Country:埃及 · Data Privacy
Egypt · Data Privacy
Egypt's Personal Data Protection Law (PDPL, Law No. 151/2020) is in force, establishing a Personal Data Protection Center and benchmarking the GDPR framework: processing personal data requires a lawful basis, data subject rights must be guaranteed, and cross-border transfers must meet restrictive conditions. Chinese companies processing Egyptian user or employee data must comply with this law and also meet China's Data Security Law and PIPL export requirements.
Key points
- Law No. 151/2020 (PDPL) is in force, establishing the Personal Data Protection Center as the regulator.
- Processing personal data requires a lawful basis and guarantees data subject rights (access, rectification, erasure, etc.).
- Cross-border transfers: must meet equivalent protection levels or obtain data subject consent, among other conditions.
- Violations can be penalized with fines and business restrictions.
- China's PIPL dual compliance also applies: domestic employee or user data leaving China must pass a security assessment or use a standard contract.
- China data export obligations (pkulaw verified 2026-07): transfers/return of data to China must use one of three routes — security assessment (CAC Order No. 11), standard contract (Order No. 13), or certification (CAC·SAMR Order No. 20, effective 2025-10-14); the 2024–2025 regulatory stance has relaxed — the Provisions on Promoting and Regulating Cross-Border Data Flows (Order No. 16) and the Regulations on Network Data Security Administration (State Council Order No. 790) exempt some situations.
Procedure
- Data inventory and lawful-basis confirmation.
- Draft privacy policies and data subject rights response mechanisms.
- Pre-transfer assessment (Egyptian PDPL + China PIPL).
- Appoint a data processing officer and conduct training.
- Establish data breach emergency procedures.
Hard requirements
- Lawful basis; cross-border transfer compliance; PIPL linkage.
Costs
Compliance system building; legal consulting.⏱ ⏱ Timeline:Continuous compliance.⚠ Common risks
- Non-compliant processing faces regulatory penalties.
- Cross-border transfer violations (dual violation on Egyptian and Chinese sides).
- Data breach reputational damage and legal liability.
Handbook
📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)
Applies to:Chinese companies processing Egyptian residents' personal data in Egypt, or transferring it back to China (governed by Law No. 151/2020 and the 2025 implementing regulations, full enforcement from 2026-10-31).
Prerequisites
- Processing activities clarified and a PDPC general license (valid 3 years) obtained.
- Cross-border transfers, sensitive processing, etc. require separate special licenses.
- Budget reserved for DPO registration and Arabic notices.
| Step | Action | Owner | Timeline | Cost | Official form / system | Notes & penalties |
|---|---|---|---|---|---|---|
| 1 | Data inventory and lawful-basis confirmation. Map personal data categories and processing purposes, confirm the lawful basis (mainly explicit consent), and establish a ROPA. | Legal/Compliance | 2–3 weeks | Internal cost | ROPA, data inventory | Consent must be specific and recorded in writing. Penalty:Fine EGP 200,000–5,000,000. |
| 2 | Apply for PDPC processing licenses (general + special). Apply to the Personal Data Protection Center (PDPC) for a general processing license (3-year validity); cross-border transfers and sensitive data require separate special licenses. | Legal | Per portal opening (mid-2026) | License/application costs | PDPC license application | Grace period until full enforcement on 2026-10-31. Penalty:Processing without a license can be penalized and business restricted. |
| 3 | Publish Arabic privacy notices and consent. Publish concise, visible privacy notices in Arabic and obtain explicit, itemized, verifiable consent (no bundling or pre-checking). | Legal | 1–2 weeks | Internal/translation costs | Arabic privacy notice, consent records | Sensitive information or children (<15) require written consent or parental consent. Penalty:Same ceiling as step 1. |
| 4 | Cross-border transfer license and mechanism. Apply to the PDPC for a cross-border transfer license and prove the destination's protection level; returning data to China requires simultaneous PIPL export mechanisms. | Legal | 3–6 weeks | License/lawyer costs | Cross-border license, PIPL export documents | Cloud storage also requires a license. Penalty:Unlicensed cross-border transfer is penalized and business suspended. |
| 5 | Appoint and register a DPO. Where applicable, appoint a qualified data protection officer and register with the PDPC (obtain an accountability code). | Management | Ongoing | DPO staffing/exam costs | DPO appointment, PDPC registration | Categories A/B/C, reassessed every three years. Penalty:Failure to appoint or register is penalized. |
| 6 | Data subject rights response (6 working days). Establish access, rectification, erasure response mechanisms; the PDPL requires responses within about 6 working days (fees up to EGP 20,000). | DPO/customer service | No more than 6 working days | Internal cost | DSAR process | Must establish a PDPC-recognized mechanism. Penalty:Refusing to respond is penalized. |
| 7 | Notify breaches within 72 hours. Notify the PDPC within 72 hours of a breach and affected individuals within 3 working days thereafter. | DPO/IT | 72 hours + 3 working days | Internal cost | PDPC breach report | Set up automatic triggers. Penalty:Late or concealed reporting aggravates penalties. |
✅ Self-check list
⚠ Common pitfalls
Assuming the PDPL is still 'dormant' and non-compliant影响:Directly penalized after 2026-10-31规避:Complete licenses and systems within the grace period
Transferring cross-border without a PDPC license影响:Penalized and relevant business suspended规避:Apply for the cross-border data transfer license first
English-only privacy notices影响:Notice invalid规避:Provide notices in Arabic
Ignoring PIPL export for data return to China影响:Dual violation规避:Handle China-side mechanisms in parallel
DPO not registered with the PDPC影响:Penalized for missing accountability mechanisms规避:Register immediately after appointment to obtain the code
Breach reported after 72 hours影响:Aggravated penalties规避:Set up automatic reporting triggers
📅 Ongoing post-incorporation obligations
- Renew PDPC licenses (general term 3 years)
- Maintain DPO registration and 3-year reassessment
- 72-hour breach notification and individual notice
- Continuously respond to DSAR requests
- China PIPL data export mechanisms remain effective
🔗 Official portals
📎 Source:Egyptian Personal Data Protection Law No. 151/2020; Egyptian Data Protection Center; https://www.cac.gov.cn
Want to turn this into an actionable compliance workflow?
CompliGo · Outbound Compliance Automation
You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.
CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.