EgyptIn ForceData Protection

Personal Data Protection Law No. 151 of 2020

eg-pdpl-2020 · Act

Verified entryReviewed by Ademola Adekunbi · 27 June 2026
Summary

Egypt's Personal Data Protection Law No. 151 of 2020 (PDPL) is Egypt's first comprehensive data protection statute. Promulgated on 15 July 2020 and published in the Official Gazette, it establishes the legal framework governing the collection, processing, storage, and transfer of personal data in Egypt. Full operational effect was achieved following the issuance of Executive Regulations by Prime Ministerial Decree No. 816 of 1 November 2025, which triggered a one-year compliance transition period running to October 2026. The PDPL applies to any person, Egyptian or foreign, who collects or processes personal data in Egypt or processes the personal data of individuals residing in Egypt. Foreign controllers and processors without a physical presence in Egypt must appoint a local representative responsible for compliance. The law establishes the Personal Data Protection Centre (PDPC) as Egypt's supervisory authority. Operating under the oversight of the Ministry of Communications and Information Technology, the PDPC is empowered to issue licences and permits for data processing activities, conduct audits and inspections, investigate violations, impose administrative sanctions, and issue binding guidelines. A defining feature of Egypt's regime is its licensing model: entities wishing to process personal data, particularly for commercial purposes, must obtain a licence from the PDPC. The Executive Regulations issued in 2025 elaborate a tiered licensing structure with different requirements based on the nature, purpose, and volume of processing. Processing of personal data must rest on a lawful basis: in most cases, prior written consent of the data subject is required. Explicit consent is mandatory for sensitive personal data, which includes health and medical data, financial data, biometric data, genetic data, data relating to sexual life, criminal records, and data concerning children and minors. Data subjects are granted rights to access their data, to request rectification of inaccurate information, to request erasure in specified circumstances, to restrict processing, and to object. Controllers must respond within prescribed timeframes. Cross-border transfers of personal data from Egypt require prior authorisation from the PDPC and are restricted to countries providing adequate protection or where contractual safeguards are in place. Breach notification must be made to the PDPC within 72 hours of the controller becoming aware of a breach. Criminal penalties include fines and imprisonment for serious violations, with enhanced penalties where sensitive personal data is involved.

Key provisions
  1. Establishes the Personal Data Protection Centre (PDPC) as Egypt's supervisory authority, with powers to licence data processing activities, conduct inspections, investigate violations, and impose sanctions.
  2. Introduces a mandatory licensing regime for personal data processing, requiring entities to obtain licences from the PDPC before undertaking processing activities, with differentiated tiers based on processing nature and volume.
  3. Requires prior written consent from data subjects as the primary lawful basis for processing, with explicit consent mandatory for sensitive categories including health, financial, biometric, and children's data.
  4. Requires foreign controllers and processors without a physical presence in Egypt to appoint a local representative responsible for ensuring compliance with the law.
  5. Restricts cross-border data transfers to countries with adequate protection or under contractual safeguards specifically authorised by the PDPC.
  6. Mandates breach notification to the PDPC within 72 hours of the controller becoming aware of a personal data breach.
  7. Grants data subjects rights of access, rectification, erasure, restriction of processing, and objection, with defined controller response timeframes.
  8. Provides for criminal penalties including fines and imprisonment for serious violations, with enhanced penalties for breaches involving sensitive personal data.
Related instruments
Entry history
Entry history
  1. 23 June 2026
    ATLPF Research Team (AI-assisted)
    Initial draft created from Egyptian Ministry of Communications and Information Technology official documentation