Egypt PDPL
Market regime · Personal Data Protection Law No. 151 of 2020 (Egypt)
Arab Republic of Egypt
Egypt
2020; executive regulations long pending
Egyptian Data Protection Centre
You process personal data of Egyptian residents, or from Egypt
Curated, versioned & cross-mapped
The obligation, plainly.
Egypt's PDPL takes a distinctive path: processing personal data requires a licence or permit from the Data Protection Centre, a data protection officer is mandatory, sensitive data and cross-border transfers each need their own permits, and breaches are notified to the Centre on a 72-hour clock.
The law's executive regulations have been long awaited, and obligations sharpen as they land. The curated framework tracks the Law's requirements as enacted, flagged where the regulations will supply detail, so adopters see exactly what is firm and what is pending.
Where programmes are tested.
Licence and permits
The Centre's licence or permit before processing, with sensitive-data and transfer permits layered on.
Mandatory DPO
A data protection officer appointed and known to the Centre, running the compliance programme.
Consent-centred processing
Processing grounded in consent or the Law's narrow alternatives, evidenced per activity.
72-hour breach notification
Breaches notified to the Centre within 72 hours, with the affected informed as required.
Curated once, evidenced continuously.
- PDPL requirements are curated with the permit regime modelled explicitly, and cross-mapped to the shared privacy control set so multinationals answer Cairo, Lagos and Brussels from one implementation.
- Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
- Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
- Every attestation carries maker/checker, and every action lands in an append-only audit trail.
Egypt PDPL, asked plainly.
The questions compliance teams actually ask before an adoption decision or an audit.
What makes Egypt's PDPL different from GDPR-style laws?
The licensing model: rather than principles alone, the Law requires a licence or permit from the Data Protection Centre for processing, with separate permits for sensitive data and cross-border transfers. Compliance is therefore partly an authorisation exercise, not only an accountability one.
Is a DPO mandatory in Egypt?
Yes, the PDPL makes appointing a data protection officer a general obligation for controllers and processors, and the DPO is the Centre's point of contact. It is one of the few regimes in the portfolio where the role is unconditional.
What is the status of the executive regulations?
The Law entered into force in 2020 but its executive regulations, which supply licensing procedure, fee schedules and operational detail, remained pending for years. We curate the Law's firm requirements and mark where the regulations will complete the picture, versioning when they issue.
Can personal data leave Egypt?
Only with the Centre's permit and to destinations offering an adequate level of protection, subject to the Law's conditions. Transfer mapping and permit evidence therefore belong in the processing inventory from day one.
Where it connects.
The full catalogCompliance you can prove.
Walk into your next audit ready.
Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.
The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.