🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
EG · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 7 sources retrieved model claude-sonnet-5 ·

Egypt

EG schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 28 claims · 7 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
28Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Primary statute in force since 2020 but implementing regulations and regulator operability only crystallized in Nov 2025-2026, with substantive compliance (licensing, DPO, cross-border) not mandatory until 31 Oct 2026.

Primary frameworkLaw No. 151 of 2020 on the Protection of Personal Data (PDPL) and Executive Regulations No. 816 of 2025
Supervisory authorityPersonal Data Protection Center (PDPC)
Traffic-light rationale — AmberPrimary statute in force since 2020 but implementing regulations and regulator operability only crystallized in Nov 2025-2026, with substantive compliance (licensing, DPO, cross-border) not mandatory until 31 Oct 2026.

Sub-modules (5)

Regulator And AuthorityAmber

PDPC is the statutory regulator; historically un-established, now issuing guidelines and templates and having posted the Executive Regulations.

Claims: CLM-EG-1a2b3c4d

Act And InstrumentsGreen

PDPL (Law 151/2020) is the central instrument, supplemented by Executive Regulations No. 816/2025.

Claims: CLM-EG-2b3c4d5e, CLM-EG-3c4d5e6f

Material ScopeGreen

Applies to electronic (in whole or part) processing of personal data, with statutory carve-outs.

Claims: CLM-EG-4d5e6f7a

Territorial ScopeAmber

Extraterritorial reach to non-resident foreigners where the underlying act is criminalized abroad and victim data belongs to an Egyptian citizen/resident.

Claims: CLM-EG-5e6f7a8b

Regulator Registration And FilingAmber

Licensing/permit regime administered by PDPC for sensitive-data processing, cross-border transfer, video surveillance, and e-marketing.

Claims: CLM-EG-6f7a8b9c

Category narrative89 words

Egypt's omnibus regime rests on Law No. 151 of 2020 on the Protection of Personal Data (PDPL), which entered into force on 15 October 2020, with the Personal Data Protection Center (PDPC) as designated regulator. The PDPC was not operationally established for years; the long-awaited Executive Regulations (No. 816 of 2025) were issued 1 November 2025 and publicly posted by the PDPC in late December 2025, opening a one-year compliance grace period ending 31 October 2026. The regime is therefore enacted but only partially operative -- hence in_transition status.

Sources and claims (6)
  1. ConfirmedOneTrust DataGuidanceThe Personal Data Protection Center (PDPC) is the supervisory authority designated to enforce Egypt's Personal Data Protection Law and issue implementing guidance.
  2. ConfirmedOneTrust DataGuidanceLaw No. 151 of 2020 on the Protection of Personal Data, published in the Official Gazette in July 2020, functions as Egypt's central omnibus data-protection statute and entered into force 15 October 2020.
  3. ConfirmedOneTrust DataGuidanceExecutive Regulations No. 816 of 2025, issued by the Ministry of Communications and Information Technology on 1 November 2025 (publicly posted by the PDPC in late December 2025), detail the procedures for implementation, supervision, and enforcement of the PDPL.
  4. ConfirmedOneTrust DataGuidanceThe PDPL applies to personal data processed electronically, in part or in full, and expressly excludes processing for personal use, official statistics, media purposes, judicial-seizure records, and data held by the Central Bank of Egypt and CBE-supervised entities (other than money-transfer/forex companies).
  5. ProbableOneTrust DataGuidanceThe PDPL extends to a non-Egyptian resident domiciled outside Egypt where the same act is criminalized in the country where it occurred and the affected personal data belongs to an Egyptian citizen or resident.
  6. ConfirmedOneTrust DataGuidanceUnder the Executive Regulations, processing sensitive personal data, cross-border transfers, video surveillance, and electronic direct marketing each require a PDPC-issued license or permit.

#

Consent and special-category provisions are documented; pseudonymisation/anonymisation definitions were not located in available secondary sources.

Primary frameworkLaw No. 151 of 2020 (PDPL), Executive Regulations No. 816/2025
Supervisory authorityPersonal Data Protection Center (PDPC)
Traffic-light rationale — AmberConsent and special-category provisions are documented; pseudonymisation/anonymisation definitions were not located in available secondary sources.

Sub-modules (4)

Lawful BasesAmber

Consent is established as the key lawful basis for processing under the PDPL.

Claims: CLM-EG-9c0d1e2f

Special CategoriesAmber

Sensitive data spans genetic, physical/mental/psychological health, biometric, financial, religious, political, security-status, and minors' data.

Claims: CLM-EG-7a8b9c0d

Pseudonymisation And AnonymisationRed

No PDPL-specific pseudonymisation/anonymisation safe-harbour definitions were identified in the sources searched.

Absence provenance: not recorded. Searched: Egypt PDPL pseudonymisation anonymisation definitions, Egypt Personal Data Protection Law special categories.

Category narrative35 words

PDPL centers processing legitimacy on data-subject consent (revocable at any time) and designates an extensive list of sensitive/special categories requiring licensing. The law does not provide a developed pseudonymisation/anonymisation safe-harbour framework in the sources reviewed.

Sources and claims (3)
  1. ProbableOneTrust DataGuidanceEgypt's Data Protection Law establishes consent as the key basis for lawful processing of personal data, alongside detailed rights, regulations, and penalties.
  2. ConfirmedOneTrust DataGuidanceData subjects under the PDPL have the right to revoke any consent previously granted for saving or processing their personal data.
  3. ConfirmedOneTrust DataGuidanceSensitive data under the PDPL covers data disclosing genetic, physical, mental, or psychological health status, biometrics, financial data, religious beliefs, political opinion, security status, and minors' data.

#

Correction/objection rights documented; access, portability, and response-window specifics remain unconfirmed from available sources.

Primary frameworkLaw No. 151 of 2020 (PDPL)
Supervisory authorityPersonal Data Protection Center (PDPC)
Traffic-light rationale — AmberCorrection/objection rights documented; access, portability, and response-window specifics remain unconfirmed from available sources.

Sub-modules (5)

Access RightAmber

PDPL is broadly described as GDPR-similar in providing data-subject rights, but a distinct access-right provision was not separately confirmed.

Claims: CLM-EG-2f3a4b5c

Rectification And ErasureGreen

Data subjects may correct, amend, delete, add, or update their personal data.

Claims: CLM-EG-0d1e2f3a

Restriction And ObjectionGreen

Data subjects may limit the purpose/scope of processing and object to processing or its results where a violation exists.

Claims: CLM-EG-1e2f3a4b

Data PortabilityRed

No explicit data-portability provision was identified in the sources searched.

Absence provenance: not recorded. Searched: Egypt PDPL data portability right.

Deadlines And Response WindowsRed

No statutory response-deadline figures for PDPL data-subject requests were identified in the sources searched.

Absence provenance: not recorded. Searched: Egypt PDPL data subject request response deadline days.

Category narrative41 words

The PDPL grants GDPR-analogous data-subject rights: rectification/erasure/update, purpose-limitation/restriction, and objection to processing where a violation exists. Distinct access-right scope, portability, and statutory response-deadline provisions were not clearly located in the secondary sources reviewed and are flagged as gaps pending primary-text/Executive-Regulations review.

Sources and claims (3)
  1. ProbableOneTrust DataGuidanceThe PDPL has similarities to the GDPR with provisions relating to data subject rights, data controller and processor obligations, and strict data-transfer obligations.
  2. ConfirmedOneTrust DataGuidanceData subjects under the PDPL may correct, amend, delete, add, or update their personal data.
  3. ConfirmedOneTrust DataGuidanceData subjects under the PDPL may limit the purpose of processing to a specific scope and object to processing or its result where a violation exists.

#

Core duties (DPO, DPIA concept, security, breach notice) exist in statute but material implementing detail is acknowledged as incomplete/uncertain by professional commentary.

Primary frameworkLaw No. 151 of 2020 (PDPL), Executive Regulations No. 816/2025
Supervisory authorityPersonal Data Protection Center (PDPC)
Traffic-light rationale — AmberCore duties (DPO, DPIA concept, security, breach notice) exist in statute but material implementing detail is acknowledged as incomplete/uncertain by professional commentary.

Sub-modules (7)

Accountability And DpiaAmber

DPIA obligation exists in concept; content/manner left to further executive detail, per comparative GDPR/PDPL analysis.

Claims: CLM-EG-4b5c6d7e

Dpo RequirementsAmber

All controllers and processors must appoint an accredited DPO; PDPL does not specify DPO qualifications.

Claims: CLM-EG-3a4b5c6d

Ropa RequirementsRed

No PDPL-specific records-of-processing (ROPA) obligation was identified in the sources searched.

Absence provenance: not recorded. Searched: Egypt PDPL records of processing activities ROPA requirement.

Joint Controller ArrangementsRed

No joint-controller-specific provision was identified in the sources searched.

Absence provenance: not recorded. Searched: Egypt PDPL joint controller arrangement.

Security MeasuresAmber

PDPL requires 'appropriate security measures' for sensitive processing and cross-border transfer but is less clear than GDPR in defining security-measure standards.

Claims: CLM-EG-5c6d7e8f

Breach NotificationAmber

A breach-notification duty exists but comparative analysis finds the PDPL does not clarify exceptions from breach-notification or processor-notification requirements.

Claims: CLM-EG-6d7e8f9a

Retention And DisposalRed

No explicit PDPL retention-limit or disposal-duty provision was identified in the sources searched.

Absence provenance: not recorded. Searched: Egypt PDPL data retention limit disposal duty.

Category narrative64 words

Controllers/processors must appoint an accredited DPO under the Executive Regulations, though the PDPL itself sets no DPO qualification standard. DPIA obligations exist conceptually but their content/manner is left to further executive detail. Comparative legal analysis flags that the PDPL is less clear than GDPR on security-measure definitions and does not clarify breach-notification exceptions for controllers or processors. ROPA and joint-controller specifics were not located.

Sources and claims (4)
  1. ConfirmedOneTrust DataGuidanceUnder the Executive Regulations, all controllers and processors must appoint an accredited Data Protection Officer, although the PDPL itself does not specify DPO qualifications.
  2. UncertainOneTrust DataGuidanceThe content and manner of carrying out Data Protection Impact Assessments under the PDPL is not detailed in the primary law and is expected to be clarified further by executive regulation.
  3. UncertainOneTrust DataGuidanceThe PDPL is less clear than the GDPR in its definitions of the security measures required of controllers and processors.
  4. UncertainOneTrust DataGuidanceUnlike the GDPR, the PDPL does not clarify exceptions from breach-notification requirements or processor-notification requirements.

#

A binding license-based transfer-restriction regime is confirmed, but GDPR-style adequacy/SCC/BCR/TIA architecture is absent or unconfirmed.

Primary frameworkLaw No. 151 of 2020 (PDPL), Executive Regulations No. 816/2025
Supervisory authorityPersonal Data Protection Center (PDPC)
Traffic-light rationale — AmberA binding license-based transfer-restriction regime is confirmed, but GDPR-style adequacy/SCC/BCR/TIA architecture is absent or unconfirmed.

Sub-modules (6)

Transfer MechanismsAmber

Cross-border transfer is prohibited absent an equivalent protection level and a PDPC license/authorization; Executive Regulations add consent and record-keeping requirements.

Claims: CLM-EG-7e8f9a0b, CLM-EG-8f9a0b1c

Adequacy ReceivedRed

No adequacy decision received by Egypt from another regime was identified in the sources searched.

Absence provenance: not recorded. Searched: Egypt PDPL adequacy decision received EU UK.

Adequacy GrantedRed

No adequacy decision granted by Egypt to another jurisdiction was identified in the sources searched.

Absence provenance: not recorded. Searched: Egypt PDPC adequacy decision granted foreign country.

Sccs And BcrsRed

No standard-contractual-clause or binding-corporate-rules instrument was identified; the PDPL instead relies on a licensing model for transfers.

Absence provenance: not recorded. Searched: Egypt PDPL standard contractual clauses binding corporate rules.

Transfer Impact AssessmentRed

No formal transfer-impact-assessment methodology distinct from the general 'appropriate security measures' requirement was identified.

Absence provenance: not recorded. Searched: Egypt PDPL transfer impact assessment.

Data LocalisationAmber

No absolute data-localisation mandate was identified beyond the CBE sectoral carve-out; NTRA has issued a data-centre establishment framework relevant to infrastructure siting.

Category narrative74 words

The PDPL prohibits transfer, storage, or sharing of personal data with a foreign state unless the destination affords protection not less than the PDPL and a PDPC license/authorization is obtained. The Executive Regulations operationalize this via a licensing requirement paired with security measures, data-subject consent, and detailed transfer records. No adequacy-decision mechanism (received or granted), SCC/BCR instrument, formal transfer-impact-assessment methodology, or absolute data-localisation mandate beyond the CBE carve-out was identified in the sources reviewed.

Sources and claims (2)
  1. ConfirmedOneTrust DataGuidanceThe PDPL prohibits transfer, storage, or sharing of personal data collected or prepared for processing to a foreign state unless the destination applies a protection level not less than the PDPL and a license or authorisation is obtained.
  2. ConfirmedOneTrust DataGuidanceUnder the Executive Regulations, cross-border transfers require a PDPC license, appropriate security measures, detailed transfer records, and data-subject consent.

#

Financial and telecom overlays are documented; other sectoral overlays are unconfirmed gaps.

Primary frameworkLaw No. 151 of 2020 (PDPL); Telecom Regulation Law No. 10/2003; Anti-Cyber and IT Crimes Law No. 175/2018
Supervisory authorityPersonal Data Protection Center (PDPC)
Traffic-light rationale — AmberFinancial and telecom overlays are documented; other sectoral overlays are unconfirmed gaps.

Sub-modules (7)

Financial Sector OverlayAmber

CBE and CBE-supervised entities are exempt from PDPL, except money-transfer/forex firms subject to CBE data rules.

Claims: CLM-EG-9a0b1c2d

Health Sector OverlayRed

No health-sector-specific DP overlay was identified in the sources searched.

Absence provenance: not recorded. Searched: Egypt health data protection sector law.

Telecoms And EprivacyAmber

NTRA enforces telecom-sector rules, including action against unsolicited SMS/spam under Telecom Law 10/2003 and Law 175/2018.

Claims: CLM-EG-0b1c2d3e

Employment DataRed

No employment-data-specific overlay was identified in the sources searched.

Absence provenance: not recorded. Searched: Egypt employment data protection code labour law.

Credit And ScoringRed

No credit-scoring-specific overlay was identified in the sources searched.

Absence provenance: not recorded. Searched: Egypt credit scoring data protection rules.

EducationRed

No education-sector-specific overlay was identified in the sources searched.

Absence provenance: not recorded. Searched: Egypt education sector student data protection rules.

InsuranceRed

No insurance-sector-specific overlay was identified in the sources searched.

Absence provenance: not recorded. Searched: Egypt insurance sector data protection rules.

Category narrative69 words

The Central Bank of Egypt (CBE) and CBE-supervised entities are exempted from the general PDPL regime (except money-transfer and forex companies, which must follow CBE-established data rules), creating a financial-sector overlay. Telecoms sit under NTRA authority (Telecom Regulation Law No. 10/2003) with active enforcement against spam/unsolicited messaging alongside the Anti-Cyber and Information Technology Crimes Law No. 175/2018. No health, employment, credit-scoring, education, or insurance sector-specific DP overlays were identified.

Sources and claims (2)
  1. ConfirmedOneTrust DataGuidancePersonal data held by the Central Bank of Egypt and entities subject to its control and supervision is excluded from the PDPL, except for money-transfer and forex companies which must observe CBE-established personal-data rules.
  2. ConfirmedOneTrust DataGuidanceThe National Telecom Regulatory Authority (NTRA) has pursued enforcement action, including referrals to public prosecution, against companies sending unsolicited SMS messages in violation of the Telecom Regulation Law No. 10 of 2003 and the Anti-Cyber and Information Technology Crimes Law No. 175 of 2018.

#

Direct-marketing licensing is confirmed; the remaining adtech sub-domains are unconfirmed gaps typical of a still-maturing regime.

Primary frameworkExecutive Regulations No. 816/2025 to the PDPL
Supervisory authorityPersonal Data Protection Center (PDPC)
Traffic-light rationale — AmberDirect-marketing licensing is confirmed; the remaining adtech sub-domains are unconfirmed gaps typical of a still-maturing regime.

Sub-modules (6)

Cookies And TrackersRed

No PDPL-specific cookie/tracker consent regime was identified in the sources searched.

Absence provenance: not recorded. Searched: Egypt PDPL cookie consent tracker rules.

Dark PatternsRed

No dark-pattern prohibition was identified in the sources searched.

Absence provenance: not recorded. Searched: Egypt PDPL dark patterns prohibition.

Opt Out SignalsRed

No recognition of opt-out signals (e.g., Global Privacy Control) was identified in the sources searched.

Absence provenance: not recorded. Searched: Egypt PDPL Global Privacy Control opt-out signal.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rule was identified in the sources searched.

Absence provenance: not recorded. Searched: Egypt PDPL data clean room data collaboration.

Cross Context AdvertisingRed

No cross-context-advertising ('sale'/'share') framework analogous to CPRA was identified in the sources searched.

Absence provenance: not recorded. Searched: Egypt PDPL cross-context advertising sale share personal data.

Direct MarketingAmber

Electronic direct marketing requires a PDPC license/permit under the Executive Regulations.

Claims: CLM-EG-1c2d3e4f

Category narrative31 words

Electronic direct marketing is licensable activity under the Executive Regulations. No Egypt-specific cookie/tracker consent regime, dark-pattern prohibition, opt-out-signal (GPC/DAA) recognition, clean-room/DCR rule, or cross-context-advertising framework was identified in the sources reviewed.

Sources and claims (1)
  1. ConfirmedOneTrust DataGuidanceElectronic direct marketing activities require a license or permit from the PDPC under the Executive Regulations to the PDPL.

#

Biometric/genetic licensing is confirmed; ADM transparency, profiling restrictions, AI risk assessment and surveillance carve-outs remain unconfirmed or purely aspirational.

Primary frameworkLaw No. 151 of 2020 (PDPL), Executive Regulations No. 816/2025
Supervisory authorityPersonal Data Protection Center (PDPC)
Traffic-light rationale — AmberBiometric/genetic licensing is confirmed; ADM transparency, profiling restrictions, AI risk assessment and surveillance carve-outs remain unconfirmed or purely aspirational.

Sub-modules (6)

Profiling RestrictionsRed

No Article-22-style profiling restriction was identified in the sources searched.

Absence provenance: not recorded. Searched: Egypt PDPL profiling restriction automated decision.

Automated Decision Making TransparencyRed

No ADM-transparency/explanation right was identified in the sources searched.

Absence provenance: not recorded. Searched: Egypt PDPL automated decision making transparency right.

Ai Risk AssessmentsRed

MCIT strategy references development of AI and data-protection laws, but no enacted AI-risk-assessment obligation was confirmed.

Claims: CLM-EG-4f5a6b7c

Biometric RegimeAmber

Biometric data is a PDPL sensitive category requiring a PDPC license to process.

Claims: CLM-EG-2d3e4f5a

Genetic DataAmber

Genetic data is a PDPL sensitive category requiring a PDPC license to process.

Claims: CLM-EG-3e4f5a6b

State Surveillance CarveoutsRed

No state-surveillance/national-security carve-out provision was identified in the sources searched.

Absence provenance: not recorded. Searched: Egypt PDPL national security exemption surveillance carve-out.

Category narrative55 words

Biometric and genetic data are enumerated PDPL sensitive categories requiring a PDPC license to process. Egypt's Ministry of Communications and Information Technology has an aspirational strategy to develop AI-specific and further data-protection laws, but no enacted AI-risk-assessment regime, Article-22-style profiling restriction, ADM transparency right, or state-surveillance carve-out provision was independently confirmed in the sources reviewed.

Sources and claims (3)
  1. ConfirmedOneTrust DataGuidanceBiometric data is enumerated as PDPL sensitive data, and its processing requires a PDPC license under the Executive Regulations.
  2. ConfirmedOneTrust DataGuidanceGenetic data is enumerated as PDPL sensitive data, and its processing requires a PDPC license under the Executive Regulations.
  3. SpeculativeOneTrust DataGuidanceEgypt's MCIT has articulated a strategy aimed at protecting personal data and developing AI and data-protection laws, though no enacted AI-specific risk-assessment obligation was confirmed.

#

Minors' data is nominally sensitive/protected, but the mechanics (age threshold, parental consent, profiling ban) are confirmed absent by comparative analysis.

Primary frameworkLaw No. 151 of 2020 (PDPL)
Supervisory authorityPersonal Data Protection Center (PDPC)
Traffic-light rationale — AmberMinors' data is nominally sensitive/protected, but the mechanics (age threshold, parental consent, profiling ban) are confirmed absent by comparative analysis.

Sub-modules (5)

Age VerificationRed

The PDPL does not set an explicit age threshold for processing a minor's data without holder-of-parental-responsibility consent, unlike GDPR Art 8.

Claims: CLM-EG-5a6b7c8d

Minor Profiling BansRed

No minor-specific profiling ban was identified in the sources searched.

Absence provenance: not recorded. Searched: Egypt PDPL minor profiling ban children.

Education SettingsRed

No education-setting-specific children's-data provision was identified in the sources searched.

Absence provenance: not recorded. Searched: Egypt PDPL education setting student data minors.

Dependent AdultsRed

No dependent-adult-specific protection provision was identified in the sources searched.

Absence provenance: not recorded. Searched: Egypt PDPL dependent adults elderly incapacitated protection.

Category narrative50 words

Minors' data is listed among PDPL sensitive/special categories, warranting heightened (licensed) treatment, but comparative legal analysis confirms the PDPL does not set an explicit age-of-consent threshold or a parental-consent mechanism analogous to GDPR Article 8, and does not otherwise explicitly address children's data. No education-setting or dependent-adult-specific provisions were identified.

Sources and claims (1)
  1. ConfirmedOneTrust DataGuidanceMinors' data is listed as PDPL sensitive data, but unlike the GDPR, the PDPL does not refer to an age threshold for processing a child's data without parental-responsibility-holder consent and does not explicitly address children's data.

#

Enforcement architecture (courts + PDPC) and a major 180-day-window development are confirmed; enforcement track record, funding, and collective-redress mechanisms remain unconfirmed given the regime's pre-operative status.

Primary frameworkLaw No. 151 of 2020 (PDPL), Executive Regulations No. 816/2025
Supervisory authorityPersonal Data Protection Center (PDPC)
Traffic-light rationale — AmberEnforcement architecture (courts + PDPC) and a major 180-day-window development are confirmed; enforcement track record, funding, and collective-redress mechanisms remain unconfirmed given the regime's pre-operative status.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

Economic and Ordinary courts may adjudicate disputes and violations of the PDPL alongside PDPC administrative enforcement.

Claims: CLM-EG-6b7c8d9e

Enforcement Activity IndexRed

No specific PDPC fines or enforcement-decision index was identified in the sources searched, consistent with the regime's pre-operative/grace-period status.

Absence provenance: not recorded. Searched: Egypt PDPC enforcement fines decisions 2025 2026.

Regulator Funding And CapacityRed

No PDPC funding or headcount data was identified in the sources searched.

Absence provenance: not recorded. Searched: Egypt PDPC budget staffing headcount capacity.

Collective Redress And Class ActionsRed

No collective-redress or class-action mechanism specific to PDPL claims was identified in the sources searched.

Absence provenance: not recorded. Searched: Egypt PDPL collective redress class action data subjects.

Private Right Of ActionAmber

Data subjects may access Economic and Ordinary courts for PDPL-related disputes, providing a general civil-litigation route, though no PDPL-specific private-right-of-action clause distinct from general court jurisdiction was confirmed.

Claims: CLM-EG-6b7c8d9e

Recent Developments 180DAmber

The Executive Regulations No. 816/2025 were issued 1 November 2025 and their contents were still being clarified by practitioners as of February 2026, with a compliance grace period running to 31 October 2026; the PDPC has separately published implementation guidelines and templates.

Claims: CLM-EG-7c8d9e0f, CLM-EG-8d9e0f1a

Category narrative73 words

Both PDPC administrative processes and the Economic and Ordinary courts may adjudicate PDPL disputes and violations. The most significant recent development is the November 2025 issuance of Executive Regulations No. 816/2025 (publicly confirmed by February 2026), commencing a one-year grace period to 31 October 2026, with initial regulatory scrutiny expected to target large-scale data holders. No fines/enforcement-decision index, regulator funding/headcount data, collective-redress mechanism, or explicit private-right-of-action provision beyond general court jurisdiction was confirmed.

Sources and claims (3)
  1. ConfirmedOneTrust DataGuidanceEconomic and Ordinary courts in Egypt may be involved in adjudicating disputes or cases related to data breaches and violations of the PDPL.
  2. ConfirmedOneTrust DataGuidanceThe Executive Regulations of the Egyptian PDPL were officially issued on 1 November 2025, giving controllers and processors a one-year grace period to comply, ending 31 October 2026, with initial regulatory scrutiny expected to target large-scale personal-data holders.
  3. ProbableOneTrust DataGuidanceThe PDPC has published guidelines and templates to aid organisations' compliance with the Personal Data Protection Law.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Egypt
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 28 claim(s), 7 source(s) in the cumulative register.