the PDPC: template(pdpc.gov.eg).gov
Share: