If any copy of personal data about Egyptian customers or staff sits outside Egypt, you need a cross-border transfer licence from the Personal Data Protection Centre (PDPC). The application asks where the data goes, what it is, why it goes there and how it is protected. The Centre has ninety working days to decide, and if it says nothing, the answer is no.
This briefing explains what the licence covers, what the application actually asks for, and why the order in which organisations file matters more than the 31 October 2026 date. It follows our longer piece, Storage abroad is a transfer, and like that piece it is not legal advice.
1What needs a licence
Any cross-border transfer of personal data, and storage abroad counts as a transfer. Article 16 of the Executive Regulations describes it broadly: transfer, storage, sharing, processing or making personal data available across borders. Article 14 of Law 151 of 2020 prohibits it without an adequate level of protection at the destination and authorisation from the Centre.
In practice that reaches far beyond a deliberate data export. A CRM tenant in a European region, backups replicated to a foreign bucket, an HR platform hosted in the Gulf, a ticketing tool, a video management cloud, a call to a foreign-hosted AI model: each keeps personal data outside Egypt, and each is in scope.
2What the application asks for
The application is a description of your architecture, not a form of words. According to the article-level renderings of Articles 24 and 25, a legal person applying must specify:
- the destination the data is transferred to
- the nature of the controller's or processor's activity
- the nature and categories of the personal data
- the security systems, and the temporary and final storage locations
- the purpose of the transfer
- evidence of compliance, and the retention period
Practitioner summaries add that applicants provide technical details of the infrastructure used, including server types and any certifications held. None of this can be completed without knowing, system by system, where every copy of the data physically sits. That map is the application.
3The ninety-day clock, and why silence matters
The Centre has ninety working days from a complete application to decide, and failure to respond is deemed a rejection. Article 26 states this for transfer applications, and Article 36 applies the same rule to licence applications by legal persons.
Ninety working days is roughly four and a half months. The clock starts when the file is complete, not when it is first submitted, so an application returned for missing information starts again. An application filed in mid-September 2026 is unlikely to be decided before the end of January 2027.
This is why the deadline is better understood as a queue than a cliff. The organisations that file complete applications first are decided first. Everyone else remains in scope, and unlicensed, while the Centre works through the files ahead of them.
4What it costs
A cross-border transfer licence is priced at fifty per cent of the controller or processor licence fee for your tier. The main fee is banded by the number of personal records held, from exempt below 100,000 records to a statutory maximum reported at EGP 2,000,000 for volumes above five million records, over a three-year term. Our pillar briefing sets out the bands in more detail.
5What changes after you are licensed
The licence describes a destination, so a vendor's infrastructure change can put you outside it. If a SaaS provider migrates your tenant to another region or adds a sub-processor in a new country, the authorisation no longer matches reality. Few Egyptian organisations have a contractual right to advance notice of such changes. It is worth asking for one, in writing, at the next renewal.
6A sequence that works
- Count the personal records you hold, including employee data. The number sets the fee tier.
- Map every system holding personal data: the country it runs in, the vendor, its sub-processors, and where its backups and disaster recovery copies go.
- Decide which flows stay abroad under a licence and which come back into Egypt. This is much cheaper once the map exists.
- Appoint and register a Data Protection Officer, because the officer must be identified in licence submissions.
- File a complete application, so the clock starts on the first submission rather than the second.
7Where we might be wrong
- Adequacy. Article 16 says the Centre will determine which countries offer adequate protection. We have not seen a published list, and at least one firm has flagged that adequacy is uncertain for United States infrastructure.
- Article numbering. English renderings of the Executive Regulations differ in places. The article numbers above follow the Consortio rendering; check them against the Arabic text before citing them in a filing.
- Portal status. We could not confirm from public sources how many transfer licences have been issued or how long decisions are taking in practice.
- Fees. Reported fee figures come from practitioner summaries of the fee tables, not from the gazetted text.
Get Egyptian counsel before you file. If you want the map built first, that is what our 90-minute data audit does.
Sources
Executive Regulations, article level: Consortio Law Firm English rendering, ID Law Firm overview including fee tables, Consortio on cross-border transfer licence rules
Primary law in translation: Law 151 of 2020, Matouk Bassiouny translation via ACC
Practitioner alerts: Baker McKenzie, Clyde & Co, Kennedys, CMS
Spotted something wrong?
This briefing is our reading of a regime that is still moving. If part of it is wrong, tell us and we will correct it here, dated and in public.
Email a correction →