Most of what has been written about Egypt's Personal Data Protection Law since the executive regulations appeared has been written for lawyers. It describes obligations, lists penalties, and stops.
This piece is written for the people who will actually have to comply: the CIO who does not know how many copies of the customer database exist, the CFO who signed a three-year SaaS contract in dollars, and the general manager who is now personally exposed. The law's demands are not primarily legal. They are architectural. And the gap between what most Egyptian corporates have and what the regulations assume is wider than the compliance conversation has so far admitted.
We built the ETA e-invoicing integration for our own systems and for our clients, so we spend our working lives inside Egyptian corporate data. What follows is our reading of what the regulations mean for the systems themselves. It is not legal advice, and section 9 sets out where the sources genuinely conflict and where you should not rely on us.
1Where things actually stand
Law 151 of 2020 sat without teeth for five years. That ended.
The Executive Regulations were issued and published in the Official Gazette on 1 November 2025, by decree of the Minister of Communications and Information Technology (numbered 816 of 2025 in most reporting), and entered into force on 2 November 2025. The text itself did not circulate widely among practitioners until late December, which is why the first serious client alerts are dated January 2026. If you have seen the date given as December 2025, that is the circulation date, not the issuance date.
The regulations grant a one-year transition period. Sources place its end at either 31 October or 1 November 2026, depending on whether they count from issuance or from entry into force. That one-day ambiguity does not matter operationally. What matters is that it is now August.
The Personal Data Protection Center is the supervisory body. Its acting chief executive has said publicly that the Center expects to be fully operational by November 2026, that entities should begin applying for licences from November, and that it does not intend to open with a full-scale audit and inspection phase, preferring to help organisations reach compliance first. That is a soft-landing signal and it is worth hearing accurately: it is a statement about enforcement posture, not about the legal position. The obligations bind regardless.
2The sentence that turns this into an architecture problem
Article 14 of the law prohibits transferring personal data outside Egypt without both an adequate level of protection at the destination and authorisation from the Center.
The regulations then define cross-border transfer to include storage.
That single drafting choice is the whole story. It means a transfer does not require anyone to transfer anything. If your CRM tenant sits in a European region, that is a transfer. If your backups replicate to a bucket in Ireland, that is a transfer. If your analytics warehouse, your HR system, your ticketing tool, your email, or your group's shared reporting environment runs on infrastructure outside Egypt, each of those is a transfer, continuously, every day, whether or not a single record is ever exported by a human being.
And then the second half: violating the cross-border rules is a criminal offence under Article 42, carrying imprisonment of not less than three months and a fine of EGP 500,000 to 5,000,000.
There is no version of this that a policy document solves. Either you know where every copy of personal data physically sits, or you do not.
3If you assumed GDPR compliance was enough
Many Egyptian corporates, particularly those with European parents or European customers, have a GDPR programme and have quietly assumed it covers them. It does not, and the reason is structural rather than a matter of detail.
GDPR is an accountability regime. Egypt's is a prior-authorisation regime. Under GDPR you establish a lawful basis, document your reasoning, and proceed. In Egypt you apply for permission and wait. Processing without a licence is not a compliance shortfall to be remediated. It is unlawful processing, and under Article 45 it carries EGP 500,000 to 5,000,000.
Six specific divergences will catch a GDPR-shaped programme:
Every legal entity needs a licence. There is no small-business exemption from the licence itself. Record volume affects the fee, not the requirement. A company holding fewer than 100,000 records pays nothing and still must be licensed.
Data subject requests must be answered in six working days, not thirty. That is five times faster than GDPR. Existing request workflows, which typically assume weeks of internal circulation, will simply fail.
Every legal entity must appoint a Data Protection Officer. There is no risk-based threshold. The DPO must hold relevant qualifications, pass an examination approved by the Center, hold a clean criminal record, and be registered with the Center on renewable two-year terms. Each DPO receives an identification code tied to the volume and categories of data they are accredited for. Practitioners report that the Center has already flagged difficulty with foreign-appointed DPOs. A group DPO sitting in London who has not sat the Egyptian examination does not satisfy this.
There are no Standard Contractual Clauses and no Binding Corporate Rules. The mechanisms that make GDPR international transfers manageable at scale have no Egyptian equivalent. Each transfer is licensed, and the licence names the destination country.
Consent notices and forms must be in Arabic.
Silence on a licence application means rejection, not deemed approval. Combined with a review period of ninety working days from a complete application, that is a real planning risk rather than an administrative footnote.
One more, reported by practitioners and worth verifying with counsel before you rely on it either way: the Egyptian regime is understood to lack a legitimate interests basis. If your fraud prevention, your marketing analytics or your security monitoring rests on legitimate interests in your GDPR documentation, it may have no Egyptian equivalent at all.
4The question your architecture has to be able to answer
Strip away the legal vocabulary and the regulations reduce to a small number of questions about your systems. Our experience is that most Egyptian corporates cannot answer any of them quickly, and several cannot answer them at all.
Where does every copy of personal data physically sit right now? Not where the primary system runs. Every copy. Production, replicas, backups, disaster recovery, the analytics warehouse, the extract someone built for a board pack, every SaaS tool that holds a customer or employee record, and the sub-processors your SaaS vendor uses that you have never been told about. This is the question the transfer licence application actually asks, because it requires you to name the destination country, the receiving entity, the purpose, the data categories, and the security measures at the storage location.
What happens when your vendor moves you? The licence names a country. If your SaaS provider migrates your tenant to a different region, adds a new sub-processor, or opens a new data centre and rebalances, your authorisation no longer describes your reality and you need fresh approval. Almost no Egyptian corporate has a contractual right to be told in advance. This is worth raising at your next renewal, in writing.
Can you produce a record of processing that an inspector can read directly? The regulations require secure internal electronic records structured so the Center can inspect them without a third party interpreting them, and Center inspectors hold judicial officer status with authority to access those records. The record must cover consent and its form and timing, data categories, purposes, recipients, retention periods, security measures, access controls, requests received and how they were handled, erasure requests and confirmation of erasure, and breach incidents. This is not the flexible Article 30 register. It is designed to be read by the state on demand.
Can you find every record about one person, across every system, in six working days? Including the warehouse, the archived exports, the ticketing system and the WhatsApp attachments. If that requires a developer to write a query for each system, you will miss the deadline on the first request that matters.
Can you delete, and prove you deleted? Erasure has to reach everywhere, including backups, and the record of processing has to show it happened. Note that the regulations permit rendering data non-identifiable as an alternative to deletion, but anonymisation is not yet regulated, so the standard for doing so acceptably does not exist yet. Treat it as unavailable until the Center says otherwise.
Would you know about a breach within seventy-two hours? The clock to notify the Center runs from awareness, and notification to affected individuals is due within three working days of notifying the Center. No source identifies any materiality threshold, unlike GDPR's "unlikely to result in a risk" gate. If you have no logging and no anomaly detection, your seventy-two hours starts when a customer complains on Facebook.
Do you know how many personal records you hold? You will need the number, because the fee is banded by record count and the curve is steeply convex. Under 100,000 records is exempt. At a million the annual fee jumps roughly fivefold. Above five million it reaches EGP 666,666 a year, which is EGP 2 million across the three-year licence term. A cross-border transfer licence adds fifty per cent of the equivalent tier. Direct electronic marketing is separately licensed at ten per cent of the main fee for your own products, twenty-five per cent if you market on behalf of others.
And do not forget your own staff. Employee data is fully in scope with no internal-processing exemption, and workplace CCTV makes you a controller. For a large employer, HR and access-control data alone can push you across a fee band before a single customer record is counted.
5The timing squeeze nobody planned for
The transition period began on 2 November 2025. Applications are filed electronically through the Center's portal, which practitioners reported as expected in May or mid-June 2026. A complete application is decided within ninety working days, and silence means rejection.
Do the arithmetic. Ninety working days is roughly four and a half months. If you file in September, a decision may not arrive before the transition period ends. Several firms have characterised the genuinely usable runway as around five months from the portal opening, against a twelve-month period on paper.
Confirm the portal's current status with the Center or with counsel before you plan around it. We could not verify from public sources whether it opened on schedule or whether licences have in fact been issued. What is clear is that a licence application is not something to begin in October.
6If you are a bank, read this line carefully
The law exempts data held by the Central Bank of Egypt and by entities under its supervision. Money transfer and currency exchange companies are expressly carved back in.
This is a significant and commercially important divergence from most regimes, and it is frequently misreported. It does not exempt you from the Central Bank's own outsourcing framework, which is a separate and in practice more demanding constraint: the CBE does not register outsourcing service providers located outside Egypt. Between the two regimes, the practical result for a regulated bank is the same. Your data stays in Egypt.
Also exempt: personal data held by individuals for personal use, official statistics, exclusively journalistic use, judicial and investigative records, and national security authorities, which the practice guides identify institutionally as the Presidency, the Ministry of Interior, the Ministry of Defence and the General Intelligence Service.
Medical records are not exempt. Health data is treated as sensitive data requiring heightened protection, not excluded.
7The flank that has no ceiling
The fines look survivable. EGP 5 million is roughly a hundred thousand dollars, which for a large Egyptian corporate is a bad quarter, not an existential event.
Two things make that reading wrong.
First, convictions are published. Article 48 requires the court to order publication of the judgment in two widely circulated newspapers and on open electronic networks, at the convicted party's expense. Recidivism doubles the penalties. For most Egyptian corporates the newspaper is worse than the fine.
Second, and more importantly, the civil route has no cap. In 2025 the Economic Court of Alexandria awarded EGP 10 million to a single individual against a telecom operator over an unauthorised SIM replacement that compromised the claimant's data. That is double the maximum regulatory fine, for one claimant. The court reached it by treating the operator as custodian of a hazardous object under Article 178 of the Civil Code, which imposes presumed liability without proof of fault. Defences of fraud, employee error and technical failure were all rejected. The operator could have escaped only by proving force majeure.
Note what the court did: it applied the PDPL directly, in a period when the executive regulations did not yet exist and most of the law was widely considered inoperable. The regulator has signalled a gentle start. The courts have not.
8What we would do in the next twelve weeks
In order, and none of it requires waiting for anything.
Count. How many personal records do you hold, across every system including HR? The number determines your fee band and your DPO tier, and you cannot file without it.
Map. Every system that holds personal data, and for each one the country it physically sits in, the vendor, the vendor's sub-processors, and the contractual notice you are owed if any of that changes. This map is the transfer licence application. It is also, in our experience, the artefact that most surprises boards, because the number of systems is always larger than anyone expects and several of them are nobody's responsibility.
Name your DPO and start the accreditation. Registration is a precondition to obtaining any licence, the examination is administered by the Center, and the appointment must be in writing with genuine independence. This has the longest lead time of anything on this list, and it cannot be delegated to a foreign group function.
Fix the six-day clock before you fix anything else. It is the obligation most likely to produce a visible, dated, provable failure, and it is the one your existing processes are least prepared for. If answering "what do you hold about me" requires a developer, you do not have a process, you have a favour.
Read your SaaS contracts for region and sub-processor terms. Then raise the ones that fail at the next renewal, in writing, so there is a record that you asked.
Then, and only then, decide what has to move. Some systems will have to come back inside Egypt. Some can stay abroad under a licence naming the destination. Most companies will be surprised by which is which, and the decision is much cheaper to make once the map exists.
9Where we might be wrong
We would rather be useful than confident, so here is what we could not settle.
- The exact end of the transition period is reported as both 31 October and 1 November 2026, depending on whether the year runs from issuance or entry into force. One firm has also flagged uncertainty over whether the Center might extend enforcement to the end of 2026.
- Whether the Center's portal actually opened in mid-2026 as projected, and whether licences have been issued. We could not verify this publicly.
- The reported right to charge a data subject up to EGP 20,000 for responding to a rights request appears in translated statutory text and is corroborated by one practitioner analysis, and is flatly contradicted by another source. It would be unlawful under GDPR, which is exactly why we would verify it against the Arabic before relying on it.
- The number of lawful bases, and specifically the reported absence of a legitimate interests ground, rests on a single practitioner source. It is consistent with the consent-centric drafting throughout, but verify it.
- Whether a standalone sensitive data licence exists as a distinct instrument is reported by one firm and omitted by others.
- No adequacy list exists yet. The Center may publish one. Until it does, controllers must assess destination countries independently, and at least one firm notes explicitly that adequacy is uncertain for United States infrastructure. Given how much Egyptian corporate data sits on US-hosted SaaS, this is the single most commercially consequential open question in the entire regime.
None of the above is legal advice. Get Egyptian counsel, and get them before you file rather than after.
Raqmix Smart Solutions builds custom software and systems integration for Egyptian and regional enterprises from Cairo, including ETA e-invoicing integration, and is certified to ISO 9001 and to ISO/IEC 42001, the international standard for AI management systems. We wrote this because we could not find it written and we needed it ourselves. If it is useful, take it. If it is wrong somewhere, tell us and we will correct it.
Sources
Primary law in translation: Law 151 of 2020, Matouk Bassiouny translation via ACC, Andersen Egypt translation, MCIT hosted copy
Executive regulations, article level: Consortio Law Firm English rendering, ID Law Firm overview including fee tables
Practitioner alerts: Baker McKenzie, Clyde & Co, Kennedys, Shalakany, CMS, Amereller, Shand & Partners on compliance developments
The Alexandria judgment: Shand & Partners
Spotted something wrong?
This briefing is our reading of a regime that is still moving. If part of it is wrong, tell us and we will correct it here, dated and in public.
Email a correction →