Egypt PDPL
Personal Data Protection Law (Law No. 151 of 2020)
Comprehensive data protection law regulating personal data processing in Egypt. Requires parental consent for children under 15, mandatory Data Protection Officer appointment, and 72-hour breach notification.
Jurisdiction
Egypt
EG
Enacted
Jul 13, 2020
Effective
Nov 1, 2020
Enforcement
Data Protection Center
Enforcement begins November 2026 after 18-month grace period
What It Requires
Who Must Comply
This law applies to:
- • Public and private entities processing personal data in Egypt
- • Entities outside Egypt offering services to Egyptian data subjects
- • Automated decision-making systems processing Egyptian personal data
Capability triggers:
Who bears obligations:
Safety Provisions
- • Children under 15 require guardian consent for data processing
- • Mandatory 72-hour breach notification to Data Protection Center
- • Data Protection Officer required for entities processing personal data
- • Security measures proportionate to risk
- • Cross-border transfer restrictions
Compliance Timeline
Nov 1, 2026
Full enforcement and compliance deadline
Enforcement
Enforced by
Data Protection Center
Penalties
EGP 3M; criminal liability
Administrative fines, criminal penalties up to EGP 3 million for violations
Quick Facts
- Binding
- Yes
- Mental Health Focus
- Yes
- Child Safety Focus
- Yes
- Algorithmic Scope
- Yes
Why It Matters
Egypt is Africa's third-largest economy. November 2026 deadline creates immediate compliance obligation for NOPE customers serving Egyptian users, particularly for chatbots used by minors.
Recent Developments
November 2026 enforcement deadline approaching after 18-month grace period
Cite This
APA
Egypt. (2020). Personal Data Protection Law (Law No. 151 of 2020). Retrieved from https://nope.net/regs/eg-pdpl-2020
BibTeX
@misc{eg_pdpl_2020,
title = {Personal Data Protection Law (Law No. 151 of 2020)},
author = {Egypt},
year = {2020},
url = {https://nope.net/regs/eg-pdpl-2020}
} Related Regulations
Zambia DPA
Zambia's comprehensive data protection law with special protections for vulnerable persons and DPIA requirements for high-risk processing.
Egypt AI Strategy 2025
Ambitious national strategy positioning Egypt as regional AI hub for Africa and Middle East. Targets 7.7% ICT sector GDP contribution by 2030, training 30,000 AI specialists, establishing 250 AI companies. Built on six strategic pillars: governance, infrastructure, technology, data, ecosystem, and talent. Accompanied by Egyptian Charter for Responsible AI (April 2023) with ethics principles.
Botswana DPA
Botswana's modernized data protection law requiring Data Protection Impact Assessment and establishing age 16 for consent.
Seychelles DPA
Seychelles' modern data protection law requiring DPO for large-scale processing and recognizing Cross-Border Privacy Rules certification.
Rwanda AI Policy
First African country to adopt comprehensive national AI policy. Establishes Responsible AI Office (RAIO) under MINICT. Implements RURA ethical guidelines covering beneficence, non-maleficence, autonomy, justice, explicability, transparency. Non-binding framework.
UNICEF AI for Children
Most specific international guidance on children and AI. Ten requirements for child-centered AI including development/wellbeing support, data/privacy protection, and safety.