Loading...
Loading...
Copyright © 2026 Anove International B.V.
All product names, logos, and brands are property of their respective owners. Use of these names does not imply affiliation, endorsement, or partnership.
PDPL
Egypt's first comprehensive data protection law regulates the electronic collection, processing, storage and transfer of personal data and establishes the Personal Data Protection Center as regulator, backed by criminal penalties of up to EGP 5 million.
Law No. 151 of 2020 was published in July 2020 and entered into force in October 2020, three months after publication. It defines personal data broadly and treats health, genetic, biometric, financial, religious, political and criminal-record data, as well as all children's data, as sensitive. Processing requires the data subject's explicit consent or another legal basis under Article 6, and sensitive data requires a specific permit. The Personal Data Protection Center (PDPC), a public economic authority under the Ministry of Communications and Information Technology, licenses controllers and processors, receives complaints, conducts inspections and regulates cross-border transfers; it is now operational and its executive regulations were issued in late 2025 to early 2026.
Controllers and processors must appoint a registered Data Protection Officer, notify the Center of breaches within 72 hours (immediately where national security is concerned) and inform affected data subjects within three days of notifying the Center. Cross-border transfers are prohibited unless the destination offers at least an equivalent level of protection and a licence or permit is obtained from the Center. Direct electronic marketing requires prior consent, sender identification and opt-out mechanisms. Enforcement is judicial, through Egypt's Economic Courts: in the first court application of the law, on 27 May 2025 an Alexandria court ordered a telecom operator to pay compensation of approximately EUR 280,000 to a customer whose SIM card had been fraudulently swapped.
Personal data may not be collected, processed or disclosed without the data subject's explicit consent or another legal basis; sensitive data processing requires a specific permit from the Center.
Controllers and processors must obtain a licence or permit from the Center to collect, store, transfer or process electronic personal data, sensitive data or conduct electronic marketing.
Legal entities acting as controller or processor must appoint a DPO registered with the Center, responsible for compliance, breach notification and data subject requests.
Breaches must be notified to the Center within 72 hours, immediately where national security is concerned, and affected data subjects must be informed within three days of notifying the Center.
Read more
Anove scans your stack against PDPL and 260+ other frameworks in minutes.
Transfers abroad are prohibited unless the recipient country ensures an equivalent level of protection and a Center licence or permit is obtained; narrow consent-based exceptions apply.