Egypt Egypt digital ID Takamol surveillance

Egypt's Data Law Puts Ordinary CCTV Cameras in the Same Licensing Track as Cross-Border Transfers

Egypt's PDPC classifies routine visual surveillance as a licensed activity ahead of an Oct. 31 deadline, but its application portal isn't built yet.

Egypt's PDPC Licensing Squeeze People of Internet Research · Egypt EGP 2M Max annual license fee Statutory cap for controllers/proc… Oct 31, 2026 Compliance deadline End of the one-year grace period f… 100,000 records Fee-exempt processing threshold Three-year controller/processor li… Not yet live Licensing portal status PDPC's electronic registration sys… peopleofinternet.com
Egypt's PDPC Licensing Squeeze People of Internet Research · Egypt EGP 2M Max annual license fee Oct 31, 2026 Compliance deadline 100,000 records Fee-exempt processing thres… Not yet live Licensing portal status peopleofinternet.com

Key Takeaways

Egypt's Personal Data Protection Center (PDPC) has spent the summer clarifying what businesses already suspected when the Executive Regulations to Law No. 151 of 2020 landed last winter: a security camera pointed at a shop floor now sits in the same regulatory bracket as a company shipping customer data offshore. Under Article 26 of the Executive Regulations — issued by Ministerial Decree No. 816 of 2025 and effective November 1, 2025 — the PDPC has confirmed that "visual monitoring in public spaces" requires a license or permit from the Center, alongside sensitive-data processing, direct electronic marketing, and cross-border data transfers (MCIT press release; Law No. 151 of 2020). Businesses have until October 31, 2026 — the end of a one-year grace period — to get licensed. The portal to apply for that license, as of the most recent legal-industry tracking, still isn't live.

The steelman: CCTV is not a trivial category

Regulators have a real point here, and it's worth stating plainly before dismissing it. Visual surveillance in public and semi-public spaces is not a niche edge case — it captures biometric-adjacent data (faces, gait, license plates) about people who never consented to being filmed, often stored indefinitely with minimal access controls. Egypt's own retail, banking, and transit sectors have expanded CCTV deployment considerably over the past decade, largely unregulated. A licensing regime that forces operators to post visible notices, restrict facial-recognition use to legally permitted cases, and document retention periods is a defensible response to a genuine accountability gap — not bureaucratic overreach in principle. Cross-border transfer and sensitive-data licensing serve an analogous function: forcing controllers to document where Egyptian residents' data ends up.

Where the bundling breaks down

The problem is not that visual surveillance is licensed — it's that the licensing track for a shopping mall's lobby camera is structurally identical to the track for a company selling customer records to an overseas processor, and the compliance apparatus was not built to distinguish between them. The Executive Regulations tier license and permit fees to the volume of personal data records processed, with three-year controller/processor licenses running fee-free up to 100,000 records and scaling to a statutory maximum of EGP 2 million annually for entities above 5 million records (ICLG Egypt Data Protection Report). A national retail chain's camera network can rack up a "records processed" count in the millions within weeks — not because it is doing anything analogous to a cross-border data broker, but because record counts scale with foot traffic, not risk. The same statute that was drafted to catch high-risk international data flows ends up pricing a supermarket's loss-prevention cameras against the same yardstick.

That matters because Egypt's PDPC itself has been actively courting the businesses most likely to feel this: an MCIT press release describes community consultations with Meta, X (formerly Twitter), Amazon, Microsoft, IBM, and Egypt's four mobile network operators specifically on "licenses, permits and approvals" procedures, with the ministry pledging "a single integrated process" across sectors (MCIT). That outreach to multinationals is sensible triage — but it also signals that the regime's practical complexity is being managed relationship-by-relationship with firms who can afford in-house counsel, while the mid-sized retailer or apartment-complex operator with a camera at the gate is left to navigate a volume-tiered fee schedule and a licensing category it may not even know applies to it.

A portal that doesn't exist yet

The more concrete problem is timing, not design. The Executive Regulations require license and permit applications to be submitted through an electronic PDPC portal. As of spring 2026, that portal had not been implemented: "the Centre has not yet implemented the electronic registration system on its website," per legal tracking current to April 2026, with regulations requiring the platform to launch "before 31 October 2026, the date when the grace period ends" (ICLG). A separate legal briefing on the Executive Regulations independently confirms the application portal and forms were "not operational yet" as of its review (Shand Partners). That leaves businesses racing to document DPO appointments, categorize their processing activities, and prepare license applications for a system that does not yet exist to receive them — with enforcement, including administrative and potentially criminal exposure, switching on the moment the grace period lapses (DSN Group).

What proportionate regulation would look like

None of this requires scrapping the visual-surveillance license — a lighter, flat-fee registration tier for low-risk CCTV (no facial recognition, standard retention, visible signage) decoupled from record-volume fee tiers would preserve the accountability goal without taxing routine security cameras at data-broker rates. And a regulator that builds its intake portal before starting the compliance clock, not three months before the deadline it set itself, would do more for actual compliance than any enforcement threat. Egypt's data protection law is younger than the GDPR by nearly a decade and inherits real lessons from how the EU handled proportionality for low-risk processors. The PDPC should apply them, rather than let a well-intentioned surveillance rule become the reason small operators simply skip licensing and hope enforcement stays selective.

Sources & Citations

  1. MCIT press release on PDPC licensing consultations
  2. Egypt Law No. 151 of 2020 (Personal Data Protection Law)
  3. ICLG Data Protection Laws and Regulations Report — Egypt
  4. Shand Partners briefing on Egypt's Executive Regulations
  5. DSN Group: Egypt's PDPL compliance countdown