Egyptian data protection requirements are now in force. Your organisation must comply — with a registered Data Protection Officer, a live compliance record, and a way to prove it on the day a regulator asks.
Executive Regulation No. 816 of 2025 sets out working obligations under PDPL 151/2020: a registered Data Protection Officer, a mapped record of processing activities, breach notification within 72 hours, and data subject rights answered within 6 working days. These are not optional, and the exposure for getting them wrong is real — up to suspension of the licence to process.
Any organisation that processes the personal data of people in Egypt — customers, employees, applicants — is a data user under PDPL 151/2020, whether or not you are based in Egypt.
Companies processing data at scale, or handling sensitive categories, must appoint a registered Data Protection Officer with the PDPC — a natural person, personally accountable.
72 hours to notify the PDPC of a breach. 6 working days to acknowledge a data subject request. There is no grace period once the clock starts.
Beyond statutory penalties, a breach without a documented response plan costs customer trust, investor confidence, and management time you don't have spare.
A policy signed twelve months ago and never revisited is not a defensible position. Compliance decays — RoPA goes stale, documents expire, vendors change.
An ongoing DPO service catches decay before it becomes exposure, and gives you someone to call the moment something goes wrong.
Your compliance position, as a single number — built directly from the PDPC's own checklist.
Legandra DPO operationalizes the Personal Data Protection Center's own Data Protection Compliance Plan Checklist as a living readiness engine, rather than an invented formula. Every point in your score traces back to a specific checklist question and its legal citation, grouped into eleven weighted pillars. It decays as evidence ages and rises as your DPO closes gaps — so you always know where you stand, and exactly what to do next.
Documented lawful basis and consent practice for every processing activity.
Technical and organisational measures, access control, encryption, privacy-by-design.
Record of Processing Activities, controller and processor, kept current.
A registered, independent Data Protection Officer with a documented mandate.
The right PDPC license or permit, and safeguards for any transfer outside Egypt.
A clear, accessible Privacy Notice, provided before data is collected.
Data collected, used and kept only as long as its stated purpose requires.
All nine PDPL rights actionable, on the statutory 6-working-day clock.
Every processor under an executed, PDPL-compliant Data Processing Agreement.
A documented plan, a DPO-led Awareness process, and the 72-hour/3-day clocks covered.
Marketing consent and CCTV/visual-surveillance conditions, where they apply.
The Compliance Readiness Index is an internal management indicator. It is not a regulatory rating, is not issued by the PDPC, and a high score is not a defence to an enforcement action.
A one-time setup engagement, then an annual retainer.
Up to 50 employees
Up to 100,000 records
Up to 250 employees
Up to 2,000,000 records
Above 250 employees
Above 2,000,000 records
Personal Data Protection Law No. 151 of 2020, with Executive Regulation No. 816 of 2025 setting out the working obligations — data user registration, DPO appointment, breach notification, and data subject rights.