Egypt PDPL

Egypt's data-protection law: a licence-and-permit regime with a mandatory DPO and 72-hour breach duty.

Market regime · Personal Data Protection Law No. 151 of 2020 (Egypt)

Issued by

Arab Republic of Egypt

Region

Egypt

Effective

2020; executive regulations long pending

Oversight

Egyptian Data Protection Centre

Applies when

You process personal data of Egyptian residents, or from Egypt

In the catalog

Curated, versioned & cross-mapped

The obligation, plainly.

Egypt's PDPL takes a distinctive path: processing personal data requires a licence or permit from the Data Protection Centre, a data protection officer is mandatory, sensitive data and cross-border transfers each need their own permits, and breaches are notified to the Centre on a 72-hour clock.

The law's executive regulations have been long awaited, and obligations sharpen as they land. The curated framework tracks the Law's requirements as enacted, flagged where the regulations will supply detail, so adopters see exactly what is firm and what is pending.

Where programmes are tested.

01

Licence and permits

The Centre's licence or permit before processing, with sensitive-data and transfer permits layered on.

02

Mandatory DPO

A data protection officer appointed and known to the Centre, running the compliance programme.

03

Consent-centred processing

Processing grounded in consent or the Law's narrow alternatives, evidenced per activity.

04

72-hour breach notification

Breaches notified to the Centre within 72 hours, with the affected informed as required.

Curated once, evidenced continuously.

  • PDPL requirements are curated with the permit regime modelled explicitly, and cross-mapped to the shared privacy control set so multinationals answer Cairo, Lagos and Brussels from one implementation.
  • Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
  • Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
  • Every attestation carries maker/checker, and every action lands in an append-only audit trail.

Egypt PDPL, asked plainly.

The questions compliance teams actually ask before an adoption decision or an audit.

What makes Egypt's PDPL different from GDPR-style laws?

The licensing model: rather than principles alone, the Law requires a licence or permit from the Data Protection Centre for processing, with separate permits for sensitive data and cross-border transfers. Compliance is therefore partly an authorisation exercise, not only an accountability one.

Is a DPO mandatory in Egypt?

Yes, the PDPL makes appointing a data protection officer a general obligation for controllers and processors, and the DPO is the Centre's point of contact. It is one of the few regimes in the portfolio where the role is unconditional.

What is the status of the executive regulations?

The Law entered into force in 2020 but its executive regulations, which supply licensing procedure, fee schedules and operational detail, remained pending for years. We curate the Law's firm requirements and mark where the regulations will complete the picture, versioning when they issue.

Can personal data leave Egypt?

Only with the Centre's permit and to destinations offering an adequate level of protection, subject to the Law's conditions. Transfer mapping and permit evidence therefore belong in the processing inventory from day one.

Where it connects.

The full catalog
Cross-mapped with

Compliance you can prove.
Walk into your next audit ready.

Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.

The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.