Skip to content

Evidence request lists

Egypt Personal Data Protection Law (Law No. 151 of 2020)

Evidence request list. 49 controls, 49 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Egypt PDPL - Budget and Financial Resources

EGY-PDPL-Art.31
Budget and financial resources of the Centre

The Centre has a special budget prepared on the economic-authority model, with its own account at the Central Bank of Egypt and deferred surpluses. Its funding sources include its share of ITIDA's budget; at least one third of fines imposed under the Law; service fees; licence/permit/certification and reconciliation fees; investment revenues; and accepted grants and donations.

Artefacts an auditor will ask for
  • Informational: the Centre's funding model (regulator finance)
Where this commonly fails
  • Not applicable to regulated entities (regulator-internal finance)

Egypt PDPL - Controller and Processor Obligations

EGY-PDPL-Art.4
Controller obligations

Sets twelve controller obligations: obtain data lawfully after consent; ensure validity/sufficiency for purpose; set processing method/standards; ensure purpose applicability; refrain from unlawful disclosure; adopt technical and regulatory security measures preventing hacking/alteration; delete or anonymise data once the purpose is satisfied; correct errors promptly; maintain a record of processing; obtain a Licence or Permit from the Centre; appoint an Egyptian representative if established abroad; and enable Centre inspection. Each of multiple controllers is bound by all obligations.

Artefacts an auditor will ask for
  • Record of personal data processing (categories, recipients, retention, transfers, security measures)
  • Licence/Permit from the Centre
  • Technical and organisational security control evidence
  • Appointment of local representative where controller is offshore
Where this commonly fails
  • No record of processing maintained
  • Operating without a Centre Licence/Permit
  • Offshore controller with no Egyptian representative
EGY-PDPL-Art.5
Processor obligations

Sets twelve processor obligations: process only per the Law and written instructions of the Centre/controller; ensure legitimate purpose; not exceed purpose/period and notify of the processing period; delete or return data after the processing period; refrain from unlawful disclosure; not process contrary to the controller's purpose (except not-for-profit statistical/educational); protect and secure processing media and devices; avoid harm to the data subject; maintain a processing-activities record; provide proof of compliance and enable Centre inspection; obtain a Licence or Permit; and appoint an Egyptian representative if established abroad.

Artefacts an auditor will ask for
  • Written processing instructions / data processing agreement
  • Processor record of processing activities
  • Licence/Permit from the Centre
  • Evidence of secured processing environments and devices
Where this commonly fails
  • Processing beyond documented instructions
  • No processor record of processing
  • Subprocessing without controller authorisation
EGY-PDPL-Art.6
Lawful bases for processing

Electronic processing is legitimate where one of four conditions is met: the data subject's consent for a specified purpose; necessity for performance of a contractual or legal obligation or an agreement for the data subject's benefit, or for claiming/defending the data subject's legal rights; necessity for a legal obligation or an order of competent investigation authorities or a judicial ruling; or necessity for the controller to perform its obligations or a relevant person to exercise legitimate rights, unless this contradicts the data subject's fundamental rights and freedoms.

Artefacts an auditor will ask for
  • Lawful-basis determination recorded per processing activity
  • Consent records where consent is the basis
  • Contract or legal-obligation references supporting processing
Where this commonly fails
  • No documented lawful basis
  • Relying on legitimate interest where it overrides fundamental rights
EGY-PDPL-Art.7
Personal data infringement (breach) notification

Controllers and processors must notify the Centre of any personal data infringement within 72 hours (immediately where national security is concerned). The notification must describe the nature, form and reasons of the infringement, the approximate number of records, DPO information, potential consequences, mitigation procedures, documentation/corrective evidence and any data the Centre requests. The data subject must be notified within three days of notifying the Centre.

Artefacts an auditor will ask for
  • Incident response plan with 72-hour Centre notification path
  • Breach register and notification templates
  • Records of data subject notifications within 3 days
  • Root-cause and corrective-action documentation
Where this commonly fails
  • No 72-hour notification capability
  • Failure to notify affected data subjects
  • Incomplete breach records lacking required content

Egypt PDPL - Crimes and Penalties

EGY-PDPL-Art.35
General penalty provision

Without prejudice to any severer sanctions under other laws and to the injured party's right to damages, the crimes set out in the following articles are penalised with the stated penalties.

Artefacts an auditor will ask for
  • Informational: framing provision for the penalty regime
Where this commonly fails
  • Underestimating cumulative liability where other laws impose severer sanctions
EGY-PDPL-Art.36
Penalty for unauthorised processing

Holders, controllers and processors who collect, process, disclose, make available or circulate electronically processed personal data without legal authorisation or the data subject's consent face a fine of EGP 100,000 to 1,000,000. Where done for material/moral benefit or to endanger/harm the data subject, the penalty is imprisonment of at least six months and/or a fine of EGP 200,000 to 2,000,000.

Artefacts an auditor will ask for
  • Evidence of lawful basis/consent for all processing (to avoid the offence)
  • Consent and authorisation records
Where this commonly fails
  • Processing without documented authorisation or consent
EGY-PDPL-Art.37
Penalty for denying rights and unlawful collection

Holders, controllers and processors who, without legal justification, refrain from enabling a data subject to exercise the rights under Article 2 face a fine up to EGP 1,000,000. Whoever collects personal data without complying with Article 3 faces a fine of EGP 200,000 to 2,000,000.

Artefacts an auditor will ask for
  • Evidence of fulfilling Article 2 rights requests
  • Evidence of Article 3 collection conditions being met
Where this commonly fails
  • Refusing rights requests without justification
  • Collecting data contrary to Article 3 conditions
EGY-PDPL-Art.38
Penalty for breach of controller/processor obligations

Controllers and processors who do not perform their obligations under Articles 4, 5 and 7 face a fine of EGP 300,000 to 3,000,000.

Artefacts an auditor will ask for
  • Evidence of meeting Article 4/5 obligations and Article 7 breach notification
Where this commonly fails
  • Gaps in controller/processor obligations or breach-notification failures
EGY-PDPL-Art.39
Penalty for failure to appoint a DPO

Legal representatives of juristic persons who do not fulfil their obligations under Article 8 (DPO appointment and registration) face a fine of EGP 200,000 to 2,000,000.

Artefacts an auditor will ask for
  • Evidence of DPO appointment and Centre registration
Where this commonly fails
  • No appointed/registered DPO for a juristic person
EGY-PDPL-Art.40
Penalty for DPO failure of duties

Data Protection Officers who fail to carry out their Article 9 duties face a fine of EGP 200,000 to 2,000,000; where the violation is due to DPO negligence the fine is EGP 50,000 to 500,000.

Artefacts an auditor will ask for
  • Evidence the DPO is discharging Article 9 duties (assessments, training, request handling)
Where this commonly fails
  • DPO not performing statutory duties
EGY-PDPL-Art.41
Penalty for unlawful sensitive-data processing

Holders, controllers and processors who collect, make available, circulate, process, disclose, store, transfer or save sensitive personal data without the data subject's consent or legal permission face imprisonment of at least three months and/or a fine of EGP 500,000 to 5,000,000.

Artefacts an auditor will ask for
  • Centre licence and explicit consent records for sensitive data (to avoid the offence)
Where this commonly fails
  • Sensitive-data processing without licence or explicit consent
EGY-PDPL-Art.42
Penalty for unlawful cross-border transfer

Whoever violates the cross-border transfer conditions under Articles 14, 15 and 16 faces imprisonment of at least three months and/or a fine of EGP 500,000 to 5,000,000.

Artefacts an auditor will ask for
  • Licences and adequacy/derogation documentation for transfers (to avoid the offence)
Where this commonly fails
  • Transferring abroad outside the Article 14-16 conditions
EGY-PDPL-Art.43
Penalty for marketing violations

Whoever violates the electronic marketing provisions of Articles 17 and 18 faces a fine of EGP 200,000 to 2,000,000.

Artefacts an auditor will ask for
  • Marketing consent and record-keeping evidence (to avoid the offence)
Where this commonly fails
  • Marketing without consent or required records
EGY-PDPL-Art.44
Penalty for breach of Centre confidentiality

Members of the Centre's Board and its employees who violate the confidentiality obligations of Article 24 face a fine of EGP 300,000 to 3,000,000.

Artefacts an auditor will ask for
  • Informational: penalty binding the regulator's personnel
Where this commonly fails
  • Not applicable to regulated entities (regulator-internal duty)
EGY-PDPL-Art.45
Penalty for license/permit/certification violations

Whoever violates the provisions of Licences, Permits or Certifications under the Law faces a fine of EGP 500,000 to 5,000,000.

Artefacts an auditor will ask for
  • Evidence of compliance with the conditions of held authorisations
Where this commonly fails
  • Operating outside the scope/conditions of a Licence or Permit
EGY-PDPL-Art.46
Penalty for obstructing Centre officers

Whoever prevents a Centre employee holding control powers from performing their work faces imprisonment of at least six months and/or a fine of EGP 200,000 to 2,000,000.

Artefacts an auditor will ask for
  • Procedures to cooperate with Centre inspections and provide access
Where this commonly fails
  • Obstructing or denying access to Centre inspectors
EGY-PDPL-Art.47
De facto manager and juristic-person liability

The de facto manager of a violating juristic person is penalised with the same sanctions where it is proven the manager knew of the violation and their breach of duties contributed to it. The juristic person is jointly liable for damages where the violation is committed by an employee in its name, for its account and benefit.

Artefacts an auditor will ask for
  • Management oversight and accountability evidence
  • Allocation of data-protection responsibilities to managers
Where this commonly fails
  • Management disengagement from data-protection compliance
EGY-PDPL-Art.48
Publication of sentences and recidivism

In addition to penalties, courts order publication of sentences in two widespread newspapers and on the internet at the convict's expense. On recidivism the minimum and maximum sanctions are doubled, and attempts to commit violations are sanctioned with half the prescribed penalties.

Artefacts an auditor will ask for
  • Informational: aggravating and publication rules for sentencing
Where this commonly fails
  • Underestimating doubled sanctions for repeat violations
EGY-PDPL-Art.49
Settlement and reconciliation

At any stage before a final judgment the defendant may reach settlement/reconciliation with the claimant and the Centre regarding the misdemeanours under Articles 36-43 (and with the Centre for Articles 42, 44, 45), paying half the minimum fine before proceedings or half the maximum fine (or the adjudicated fine, whichever is higher) after proceedings begin. Reconciliation ends criminal proceedings without affecting the injured party's rights.

Artefacts an auditor will ask for
  • Informational: the settlement/reconciliation mechanism
Where this commonly fails
  • Assuming reconciliation removes civil liability to injured parties

Egypt PDPL - Cross-Border Data Transfer

EGY-PDPL-Art.14
Cross-border transfer adequacy and licensing

Transfer, storage or sharing of personal data collected or prepared for processing to a foreign country may only occur if the foreign country's level of data protection or security meets or exceeds the requirements of the Law, and subject to obtaining a relevant Licence or Permit from the Centre. The Executive Regulations set the criteria and rules for cross-border transfers.

Artefacts an auditor will ask for
  • Adequacy assessment of destination country protection level
  • Centre Licence/Permit authorising the transfer
  • Transfer register with safeguards
Where this commonly fails
  • Transferring abroad without a Centre Licence/Permit
  • No assessment of the destination's protection level
EGY-PDPL-Art.15
Derogations from the cross-border protection level

Where the data subject's (or representative's) explicit consent is obtained, transfer/sharing/processing of personal data may proceed without the minimum protection level of Article 14 in seven cases: to preserve the data subject's life or provide medical care; to prove/exercise/defend a right before the judiciary; to conclude or perform an agreement for the data subject's benefit; for international judicial cooperation; legal necessity to protect the public interest; to transfer money to another country under that country's laws; or under a bilateral/multilateral international agreement to which Egypt is a party.

Artefacts an auditor will ask for
  • Explicit consent records relied on for the derogation
  • Documentation of the specific Article 15 derogation case
  • Necessity assessment for the transfer
Where this commonly fails
  • Using a derogation as routine basis for bulk transfers
  • No explicit consent where the derogation requires it
EGY-PDPL-Art.16
Disclosure to controllers/processors abroad under licence

A controller or processor may disclose personal data to another controller or processor outside Egypt under a Centre Licence, provided: there is conformity between the parties' nature of work or unity of purpose; each party (or the data subject) has a legitimate interest in the data; and the level of legal and technical protection abroad is not less than that provided in Egypt.

Artefacts an auditor will ask for
  • Centre Licence for the offshore disclosure
  • Assessment of the recipient's protection level
  • Documentation of conformity of purpose and legitimate interest
Where this commonly fails
  • Offshore disclosure without a Licence
  • Recipient protection level below Egyptian requirements

Egypt PDPL - Data Protection Officer

EGY-PDPL-Art.8
Appointment of the Data Protection Officer

The Centre maintains a register of Data Protection Officers. The legal representative of a juristic person acting as controller or processor must appoint a competent employee responsible for personal data protection within the entity, register that DPO with the Centre and announce the appointment. A natural-person controller or processor is themselves responsible for applying the Law.

Artefacts an auditor will ask for
  • DPO appointment letter and announcement
  • Registration of the DPO in the Centre register
  • DPO role description and position in the org structure
Where this commonly fails
  • No DPO appointed by a juristic person
  • DPO not registered with the Centre
EGY-PDPL-Art.9
Data Protection Officer obligations

The DPO is responsible for applying the Law, its Executive Regulations and Centre decisions, and for supervising procedures and handling data requests. Specific duties: regular evaluation/inspection of protection systems and documenting results; acting as contact point with the Centre; enabling data subjects to exercise rights; notifying the Centre of infringements; responding to requests and complaints; following up the record of processing; eliminating violations and taking corrective action; and organising staff training.

Artefacts an auditor will ask for
  • DPO periodic assessment reports
  • Records of requests/complaints handled by the DPO
  • Staff training programme records
  • Corrective-action logs for identified violations
Where this commonly fails
  • No periodic evaluation of protection systems
  • DPO not acting as Centre contact point
  • No staff training programme

Egypt PDPL - Data Subject Rights and Processing Conditions

EGY-PDPL-Art.2
Data subject rights and consent requirement

Personal data may not be collected, processed, disclosed or revealed except with the explicit consent of the data subject or where otherwise permitted by law. Grants data subjects the rights to know/review/access their data; to withdraw prior consent; to correct, edit, delete, add or update; to limit processing to a specified purpose; to be notified of any infringement; and to object to processing. A consideration (capped at EGP 20,000) may be charged for exercising rights other than infringement notification.

Artefacts an auditor will ask for
  • Consent capture and withdrawal logs
  • Documented procedure for access, rectification, erasure, restriction and objection requests
  • Records of infringement notifications to data subjects
  • Fee schedule for rights requests within the EGP 20,000 cap
Where this commonly fails
  • No mechanism to withdraw consent
  • Charging for infringement notification (prohibited)
  • Exceeding the statutory fee cap
EGY-PDPL-Art.3
Conditions for lawful collection and processing

Personal data must be collected for legitimate, specific and transparent purposes; be correct, valid and secured; be processed lawfully and consistently with the purpose of collection; and not be retained longer than necessary for that purpose. The Executive Regulations specify the policies, procedures and standard criteria for collecting, processing, storing and securing data.

Artefacts an auditor will ask for
  • Documented lawful purposes per processing activity
  • Data quality/accuracy controls
  • Retention schedule and deletion evidence
  • Security measures records
Where this commonly fails
  • Open-ended retention with no schedule
  • Purpose creep beyond the stated collection purpose
  • No accuracy/validation controls

Egypt PDPL - Definitions and Scope

EGY-PDPL-Art.1
Definitions

Defines the key terms of the Law: Personal Data, Processing, Sensitive Personal Data, Data Subject, Holder, Controller, Processor, Disclosing Personal Data, Data Security, Personal Data Infringement, Cross-Border Personal Data Transfer, Electronic Marketing, National Security Authorities, the Centre, License, Permit, Certification and Competent Minister. Scope is limited to personal data processed electronically, in whole or in part.

Artefacts an auditor will ask for
  • Data map distinguishing personal vs sensitive personal data
  • Records of processing scoped to electronic processing
  • Role designations (holder/controller/processor) per processing activity
Where this commonly fails
  • Treating only structured databases as in-scope while ignoring electronic processing in part
  • No clear controller/processor role assignment

Egypt PDPL - Direct Electronic Marketing

EGY-PDPL-Art.17
Conditions for direct electronic marketing

Electronic communication for direct marketing to a data subject is prohibited unless: the data subject's consent is obtained; the communication includes the sender's identity; the sender has a valid and complete contactable address; there is a clear indication that the purpose is direct marketing; and clear, uncomplicated opt-out/consent-withdrawal mechanisms are provided.

Artefacts an auditor will ask for
  • Marketing consent records
  • Sender identity and contact address in communications
  • Functioning opt-out/withdrawal mechanism logs
Where this commonly fails
  • Sending marketing without prior consent
  • No working opt-out mechanism
  • Concealed sender identity
EGY-PDPL-Art.18
Obligations of the direct-marketing sender

The sender of direct-marketing electronic communications must specify a defined marketing purpose; not disclose the data subject's contact details; and maintain electronic records evidencing the data subject's consent (or non-objection to continuity) for three years from the date of the last communication.

Artefacts an auditor will ask for
  • Defined marketing-purpose documentation
  • Three-year consent/non-objection records
  • Controls preventing disclosure of contact details
Where this commonly fails
  • No retention of consent records for the 3-year period
  • Disclosing recipients' contact details

Egypt PDPL - Disclosure of Personal Data

EGY-PDPL-Art.10
Procedures for disclosure of personal data

Where a controller, processor or holder is requested to disclose personal data it must follow set procedures: the request must be written and submitted by the relevant person or under a legal deed; the required documents granting access must be verified and retained; and the disclosure decision with supporting documents must be made within six working days of submission, with rejection reasons stated. Lapse of the period without a decision is deemed a rejection.

Artefacts an auditor will ask for
  • Written disclosure-request intake records
  • Verification and retention of access-authorising documents
  • Decision log evidencing the six-working-day timeline
Where this commonly fails
  • Disclosing without a written, verified request
  • Missing the six-working-day decision deadline
EGY-PDPL-Art.11
Determinative effect of digital evidence

Digital evidence derived from personal data under the Law has the same determinative (evidentiary) effect as evidence derived from written data, provided it meets the criteria and technical conditions set out in the Executive Regulations.

Artefacts an auditor will ask for
  • Controls ensuring integrity and authenticity of digital evidence
  • Logging and chain-of-custody for personal-data-derived evidence
Where this commonly fails
  • No integrity controls to support evidentiary reliability

Egypt PDPL - Judicial Control

EGY-PDPL-Art.34
Judicial control powers

Centre employees appointed by decision of the Minister of Justice (on the Competent Minister's proposal) hold judicial control (law-enforcement) powers in relation to violations of the Law.

Artefacts an auditor will ask for
  • Informational: judicial-control powers of designated Centre officers
Where this commonly fails
  • Obstructing designated officers exercising judicial-control powers

Egypt PDPL - Licenses, Permits and Certifications

EGY-PDPL-Art.26
Types of licenses, permits and certifications

The Centre issues Licences, Permits and Certifications, classifying their types and conditions: licences/permits for storing/handling/processing data; for direct electronic marketing; for processing by associations/unions/clubs; for visual surveillance in public places; for control and processing of sensitive personal data; permits/certifications for consultancy services; and licences/permits for cross-border transfer. Licence fees may not exceed EGP 2,000,000 and permit/certification fees EGP 500,000.

Artefacts an auditor will ask for
  • Inventory of activities requiring a Licence/Permit/Certification
  • Held Centre Licences/Permits/Certifications matching each activity
  • Surveillance and sensitive-data licences where applicable
Where this commonly fails
  • Conducting a licensable activity (e.g. CCTV in public, marketing, sensitive data) without the matching Centre authorisation
EGY-PDPL-Art.27
Procedures for issuing licenses, permits and certifications

Applications are submitted on Centre forms with supporting documents and proof of financial and technical ability. Decisions are made within 90 days of completing documentation; lapse without decision is deemed rejection. The Centre may request further data or additional protection guarantees. A controller or processor may hold more than one Licence or Permit by data type.

Artefacts an auditor will ask for
  • Complete licence/permit applications with supporting evidence
  • Proof of financial and technical capability submitted
  • Records of Centre correspondence and additional-guarantee requests
Where this commonly fails
  • Incomplete applications causing deemed rejection
  • Operating while an application is pending without authorisation
EGY-PDPL-Art.28
Amendment of license and permit conditions

In the public interest the Centre may amend Licence or Permit conditions after issuance: in response to international, regional or national laws; upon the licensee's request; on merger of a controller/processor with others inside or outside Egypt; or where amendment is necessary to achieve the Law's objectives.

Artefacts an auditor will ask for
  • Process to track and implement Centre-amended licence conditions
  • Notifications to the Centre on mergers or material changes
Where this commonly fails
  • Not updating practices after the Centre amends licence conditions
  • Failing to notify the Centre of a merger
EGY-PDPL-Art.29
Cancellation of licenses, permits and certifications

The Centre may cancel a Licence, Permit or Certification for: breach of its terms; non-payment of renewal fees; repeated non-compliance with Centre decisions; assignment to a third party without Centre approval; or bankruptcy of the controller/processor by judicial ruling.

Artefacts an auditor will ask for
  • Renewal-fee payment records
  • Evidence of compliance with Centre decisions
  • Controls preventing unauthorised assignment of authorisations
Where this commonly fails
  • Lapsed renewal payments
  • Assigning a licence without Centre approval
EGY-PDPL-Art.30
Administrative sanctions

Without prejudice to civil/criminal liability, the Centre CEO notifies a violator to stop and remedy a violation within a set period; if unremedied, the Board may issue a reasoned decision: warning of partial/total suspension; suspension of the Licence/Permit/Certification; cancellation or revocation; publication of the proven violations at the violator's cost; or subjecting the controller/processor to the Centre's technical supervision at its own cost.

Artefacts an auditor will ask for
  • Records of Centre notices and remediation undertaken
  • Remediation tracking within the period set by the Centre
Where this commonly fails
  • Ignoring a Centre stop-and-remedy notice
  • No tracking of administrative-sanction remediation

Egypt PDPL - Personal Data Protection Centre

EGY-PDPL-Art.19
Establishment and mandate of the Personal Data Protection Centre

Establishes the Personal Data Protection Centre as a public economic authority with juristic personality, affiliated to the Competent Minister and headquartered in Cairo. The Centre's mandate covers setting policies and strategic plans; unifying protection/processing policies; issuing decisions, regulations and criteria; approving codes of conduct; issuing licences/permits/certifications; receiving complaints; advising on draft laws and international agreements; controlling and inspecting addressees; verifying cross-border transfer conditions; awareness and training; and issuing an annual report on data protection in Egypt.

Artefacts an auditor will ask for
  • Reference to Centre guidance, decisions and codes of conduct relied upon
  • Registration/notification interactions with the Centre
Where this commonly fails
  • Ignoring Centre guidance and codes of conduct applicable to the activity
EGY-PDPL-Art.20
Board of Directors of the Centre

The Centre has a Board chaired by the Competent Minister and including representatives of the Ministries of Defence and Interior, the General Intelligence Service, the Administrative Control Authority, ITIDA, the NTRA, the Centre's CEO and three appointed experts. Board membership is for renewable three-year terms; the Prime Minister issues the formation decree and sets remuneration. The Board may form committees and delegate competencies.

Artefacts an auditor will ask for
  • Informational: composition of the Centre's Board (regulator governance)
Where this commonly fails
  • Not applicable to regulated entities (regulator-internal governance)
EGY-PDPL-Art.21
Competencies of the Centre's Board

The Board is the dominant authority over the Centre's affairs and may take decisions to pursue the Centre's purposes, including adopting protection policies/plans; approving regulations, controls and standards; approving international cooperation plans; approving the organisational structure, financial/administrative/HR regulations and annual budget; approving establishment of offices/branches; and accepting grants, funds and donations.

Artefacts an auditor will ask for
  • Informational: the Board's decision-making powers (regulator governance)
Where this commonly fails
  • Not applicable to regulated entities (regulator-internal governance)
EGY-PDPL-Art.22
Board meetings and resolutions

The Board meets at least monthly upon the Chairman's invitation and whenever necessary; meetings are valid with a majority present; resolutions pass by a two-thirds majority of attending members; and the Chairman may invite non-voting attendees.

Artefacts an auditor will ask for
  • Informational: Board meeting and quorum rules (regulator governance)
Where this commonly fails
  • Not applicable to regulated entities (regulator-internal governance)
EGY-PDPL-Art.23
Chief Executive Officer of the Centre

The Centre has a CEO appointed by Prime Ministerial decree on the Competent Minister's proposal for a renewable four-year term. The CEO is responsible before the Board for the Centre's technical, administrative and financial work and represents the Centre, including supervising implementation of Board resolutions, managing the Centre, submitting periodic reports and enforcing the Centre's functions.

Artefacts an auditor will ask for
  • Informational: the Centre CEO's role and accountability (regulator governance)
Where this commonly fails
  • Not applicable to regulated entities (regulator-internal governance)
EGY-PDPL-Art.24
Confidentiality obligation of Board members and Centre staff

Board members and Centre employees are prohibited from disclosing documents or data relating to cases monitored or examined by the Centre, or submitted/circulated during examination or decision-making; this obligation survives the end of the relationship with the Centre. Such information may only be disclosed to investigating and judicial authorities.

Artefacts an auditor will ask for
  • Informational: confidentiality duties binding the regulator's personnel
Where this commonly fails
  • Not applicable to regulated entities (regulator-internal duty)
EGY-PDPL-Art.25
International cooperation by the Centre

The Centre may, in coordination with competent authorities, cooperate with foreign counterparts within international, regional and bilateral cooperation agreements, ratified protocols or reciprocity, to protect personal data and verify compliance by controllers/processors outside Egypt, exchanging data while ensuring its protection and assisting investigation of violations.

Artefacts an auditor will ask for
  • Informational: the Centre's cross-border cooperation mandate
Where this commonly fails
  • Assuming offshore processing escapes oversight despite Centre cooperation channels

Egypt PDPL - Requests and Complaints

EGY-PDPL-Art.32
Requests by data subjects

A data subject or relevant person may submit a request to any holder, controller or processor to exercise their rights under the Law, and the holder/controller/processor must reply within six working days of submission.

Artefacts an auditor will ask for
  • Request intake and response procedure meeting the six-working-day deadline
  • Logs of rights requests and responses
Where this commonly fails
  • Missing the six-working-day response deadline
  • No request-handling procedure
EGY-PDPL-Art.33
Complaints to the Centre

Without prejudice to judicial proceedings, a data subject or relevant person may complain to the Centre for: infringement/breach of the right to data protection; failure to enable exercise of rights; or decisions of the DPO of the processor/controller on submitted requests. The Centre investigates and decides within 30 working days and notifies both parties; the respondent must execute the decision within seven working days and notify the Centre.

Artefacts an auditor will ask for
  • Procedure to respond to Centre complaint investigations
  • Evidence of executing Centre decisions within seven working days
Where this commonly fails
  • Failing to execute a Centre decision in time
  • No process to handle escalated complaints

Egypt PDPL - Sensitive Personal Data

EGY-PDPL-Art.12
Processing of sensitive personal data and children's data

Controllers and processors are prohibited from collecting, transferring, storing, processing or disclosing sensitive personal data except under a licence from the Centre, and (save where authorised by law) must obtain the data subject's explicit written consent. Processing children's data requires the legal guardian's consent, and a child's participation in a game, competition or activity may not be conditioned on submitting more personal data than necessary for participation.

Artefacts an auditor will ask for
  • Centre licence covering sensitive personal data
  • Explicit written consent records for sensitive data
  • Guardian consent records for children's data
  • Data minimisation controls for children's services
Where this commonly fails
  • Processing sensitive data without a Centre licence
  • No explicit written consent for sensitive data
  • No guardian-consent mechanism for children
EGY-PDPL-Art.13
DPO security duties for sensitive personal data

In addition to the Article 9 obligations, the DPO of the controller or processor must follow and implement the security policies and procedures necessary to avoid any breach or infringement of sensitive personal data.

Artefacts an auditor will ask for
  • Enhanced security policy for sensitive data
  • Evidence of DPO oversight of sensitive-data safeguards
Where this commonly fails
  • No differentiated safeguards for sensitive data
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Egypt Personal Data Protection Law (Law No. 151 of 2020) framework page.