Egypt's Personal Data Protection Center (PDPC) has spent the summer clarifying what businesses already suspected when the Executive Regulations to Law No. 151 of 2020 landed last winter: a security camera pointed at a shop floor now sits in the same regulatory bracket as a company shipping customer data offshore. Under Article 26 of the Executive Regulations — issued by Ministerial Decree No. 816 of 2025 and effective November 1, 2025 — the PDPC has confirmed that "visual monitoring in public spaces" requires a license or permit from the Center, alongside sensitive-data processing, direct electronic marketing, and cross-border data transfers (MCIT press release; Law No. 151 of 2020). Businesses have until October 31, 2026 — the end of a one-year grace period — to get licensed. The portal to apply for that license, as of the most recent legal-industry tracking, still isn't live.
The steelman: CCTV is not a trivial category
Regulators have a real point here, and it's worth stating plainly before dismissing it. Visual surveillance in public and semi-public spaces is not a niche edge case — it captures biometric-adjacent data (faces, gait, license plates) about people who never consented to being filmed, often stored indefinitely with minimal access controls. Egypt's own retail, banking, and transit sectors have expanded CCTV deployment considerably over the past decade, largely unregulated. A licensing regime that forces operators to post visible notices, restrict facial-recognition use to legally permitted cases, and document retention periods is a defensible response to a genuine accountability gap — not bureaucratic overreach in principle. Cross-border transfer and sensitive-data licensing serve an analogous function: forcing controllers to document where Egyptian residents' data ends up.
Where the bundling breaks down
The problem is not that visual surveillance is licensed — it's that the licensing track for a shopping mall's lobby camera is structurally identical to the track for a company selling customer records to an overseas processor, and the compliance apparatus was not built to distinguish between them. The Executive Regulations tier license and permit fees to the volume of personal data records processed, with three-year controller/processor licenses running fee-free up to 100,000 records and scaling to a statutory maximum of EGP 2 million annually for entities above 5 million records (ICLG Egypt Data Protection Report). A national retail chain's camera network can rack up a "records processed" count in the millions within weeks — not because it is doing anything analogous to a cross-border data broker, but because record counts scale with foot traffic, not risk. The same statute that was drafted to catch high-risk international data flows ends up pricing a supermarket's loss-prevention cameras against the same yardstick.
That matters because Egypt's PDPC itself has been actively courting the businesses most likely to feel this: an MCIT press release describes community consultations with Meta, X (formerly Twitter), Amazon, Microsoft, IBM, and Egypt's four mobile network operators specifically on "licenses, permits and approvals" procedures, with the ministry pledging "a single integrated process" across sectors (MCIT). That outreach to multinationals is sensible triage — but it also signals that the regime's practical complexity is being managed relationship-by-relationship with firms who can afford in-house counsel, while the mid-sized retailer or apartment-complex operator with a camera at the gate is left to navigate a volume-tiered fee schedule and a licensing category it may not even know applies to it.
A portal that doesn't exist yet
The more concrete problem is timing, not design. The Executive Regulations require license and permit applications to be submitted through an electronic PDPC portal. As of spring 2026, that portal had not been implemented: "the Centre has not yet implemented the electronic registration system on its website," per legal tracking current to April 2026, with regulations requiring the platform to launch "before 31 October 2026, the date when the grace period ends" (ICLG). A separate legal briefing on the Executive Regulations independently confirms the application portal and forms were "not operational yet" as of its review (Shand Partners). That leaves businesses racing to document DPO appointments, categorize their processing activities, and prepare license applications for a system that does not yet exist to receive them — with enforcement, including administrative and potentially criminal exposure, switching on the moment the grace period lapses (DSN Group).
What proportionate regulation would look like
None of this requires scrapping the visual-surveillance license — a lighter, flat-fee registration tier for low-risk CCTV (no facial recognition, standard retention, visible signage) decoupled from record-volume fee tiers would preserve the accountability goal without taxing routine security cameras at data-broker rates. And a regulator that builds its intake portal before starting the compliance clock, not three months before the deadline it set itself, would do more for actual compliance than any enforcement threat. Egypt's data protection law is younger than the GDPR by nearly a decade and inherits real lessons from how the EU handled proportionality for low-risk processors. The PDPC should apply them, rather than let a well-intentioned surveillance rule become the reason small operators simply skip licensing and hope enforcement stays selective.