1---2name: kb-data-privacy-egypt3description: Use when a matter involves personal data processing, privacy obligations, or data-breach response in Egypt. Covers Egypt's Personal Data Protection Law (Law 151/2020) and its executive regulations, the role of the Personal Data Protection Centre (PDPC), consent requirements, data subject rights, cross-border transfer restrictions, and penalties. Triggers on questions about Egyptian data privacy compliance, PDPL Egypt, data controller obligations, or sensitive-data handling in Egyptian jurisdiction.4license: MIT5---67# Knowledge Pack — Egypt Personal Data Protection Law (Law 151/2020)89## Scope1011Egypt's Personal Data Protection Law (Law No. 151 of 2020) and its Executive Regulations (Prime Ministerial Decree 1074/2022) constitute the country's first comprehensive data-protection framework. The law applies to:1213- **Any entity** (natural or legal, public or private) that collects, stores, processes, or transmits personal data of individuals who are:14 - Located in Egypt at the time of processing, **or**15 - Egyptian nationals (regardless of location)16- **Extra-territorial reach**: foreign entities processing Egyptian residents' or nationals' data are covered.17- Exempted: purely personal/household use; national security and public order data processed by competent authorities; statistical research using anonymized data.1819## Key Definitions2021| Term | Egyptian Law Definition |22|---|---|23| Personal data | Any data that identifies or could identify a natural person |24| Sensitive data | Health, genetic, biometric, religious belief, political opinion, criminal records, financial data |25| Controller | Entity that determines purposes and means of processing |26| Processor | Entity that processes data on behalf of a controller |27| Processing | Any operation performed on personal data (collection, storage, use, transfer, erasure, etc.) |28| PDPC | Personal Data Protection Centre — supervisory authority |2930## Lawful Bases for Processing31321. **Express consent** — written, explicit, and informed; may be withdrawn at any time.332. **Contractual necessity** — processing necessary to perform a contract to which the data subject is a party.343. **Legal obligation** — required by Egyptian law.354. **Vital interests** — necessary to protect the life or health of the data subject or a third party.365. **Public task** — processing by a public authority for a task in the public interest.376. **Legitimate interests** — balance-of-interests test; **not available for sensitive data**.3839### Sensitive data requires **explicit written consent** plus additional safeguards — no legitimate-interests basis.4041## Data Subject Rights4243| Right | Details |44|---|---|45| Access | Request a copy of personal data held |46| Rectification | Correct inaccurate or incomplete data |47| Erasure | Request deletion when legal basis ceases or consent withdrawn |48| Restriction | Suspend processing while dispute is resolved |49| Objection | Object to processing (especially direct marketing) |50| Portability | Receive data in a machine-readable format |51| Withdraw consent | At any time; withdrawal does not affect prior lawful processing |5253- Controllers must respond to requests within **30 days** (extendable to 60 days with notice).5455## Registration & Notification Obligations5657- Controllers and processors that process **sensitive data** or that process **on a large scale** must **register with the PDPC** before commencing processing.58- Registration fee + periodic renewal.59- Prior notification to PDPC required for:60 - High-risk processing activities (DPIA-equivalent assessment required)61 - Automated decision-making affecting individuals62 - Large-scale processing of sensitive categories6364## Cross-Border Data Transfers6566- Transfer outside Egypt is **prohibited unless**:67 1. The destination country provides **adequate protection** (PDPC adequacy list — not yet published as of 2025; EU SCCs used as reference practice).68 2. **Contractual safeguards** approved by PDPC (standard contractual clauses or binding corporate rules).69 3. **Express consent** of the data subject for the specific transfer.70 4. Transfer is necessary for contract performance, legal claims, vital interests, or public interest.71- Controllers must document the transfer basis and retain records.7273## Data Breach Obligations7475- Notify **PDPC within 72 hours** of becoming aware of a breach that is likely to risk data subjects' rights or freedoms.76- Notify **affected data subjects without undue delay** if the breach is likely to cause high risk.77- Maintain internal breach register.7879## Data Protection Officer (DPO)8081- Required for:82 - Public authorities83 - Entities whose core activities involve **large-scale processing of sensitive data**84 - Entities whose core activities involve **large-scale systematic monitoring**85- DPO must have expertise in data-protection law; may be internal or external.8687## Security Requirements8889- Implement **technical and organizational measures** appropriate to the risk level.90- Measures include: encryption, pseudonymization, access controls, regular testing.91- Third-party processors must provide sufficient security guarantees; documented by a **Data Processing Agreement (DPA)**.9293## Penalties9495| Violation | Penalty |96|---|---|97| Processing without lawful basis or without consent | EGP 100,000 – 1,000,000 |98| Transfer outside Egypt without authorization | EGP 500,000 – 5,000,000 |99| Processing sensitive data without explicit consent | EGP 500,000 – 5,000,000 |100| Failure to notify breach | EGP 50,000 – 500,000 |101| General non-compliance | EGP 10,000 – 1,000,000 |102| Repeated violations | Doubled fines + criminal liability for responsible individuals |103104## Supervisory Authority: PDPC105106- **Personal Data Protection Centre (PDPC)** — under the Ministry of Communications.107- Powers: registration, inspection, investigation, issuing guidance, imposing fines.108- Complaint mechanism: data subjects may file complaints with PDPC.109- PDPC may issue binding guidance and codes of practice.110111## Practical Compliance Checklist112113- [ ] Map all personal data flows (data mapping / inventory)114- [ ] Identify and document lawful basis for each processing activity115- [ ] Update privacy notices / privacy policy (Arabic and English)116- [ ] Ensure consent mechanisms meet "explicit, informed, withdrawable" standard117- [ ] Register with PDPC if required (sensitive data / large-scale processing)118- [ ] Put **Data Processing Agreements** in place with all processors119- [ ] Establish cross-border transfer mechanisms for international data flows120- [ ] Implement breach detection and notification procedures121- [ ] Appoint DPO if triggered122- [ ] Conduct Data Protection Impact Assessments (DPIAs) for high-risk activities123124## Comparison with GDPR and Regional PDPLs125126| Feature | Egypt 151/2020 | GDPR (EU) | KSA PDPL | UAE PDPL |127|---|---|---|---|---|128| Adequacy mechanism | Yes (PDPC list) | Yes (EC list) | Yes (NDMO list) | Yes (DIFC/ADGM separate) |129| DPO mandatory | Large-scale/sensitive | Public/core activities | Not specified | Certain controllers |130| Max fine | EGP 5M | €20M / 4% global | SAR 5M | AED 20M |131| Breach notification | 72 hours to PDPC | 72 hours to DPA | 72 hours to SDAIA | 72 hours to TDRA |132| Extra-territorial | Yes | Yes | Yes | Yes |133134## Caveats & Currency135136Egypt's PDPC is newly established and enforcement practice is still developing. Executive Regulations were issued in 2022; implementing guidance continues to be published. Verify current PDPC adequacy lists, registration fees, and specific thresholds before advising. The penalty amounts above reflect the law as enacted; assess any amendments post-2023 with current sources.137138## Related Skills139140- [[kb-data-privacy-gdpr]]141- [[kb-data-privacy-ksa-pdpl]]142- [[kb-data-privacy-uae-pdpl]]143- [[kb-healthcare-regulation-mena]]144- [[draft-privacy-policy]]145- [[draft-data-processing-agreement]]