{
 "jurisdiction_id": "EG",
 "jurisdiction": "Egypt",
 "url": "https://dataprotection.gi/jurisdictions/egypt/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 28,
  "sub_modules": 57,
  "source_register": 7
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/egypt/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Primary statute in force since 2020 but implementing regulations and regulator operability only crystallized in Nov 2025-2026, with substantive compliance (licensing, DPO, cross-border) not mandatory until 31 Oct 2026.",
   "claims": [
    {
     "statement": "The Personal Data Protection Center (PDPC) is the supervisory authority designated to enforce Egypt's Personal Data Protection Law and issue implementing guidance.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/egypt",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Law No. 151 of 2020 on the Protection of Personal Data, published in the Official Gazette in July 2020, functions as Egypt's central omnibus data-protection statute and entered into force 15 October 2020.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/egypt-data-protection-law-published-official-gazette-enters-force-3-months",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Executive Regulations No. 816 of 2025, issued by the Ministry of Communications and Information Technology on 1 November 2025 (publicly posted by the PDPC in late December 2025), detail the procedures for implementation, supervision, and enforcement of the PDPL.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/egypt-pdpc-issues-executive-regulations-personal-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPL applies to personal data processed electronically, in part or in full, and expressly excludes processing for personal use, official statistics, media purposes, judicial-seizure records, and data held by the Central Bank of Egypt and CBE-supervised entities (other than money-transfer/forex companies).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/egypt-new-data-protection-law-and-what-expect",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPL extends to a non-Egyptian resident domiciled outside Egypt where the same act is criminalized in the country where it occurred and the affected personal data belongs to an Egyptian citizen or resident.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/egypt-new-data-protection-law-and-what-expect",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under the Executive Regulations, processing sensitive personal data, cross-border transfers, video surveillance, and electronic direct marketing each require a PDPC-issued license or permit.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/egypt-pdpc-issues-executive-regulations-personal-data",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/egypt/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Consent and special-category provisions are documented; pseudonymisation/anonymisation definitions were not located in available secondary sources.",
   "claims": [
    {
     "statement": "Egypt's Data Protection Law establishes consent as the key basis for lawful processing of personal data, alongside detailed rights, regulations, and penalties.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/egypt",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Data subjects under the PDPL have the right to revoke any consent previously granted for saving or processing their personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/egypt-new-data-protection-law-and-what-expect",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Sensitive data under the PDPL covers data disclosing genetic, physical, mental, or psychological health status, biometrics, financial data, religious beliefs, political opinion, security status, and minors' data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/egypt-new-data-protection-law-and-what-expect",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/egypt/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Correction/objection rights documented; access, portability, and response-window specifics remain unconfirmed from available sources.",
   "claims": [
    {
     "statement": "The PDPL has similarities to the GDPR with provisions relating to data subject rights, data controller and processor obligations, and strict data-transfer obligations.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/egypt",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Data subjects under the PDPL may correct, amend, delete, add, or update their personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/egypt-new-data-protection-law-and-what-expect",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Data subjects under the PDPL may limit the purpose of processing to a specific scope and object to processing or its result where a violation exists.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/egypt-new-data-protection-law-and-what-expect",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/egypt/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Core duties (DPO, DPIA concept, security, breach notice) exist in statute but material implementing detail is acknowledged as incomplete/uncertain by professional commentary.",
   "claims": [
    {
     "statement": "Under the Executive Regulations, all controllers and processors must appoint an accredited Data Protection Officer, although the PDPL itself does not specify DPO qualifications.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/egypt-pdpc-issues-executive-regulations-personal-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The content and manner of carrying out Data Protection Impact Assessments under the PDPL is not detailed in the primary law and is expected to be clarified further by executive regulation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_pdpl_v2.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPL is less clear than the GDPR in its definitions of the security measures required of controllers and processors.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_pdpl_v2.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Unlike the GDPR, the PDPL does not clarify exceptions from breach-notification requirements or processor-notification requirements.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_pdpl_v2.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/egypt/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "A binding license-based transfer-restriction regime is confirmed, but GDPR-style adequacy/SCC/BCR/TIA architecture is absent or unconfirmed.",
   "claims": [
    {
     "statement": "The PDPL prohibits transfer, storage, or sharing of personal data collected or prepared for processing to a foreign state unless the destination applies a protection level not less than the PDPL and a license or authorisation is obtained.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/egypt-new-data-protection-law-and-what-expect",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under the Executive Regulations, cross-border transfers require a PDPC license, appropriate security measures, detailed transfer records, and data-subject consent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/egypt-pdpc-issues-executive-regulations-personal-data",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/egypt/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Financial and telecom overlays are documented; other sectoral overlays are unconfirmed gaps.",
   "claims": [
    {
     "statement": "Personal data held by the Central Bank of Egypt and entities subject to its control and supervision is excluded from the PDPL, except for money-transfer and forex companies which must observe CBE-established personal-data rules.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/egypt-new-data-protection-law-and-what-expect",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The National Telecom Regulatory Authority (NTRA) has pursued enforcement action, including referrals to public prosecution, against companies sending unsolicited SMS messages in violation of the Telecom Regulation Law No. 10 of 2003 and the Anti-Cyber and Information Technology Crimes Law No. 175 of 2018.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/egypt-ntra-submits-note-public-prosecution-spam",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/egypt/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Direct-marketing licensing is confirmed; the remaining adtech sub-domains are unconfirmed gaps typical of a still-maturing regime.",
   "claims": [
    {
     "statement": "Electronic direct marketing activities require a license or permit from the PDPC under the Executive Regulations to the PDPL.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/egypt-pdpc-issues-executive-regulations-personal-data",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/egypt/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Biometric/genetic licensing is confirmed; ADM transparency, profiling restrictions, AI risk assessment and surveillance carve-outs remain unconfirmed or purely aspirational.",
   "claims": [
    {
     "statement": "Biometric data is enumerated as PDPL sensitive data, and its processing requires a PDPC license under the Executive Regulations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/egypt-new-data-protection-law-and-what-expect",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Genetic data is enumerated as PDPL sensitive data, and its processing requires a PDPC license under the Executive Regulations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/egypt-new-data-protection-law-and-what-expect",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Egypt's MCIT has articulated a strategy aimed at protecting personal data and developing AI and data-protection laws, though no enacted AI-specific risk-assessment obligation was confirmed.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Speculative",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/egypt",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/egypt/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Minors' data is nominally sensitive/protected, but the mechanics (age threshold, parental consent, profiling ban) are confirmed absent by comparative analysis.",
   "claims": [
    {
     "statement": "Minors' data is listed as PDPL sensitive data, but unlike the GDPR, the PDPL does not refer to an age threshold for processing a child's data without parental-responsibility-holder consent and does not explicitly address children's data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_pdpl_v2.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/egypt/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Enforcement architecture (courts + PDPC) and a major 180-day-window development are confirmed; enforcement track record, funding, and collective-redress mechanisms remain unconfirmed given the regime's pre-operative status.",
   "claims": [
    {
     "statement": "Economic and Ordinary courts in Egypt may be involved in adjudicating disputes or cases related to data breaches and violations of the PDPL.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/egypt-data-breach",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Executive Regulations of the Egyptian PDPL were officially issued on 1 November 2025, giving controllers and processors a one-year grace period to comply, ending 31 October 2026, with initial regulatory scrutiny expected to target large-scale personal-data holders.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/egypt-pdpc-issues-executive-regulations-personal-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPC has published guidelines and templates to aid organisations' compliance with the Personal Data Protection Law.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/egypt",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}