Law / Egypt

Egypt

10 of 12 named instruments researched to a stage, across four of the six areas of law we track: 10 in force. As of 19 September 2026.

When they take effect10 of 10 carry a date. Earlier is before 2014.
Before 2014: 2 instruments (2 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 2 instruments (2 in force) 2019: 0 instruments 2020: 6 instruments (6 in force) ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law 1
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (178 words)

Egypt's Personal Data Protection Law No. 151 of 2020 (PDPL) is a comprehensive regime covering any recipient, controller, or processor handling personal data of natural persons that is processed electronically, in whole or in part.

It defines Sensitive Personal Data broadly (health, genetic and biometric data, financial data, religious beliefs, political views, criminal records, and, in all cases, any data relating to a child) and requires a license from the Personal Data Protection Center before any such data is collected, transferred, or processed.

Cross-border transfer is prohibited unless the destination country's protection level meets or exceeds Egypt's own and a Center license or permit is obtained, or the data subject gives explicit consent.

The Center's Executive Regulations (Ministerial Decree No. 816 of 2025) were only issued on 1 November 2025, five years after the PDPL itself took effect, and set a one-year transitional period for organizations to align their operations before full enforcement; secondary sources differ on whether that grace period runs to October or November 2026, and the Decree's own Official Gazette publication date is not established.

Breach notification

Egypt Personal Data Protection Law, Personal Data Infringement notification

Law No. 151 of 2020, Article 7 (Personal Data Infringement notification)Personal Data Protection Law, English translation as republished by the ILO's NATLEX legislative database

In force since 16 October 2020. Binds public and private bodies.

What this law does

Article 7 requires the Controller and the Processor, as the case may be, to notify the Personal Data Protection Center of any Personal Data Infringement within seventy-two hours of the infringement, and to notify immediately where the infringement relates to national security protection concerns.

The Center then notifies the National Security Authorities immediately and, within seventy-two hours of becoming aware of the infringement, supplies them with a description of its nature, form and reasons and the approximate number of Personal Data and records affected, the Data Protection Officer's information, the potential consequences, a description of the procedures followed and proposed to minimise the negative impacts, evidence documenting the infringement and the corrective actions taken, and any further documents the Center requests.

In all events the Controller or Processor must notify the Data Subject within three days from the date it notified the Center, with the infringement and the procedures adopted about it. The Executive Regulations determine the procedures for that duty to notify and inform.

Article 7 of the promulgating law brings the annexed Personal Data Protection Law into force three months after the day following its publication in the Official Gazette, and the law was issued at the Presidency on 13 July 2020, so these provisions have bound since 16 October 2020.

What it requires

Comprehensive regime

Law No. 151 of 2020 Promulgating the Personal Data Protection Law

Law No. 151 of 2020 Promulgating the Personal Data Protection Law, general duties (annexed arts. 1-6, 8-11, 13 and 17-18)Personal Data Protection Law, English translation as republished by the ILO's NATLEX legislative database

In force since 16 October 2020. Binds public and private bodies.

What this law does

Article 3 sets the conditions for collecting, processing and retaining Personal Data: it must be collected for legitimate, specific purposes transparent to the Data Subject, be correct, valid and secured, be processed legitimately and in compliance with the purposes it was collected for, and not be retained longer than that purpose needs.

Article 4 lists the Controller's obligations, among them obtaining the Data Subject's consent before receiving the data, ensuring its validity and sufficiency for the purpose, adopting technical and regulatory procedures to protect it and prevent any hack, damage, alteration or manipulation, deleting it once the purpose is satisfied or holding it in a form that no longer identifies the Data Subject, correcting an error immediately on becoming aware of it, and maintaining a record of the Personal Data in its possession.

Article 5 lists the Processor's obligations. Article 6 fixes when electronic processing is legitimate. Articles 8, 9 and 13 require a Data Protection Officer, register the officer with the Center and set the officer's duties. Article 10 governs a request to disclose Personal Data and article 11 gives digital evidence derived from Personal Data its evidentiary weight. Articles 17 and 18 govern electronic communication for direct marketing.

Article 7 of the promulgating law brings the annexed Personal Data Protection Law into force three months after the day following its publication in the Official Gazette, and the law was issued at the Presidency on 13 July 2020, so these provisions have bound since 16 October 2020.

What it requires

Cross border transfer

Egypt Personal Data Protection Law, cross-border transfer of Personal Data

Law No. 151 of 2020, Articles 14-16 (cross-border transfer of Personal Data)Personal Data Protection Law, English translation as republished by the ILO's NATLEX legislative database

In force since 16 October 2020. Binds public and private bodies.

What this law does

Article 14 permits the transfer of Personal Data collected or prepared for processing to a foreign country, or its storage or sharing there, only where the level of data protection or security in that country meets or exceeds this Law's requirements and a relevant Licence or Permit is obtained from the Center.

Article 15 lets a transfer, sharing, circulation or processing proceed without that minimum protection level where the Data Subject or their representative has given explicit consent and the case is one of seven the article lists: preserving the Data Subject's life and providing medical care, treatment or health-service management; proving, exercising or defending a right before the judiciary; concluding or executing an agreement between the Processor and a third party for the Data Subject's benefit; international judicial cooperation; legal necessity or an obligation to protect the public interest; transferring money to another country under that country's laws; and a bilateral or multilateral international agreement Egypt is party to.

Article 16 lets a Controller or Processor disclose Personal Data to another Controller or Processor outside Egypt under a Licence from the Center, provided their work or purpose corresponds, each of them or the Data Subject has a legitimate interest in the data, and the legal and technical protection abroad is not below Egypt's own.

Article 7 of the promulgating law brings the annexed Personal Data Protection Law into force three months after the day following its publication in the Official Gazette, and the law was issued at the Presidency on 13 July 2020, so these provisions have bound since 16 October 2020.

What it requires

Data subject rights

Egypt Personal Data Protection Law, rights of the Data Subject

Law No. 151 of 2020, Articles 2, 32 and 33 (rights of the Data Subject)Personal Data Protection Law, English translation as republished by the ILO's NATLEX legislative database

In force since 16 October 2020. Binds public and private bodies.

What this law does

Article 2 bars collecting, processing, disclosing or revealing Personal Data by any means except with the Data Subject's explicit consent or where a law permits it, and gives the Data Subject six rights: to know, review and obtain their own Personal Data held by any Holder, Controller or Processor; to withdraw prior consent to its retention or processing; to correct, edit, delete, add to or update it; to limit the processing to a specified purpose; to be notified of any infringement of their Personal Data; and to object to the processing or its results where it contradicts their fundamental rights and freedoms.

Except for the right to be notified of an infringement, the Data Subject pays a consideration for the service of exercising those rights, which the Center fixes and which may not exceed twenty thousand Egyptian pounds. Article 32 requires a Holder, Controller or Processor to reply to a request to exercise those rights within six working days of its submission.

Article 33 lets the Data Subject and any relevant person complain to the Center, without prejudice to judicial proceedings, where the right of Personal Data protection has been infringed, where the Data Subject has not been able to exercise their rights, or against a decision of the Data Protection Officer on a request made to them.

Article 7 of the promulgating law brings the annexed Personal Data Protection Law into force three months after the day following its publication in the Official Gazette, and the law was issued at the Presidency on 13 July 2020, so these provisions have bound since 16 October 2020.

What it requires

Enforcement supervision

Egypt Personal Data Protection Law, the Center, judicial control and penalties

Law No. 151 of 2020, Articles 19-31 and 34-44 (the Center, judicial control and penalties)Personal Data Protection Law, English translation as republished by the ILO's NATLEX legislative database

In force since 16 October 2020. Binds public and private bodies.

What this law does

Article 19 establishes the Personal Data Protection Center as a public economic authority, and articles 20 to 25 set its board, competences, meetings, chief executive, the confidentiality its members and employees owe, and its cooperation with counterpart authorities abroad. Articles 26 to 30 govern the Licences, Permits and Certifications the Center issues, how they are applied for, amended and cancelled, and article 31 the Center's budget.

Article 33 requires the Center to decide a complaint within thirty working days of its submission, to notify the complainant and the respondent of the decision, and requires the respondent to carry it out within seven working days of that notification and tell the Center it has done so. Article 34 gives the Center's employees, appointed by the Minister of Justice, judicial control powers over violations of the Law.

Article 35 opens the penalties without prejudice to severer sanctions under any other law and without prejudice to an injured party's right to seek damages.

Article 36 penalises collecting, processing, disclosing, making available or circulating Personal Data outside the Law, article 38 a Controller's or Processor's failure to perform its articles 4, 5 and 7 obligations, article 39 the legal representatives of juristic persons who do not fulfil theirs, and article 40 a Data Protection Officer who fails to carry out the article 9 duties.

Article 7 of the promulgating law brings the annexed Personal Data Protection Law into force three months after the day following its publication in the Official Gazette, and the law was issued at the Presidency on 13 July 2020, so these provisions have bound since 16 October 2020.

What it requires

Sensitive categories

Egypt Personal Data Protection Law, Sensitive Personal Data and a child's data

Law No. 151 of 2020, Article 12 (Sensitive Personal Data and a child's data)Personal Data Protection Law, English translation as republished by the ILO's NATLEX legislative database

In force since 16 October 2020. Binds public and private bodies.

What this law does

Article 12 prohibits a Controller or Processor, natural or juristic, from collecting, transferring, storing, saving, processing or disclosing Sensitive Personal Data except under a licence issued by the Personal Data Protection Center. Outside the cases a law authorises, the Controller or Processor must also obtain the Data Subject's explicit written consent.

Where any of those activities concerns a child's data, the legal guardian's consent must be obtained instead, and a child's participation in a game, competition or any other activity may not be made conditional on submitting more of the child's Personal Data than participation needs.

Article 1 defines Sensitive Personal Data as data revealing psychological, mental, physical or genetic health, biometric data, financial data, religious beliefs, political opinions or criminal record, and makes any data relating to a child sensitive in every case.

Article 7 of the promulgating law brings the annexed Personal Data Protection Law into force three months after the day following its publication in the Official Gazette, and the law was issued at the Presidency on 13 July 2020, so these provisions have bound since 16 October 2020.

What it requires

Scraping law2 instruments, 2 in force

Research summary (299 words)

Open-web crawling of public pages carries no dedicated Egyptian statute; the general Anti-Cyber and Information Technology Crimes Law No. 175 of 2018 is the applicable authority for unauthorized-access questions, criminalizing intentional access to, or unlawful remaining present in, a restricted website, private account, or information system, with escalated penalties where access is coupled with copying, altering, or republishing data (Arts. 14-15).

No Egyptian court decision addressing how "authorization" is read for a public, unauthenticated page, or addressing terms-of-service enforceability (browsewrap versus clickwrap), was located; ordinary Civil Code offer-and-acceptance principles and the Electronic Signature Law No. 15 of 2004 (which gives electronic records and signatures legal recognition) would be the applicable general law for a contract-formation question, but this is unsettled rather than a specific regime.

Copyright protects a database as a compilation, not through a separate sui generis database right: Law No. 82 of 2002 on the Protection of Intellectual Property Rights protects "databases, whether readable by computer or otherwise" as a category of protected work, and its exceptions are enumerated (personal use, quotation and analysis for criticism, teaching, and library or legal-proceeding copying) rather than a general fair-use or text-and-data-mining carve-out; nothing in the Law addresses AI training specifically, and reproducing all or a substantial part of a database remains an act the author may prevent even after the exceptions.

Personal-data reach over scraped public personal data is governed by the Personal Data Protection Law No. 151 of 2020, researched in full under the privacy topic, and its broad, undifferentiated definition of personal data with no publicly-available carve-out reaches personal data regardless of whether it was scraped from a public page.

No specific unfair-competition or misappropriation doctrine addressed to scraping, and no case law or regulatory statement giving robots.txt legal weight or addressing AI-training-specific access rules, was located.

Computer misuse

Law No. 175 of 2018 on Anti-Cyber and Information Technology Crimes

Law No. 175 of 2018 on Anti-Cyber and Information Technology CrimesAnti-Cyber and Information Technology Crimes Law, English translation published by Andersen's Egypt office

In force since 15 August 2018. Binds public and private bodies.

What this law does

Egypt's general computer-misuse statute. Article 14 punishes intentional access to, or unintentional access and unlawful continued presence in, a restricted website, private account, or information system with imprisonment of not less than one year and a fine of EGP 50,000 to 100,000, rising to not less than two years and a fine of EGP 100,000 to 200,000 where the access results in destroying, altering, copying, or republishing data.

Article 15 separately punishes exceeding the scope of access rights legally granted on a website, account, or system. Penalties are further aggravated where the target belongs to, or is operated on behalf of, the State or a public legal entity. The Law does not define "authorization" specifically for a public, unauthenticated web page, and no Egyptian court decision construing Articles 14-15 in that context was located.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (637 words)

Egypt has no standalone statute setting security requirements a connected device or software product must meet before it is placed on the market, so the product-requirements dimension is a researched absence.

It also has no general vulnerability or incident-reporting statute reaching an ordinary software developer: Law No. 175 of 2018 on Anti-Cyber and Information Technology Crimes names the National Computer and Network Emergency Response Center at the National Telecommunications Regulatory Authority (the Authority) as Egypt's technical contact point for international cybercrime cooperation (Art. 4), but that is an inter-agency cooperation channel, not a duty for a private operator to report an incident to it.

The closest thing Egypt has to a baseline security duty is the same Law's Article 29, which punishes any person responsible for managing a website, private account, email account, or information system in two tiers: intentionally exposing it to the commission of a crime under the Law (imprisonment of not less than one year plus a fine of EGP 20,000 to 200,000), and negligently causing the same kind of exposure through a failure to take the security precautions and measures the Law's own executive regulations are to prescribe (imprisonment of not less than six months plus a fine of EGP 10,000 to 100,000).

That duty does not turn on whether personal data is involved and does not require a telecommunications licence, so it is filed here rather than deferred. Whether the Prime Minister ever issued the Article 44 executive regulations that are to define those 'security precautions and measures', and what they require, could not be confirmed from a reachable source; WIPO Lex's own record of the Law lists no related implementing text.

The same Law's Article 2 separately obligates a 'Service Provider' (defined as any person providing information and communication technology services, including processing or storing information for others) to retain system logs for 180 days, keep stored data confidential, and 'Secure the data and information to ensure its confidentiality, prevent unauthorized access, and protect against damage'; that duty runs throughout to a telecommunications licence under Law No. 10 of 2003 and to the 'Licensing data identifying the provider and the supervisory authority' Article 2(Second) requires a provider to publish, so the bound party reads as a licensed telecom or internet-service operator, a status no declared LexLint activity expresses, and the duty is deferred rather than flagged on a guess.

Two further sector regimes reach a licensed status the same way and are named here rather than filed: the National Telecommunications Regulatory Authority's own site lists a dedicated 'Cyber Security' area under its Industry menu, and the Central Bank of Egypt's site names a 'Cybersecurity' programme for the banking and payments sector with its own 'Report an Incident' channel, 'Cybersecurity Organizational Structure', and training track; neither page's substantive regulatory text loaded as browsable content, and the National Telecommunications Regulatory Authority's page stayed unreachable under a stealth-browser retry too, so neither regime's content could be verified beyond its own site naming it.

Egypt's comprehensive privacy statute, the Personal Data Protection Law No. 151 of 2020 (researched in full under the privacy topic), carries its own security-of-processing article: Article 13 requires a Controller's or Processor's Data Protection Officer to 'follow and implement the security policies and procedures necessary for avoiding any breach or infringement of Sensitive Personal Data'. That provision stays with the privacy row rather than being filed twice here.

Enforcement of Article 29 runs through the ordinary criminal courts and the Public Prosecution; reconciliation of an Article 29 charge additionally requires the Authority's own approval (Art. 42), and no published enforcement record specific to Article 29 was located. The Law does not itself create a statutory private right of action or compensation scheme for a security failure, though a victim's ordinary civil claim survives a criminal reconciliation under Article 42's own terms.

Security baseline statutes

Law No. 175 of 2018 on Anti-Cyber and Information Technology Crimes, System-Security Duty on a System Manager

Law No. 175 of 2018 on Anti-Cyber and Information Technology Crimes, Arts. 29, 42, 44Anti-Cyber and Information Technology Crimes Law, English translation published by Andersen's Egypt office

In force since 15 August 2018. Binds public and private bodies.

What this law does

Article 29 of Law No. 175 of 2018 on Anti-Cyber and Information Technology Crimes punishes any person responsible for managing a website, private account, email account, or information system who intentionally exposes it to the commission of a crime under this Law, with imprisonment of not less than one year plus a fine of EGP 20,000 to 200,000.

It separately punishes the same person for negligently causing that kind of exposure through a failure to take the security precautions and measures the Law's own executive regulations are to prescribe, with imprisonment of not less than six months plus a fine of EGP 10,000 to 100,000. The duty is general.

It does not turn on whether personal data is involved and does not require a telecommunications licence, unlike the separate service-provider duties Article 2 of the same Law places on a licensed 'Service Provider'. Reconciliation of an Article 29 charge requires the National Telecommunications Regulatory Authority's own approval. Reconciliation extinguishes the criminal case without affecting a victim's civil claim.

No source located confirms whether the Prime Minister issued the Article 44 executive regulations, or what specific security precautions and measures they set. WIPO Lex's own record of this Law lists no related implementing text.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (148 words)

Egypt has no press-publisher neighbouring right, no mandatory platform-to-publisher bargaining code, no recognized hot-news misappropriation doctrine, and no located statute or case law addressing hyperlinking or framing liability specifically; each of those five dimensions is a sourced absence rather than an unresolved question.

The one relevant instrument is a general copyright exception: Article 171(4) of Law No. 82 of 2002 on the Protection of Intellectual Property Rights lets any person analyze a published work, or quote or excerpt from it, for the purpose of criticism, discussion, or information, without the author's authorization.

The exception is framed around analysis and criticism rather than a dedicated news-reporting privilege, and no Egyptian court decision applying it to a systematic news aggregator, as opposed to an individual quoting for commentary, was located. The Law predates the concept of a machine-readable text-and-data-mining reservation entirely, so no opt-out mechanism of that kind exists either.

Snippet reproduction

Law No. 82 of 2002 on the Protection of Intellectual Property Rights, quotation and analysis exception (Book Three, Art. 171(4))

Law No. 82 of 2002 News Quotation Exception (Book Three), on the Protection of Intellectual Property Rights, as amended by Law No. 178 of 2020Law No. 82 of 2002 on the Protection of Intellectual Property Rights

In force since 3 June 2002. Binds public and private bodies.

What this law does

Article 171(4) permits any person, without the author's authorization and after a work's publication, to "make an analysis of the work, or excerpts or quotations therefrom, for the purpose of criticism, discussion or information."

The exception is not tied to the news media specifically and carries no headline-versus-substantial-extract threshold of its own; whether it reaches an aggregator's systematic reproduction of headlines and snippets, as opposed to an individual's quotation for commentary, has not been tested in a reported Egyptian decision.

Egypt has no separate press-publisher neighbouring right, no compelled platform-to-publisher bargaining regime, no recognized hot-news or misappropriation doctrine distinct from ordinary copyright and unfair-competition law, and no located case law on hyperlinking or framed display.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.