Egypt’s Personal Data Protection Law, No. 151 of 2020 (“PDPL”) and its Executive Regulation issued by virtue of Decree No 816 of 2025 serve as the primary legislation governing data privacy and protection by private sector entities and certain public sector entities that process personal data for non-sovereign activities. They outline fundamental principles of data processing, including:
- Lawfulness and transparency;
- Purpose limitation;
- Data minimisation;
- Accuracy;
- Storage limitation; and
- Confidentiality and security.
Additionally, PDPL covers both automated and non-automated processing of personal data and applies to data controllers and processors, whether they are based in Egypt or processing the data of individuals in Egypt from outside Egypt.
Entities addressed by the provisions of PDPL must comply with its provisions from 1 November 2026.
Relationship with GDPR
Egypt’s PDPL is inspired by the European Union’s General Data Protection Regulation (“GDPR”) and adopts key principles like privacy rights, consent requirements and data security rules. However, PDPL introduces stricter, more centralised provisions, namely:
- Strong governmental control;
- Criminal penalties for some violations; and
- Restrictions on legal bases for processing, emphasising explicit consent.
Key Differences between PDPL & GDPR
The notable differences are shown in the following table:
| Scope | PDPL | GDPR |
| Legal basis for processing data | Primarily requires explicit consent from individuals, in addition to limited exceptions as legal obligations or contractual necessity. | Processing is done on multiple legal bases, such as consent, contractual necessity, legal obligations, legitimate interest, vital interest, and public interest. |
| Appointment of a data protection officer | Required for any juridical entity. | Required for public entities that process large-scale sensitive or special-category data. |
| Cross-border data transfers | Should only be transferred abroad in the event that: I) the receiving state has adequate data protection laws; II) the Egyptian Data Protection Center approves the transfer; and III) the data subject gives explicit consent. (There is an exception) | Free transfer of data within the EU states. For non-EU states, data should be transferred in the event that the state has an adequacy decision, or in the event that companies use standard contractual clauses or binding corporate rules. |
| Data breach notification | Notify the Egyptian Data Protection Center within seventy-two (72) hours in the event that a data breach occurs and immediately if related to national security protection. | Notify the Data Protection Authority within seventy-two (72) hours in the event that the breach poses a risk to individuals’ rights. |
| Penalties | Fines range from EGP 50,000 to EGP 5 million. In some cases, criminal penalties (including impris- onment). | Fines of up to €20 million or 4% of global annual turnover, whichever is higher, in addition to penalties at the national level. |
For more information and updates, contact the author of this article, Amir Marghany from Marghany Advocates, the LEX Africa member for Egypt, on Amir@Marghany.com or visit https://www.marghany.com/




