Middle East & Africa Egypt

Egypt PDPL: Law No. 151 of 2020 Compliance Guide

Egypt's Personal Data Protection Law: Data Protection Center licensing, consent rules, DPO duties, cross-border transfer permits, and criminal penalties up to EGP 5 million.

Regulation

Personal Data Protection Law No. 151 of 2020 (in force October 2020); executive regulations pending

Max Penalty

Fines from EGP 100,000 to EGP 5 million per offense plus imprisonment (three months to three years) for listed violations, including unlicensed cross-border transfers

Enforcing Authority

Personal Data Protection Center (under Egypt's Ministry of Communications and IT / ITIDA framework)

Official Source

itida.gov.eg

Executive Summary

  • Law No. 151 of 2020 is Egypt's first comprehensive data protection statute, in force since October 2020, built on consent as the default lawful basis and enforced criminally as well as administratively.
  • It creates the Personal Data Protection Center as regulator, with a licensing and permit system: controllers and processors need licenses or permits for defined processing, and cross-border transfers require the Center's permission.
  • The executive regulations, which the law needs to become fully operational (license fees, forms, procedures), have remained pending for years; companies should build to the statute's text and track the regulations' issuance.
  • DPO appointment is mandatory for controllers and processors under the law, one of the stricter DPO rules in the region.
  • Penalties are criminal-flavored: fines from EGP 100,000 to EGP 5 million and imprisonment for violations including unlawful sensitive-data processing and unlicensed transfers, with liability reaching responsible managers.

Egypt passed a strict law and then left it half-armed: Law No. 151 of 2020 has been in force since October 2020, complete with criminal penalties and a licensing regime, while the executive regulations needed to run that regime have stayed pending year after year. The result is a compliance landscape defined by asymmetry, the prohibitions (unlicensed transfers, unconsented sensitive-data processing, unlawful marketing) are enforceable now through criminal law, while the permissions machinery you would use to comply formally is still being built. Companies in Egypt manage that by complying with the statute’s substance and keeping application-ready files for the day the Center’s procedures go live.

LawLaw No. 151 of 2020
In forceOctober 2020 (executive regulations pending)
RegulatorPersonal Data Protection Center
DPOMandatory, registered
TransfersCenter permit required; criminal exposure without
PenaltiesEGP 100K to 5M + imprisonment for listed offenses

Building the Egypt module

Comply with the text, track the regulations. Consent records, DPO appointment, security measures, and 72-hour breach readiness are statute-level duties that need no regulations to bind.

Treat transfers as the red zone. Minimize exports, document consent-based justifications, and keep permit-application files ready; unlicensed transfer is the law’s sharpest criminal edge.

Prepare licensing dossiers now. Sensitive-data processing and marketing authorizations will need application-grade documentation; building it early converts regulatory activation from crisis to filing.

Fit Egypt into the regional matrix. Its regulator-gated design echoes Bahrain more than Saudi Arabia’s registration model or the UAE’s patchwork; pan-MENA programs should annex it accordingly.

Electronic marketing without consent is among the law’s criminal offenses, and your site’s behavior is the evidence: check it with a free scan.

Frequently Asked Questions

What does Egypt's PDPL cover and who is in scope?

Personal data of natural persons processed electronically, wholly or partly, by controllers or processors, Egyptian entities, and foreign entities processing Egyptians' data where the processing relates to offering goods or services in Egypt. Carve-outs include central bank and banking-sector data (governed by banking law), national security bodies, and purely personal use. Sensitive data (health, biometrics, genetics, religion, financial data of children, and more) requires the Center's license and explicit consent. The electronic-processing framing means purely paper records sit outside, a narrower net than the GDPR's.

What is the licensing and permit system?

The law conditions defined activities on authorization from the Personal Data Protection Center: licenses for sensitive-data processing, permits for cross-border transfers, and authorizations for direct electronic marketing, with fees and procedures left to the executive regulations. This regulator-gated design resembles Bahrain's more than the GDPR's accountability model: certain processing is unlawful without a document from the Center, not merely unlawful if done badly. Until the executive regulations fully operationalize the machinery, companies document readiness (application-grade descriptions of processing, security, and transfer flows) so filings can move when procedures crystallize.

Who needs a DPO in Egypt?

The law requires controllers and processors to appoint a data protection officer responsible for compliance, a registry of processing, breach notification, and serving as the Center's contact, and the DPO must be registered. Unlike the GDPR's conditional triggers, Egypt's duty reads as general for entities within scope, making it one of the region's broadest DPO mandates. Multinationals typically designate a local officer paired with regional privacy counsel. Breach notification runs through the DPO to the Center within 72 hours of awareness, with data subject notice within three days where required.

How do cross-border transfers work?

Restrictively, on the statute's face: transferring personal data outside Egypt requires a level of protection not lower than Egypt's and the Center's license or permit; unlicensed transfers are criminal offenses carrying both fines and potential imprisonment. Exceptions exist with the data subject's consent for defined purposes (international judicial cooperation, contract performance involving the data subject, and similar). Because the executive regulations and the Center's permit practice remain immature, companies run transfers on documented consent plus readiness files, and structure Egyptian operations to minimize unnecessary exports. This is the highest-risk compliance area in the law, treat it accordingly.

What is the enforcement reality given the pending regulations?

The law is in force and its criminal provisions are prosecutable, but the regulator's administrative machinery (licenses, fees, inspection practice) has been slowed by the wait for executive regulations, drafts have circulated for years without final issuance as of early 2026. Practically: exposure today concentrates in the criminal provisions (sensitive data, transfers, marketing without consent) which prosecutors can pursue independent of the regulations, and in commercial pressure, regional counterparties increasingly require Egypt-aware contract terms. The prudent posture is statute-level compliance now (consent, DPO, security, breach readiness, transfer discipline) with a tracking file on the regulations so licensing obligations can be met promptly when activated.

Regulatory Crosswalk

GDPRSaudi PDPLUAE federal PDPLBahrain PDPL

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.