Country:埃及 · Data Privacy
Medium confidenceUpdated 2026-08-03Handbook

Egypt · Data Privacy

Egypt's Personal Data Protection Law (PDPL, Law No. 151/2020) is in force, establishing a Personal Data Protection Center and benchmarking the GDPR framework: processing personal data requires a lawful basis, data subject rights must be guaranteed, and cross-border transfers must meet restrictive conditions. Chinese companies processing Egyptian user or employee data must comply with this law and also meet China's Data Security Law and PIPL export requirements.

Key points

Procedure

  1. Data inventory and lawful-basis confirmation.
  2. Draft privacy policies and data subject rights response mechanisms.
  3. Pre-transfer assessment (Egyptian PDPL + China PIPL).
  4. Appoint a data processing officer and conduct training.
  5. Establish data breach emergency procedures.

Hard requirements

Costs

Compliance system building; legal consulting.⏱ ⏱ Timeline:Continuous compliance.

⚠ Common risks

  • Non-compliant processing faces regulatory penalties.
  • Cross-border transfer violations (dual violation on Egyptian and Chinese sides).
  • Data breach reputational damage and legal liability.
Handbook

📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)

Applies to:Chinese companies processing Egyptian residents' personal data in Egypt, or transferring it back to China (governed by Law No. 151/2020 and the 2025 implementing regulations, full enforcement from 2026-10-31).

Prerequisites

  • Processing activities clarified and a PDPC general license (valid 3 years) obtained.
  • Cross-border transfers, sensitive processing, etc. require separate special licenses.
  • Budget reserved for DPO registration and Arabic notices.
StepActionOwnerTimelineCostOfficial form / systemNotes & penalties
1Data inventory and lawful-basis confirmation.
Map personal data categories and processing purposes, confirm the lawful basis (mainly explicit consent), and establish a ROPA.
Legal/Compliance2–3 weeksInternal costROPA, data inventoryConsent must be specific and recorded in writing.
Penalty:Fine EGP 200,000–5,000,000.
2Apply for PDPC processing licenses (general + special).
Apply to the Personal Data Protection Center (PDPC) for a general processing license (3-year validity); cross-border transfers and sensitive data require separate special licenses.
LegalPer portal opening (mid-2026)License/application costsPDPC license applicationGrace period until full enforcement on 2026-10-31.
Penalty:Processing without a license can be penalized and business restricted.
3Publish Arabic privacy notices and consent.
Publish concise, visible privacy notices in Arabic and obtain explicit, itemized, verifiable consent (no bundling or pre-checking).
Legal1–2 weeksInternal/translation costsArabic privacy notice, consent recordsSensitive information or children (<15) require written consent or parental consent.
Penalty:Same ceiling as step 1.
4Cross-border transfer license and mechanism.
Apply to the PDPC for a cross-border transfer license and prove the destination's protection level; returning data to China requires simultaneous PIPL export mechanisms.
Legal3–6 weeksLicense/lawyer costsCross-border license, PIPL export documentsCloud storage also requires a license.
Penalty:Unlicensed cross-border transfer is penalized and business suspended.
5Appoint and register a DPO.
Where applicable, appoint a qualified data protection officer and register with the PDPC (obtain an accountability code).
ManagementOngoingDPO staffing/exam costsDPO appointment, PDPC registrationCategories A/B/C, reassessed every three years.
Penalty:Failure to appoint or register is penalized.
6Data subject rights response (6 working days).
Establish access, rectification, erasure response mechanisms; the PDPL requires responses within about 6 working days (fees up to EGP 20,000).
DPO/customer serviceNo more than 6 working daysInternal costDSAR processMust establish a PDPC-recognized mechanism.
Penalty:Refusing to respond is penalized.
7Notify breaches within 72 hours.
Notify the PDPC within 72 hours of a breach and affected individuals within 3 working days thereafter.
DPO/IT72 hours + 3 working daysInternal costPDPC breach reportSet up automatic triggers.
Penalty:Late or concealed reporting aggravates penalties.

✅ Self-check list

⚠ Common pitfalls

Assuming the PDPL is still 'dormant' and non-compliant影响:Directly penalized after 2026-10-31规避:Complete licenses and systems within the grace period
Transferring cross-border without a PDPC license影响:Penalized and relevant business suspended规避:Apply for the cross-border data transfer license first
English-only privacy notices影响:Notice invalid规避:Provide notices in Arabic
Ignoring PIPL export for data return to China影响:Dual violation规避:Handle China-side mechanisms in parallel
DPO not registered with the PDPC影响:Penalized for missing accountability mechanisms规避:Register immediately after appointment to obtain the code
Breach reported after 72 hours影响:Aggravated penalties规避:Set up automatic reporting triggers

📅 Ongoing post-incorporation obligations

  • Renew PDPC licenses (general term 3 years)
  • Maintain DPO registration and 3-year reassessment
  • 72-hour breach notification and individual notice
  • Continuously respond to DSAR requests
  • China PIPL data export mechanisms remain effective

🔗 Official portals

📎 Source:Egyptian Personal Data Protection Law No. 151/2020; Egyptian Data Protection Center; https://www.cac.gov.cn
Want to turn this into an actionable compliance workflow?

CompliGo · Outbound Compliance Automation

You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.

CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.