Skip to content
The site is currently in beta.
Smart One Group
Security

Egypt's Data Protection Law: Website Compliance Checklist Before 1 Nov 2026

Smart One Group Team· · 11 min read
Egypt's Data Protection Law: Website Compliance Checklist Before 1 Nov 2026

Short answer: Egypt's Personal Data Protection Law No. 151 of 2020 and its Executive Regulations (Ministerial Decree No. 816 of 2025) require every company that processes individuals' data electronically, including website forms, customer records and employee files, to hold a licence or permit from the Personal Data Protection Center (PDPC), appoint a registered data protection officer, record consent, and report any breach within 72 hours. The grace period ends on 1 November 2026. Licence fees are waived up to 100,000 records, but the licence itself is still required.

With under three weeks left on the clock (as of 9 October 2026), business owners are asking one practical question: how do we comply with Egypt's data protection law without launching a heavy legal project? This guide gives you a seven-step technical compliance checklist for your website and systems, with costs in Egyptian pounds, penalties and a three-week plan. It is based on the text of the law and regulations and on official and legal sources we reviewed while writing.

What is Egypt's Personal Data Protection Law No. 151 of 2020, and who must comply?

Egypt's Personal Data Protection Law is the legislation that regulates how personal data processed electronically is collected, stored and transferred, and it gives individuals the rights to access, correct, erase and object. It also creates the PDPC, which issues licences and supervises compliance.

It applies to every controller (whoever decides how data is collected and processed, such as the company that owns a website) and every processor (whoever processes it on the controller's behalf, such as a hosting company or a messaging provider). Article 1 defines personal data as any data identifying a natural person, such as a name, voice, photograph, ID number or an "online identity identifier". Health, biometric and financial data count as sensitive data and carry stricter rules.

The PDPC's acting CEO told ICT Business that the number of customers or the size of the company is not the only test, and that appointing a data protection officer is required of anyone processing personal data regardless of size.

What is the deadline, and what happens after it?

  • The Executive Regulations were published in the Official Gazette (Issue 244, Supplement A) on 1 November 2025, giving organisations a one-year grace period.
  • End date: the PDPC's acting CEO says the grace period ends on 1 November 2026, while some law-firm updates cite 31 October. The safe move is to treat 31 October as your internal deadline.
  • The PDPC portal: the electronic portal for licence and permit applications launched in October 2026. Creating a profile and applying requires authentication through the Digital Egypt platform, which is tied to an Egyptian national ID.
  • Review time: the PDPC has up to 90 working days to decide a complete application, and silence counts as rejection. That is longer than the time left, so applying now is the strongest position.
  • After the grace period: supervision and inspection begin, and PDPC inspectors hold judicial police powers.

How much does a data protection licence cost in Egypt in EGP?

The consolidated controller/processor licence for legal entities is charged annually by the number of individual records you hold, and it is fully waived up to 100,000 records. These are examples from the Article 19 table of the Regulations:

Number of individual recordsAnnual fee
1 to 100,000Exempt from fees
101,000 to 200,000EGP 200
501,000 to 600,000EGP 600
901,000 to 1,000,000EGP 1,000
1,000,001 to 1,100,000EGP 5,000
1,900,001 to 2,000,000EGP 50,000
Over 5,000,000EGP 666,666 per year (the legal maximum, EGP 2 million over three years)

Fees are halved if you act only as a controller or only as a processor. A temporary permit (up to one year) is fee-exempt up to 25,000 records. Direct electronic marketing has its own licence priced at 10% of the controller/processor fee for your own marketing and 25% when marketing for others, and cross-border transfer licences cost 50%. A fee waiver does not waive the licence or the data protection officer.

How do you make your website compliant? A 7-step technical checklist

We built this checklist from a technical perspective for anyone who owns a website or an online system. For each step we separate what the regulations say from what we recommend in practice.

1. Map your data: where does personal data enter your company?

List every collection point: the contact form, sign-up and customer accounts, orders and payments, visitor analytics, WhatsApp messages, employee files and CCTV. For each, record the data type, purpose, storage location and who receives it. This map is the foundation of your licence application and your processing record.

2. Determine your role, category and record volume

Decide whether you are a controller, a processor or both, and whether you handle sensitive data or children's data, run electronic marketing, or send data abroad. Each case carries its own licence or conditions. Then estimate your record count to find your fee tier. A qualified lawyer should confirm the exact category that applies to you.

3. Consent and notice: what do the regulations require?

Data may only be collected after the person consents and is clearly told the purpose, and it may not be reused for another purpose without prior consent. Consent for sensitive data must be explicit and written (paper or electronic), and parental consent is needed for children under 15. The PDPC must also approve the mechanism you use to collect consent.

What we implement: an unticked consent box, a clear Arabic privacy notice beside every form, separate consent for marketing, and a withdraw-consent control. The regulations do not mention cookies by name, but because "online identity identifier" is part of the definition of personal data, the safer approach is to hold analytics and ad tags until the visitor agrees.

4. Data subject rights and consent records

You need an approved mechanism that lets people access, correct, withdraw consent for, erase or restrict the processing of their data. You must keep a secure electronic register of consents (with date and form) and of erasure and correction requests and proof they were actioned. Complaints go to the PDPC, which decides within 30 working days, and the respondent must comply within 7 working days.

What we implement: a consent table that stores time, form and consent text, plus an internal requests dashboard with an audit trail.

5. Security, backups and erasure

The regulations require technical measures to keep data confidential and prevent breaches, require processors to store data in unreadable form for unauthorised parties, and require both roles to be able to restore data and access it in a timely manner after an incident. Data must be erased once its purpose ends, and the person notified. The licence file also asks about your infrastructure, including data centre classification and technical certifications.

What we implement: HTTPS, encryption of sensitive fields, least-privilege access, encrypted backups with tested restores, an automated retention policy, and clear details about your hosting and servers to include in the application.

6. A breach-response plan: 72 hours

You must notify the PDPC through the portal or hotline within 72 hours of learning of a breach, and log it in a secure register covering the time of awareness, the nature of the breach, likely impact, urgent measures and your DPO's details. Individuals must then be told within three working days of your notification to the PDPC, using the channel they chose when they consented.

What we implement: access logs and alerts, a ready-made incident form, and a clear call tree for the first hours. A technical support retainer helps make sure someone can respond outside office hours.

7. Governance: your DPO and vendor contracts

Appoint a data protection officer registered with the PDPC, either an employee or a contractor, and notify the PDPC at least 15 days before ending that relationship. List the vendors that touch your customers' data (hosting, email, messaging, analytics), sign processing agreements with them, and check whether data leaves Egypt, because that requires a licence and the person's consent. Law firm Riad & Riad notes that application files typically include a record of processing activities, a retention policy, an incident response plan and a processing agreement template.

A 3-week compliance timeline

PeriodTasks
Until 16 OctoberMap data, decide role, category and record count, choose a DPO, and start your portal account through Digital Egypt.
Until 23 OctoberUpdate the privacy notice and consent forms, build the consent register, and prepare the retention policy and vendor contracts.
Until 31 OctoberAudit security and backups, approve the breach plan, submit the application through the portal and keep proof of submission.

What are the penalties for violating Egypt's data protection law?

ViolationPenalty
Collecting or processing data without consent or outside lawful cases (Art. 36)Fine of EGP 100,000 to 1 million; rising to at least 6 months' imprisonment and a fine of EGP 200,000 to 2 million, or either, if done for benefit or to harm the data subject
Refusing to let a person exercise their rights (Art. 37)Fine of EGP 100,000 to 1 million
Controller or processor failing its obligations (Art. 38)Fine of EGP 300,000 to 3 million
Handling sensitive data without consent (Art. 41)At least 3 months' imprisonment and a fine of EGP 500,000 to 5 million, or either
Breaching electronic marketing rules (Art. 43)Fine of EGP 200,000 to 2 million
Breaching licence or permit rules (Art. 45)Fine of EGP 500,000 to 5 million

The person in actual management of the company faces the same penalties if they knew of the violation and contributed to it. Penalties double for repeat offences, and the court orders the conviction published at the offender's expense. The law also allows settlement for some offences under set conditions.

Frequently asked questions about Egypt's data protection law

Does Egypt's data protection law apply to small businesses?

Yes. It applies to every entity that processes personal data electronically, whatever its size. A small company with fewer than 100,000 records pays no licence fee, but it must still hold the licence, appoint a data protection officer, collect consent and keep records.

When does the compliance grace period end?

The PDPC's acting CEO says the grace period ends on 1 November 2026, while some legal sources cite 31 October 2026. Supervision and inspection begin afterwards, so aim to submit your application before 31 October.

Must a small company appoint a data protection officer?

Yes. According to the PDPC's acting CEO, controllers and processors must appoint a data protection officer and register them with the PDPC whenever they process personal data, regardless of customer numbers or company size. The officer can be an employee or an external contractor.

Do I have to tell anyone if my website is hacked?

Yes. You must notify the PDPC within 72 hours of becoming aware of the breach, through the portal or hotline, log it in a secure register, and then inform the affected individuals within three working days of notifying the PDPC.

Do I need an extra licence for WhatsApp or email marketing?

Yes, if your messages are marketing messages aimed at specific people. Direct electronic marketing requires its own licence, the recipient's explicit consent, identification of the sender and purpose, a way to opt out, and erasure of their data when they withdraw. Service messages such as appointment confirmations stay within the purpose for which the data was collected.

Does hosting my site outside Egypt count as a cross-border transfer?

It can. The law defines cross-border movement as transferring, storing, processing or making data available from inside Egypt to outside it. That requires a PDPC licence and the person's consent, and your application must state temporary and final storage locations, so find out where your website and system data actually sit.

Next step

Compliance has a legal side, decided by your lawyer and data protection officer, and a technical side covering the website, servers, backups and consent records. The Smart One Group team can review the technical side with you, whether in your existing website, your custom system or your WhatsApp business messaging. If you would like to know what your system is missing before you apply, we would be glad to talk with you in a free consultation.

Note: this article is general information, not legal advice. Smart One Group is a technology company, not a law firm, and does not issue licences. Key sources: the PDPC portal, the Executive Regulations in English translation, the text of Law 151 of 2020, and the Baker McKenzie update of 7 October 2026.

Personal Data Protection Law PDPC Egypt Data Protection Officer Information Security Technical Compliance Website Privacy

Related reading

Start your project with us

Book a free consultation and get back a clear plan and a firm cost.