Egypt Personal Data Protection Law (Law No. 151 of 2020)
Evidence request list. 49 controls, 49 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Egypt PDPL - Budget and Financial Resources
The Centre has a special budget prepared on the economic-authority model, with its own account at the Central Bank of Egypt and deferred surpluses. Its funding sources include its share of ITIDA's budget; at least one third of fines imposed under the Law; service fees; licence/permit/certification and reconciliation fees; investment revenues; and accepted grants and donations.
- Informational: the Centre's funding model (regulator finance)
- Not applicable to regulated entities (regulator-internal finance)
Egypt PDPL - Controller and Processor Obligations
Sets twelve controller obligations: obtain data lawfully after consent; ensure validity/sufficiency for purpose; set processing method/standards; ensure purpose applicability; refrain from unlawful disclosure; adopt technical and regulatory security measures preventing hacking/alteration; delete or anonymise data once the purpose is satisfied; correct errors promptly; maintain a record of processing; obtain a Licence or Permit from the Centre; appoint an Egyptian representative if established abroad; and enable Centre inspection. Each of multiple controllers is bound by all obligations.
- Record of personal data processing (categories, recipients, retention, transfers, security measures)
- Licence/Permit from the Centre
- Technical and organisational security control evidence
- Appointment of local representative where controller is offshore
- No record of processing maintained
- Operating without a Centre Licence/Permit
- Offshore controller with no Egyptian representative
Sets twelve processor obligations: process only per the Law and written instructions of the Centre/controller; ensure legitimate purpose; not exceed purpose/period and notify of the processing period; delete or return data after the processing period; refrain from unlawful disclosure; not process contrary to the controller's purpose (except not-for-profit statistical/educational); protect and secure processing media and devices; avoid harm to the data subject; maintain a processing-activities record; provide proof of compliance and enable Centre inspection; obtain a Licence or Permit; and appoint an Egyptian representative if established abroad.
- Written processing instructions / data processing agreement
- Processor record of processing activities
- Licence/Permit from the Centre
- Evidence of secured processing environments and devices
- Processing beyond documented instructions
- No processor record of processing
- Subprocessing without controller authorisation
Electronic processing is legitimate where one of four conditions is met: the data subject's consent for a specified purpose; necessity for performance of a contractual or legal obligation or an agreement for the data subject's benefit, or for claiming/defending the data subject's legal rights; necessity for a legal obligation or an order of competent investigation authorities or a judicial ruling; or necessity for the controller to perform its obligations or a relevant person to exercise legitimate rights, unless this contradicts the data subject's fundamental rights and freedoms.
- Lawful-basis determination recorded per processing activity
- Consent records where consent is the basis
- Contract or legal-obligation references supporting processing
- No documented lawful basis
- Relying on legitimate interest where it overrides fundamental rights
Controllers and processors must notify the Centre of any personal data infringement within 72 hours (immediately where national security is concerned). The notification must describe the nature, form and reasons of the infringement, the approximate number of records, DPO information, potential consequences, mitigation procedures, documentation/corrective evidence and any data the Centre requests. The data subject must be notified within three days of notifying the Centre.
- Incident response plan with 72-hour Centre notification path
- Breach register and notification templates
- Records of data subject notifications within 3 days
- Root-cause and corrective-action documentation
- No 72-hour notification capability
- Failure to notify affected data subjects
- Incomplete breach records lacking required content
Egypt PDPL - Crimes and Penalties
Without prejudice to any severer sanctions under other laws and to the injured party's right to damages, the crimes set out in the following articles are penalised with the stated penalties.
- Informational: framing provision for the penalty regime
- Underestimating cumulative liability where other laws impose severer sanctions
Holders, controllers and processors who collect, process, disclose, make available or circulate electronically processed personal data without legal authorisation or the data subject's consent face a fine of EGP 100,000 to 1,000,000. Where done for material/moral benefit or to endanger/harm the data subject, the penalty is imprisonment of at least six months and/or a fine of EGP 200,000 to 2,000,000.
- Evidence of lawful basis/consent for all processing (to avoid the offence)
- Consent and authorisation records
- Processing without documented authorisation or consent
Holders, controllers and processors who, without legal justification, refrain from enabling a data subject to exercise the rights under Article 2 face a fine up to EGP 1,000,000. Whoever collects personal data without complying with Article 3 faces a fine of EGP 200,000 to 2,000,000.
- Evidence of fulfilling Article 2 rights requests
- Evidence of Article 3 collection conditions being met
- Refusing rights requests without justification
- Collecting data contrary to Article 3 conditions
Controllers and processors who do not perform their obligations under Articles 4, 5 and 7 face a fine of EGP 300,000 to 3,000,000.
- Evidence of meeting Article 4/5 obligations and Article 7 breach notification
- Gaps in controller/processor obligations or breach-notification failures
Legal representatives of juristic persons who do not fulfil their obligations under Article 8 (DPO appointment and registration) face a fine of EGP 200,000 to 2,000,000.
- Evidence of DPO appointment and Centre registration
- No appointed/registered DPO for a juristic person
Data Protection Officers who fail to carry out their Article 9 duties face a fine of EGP 200,000 to 2,000,000; where the violation is due to DPO negligence the fine is EGP 50,000 to 500,000.
- Evidence the DPO is discharging Article 9 duties (assessments, training, request handling)
- DPO not performing statutory duties
Holders, controllers and processors who collect, make available, circulate, process, disclose, store, transfer or save sensitive personal data without the data subject's consent or legal permission face imprisonment of at least three months and/or a fine of EGP 500,000 to 5,000,000.
- Centre licence and explicit consent records for sensitive data (to avoid the offence)
- Sensitive-data processing without licence or explicit consent
Whoever violates the cross-border transfer conditions under Articles 14, 15 and 16 faces imprisonment of at least three months and/or a fine of EGP 500,000 to 5,000,000.
- Licences and adequacy/derogation documentation for transfers (to avoid the offence)
- Transferring abroad outside the Article 14-16 conditions
Whoever violates the electronic marketing provisions of Articles 17 and 18 faces a fine of EGP 200,000 to 2,000,000.
- Marketing consent and record-keeping evidence (to avoid the offence)
- Marketing without consent or required records
Members of the Centre's Board and its employees who violate the confidentiality obligations of Article 24 face a fine of EGP 300,000 to 3,000,000.
- Informational: penalty binding the regulator's personnel
- Not applicable to regulated entities (regulator-internal duty)
Whoever violates the provisions of Licences, Permits or Certifications under the Law faces a fine of EGP 500,000 to 5,000,000.
- Evidence of compliance with the conditions of held authorisations
- Operating outside the scope/conditions of a Licence or Permit
Whoever prevents a Centre employee holding control powers from performing their work faces imprisonment of at least six months and/or a fine of EGP 200,000 to 2,000,000.
- Procedures to cooperate with Centre inspections and provide access
- Obstructing or denying access to Centre inspectors
The de facto manager of a violating juristic person is penalised with the same sanctions where it is proven the manager knew of the violation and their breach of duties contributed to it. The juristic person is jointly liable for damages where the violation is committed by an employee in its name, for its account and benefit.
- Management oversight and accountability evidence
- Allocation of data-protection responsibilities to managers
- Management disengagement from data-protection compliance
In addition to penalties, courts order publication of sentences in two widespread newspapers and on the internet at the convict's expense. On recidivism the minimum and maximum sanctions are doubled, and attempts to commit violations are sanctioned with half the prescribed penalties.
- Informational: aggravating and publication rules for sentencing
- Underestimating doubled sanctions for repeat violations
At any stage before a final judgment the defendant may reach settlement/reconciliation with the claimant and the Centre regarding the misdemeanours under Articles 36-43 (and with the Centre for Articles 42, 44, 45), paying half the minimum fine before proceedings or half the maximum fine (or the adjudicated fine, whichever is higher) after proceedings begin. Reconciliation ends criminal proceedings without affecting the injured party's rights.
- Informational: the settlement/reconciliation mechanism
- Assuming reconciliation removes civil liability to injured parties
Egypt PDPL - Cross-Border Data Transfer
Transfer, storage or sharing of personal data collected or prepared for processing to a foreign country may only occur if the foreign country's level of data protection or security meets or exceeds the requirements of the Law, and subject to obtaining a relevant Licence or Permit from the Centre. The Executive Regulations set the criteria and rules for cross-border transfers.
- Adequacy assessment of destination country protection level
- Centre Licence/Permit authorising the transfer
- Transfer register with safeguards
- Transferring abroad without a Centre Licence/Permit
- No assessment of the destination's protection level
Where the data subject's (or representative's) explicit consent is obtained, transfer/sharing/processing of personal data may proceed without the minimum protection level of Article 14 in seven cases: to preserve the data subject's life or provide medical care; to prove/exercise/defend a right before the judiciary; to conclude or perform an agreement for the data subject's benefit; for international judicial cooperation; legal necessity to protect the public interest; to transfer money to another country under that country's laws; or under a bilateral/multilateral international agreement to which Egypt is a party.
- Explicit consent records relied on for the derogation
- Documentation of the specific Article 15 derogation case
- Necessity assessment for the transfer
- Using a derogation as routine basis for bulk transfers
- No explicit consent where the derogation requires it
A controller or processor may disclose personal data to another controller or processor outside Egypt under a Centre Licence, provided: there is conformity between the parties' nature of work or unity of purpose; each party (or the data subject) has a legitimate interest in the data; and the level of legal and technical protection abroad is not less than that provided in Egypt.
- Centre Licence for the offshore disclosure
- Assessment of the recipient's protection level
- Documentation of conformity of purpose and legitimate interest
- Offshore disclosure without a Licence
- Recipient protection level below Egyptian requirements
Egypt PDPL - Data Protection Officer
The Centre maintains a register of Data Protection Officers. The legal representative of a juristic person acting as controller or processor must appoint a competent employee responsible for personal data protection within the entity, register that DPO with the Centre and announce the appointment. A natural-person controller or processor is themselves responsible for applying the Law.
- DPO appointment letter and announcement
- Registration of the DPO in the Centre register
- DPO role description and position in the org structure
- No DPO appointed by a juristic person
- DPO not registered with the Centre
The DPO is responsible for applying the Law, its Executive Regulations and Centre decisions, and for supervising procedures and handling data requests. Specific duties: regular evaluation/inspection of protection systems and documenting results; acting as contact point with the Centre; enabling data subjects to exercise rights; notifying the Centre of infringements; responding to requests and complaints; following up the record of processing; eliminating violations and taking corrective action; and organising staff training.
- DPO periodic assessment reports
- Records of requests/complaints handled by the DPO
- Staff training programme records
- Corrective-action logs for identified violations
- No periodic evaluation of protection systems
- DPO not acting as Centre contact point
- No staff training programme
Egypt PDPL - Data Subject Rights and Processing Conditions
Personal data may not be collected, processed, disclosed or revealed except with the explicit consent of the data subject or where otherwise permitted by law. Grants data subjects the rights to know/review/access their data; to withdraw prior consent; to correct, edit, delete, add or update; to limit processing to a specified purpose; to be notified of any infringement; and to object to processing. A consideration (capped at EGP 20,000) may be charged for exercising rights other than infringement notification.
- Consent capture and withdrawal logs
- Documented procedure for access, rectification, erasure, restriction and objection requests
- Records of infringement notifications to data subjects
- Fee schedule for rights requests within the EGP 20,000 cap
- No mechanism to withdraw consent
- Charging for infringement notification (prohibited)
- Exceeding the statutory fee cap
Personal data must be collected for legitimate, specific and transparent purposes; be correct, valid and secured; be processed lawfully and consistently with the purpose of collection; and not be retained longer than necessary for that purpose. The Executive Regulations specify the policies, procedures and standard criteria for collecting, processing, storing and securing data.
- Documented lawful purposes per processing activity
- Data quality/accuracy controls
- Retention schedule and deletion evidence
- Security measures records
- Open-ended retention with no schedule
- Purpose creep beyond the stated collection purpose
- No accuracy/validation controls
Egypt PDPL - Definitions and Scope
Defines the key terms of the Law: Personal Data, Processing, Sensitive Personal Data, Data Subject, Holder, Controller, Processor, Disclosing Personal Data, Data Security, Personal Data Infringement, Cross-Border Personal Data Transfer, Electronic Marketing, National Security Authorities, the Centre, License, Permit, Certification and Competent Minister. Scope is limited to personal data processed electronically, in whole or in part.
- Data map distinguishing personal vs sensitive personal data
- Records of processing scoped to electronic processing
- Role designations (holder/controller/processor) per processing activity
- Treating only structured databases as in-scope while ignoring electronic processing in part
- No clear controller/processor role assignment
Egypt PDPL - Direct Electronic Marketing
Electronic communication for direct marketing to a data subject is prohibited unless: the data subject's consent is obtained; the communication includes the sender's identity; the sender has a valid and complete contactable address; there is a clear indication that the purpose is direct marketing; and clear, uncomplicated opt-out/consent-withdrawal mechanisms are provided.
- Marketing consent records
- Sender identity and contact address in communications
- Functioning opt-out/withdrawal mechanism logs
- Sending marketing without prior consent
- No working opt-out mechanism
- Concealed sender identity
The sender of direct-marketing electronic communications must specify a defined marketing purpose; not disclose the data subject's contact details; and maintain electronic records evidencing the data subject's consent (or non-objection to continuity) for three years from the date of the last communication.
- Defined marketing-purpose documentation
- Three-year consent/non-objection records
- Controls preventing disclosure of contact details
- No retention of consent records for the 3-year period
- Disclosing recipients' contact details
Egypt PDPL - Disclosure of Personal Data
Where a controller, processor or holder is requested to disclose personal data it must follow set procedures: the request must be written and submitted by the relevant person or under a legal deed; the required documents granting access must be verified and retained; and the disclosure decision with supporting documents must be made within six working days of submission, with rejection reasons stated. Lapse of the period without a decision is deemed a rejection.
- Written disclosure-request intake records
- Verification and retention of access-authorising documents
- Decision log evidencing the six-working-day timeline
- Disclosing without a written, verified request
- Missing the six-working-day decision deadline
Digital evidence derived from personal data under the Law has the same determinative (evidentiary) effect as evidence derived from written data, provided it meets the criteria and technical conditions set out in the Executive Regulations.
- Controls ensuring integrity and authenticity of digital evidence
- Logging and chain-of-custody for personal-data-derived evidence
- No integrity controls to support evidentiary reliability
Egypt PDPL - Judicial Control
Centre employees appointed by decision of the Minister of Justice (on the Competent Minister's proposal) hold judicial control (law-enforcement) powers in relation to violations of the Law.
- Informational: judicial-control powers of designated Centre officers
- Obstructing designated officers exercising judicial-control powers
Egypt PDPL - Licenses, Permits and Certifications
The Centre issues Licences, Permits and Certifications, classifying their types and conditions: licences/permits for storing/handling/processing data; for direct electronic marketing; for processing by associations/unions/clubs; for visual surveillance in public places; for control and processing of sensitive personal data; permits/certifications for consultancy services; and licences/permits for cross-border transfer. Licence fees may not exceed EGP 2,000,000 and permit/certification fees EGP 500,000.
- Inventory of activities requiring a Licence/Permit/Certification
- Held Centre Licences/Permits/Certifications matching each activity
- Surveillance and sensitive-data licences where applicable
- Conducting a licensable activity (e.g. CCTV in public, marketing, sensitive data) without the matching Centre authorisation
Applications are submitted on Centre forms with supporting documents and proof of financial and technical ability. Decisions are made within 90 days of completing documentation; lapse without decision is deemed rejection. The Centre may request further data or additional protection guarantees. A controller or processor may hold more than one Licence or Permit by data type.
- Complete licence/permit applications with supporting evidence
- Proof of financial and technical capability submitted
- Records of Centre correspondence and additional-guarantee requests
- Incomplete applications causing deemed rejection
- Operating while an application is pending without authorisation
In the public interest the Centre may amend Licence or Permit conditions after issuance: in response to international, regional or national laws; upon the licensee's request; on merger of a controller/processor with others inside or outside Egypt; or where amendment is necessary to achieve the Law's objectives.
- Process to track and implement Centre-amended licence conditions
- Notifications to the Centre on mergers or material changes
- Not updating practices after the Centre amends licence conditions
- Failing to notify the Centre of a merger
The Centre may cancel a Licence, Permit or Certification for: breach of its terms; non-payment of renewal fees; repeated non-compliance with Centre decisions; assignment to a third party without Centre approval; or bankruptcy of the controller/processor by judicial ruling.
- Renewal-fee payment records
- Evidence of compliance with Centre decisions
- Controls preventing unauthorised assignment of authorisations
- Lapsed renewal payments
- Assigning a licence without Centre approval
Without prejudice to civil/criminal liability, the Centre CEO notifies a violator to stop and remedy a violation within a set period; if unremedied, the Board may issue a reasoned decision: warning of partial/total suspension; suspension of the Licence/Permit/Certification; cancellation or revocation; publication of the proven violations at the violator's cost; or subjecting the controller/processor to the Centre's technical supervision at its own cost.
- Records of Centre notices and remediation undertaken
- Remediation tracking within the period set by the Centre
- Ignoring a Centre stop-and-remedy notice
- No tracking of administrative-sanction remediation
Egypt PDPL - Personal Data Protection Centre
Establishes the Personal Data Protection Centre as a public economic authority with juristic personality, affiliated to the Competent Minister and headquartered in Cairo. The Centre's mandate covers setting policies and strategic plans; unifying protection/processing policies; issuing decisions, regulations and criteria; approving codes of conduct; issuing licences/permits/certifications; receiving complaints; advising on draft laws and international agreements; controlling and inspecting addressees; verifying cross-border transfer conditions; awareness and training; and issuing an annual report on data protection in Egypt.
- Reference to Centre guidance, decisions and codes of conduct relied upon
- Registration/notification interactions with the Centre
- Ignoring Centre guidance and codes of conduct applicable to the activity
The Centre has a Board chaired by the Competent Minister and including representatives of the Ministries of Defence and Interior, the General Intelligence Service, the Administrative Control Authority, ITIDA, the NTRA, the Centre's CEO and three appointed experts. Board membership is for renewable three-year terms; the Prime Minister issues the formation decree and sets remuneration. The Board may form committees and delegate competencies.
- Informational: composition of the Centre's Board (regulator governance)
- Not applicable to regulated entities (regulator-internal governance)
The Board is the dominant authority over the Centre's affairs and may take decisions to pursue the Centre's purposes, including adopting protection policies/plans; approving regulations, controls and standards; approving international cooperation plans; approving the organisational structure, financial/administrative/HR regulations and annual budget; approving establishment of offices/branches; and accepting grants, funds and donations.
- Informational: the Board's decision-making powers (regulator governance)
- Not applicable to regulated entities (regulator-internal governance)
The Board meets at least monthly upon the Chairman's invitation and whenever necessary; meetings are valid with a majority present; resolutions pass by a two-thirds majority of attending members; and the Chairman may invite non-voting attendees.
- Informational: Board meeting and quorum rules (regulator governance)
- Not applicable to regulated entities (regulator-internal governance)
The Centre has a CEO appointed by Prime Ministerial decree on the Competent Minister's proposal for a renewable four-year term. The CEO is responsible before the Board for the Centre's technical, administrative and financial work and represents the Centre, including supervising implementation of Board resolutions, managing the Centre, submitting periodic reports and enforcing the Centre's functions.
- Informational: the Centre CEO's role and accountability (regulator governance)
- Not applicable to regulated entities (regulator-internal governance)
Board members and Centre employees are prohibited from disclosing documents or data relating to cases monitored or examined by the Centre, or submitted/circulated during examination or decision-making; this obligation survives the end of the relationship with the Centre. Such information may only be disclosed to investigating and judicial authorities.
- Informational: confidentiality duties binding the regulator's personnel
- Not applicable to regulated entities (regulator-internal duty)
The Centre may, in coordination with competent authorities, cooperate with foreign counterparts within international, regional and bilateral cooperation agreements, ratified protocols or reciprocity, to protect personal data and verify compliance by controllers/processors outside Egypt, exchanging data while ensuring its protection and assisting investigation of violations.
- Informational: the Centre's cross-border cooperation mandate
- Assuming offshore processing escapes oversight despite Centre cooperation channels
Egypt PDPL - Requests and Complaints
A data subject or relevant person may submit a request to any holder, controller or processor to exercise their rights under the Law, and the holder/controller/processor must reply within six working days of submission.
- Request intake and response procedure meeting the six-working-day deadline
- Logs of rights requests and responses
- Missing the six-working-day response deadline
- No request-handling procedure
Without prejudice to judicial proceedings, a data subject or relevant person may complain to the Centre for: infringement/breach of the right to data protection; failure to enable exercise of rights; or decisions of the DPO of the processor/controller on submitted requests. The Centre investigates and decides within 30 working days and notifies both parties; the respondent must execute the decision within seven working days and notify the Centre.
- Procedure to respond to Centre complaint investigations
- Evidence of executing Centre decisions within seven working days
- Failing to execute a Centre decision in time
- No process to handle escalated complaints
Egypt PDPL - Sensitive Personal Data
Controllers and processors are prohibited from collecting, transferring, storing, processing or disclosing sensitive personal data except under a licence from the Centre, and (save where authorised by law) must obtain the data subject's explicit written consent. Processing children's data requires the legal guardian's consent, and a child's participation in a game, competition or activity may not be conditioned on submitting more personal data than necessary for participation.
- Centre licence covering sensitive personal data
- Explicit written consent records for sensitive data
- Guardian consent records for children's data
- Data minimisation controls for children's services
- Processing sensitive data without a Centre licence
- No explicit written consent for sensitive data
- No guardian-consent mechanism for children
In addition to the Article 9 obligations, the DPO of the controller or processor must follow and implement the security policies and procedures necessary to avoid any breach or infringement of sensitive personal data.
- Enhanced security policy for sensitive data
- Evidence of DPO oversight of sensitive-data safeguards
- No differentiated safeguards for sensitive data
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Egypt Personal Data Protection Law (Law No. 151 of 2020) framework page.