Egypt Egypt digital ID Takamol surveillance

Egypt's New Data Protection Regulator Reports to the Security Services Its Own Law Exempts

As Egypt's PDPC opens registration ahead of a Nov. 1, 2026 deadline, its governing board seats the same security agencies the law excludes from oversight.

Egypt's PDPL Compliance Countdown People of Internet Research · Egypt 12 months Grace period before enforcement Executive Regulations took effect … ~5 months Portal-to-deadline runway The licensing portal opened mid-Ju… 200–50,000 EGP Registration fee range Fees scale with database size, fro… peopleofinternet.com
Egypt's PDPL Compliance Countdown People of Internet Research · Egypt 12 months Grace period before enforceme… ~5 months Portal-to-deadlin e runway 200–50,000 EGP Registration fee range peopleofinternet.com

Key Takeaways

A Narrow Window to Register

Sometime around mid-June 2026, Egypt's Personal Data Protection Center (PDPC) switched on the electronic portal that every company, NGO, and public body processing Egyptians' personal data must now use to register as a "controller" or "processor" — and, in most cases, pay for a license. The clock was already running. The Executive Regulations issued under Ministerial Decree No. 816 of 2025, implementing Law No. 151 of 2020, took effect on November 1, 2025, opening a one-year reconciliation period that expires November 1, 2026. That leaves organizations roughly five months between the portal's launch and the deadline to register, appoint a Data Protection Officer, and secure whatever license their data footprint requires.

The licensing fees are volume-based: as little as 200 Egyptian pounds (~$4) for the smallest registries, rising to 50,000 EGP (~$1,000) for holdings above five million records. The regulations also require separate licenses for higher-risk activity — cross-border data transfers, electronic marketing, certain surveillance-adjacent processing — with transfer applications specifying destination country, purpose, data categories, and safeguards.

That fee structure is, on its own, defensible. A tiered schedule that scales with a company's actual data footprint is more proportionate than a flat licensing tax that would fall hardest on Egypt's startups and SMEs. Getting a functioning registry of who controls what data up and running at all is a real step beyond the five years the PDPL spent in legal limbo after its 2020 passage without implementing regulations.

The Steelman for a Powerful Board

The sharper criticism, from digital rights groups, targets who sits on the PDPC's governing board. Chaired under the Ministry of Communications and Information Technology, the board reserves seats for the Ministry of Defence, the Ministry of Interior, and Egypt's General Intelligence Service. There is a real case for that design. A privacy regulator with no institutional standing is a talking shop; giving it a seat at the table with the security ministries that generate some of the country's largest and most sensitive datasets — biometric records, telecom metadata, identity and border systems — could in principle make compliance findings harder for those same ministries to wave away. Regulators everywhere struggle to get security services to internalize data-protection obligations; embedding them in the room is one way states have tried to solve that, rather than leaving security data entirely outside the regulator's view.

Why the Structure Undermines the Point

The steelman collapses on inspection of the rest of the law. Law 151/2020 exempts the presidency, the Ministry of Defence, the Ministry of Interior, and the General Intelligence Service from most of its substantive obligations in the first place. So the very agencies that sit on the board licensing everyone else — and that can compel disclosure under the law's 72-hour breach-notification rule — are largely the ones the underlying statute does not meaningfully bind. As the digital rights group Access Now put it in its analysis of the law, a board seat for these ministries "does not represent independent oversight of this regulatory function, especially since the board has decision-making authority."

"That does not represent independent oversight of this regulatory function, especially since the board has decision-making authority." — Access Now

This is precisely the design flaw that the "independence" requirement in modern data-protection frameworks — the EU's GDPR foremost among them — exists to prevent: an executive-appointed board where the entities most likely to want access to citizens' data, rather than oversight of it, hold a vote on enforcement decisions. It isn't hypothetical. Every breach notification a controller files with the PDPC within the mandated 72-hour window now flows through an institution structurally answerable to the same security ministries the law exempts from its coverage.

The Fix Is Structural, Not Rhetorical

None of this argues for scrapping the licensing regime — a functioning inventory of data controllers, with real deadlines and real fees, is worth having. The fix is narrower than critics sometimes suggest: strip security-ministry representatives of voting authority on licensing and enforcement decisions specifically, or firewall breach-notification data from board members drawn from agencies the law exempts. Either would preserve the coordination benefit the current design is presumably meant to serve, without collapsing the independence a regulator needs to be credible — both to the businesses now paying registration fees and to the citizens whose records they're registering.

Foreign investors and multinational platforms weighing whether Egypt's regime can eventually underpin GDPR-style cross-border transfer adequacy will be watching the same gap. A licensing portal is not equivalent to an independent regulator, and the five-month compliance sprint now underway does nothing on its own to close that distance.

Sources & Citations

  1. Law No. 151 of 2020 (PDPL text, MCIT)
  2. MCIT press release on PDPC licensing
  3. Access Now: 'Data protection or data control?'
  4. DSN Group compliance briefing
  5. PPC Land: Egypt implements data protection law
  6. Access Partnership: Executive Regulations analysis