Skip to the content
Global Data RulesData governance rules, country by country

Egypt

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Egypt — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: Very highEnforcement: Waking up

Egypt now runs a full permission system. You need a government licence just to handle people's data. You need a second licence on top of that to send any of it out of the country. Using a cloud service whose servers sit abroad counts as sending it out. The detailed rules finally arrived on the first of November 2025. Every organisation has until early November 2026 to get licensed.

Data governance in Egypt

The eight things that decide how you handle data about people in Egypt. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law follows the person, not the office. It covers the data of Egyptian citizens wherever in the world they live. It also covers anyone else living in Egypt. If your company has no office or branch in Egypt but handles that data, you must appoint a legal representative inside Egypt. The regulator has to approve your choice. No size or revenue level lets you off. Licence fees rise with how many people's records you hold. There is no level below which you are free.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Only with written permission from the regulator, granted to you specifically. Sending personal data out of Egypt is banned unless you hold a cross-border transfer licence or permit from the Personal Data Protection Centre. A short list of emergencies is the only other way. Storing data with a cloud provider whose servers are outside Egypt counts as sending it out. Two industries are stricter still. Financial technology firms in non-bank finance must keep the customer database inside Egypt. Footage from cameras in public places may not leave at all, unless a law says so.

What you have to do here:
Keep the data in the country · Put a transfer safeguard in place

What to do: Get the paperwork for one of the routes below signed before any data leaves Egypt.

Sending data out of the country

You apply, and you wait. First you need a general licence to handle data at all. Then you apply for a separate cross-border transfer licence. To get it you must show one of two things. Either the destination country is on the regulator's approved list. Or you have extra protections in place, such as the contract wording the regulator recommends. The approved list has not been published yet, so everyone is on the second route. The regulator has ninety days to decide, and silence means refusal.

Ways to send data out:
Government sign-off needed · Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Approved code of conduct · Explicit consent · Needed for a contract · Legal claims · Important public interest · To save someone’s life

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Personal Data Protection Centre. It is real and working, not just a name on paper. It has staff, departments and an acting chief executive. It has published guidelines updated in January 2026. It runs an online application portal and a training programme for data protection officers. What it has not done yet is punish anyone in public. Its own website page for decisions is empty. So are its news, press release and annual report pages. Industry regulators for banking, non-bank finance, telecoms and medicines have been enforcing for years.

How long you must keep it — and when to delete it

There is a minimum and a maximum, and they come from different laws. The maximum is simple. You may not keep personal data longer than the purpose you collected it for. The minimums we could verify are narrow. Marketing consents and opt-out requests must be kept for at least three years. Internet and technology service providers must keep their system records for one hundred and eighty days in a row. You must also keep your paperwork about any data breach.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep records of how you use data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

Two deadlines run one after the other. You have seventy-two hours from the moment you find out to tell the regulator. If the breach touches national security you must tell it immediately, with no grace period at all. Then you have three working days from the date you told the regulator to tell the people affected. You must also tell them what you did to contain the damage. The regulator publishes a form for each of those two notifications.

What you have to do here:
Report breaches to the regulator · Tell affected people · Secure the data

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things catch people out. First, you need a licence to handle personal data at all, not just to move it abroad. You cannot get one without a data protection officer registered with the regulator. Second, breaking the transfer rules is a crime, not a fine. It carries at least three months in prison plus a penalty of up to five million Egyptian pounds, roughly one hundred thousand United States dollars. Third, a child means anyone under eighteen, in two stages. Fourth, banks are outside the privacy law but money changers are not. Fifth, you have six working days, not a month, to answer someone who asks about their data.

What you have to do here:
Register or notify · Appoint a data protection officer · Get a parent's consent for children · Let people see their data · Do not hand data to foreign authorities on demand
What it costs if you get it wrong:
Criminal liability

What's changing next

One date dominates. The detailed rules were published on the first of November 2025 and took effect the next day. That started a one-year window to get licensed. The window closes at the beginning of November 2026. After that, handling personal data without the right licence simply breaks the law. Everything else that matters is a power the government already holds. It can use any of them without warning.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Finance

Finance data needs a copy kept in the country

Official name: قرار مجلس إدارة الهيئة العامة للرقابة المالية رقم 139 لسنة 2023 (Financial Regulatory Authority Board Decision No. 139 of 2023) · Board Decision No. 139 of 2023 dated 21 June 2023, published in Al-Waqa'i al-Misriyya issue 150 supplement (A), 11 July 2023 · Directly binding regulation

In forceA copy must stay

Some firms are licensed to do non-bank financial work in Egypt using financial technology. They must keep their customer database inside Egypt. They must tell the Financial Regulatory Authority within thirty days if they start moving their head office or data centre. The decision sets where the database sits. It does not say whether a further copy may also be held abroad.

In force since 12 July 2023

Enforced by Financial Regulatory Authority

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed

Banking

Banking rules

Official name: Personal Data Protection Law No. 151 of 2020 — exclusion of the Central Bank of Egypt and the entities under its supervision · Law No. 151 of 2020, scope exclusions; supervision under the Central Bank and Banking System Law No. 194 of 2020 · Act of parliament

In forceNot yet established

Personal data held by the Central Bank of Egypt, and by the banks and institutions it supervises, is left out of the privacy law entirely. The national licence and transfer rules do not reach it. Money transfer companies and exchange offices are expressly not left out and stay fully inside the privacy law. We could not find what rules on data location the central bank applies to banks instead. So this row is rated unknown rather than open.

In force since 16 October 2020

Enforced by Central Bank of Egypt

How this country controls where data goes: Approval each time

Not fully verified — see “What we're not sure about” below.
Telecoms

State and security data rules

Official name: قانون رقم 175 لسنة 2018 في شأن مكافحة جرائم تقنية المعلومات (Law No. 175 of 2018 on Combating Information Technology Crimes) · Law No. 175 of 2018, Official Gazette issue 32 bis (c), 14 August 2018, Article 2; executive regulations published by the National Telecom Regulatory Authority · Act of parliament

In forceYes — store it anywhere

Anyone supplying information and communication technology services in Egypt must keep system logs for one hundred and eighty days in a row. They must keep them confidential, except on a judge's reasoned order. They must also give national security bodies the technical means to do their work. We found no requirement in the text we read that these logs be stored inside Egypt, checked 18 August 2026.

In force since 15 August 2018

Enforced by National Telecom Regulatory Authority

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.

Applies to every company1 rule

These bind you whatever business you are in, once the country's rules reach you.

Cloud and outsourcing rules

Official name: قانون حماية البيانات الشخصية رقم 151 لسنة 2020 (Personal Data Protection Law No. 151 of 2020) · Law No. 151 of 2020, Official Gazette 15 July 2020; Executive Regulations issued by Ministerial Decree No. 816 of 2025, Official Gazette 1 November 2025 · Act of parliament

In forceYes, with paperwork

Egypt's general privacy law. You need a government licence to handle personal data at all. You need a second licence to send it abroad. Cloud storage on foreign servers counts as sending it abroad. Detailed rules came into force on 2 November 2025. Every organisation must be licensed by early November 2026. Breaking the transfer rules is a crime.

In force since 16 October 2020In force now, but not enforced until 2 November 2026

That is a long gap: the duty is real law today, but no penalty can follow until 2 November 2026. A contract you sign can still hold you to it from day one — and government contracts often do.

Enforced by Personal Data Protection Centre

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed, Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Important public interest, To save someone’s life

Who you would hear from

  • مركز حماية البيانات الشخصية

    General privacy law: licences, permits, accreditation, the register of data protection officers, complaints and inspection

    Really operating, but not yet punishing anyone in public. The evidence as at 18 August 2026: guidelines version 1.1 dated 26 January 2026; a slide deck on the rules and enforcement dated March 2026; an online licensing portal; a data protection officer register with three examined categories; a four-day officer training programme in February 2026 with the German Embassy, the European Union Delegation and the African Union; and attendance at the Global Cross-Border Privacy Rules Forum in March 2026. It is led by an Acting Chief Executive. It has published no enforcement decision, annual report, news item or press release on its site. The site's content has not changed since 7 April 2026.

  • وزارة الاتصالات وتكنولوجيا المعلومات

    Issued the executive regulations of the privacy law by Ministerial Decree No. 816 of 2025; parent ministry of the Personal Data Protection Centre

  • البنك المركزي المصري

    Banks and the institutions it supervises, which are excluded from the privacy law; payment systems

    A fully active supervisor, issuing circulars all through 2026. We could not retrieve its own rules on cloud use, outsourcing and where bank data must sit.

  • الهيئة العامة للرقابة المالية

    Non-bank finance: insurance, capital markets, leasing, consumer and mortgage finance, and financial technology in all of those

    Active, issuing board decisions continuously. It publishes a list of companies that have broken non-bank finance law.

  • الجهاز القومي لتنظيم الاتصالات

    Telecoms licensing, and the log retention and state access duties on service providers under the 2018 information technology crimes law

  • هيئة الدواء المصرية

    Medicines, medical devices and clinical research, alongside the Supreme Council for Clinical Medical Research

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That the Personal Data Protection Centre's approved-country list and recommended contract clauses are still unpublished today

    We could not confirm the position after April 2026. The Centre's own website content was last changed on 7 April 2026, so our evidence stops there. Anything issued between April and August 2026 would not show. Treat the empty list as a snapshot in time, not a certainty.

  • Whether the online licence and permit application portal is actually accepting and granting applications

    We could not confirm that the licensing portal is open, or how many licences it has issued. The Centre's March 2026 slide deck announces the launch and describes the steps. The portal addresses we tried did not load from outside Egypt, and we found no published count of licences.

  • What rules the Central Bank of Egypt applies to banks on cloud computing, outsourcing and where data may be stored

    We could not confirm what rules the central bank applies to bank data. Banks sit outside the privacy law, so the central bank's rulebook is what binds them. Its circular archive is filtered by a script we could not use. No cloud or data-location circular appears in the English list of titles we could read. This is the biggest gap in this record. If you are a bank, ask the central bank directly.

  • Whether conventional insurers, brokers and securities firms face a keeping data in the country duty when they are not using financial technology

    We could not confirm the position for non-bank finance firms that do not use financial technology. The Financial Regulatory Authority decision we verified is expressly about doing non-bank financial work through financial technology. We found no equivalent rule for other firms.

  • Whether Financial Regulatory Authority Decision No. 139 of 2023 permits an additional copy of the customer database to be held abroad

    We could not confirm whether a second copy of the database may be held abroad. The decision says where the database must be and says nothing either way about a copy. For that reason we have recorded it as a duty to keep a copy in Egypt, rather than a full ban on holding data elsewhere.

  • Egypt's general tax and commercial book-keeping retention periods

    We could not confirm Egypt's general tax and book-keeping keep-times. The tax authority's website did not show us its list of legislation. We would rather state nothing than repeat an unverified figure. Check with the tax authority before you rely on it.

  • Any where data has to be stored or sovereignty condition in government cloud procurement, education, gambling, mapping or defence

    We found no rule in an official source, checked 18 August 2026. The ministry's site blocks automated access, and the survey authority publishes no rule on sending mapping data abroad. This is a gap in our search, not proof that no rule exists. If you work with maps, check before you rely on it.

  • Whether the telecom regulator's incident response team or the central bank impose their own separate breach reporting deadlines

    We could not confirm whether either body sets its own incident deadline in hours. Both publish a 'report an incident' route, but we could not open a document setting a time limit.

  • The exact wording of the executive regulations issued by Ministerial Decree No. 816 of 2025

    We could not read the original text of this decision. The only copy the regulator publishes is a scanned Arabic image with no text layer. Our account of what it says relies on the regulator's own English guidelines, slide deck and published questions and answers. All of those describe it directly.

  • The composition of the Personal Data Protection Centre's board of directors

    We could not confirm who sits on the Centre's board. Its executive management page has no entries, although its guidelines refer to board decisions on fees.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.