Egypt (with extraterritorial reach to processing of Egyptians' and Egyptian residents' data)

Egypt Personal Data Protection Law (Law No. 151 of 2020)

105 controls. 2 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

105 controls 2 frameworks share controls with it Egypt (with extraterritorial reach to processing of Egyptians' and Egyptian residents' data) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

Egypt Personal Data Protection Law (151/2020) Evidence & Implementation Kit

105 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
EGY-PDPL-Art.10Procedures for disclosure of personal data0
EGY-PDPL-Art.11Determinative effect of digital evidence0
EGY-PDPL-Art.12Processing of sensitive personal data and children's data1
EGY-PDPL-Art.13DPO security duties for sensitive personal data1
EGY-PDPL-Art.14Cross-border transfer adequacy and licensing1
EGY-PDPL-Art.15Derogations from the cross-border protection level1
EGY-PDPL-Art.16Disclosure to controllers/processors abroad under licence1
EGY-PDPL-Art.17Conditions for direct electronic marketing1
EGY-PDPL-Art.18Obligations of the direct-marketing sender1
EGY-PDPL-Art.19Establishment and mandate of the Personal Data Protection Centre0
EGY-PDPL-Art.2Data subject rights and consent requirement1
EGY-PDPL-Art.20Board of Directors of the Centre0
EGY-PDPL-Art.21Competencies of the Centre's Board0
EGY-PDPL-Art.22Board meetings and resolutions0
EGY-PDPL-Art.23Chief Executive Officer of the Centre0
EGY-PDPL-Art.24Confidentiality obligation of Board members and Centre staff0
EGY-PDPL-Art.25International cooperation by the Centre0
EGY-PDPL-Art.26Types of licenses, permits and certifications0
EGY-PDPL-Art.27Procedures for issuing licenses, permits and certifications0
EGY-PDPL-Art.28Amendment of license and permit conditions0
EGY-PDPL-Art.29Cancellation of licenses, permits and certifications0
EGY-PDPL-Art.3Conditions for lawful collection and processing2
EGY-PDPL-Art.30Administrative sanctions0
EGY-PDPL-Art.31Budget and financial resources of the Centre0
EGY-PDPL-Art.32Requests by data subjects1
EGY-PDPL-Art.33Complaints to the Centre0
EGY-PDPL-Art.34Judicial control powers0
EGY-PDPL-Art.35General penalty provision0
EGY-PDPL-Art.36Penalty for unauthorised processing1
EGY-PDPL-Art.37Penalty for denying rights and unlawful collection1
EGY-PDPL-Art.38Penalty for breach of controller/processor obligations0
EGY-PDPL-Art.39Penalty for failure to appoint a DPO0
EGY-PDPL-Art.4Controller obligations1
EGY-PDPL-Art.40Penalty for DPO failure of duties0
EGY-PDPL-Art.41Penalty for unlawful sensitive-data processing1
EGY-PDPL-Art.42Penalty for unlawful cross-border transfer0
EGY-PDPL-Art.43Penalty for marketing violations0
EGY-PDPL-Art.44Penalty for breach of Centre confidentiality0
EGY-PDPL-Art.45Penalty for license/permit/certification violations0
EGY-PDPL-Art.46Penalty for obstructing Centre officers0
EGY-PDPL-Art.47De facto manager and juristic-person liability0
EGY-PDPL-Art.48Publication of sentences and recidivism0
EGY-PDPL-Art.49Settlement and reconciliation0
EGY-PDPL-Art.5Processor obligations1
EGY-PDPL-Art.6Lawful bases for processing1
EGY-PDPL-Art.7Personal data infringement (breach) notification1
EGY-PDPL-Art.8Appointment of the Data Protection Officer1
EGY-PDPL-Art.9Data Protection Officer obligations1
Art.10Art.10 Procedure for disclosure requests0
Art.11Article 11 Digital evidence0
Art.12Art.12 Sensitive personal data and children's data0
Art.13Art.13 DPO security duties for sensitive personal data0
Art.14Art.14 Cross-border transfer only to adequate protection and under licence or permit0
Art.15Art.15 Transfer with explicit consent below the protection level0
Art.16Art.16 Making data available to a controller or processor abroad under licence0
Art.17Art.17 Conditions for direct electronic marketing0
Art.18Art.18 Duties of the sender: defined purpose, no disclosure of contacts, three-year consent records0
Art.19-25Articles 19 to 25 The Personal Data Protection Centre0
Art.2Art.2 Explicit consent and the data subject's rights0
Art.26,28-31Articles 26, 28 to 31 The licensing regime, administrative sanctions and the Centre's budget0
Art.27Art.27 Applying for licences, permits and certifications0
Art.3Art.3 Conditions for lawful collection, processing and retention0
Art.32Art.32 Requests answered within six working days0
Art.33Art.33 Execution of the Centre's complaint decisions within seven working days0
Art.34Article 34 Judicial control0
Art.35-49Articles 35 to 49 Crimes, penalties, liability of managers and juristic persons, publication and reconciliation0
Art.4.1-4Art.4.1-4 Controller: lawful sourcing, adequacy, processing method and purpose0
Art.4.10-12Art.4.10-12 Controller: licence or permit, Egyptian representative and demonstrable compliance0
Art.4.5-6Art.4.5-6 Controller: no unlawful disclosure and technical and organisational security0
Art.4.7-9Art.4.7-9 Controller: deletion, correction and the record of personal data0
Art.5.1-5Art.5.1-5 Processor: instructions, purpose, period, deletion and no unlawful disclosure0
Art.5.6-8Art.5.6-8 Processor: no processing beyond the controller's purpose, security and no harm0
Art.5.9-12Art.5.9-12 Processor: record of processing activities, demonstrable compliance, licence and representative0
Art.6Art.6 Lawful bases for electronic processing0
Art.7Art.7 Breach notification: the Centre within 72 hours and the data subject within three days0
Art.8Art.8 Appointment and registration of a data protection officer0
Art.9Art.9 Duties of the data protection officer0
CController and processor obligations (Articles 4, 5, 7, 10)0
DData protection officer (Articles 8, 9, 13)0
EExecutive Regulations (MCIT Decree 816 of 2025): delegated duties0
LLicences, permits and the Centre's supervision (Article 27 and the licensing regime)0
MDirect electronic marketing (Articles 17, 18)0
PDPLThe Law, its promulgation, scope, exclusions and status0
RRights of the data subject and conditions of processing (Articles 2, 3, 6, 32, 33)0
Reg.10-11Reg.10-11 Replacing a DPO on fifteen days' notice, suspension and one officer for several entities0
Reg.12Reg.12 DPO duties under the Regulations: annual privacy report, monitoring of requests and complaints, no conflicting assignments0
Reg.14Reg.14 Sensitive data controls: licence, explicit written consent, necessity, Centre security standards, no profiling of children and secure records0
Reg.15Reg.15 Children's data: explicit written guardian consent under 15 and guardian consent from 15 to 180
Reg.16Reg.16 Cross-border transfer controls: licence per adequacy, consent, protective technologies and named destination countries0
Reg.17Reg.17 Making data available to a controller or processor abroad: complementary activity and equal protection0
Reg.18Reg.18 Direct electronic marketing rules: marketing licence, explicit consent, erasure on withdrawal or expiry, first-contact disclosures, intermediary duties and records0
Reg.19-20,32-34,41Regulations Articles 19, 20, 32 to 34 and 41: licence and permit categories and fees, consultant accreditation, forms0
Reg.2Reg.2 Collection controls: licence, informed consent, Centre-approved mechanisms, retention, confidentiality and the consent record0
Reg.21-22Reg.21-22 Conditions for a controller or processor licence or permit0
Reg.24-27Reg.24-27 Cross-border transfer licence or permit: conditions, procedure, ninety working days and fees0
Reg.28-30Reg.28-30 Direct electronic marketing licence: categories, fees and conditions0
Reg.3Reg.3 Controller controls: accuracy checks, deletion with notice, a Centre-approved rights mechanism, the Egyptian representative, inspector access and records of requests0
Reg.31Reg.31 Visual surveillance in public places: licence, signage, no transfer abroad, no facial recognition without consent, confidentiality and security0
Reg.35Reg.35 Data and documents for a legal person's licence or permit application0
Reg.39-40Reg.39-40 Amendment when record volumes grow, associations' licences and renewal deadlines0
Reg.4Reg.4 Processor controls: Centre-approved processing mechanism, handler confidentiality, representative, the statistical exception, AI training and processing records0
Reg.5Reg.5 Breach notification through the portal within 72 hours of awareness, with a secure log, and data subjects within three working days0
Reg.7-9Reg.7-9 DPO registration: conditions, documents, the officer's code and the thirty-working-day decision0
SSensitive personal data and children (Article 12)0
TCross-border transfer (Articles 14 to 16)0

Tell me when Egypt Personal Data Protection Law (Law No. 151 of 2020) files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Record of the lawful basis relied on per processing
  • Consent records
  • Lawful-basis register
  • Lawful-basis determination recorded per processing activity
  • Consent records where consent is the basis
  • Contract or legal-obligation references supporting processing
  • Incident response plan with 72-hour Centre notification path
  • Breach register and notification templates
  • Records of data subject notifications within 3 days
  • Root-cause and corrective-action documentation

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for Egypt Personal Data Protection Law (Law No. 151 of 2020), drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition