Egypt’s Personal Data Protection Law (PDPL) put formal obligations on almost every business that handles personal data: customers, employees, or suppliers. Compliance is not a one-off project; it is an operating posture. Here is a practical checklist to get and stay compliant.

Know what data you hold

You cannot protect what you have not mapped. Start with a data inventory: what personal data you collect, why, where it lives, who can access it, and how long you keep it. Most compliance gaps are simply data no one remembered they were holding.

Establish a lawful basis and give notice

Every use of personal data needs a lawful basis, and individuals are entitled to clear notice of how their data is used. Privacy notices (for customers and employees alike) should be written in plain language and actually reflect what you do.

The core checklist

  • Maintain a data inventory and processing register;
  • Publish accurate privacy notices for customers and staff;
  • Put data-processing agreements in place with vendors who handle data on your behalf;
  • Implement reasonable security measures: access controls, encryption where appropriate, retention limits;
  • Define a process for handling data-subject requests and reporting breaches within the required timeframe;
  • Confirm the rules before transferring personal data outside Egypt.

Cross-border transfers

If you share data with a parent company, a cloud provider, or partners abroad, transfer restrictions may apply. For groups operating across Egypt and the GCC, this is one of the most commonly overlooked obligations, and one of the easiest to fix with the right agreements in place.

Make it a habit, not a project

Assign ownership, review annually, and fold data protection into new projects from the start rather than bolting it on afterwards. Regulators respond far better to a documented, improving programme than to a perfect policy no one follows.

How LEXCAP helps

We run PDPL gap assessments, draft privacy notices and data-processing agreements, and advise on cross-border transfers and breach response: pragmatic compliance sized to your business, not a box-ticking exercise.

This article is provided for general information and does not constitute legal advice. For guidance on your specific situation, contact LEXCAP.