Platform AI governance Coverage Pricing Partners Sign in
Free readiness checkTalk to us
HomePrivacy laws › Egypt
Privacy law · Africa

🇪🇬 PDPL 151/2020 in Egypt

Egypt's Personal Data Protection Law (Law No. 151 of 2020) is a comprehensive regime requiring consent or another lawful basis, licensing for certain activities, and safeguards for cross-border transfers.

Verified - legal review completed
PDPL 151/2020
Governing framework
Personal Data Protection Center
Supervisory authority
11
Controls this market requires
18
Required or strongly expected

What PDPL 151/2020 expects of you

22 of our 22 tracked controls apply in Egypt, graded by how firmly the law requires each one.

Required mandated by law Expected near-mandatory Prudent advisable Optional emerging
RecordsRequired

Records of processing (RoPA)

A living inventory of what personal data you hold, why, where it sits and where it flows.

Closes with: Records of Processing register
Lawful basisRequired

Lawful basis mapping

A valid legal reason for each use of personal data, mapped per activity.

Closes with: Lawful-basis mapping
ConsentRequired

Consent - specific, logged, withdrawable

Where you rely on consent it is freely given, specific, informed, unbundled and withdrawable, with a record.

Closes with: Consent notice + consent-record schema
TransparencyRequired

Privacy notice / transparency

A published, current privacy notice giving the prescribed information.

Closes with: Public privacy notice (per-market)
RightsRequired

Individual rights handling

Ability to find, correct and delete one person's data on request within the legal deadline.

Closes with: Rights-request procedure
Cross-borderRequired

Cross-border transfer mechanism

Every export of personal data is covered by a lawful transfer mechanism.

Closes with: Data-flow map + transfer pack (SCCs/TRA/adequacy)
SecurityRequired

Security controls (TOMs)

Encryption in transit and at rest, least-privilege access, and access logging.

Closes with: Security controls statement (TOMs)
BreachRequired

Breach detection & notification

A written breach plan and knowledge of each market's notification clock.

Closes with: Breach response plan + per-market templates
VendorsRequired

Vendor / processor agreements

DPAs with vendors handling your data, with controller/processor roles defined.

Closes with: Processor agreement template + role allocation
RegistrationRequired

Authority registration / filing

Registration or filing with the DPA where the market requires it.

Closes with: Registration pack (per market)
RepresentativeRequired

Local representative appointment

A local/EU representative where you have no establishment in a market that requires one.

Closes with: Representative appointment letter
GovernanceExpected

Accountable privacy owner / DPO

A named person or role accountable for data protection, with published contact where required.

Closes with: DPO / privacy-owner appointment letter
RetentionExpected

Retention & deletion schedule

Defined, enforced retention periods and deletion, balancing storage-limitation and legal keep-periods.

Closes with: Retention schedule + deletion runbook
ChildrenExpected

Children's-data safeguards

Age assurance and verifiable parental consent; no behavioural tracking of children.

Closes with: Children's-data procedure + age-gating
SensitiveExpected

Sensitive / special-category data

Explicit consent, tighter access, and often a DPIA for special-category data.

Closes with: Sensitive-data policy + DPIA where required
MarketingExpected

Direct-marketing consent

Lawful basis/consent for e-marketing and an unsubscribe route.

Closes with: Marketing consent + suppression list
DPIAExpected

Impact assessment / dossier

A DPIA/impact assessment for high-risk processing; some markets require a filed dossier.

Closes with: DPIA / transfer-impact assessment
PaymentsExpected

PCI / payment-card handling

Card data offloaded to a compliant processor; PCI-DSS scope controlled.

Closes with: PCI-DSS scope note + card-handling policy
GrievancePrudent

Grievance / complaints channel

A published route to raise a privacy complaint; India requires a grievance officer.

Closes with: Grievance / complaint notice
ePrivacyPrudent

Cookies / e-privacy consent

Cookie/tracker consent and an accurate cookie policy where required (esp. EU/UK).

Closes with: Cookie policy + consent banner
ADM/AIPrudent

Automated decisions / profiling

Safeguards and transparency for automated decision-making and profiling.

Closes with: ADM transparency + safeguards note
LocalisationOptional

Data localisation / residency

Local storage/residency requirements for certain data or sectors.

Closes with: Data-residency design note

Get Egypt-ready without the guesswork

Answer a few questions and PrivMatrix shows you exactly where you stand against PDPL 151/2020, then generates the policies, notices and registers that close each gap - written for Egypt.

Other markets

See all 28 →
🇦🇪 UAE🇸🇦 Saudi Arabia🇶🇦 Qatar🇧🇭 Bahrain🇴🇲 Oman🇰🇼 Kuwait🇹🇷 Turkey🇪🇺 EU / UK