Skip to content

Egypt · Data protection

Licensing regime enforceable 1 November 2026

Egypt PDPL Readiness Check

Ten questions on where your Egyptian operation stands against Law 151/2020 and its Executive Regulations, and against the GDPR obligations that run alongside them.

Egypt has no EU adequacy decision. Move personal data between Europe and Egypt and you answer to both regimes at once: a PDPC transfer licence on one side, standard contractual clauses and a transfer impact assessment on the other. We have senior counsel schooled in GDPR based in Europe, and a full team on the ground in Cairo. Both halves of the problem, one firm.

10 questions · About 4 minutes · Instant score · Our digital compliance practice

0 of 10 answered

Before you start. This is a general information tool, not legal advice, and it does not create a lawyer and client relationship. Answers are indicative only. Please do not enter confidential or case-specific detail; nothing submitted here is privileged until a retainer is in place.

01Do you know exactly what personal data your Egyptian operation holds, and where it flows?

A data map covering employees, customers and users, not a general sense of it.

02Have you appointed a Data Protection Officer and registered them with the PDPC?

The Executive Regulations make a registered DPO mandatory, with a PDPC examination and registration category.

03Do you hold, or have you applied for, the PDPC licence your processing requires?

Licences are required for processing, and applications take around 90 working days.

04If personal data leaves Egypt, do you hold a PDPC cross-border transfer permit?

Any transfer to a parent, a group company or a cloud provider outside Egypt needs one.

05For the Europe to Egypt leg, do you have standard contractual clauses and a transfer impact assessment?

Egypt has no EU adequacy decision, so Article 46 safeguards are required in the other direction too.

06Do you hold a PDPC permit for any electronic direct marketing you carry out in Egypt?

Direct electronic marketing is separately licensed under the Regulations.

07Do you keep a written record of your processing activities?

A documented register, kept current, not a spreadsheet someone made once.

08Could you notify the PDPC of a personal data breach within 72 hours?

A documented, rehearsed process with named owners, plus notification to individuals within three working days.

09Do you capture and record consent to the Egyptian standard?

Group templates written for GDPR do not automatically satisfy the Egyptian requirements.

10Have your European client contracts been updated to reflect the Egyptian regime?

Processor terms, audit rights and transfer mechanics, seen from both sides.

Answer all ten questions to see your score.

This assessment provides general information about Egypt’s Personal Data Protection Law (Law 151 of 2020) and its Executive Regulations (Prime Ministerial Decree 816 of 2025), together with the EU General Data Protection Regulation. It is not legal advice, does not take account of your specific circumstances, and creates no lawyer and client relationship. Information submitted through this page is not privileged or confidential until a retainer is in place. Scores are indicative and should not be relied on as a compliance assessment. Statutory dates and penalties should be confirmed against the Personal Data Protection Centre before any action is taken. For verified, dated tracking of this and every other MENA regime, see LegalEyes.