Key points
- Egypt’s executive regulations came more than five years after its 2020 law, and organisations must comply by about 1 November 2026.
- The Personal Data Protection Centre is attached to, and chaired by, the Minister of Communications, and its board includes defence, interior and intelligence representatives.
- Transfers abroad need an adequate destination, a destination-specific licence and the data subject’s consent, backed by prison terms.
- Morocco and Tunisia show a different model, anchored in Council of Europe Convention 108, but their own reforms have stalled.
North Africa has some of the continent’s oldest data protection laws, and Egypt has one of its most consequential. Egypt’s Personal Data Protection Law, Law No. 151 of 2020, was published in July 2020.1 Its executive regulations, issued as Decree No. 816 of 2025 by the Minister of Communications and Information Technology, were dated 1 November 2025 but released publicly only on 25 December 2025.2 Organisations have one year from the regulations to comply, which brings Egypt’s regime into full effect around 1 November 2026.3
That deadline makes this the moment to look closely at how the regime is built. Three features stand out: where the regulator sits, what the law leaves out, and how it treats data leaving the country.
A regulator inside the executive
The law creates a Personal Data Protection Centre as a “public economic authority” attached to the Minister of Communications and Information Technology. The Minister chairs its board, which also includes representatives of the Ministries of Defence and Interior, the General Intelligence Service, the Administrative Control Authority, the IT industry development agency and the telecommunications regulator.4 As of January 2026 the board had not yet been constituted, and the Centre is led by an acting chief executive who is also an adviser to the Minister.5
Egyptian and regional civil society groups have questioned whether this structure allows independent oversight. Access Now argued in 2020 that a board of this composition “does not represent independent oversight of this regulatory function”, and in 2026 the Egyptian Initiative for Personal Rights and Masaar raised “practical concerns about its independence”.6 The concern is practical as well as principled. A regulator that sits within the ministry responsible for digital government will find it hard to enforce the law against that government.
What the law leaves out
The law does not apply to personal data held by the national security authorities, defined as the Presidency, the Ministries of Defence and Interior, the General Intelligence Directorate and the Administrative Control Authority. It also excludes data held by the Central Bank and the institutions it supervises, apart from money-transfer and currency-exchange companies.7
The exemption goes further than exclusion. At the request of the security authorities, the Centre must notify controllers to “modify, delete, hide, make available” personal data.8 In most data protection systems the regulator stands between the individual and the state. Here the law also makes it a channel for the state’s instructions to controllers. The Egyptian Initiative for Personal Rights and Masaar warn that the broadly worded exemption leaves “areas effectively beyond the reach of the Law”.9
A data protection authority should stand between citizens and the state’s demands for their data, not relay those demands.
A triple lock on transfers
Egypt treats data leaving the country as the exception. Under the law, personal data may be transferred abroad only where the destination’s level of protection meets or exceeds Egypt’s, and only with a licence or permit from the Centre.10 The regulations add the data subject’s consent and require the licence to name the destination countries, so adding a country means updating the licence.11 A transfer licence costs half the fee of the underlying controller or processor licence, the Centre has 90 working days to decide, and silence counts as refusal.12 Breaking the transfer rules can be punished by at least three months’ imprisonment, a fine of up to EGP 5 million, or both.13
The regulations provide no standard contractual clauses, and Egypt has not published a list of countries with adequate protection.14 For organisations that run services across borders, including African businesses serving Egyptian customers, each new destination becomes an administrative application with an uncertain outcome.
This sits uneasily with the direction of African trade policy. The African Continental Free Trade Area’s Protocol on Digital Trade, adopted in February 2024, requires its parties to allow cross-border transfers of data, including personal data, subject to an annex on data transfers and to exceptions for legitimate public policy and essential security interests.15 The Centre says it is pursuing “reciprocal adequacy decisions” to ease transfers.16 That is the right instinct. African partners should be first in line.
Implementation and redress
With weeks to go, visible implementation is thin. The Centre presented online services for licence applications and the registration of data protection officers in February 2026, but when we checked its website on 25 September 2026 it had published no decisions, and the status of its application portal was unclear.17 The most significant redress so far has come from the courts: in September 2025 the Alexandria Economic Court ordered EGP 10 million in compensation over a compromise of customer data.18
Morocco and Tunisia: a different anchor
Morocco and Tunisia took a different path. Morocco’s Law 09-08 of 2009 is enforced by the National Commission for the Control of the Protection of Personal Data (CNDP), a seven-member body appointed by the King, six of them on the proposal of the Prime Minister and the presidents of the two houses of Parliament, for five-year terms renewable once.19 Tunisia’s Organic Law 2004-63 is enforced by its national authority, the INPDP.20 Both countries have acceded to the Council of Europe’s Convention 108, which gives them an external standard to measure themselves against.21
Their laws are not without state carve-outs: Morocco’s does not apply to processing for national defence and state security.22 The CNDP has also taken a considered position on a contested technology. After a moratorium, it decided in December 2020 to allow facial recognition only case by case, following prior authorisation.23
But both reform agendas have stalled. The CNDP planned to send the government a draft replacement for Law 09-08 in October 2022, and no definitive text had been adopted by April 2026. A draft law modelled on the GDPR was introduced in Tunisia’s Parliament in March 2018 and has not been passed.24
Recommendations
- Give Egypt’s Centre independent leadership. Constitute the board with a majority of independent members, appoint a permanent chief executive through open competition, and detach the Centre from the Ministry it will need to regulate.
- Put security requests under judicial control. Requests by security bodies to modify, disclose or delete personal data should require a court order, and the exemptions should be narrowed to what is necessary for national security.
- Replace the triple lock with workable safeguards. Publish a list of adequate countries, adopt standard contractual clauses, and drop the consent requirement where another safeguard applies. A late decision on a transfer licence should not count as a refusal.
- Publish decisions from the start. The Centre should publish its licensing and enforcement decisions, and confirm how organisations can apply, before the compliance deadline takes effect.
- Finish the reforms in Morocco and Tunisia. Both countries should complete the modernisation of their laws, and North African states should pursue reciprocal adequacy with African partners in line with the AfCFTA Digital Trade Protocol.
Quotations from Egyptian and Moroccan legal texts are taken from unofficial English translations or translated by ACTPOL.
Notes
-
Law No. 151 of 2020 on the Protection of Personal Data, Official Gazette No. 28 bis (h), 15 July 2020, as reproduced by Al-Dhshan; unofficial English translation in the ILO NATLEX database. ↩
-
Minister of Communications and Information Technology, Decree No. 816 of 2025, as reproduced by Ahmed Azim El-Gamel; Baker McKenzie, “Egypt: important data protection update”, January 2026. ↩
-
Law No. 151 of 2020, promulgating law; Personal Data Protection Centre, website content; Baker McKenzie, January 2026. ↩
-
Law No. 151 of 2020, articles 19 and 20. ↩
-
Baker McKenzie, January 2026; Personal Data Protection Centre, website content. ↩
-
Access Now, “Egypt’s new data protection law: data protection or data control?”, 24 September 2020; Egyptian Initiative for Personal Rights, press release on the legal commentary with Masaar, 28 July 2026. ↩
-
Law No. 151 of 2020, article 3 of the promulgating law and definitions. ↩
-
Law No. 151 of 2020, definitions and provisions on the national security authorities. ↩
-
Egyptian Initiative for Personal Rights, 28 July 2026. ↩
-
Law No. 151 of 2020, articles 14 and 15. ↩
-
Decree No. 816 of 2025, article 16. ↩
-
Decree No. 816 of 2025, articles 26 and 27. ↩
-
Law No. 151 of 2020, article 42. ↩
-
Baker McKenzie, January 2026; Office of the United States Trade Representative, 2026 National Trade Estimate Report, Egypt chapter. ↩
-
Protocol to the Agreement Establishing the African Continental Free Trade Area on Digital Trade, article 20; Covington, “Adoption of the AfCFTA Protocol on Digital Trade”, 28 February 2024; tralac, “The AfCFTA Digital Trade Protocol: clarification of key issues”, 25 February 2024. ↩
-
Personal Data Protection Centre, website content. ↩
-
Personal Data Protection Centre, website content, including its events of 15 February 2026, checked on 25 September 2026. ↩
-
Shehata & Partners, “Data Protection and Privacy 2026: Egypt”, Chambers Practice Guides, 10 March 2026. ↩
-
Law 09-08 on the protection of individuals with regard to the processing of personal data, articles 27 and 32. ↩
-
DLA Piper, Data Protection Laws of the World: Tunisia, February 2026. ↩
-
CNDP, deliberation D-97-2020, 26 March 2020; DLA Piper, Tunisia. ↩
-
Law 09-08, article 2. ↩
-
CNDP, deliberation D-195-EUS/2020 on facial recognition, 30 December 2020. ↩
-
Finance News Hebdo, interview on the sanctions regime, 29 July 2022; RMG Solutions, guide to Law 09-08, April 2026; DLA Piper, Tunisia. ↩