Skip to content
Ceci est une traduction de commodite. La version anglaise est la version officielle et juridiquement contraignante. Voir la version anglaise
Middle East / AfricaMEDIUM coverage

Egypt Personal Data Protection Law No. 151 of 2020: AI Compliance Requirements

Egypt's PDPL (No. 151/2020), enforced by the Personal Data Protection Centre (PDPC), is the first comprehensive data protection law in the Arab world. It applies to AI systems processing Egyptian resident data. Key requirements: explicit consent or documented legal basis, data subject rights against automated decisions, and cross-border transfer controls.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

October 15, 2021

Maximum Penalty

EGP 5,000,000 (~$103,000 USD) administrative fines; up to 3 years imprisonment for criminal violations.

What Your Business Must Do

3 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Documented Legal Basis for AI Processing (Egypt)

High Priority

Egypt PDPL requires explicit consent or documented legitimate interest for AI processing of Egyptian resident personal data. Document the legal basis for each AI use case.

Deadline: November 1, 2026

Egypt PDPL (Law No. 151 of 2020) + Executive Regulations (PM Decree 816/2025)

DPO Appointment & 72-Hour Breach Notification (Egypt)

High Priority

Egypt PDPL Executive Regulations (PM Decree 816/2025, in force 2025-11-02) require: (1) DPO APPOINTMENT — every legal entity processing personal data must appoint a Data Protection Officer, register them in the PDPC's DPO registry (subject to qualification/exam requirements, independence/conflict-of-interest rules, and annual reporting), receiving a unique PDPC code scaled to the entity's processing volume/sensitivity — this applies directly to any organization operating AI systems that process Egyptian residents' personal data. (2) BREACH NOTIFICATION — on becoming aware of a personal data breach, notify the PDPC within 72 hours, then notify affected data subjects within three days of that PDPC notification (sooner where national-security concerns apply), describing the breach, its consequences, and remedial steps. Maintain an incident register for PDPC inspection readiness.

Deadline: November 1, 2026

Egypt PDPL Executive Regulations (PM Decree 816/2025)

Data Subject Rights Against AI Decisions (Egypt)

Medium Priority

Egyptian residents have rights to object to automated decisions and request human review. Implement mechanisms for Egyptian users to exercise these rights.

Egypt PDPL (Law No. 151 of 2020)

Who Does This Apply To?

Applies to: any controller or processor that processes the personal data of individuals in Egypt, including (under the law's provisions) entities outside Egypt processing the data of Egyptian residents. Egypt's PDPL (Law No. 151 of 2020) is the first comprehensive data-protection law in the Arab world and applies to AI systems processing Egyptian residents' data; there is no general small-business exemption. Core in-scope obligations: a documented lawful basis or explicit consent before processing; data-subject rights against decisions based on automated processing; cross-border-transfer controls; and a licence/permit and a Data Protection Officer for certain processing once the implementing regulations and the Personal Data Protection Centre (PDPC) are fully operational. Sensitive data and electronic-marketing activities carry heightened requirements. Enforced by the PDPC; administrative fines reach EGP 5,000,000 with criminal liability (up to three years' imprisonment) for serious violations.

Recent Regulatory Guidance

guidance2023-10

PDPC Egypt — AI Processing Guidance under PDPL No. 151/2020 (2023)

Egypt's PDPC published guidance on applying PDPL No. 151/2020 to AI systems: AI processing of Egyptian residents' personal data requires explicit consent or documented legitimate interest; automated decision-making with significant effects requires disclosure and a human review mechanism; cross-border transfers of Egyptian data to AI cloud vendors require PDPC authorization or adequacy determination; DPIAs recommended before deploying high-risk AI systems in Egypt.

Frequently Asked Questions

Does Egypt Personal Data Protection Law No. 151 of 2020 apply to my business?

Egypt's PDPL (No. 151/2020), enforced by the Personal Data Protection Centre (PDPC), is the first comprehensive data protection law in the Arab world. It applies to AI systems processing Egyptian resident data. Key requirements: explicit consent or… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Egypt Personal Data Protection Law No. 151 of 2020 is: EGP 5,000,000 (~$103,000 USD) administrative fines; up to 3 years imprisonment for criminal violations.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Egypt Personal Data Protection Law No. 151 of 2020?

The 3 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://mcit.gov.eg/en/Personal_Data_Protection

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan