Egypt passed a strict law and then left it half-armed: Law No. 151 of 2020 has been in force since October 2020, complete with criminal penalties and a licensing regime, while the executive regulations needed to run that regime have stayed pending year after year. The result is a compliance landscape defined by asymmetry, the prohibitions (unlicensed transfers, unconsented sensitive-data processing, unlawful marketing) are enforceable now through criminal law, while the permissions machinery you would use to comply formally is still being built. Companies in Egypt manage that by complying with the statute’s substance and keeping application-ready files for the day the Center’s procedures go live.
| Law | Law No. 151 of 2020 |
|---|---|
| In force | October 2020 (executive regulations pending) |
| Regulator | Personal Data Protection Center |
| DPO | Mandatory, registered |
| Transfers | Center permit required; criminal exposure without |
| Penalties | EGP 100K to 5M + imprisonment for listed offenses |
Building the Egypt module
Comply with the text, track the regulations. Consent records, DPO appointment, security measures, and 72-hour breach readiness are statute-level duties that need no regulations to bind.
Treat transfers as the red zone. Minimize exports, document consent-based justifications, and keep permit-application files ready; unlicensed transfer is the law’s sharpest criminal edge.
Prepare licensing dossiers now. Sensitive-data processing and marketing authorizations will need application-grade documentation; building it early converts regulatory activation from crisis to filing.
Fit Egypt into the regional matrix. Its regulator-gated design echoes Bahrain more than Saudi Arabia’s registration model or the UAE’s patchwork; pan-MENA programs should annex it accordingly.
Electronic marketing without consent is among the law’s criminal offenses, and your site’s behavior is the evidence: check it with a free scan.