Data & Privacy ยท Egypt
Data protection & privacy law in Egypt (2026)
Egypt shaded by its data & privacy status
Data protection in Egypt: comprehensive law.
FrameworkPersonal Data Protection Law No. 151 of 2020 (PDPL), supplemented by Executive Regulations issued via Prime Ministerial/MCIT Decree No. 816 of 2025 (1 November 2025); supervised by the Personal Data Protection Center (PDPC) under the Ministry of Communications and Information Technology (MCIT).
Egypt has a comprehensive, GDPR-inspired personal data protection regime in force. Law No. 151 of 2020 was enacted on 13 July 2020 and took effect on 14 October 2020, but remained largely unenforceable until the long-awaited Executive Regulations (Decree 816/2025) were issued on 1 November 2025 and the Personal Data Protection Center (PDPC) was operationalised. In-scope controllers and processors have a one-year grace period to achieve full compliance by 31 October / 1 November 2026.
Key points
Law No. 151 of 2020 Promulgating the Personal Data Protection Law was published in the Official Gazette in July 2020 and entered into force on 14 October 2020, creating Egypt's first comprehensive personal-data regime covering electronic processing of personal data with extraterritorial reach.
MCIT Decree No. 816 of 2025, issued on 1 November 2025, enacted the Executive Regulations to the PDPL โ providing detailed operational rules on consent, licensing, record-keeping, breach notification, cross-border transfers, special-category and children's data, and direct electronic marketing.
The Personal Data Protection Center (PDPC), affiliated with MCIT, has been established as the sole supervisory authority. It licenses controllers/processors, issues guidance, receives complaints, investigates breaches and imposes administrative sanctions.
The Executive Regulations grant in-scope organisations a one-year transitional period; full enforcement of substantive PDPL obligations begins on 31 October / 1 November 2026, by which point controllers and processors must have completed licensing, DPO appointment where required, and record-keeping.
Transfers of personal data outside Egypt require a licence or permit from the PDPC, based on an adequacy-style assessment of the destination country, plus the explicit consent of the data subject; limited derogations are available under Article 15 of the PDPL.
The regime requires lawful basis / prior informed consent, purpose limitation, data minimisation and defined retention, appointment of a Data Protection Officer in prescribed cases, maintenance of processing records, security-by-design, and 72-hour breach notification to the PDPC. Data subjects have GDPR-style rights of access, rectification, erasure, withdrawal of consent and objection.
The PDPL provides for administrative fines up to EGP 5 million and criminal penalties including imprisonment (generally six months or more) for serious violations such as unlawful processing, unauthorised cross-border transfers, or failure to notify breaches.
Timeline - major decisions & events
Prime Ministerial Decree No. 816 / MCIT Decision No. 81 of 2025 issued the long-awaited implementing regulations, made the Personal Data Protection Center operational, and introduced licensing, breach-notification (72 hours) and tiered-fee rules; a 12-month grace period sets full enforcement for 31 October 2026.
Clyde & Co โA breach exposed personal data of large numbers of Egyptian students, highlighting weak data-security practices in the public sector ahead of the privacy law's enforcement.
Human Rights Watch โA scraped dataset exposed names, phone numbers, locations and other details of nearly all Facebook users in Egypt, underscoring the scale of personal-data exposure as the new law took shape.
Egyptian Streets โEgypt's first comprehensive data-protection law took effect 90 days after publication, establishing GDPR-inspired rights, lawful processing bases, cross-border transfer controls and the Personal Data Protection Center.
Library of Congress โClaims of a leak of Vodafone Egypt customer data prompted a fact-finding committee under the National Telecom Regulatory Authority, an early test of telecom data-protection oversight.
Egypt Today โRatification and publication in the Official Gazette (15 July 2020) created Egypt's first standalone personal-data framework, with enforcement set to begin 90 days later.
Ministry of Communications and Information Technology โThe House of Representatives approved the Personal Data Protection bill, modeled in part on the EU GDPR, prohibiting processing of personal data without consent except in defined cases.
IAPP โThe cybercrime law imposed a 180-day data-retention duty on telecom/service providers and website-blocking powers, shaping the surveillance-and-data-handling backdrop that the later privacy law operates within.
Library of Congress โArticles 57 and 99 made private life inviolable, protected confidentiality of communications and treated violations as crimes, providing the constitutional foundation for later data-protection legislation.
ICLG โThe law regulated electronic signatures and transactions and created the Information Technology Industry Development Authority, an early pillar of Egypt's digital-data legal infrastructure.
WIPO Lex โEgypt - other topics
Data & Privacy in other countries
Last verified 9/1/2026 ยท Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite ยท State of Technology Regulation 2026 ยท Explore the full world map โ