Egypt PDPL Executive Regulations 816/2025: The 31 October 2026 Compliance Countdown
Published: 27 July 2026 · Updated: 27 July 2026
Egypt’s Personal Data Protection Law — Law 151 of 2020 — has been on the books for six years, but it only became an operational reality on 1 November 2025, when the Ministry of Communications and Information Technology issued Ministerial Decree No. 816 of 2025: the law’s executive regulations. This guide is for CTOs and compliance leads who process personal data in Egypt and want the deadline, the obligations, and the architecture implications in one place. It is information, not legal advice.
What’s new — the law now has an operating manual
Between 2020 and late 2025, the PDPL sat in an uncomfortable limbo: the obligations existed on paper, but without executive regulations there was no way to register, no fee schedule, and no working definition of what the Personal Data Protection Centre — the regulator the law created — would actually ask for. Decree 816/2025 closes that gap. It sets out how controllers and processors register with the Centre, what registration costs, how the mandatory Data Protection Officer is graded, how fast breaches must be reported, and how cross-border transfers get licensed.
The practical consequence: “we’re watching it” stopped being a defensible posture on 1 November 2025. The regulations also started a one-year grace period for organisations to bring themselves into compliance — and that clock runs out on 31 October 2026.
The deadline math
The grace period ends on 31 October 2026 — one year from the day the regulations were issued. From the date this guide was published (27 July 2026), that is 96 days away: one quarter, in a year where the registration machinery is still being switched on.
That last part matters. The Centre’s online registration platform is not yet live; it is expected to open before the deadline. Every controller and processor in the country will be registering through the same portal in the same short window, so the realistic deadline is not 31 October — it is whenever the platform opens, plus the time it takes you to assemble what it asks for. Organisations that treat the summer as preparation time will file in days; the ones that wait will be counting records and drafting DPO appointments while the queue forms.
A useful way to frame it internally: you are not 96 days from a deadline, you are one platform launch from it.
Obligation 1 — Register, and budget for the tiers
Controllers and processors must be licensed by the Centre, and the regulations price the licence by the volume of personal data you handle. Registration is free up to 100,000 records, and rises to EGP 2 million for organisations processing above 5 million records.
Two details are worth budgeting around. If you act in a single role — controller only, or processor only — the licence costs 50% of the full fee. And temporary permits, for shorter or one-off processing engagements, run between EGP 10,000 and EGP 500,000.
The number that concentrates minds is the other side of the ledger: processing without the required licence carries a fine of EGP 500,000 to EGP 5 million. Counting your records is no longer a data-governance nicety — it determines your fee tier and your exposure.
Obligation 2 — Appoint a Data Protection Officer
A DPO is mandatory, and the regulations grade the role into three tiers — A, B and C — so the seniority and certification expected of the officer scales with the organisation. Confirm which tier applies to you before the registration window opens; the appointment will be part of what the platform asks for.
Treat this as a hiring decision, not a title. When every company in the market needs a DPO in the same quarter, the pool of people who can credibly fill the role gets very thin, very fast.
Obligation 3 — Build the 72-hour breach muscle
The regulations set two clocks for personal data breaches: the Centre must be notified within 72 hours, and the affected individuals within 3 working days. These are among the shortest notification windows in the region, and they are measured from when you become aware — not from when you finish investigating.
Seventy-two hours is an engineering requirement before it is a legal one. You need to know which systems hold personal data, be able to detect that one of them is bleeding, assess what was exposed, and draft a notification — inside a long weekend. If that chain has never been rehearsed, the first rehearsal will be a real breach.
Obligation 4 — License every cross-border transfer
Moving personal data out of Egypt requires a separate licence from the Centre, issued for a specific destination. The Centre assesses whether the destination offers adequate protection, so “we host on a global cloud region” is not an answer — the question is which countries your data flows to, and whether each of those flows is licensed.
Map the flows now: your cloud regions, your support tooling, your analytics, and — increasingly — your AI stack. Every external service that touches personal data is a potential licensable transfer.
Obligation 5 — Sequence the work before the platform opens
Because the registration platform is not yet live, the fifth obligation is timing itself. The sensible order of operations: inventory your personal data and count records (your fee tier), map every cross-border flow (your licence list), appoint the DPO (your registration dependency), and rehearse breach response (your 72-hour clock). Then, when the platform opens, registration is an afternoon of form-filling rather than a quarter of archaeology.
What this means if you run AI on your data
The cross-border licence is where the PDPL stops being paperwork and becomes architecture. The dominant pattern for “adding AI” to a company — streaming database contents to a foreign model API — manufactures exactly the kind of transfer the regulations make you license, per destination, with the Centre judging adequacy. Every prompt that carries a customer row is a compliance event.
There is a quieter pattern, and it is the one DEBO is built on: bring the intelligence to the data instead of the data to the intelligence. DEBO deploys inside your environment and processes in-country, so personal data never crosses a border by architecture — there is no per-destination licence to chase for the AI layer, because there is no transfer. Every query and every answer is written to an audit log, which is the evidence trail a DPO needs when the Centre asks how personal data is being processed, and role-based permissions decide what each person can ask in the first place.
Whatever you deploy, the principle holds: under Decree 816/2025, where your AI runs is a compliance decision. Choose an architecture your DPO can defend.
Frequently asked questions
What exactly changed in November 2025?
The executive regulations of the PDPL (Law 151 of 2020) were issued as MCIT Ministerial Decree No. 816 of 2025 on 1 November 2025, making the law’s obligations operational and starting the one-year grace period.
When is the real deadline?
31 October 2026. The grace period ends one year after the regulations were issued; after that date, controllers and processors are expected to be licensed and compliant.
How much does registration cost?
It is tiered by records: free up to 100,000 personal data records, rising to EGP 2 million above 5 million records. A licence for a single role (controller only or processor only) costs 50% of the full fee, and temporary permits run between EGP 10,000 and EGP 500,000.
What happens if we do not register?
Processing personal data without the required licence exposes the company to a fine of EGP 500,000 to EGP 5 million.
Can we move personal data outside Egypt?
Only with a separate licence from the Personal Data Protection Centre for the specific destination. The Centre assesses whether the destination offers adequate protection, so plan for per-destination licensing.
How fast must breaches be reported?
The Centre must be notified within 72 hours of becoming aware of a breach, and the affected individuals within 3 working days.
Do we need a Data Protection Officer?
Yes. A DPO is mandatory, and the regulations grade the role into tiers A, B and C. Confirm which tier your organisation falls into before the registration window opens.
See in-country AI on your own data
A 30-minute demo on your own use case: watch DEBO answer questions straight from your database, inside your environment, with the audit log to prove it.
Book a demo