We provide your data protection officer.
A qualified DPO appointed to your licensed entity in Egypt, monthly. They work inside Thiqa, so the record builds itself.
Early access · work email only
Your outsourced DPO works inside Thiqa
Personnel
Appointed officers and the approvals that carry their name
Your data protection officer
Qualified appointment · monthly engagement · appointed 1 March
Approvals
4 this monthMost outsourced arrangements end with a person and a mailbox. Yours works inside your Thiqa workspace.
Their approvals are the evidence — dated, attributed, traceable. Nothing is reconstructed for an auditor later, because it was never kept anywhere else.
How your DPO is appointed
Four steps from the first call to an appointed officer working inside your workspace.
01
Scoping call
We learn your entities, your licences and your data flows. Thirty minutes, no deck. You leave knowing whether you need one officer or several.
02
Matching
A qualified DPO is appointed to your organisation — matched to your sector, your regulators and your working language. You meet them, and you approve them, before anything is signed.
03
Onboarding into your workspace
Your DPO works inside Thiqa from day one, scoped to the obligations the entity actually holds. The record of processing starts immediately rather than at the first audit.
04
Ongoing duties and reporting
Decisions, evidence and approvals are recorded as they happen. Requests, assessments and breach readiness run on their own cadence, and a standing report goes to your board.
Who must appoint a DPO under Egypt’s PDPL
If your entity processes personal data as a controller or a processor, assume yes until your counsel tells you otherwise — and the duty attaches to the licensed entity, not to the group above it. One appointment at a parent does not automatically cover a subsidiary holding its own licence.
[Which controllers and processors fall in scope, whether any threshold applies by headcount, data volume or category of processing, whether one officer may serve several entities, and the compliance deadline — counsel to confirm against the law and its executive regulations. Publish no threshold and no date until each is checked.]
For how the organisation handles personal data, and for being the named contact when a regulator or a data subject asks who that is. It is a standing programme rather than a project: the record of processing kept current, assessments run before new processing ships, requests answered, breaches decided and notified, processors and transfers reviewed, and the board told where things actually stand.
[That list describes what this engagement covers, not a recital of the statute. The statutory duty list, the data-subject response window and the breach notification window — counsel to confirm against the executive regulations before any of the three is stated as law.]
Not appointing is a compliance failure in its own right, separate from anything that ever happens to the data — it does not wait for an incident. For a licensed institution the exposure usually arrives first as a finding: an unanswered data-subject request, an unreported breach, or a supervisory question about who owns data protection that nobody in the room can answer with a name.
[Administrative penalties for non-appointment, and whether liability extends to officers or directors personally — counsel to confirm. No figure is stated here on purpose.]
This section describes the general shape of the obligation. It is not legal advice, and every bracketed note above is an open question for counsel rather than a gap in the service.