Be ready for Egypt’s PDPL before November 2026.
Law 151 of 2020 places seven duties on the organisations it reaches. Thiqa maps each one onto the controls you already run, collects the evidence from your systems, and can appoint the data protection officer to go with them.
Early access · work email only
Compliance
PDPL · Law 151 of 2020 · Egypt
Personal Data Protection Law
Seven duties · derived from the evidence that exists
PDPL as a control set, not a project
One control set, with PDPL duties derived from the evidence you already collect rather than asserted separately.
PDPL explained
Four things worth knowing before the compliance period closes.
01
What the law is
Egypt’s Personal Data Protection Law — Law 151 of 2020 — governs how personal data is collected, processed, stored and moved. It sat without executive regulations for five years; those arrived in November 2025 and started a one-year compliance period, which is why November 2026 is the date on this page. Enforcement belongs to the Personal Data Protection Center, which licenses the organisations that process data, registers their data protection officers and investigates complaints against them.
02
Who it reaches
It follows the data rather than the office. The law covers personal data about Egyptian citizens wherever they live, and about anyone resident in Egypt — so an organisation with no Egyptian premises can still be inside it, and an Egyptian payroll is enough on its own. There is one carve-out worth checking before anything else: data held by the Central Bank of Egypt and by the entities it supervises sits outside the law, with money transfer companies and exchange offices named as exceptions that stay inside it.
03
What it asks of you
Seven duties, and they are a fixed list rather than a stream of circulars: a lawful basis for every processing activity you run, answers when someone asks what you hold about them, notification when there is a breach, permission from the regulator before data leaves Egypt, consent and records for direct marketing, a data protection officer appointed to the entity and entered in the regulator’s register, and the licence or permit to process at all. Each of them resolves, in the end, to evidence somebody has to be able to produce.
04
What Thiqa does about it
Each duty is mapped onto the control set you already operate, so PDPL becomes a view of your existing controls rather than a second programme beside them. Controls that PCI DSS or ISO 27001 already cover are counted once instead of twice, evidence is collected from your systems on each control’s own cadence, and a named approver signs off before anything reaches the regulator. Where the duty is the officer itself, we can appoint one.
PDPL FAQ
If you process personal data about people in Egypt, assume it reaches you until your counsel says otherwise. It follows the data rather than the office, so an organisation with no Egyptian premises can still be inside it — and an Egyptian payroll is enough on its own.
November 2026. The executive regulations took effect in November 2025 and started a one-year compliance period, so that is the date to work back from.
The law provides for one, appointed to the entity and registered with the Personal Data Protection Center. Whether your particular organisation must appoint one is a question for counsel — and if the answer is yes, Thiqa can provide the officer.
Not without permission from the regulator for that transfer. The practical work is knowing which transfers you actually run, which is what Thiqa maps against the permission covering them.
Much of it does. Access reviews, encryption, logging and vendor due diligence are the same artefacts several frameworks ask for, so Thiqa attaches one artefact to every control it proves instead of collecting it again per framework.
Possibly not, and it is worth settling first rather than last. Data held by the Central Bank of Egypt and by entities under its supervision sits outside the law, with money transfer companies and exchange offices named as exceptions that stay inside it. Confirm your own status with counsel before assuming either way.
This page summarises Egypt’s Personal Data Protection Law. It is not legal advice.