Egypt
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Egypt — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Egypt now runs a full permission system. You need a government licence just to handle people's data. You need a second licence on top of that to send any of it out of the country. Using a cloud service whose servers sit abroad counts as sending it out. The detailed rules finally arrived on the first of November 2025. Every organisation has until early November 2026 to get licensed.
Data governance in Egypt
The eight things that decide how you handle data about people in Egypt. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law follows the person, not the office. It covers the data of Egyptian citizens wherever in the world they live. It also covers anyone else living in Egypt. If your company has no office or branch in Egypt but handles that data, you must appoint a legal representative inside Egypt. The regulator has to approve your choice. No size or revenue level lets you off. Licence fees rise with how many people's records you hold. There is no level below which you are free.
- What you have to do here:
- Appoint a representative
The regulator's own slide deck says what happens if you have no office in Egypt. If you use or store personal data about Egyptian citizens, or about people living in Egypt, you must appoint a legal representative in Egypt. You submit that person to the Personal Data Protection Centre for examination and approval. The representative is then your official point of contact with the Centre. Fees are banded by the number of records you hold, where one record means one person. Associations, unions and clubs have their own single fee table. The reach also works the other way. A foreign bank is not automatically caught, because the law expressly leaves out the Central Bank of Egypt and the entities it supervises.
Sources
- Official sourcePersonal Data Protection CentreEgypt's Personal Data Protection Framework: From Legal Foundations to Practical Compliance and Enforcement, March 2026 — Appointment of a Representative in Egypt
pdpc.gov.eg
“Where an entity does not have an establishment within the Arab Republic of Egypt and processes personal data relating to Egyptian data subjects or data subjects resident in Egypt, such entity shall appoint a legal representative in Egypt.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CentrePersonal Data Protection Centre website content, English text of the published questions and answers (machine-readable copy of the site's own pages)
pdpc.gov.eg
“regulate the collection, processing, storage, use, and transfer of electronic personal data belonging to Egyptian citizens, whether residing inside or outside Egypt, and non-Egyptian citizens residing in Egypt”
Link checked 18 August 2026
Where the data is allowed to live
Only with written permission from the regulator, granted to you specifically. Sending personal data out of Egypt is banned unless you hold a cross-border transfer licence or permit from the Personal Data Protection Centre. A short list of emergencies is the only other way. Storing data with a cloud provider whose servers are outside Egypt counts as sending it out. Two industries are stricter still. Financial technology firms in non-bank finance must keep the customer database inside Egypt. Footage from cameras in public places may not leave at all, unless a law says so.
- What you have to do here:
- Keep the data in the country · Put a transfer safeguard in place
Industry by industry as of 18 August 2026. BANKING: the Central Bank of Egypt and the entities it supervises are left out of the privacy law entirely. Bank data follows central bank rules that we could not retrieve. Money transfer companies and exchange offices are expressly NOT left out and stay inside the privacy law. NON-BANK FINANCE AND PAYMENTS TECHNOLOGY: the Financial Regulatory Authority requires the customer database of a licensed financial-technology firm to sit within Egypt's borders. The firm must tell the Authority within thirty days if it starts moving its head office or its data centre. INSURANCE AND SECURITIES: the same Financial Regulatory Authority decision covers these where the work is done through financial technology. We found no separate general rule forcing ordinary insurers or brokers to keep data in Egypt. HEALTH: human samples taken in clinical research may not enter or leave Egypt without approval from the Supreme Council for Clinical Medical Research. National-security requirements are taken into account. Research data must be open to inspection by the Supreme Council, the Egyptian Drug Authority and the General Intelligence Agency. TELECOM: service providers must keep system logs for one hundred and eighty days. They must also give national security bodies the technical means to do their work. We found no requirement in the text that those logs be held inside Egypt. VIDEO SURVEILLANCE: using or sending public-space camera data outside Egypt is banned, except for reasons set out in law. GOVERNMENT CLOUD, EDUCATION, GAMBLING, MAPPING AND DEFENCE: we found no rule in an official source, checked 18 August 2026, low confidence.
Sources
- Official sourcePersonal Data Protection Centre (official gazette copy)Personal Data Protection Law No. 151 of 2020, Official Gazette, 15 July 2020 — Chapter on cross-border personal data (Article 14)
pdpc.gov.eg
“تحظر إجراء عمليات نقل للبيانات الشخصية التي تم جمعها أو تجهيزها للمعالجة إلى دولة أجنبية أو تخزينها أو مشاركتها إلا بتوافر مستوى من الحماية لا يقل عن المستوى المنصوص عليه في هذا القانون وبترخيص أو تصريح من المركز”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CentreLicenses and Permits Guidelines, version 1.1, 26 January 2026 — Cross-Border Data Transfer License or Permit
pdpc.gov.eg
“This license or permit is granted to a natural or juridical person who transfers, or intends to transfer, personal data to a recipient outside the Arab Republic of Egypt. This includes engaging with cloud service providers where personal data is processed or stored on servers located outside Egypt”
Link checked 18 August 2026
- Official sourceFinancial Regulatory AuthorityFinancial Regulatory Authority Board Decision No. 139 of 2023, Egyptian Official Gazette (Al-Waqa'i al-Misriyya) issue 150 supplement (A), 11 July 2023
fra.gov.eg
“أن تكون قاعدة بيانات عملاء الشركة داخل الحدود الجغرافية لجمهورية مصر العربية”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CentrePersonal Data Protection Centre published questions and answers — categories excluded from the law, including the Central Bank of Egypt and entities under its supervision
pdpc.gov.eg
“Personal data held by the Central Bank of Egypt and entities under its supervision and control, except money transfer companies and exchange offices, which remain subject to the PDPL.”
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Egypt.
Sending data out of the country
You apply, and you wait. First you need a general licence to handle data at all. Then you apply for a separate cross-border transfer licence. To get it you must show one of two things. Either the destination country is on the regulator's approved list. Or you have extra protections in place, such as the contract wording the regulator recommends. The approved list has not been published yet, so everyone is on the second route. The regulator has ninety days to decide, and silence means refusal.
- Ways to send data out:
- Government sign-off needed · Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Approved code of conduct · Explicit consent · Needed for a contract · Legal claims · Important public interest · To save someone’s life
The regulator decides each case one by one. It also plans a list of approved countries, but that list is empty. The Centre's own document uses the future tense. It says it 'will maintain a whitelist of countries deemed to have an adequate level of personal data protection'. No such list appears in the Centre's published material as of 18 August 2026. Nor does a standard contract template. The tab on its website for the Centre's decisions is empty. Alongside the licence route sits a short set of exceptions in the law. All of them still need the person's valid consent. They are: saving a life or providing medical care, defending a legal right in court, entering or performing a contract for the person's benefit, international judicial cooperation, protecting the public interest or complying with a law, making money transfers abroad under the applicable rules, and transfers under a treaty Egypt has signed. A licence lasts three years. You must renew it at least three months before it expires, or it lapses automatically. A permit lasts up to one year and must be renewed at least one month before expiry. Fees are set in tables attached to the detailed rules. The Centre's board can change them by its own decision.
Sources
- Official sourcePersonal Data Protection CentreEgypt's Personal Data Protection Framework, March 2026 — Pursuing Adequacy and Alternative Mechanisms for Secure Cross-Border Data Transfers
pdpc.gov.eg
“PDPC will maintain a whitelist of countries deemed to have an adequate level of personal data protection, equivalent to that of Egypt.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CentreLicenses and Permits Guidelines, version 1.1, 26 January 2026 — Application Review and Decision Issuance
pdpc.gov.eg
“The PDPC shall review the application and issue a decision thereon within a period not exceeding ninety (90) days from the date of receipt of the application; failing which, the application shall be deemed rejected.”
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The Personal Data Protection Centre. It is real and working, not just a name on paper. It has staff, departments and an acting chief executive. It has published guidelines updated in January 2026. It runs an online application portal and a training programme for data protection officers. What it has not done yet is punish anyone in public. Its own website page for decisions is empty. So are its news, press release and annual report pages. Industry regulators for banking, non-bank finance, telecoms and medicines have been enforcing for years.
The evidence that the regulator works comes from the Centre's own site. It published Licenses and Permits Guidelines version 1.1 dated 26 January 2026. It published a slide deck on the rules and enforcement dated March 2026. It ran a four-day training programme for data protection officers in February 2026. That was attended by the German Embassy, the European Union Delegation and the African Union. It held a joint session with the State Lawsuits Authority and the British University in Egypt in early 2026 on the new rules. It attended the Global Cross-Border Privacy Rules Forum spring workshop in March 2026. Suzanne El Akabaoui is described as Acting Chief Executive of the Centre. She is also adviser to the Minister of Communications and Information Technology for data governance. We rate the regulator 'waking' rather than 'active' for three reasons. No enforcement decision has been published. The one-year window to get licensed does not close until early November 2026. And the site's own content has not been refreshed since 7 April 2026. The complaints process is set out. The Centre must decide a complaint within thirty working days. The offender then has seven working days to comply. If it does not, the Centre may sue it.
Sources
- Official sourcePersonal Data Protection CentrePersonal Data Protection Centre — official website
pdpc.gov.eg
Link checked 18 August 2026
- Official sourcePersonal Data Protection CentreLicenses and Permits Guidelines, version 1.1, 26 January 2026 — evidence of an operating regulator issuing dated, versioned guidance
pdpc.gov.eg
“Where the violation is not rectified, the PDPC may impose disciplinary measures, including the partial or complete suspension of the license or permit for a specified period.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CentrePersonal Data Protection Centre website content — the decisions, news, press release and annual report sections carry no entries
pdpc.gov.eg
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a minimum and a maximum, and they come from different laws. The maximum is simple. You may not keep personal data longer than the purpose you collected it for. The minimums we could verify are narrow. Marketing consents and opt-out requests must be kept for at least three years. Internet and technology service providers must keep their system records for one hundred and eighty days in a row. You must also keep your paperwork about any data breach.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep records of how you use data
The one-hundred-and-eighty-day duty comes from the Anti-Cyber and Information Technology Crimes Law No. 175 of 2018. It covers data that identifies the user, content data under the provider's control, traffic data, terminal device data, and any further category the telecom regulator's board decides to add. The privacy law's own rule on not keeping data too long is one of seven principles the regulator lists. Sometimes one law tells you to keep data and another tells you to delete it. The licences guideline is clear on this. A licence from the Centre does not replace approvals or duties you owe to other authorities. So the longer keep-time set by law wins. You lock the data down rather than delete it. We could not verify Egypt's general tax and book-keeping keep-times from an official source, so we do not state them here.
Sources
- Official sourceNational Telecom Regulatory AuthorityLaw No. 175 of 2018 on Combating Information Technology Crimes, Official Gazette issue 32 bis (c), 14 August 2018, Article 2
tra.gov.eg
“حفظ وتخزين سجل النظام المعلوماتي أو أي وسيلة لتقنية المعلومات لمدة مائة وثمانين يوماً متصلة”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CentrePersonal Data Protection Centre published questions and answers — electronic direct marketing record keeping
pdpc.gov.eg
“Both creators and senders must maintain accurate electronic records of consents and opt-out requests for at least three years.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CentreEgypt's Personal Data Protection Framework, March 2026 — the seven processing principles, including storage limitation
pdpc.gov.eg
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
Two deadlines run one after the other. You have seventy-two hours from the moment you find out to tell the regulator. If the breach touches national security you must tell it immediately, with no grace period at all. Then you have three working days from the date you told the regulator to tell the people affected. You must also tell them what you did to contain the damage. The regulator publishes a form for each of those two notifications.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Secure the data
A third deadline runs on complaints rather than breaches. Once someone complains, the Centre must issue its decision within thirty working days. Your organisation then has seven working days to put things right and report back. A fourth deadline catches people out in normal day-to-day work. Someone using any of their nine rights must get an answer within six working days of asking. We could not verify whether the telecom regulator's incident response team or the central bank set their own separate incident deadlines. So we do not state any here.
Sources
- Official sourcePersonal Data Protection CentreEgypt's Personal Data Protection Framework, March 2026 — Data Breach Notification
pdpc.gov.eg
“Notify PDPC within seventy-two (72) hours from the date of becoming aware of the breach. Where the breach is related to national security considerations or the entities responsible therefor, notification to PDPC shall be made immediately. Data subjects shall be notified within three (3) working days from the date of notifying PDPC”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CentrePersonal Data Protection Centre published questions and answers — complaint timetable and the six working day response to individuals
pdpc.gov.eg
“The PDPC must issue its decision within 30 working days and notify both parties. The violator must comply within 7 working days of the PDPC decision”
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things catch people out. First, you need a licence to handle personal data at all, not just to move it abroad. You cannot get one without a data protection officer registered with the regulator. Second, breaking the transfer rules is a crime, not a fine. It carries at least three months in prison plus a penalty of up to five million Egyptian pounds, roughly one hundred thousand United States dollars. Third, a child means anyone under eighteen, in two stages. Fourth, banks are outside the privacy law but money changers are not. Fifth, you have six working days, not a month, to answer someone who asks about their data.
- What you have to do here:
- Register or notify · Appoint a data protection officer · Get a parent's consent for children · Let people see their data · Do not hand data to foreign authorities on demand
- What it costs if you get it wrong:
- Criminal liability
On children. For a child under fifteen you must get written explicit consent from the parent or guardian before collecting anything. That consent must state the purpose and how long you will use the data. A young person aged fifteen to eighteen may hand over the guardian's written explicit consent themselves. Either way the age limit is eighteen, well above the thirteen or sixteen used elsewhere. On the data protection officer. They must be named in the organisation chart. They must report to the highest level of management. They must be independent of decisions about how data is used. They must be entered in the Centre's register after sitting the Centre's examination for one of three categories. They may be Egyptian or foreign. On prison risk in health. Anyone who helps human research samples leave Egypt without prior approval faces imprisonment plus a fine. The fine runs from five hundred thousand to one million Egyptian pounds. That is roughly ten to twenty thousand United States dollars. On state access. When national security bodies ask, telecom and technology service providers must supply all the technical capabilities those bodies need. Clinical research data must also be open to the General Intelligence Agency for audit. On what the regulator can do after granting your licence. It may change your licence terms on public-interest grounds. It may publish proven violations in the media at your expense. It may place you under technical supervision, and you pay the cost.
Sources
- Official sourcePersonal Data Protection Centre (official gazette copy)Personal Data Protection Law No. 151 of 2020 — penalties chapter, including imprisonment of not less than three months and a fine of five hundred thousand to five million Egyptian pounds for breaching the cross-border data movement rules
pdpc.gov.eg
“يعاقب بالحبس مدة لا تقل عن ثلاثة شهور وبغرامة لا تقل عن خمسمائة ألف جنيه ولا تجاوز خمسة ملايين جنيه، أو بإحدى هاتين العقوبتين، كل من خالف أحكام حركة البيانات”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CentreEgypt's Personal Data Protection Framework, March 2026 — children's data obligations and data protection officer requirements
pdpc.gov.eg
“Children under 15 years of age: The controller shall obtain the explicit written consent of the parent or legal guardian prior to collecting or processing the child's personal data”
Link checked 18 August 2026
- Official sourceEgyptian Drug AuthorityLaw No. 214 of 2020 regulating Clinical Medical Research, Official Gazette issue 51 bis (F), 23 December 2020, Articles 20 and 22 (official English translation published by the Egyptian Drug Authority)
edaegypt.gov.eg
“Any person who contributes in any way whatsoever in the exit of human samples used in clinical medical research during or after the research without the prior approvals stipulated under the law shall be punishable by imprisonment and a fine of at least five hundred thousand Egyptian Pounds and no more than one million Egyptian Pounds.”
Link checked 18 August 2026
- Official sourceNational Telecom Regulatory AuthorityLaw No. 175 of 2018, Article 2 (Third) — duty to give national security bodies the technical means to exercise their powers
tra.gov.eg
“يلتزم مقدمو الخدمة والتابعون لهم أن يوفروا حال طلب جهات الأمن القومي ووفقاً لاحتياجاتها كافة الإمكانيات الفنية التي تتيح لتلك الجهات ممارسة اختصاصاتها وفقاً للقانون”
Link checked 18 August 2026
What's changing next
One date dominates. The detailed rules were published on the first of November 2025 and took effect the next day. That started a one-year window to get licensed. The window closes at the beginning of November 2026. After that, handling personal data without the right licence simply breaks the law. Everything else that matters is a power the government already holds. It can use any of them without warning.
Powers the government already holds, in order of how much they would change things. One: the list of countries the regulator considers safe enough to receive Egyptian data. It is promised but not published. Publishing it would make transfers to those countries much easier straight away. Two: the recommended contract wording for transfers. Also promised, also not published. Applicants are left guessing what protections will satisfy the regulator. Three: the Centre's decisions page. It is empty today and can be filled at any time with binding rules for any industry. Four: fees, which the Centre's board can change by its own decision. Five: the telecom regulator's board can add new kinds of data to the one-hundred-and-eighty-day keep-time by decision. Six: the Centre may change the terms of a licence you already hold, on public-interest grounds. Egypt attended the Global Cross-Border Privacy Rules Forum spring workshop in March 2026. It says it is seeking mutual recognition with other countries. Movement is possible but nothing is agreed.
Sources
- Official sourcePersonal Data Protection CentrePersonal Data Protection Centre published questions and answers — commencement of the executive regulations and start of the compliance period
pdpc.gov.eg
“The Executive Regulations No. 816 of 2025 of the Egyptian Personal Data Protection Law (PDPL), issued under the Ministerial Decree No. 816 of 2025 and published in the Official Gazette on 1 November 2025, enters into force on the day following its publication. A one-year compliance period commences from the date of entry into force of the Executive Regulations No. 816 of 2025.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CentreLicenses and Permits Guidelines, version 1.1, 26 January 2026 — Transitional Provisions: The One-Year Compliance Grace Period
pdpc.gov.eg
“All data users, whether natural or juridical persons, must apply for the necessary licenses or permits within the one-year grace period, as stipulated by the PDPL. If entities fail to obtain the required licenses or permits within this period, any processing of personal data thereafter shall constitute a violation of the provisions of the PDPL and the ER.”
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Finance data needs a copy kept in the country
Official name: قرار مجلس إدارة الهيئة العامة للرقابة المالية رقم 139 لسنة 2023 (Financial Regulatory Authority Board Decision No. 139 of 2023) · Board Decision No. 139 of 2023 dated 21 June 2023, published in Al-Waqa'i al-Misriyya issue 150 supplement (A), 11 July 2023 · Directly binding regulation
Some firms are licensed to do non-bank financial work in Egypt using financial technology. They must keep their customer database inside Egypt. They must tell the Financial Regulatory Authority within thirty days if they start moving their head office or data centre. The decision sets where the database sits. It does not say whether a further copy may also be held abroad.
Enforced by Financial Regulatory Authority
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryThe company's customer database must sit within Egypt's geographic borders.
- Tell people what you do — within 720 hoursThe Authority must be told within thirty days of the company starting any steps to move its head office or its data centre.
- Secure the dataThe decision sets a minimum: firewall, web application firewall, security across all assets, real-time event monitoring, database encryption to international standards, and continuous patching.
- Hold a security certificateLicensed operating systems and applications are a minimum condition. So is keeping the system available at all times.
What it costs if you get it wrong
- Loss of your licenceFailure to meet the technology and infrastructure requirements attached to a financial technology licence
Sources
- Official sourceFinancial Regulatory AuthorityFinancial Regulatory Authority Board Decision No. 139 of 2023 on the equipment, technological infrastructure, information systems and protection means required for using financial technology in non-bank financial activities
fra.gov.eg
“أن تكون قاعدة بيانات عملاء الشركة داخل الحدود الجغرافية لجمهورية مصر العربية”
Link checked 18 August 2026
- Official sourceFinancial Regulatory AuthorityFinancial Regulatory Authority legislative portal — Board Decision No. 139 of 2023
fra.gov.eg
Link checked 18 August 2026
Banking rules
Official name: Personal Data Protection Law No. 151 of 2020 — exclusion of the Central Bank of Egypt and the entities under its supervision · Law No. 151 of 2020, scope exclusions; supervision under the Central Bank and Banking System Law No. 194 of 2020 · Act of parliament
Personal data held by the Central Bank of Egypt, and by the banks and institutions it supervises, is left out of the privacy law entirely. The national licence and transfer rules do not reach it. Money transfer companies and exchange offices are expressly not left out and stay fully inside the privacy law. We could not find what rules on data location the central bank applies to banks instead. So this row is rated unknown rather than open.
Enforced by Central Bank of Egypt
How this country controls where data goes: Approval each time
What you have to do
- Register or notifyBanks are licensed and supervised by the Central Bank of Egypt rather than by the privacy regulator.
What it costs if you get it wrong
- Loss of your licenceBreach of central bank supervisory requirements
Sources
- Official sourcePersonal Data Protection CentrePersonal Data Protection Centre published questions and answers — categories of personal data outside the law's scope
pdpc.gov.eg
“Personal data held by the Central Bank of Egypt and entities under its supervision and control, except money transfer companies and exchange offices, which remain subject to the PDPL.”
Link checked 18 August 2026
- Official sourceCentral Bank of EgyptCentral Bank of Egypt — Banking Laws, including CBE Law No. 194 of 2020 and its executive regulations
cbe.org.eg
Link checked 18 August 2026
State and security data rules
Official name: قانون رقم 175 لسنة 2018 في شأن مكافحة جرائم تقنية المعلومات (Law No. 175 of 2018 on Combating Information Technology Crimes) · Law No. 175 of 2018, Official Gazette issue 32 bis (c), 14 August 2018, Article 2; executive regulations published by the National Telecom Regulatory Authority · Act of parliament
Anyone supplying information and communication technology services in Egypt must keep system logs for one hundred and eighty days in a row. They must keep them confidential, except on a judge's reasoned order. They must also give national security bodies the technical means to do their work. We found no requirement in the text we read that these logs be stored inside Egypt, checked 18 August 2026.
Enforced by National Telecom Regulatory Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep logs — 6 monthsOne hundred and eighty days in a row. This covers data identifying the user, content data under the provider's control, traffic data, terminal device data, and any further kinds the telecom regulator's board adds by decision.
- Secure the dataProviders must keep the stored data confidential and may only disclose it on a reasoned order from a competent judicial authority.
- Do not hand data to foreign authorities on demandThis duty runs the other way. Providers must give Egypt's own national security bodies all the technical capabilities those bodies need.
What it costs if you get it wrong
- Criminal liabilityBreach of service provider duties under the law
Sources
- Official sourceNational Telecom Regulatory AuthorityLaw No. 175 of 2018 on Combating Information Technology Crimes, Official Gazette copy, Article 2
tra.gov.eg
“حفظ وتخزين سجل النظام المعلوماتي أو أي وسيلة لتقنية المعلومات لمدة مائة وثمانين يوماً متصلة”
Link checked 18 August 2026
- Official sourceNational Telecom Regulatory AuthorityNational Telecom Regulatory Authority — Laws and Legislations, listing Law No. 175 of 2018 and its executive regulations
tra.gov.eg
Link checked 18 August 2026
Health and social care data must stay in the country
Official name: قانون رقم 214 لسنة 2020 بإصدار قانون تنظيم البحوث الطبية الإكلينيكية (Law No. 214 of 2020 regulating Clinical Medical Research) · Law No. 214 of 2020, Official Gazette issue 51 bis (F), 23 December 2020, Articles 15, 20 and 22 · Act of parliament
Clinical medical research on people in Egypt has its own law. Human samples may not cross the border in either direction without approval from the Supreme Council for Clinical Medical Research. National security is taken into account. Helping samples leave without that approval means prison plus a fine of five hundred thousand to one million Egyptian pounds. Research records must be open to the intelligence service for audit.
Enforced by Egyptian Drug Authority
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Get consentYou need informed consent from the research subject, or their legal representative, to use human samples at all. You need it again to keep leftover samples for future research.
- Keep records of how you use dataAll information, data and reports must be recorded, filed, kept and verified for integrity and accuracy.
- Independent auditData and reports must be made available during and after the research. Four bodies can ask for them: the institutional review board, the Supreme Council, the General Intelligence Agency and the Egyptian Drug Authority.
- Keep the data in the countryHuman samples may not enter or leave Egypt without the approval of the Supreme Council, with national security requirements taken into account.
What it costs if you get it wrong
- Criminal liability: EGP 1,000,000 and imprisonment — about $20 thousandContributing in any way to human research samples leaving Egypt without the prior approvals required by the law
Sources
- Official sourceEgyptian Drug AuthorityLaw No. 214 of 2020 regulating Clinical Medical Research — official English translation published by the Egyptian Drug Authority
edaegypt.gov.eg
“The approval of the Supreme Council and considerations and requirements of national security shall be taken into account before the entry or exit of any human samples related to medical research into or out of the Arab Republic of Egypt for any purpose whatsoever.”
Link checked 18 August 2026
- Official sourceEgyptian Drug AuthorityEgyptian Drug Authority — Laws and Executive Regulations index listing Law No. 214 of 2020
edaegypt.gov.eg
Link checked 18 August 2026
Applies to every company1 rule
These bind you whatever business you are in, once the country's rules reach you.
Cloud and outsourcing rules
Official name: قانون حماية البيانات الشخصية رقم 151 لسنة 2020 (Personal Data Protection Law No. 151 of 2020) · Law No. 151 of 2020, Official Gazette 15 July 2020; Executive Regulations issued by Ministerial Decree No. 816 of 2025, Official Gazette 1 November 2025 · Act of parliament
Egypt's general privacy law. You need a government licence to handle personal data at all. You need a second licence to send it abroad. Cloud storage on foreign servers counts as sending it abroad. Detailed rules came into force on 2 November 2025. Every organisation must be licensed by early November 2026. Breaking the transfer rules is a crime.
That is a long gap: the duty is real law today, but no penalty can follow until 2 November 2026. A contract you sign can still hold you to it from day one — and government contracts often do.
Enforced by Personal Data Protection Centre
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed, Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Important public interest, To save someone’s life
What you have to do
- Register or notify — from 2 November 2025You need a general licence, lasting three years, or a permit, lasting up to one year, to handle personal data at all. You need an extra licence to send data abroad, to run electronic direct marketing, and to use cameras in public places.
- Put a transfer safeguard in placeBefore you apply, you need a written check on the risks of the transfer, contracts in place, and an assessment of the destination country's laws.
- Appoint a data protection officerThey must be in the Centre's register, sit the Centre's category examination, report to top management and be independent. You cannot get any licence without one.
- Appoint a representativeYou need this if you have no office in Egypt. The Centre must approve the appointment.
- Get consent
- Document a legitimate interest
- Allowed because the law requires it
- Tell people what you do
- Let people see their dataAnswer within six working days of the request.
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Secure the data
- Keep records of how you use dataA written record of what you do with personal data. The Centre publishes a template.
- Assess high-risk projects
- Report breaches to the regulator — within 72 hoursImmediately where the breach touches national security.
- Tell affected peopleWithin three working days of notifying the Centre.
- Get a parent's consent for children — applies at: under 18, in two tiers: under 15 and 15 to 18
- Keep data for a minimum period — applies at: Electronic direct marketing consents and opt-out requests, 3 years
- Delete data after a periodNot keeping data longer than you need it is one of the seven principles.
- Written vendor contract
What it costs if you get it wrong
- Criminal liability: EGP 5,000,000 and imprisonment of not less than three months — about $99 thousandBreaching the rules on cross-border movement of personal data
- Criminal liability: EGP 5,000,000 and imprisonment of not less than three months — about $99 thousandUnlawful handling of sensitive personal data by a holder, controller or processor
- Fixed maximum fine: EGP 3,000,000 — about $59 thousandController breaches of core duties
- Fixed maximum fine: EGP 2,000,000 — about $40 thousandCollecting personal data without meeting the statutory conditions
- Fixed maximum fine: EGP 1,000,000 — about $20 thousandGeneral breach by a holder or controller
- Criminal liability: EGP 2,000,000 and imprisonment of not less than six months — about $40 thousandObstructing staff of the Personal Data Protection Centre
- Order to stopFailure to remedy a violation after warning; partial or complete suspension of the licence or permit
- Loss of your licenceFailing licence conditions, non-payment of renewal fees, repeated breaches of the Centre's decisions, transferring the licence without authorisation, or bankruptcy
Sources
- Official sourcePersonal Data Protection CentrePersonal Data Protection Law No. 151 of 2020, Official Gazette text
pdpc.gov.eg
Link checked 18 August 2026
- Official sourcePersonal Data Protection CentreExecutive Regulations of the Personal Data Protection Law, issued by Ministerial Decree No. 816 of 2025
pdpc.gov.eg
Link checked 18 August 2026
- Official sourcePersonal Data Protection CentreLicenses and Permits Guidelines, version 1.1, 26 January 2026
pdpc.gov.eg
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
That the Personal Data Protection Centre's approved-country list and recommended contract clauses are still unpublished today
We could not confirm the position after April 2026. The Centre's own website content was last changed on 7 April 2026, so our evidence stops there. Anything issued between April and August 2026 would not show. Treat the empty list as a snapshot in time, not a certainty.
Whether the online licence and permit application portal is actually accepting and granting applications
We could not confirm that the licensing portal is open, or how many licences it has issued. The Centre's March 2026 slide deck announces the launch and describes the steps. The portal addresses we tried did not load from outside Egypt, and we found no published count of licences.
What rules the Central Bank of Egypt applies to banks on cloud computing, outsourcing and where data may be stored
We could not confirm what rules the central bank applies to bank data. Banks sit outside the privacy law, so the central bank's rulebook is what binds them. Its circular archive is filtered by a script we could not use. No cloud or data-location circular appears in the English list of titles we could read. This is the biggest gap in this record. If you are a bank, ask the central bank directly.
Whether conventional insurers, brokers and securities firms face a keeping data in the country duty when they are not using financial technology
We could not confirm the position for non-bank finance firms that do not use financial technology. The Financial Regulatory Authority decision we verified is expressly about doing non-bank financial work through financial technology. We found no equivalent rule for other firms.
Whether Financial Regulatory Authority Decision No. 139 of 2023 permits an additional copy of the customer database to be held abroad
We could not confirm whether a second copy of the database may be held abroad. The decision says where the database must be and says nothing either way about a copy. For that reason we have recorded it as a duty to keep a copy in Egypt, rather than a full ban on holding data elsewhere.
Egypt's general tax and commercial book-keeping retention periods
We could not confirm Egypt's general tax and book-keeping keep-times. The tax authority's website did not show us its list of legislation. We would rather state nothing than repeat an unverified figure. Check with the tax authority before you rely on it.
Any where data has to be stored or sovereignty condition in government cloud procurement, education, gambling, mapping or defence
We found no rule in an official source, checked 18 August 2026. The ministry's site blocks automated access, and the survey authority publishes no rule on sending mapping data abroad. This is a gap in our search, not proof that no rule exists. If you work with maps, check before you rely on it.
Whether the telecom regulator's incident response team or the central bank impose their own separate breach reporting deadlines
We could not confirm whether either body sets its own incident deadline in hours. Both publish a 'report an incident' route, but we could not open a document setting a time limit.
The exact wording of the executive regulations issued by Ministerial Decree No. 816 of 2025
We could not read the original text of this decision. The only copy the regulator publishes is a scanned Arabic image with no text layer. Our account of what it says relies on the regulator's own English guidelines, slide deck and published questions and answers. All of those describe it directly.
The composition of the Personal Data Protection Centre's board of directors
We could not confirm who sits on the Centre's board. Its executive management page has no entries, although its guidelines refer to board decisions on fees.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.