A statue of Lady Justice against a blurred background of law books.

Egypt’s Personal Data Protection Law – Before You Process, You Need a Licence

The Arab Republic of Egypt enacted a comprehensive data protection law in 2020. For five years, its practical impact remained limited. There was no supervisory authority, no executive regulations and no enforcement. That changed on 1 November 2025. From 31 October 2026, full compliance will be mandatory.

Background: Egypt’s Path to Data Protection

Egypt is the most populous country in the Arab world and one of Africa’s largest economies, with a population of over 100 million. Its modern state tradition stretches back to the 19th century, but the country’s political landscape has been shaped by successive waves of change: the 1952 revolution that ended the monarchy, the presidency of Gamal Abdel Nasser and his Arab socialist project, Anwar Sadat’s pivot towards the West and the open-door economic policy, and then three decades of Hosni Mubarak’s rule before the 2011 uprising that formed part of the broader Arab Spring.

Since 2014, Egypt has been governed under President Abdel Fattah el-Sisi. The current government has pursued a dual agenda of large-scale infrastructure investment and digital transformation. The Egypt Vision 2030 strategy explicitly prioritises digitalisation, e-government, and the growth of the technology and communications sector. It is in this context, a state actively building digital infrastructure and an expanding digital economy, that data protection regulation became a policy priority.

The Egyptian Personal Data Protection Regime

The Egyptian Personal Data Protection Law No. 151 of 2020 (PDPL)  (find the original text here) entered into force in 2020. On paper, it established a comprehensive framework with definitions of personal data, processing, sensitive data and data subjects. It established rights for individuals, obligations for controllers and processors, and a new supervisory authority, the Personal Data Protection Center (PDPC).

In practice, however, the law’s impact on Egyptian business remained manageable for years. Without the PDPC, there was no licensing body, no enforcement mechanism, and no DPO register. Without the Executive Regulations, the detailed technical and procedural requirements did not exist.

That changed on 1 November 2025, when the Egyptian Ministry for Communication and Information Technology issued Decree No. 816 of 2025 enacting the long-awaited Executive Regulations. Their entry into force triggered the one-year reconciliation period provided under Art. 6 PDPL. From 31 October 2026, full compliance is mandatory. The PDPC is already established under Art. 19 PDPL and chaired by the Minister of Telecommunication and Information Technology. The PDPC’s official electronic portal where licencing and registration will be performed is expected to go live by mid-June 2026.

Core Content of the PDPL in Contrast to the GDPR

The PDPL draws on internationally recognised data protection principles and is broadly aligned with the GDPR in structure and terminology. However, it differs from the GDPR in several significant aspects.

Definitions and Scope

The PDPL applies to the electronic processing of personal data of natural persons by any holder, controller or processor, Art. 1 PDPL. Unlike the GDPR, which recognises only controllers and processors, Art. 4 para. 7 and 8 GDPR, the PDPL introduces a third actor: the holder. This is a person who holds data without decisional authority over its processing.

The PDPL’s extraterritorial reach is narrower than the GDPR’s, as it covers non-Egyptian persons abroad only where the data subject is an Egyptian national or resident, Art. 2 PDPL (enacting law). The GDPR has a broader trigger of targeting or monitoring EU residents regardless of nationality, Art. 3 para. 2 GDPR.

Legal Bases

Processing is lawful in four cases:

  1. consent,
  2. contractual necessity or exercise of legal rights,
  3. legal obligation or court order, and
  4. enabling the controller to exercise legitimate rights, provided this does not override the data subject’s fundamental rights, Art. 6 PDPL.

The GDPR provides two additional bases: Vital interests, Art. 6 para. 1 lit. d GDPR and most significantly, legitimate interests as a standalone balancing ground, Art. 6 para. 1 lit. f GDPR.

Data Subject Rights

The PDPL reflects the rights of data subjects under the GDPR. The most notable differences from the GDPR are the response period of only six business days (Art. 32 PDPL) instead of one month (Art. 12 para. 3 GDPR), and the fact that data controllers may charge data subjects a fee of up to EGP 20,000 for exercising most rights (Art. 2 PDPL). The GDPR requires responses to be free of charge by default (Art. 12 para. 5 GDPR).

To put the fee of EGP 20,000 in context: the current EUR/EGP exchange rate is approximately 62.7, making the maximum fee roughly EUR 320. The average gross monthly salary in Egypt is approximately EGP 8,000, against a private sector minimum wage of EGP 7,000 per month. The maximum fee for exercising a data subject right therefore represents roughly 2.5 times the average monthly salary. For most Egyptian residents, this is not a symbolic threshold but a material barrier to exercising legal rights.

Controller and Processor Obligations

The core duties, accuracy, security, erasure and record-keeping, mirror the GDPR broadly. The decisive difference is the licence requirement: both controllers and processors must obtain a licence or permit from the PDPC before handling personal data, Arts. 4 para. 10, 5 para. 11 PDPL. The GDPR requires no such prior authorisation.

Sensitive Data

The PDPL’s definition is broader than the GDPR’s as it adds financial data and security standing as sensitive categories, Art. 1 PDPL. Processing sensitive data requires a separate PDPC licence, Art. 12 PDPL. The GDPR requires no licence, only a valid ground under Art. 9 para. 2 GDPR.

Cross-Border Transfers

Transfers outside Egypt are prohibited unless the receiving country provides a level of protection not lower than Egypt’s standards. The difference to GDPR is again the licence requirement. Every transfer outside Egypt requires a PDPC licence, Art. 14 PDPL.

Impact for the Egyptian Business Market

The issuance of the Executive Regulations fundamentally changes the situation for businesses operating in Egypt. For the first time, the licensing regime is operational, fees are set, and a definite compliance deadline exists.

The PDPC portal is expected to be live by May 2026, meaning businesses have a narrow window of approximately five months from portal launch to the 31 October 2026 deadline to complete registration, appoint and register a Data Protection Officer (DPO), and obtain all required licences.

The licensing fees are volume-based (the number of data subjects processed equals the number of records), which means that large-scale data processors face proportionally higher costs. The fee for obtaining a licence to transfer personal data outside Egypt is 50% of the local licence fee for the same category of data, a material additional cost for any organisation with cross-border data flows.

For international businesses processing personal data of individuals located in Egypt without a local establishment, the PDPL requires appointment of a local representative, subject to PDPC approval, Art. 4 para. 11 PDPL.

Companies that process personal data of individuals located in Egypt need to determine whether the PDPL’s licensing obligations apply to them before 31 October 2026. Where they do, the relevant licences must be in place before the deadline. Data volumes should be assessed early, as licensing fees are calculated on that basis. Where no local establishment exists, the question of whether a local representative must be appointed requires attention.

Concluding Remarks: A Comparative Perspective

The PDPL shares the GDPR’s core principles of purpose limitation, data minimisation, data subject rights and breach notification. The procedural architecture, however, is fundamentally different.

Under the GDPR, processing may begin once a valid legal basis exists. No licence is required, no fee is payable, and no prior regulatory approval is needed. The GDPR’s supervisory model is principally ex post.

The PDPL takes the opposite approach. A licence is required simply for everything. Every controller and processor must obtain a licence before handling personal data. Sensitive data processing, cross-border transfers, direct electronic marketing, visual surveillance in public areas, and data protection consultancy each require a separate licence or permit. Fees are payable for each. The result is a regulatory approval system, rather than a compliance system. Where the GDPR asks: “Do you have a legal basis?”, the PDPL asks: “Do you have a licence?”. For organisations operating under both regimes, GDPR compliance is not a substitute for PDPL compliance. Answering the second question takes longer and costs more.

Prior authorization as a regulatory tool is not inherently undesirable. There are processing contexts, such as the large-scale processing of medical or genetic data, where a requirement to obtain regulatory approval before processing begins is defensible. The concern with the PDPL’s model, is not the concept itself, but its scope.

A licensing obligation that applies to every controller and every processor regardless of risk profile, sector, or data volume ceases to function as a targeted safeguard.  It becomes, among other things, a revenue stream: fees are volume-based, apply to every licence category, and are payable on renewal, with the PDPC’s own budget partly funded by the fees it collects (Art. 31 PDPL). More significantly, the power to grant, refuse, suspend or revoke a licence is the power to decide who may process data at all. In a jurisdiction where national security authorities hold explicit exemptions from the law and are represented on the PDPC’s own board of directors, the licensing regime is not purely a data protection instrument. It becomes an instrument of state oversight and, where it suits, a point of leverage over disfavoured actors.

The PDPL is not unique in combining data protection with state control mechanisms. But it is worth naming clearly: a licensing regime of this impact is not principally about protecting individuals‘ personal data. It is about who controls the flow of data, and who decides.



No comments


« Previous post Next post »