Egypt
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
Egypt now runs a full permission system. You need a government licence just to handle people's data, and a second licence on top of that to send any of it out of the country. Using a cloud service whose servers sit abroad counts as sending it out. The detailed rules finally arrived on the first of November 2025 and every organisation has until early November 2026 to get licensed.
Data governance in Egypt
The eight things that decide how you handle data about people in Egypt. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law follows the person, not the office. It covers the data of Egyptian citizens wherever in the world they live, and of anyone else living in Egypt. If your company has no office or branch in Egypt but handles that data, you must appoint a legal representative inside Egypt, and the regulator has to approve your choice. No size or revenue level lets you off. Licence fees rise with how many people's records you hold, but there is no floor below which you are free.
The regulator's own framework deck states that where an entity has no establishment in Egypt and processes personal data relating to Egyptian data subjects or people resident in Egypt, it must appoint a legal representative in Egypt, submitted to the Personal Data Protection Centre for examination and approval, and that this representative acts as the entity's official interface with the Centre. Fee bands are set by the number of records, where one record equals one data subject, with a separate unified fee table for associations, unions and clubs. Note the reverse of the extraterritorial reach: a foreign bank is not automatically caught, because the law expressly excludes the Central Bank of Egypt and the entities it supervises.
Sources
- Official sourcePersonal Data Protection CentreEgypt's Personal Data Protection Framework: From Legal Foundations to Practical Compliance and Enforcement, March 2026 — Appointment of a Representative in Egypt
pdpc.gov.eg
“Where an entity does not have an establishment within the Arab Republic of Egypt and processes personal data relating to Egyptian data subjects or data subjects resident in Egypt, such entity shall appoint a legal representative in Egypt.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CentrePersonal Data Protection Centre website content, English text of the published questions and answers (machine-readable copy of the site's own pages)
pdpc.gov.eg
“regulate the collection, processing, storage, use, and transfer of electronic personal data belonging to Egyptian citizens, whether residing inside or outside Egypt, and non-Egyptian citizens residing in Egypt”
Link checked 18 August 2026
Where the data is allowed to live
Only with written permission from the regulator, granted to you specifically. Sending personal data out of Egypt is banned unless you hold a cross-border transfer licence or permit from the Personal Data Protection Centre, or your case falls inside a short list of emergencies. Storing data with a cloud provider whose servers are outside Egypt is treated as sending it out. Two industries are stricter still: financial technology firms in non-bank finance must keep the customer database inside Egypt, and footage from cameras in public places may not leave at all except where a law says so.
Sector by sector as of 18 August 2026. BANKING: the Central Bank of Egypt and the entities under its supervision are excluded from the privacy law entirely, so bank data is governed by central bank rules we could not retrieve; money transfer companies and exchange offices are expressly NOT excluded and stay inside the privacy law. NON-BANK FINANCE AND PAYMENTS TECHNOLOGY: the Financial Regulatory Authority requires that the customer database of a licensed financial-technology firm sit within Egypt's geographic borders, and that the Authority be told within thirty days if the firm starts moving its head office or its data centre. INSURANCE AND SECURITIES: covered by the same Financial Regulatory Authority decision where the activity is carried on through financial technology; we found no separate general localisation rule for conventional insurers or brokers. HEALTH: human samples taken in clinical research may not enter or leave Egypt without the approval of the Supreme Council for Clinical Medical Research, with national-security requirements taken into account; research data must be open to inspection by the Supreme Council, the Egyptian Drug Authority and the General Intelligence Agency. TELECOM: service providers must keep system logs for one hundred and eighty days and must give national security bodies the technical means to exercise their powers; we found no requirement in the text that those logs be held inside Egypt. VIDEO SURVEILLANCE: processing or transferring public-space camera data outside Egypt is prohibited except for legally prescribed reasons. GOVERNMENT CLOUD, EDUCATION, GAMBLING, MAPPING AND DEFENCE: no rule found in an official source, checked 18 August 2026, confidence low.
Sources
- Official sourcePersonal Data Protection Centre (official gazette copy)Personal Data Protection Law No. 151 of 2020, Official Gazette, 15 July 2020 — Chapter on cross-border personal data (Article 14)
pdpc.gov.eg
“تحظر إجراء عمليات نقل للبيانات الشخصية التي تم جمعها أو تجهيزها للمعالجة إلى دولة أجنبية أو تخزينها أو مشاركتها إلا بتوافر مستوى من الحماية لا يقل عن المستوى المنصوص عليه في هذا القانون وبترخيص أو تصريح من المركز”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CentreLicenses and Permits Guidelines, version 1.1, 26 January 2026 — Cross-Border Data Transfer License or Permit
pdpc.gov.eg
“This license or permit is granted to a natural or juridical person who transfers, or intends to transfer, personal data to a recipient outside the Arab Republic of Egypt. This includes engaging with cloud service providers where personal data is processed or stored on servers located outside Egypt”
Link checked 18 August 2026
- Official sourceFinancial Regulatory AuthorityFinancial Regulatory Authority Board Decision No. 139 of 2023, Egyptian Official Gazette (Al-Waqa'i al-Misriyya) issue 150 supplement (A), 11 July 2023
fra.gov.eg
“أن تكون قاعدة بيانات عملاء الشركة داخل الحدود الجغرافية لجمهورية مصر العربية”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CentrePersonal Data Protection Centre published questions and answers — categories excluded from the law, including the Central Bank of Egypt and entities under its supervision
pdpc.gov.eg
“Personal data held by the Central Bank of Egypt and entities under its supervision and control, except money transfer companies and exchange offices, which remain subject to the PDPL.”
Link checked 18 August 2026
Sending data out of the country
You apply, and you wait. First you need a general licence to process data at all. Then you apply for a separate cross-border transfer licence. To get it you must show either that the destination country is on the regulator's approved list, or that you have extra protections in place, such as the contract wording the regulator recommends. The approved list has not been published yet, so in practice everyone is on the second route. The regulator has ninety days to decide, and silence means refusal.
This is a case-by-case authorisation model with an allowlist bolted on that is not yet populated. The Centre's own framework document uses the future tense: it 'will maintain a whitelist of countries deemed to have an adequate level of personal data protection'. No such list, and no standard contract template, appears on the Centre's published materials as of 18 August 2026, and the tab on its website for the Centre's decisions is empty. Alongside the licence route sits a narrow set of exceptions in Article 15 of the law which still require the person's valid consent: saving a life or providing medical care, defending a legal right in court, entering or performing a contract for the person's benefit, international judicial cooperation, protecting the public interest or complying with a law, making money transfers abroad under the applicable rules, and transfers under a treaty Egypt has signed. A licence lasts three years and must be renewed at least three months before it expires or it lapses automatically; a permit lasts up to one year and must be renewed at least one month before expiry. Fees are set in financial tables attached to the executive regulations and can be changed by a decision of the Centre's board.
Sources
- Official sourcePersonal Data Protection CentreEgypt's Personal Data Protection Framework, March 2026 — Pursuing Adequacy and Alternative Mechanisms for Secure Cross-Border Data Transfers
pdpc.gov.eg
“PDPC will maintain a whitelist of countries deemed to have an adequate level of personal data protection, equivalent to that of Egypt.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CentreLicenses and Permits Guidelines, version 1.1, 26 January 2026 — Application Review and Decision Issuance
pdpc.gov.eg
“The PDPC shall review the application and issue a decision thereon within a period not exceeding ninety (90) days from the date of receipt of the application; failing which, the application shall be deemed rejected.”
Link checked 18 August 2026
The regulator, and whether it actually acts
The Personal Data Protection Centre, and unlike many countries with a paper regulator, this one is real and working. It has staff, departments, a chief executive in an acting capacity, a published set of guidelines updated in January 2026, an online application portal and a training programme for data protection officers. What it has not done yet is punish anyone in public. Its own website page for decisions is empty, and so are its news, press release and annual report pages. Sector regulators for banking, non-bank finance, telecoms and medicines have been enforcing for years.
Evidence of a functioning regulator, all from the Centre's own site: Licenses and Permits Guidelines version 1.1 dated 26 January 2026; a framework and enforcement deck dated March 2026; a four-day capacity-building programme for data protection officers in February 2026 attended by the German Embassy, the European Union Delegation and the African Union; a joint session with the State Lawsuits Authority and the British University in Egypt in early 2026 on the new regulations; and attendance at the Global Cross-Border Privacy Rules Forum spring workshop in March 2026. Suzanne El Akabaoui is described as Acting Chief Executive of the Centre and adviser to the Minister of Communications and Information Technology for data governance. The rating is 'waking' rather than 'active' for three reasons: no enforcement decision has been published, the one-year compliance period does not end until early November 2026, and the site's own content has not been refreshed since 7 April 2026. The complaints machinery is defined: the Centre must decide a complaint within thirty working days, the offender has seven working days to comply, and if it does not, the Centre may sue it.
Sources
- Official sourcePersonal Data Protection CentrePersonal Data Protection Centre — official website
pdpc.gov.eg
Link checked 18 August 2026
- Official sourcePersonal Data Protection CentreLicenses and Permits Guidelines, version 1.1, 26 January 2026 — evidence of an operating regulator issuing dated, versioned guidance
pdpc.gov.eg
“Where the violation is not rectified, the PDPC may impose disciplinary measures, including the partial or complete suspension of the license or permit for a specified period.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CentrePersonal Data Protection Centre website content — the decisions, news, press release and annual report sections carry no entries
pdpc.gov.eg
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a floor and a ceiling, and they come from different laws. The ceiling is the storage limitation rule: you may not keep personal data longer than the purpose you collected it for. The floors we could verify are narrow. Marketing consents and opt-out requests must be kept for at least three years. Internet and technology service providers must keep their system records for one hundred and eighty days in a row. Breach paperwork must be kept as well.
The one-hundred-and-eighty-day duty sits in Article 2 of the Anti-Cyber and Information Technology Crimes Law No. 175 of 2018 and covers data that identifies the user, content data under the provider's control, traffic data, terminal device data, and any further category the telecom regulator's board decides to add. The privacy law's own storage limitation principle is one of seven processing principles the regulator lists. Where a keeping duty and a deleting duty conflict, the licences guideline is explicit that a licence from the Centre does not replace approvals or obligations owed to other authorities, so the longer statutory keeping duty wins and the data must be locked down rather than deleted. We could not verify Egypt's general tax and commercial book-keeping periods from an official source in this run and have not asserted them.
Sources
- Official sourceNational Telecom Regulatory AuthorityLaw No. 175 of 2018 on Combating Information Technology Crimes, Official Gazette issue 32 bis (c), 14 August 2018, Article 2
tra.gov.eg
“حفظ وتخزين سجل النظام المعلوماتي أو أي وسيلة لتقنية المعلومات لمدة مائة وثمانين يوماً متصلة”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CentrePersonal Data Protection Centre published questions and answers — electronic direct marketing record keeping
pdpc.gov.eg
“Both creators and senders must maintain accurate electronic records of consents and opt-out requests for at least three years.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CentreEgypt's Personal Data Protection Framework, March 2026 — the seven processing principles, including storage limitation
pdpc.gov.eg
Link checked 18 August 2026
If something goes wrong
Two clocks run one after the other. You have seventy-two hours from the moment you find out to tell the regulator, and if the breach touches national security you must tell it immediately with no grace period at all. Then you have three working days from the date you notified the regulator to tell the people affected, including what you did to contain the damage. The regulator publishes a form for each of those two notifications.
A third clock runs on complaints rather than breaches: once someone complains, the Centre must issue its decision within thirty working days, and the organisation then has seven working days to put things right and report back. A fourth timer catches people out in normal operations: an individual exercising any of their nine rights must get an answer within six working days of asking. We could not verify whether the telecom regulator's incident response team or the central bank impose their own separate incident deadlines on the firms they supervise, and have not asserted any.
Sources
- Official sourcePersonal Data Protection CentreEgypt's Personal Data Protection Framework, March 2026 — Data Breach Notification
pdpc.gov.eg
“Notify PDPC within seventy-two (72) hours from the date of becoming aware of the breach. Where the breach is related to national security considerations or the entities responsible therefor, notification to PDPC shall be made immediately. Data subjects shall be notified within three (3) working days from the date of notifying PDPC”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CentrePersonal Data Protection Centre published questions and answers — complaint timetable and the six working day response to individuals
pdpc.gov.eg
“The PDPC must issue its decision within 30 working days and notify both parties. The violator must comply within 7 working days of the PDPC decision”
Link checked 18 August 2026
What catches people out
Five things catch people out. First, you need a licence to touch personal data at all, not just to move it abroad, and you cannot get one without a data protection officer registered with the regulator. Second, breaking the transfer rules is a crime, not a fine: at least three months in prison plus a penalty of up to five million Egyptian pounds, roughly one hundred thousand United States dollars. Third, children means under eighteen, in two stages. Fourth, banks are outside the privacy law but money changers are not. Fifth, you have six working days, not a month, to answer someone who asks about their data.
On children: for a child under fifteen the organisation must obtain the written explicit consent of the parent or guardian before collecting anything, and that consent must state the purpose and how long the processing will last; for a young person aged fifteen to eighteen, they may themselves hand over the guardian's written explicit consent. Either way an eighteen-year-old threshold governs, well above the thirteen or sixteen used elsewhere. On the data protection officer: they must be named in the organisation chart, report to the highest level of management, be independent of decisions about processing, and be entered in the Centre's register after sitting the Centre's examination for one of three categories; they may be Egyptian or foreign. On criminal exposure in health: anyone who contributes in any way to human research samples leaving Egypt without prior approval faces imprisonment plus a fine of between five hundred thousand and one million Egyptian pounds, roughly ten to twenty thousand United States dollars. On state access: telecom and technology service providers must, when national security bodies ask, supply all the technical capabilities those bodies need to exercise their powers, and clinical research data must be open to the General Intelligence Agency for audit. On the regulator's reach after the fact: it may amend your licence terms after issuing them on public-interest grounds, publish proven violations in the media at your expense, and place you under technical supervision with you paying the cost.
Sources
- Official sourcePersonal Data Protection Centre (official gazette copy)Personal Data Protection Law No. 151 of 2020 — penalties chapter, including imprisonment of not less than three months and a fine of five hundred thousand to five million Egyptian pounds for breaching the cross-border data movement rules
pdpc.gov.eg
“يعاقب بالحبس مدة لا تقل عن ثلاثة شهور وبغرامة لا تقل عن خمسمائة ألف جنيه ولا تجاوز خمسة ملايين جنيه، أو بإحدى هاتين العقوبتين، كل من خالف أحكام حركة البيانات”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CentreEgypt's Personal Data Protection Framework, March 2026 — children's data obligations and data protection officer requirements
pdpc.gov.eg
“Children under 15 years of age: The controller shall obtain the explicit written consent of the parent or legal guardian prior to collecting or processing the child's personal data”
Link checked 18 August 2026
- Official sourceEgyptian Drug AuthorityLaw No. 214 of 2020 regulating Clinical Medical Research, Official Gazette issue 51 bis (F), 23 December 2020, Articles 20 and 22 (official English translation published by the Egyptian Drug Authority)
edaegypt.gov.eg
“Any person who contributes in any way whatsoever in the exit of human samples used in clinical medical research during or after the research without the prior approvals stipulated under the law shall be punishable by imprisonment and a fine of at least five hundred thousand Egyptian Pounds and no more than one million Egyptian Pounds.”
Link checked 18 August 2026
- Official sourceNational Telecom Regulatory AuthorityLaw No. 175 of 2018, Article 2 (Third) — duty to give national security bodies the technical means to exercise their powers
tra.gov.eg
“يلتزم مقدمو الخدمة والتابعون لهم أن يوفروا حال طلب جهات الأمن القومي ووفقاً لاحتياجاتها كافة الإمكانيات الفنية التي تتيح لتلك الجهات ممارسة اختصاصاتها وفقاً للقانون”
Link checked 18 August 2026
What's changing next
One date dominates. The detailed rules were published on the first of November 2025 and took effect the next day, starting a one-year window to get licensed. That window closes at the beginning of November 2026. After it, processing personal data without the right licence is simply a breach of the law. Everything else that matters is a switch the government already holds and can flip without warning.
Dormant switches, in order of how much they would change the picture. One: the list of countries the regulator considers safe enough to receive Egyptian data. It is promised, it is not published, and publishing it would instantly make transfers to those countries far easier, while leaving everyone else worse off by comparison. Two: the recommended contract wording for transfers. Also promised, also not published, which leaves applicants guessing what safeguards will satisfy the regulator. Three: the Centre's decisions page, which is empty today and can be filled at any time with binding rules on any sector. Four: fees, which the Centre's board can change by its own decision. Five: the telecom regulator's board can add new categories of data to the one-hundred-and-eighty-day retention duty by decision. Six: the Centre may amend the terms of a licence you already hold, after it has been issued, on public-interest grounds. Egypt attended the Global Cross-Border Privacy Rules Forum spring workshop in March 2026 and says it is pursuing reciprocal adequacy findings, so movement on international recognition is plausible but nothing is agreed.
Sources
- Official sourcePersonal Data Protection CentrePersonal Data Protection Centre published questions and answers — commencement of the executive regulations and start of the compliance period
pdpc.gov.eg
“The Executive Regulations No. 816 of 2025 of the Egyptian Personal Data Protection Law (PDPL), issued under the Ministerial Decree No. 816 of 2025 and published in the Official Gazette on 1 November 2025, enters into force on the day following its publication. A one-year compliance period commences from the date of entry into force of the Executive Regulations No. 816 of 2025.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CentreLicenses and Permits Guidelines, version 1.1, 26 January 2026 — Transitional Provisions: The One-Year Compliance Grace Period
pdpc.gov.eg
“All data users, whether natural or juridical persons, must apply for the necessary licenses or permits within the one-year grace period, as stipulated by the PDPL. If entities fail to obtain the required licenses or permits within this period, any processing of personal data thereafter shall constitute a violation of the provisions of the PDPL and the ER.”
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
قرار مجلس إدارة الهيئة العامة للرقابة المالية رقم 139 لسنة 2023 (Financial Regulatory Authority Board Decision No. 139 of 2023)
Directly binding regulation · Board Decision No. 139 of 2023 dated 21 June 2023, published in Al-Waqa'i al-Misriyya issue 150 supplement (A), 11 July 2023
Firms licensed to carry on non-bank financial activities in Egypt using financial technology must keep their customer database physically inside Egypt, and must tell the Financial Regulatory Authority within thirty days if they begin moving their head office or data centre. The decision sets the database location but does not expressly say whether a further copy may also be held abroad.
Enforced by Financial Regulatory Authority
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryThe company's customer database must sit within Egypt's geographic borders.
- Tell people what you do — within 720 hoursThe Authority must be told within thirty days of the company starting any steps to move its head office or its data centre.
- Secure the dataMinimum stack specified: firewall, web application firewall, asset-wide security, real-time event monitoring, database encryption to international standards, and continuous patching.
- Hold a security certificateLicensed operating systems and applications, and high availability, are minimum conditions.
What it costs if you get it wrong
- Loss of your licenceFailure to meet the technology and infrastructure requirements attached to a financial technology licence
Sources
- Official sourceFinancial Regulatory AuthorityFinancial Regulatory Authority Board Decision No. 139 of 2023 on the equipment, technological infrastructure, information systems and protection means required for using financial technology in non-bank financial activities
fra.gov.eg
“أن تكون قاعدة بيانات عملاء الشركة داخل الحدود الجغرافية لجمهورية مصر العربية”
Link checked 18 August 2026
- Official sourceFinancial Regulatory AuthorityFinancial Regulatory Authority legislative portal — Board Decision No. 139 of 2023
fra.gov.eg
Link checked 18 August 2026
Personal Data Protection Law No. 151 of 2020 — exclusion of the Central Bank of Egypt and the entities under its supervision
Act of parliament · Law No. 151 of 2020, scope exclusions; supervision under the Central Bank and Banking System Law No. 194 of 2020
Personal data held by the Central Bank of Egypt and the banks and institutions it supervises is carved out of the privacy law entirely, so the national licence and transfer regime does not reach it. Money transfer companies and exchange offices are expressly not carved out and remain fully inside the privacy law. What rules on data location the central bank applies to banks instead is not publicly retrievable, so this row is rated unknown rather than open.
Enforced by Central Bank of Egypt
Transfer model: Approval each time
What it makes you do
- Register or notifyBanks are licensed and supervised by the Central Bank of Egypt rather than by the privacy regulator.
What it costs if you get it wrong
- Loss of your licenceBreach of central bank supervisory requirements
Sources
- Official sourcePersonal Data Protection CentrePersonal Data Protection Centre published questions and answers — categories of personal data outside the law's scope
pdpc.gov.eg
“Personal data held by the Central Bank of Egypt and entities under its supervision and control, except money transfer companies and exchange offices, which remain subject to the PDPL.”
Link checked 18 August 2026
- Official sourceCentral Bank of EgyptCentral Bank of Egypt — Banking Laws, including CBE Law No. 194 of 2020 and its executive regulations
cbe.org.eg
Link checked 18 August 2026
قانون رقم 175 لسنة 2018 في شأن مكافحة جرائم تقنية المعلومات (Law No. 175 of 2018 on Combating Information Technology Crimes)
Act of parliament · Law No. 175 of 2018, Official Gazette issue 32 bis (c), 14 August 2018, Article 2; executive regulations published by the National Telecom Regulatory Authority
Anyone supplying information and communication technology services in Egypt must keep system logs for one hundred and eighty consecutive days, keep them confidential except on a judge's reasoned order, and give national security bodies the technical means to do their work. We found no requirement in the text we read that these logs be stored inside Egypt, checked 18 August 2026.
Enforced by National Telecom Regulatory Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep logs — 6 monthsOne hundred and eighty consecutive days, covering data identifying the user, content data under the provider's control, traffic data, terminal device data, and any further categories added by decision of the telecom regulator's board.
- Secure the dataProviders must keep the stored data confidential and may only disclose it on a reasoned order from a competent judicial authority.
- Do not hand data to foreign authorities on demandThe opposite duty applies here: providers must give Egypt's own national security bodies all the technical capabilities those bodies need.
What it costs if you get it wrong
- Criminal liabilityBreach of service provider duties under the law
Sources
- Official sourceNational Telecom Regulatory AuthorityLaw No. 175 of 2018 on Combating Information Technology Crimes, Official Gazette copy, Article 2
tra.gov.eg
“حفظ وتخزين سجل النظام المعلوماتي أو أي وسيلة لتقنية المعلومات لمدة مائة وثمانين يوماً متصلة”
Link checked 18 August 2026
- Official sourceNational Telecom Regulatory AuthorityNational Telecom Regulatory Authority — Laws and Legislations, listing Law No. 175 of 2018 and its executive regulations
tra.gov.eg
Link checked 18 August 2026
قانون رقم 214 لسنة 2020 بإصدار قانون تنظيم البحوث الطبية الإكلينيكية (Law No. 214 of 2020 regulating Clinical Medical Research)
Act of parliament · Law No. 214 of 2020, Official Gazette issue 51 bis (F), 23 December 2020, Articles 15, 20 and 22
Clinical medical research on people in Egypt sits under its own law. Human samples may not cross the border in either direction without approval from the Supreme Council for Clinical Medical Research and consideration of national security, and helping samples leave without that approval is punishable by imprisonment plus a fine of five hundred thousand to one million Egyptian pounds. Research records must be open to the intelligence service for audit.
Enforced by Egyptian Drug Authority
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Get consentInformed consent of the research subject or their legal representative is required to use human samples at all, and again to keep leftover samples for future research.
- Keep records of processingAll information, data and reports must be recorded, filed, kept and verified for integrity and accuracy.
- Independent auditData and reports must be made available during and after the research to the institutional review board, the Supreme Council, the General Intelligence Agency and the Egyptian Drug Authority.
- Keep the data in the countryHuman samples may not enter or leave Egypt without the approval of the Supreme Council, with national security requirements taken into account.
What it costs if you get it wrong
- Criminal liability: EGP 1,000,000 and imprisonment — about $20 thousandContributing in any way to human research samples leaving Egypt without the prior approvals required by the law
Sources
- Official sourceEgyptian Drug AuthorityLaw No. 214 of 2020 regulating Clinical Medical Research — official English translation published by the Egyptian Drug Authority
edaegypt.gov.eg
“The approval of the Supreme Council and considerations and requirements of national security shall be taken into account before the entry or exit of any human samples related to medical research into or out of the Arab Republic of Egypt for any purpose whatsoever.”
Link checked 18 August 2026
- Official sourceEgyptian Drug AuthorityEgyptian Drug Authority — Laws and Executive Regulations index listing Law No. 214 of 2020
edaegypt.gov.eg
Link checked 18 August 2026
Applies to every company1 rule
These bind you whatever business you are in, once the country's rules reach you.
قانون حماية البيانات الشخصية رقم 151 لسنة 2020 (Personal Data Protection Law No. 151 of 2020)
Act of parliament · Law No. 151 of 2020, Official Gazette 15 July 2020; Executive Regulations issued by Ministerial Decree No. 816 of 2025, Official Gazette 1 November 2025
Egypt's general privacy law. You need a government licence to process personal data at all, and a second licence to send it abroad; cloud storage on foreign servers counts as sending it abroad. Detailed rules came into force on 2 November 2025 and every organisation must be licensed by early November 2026. Breaking the transfer rules is a criminal offence.
Enforced by Personal Data Protection Centre
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed, Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Important public interest, Someone's life is at risk
What it makes you do
- Register or notify — from 2 November 2025A general licence (three years) or permit (up to one year) is required to process personal data at all. A supplementary licence is required for cross-border transfer, electronic direct marketing, and cameras in public places.
- Put a transfer safeguard in placeA transfer impact assessment, contractual arrangements and an assessment of the destination country's legal framework are required before applying.
- Appoint a data protection officerMust be registered in the Centre's register, sit the Centre's category examination, report to top management and be independent. A prerequisite for any licence.
- Appoint a local representativeRequired where the organisation has no establishment in Egypt. The Centre must approve the appointment.
- Get consent
- Document a legitimate interest
- Allowed because the law requires it
- Tell people what you do
- Let people see their dataAnswer within six working days of the request.
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Secure the data
- Keep records of processingRecord of processing activities; the Centre publishes a template.
- Assess high-risk projects
- Report breaches to the regulator — within 72 hoursImmediately where the breach touches national security.
- Tell affected peopleWithin three working days of notifying the Centre.
- Get a parent's consent for children — applies at: under 18, in two tiers: under 15 and 15 to 18
- Keep data for a minimum period — applies at: Electronic direct marketing consents and opt-out requests, 3 years
- Delete data after a periodStorage limitation is one of the seven processing principles.
- Written vendor contract
What it costs if you get it wrong
- Criminal liability: EGP 5,000,000 and imprisonment of not less than three months — about $99 thousandBreaching the rules on cross-border movement of personal data
- Criminal liability: EGP 5,000,000 and imprisonment of not less than three months — about $99 thousandUnlawful handling of sensitive personal data by a holder, controller or processor
- Fixed maximum fine: EGP 3,000,000 — about $59 thousandController breaches of core duties
- Fixed maximum fine: EGP 2,000,000 — about $40 thousandCollecting personal data without meeting the statutory conditions
- Fixed maximum fine: EGP 1,000,000 — about $20 thousandGeneral breach by a holder or controller
- Criminal liability: EGP 2,000,000 and imprisonment of not less than six months — about $40 thousandObstructing staff of the Personal Data Protection Centre
- Order to stopFailure to remedy a violation after warning; partial or complete suspension of the licence or permit
- Loss of your licenceFailing licence conditions, non-payment of renewal fees, repeated breaches of the Centre's decisions, transferring the licence without authorisation, or bankruptcy
Sources
- Official sourcePersonal Data Protection CentrePersonal Data Protection Law No. 151 of 2020, Official Gazette text
pdpc.gov.eg
Link checked 18 August 2026
- Official sourcePersonal Data Protection CentreExecutive Regulations of the Personal Data Protection Law, issued by Ministerial Decree No. 816 of 2025
pdpc.gov.eg
Link checked 18 August 2026
- Official sourcePersonal Data Protection CentreLicenses and Permits Guidelines, version 1.1, 26 January 2026
pdpc.gov.eg
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
That the Personal Data Protection Centre's approved-country list and recommended contract clauses are still unpublished today
The Centre's own website content was last changed on 7 April 2026, so we can only evidence the position to that date. Anything issued between April and August 2026 would not show. Treat the empty list as a snapshot, not a certainty.
Whether the online licence and permit application portal is actually accepting and granting applications
The Centre's March 2026 deck announces the launch and describes the steps, but the portal subdomains we tried did not resolve from outside Egypt and we found no published count of licences issued.
What rules the Central Bank of Egypt applies to banks on cloud computing, outsourcing and where data may be stored
Banks are outside the privacy law, so the central bank's rulebook is what binds them. Its circular archive is filtered by a script we could not drive, and no cloud or data-location circular appears in the English list of titles we could read. This is the single largest gap in this record.
Whether conventional insurers, brokers and securities firms face a data localisation duty when they are not using financial technology
The Financial Regulatory Authority decision we verified is expressly about carrying on non-bank financial activities through financial technology. We did not locate an equivalent rule for firms outside that route.
Whether Financial Regulatory Authority Decision No. 139 of 2023 permits an additional copy of the customer database to be held abroad
The decision states where the database must be, and says nothing either way about a second copy. We have rated it as a mirror requirement for that reason rather than a full prohibition.
Egypt's general tax and commercial book-keeping retention periods
The tax authority's website did not expose its legislation index to us in this run. We have not asserted a figure rather than repeat an unverified one.
Any data residency or sovereignty condition in government cloud procurement, education, gambling, mapping or defence
No rule found in an official source, checked 18 August 2026. The ministry's site blocks automated access, and the survey authority publishes no rule on the export of mapping data. Absence of a finding here is a gap in our search, not evidence that no rule exists.
Whether the telecom regulator's incident response team or the central bank impose their own separate breach reporting deadlines
Both publish a 'report an incident' route but we could not open a document setting a deadline in hours.
The exact wording of the executive regulations issued by Ministerial Decree No. 816 of 2025
The only copy published by the regulator is a scanned Arabic image with no text layer. Our account of its content relies on the regulator's own English guidelines, framework deck and published questions and answers, all of which describe it directly.
The composition of the Personal Data Protection Centre's board of directors
The Centre's executive management page carries no entries, although its guidelines refer to board decisions on fees.
30-day cadence. Egypt is mid-commencement: the licensing grace period ends in early November 2026, and the regulator's approved-country list, its standard contract clauses and its first enforcement decisions are all pending and can each appear without consultation. The regulator's own website has not been updated since April 2026, so this record's picture of what has and has not been published is the most perishable part of it.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.
Put this next to another country
Egypt versus
Compare