🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
EG v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 1 failing7 sources retrieved model claude-sonnet-5 · 2026-08-05

Based mainly on secondary sources. None of the sources retrieved for this jurisdiction is official or direct reporting of official material (tier 1 or 2); we look for at least 3. No finding on this page is shown with confidence above “Uncertain” until stronger sources are retrieved.

Egypt

EG schema gdpri-v2 trajectory: not yet assessedin transitionoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 28 claims · 19 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
28Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 32 sub-modules are flagged red.

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Egypt's Personal Data Protection Law regime has moved from dormant to formally activated. The Executive Regulations under Decree No. 816 of 2025 confirm the Personal Data Protection Center as the supervisory authority responsible for implementation, monitoring and enforcement of Law No. 151 of 2020, five years after that law was passed. The Regulations entered into force on 2 November 2025 and carry a one-year transitional grace period ending 1 November 2026, after which full enforcement is expected. This is the most consequential development in Egypt's data protection posture since the underlying law's enactment, and it converts a long-dormant statute into an operative compliance regime with a hard deadline.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Primary statute in force since 2020 but implementing regulations and regulator operability only crystallized in Nov 2025-2026, with substantive compliance (licensing, DPO, cross-border) not mandatory until 31 Oct 2026.

Primary frameworkLaw No. 151 of 2020 on the Protection of Personal Data (PDPL) and Executive Regulations No. 816 of 2025
Supervisory authorityPersonal Data Protection Center (PDPC)
Traffic-light rationale — AmberPrimary statute in force since 2020 but implementing regulations and regulator operability only crystallized in Nov 2025-2026, with substantive compliance (licensing, DPO, cross-border) not mandatory until 31 Oct 2026.

Sub-modules (5)

Regulator And AuthorityAmber

PDPC is the statutory regulator; historically un-established, now issuing guidelines and templates and having posted the Executive Regulations.

Claims (1):

  • The Personal Data Protection Center (PDPC) is the supervisory authority designated to enforce Egypt's Personal Data Protection Law and issue implementing guidance.

Act And InstrumentsGreen

PDPL (Law 151/2020) is the central instrument, supplemented by Executive Regulations No. 816/2025.

Claims (2):

  • Law No. 151 of 2020 on the Protection of Personal Data, published in the Official Gazette in July 2020, functions as Egypt's central omnibus data-protection statute and entered into force 15 October 2020.
  • Executive Regulations No. 816 of 2025, issued by the Ministry of Communications and Information Technology on 1 November 2025 (publicly posted by the PDPC in late December 2025), detail the procedures for implementation, supervision, and enforcement of the PDPL.

Material ScopeGreen

Applies to electronic (in whole or part) processing of personal data, with statutory carve-outs.

Claims (1):

  • The PDPL applies to personal data processed electronically, in part or in full, and expressly excludes processing for personal use, official statistics, media purposes, judicial-seizure records, and data held by the Central Bank of Egypt and CBE-supervised entities (other than money-transfer/forex companies).

Territorial ScopeAmber

Extraterritorial reach to non-resident foreigners where the underlying act is criminalized abroad and victim data belongs to an Egyptian citizen/resident.

Claims (1):

  • The PDPL extends to a non-Egyptian resident domiciled outside Egypt where the same act is criminalized in the country where it occurred and the affected personal data belongs to an Egyptian citizen or resident.

Regulator Registration And FilingAmber

Licensing/permit regime administered by PDPC for sensitive-data processing, cross-border transfer, video surveillance, and e-marketing.

Claims (1):

  • Under the Executive Regulations, processing sensitive personal data, cross-border transfers, video surveillance, and electronic direct marketing each require a PDPC-issued license or permit.
Category narrative89 words

Egypt's omnibus regime rests on Law No. 151 of 2020 on the Protection of Personal Data (PDPL), which entered into force on 15 October 2020, with the Personal Data Protection Center (PDPC) as designated regulator. The PDPC was not operationally established for years; the long-awaited Executive Regulations (No. 816 of 2025) were issued 1 November 2025 and publicly posted by the PDPC in late December 2025, opening a one-year compliance grace period ending 31 October 2026. The regime is therefore enacted but only partially operative -- hence in_transition status.

Periodic update · new data 2026-09-28

Regulator & Framework

The Personal Data Protection Center is confirmed as the supervisory authority responsible for implementation, monitoring and enforcement of Law No. 151 of 2020, a status formalised by the Executive Regulations issued under Decree No. 816 of 2025. This activates a supervisory structure that had existed on paper since 2020 but lacked operative implementing detail for five years. The Executive Regulations themselves entered into force on 2 November 2025 and carry a one-year transitional grace period, running to 1 November 2026, before full enforcement is expected to apply. The framework is now a two-instrument stack: the primary Law No. 151/2020 establishing rights and obligations in principle, and the Executive Regulations giving those obligations operative content, including the PDPC's supervisory mandate. No primary PDPC gazette text was directly retrieved this cycle; the findings rest on T3 law-firm commentary describing the same Regulations, which is recorded as an evidentiary gap rather than absorbed silently.

Outlook

The governing date is 1 November 2026, when the transitional grace period lapses and the PDPC's enforcement and licensing functions become fully operative in practice, not merely on paper.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (6)
  1. UncertainOneTrust DataGuidance — The Personal Data Protection Center (PDPC) is the supervisory authority designated to enforce Egypt's Personal Data Protection Law and issue implementing guidance.observed
  2. UncertainOneTrust DataGuidance — Law No. 151 of 2020 on the Protection of Personal Data, published in the Official Gazette in July 2020, functions as Egypt's central omnibus data-protection statute and entered into force 15 October 2020.observed
  3. UncertainOneTrust DataGuidance — Executive Regulations No. 816 of 2025, issued by the Ministry of Communications and Information Technology on 1 November 2025 (publicly posted by the PDPC in late December 2025), detail the procedures for implementation, supervision, and enforcement of the PDPL.observed
  4. UncertainOneTrust DataGuidance — The PDPL applies to personal data processed electronically, in part or in full, and expressly excludes processing for personal use, official statistics, media purposes, judicial-seizure records, and data held by the Central Bank of Egypt and CBE-supervised entities (other than money-transfer/forex companies).observed
  5. UncertainOneTrust DataGuidance — The PDPL extends to a non-Egyptian resident domiciled outside Egypt where the same act is criminalized in the country where it occurred and the affected personal data belongs to an Egyptian citizen or resident.observed
  6. UncertainOneTrust DataGuidance — Under the Executive Regulations, processing sensitive personal data, cross-border transfers, video surveillance, and electronic direct marketing each require a PDPC-issued license or permit.observed

#

Consent and special-category provisions are documented; pseudonymisation/anonymisation definitions were not located in available secondary sources.

Primary frameworkLaw No. 151 of 2020 (PDPL), Executive Regulations No. 816/2025
Supervisory authorityPersonal Data Protection Center (PDPC)
Traffic-light rationale — AmberConsent and special-category provisions are documented; pseudonymisation/anonymisation definitions were not located in available secondary sources.

Sub-modules (4)

Lawful BasesAmber

Consent is established as the key lawful basis for processing under the PDPL.

Claims (1):

  • Egypt's Data Protection Law establishes consent as the key basis for lawful processing of personal data, alongside detailed rights, regulations, and penalties.

Special CategoriesAmber

Sensitive data spans genetic, physical/mental/psychological health, biometric, financial, religious, political, security-status, and minors' data.

Claims (1):

  • Sensitive data under the PDPL covers data disclosing genetic, physical, mental, or psychological health status, biometrics, financial data, religious beliefs, political opinion, security status, and minors' data.

Pseudonymisation And AnonymisationRed

No PDPL-specific pseudonymisation/anonymisation safe-harbour definitions were identified in the sources searched.

Absence provenance: unavailable. Searched: Egypt PDPL pseudonymisation anonymisation definitions, Egypt Personal Data Protection Law special categories.

Category narrative35 words

PDPL centers processing legitimacy on data-subject consent (revocable at any time) and designates an extensive list of sensitive/special categories requiring licensing. The law does not provide a developed pseudonymisation/anonymisation safe-harbour framework in the sources reviewed.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. UncertainOneTrust DataGuidance — Egypt's Data Protection Law establishes consent as the key basis for lawful processing of personal data, alongside detailed rights, regulations, and penalties.observed
  2. UncertainOneTrust DataGuidance — Data subjects under the PDPL have the right to revoke any consent previously granted for saving or processing their personal data.observed
  3. UncertainOneTrust DataGuidance — Sensitive data under the PDPL covers data disclosing genetic, physical, mental, or psychological health status, biometrics, financial data, religious beliefs, political opinion, security status, and minors' data.observed

#

Correction/objection rights documented; access, portability, and response-window specifics remain unconfirmed from available sources.

Primary frameworkLaw No. 151 of 2020 (PDPL)
Supervisory authorityPersonal Data Protection Center (PDPC)
Traffic-light rationale — AmberCorrection/objection rights documented; access, portability, and response-window specifics remain unconfirmed from available sources.

Sub-modules (5)

Access RightAmber

PDPL is broadly described as GDPR-similar in providing data-subject rights, but a distinct access-right provision was not separately confirmed.

Claims (1):

  • The PDPL has similarities to the GDPR with provisions relating to data subject rights, data controller and processor obligations, and strict data-transfer obligations.

Rectification And ErasureGreen

Data subjects may correct, amend, delete, add, or update their personal data.

Claims (1):

  • Data subjects under the PDPL may correct, amend, delete, add, or update their personal data.

Restriction And ObjectionGreen

Data subjects may limit the purpose/scope of processing and object to processing or its results where a violation exists.

Claims (1):

  • Data subjects under the PDPL may limit the purpose of processing to a specific scope and object to processing or its result where a violation exists.

Data PortabilityRed

No explicit data-portability provision was identified in the sources searched.

Absence provenance: unavailable. Searched: Egypt PDPL data portability right.

Deadlines And Response WindowsRed

No statutory response-deadline figures for PDPL data-subject requests were identified in the sources searched.

Absence provenance: unavailable. Searched: Egypt PDPL data subject request response deadline days.

Category narrative41 words

The PDPL grants GDPR-analogous data-subject rights: rectification/erasure/update, purpose-limitation/restriction, and objection to processing where a violation exists. Distinct access-right scope, portability, and statutory response-deadline provisions were not clearly located in the secondary sources reviewed and are flagged as gaps pending primary-text/Executive-Regulations review.

Sources and claims (3)
  1. UncertainOneTrust DataGuidance — The PDPL has similarities to the GDPR with provisions relating to data subject rights, data controller and processor obligations, and strict data-transfer obligations.observed
  2. UncertainOneTrust DataGuidance — Data subjects under the PDPL may correct, amend, delete, add, or update their personal data.observed
  3. UncertainOneTrust DataGuidance — Data subjects under the PDPL may limit the purpose of processing to a specific scope and object to processing or its result where a violation exists.observed

#

Core duties (DPO, DPIA concept, security, breach notice) exist in statute but material implementing detail is acknowledged as incomplete/uncertain by professional commentary.

Primary frameworkLaw No. 151 of 2020 (PDPL), Executive Regulations No. 816/2025
Supervisory authorityPersonal Data Protection Center (PDPC)
Traffic-light rationale — AmberCore duties (DPO, DPIA concept, security, breach notice) exist in statute but material implementing detail is acknowledged as incomplete/uncertain by professional commentary.

Sub-modules (7)

Accountability And DpiaAmber

DPIA obligation exists in concept; content/manner left to further executive detail, per comparative GDPR/PDPL analysis.

Claims (1):

  • The content and manner of carrying out Data Protection Impact Assessments under the PDPL is not detailed in the primary law and is expected to be clarified further by executive regulation.

Dpo RequirementsAmber

All controllers and processors must appoint an accredited DPO; PDPL does not specify DPO qualifications.

Claims (1):

  • Under the Executive Regulations, all controllers and processors must appoint an accredited Data Protection Officer, although the PDPL itself does not specify DPO qualifications.

Ropa RequirementsRed

No PDPL-specific records-of-processing (ROPA) obligation was identified in the sources searched.

Absence provenance: unavailable. Searched: Egypt PDPL records of processing activities ROPA requirement.

Joint Controller ArrangementsRed

No joint-controller-specific provision was identified in the sources searched.

Absence provenance: unavailable. Searched: Egypt PDPL joint controller arrangement.

Security MeasuresAmber

PDPL requires 'appropriate security measures' for sensitive processing and cross-border transfer but is less clear than GDPR in defining security-measure standards.

Claims (1):

  • The PDPL is less clear than the GDPR in its definitions of the security measures required of controllers and processors.

Breach NotificationAmber

A breach-notification duty exists but comparative analysis finds the PDPL does not clarify exceptions from breach-notification or processor-notification requirements.

Claims (1):

  • Unlike the GDPR, the PDPL does not clarify exceptions from breach-notification requirements or processor-notification requirements.

Retention And DisposalRed

No explicit PDPL retention-limit or disposal-duty provision was identified in the sources searched.

Absence provenance: unavailable. Searched: Egypt PDPL data retention limit disposal duty.

Category narrative64 words

Controllers/processors must appoint an accredited DPO under the Executive Regulations, though the PDPL itself sets no DPO qualification standard. DPIA obligations exist conceptually but their content/manner is left to further executive detail. Comparative legal analysis flags that the PDPL is less clear than GDPR on security-measure definitions and does not clarify breach-notification exceptions for controllers or processors. ROPA and joint-controller specifics were not located.

Periodic update · new data 2026-09-28

Controller/Processor Duties

The Executive Regulations introduce operative controller and processor duties that were previously undefined in practice. Data users must appoint a Data Protection Officer in applicable cases and are subject to licensing obligations as data users, a status distinct from mere registration. Breach notification is now concrete and time-bound: notification to the PDPC is required within 72 hours of a controller becoming aware of a breach, with immediate notification required where the breach touches national security, and affected individuals must be informed within three business days. These are the most fully specified new obligations in the current evidence base and represent a clear escalation from the principle-level duties in the underlying 2020 law to enforceable operational deadlines.

Outlook

These duties are enacted but not yet effective in the sense that full penalty exposure attaches only once the transitional grace period ends on 1 November 2026; controllers and processors have until that date to establish DPO appointments, licensing status and breach-response procedures capable of meeting the 72-hour and three-business-day windows.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (4)
  1. UncertainOneTrust DataGuidance — Under the Executive Regulations, all controllers and processors must appoint an accredited Data Protection Officer, although the PDPL itself does not specify DPO qualifications.observed
  2. UncertainOneTrust DataGuidance — The content and manner of carrying out Data Protection Impact Assessments under the PDPL is not detailed in the primary law and is expected to be clarified further by executive regulation.observed
  3. UncertainOneTrust DataGuidance — The PDPL is less clear than the GDPR in its definitions of the security measures required of controllers and processors.observed
  4. UncertainOneTrust DataGuidance — Unlike the GDPR, the PDPL does not clarify exceptions from breach-notification requirements or processor-notification requirements.observed

#

A binding license-based transfer-restriction regime is confirmed, but GDPR-style adequacy/SCC/BCR/TIA architecture is absent or unconfirmed.

Primary frameworkLaw No. 151 of 2020 (PDPL), Executive Regulations No. 816/2025
Supervisory authorityPersonal Data Protection Center (PDPC)
Traffic-light rationale — AmberA binding license-based transfer-restriction regime is confirmed, but GDPR-style adequacy/SCC/BCR/TIA architecture is absent or unconfirmed.

Sub-modules (6)

Transfer MechanismsAmber

Cross-border transfer is prohibited absent an equivalent protection level and a PDPC license/authorization; Executive Regulations add consent and record-keeping requirements.

Claims (2):

  • The PDPL prohibits transfer, storage, or sharing of personal data collected or prepared for processing to a foreign state unless the destination applies a protection level not less than the PDPL and a license or authorisation is obtained.
  • Under the Executive Regulations, cross-border transfers require a PDPC license, appropriate security measures, detailed transfer records, and data-subject consent.

Adequacy ReceivedRed

No adequacy decision received by Egypt from another regime was identified in the sources searched.

Absence provenance: unavailable. Searched: Egypt PDPL adequacy decision received EU UK.

Adequacy GrantedRed

No adequacy decision granted by Egypt to another jurisdiction was identified in the sources searched.

Absence provenance: unavailable. Searched: Egypt PDPC adequacy decision granted foreign country.

Sccs And BcrsRed

No standard-contractual-clause or binding-corporate-rules instrument was identified; the PDPL instead relies on a licensing model for transfers.

Absence provenance: unavailable. Searched: Egypt PDPL standard contractual clauses binding corporate rules.

Transfer Impact AssessmentRed

No formal transfer-impact-assessment methodology distinct from the general 'appropriate security measures' requirement was identified.

Absence provenance: unavailable. Searched: Egypt PDPL transfer impact assessment.

Data LocalisationAmber

No absolute data-localisation mandate was identified beyond the CBE sectoral carve-out; NTRA has issued a data-centre establishment framework relevant to infrastructure siting.

Category narrative74 words

The PDPL prohibits transfer, storage, or sharing of personal data with a foreign state unless the destination affords protection not less than the PDPL and a PDPC license/authorization is obtained. The Executive Regulations operationalize this via a licensing requirement paired with security measures, data-subject consent, and detailed transfer records. No adequacy-decision mechanism (received or granted), SCC/BCR instrument, formal transfer-impact-assessment methodology, or absolute data-localisation mandate beyond the CBE carve-out was identified in the sources reviewed.

Periodic update · new data 2026-09-28

Cross-Border & Adequacy

Cross-border personal data transfers are now subject to a licensing requirement under the Executive Regulations, in addition to a standing requirement for explicit data-subject consent. No adequacy decisions issued by or in respect of Egypt were identified this cycle, and no SCC-equivalent or BCR-equivalent transfer mechanism was located in the available sourcing. On the current evidence, PDPC licensing plus explicit consent is the sole lawful transfer basis in the regime, which is a materially narrower set of options than jurisdictions offering a menu of adequacy, standard clauses and binding corporate rules. This narrows the practical routes available to any organisation moving Egyptian personal data outside the country's borders once the transitional period ends.

Outlook

Whether the PDPC develops or publishes an adequacy framework, or an SCC/BCR-equivalent instrument, ahead of or after the 1 November 2026 deadline is the open question on this dimension; nothing in the current record indicates such a mechanism is under development.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (2)
  1. UncertainOneTrust DataGuidance — The PDPL prohibits transfer, storage, or sharing of personal data collected or prepared for processing to a foreign state unless the destination applies a protection level not less than the PDPL and a license or authorisation is obtained.observed
  2. UncertainOneTrust DataGuidance — Under the Executive Regulations, cross-border transfers require a PDPC license, appropriate security measures, detailed transfer records, and data-subject consent.observed

#

Financial and telecom overlays are documented; other sectoral overlays are unconfirmed gaps.

Primary frameworkLaw No. 151 of 2020 (PDPL); Telecom Regulation Law No. 10/2003; Anti-Cyber and IT Crimes Law No. 175/2018
Supervisory authorityPersonal Data Protection Center (PDPC)
Traffic-light rationale — AmberFinancial and telecom overlays are documented; other sectoral overlays are unconfirmed gaps.

Sub-modules (7)

Financial Sector OverlayAmber

CBE and CBE-supervised entities are exempt from PDPL, except money-transfer/forex firms subject to CBE data rules.

Claims (1):

  • Personal data held by the Central Bank of Egypt and entities subject to its control and supervision is excluded from the PDPL, except for money-transfer and forex companies which must observe CBE-established personal-data rules.

Health Sector OverlayRed

No health-sector-specific DP overlay was identified in the sources searched.

Absence provenance: unavailable. Searched: Egypt health data protection sector law.

Telecoms And EprivacyAmber

NTRA enforces telecom-sector rules, including action against unsolicited SMS/spam under Telecom Law 10/2003 and Law 175/2018.

Claims (1):

  • The National Telecom Regulatory Authority (NTRA) has pursued enforcement action, including referrals to public prosecution, against companies sending unsolicited SMS messages in violation of the Telecom Regulation Law No. 10 of 2003 and the Anti-Cyber and Information Technology Crimes Law No. 175 of 2018.

Employment DataRed

No employment-data-specific overlay was identified in the sources searched.

Absence provenance: unavailable. Searched: Egypt employment data protection code labour law.

Credit And ScoringRed

No credit-scoring-specific overlay was identified in the sources searched.

Absence provenance: unavailable. Searched: Egypt credit scoring data protection rules.

EducationRed

No education-sector-specific overlay was identified in the sources searched.

Absence provenance: unavailable. Searched: Egypt education sector student data protection rules.

InsuranceRed

No insurance-sector-specific overlay was identified in the sources searched.

Absence provenance: unavailable. Searched: Egypt insurance sector data protection rules.

Category narrative69 words

The Central Bank of Egypt (CBE) and CBE-supervised entities are exempted from the general PDPL regime (except money-transfer and forex companies, which must follow CBE-established data rules), creating a financial-sector overlay. Telecoms sit under NTRA authority (Telecom Regulation Law No. 10/2003) with active enforcement against spam/unsolicited messaging alongside the Anti-Cyber and Information Technology Crimes Law No. 175/2018. No health, employment, credit-scoring, education, or insurance sector-specific DP overlays were identified.

Sources and claims (2)
  1. UncertainOneTrust DataGuidance — Personal data held by the Central Bank of Egypt and entities subject to its control and supervision is excluded from the PDPL, except for money-transfer and forex companies which must observe CBE-established personal-data rules.observed
  2. UncertainOneTrust DataGuidance — The National Telecom Regulatory Authority (NTRA) has pursued enforcement action, including referrals to public prosecution, against companies sending unsolicited SMS messages in violation of the Telecom Regulation Law No. 10 of 2003 and the Anti-Cyber and Information Technology Crimes Law No. 175 of 2018.observed

#

Direct-marketing licensing is confirmed; the remaining adtech sub-domains are unconfirmed gaps typical of a still-maturing regime.

Primary frameworkExecutive Regulations No. 816/2025 to the PDPL
Supervisory authorityPersonal Data Protection Center (PDPC)
Traffic-light rationale — AmberDirect-marketing licensing is confirmed; the remaining adtech sub-domains are unconfirmed gaps typical of a still-maturing regime.

Sub-modules (6)

Cookies And TrackersRed

No PDPL-specific cookie/tracker consent regime was identified in the sources searched.

Absence provenance: unavailable. Searched: Egypt PDPL cookie consent tracker rules.

Dark PatternsRed

No dark-pattern prohibition was identified in the sources searched.

Absence provenance: unavailable. Searched: Egypt PDPL dark patterns prohibition.

Opt Out SignalsRed

No recognition of opt-out signals (e.g., Global Privacy Control) was identified in the sources searched.

Absence provenance: unavailable. Searched: Egypt PDPL Global Privacy Control opt-out signal.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rule was identified in the sources searched.

Absence provenance: unavailable. Searched: Egypt PDPL data clean room data collaboration.

Cross Context AdvertisingRed

No cross-context-advertising ('sale'/'share') framework analogous to CPRA was identified in the sources searched.

Absence provenance: unavailable. Searched: Egypt PDPL cross-context advertising sale share personal data.

Direct MarketingAmber

Electronic direct marketing requires a PDPC license/permit under the Executive Regulations.

Claims (1):

  • Electronic direct marketing activities require a license or permit from the PDPC under the Executive Regulations to the PDPL.
Category narrative31 words

Electronic direct marketing is licensable activity under the Executive Regulations. No Egypt-specific cookie/tracker consent regime, dark-pattern prohibition, opt-out-signal (GPC/DAA) recognition, clean-room/DCR rule, or cross-context-advertising framework was identified in the sources reviewed.

Sources and claims (1)
  1. UncertainOneTrust DataGuidance — Electronic direct marketing activities require a license or permit from the PDPC under the Executive Regulations to the PDPL.observed

#

Biometric/genetic licensing is confirmed; ADM transparency, profiling restrictions, AI risk assessment and surveillance carve-outs remain unconfirmed or purely aspirational.

Primary frameworkLaw No. 151 of 2020 (PDPL), Executive Regulations No. 816/2025
Supervisory authorityPersonal Data Protection Center (PDPC)
Traffic-light rationale — AmberBiometric/genetic licensing is confirmed; ADM transparency, profiling restrictions, AI risk assessment and surveillance carve-outs remain unconfirmed or purely aspirational.

Sub-modules (6)

Profiling RestrictionsRed

No Article-22-style profiling restriction was identified in the sources searched.

Absence provenance: unavailable. Searched: Egypt PDPL profiling restriction automated decision.

Automated Decision Making TransparencyRed

No ADM-transparency/explanation right was identified in the sources searched.

Absence provenance: unavailable. Searched: Egypt PDPL automated decision making transparency right.

Ai Risk AssessmentsRed

MCIT strategy references development of AI and data-protection laws, but no enacted AI-risk-assessment obligation was confirmed.

Claims (1):

  • Egypt's MCIT has articulated a strategy aimed at protecting personal data and developing AI and data-protection laws, though no enacted AI-specific risk-assessment obligation was confirmed.

Biometric RegimeAmber

Biometric data is a PDPL sensitive category requiring a PDPC license to process.

Claims (1):

  • Biometric data is enumerated as PDPL sensitive data, and its processing requires a PDPC license under the Executive Regulations.

Genetic DataAmber

Genetic data is a PDPL sensitive category requiring a PDPC license to process.

Claims (1):

  • Genetic data is enumerated as PDPL sensitive data, and its processing requires a PDPC license under the Executive Regulations.

State Surveillance CarveoutsRed

No state-surveillance/national-security carve-out provision was identified in the sources searched.

Absence provenance: unavailable. Searched: Egypt PDPL national security exemption surveillance carve-out.

Category narrative55 words

Biometric and genetic data are enumerated PDPL sensitive categories requiring a PDPC license to process. Egypt's Ministry of Communications and Information Technology has an aspirational strategy to develop AI-specific and further data-protection laws, but no enacted AI-risk-assessment regime, Article-22-style profiling restriction, ADM transparency right, or state-surveillance carve-out provision was independently confirmed in the sources reviewed.

Sources and claims (3)
  1. UncertainOneTrust DataGuidance — Biometric data is enumerated as PDPL sensitive data, and its processing requires a PDPC license under the Executive Regulations.observed
  2. UncertainOneTrust DataGuidance — Genetic data is enumerated as PDPL sensitive data, and its processing requires a PDPC license under the Executive Regulations.observed
  3. SpeculativeOneTrust DataGuidance — Egypt's MCIT has articulated a strategy aimed at protecting personal data and developing AI and data-protection laws, though no enacted AI-specific risk-assessment obligation was confirmed.observed

#

Minors' data is nominally sensitive/protected, but the mechanics (age threshold, parental consent, profiling ban) are confirmed absent by comparative analysis.

Primary frameworkLaw No. 151 of 2020 (PDPL)
Supervisory authorityPersonal Data Protection Center (PDPC)
Traffic-light rationale — AmberMinors' data is nominally sensitive/protected, but the mechanics (age threshold, parental consent, profiling ban) are confirmed absent by comparative analysis.

Sub-modules (5)

Age VerificationRed

The PDPL does not set an explicit age threshold for processing a minor's data without holder-of-parental-responsibility consent, unlike GDPR Art 8.

Claims (1):

  • Minors' data is listed as PDPL sensitive data, but unlike the GDPR, the PDPL does not refer to an age threshold for processing a child's data without parental-responsibility-holder consent and does not explicitly address children's data.

Minor Profiling BansRed

No minor-specific profiling ban was identified in the sources searched.

Absence provenance: unavailable. Searched: Egypt PDPL minor profiling ban children.

Education SettingsRed

No education-setting-specific children's-data provision was identified in the sources searched.

Absence provenance: unavailable. Searched: Egypt PDPL education setting student data minors.

Dependent AdultsRed

No dependent-adult-specific protection provision was identified in the sources searched.

Absence provenance: unavailable. Searched: Egypt PDPL dependent adults elderly incapacitated protection.

Category narrative50 words

Minors' data is listed among PDPL sensitive/special categories, warranting heightened (licensed) treatment, but comparative legal analysis confirms the PDPL does not set an explicit age-of-consent threshold or a parental-consent mechanism analogous to GDPR Article 8, and does not otherwise explicitly address children's data. No education-setting or dependent-adult-specific provisions were identified.

no periodic updates on record for this sub-brief

Sources and claims (1)
  1. UncertainOneTrust DataGuidance — Minors' data is listed as PDPL sensitive data, but unlike the GDPR, the PDPL does not refer to an age threshold for processing a child's data without parental-responsibility-holder consent and does not explicitly address children's data.observed

#

Enforcement architecture (courts + PDPC) and a major 180-day-window development are confirmed; enforcement track record, funding, and collective-redress mechanisms remain unconfirmed given the regime's pre-operative status.

Primary frameworkLaw No. 151 of 2020 (PDPL), Executive Regulations No. 816/2025
Supervisory authorityPersonal Data Protection Center (PDPC)
Traffic-light rationale — AmberEnforcement architecture (courts + PDPC) and a major 180-day-window development are confirmed; enforcement track record, funding, and collective-redress mechanisms remain unconfirmed given the regime's pre-operative status.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

Economic and Ordinary courts may adjudicate disputes and violations of the PDPL alongside PDPC administrative enforcement.

Claims (1):

  • Economic and Ordinary courts in Egypt may be involved in adjudicating disputes or cases related to data breaches and violations of the PDPL.

Enforcement Activity IndexRed

No specific PDPC fines or enforcement-decision index was identified in the sources searched, consistent with the regime's pre-operative/grace-period status.

Absence provenance: unavailable. Searched: Egypt PDPC enforcement fines decisions 2025 2026.

Regulator Funding And CapacityRed

No PDPC funding or headcount data was identified in the sources searched.

Absence provenance: unavailable. Searched: Egypt PDPC budget staffing headcount capacity.

Collective Redress And Class ActionsRed

No collective-redress or class-action mechanism specific to PDPL claims was identified in the sources searched.

Absence provenance: unavailable. Searched: Egypt PDPL collective redress class action data subjects.

Private Right Of ActionAmber

Data subjects may access Economic and Ordinary courts for PDPL-related disputes, providing a general civil-litigation route, though no PDPL-specific private-right-of-action clause distinct from general court jurisdiction was confirmed.

Claims (1):

  • Economic and Ordinary courts in Egypt may be involved in adjudicating disputes or cases related to data breaches and violations of the PDPL.

Recent Developments 180DAmber

The Executive Regulations No. 816/2025 were issued 1 November 2025 and their contents were still being clarified by practitioners as of February 2026, with a compliance grace period running to 31 October 2026; the PDPC has separately published implementation guidelines and templates.

Claims (2):

  • The Executive Regulations of the Egyptian PDPL were officially issued on 1 November 2025, giving controllers and processors a one-year grace period to comply, ending 31 October 2026, with initial regulatory scrutiny expected to target large-scale personal-data holders.
  • The PDPC has published guidelines and templates to aid organisations' compliance with the Personal Data Protection Law.
Category narrative73 words

Both PDPC administrative processes and the Economic and Ordinary courts may adjudicate PDPL disputes and violations. The most significant recent development is the November 2025 issuance of Executive Regulations No. 816/2025 (publicly confirmed by February 2026), commencing a one-year grace period to 31 October 2026, with initial regulatory scrutiny expected to target large-scale data holders. No fines/enforcement-decision index, regulator funding/headcount data, collective-redress mechanism, or explicit private-right-of-action provision beyond general court jurisdiction was confirmed.

Periodic update · new data 2026-09-28

Enforcement & Redress

The Executive Regulations establish a penalty framework of imprisonment and/or fines of up to EGP 5,000,000, with enforcement jurisdiction sitting with Egypt's Economic Courts and PDPC staff holding judicial-control powers. No published enforcement decisions have been located for Egypt to date, consistent with a regime that has only just entered the transitional grace period and has not yet reached the point of full penalty exposure. A distinct operational signal is that, as of a 10 September 2026 verification, the PDPC's public-facing Licenses and Permits electronic portal was not reachable from the regulator's own public site, despite the approaching 1 November 2026 enforcement deadline that conditions data-user and cross-border-transfer licensing on exactly that mechanism. This is a readiness gap worth tracking rather than a substantive change to the penalty framework itself.

Outlook

The key date remains 1 November 2026. Whether the licensing portal becomes functional before that date, and whether the Economic Courts and PDPC begin issuing decisions once full enforcement applies, are the two concrete signals to watch for the next assessment of Egypt's enforcement posture.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (3)
  1. UncertainOneTrust DataGuidance — Economic and Ordinary courts in Egypt may be involved in adjudicating disputes or cases related to data breaches and violations of the PDPL.observed
  2. UncertainOneTrust DataGuidance — The Executive Regulations of the Egyptian PDPL were officially issued on 1 November 2025, giving controllers and processors a one-year grace period to comply, ending 31 October 2026, with initial regulatory scrutiny expected to target large-scale personal-data holders.observed
  3. UncertainOneTrust DataGuidance — The PDPC has published guidelines and templates to aid organisations' compliance with the Personal Data Protection Law.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

Blocking. 1 failing check(s).

schema_validpass
min_t1_per_instrument_metwaived
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metFAIL
tier_a_b_national_primary_pct0.0
aggregator_only_jurisdiction_count1
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Egypt
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 28 claim(s) (28 category placement(s)), 19 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (14 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 13-22Data Subject Rightsaccess right
Art. 32-34Controller/Processor Dutiessecurity measures
Art. 37-39Controller/Processor Dutiesdpo requirements
Art. 44-49Cross-Border & Adequacytransfer mechanisms
Art. 77-84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules were populated. regulator_and_framework, lawful_processing_and_special_data (partial), data_subject_rights (partial), controller_processor_duties (partial), cross_border_and_adequacy (partial), sectoral_watch (partial: financial + telecom only), adtech_and_commercial_privacy (partial: direct marketing only), algorithmic_biometric_and_surveillance_governance (partial: biometric/genetic only), children_and_vulnerable_groups (age/parental-consent gap explicitly confirmed absent), and enforcement_and_redress (partial) all relied exclusively on T3 commercial legal-intelligence secondary sources (OneTrust DataGuidance news/notes/opinion/comparative PDF) rather than direct T1 access to the Arabic-language Official Gazette text of Law 151/2020 or Executive Regulations 816/2025, which were not independently retrieved in original-language primary form. No T1 regulator (PDPC) URL or official English-language text was located during this run.

Unresolved questions (6):

  • What is the PDPC's official homepage/URL and does it publish English-language guidance?
  • What specific statutory penalties/fine amounts and imprisonment terms attach to PDPL violations (Articles on penalties were referenced in secondary sources but figures not confirmed)?
  • Does the PDPL/Executive Regulations define a statutory response deadline for data-subject-rights requests?
  • Is there a data-portability right, ROPA obligation, or joint-controller provision in the primary text or Executive Regulations not surfaced by secondary commentary?
  • Are there separate CBE-issued personal-data rules for money-transfer/forex companies that should be tracked as a distinct financial-sector instrument?
  • Will the PDPC show flexibility on the 31 October 2026 compliance grace-period deadline, as anticipated by local practitioners?

Escalate to primary-source review: yes