← Back to list

Understanding Egypt’s PDPL in the Context of Global Data Protection Standards

Egypt’s Personal Data Protection Law was enacted on 15 July 2020 and took effect on 16 October 2020, marking place for data privacy in…

Tsaaro Consulting · 2025-06-26 14:45 · 0 claps · 3.3 min read
#pdpl #data-privacy #data-protection #must #read
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity ⚖️ · Law & Justice

Understanding Egypt’s PDPL in the Context of Global Data Protection Standards

Egypt’s Personal Data Protection Law was enacted on 15 July 2020 and took effect on 16 October 2020, marking place for data privacy in Egypt. The PDPL creates an all-inclusive framework for protecting personal data in both the public and private sectors. It generally prohibits processing personal data without the data subject’s explicit consent and grants individual’s rights to control their information.

The PDPL aims to regulate the collection, processing, storage, and transfer of personal data within Egypt. It applies to businesses, government agencies, and foreign entities that process data related to Egyptian citizens. The law introduces several obligations for businesses, grants new rights to individuals, and imposes strict penalties for non-compliance.

I. Legal and Regulatory Framework of PDPL

The PDPL is the core of Egypt’s data protection. It applies broadly to any e-processing of personal data by controllers or processors inside or outside Egypt involving Egyptian data subjects. The law distinguishes personal data i.e., any information relating to an identified or identifiable natural person and sensitive data like health, financial, biometric, religious or political information. The PDPL creates a new regulator, the Personal Data Protection Centre as a public authority under the Ministry of Communications and Information Technology to enforce the law. The PDPC will issue licenses, decrees, and guidelines, unify privacy policies, handle complaints, and coordinate with other agencies and international bodies on data protection.

Despite creating a unified framework, the PDPL sits atop several sector-specific laws that add privacy protections in crucial areas. For instance, the Telecommunications Law mandates that licensed operators protect the confidentiality of customer communications and private calls, effectively reinforcing PDPL safeguards for telecom data. Similarly, the legislation on cyber-crimes known as , Anti-Cyber and Information Technology Crimes imposes obligations on online service providers to keep logs for 180 days, secure user data, and only disclose information with judicial authorization. Egypt’s Penal Code criminalizes unlawful interception or disclosure of personal information, and the e-Signature Law requires secure systems to protect users’ personal data in digital signature services. Other regulations, from The National Telecom Regulatory Authority licensing rules to consumer-protection laws, further support data privacy in contexts like e-commerce and broadcasting.

II. Rights Under the PDPL

  1. Right to be informed & Right to know- Individuals must be told why their data is collected and how it will be used. Controllers must notify data subjects if any personal data breach occurs that affects them.
  2. Right of access- Data subjects can request and obtain a copy of any of their personal data held by a controller or processor.
  3. Right to correction and deletion- If personal data is inaccurate or no longer needed, individuals may demand that it be corrected, updated or erased, also called right to be forgotten.
  4. Right to restrict processing- Data subjects can limit processing to a specific purpose, or object entirely if processing would infringe on their rights and freedoms.
  5. Right to withdraw consent- Consent is revocable at any time, the law explicitly guarantees the right to withdraw prior consent to data processing.
  6. Right to data portability- The PDPL provides that citizens may obtain and reuse their data across services.

III. Organizational Obligations, Ensuring Compliance

You May Also Like this: Navigating Consent: What Egyptian Businesses Need to Know About Data Subject Consent Under the PDPL

Similar to GDPR as well as DPDP-

  1. Data Protection Officer (DPO)- Every controller and processor must appoint an internal DPO and register them with the PDPC. The DPO acts as liaison with the regulator, oversees compliance, updates records of processing, and ensures data subject requests are handled.
  2. Data Security- Entities must adopt appropriate technical and organizational measures to protect personal data. This means ensuring accuracy, confidentiality and integrity of data through encryption, access controls, secure storage and so on. The law expressly forbids excessive retention not for longer than necessary, and requires prompt correction of errors upon discovery.
  3. Consent Management- As consent is the default legal basis, controllers must obtain clear, explicit consent before processing personal data with limited exceptions. Consent must be specific and documented for sensitive data, written consent is required.
  4. Breach Notification- Controllers and processors must notify the PDPC of any personal data breach within 72 hours of becoming aware of it. The notification must describe the breach’s nature, scope, DPO details, consequences and mitigation steps. If the breach affects national security, immediate notification is required. Within 3 days of notifying the PDPC, the entity must also inform affected individuals of the breach and planned remedies.
  5. Records and Accountability- Appointing an experienced DPO and building a compliance blueprint including security audits, employee training and updated privacy notices are essential first steps. While the PDPL does not explicitly require a data protection impact assessment, the spirit of the law implies that high-risk processing should be assessed and justified before launch.

Read Full Blog Here — Understanding Egypt’s PDPL in the Context of Global Data Protection Standards


메타데이터
post_id
be4c632fd5cd
slug
understanding-egypts-pdpl-in-the-context-of-global-data-protection-standards-be4c632fd5cd
url
https://medium.com/@tsaaro-consulting/understanding-egypts-pdpl-in-the-context-of-global-data-protection-standards-be4c632fd5cd
canonical_url
https://medium.com/@tsaaro-consulting/understanding-egypts-pdpl-in-the-context-of-global-data-protection-standards-be4c632fd5cd
author_url
https://medium.com/@tsaaro-consulting
status
ok
fetched_at
2026-06-20 20:29:01