Egypt’s Data Protection Law Finally Has Operating Rules. The Clock Ends in November 2026.
Egypt’s Personal Data Protection Law was enacted in 2020, but many of its practical mechanisms depended on executive regulations. Decision No. 816 of 2025 finally supplied them and started a compliance period ending in November 2026.
The regulations were published on 1 November 2025 and entered into force the following day. They provide procedures for licensing and permits, security, breach reporting, cross-border transfers, direct marketing and regulatory oversight by the Personal Data Protection Center.
This is the moment when a framework law becomes an operating regime. Organisations cannot wait for the November 2026 deadline to discover whether their data inventory, representative, licences and incident process exist.
Processing now has an authorisation workflow
The regulations establish differentiated licences, permits and approvals for controllers and processors and for specific activities. Applications require information about processing, data categories, security, retention and compliance capability.
A licence is not a substitute for governance. It forces governance to become visible. The declared processing model, security controls and retention periods must match what systems and suppliers actually do after approval.
Foreign providers need a local compliance path
Foreign controllers and processors within scope may need a representative in Egypt. The regulations specify representative arrangements and make local accountability part of the licensing structure.
International service providers should identify the contracting entity, processing role, Egyptian users and local representative before filing. An informal reseller relationship may not satisfy a statutory representation duty.
A breach triggers a 72-hour notification
Controllers and processors must notify the Center within 72 hours of becoming aware of a personal-data breach or violation through the designated electronic channel. The record must cover awareness and reporting times, nature and timing, affected records, expected harm, urgent measures and the data protection contact.
The affected person must then be notified within three days of the Center notification using the agreed communication method. Incident teams need to coordinate the two clocks and avoid waiting for a final forensic report.
Cross-border transfers are licensed architecture
The regulations require a licence or permit for covered transfers outside Egypt and demand information about the destination, purpose, volume, retention, security, storage locations and protection level. The Center may take up to 90 business days after receiving a complete application, and no response is treated as rejection.
This makes late discovery expensive. A new cloud region, support centre or analytics provider can create a regulatory lead time that procurement schedules often ignore.
The November 2026 deadline is an implementation deadline
The statutory one-year period runs to 1 November 2026. By then, organisations need more than a project plan. Relevant processing should be regularised, applications prepared or completed, representatives appointed and security evidence available.
What organisations should do now
- Inventory Egyptian processing and assign controller or processor roles.
- Identify required licences, permits, approvals and local representation.
- Map every cross-border transfer, storage location and onward recipient.
- Build a 72-hour Center notification and three-day individual communication process.
- Document retention, deletion and security controls for inspection.
- Work backward from 1 November 2026, including regulator processing time.
The missing machinery has arrived
Egypt’s privacy law is no longer waiting for its operating instructions. The organisations most exposed are those that treated the delay as permission to postpone data mapping. Licensing, transfer and incident requirements all depend on knowing the data system in detail.
Official sources
- Egypt Personal Data Protection Center
- PDPC guidance referencing Law No. 151 of 2020 and Decision No. 816 of 2025
- English translation of Ministerial Decision No. 816 of 2025
This article provides general information and is not legal advice.
Continue the series: Africa Cyber & Digital Law Series index


