Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
EgyptChecked 18 August 2026
Yes, with paperworkWork: Very highEnforcement: Waking up
In one paragraph
Egypt now runs a full permission system. You need a government licence just to handle people's data, and a second licence on top of that to send any of it out of the country. Using a cloud service whose servers sit abroad counts as sending it out. The detailed rules finally arrived on the first of November 2025 and every organisation has until early November 2026 to get licensed.
The catch
The licence route is the general answer, not the whole answer. Companies using financial technology in Egypt's non-bank finance sector must keep their customer database physically inside Egypt. Banks are cut out of the privacy law altogether and follow the central bank's own rulebook instead. Health research samples and street camera footage have their own hard walls, and breaking the health one is a prison offence.
Does this apply to me?
Yes. The law follows the person, not the office. It covers the data of Egyptian citizens wherever in the world they live, and of anyone else living in Egypt. If your company has no office or branch in Egypt but handles that data, you must appoint a legal representative inside Egypt, and the regulator has to approve your choice. No size or revenue level lets you off. Licence fees rise with how many people's records you hold, but there is no floor below which you are free.High confidence
Can the data leave the country?
Only with written permission from the regulator, granted to you specifically. Sending personal data out of Egypt is banned unless you hold a cross-border transfer licence or permit from the Personal Data Protection Centre, or your case falls inside a short list of emergencies. Storing data with a cloud provider whose servers are outside Egypt is treated as sending it out. Two industries are stricter still: financial technology firms in non-bank finance must keep the customer database inside Egypt, and footage from cameras in public places may not leave at all except where a law says so.High confidence
What do I have to do to send it abroad?
You apply, and you wait. First you need a general licence to process data at all. Then you apply for a separate cross-border transfer licence. To get it you must show either that the destination country is on the regulator's approved list, or that you have extra protections in place, such as the contract wording the regulator recommends. The approved list has not been published yet, so in practice everyone is on the second route. The regulator has ninety days to decide, and silence means refusal.High confidence
Who enforces this — and are they actually working?
The Personal Data Protection Centre, and unlike many countries with a paper regulator, this one is real and working. It has staff, departments, a chief executive in an acting capacity, a published set of guidelines updated in January 2026, an online application portal and a training programme for data protection officers. What it has not done yet is punish anyone in public. Its own website page for decisions is empty, and so are its news, press release and annual report pages. Sector regulators for banking, non-bank finance, telecoms and medicines have been enforcing for years.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling, and they come from different laws. The ceiling is the storage limitation rule: you may not keep personal data longer than the purpose you collected it for. The floors we could verify are narrow. Marketing consents and opt-out requests must be kept for at least three years. Internet and technology service providers must keep their system records for one hundred and eighty days in a row. Breach paperwork must be kept as well.Medium confidence
What happens when something goes wrong?
Two clocks run one after the other. You have seventy-two hours from the moment you find out to tell the regulator, and if the breach touches national security you must tell it immediately with no grace period at all. Then you have three working days from the date you notified the regulator to tell the people affected, including what you did to contain the damage. The regulator publishes a form for each of those two notifications.High confidence
What's the trap?
Five things catch people out. First, you need a licence to touch personal data at all, not just to move it abroad, and you cannot get one without a data protection officer registered with the regulator. Second, breaking the transfer rules is a crime, not a fine: at least three months in prison plus a penalty of up to five million Egyptian pounds, roughly one hundred thousand United States dollars. Third, children means under eighteen, in two stages. Fourth, banks are outside the privacy law but money changers are not. Fifth, you have six working days, not a month, to answer someone who asks about their data.High confidence
What's about to change?
One date dominates. The detailed rules were published on the first of November 2025 and took effect the next day, starting a one-year window to get licensed. That window closes at the beginning of November 2026. After it, processing personal data without the right licence is simply a breach of the law. Everything else that matters is a switch the government already holds and can flip without warning.High confidence
Hardest industry wall
  • Finance قرار مجلس إدارة الهيئة العامة للرقابة المالية رقم 139 لسنة 2023 (Financial Regulatory Authority Board Decision No. 139 of 2023)
AlgeriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
In one paragraph
Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
The catch
The national rule is already strict, and three areas are stricter still. Online shops must run their site on servers inside Algeria under a .com.dz address. Electronic trust services, such as digital signatures and electronic identity, must host all the data they collect inside Algeria. Public bodies must exchange data only over a state-run network that is deliberately kept separate from the internet. Banking, insurance and securities have no storage rule that we could find, but the central bank's own website could not be reached, so treat that as unchecked rather than settled.
Does this apply to me?
Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.High confidence
Can the data leave the country?
Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.High confidence
What do I have to do to send it abroad?
The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.High confidence
Who enforces this — and are they actually working?
The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.High confidence
What happens when something goes wrong?
There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.High confidence
What's the trap?
Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.High confidence
What's about to change?
Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.High confidence
Hardest industry wall
  • Telecoms Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique
  • E-commerce Loi n° 18-05 relative au commerce electronique
  • Government Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees