Worldwide Locations:

PDPL Compliance Lawyers in Egypt

PDPL Compliance Lawyers in Egypt help businesses meet data protection requirements, prepare compliance documents, and register DPOs.

Egypt’s Personal Data Protection Law No. 151 of 2020 (PDPL) and Executive Regulations No. 816 of 2025 regulate the processing and protection of electronic personal data. Andersen in Egypt helps local and international businesses prepare compliance documentation, review data protection practices, support DPO appointment and registration, and communicate with the Personal Data Protection Center (PDPC).
PDPL Compliance Lawyers in Egypt​

PDPL Compliance Framework in Egypt

The Egyptian PDPL regulates the electronic processing of personal data and sets obligations for controllers, processors, data holders, and other persons involved in handling personal data. With the establishment of the Personal Data Protection Center (PDPC) and the issuance of the Executive Regulations in 2025, organizations operating in Egypt are now expected to assess their compliance at both a legal and operational level.

  • Regulatory Compliance: The PDPC supervises and enforces the PDPL, including DPO registration, licenses and permits, complaints, inspections, and other regulatory matters.
  • Documentation and Governance: Businesses should maintain appropriate privacy notices, policies, processing records, consent documentation, contracts, DPO arrangements, and other records demonstrating compliance
  • Data Handling and Security: Organizations should review how personal data is collected, used, stored, shared, retained, transferred, secured, and deleted, while maintaining procedures for data subject requests and personal data breaches.
  • Regulatory Readiness: Companies should assess whether their activities require PDPC approvals, registrations, licenses, or permits and ensure their compliance framework is aligned with the PDPL and its Executive Regulations.
PDPL Compliance Framework in Egypt

Preparation of Data Protection Compliance Documents

PDPL Documents Section — Preview
PDPL Compliance Documentation

We prepare and review the legal documents required to support your company's PDPL compliance program. The documents required depend on your organization, processing activities, categories of personal data, and regulatory obligations.

01
DATA

Data Mapping & Records

  • Personal Data Inventories
  • Data Maps
  • Records of Processing Activities
  • Processing Registers
  • Internal Accountability Records
02
PRIVACY

Privacy & Data Subject Documents

  • Privacy Notices
  • Consent Forms
  • Consent Management Documentation
  • Data Subject Rights Procedures
  • Data Subject Request Registers
03
GOVERNANCE

Policies & Internal Governance

  • Data Protection & Privacy Policies
  • Data Retention & Deletion Policies
  • DPO Appointment Documents
  • DPO Governance Documentation
  • Employee Awareness Materials
04
CONTRACTS

Contracts & Third Parties

  • Data Processing Agreements
  • Controller-Processor Agreements
  • Vendor Data Protection Clauses
  • Employee Confidentiality Obligations
  • Third-Party Data Protection Terms
05
RISK

Risk, Security & Breach Response

  • Data Protection Impact Assessments
  • Legitimate Interest Assessments
  • Personal Data Breach Procedures
  • Personal Data Breach Registers
  • Sensitive & Children's Data Procedures
06
TRANSFER

Transfers & Marketing

  • Cross-Border Transfer Documentation
  • Data Transfer Assessments
  • Direct Electronic Marketing Documents
  • Compliance Checklists
  • Related Regulatory Documentation
Tailored to Your Operations

The precise documentation required should reflect the company's actual processing activities rather than relying on generic privacy templates. A well-structured PDPL compliance framework should address processing records, privacy documentation, risk assessments, breach management, data subject procedures, DPO governance, and employee awareness.

Privacy Notices Under the Egyptian PDPL

PDPL Privacy Notice — Section Preview
PDPL · Transparency Requirement

The Egyptian Data Protection Center's Privacy Notice Guidelines require a distinct, standalone notice at the point personal data is collected, disclosing eleven specific matters, issued in Arabic as the primary language of record.

What the notice must disclose

  1. a

    Identity & contact

    Who the data user is, and how a data subject can reach them.

  2. b

    DPO contact

    Direct contact details for the Data Protection Officer.

  3. c

    Categories of data

    What personal data is collected, described by category.

  4. d

    Which PDPL ground justifies each processing activity.

  5. e

    Purposes of processing

    What the data is used for, stated specifically, not broadly.

  6. f

    Recipients

    Who receives the data, or the categories of parties it's shared with.

  7. g

    Cross-border transfers

    Where data leaves Egypt, and under what safeguard, where applicable.

  8. h

    Retention

    How long data is kept, or the criteria used to decide that.

  9. i

    Data subject rights

    Access, correction and erasure, and how to exercise each one.

  10. j

    Source of indirect data

    Where the data came from, when it wasn't collected directly.

  11. k

    Right to complain

    How to lodge a complaint with the Egyptian Data Protection Center.

العربية أولاً Arabic, first

The Egyptian Data Protection Center requires the notice in Arabic as the primary language. Additional languages can be layered in depending on the audience, but Arabic is never the optional one.

Andersen in Egypt builds each one separately, mapped to your real processing operations, so none of the three is left doing the other's job.

Talk to our PDPL attorneys

DPO Appointment and Registration in Egypt

DPO Appointment & Registration — Redesigned

Every juridical data user must appoint a DPO under the Egyptian Data Protection Center's guidance, irrespective of the scale of their processing. The appointee, whether an internal employee or an external provider, isn't recognized as a registered DPO until entered in the Egyptian Data Protection Center's Data Protection Officers' Registry.

Andersen in Egypt handles the registration file end to end, not just the appointment paperwork.

Five-step registration path

From eligibility to the Egyptian Data Protection Center registry.

1

Eligibility review

Confirming who in the business can serve as DPO, and whether an internal or external appointment fits better.

2

Corporate documentation

Preparing the internal resolutions and records the registration file requires.

3

Registration file

Assembling and submitting the file to the Egyptian Data Protection Center's Data Protection Officers' Registry.

4

Appointment declaration

Drafting the formal declaration that names the DPO and defines their role.

5

Independence safeguards

Advising on the reporting lines and organizational arrangements that preserve the DPO's independence.

Documents Required for DPO Registration

DPO Registration Requirements Section — Preview
DPO Registration File

Under current Personal Data Protection Center guidance and the Executive Regulations, a DPO registration application may require the following documents. What applies to a given applicant depends on their individual circumstances.

FORM DPO · 01

Identity document

National ID for an Egyptian applicant, or a passport for a foreign applicant.

FORM DPO · 02

Personal photograph

A recent photograph of the applicant, for the registration file.

FORM DPO · 03

Academic & professional credentials

Evidence of the qualifications relevant to serving as DPO.

FORM DPO · 04

Practical experience

Evidence of relevant hands-on experience in data protection.

FORM DPO · 05

Criminal record certificate

Foreign-issued certificates may require certification or authentication.

FORM DPO · 06

PDPC examination certificate

Proof of having successfully completed the applicable PDPC examination.

FORM DPO · 07

Existing DPO Code

Where the applicant already holds one, from a prior registration.

FORM DPO · 08

Application & registration fees

The applicable fees set for the registration application.

Filed through the Egyptian Personal Data Protection Center portal

The applicant submits the registration application through the Egyptian Personal Data Protection Center's electronic portal. Upon successful registration, the DPO receives a unique identification number — the DPO Code.

Portal submission Application filed
PDPC decision 30 working days
If info is requested 15 days after completion
On approval DPO Code issued

Business Obligations Under the Egyptian PDPL

Key PDPL Compliance Areas Section — Preview

DPO Responsibilities

The compliance framework's day-to-day owner

The Data Protection Officer oversees the organization's compliance framework, including Records of Processing Activities, privacy policies, risk assessments, security measures, employee training, breach procedures, and data subject rights. The DPO also acts as a contact point for data subjects and the PDPC, and supports regulatory reporting, including breach notifications and periodic compliance reporting.

PDPC Licenses & Permits

Required depending on activity, status, and volume

Depending on the organization's activities, legal status, and the nature and volume of personal data processed, licenses or permits from the PDPC may be required. Applications may involve corporate information, processing activities, sensitive data, retention periods, security measures, DPO details, consent mechanisms, technical infrastructure, and other supporting documentation.

Cross-Border Personal Data Transfers

Cloud, overseas vendors, and regional HQs all count

Businesses using international cloud providers, overseas service providers, regional headquarters, or global HR and customer-management systems should assess whether personal data is transferred outside Egypt. Compliance may require reviewing the destination country, purpose of transfer, categories and volume of data, retention periods, security safeguards, and applicable PDPC approvals.

Controller & Processor Compliance

The label changes what has to be documented

Organizations should determine whether they act as a controller, processor, or both for each processing activity. Appropriate records and contracts should document processing instructions, categories of personal data, processing periods, security measures, DPO information, and relevant international transfers. Existing vendor, outsourcing, cloud, and service agreements may also require PDPL-specific provisions.

Data Subject Rights

A procedure, with someone accountable for it

Companies should maintain procedures for receiving, verifying, evaluating, documenting, and responding to requests involving access, correction, deletion, withdrawal of consent, restriction, objection, and other rights available under the PDPL. These procedures should clearly identify responsible personnel, escalation channels, response records, and DPO oversight.

Personal Data Breaches

The response process has to exist before the incident

Organizations should establish a documented breach-response process before an incident occurs. Where the applicable reporting requirements are triggered, the PDPC must be notified within 72 hours of awareness of the breach. Organizations should also maintain a secure breach record documenting the incident, affected data, potential consequences, corrective actions, and DPO involvement. Notification to affected data subjects may also be required in applicable circumstances.

Electronic Direct Marketing

Every channel, one set of requirements

Businesses using email, SMS, calls, social media, or other electronic marketing channels should review their compliance with consent, opt-out, sender-identification, record-keeping, and licensing requirements. Consent and withdrawal records should be maintained in accordance with applicable PDPC requirements.

Andersen in Egypt covers all seven areas, not just one

We review existing practices, prepare the required documentation, assess regulatory and contractual requirements, and support applications, registrations, and notifications with the PDPC.

Talk to our PDPL attorneys

A Practical PDPL Compliance Roadmap

PDPL Implementation Roadmap Section — Preview
Start

Identify the entities, operations, and processing activities within PDPL scope, and whether each acts as a controller, processor, or both.

1
2

Map personal data

What's collected, where it originates, why it's processed, where it's stored, who receives it, how long it's kept, and whether it leaves Egypt.

Determine the legal basis for each activity, and how consent is requested, obtained, recorded, withdrawn, and retained.

3
4

Conduct a PDPL gap assessment

Compare existing practices against the PDPL, Executive Regulations, and PDPC guidance to find what's missing.

Prepare the compliance documentation

Develop the notices, policies, registers, agreements, procedures, assessments, and governance documents required.

5
6

Appoint & register the DPO

Identify a suitable DPO, prepare the registration file, complete the PDPC process, and document appointment and independence.

Assess PDPC licensing & permits

Determine whether a controller or processor license, permit, or additional approval is required — including for transfers or marketing.

7
8

Implement the compliance program

Roll the approved documents and procedures out across HR, IT, marketing, sales, procurement, and customer service.

Train relevant employees

Make sure staff understand the rules for their role — collection, disclosures, data subject requests, incidents, retention, escalation.

9
10

Maintain ongoing compliance

Not a one-time filing — records, notices, contracts, DPO arrangements, and data flows get reviewed and updated as the business changes.

Ongoing — review & repeat

Frequently Asked Questions​

FAQ – PDPL Compliance Lawyers in Egypt

What is the Egyptian PDPL?

The Personal Data Protection Law No. 151 of 2020 is Egypt's principal legislation regulating the processing of electronic personal data. It is supplemented by Executive Regulations No. 816 of 2025 and regulatory guidance issued by the Personal Data Protection Center.

What is the Personal Data Protection Center?

The Personal Data Protection Center, or PDPC, is Egypt's national authority responsible for regulating and enforcing the PDPL. Its responsibilities include DPO registration, licenses and permits, complaints, inspections, compliance supervision, guidance, and other regulatory functions.

Who must comply with the PDPL in Egypt?

The PDPL can apply to controllers, processors, data holders, and other persons processing electronic personal data falling within its territorial and material scope. Businesses should assess their specific operations rather than assuming that the law applies only to technology companies.

Does the PDPL apply to foreign companies?

Potentially, yes. The PDPL has provisions extending beyond purely Egyptian entities, and foreign controllers or processors handling personal data within the law's scope may have Egyptian compliance requirements. The Executive Regulations also contemplate representatives in Egypt for certain controllers and processors established outside the country.

What types of personal data are covered?

Personal data generally includes information relating to an identified or identifiable natural person. Additional requirements may apply when an organization handles sensitive personal data or children's data.

Is having a privacy policy enough for PDPL compliance?

No. A privacy policy is only one part of a broader compliance framework. Depending on the organization, compliance may also involve data mapping, processing records, privacy notices, contracts, consent records, DPO appointment and registration, data subject procedures, security measures, breach procedures, licenses, permits, and cross-border transfer requirements.

What is the current PDPL compliance deadline?

The PDPL provided persons subject to the law with a one-year period following issuance of the Executive Regulations to reconcile their position with the new framework. The Executive Regulations were issued in November 2025, and the transition period is generally regarded as expiring on 1 November 2026. Organizations should confirm the current PDPC position and any subsequent implementation measures when taking action.

How can PDPL Compliance Lawyers in Egypt help a business?

Lawyers can determine the company's regulatory position, conduct a compliance assessment, prepare required documentation, advise on data-processing contracts, assist with DPO registration, identify applicable PDPC licenses or permits, advise on cross-border transfers, and provide support during breaches or regulatory interactions.

Does a company in Egypt have to appoint a DPO?

Current PDPC guidance states that juridical persons acting as data users must appoint a Data Protection Officer irrespective of the scale of their processing activities.

Does the DPO need to be registered with the PDPC?

Yes. The PDPC has established a Data Protection Officers' Registry, and a DPO must be registered in that registry to be recognized as such under the current regulatory framework.

What documents are required to register a DPO?

The current requirements include identification documentation, a recent photograph, evidence of qualifications and relevant experience, a criminal record certificate, proof of passing the relevant PDPC examination, and other information applicable to the applicant's circumstances.

How is a DPO registration application submitted?

Current PDPC guidance provides that the DPO applicant submits the registration application through the PDPC's electronic portal.

How long does DPO registration take?

Where a complete application has been submitted, current guidance provides for the PDPC to determine the registration application within 30 working days. If additional information is requested, a further 15-day determination period applies after the application has been completed.

What is a DPO Code?

Following successful registration, the DPO receives a unique identification number known as the DPO Code. The code is linked to the DPO's registration and applicable category.

Can the DPO be an external service provider?

Yes. Current PDPC guidance allows the DPO to be an internal employee or an external service provider, subject to the applicable registration, appointment, independence, category, and conflict-of-interest requirements.

Can one DPO serve more than one company?

Current PDPC guidance recognizes shared DPO arrangements, including in some group and unrelated-company situations, subject to applicable requirements, the absence of conflicts, and PDPC approval where required.

What are the main responsibilities of a DPO?

The DPO oversees compliance, supports the organization's privacy program, monitors processing records and policies, advises on risk assessments and security measures, oversees data subject request processes, acts as a contact point for data subjects, and communicates with the PDPC.

Can Andersen assist with DPO registration?

Yes. Andersen can assist with reviewing DPO eligibility, preparing and reviewing the registration documentation, advising on the application process, preparing appointment documentation, and supporting the client in complying with the organizational requirements associated with the DPO role.

What PDPL compliance documents should a company prepare?

The appropriate documentation depends on the company's activities but may include data maps, processing records, privacy notices, internal policies, consent records, data subject request procedures, retention schedules, data processing agreements, breach procedures, transfer documentation, DPO documentation, and compliance assessments.

Is a privacy notice required under the PDPL?

The PDPC states that data users must provide an appropriate privacy notice when collecting and processing personal data. The content must explain essential information concerning the processing activity.

Does the privacy notice need to be in Arabic?

Current PDPC guidance states that Arabic must be the primary language of the privacy notice. Additional languages may be provided depending on the intended audience.

What information should a privacy notice contain?

Among other matters, it should identify the data user, DPO contact details, categories of data, legal basis, processing purposes, recipients, relevant international transfers, retention, data subject rights, and the right to complain to the PDPC.

What is a Record of Processing Activities?

A Record of Processing Activities, commonly referred to as a ROPA or processing register, documents how personal data is processed within the organization. It can serve as an important accountability and compliance record and should reflect actual operations rather than generic descriptions.

Where consent is relied upon, organizations should be capable of demonstrating how and when valid consent was obtained and of processing withdrawals appropriately. Specific record-keeping requirements also apply in areas such as electronic direct marketing.

Do processor contracts need to address data protection?

Processor relationships should be appropriately documented. The Executive Regulations contemplate processing contracts and require processors to maintain information regarding the processing relationship, relevant controller information, security arrangements, and processing activities.

Does a company need a data retention policy?

Organizations should establish clear retention periods or criteria and procedures for deleting personal data when it is no longer required, subject to applicable legal retention obligations.

When should a company conduct a DPIA?

A Data Protection Impact Assessment can be an important risk-management tool where processing presents elevated privacy risks. The PDPC's DPO guidance expressly identifies DPIAs among the risk assessments a DPO may review and advise upon.

Does a company need a PDPC license or permit?

Potentially. The Executive Regulations establish licenses and permits for controllers, processors, and certain specified processing activities. The applicable requirement depends on the organization, its activities, its legal form, and the nature and volume of data processed.

What information may be required for a PDPC license or permit?

For legal entities, application information can include corporate records, organizational structure, the nature and volume of personal data, sensitive-data identification, retention periods, storage arrangements, security procedures, deletion mechanisms, the DPO, consent mechanisms, technical infrastructure, and relevant certifications.

Do cross-border transfers require additional attention?

Yes. Sending personal data outside Egypt can trigger specific PDPL requirements and licensing or permitting considerations. Companies using foreign cloud providers, overseas group companies, regional systems, or international service providers should map these transfers.

What information is relevant to a cross-border transfer application?

The Executive Regulations contemplate information such as the destination, purpose of transfer, categories and volume of data, retention period, security systems, storage locations, data-flow arrangements, and safeguards used to protect the information.

Do electronic marketing activities require PDPL compliance?

Yes. Direct electronic marketing is specifically regulated. Requirements can include valid consent, opt-out mechanisms, sender identification, record keeping, and applicable licensing or permitting requirements.

Does the PDPL regulate sensitive personal data?

Yes. Sensitive personal data is subject to additional protections and organizations processing such data should specifically review the applicable compliance and regulatory requirements.

How quickly must a personal data breach be reported to the PDPC?

The Executive Regulations provide for notification to the PDPC within 72 hours after the controller or processor becomes aware of a personal data breach or violation falling within the reporting obligation.

What information should be recorded about a data breach?

The organization's secure breach record should include information such as when the incident became known, the nature and timing of the breach, the approximate affected records, potential consequences, remedial actions, and DPO information.

Must affected individuals also be notified?

The Executive Regulations provide for notification of affected data subjects within three business days following notification to the PDPC in applicable circumstances.

What rights do data subjects have?

Depending on the applicable circumstances, data subjects may have rights concerning access to their personal data, correction, deletion, withdrawal of consent, restriction or objection to processing, and information about how their personal data is handled.

Can individuals complain directly to the PDPC?

Yes. Receiving and investigating complaints from data subjects forms part of the PDPC's statutory compliance and enforcement functions.

Can the PDPC inspect a company?

Yes. The PDPC's mandate includes inspection and supervision of compliance with the PDPL and its Executive Regulations.

What are the consequences of non-compliance with the PDPL?

The PDPL establishes criminal and financial consequences for specified violations, and the regulatory framework also allows for compliance supervision, inspections, and other enforcement measures. The potential exposure depends on the particular breach and applicable provision.

Is PDPL compliance a one-time project?

No. Organizations should maintain and update their processing records, privacy notices, contracts, consent mechanisms, DPO arrangements, security procedures, transfer arrangements, and regulatory authorizations as their operations evolve.

Does the DPO have ongoing reporting obligations?

Yes. Current PDPC guidance states that the DPO acts as the organization's regulatory contact and is responsible for matters including breach notifications and submitting annual reports to the PDPC concerning the organization's personal data protection compliance status.

When should a business speak to PDPL Compliance Lawyers in Egypt?

Businesses should seek advice when preparing for PDPL compliance, appointing or registering a DPO, preparing compliance documentation, applying for licenses or permits, transferring personal data internationally, introducing new data-intensive products or technologies, responding to data-subject requests, or managing a personal data breach.

Contact Us

Services Form
Newsletter

Andersen, law & tax firm