Egypt's Personal Data Protection Law (Law 151 of 2020): what it means for websites
Egypt's data protection law has applied since October 2020, but the date that matters is 1 November 2026: the Executive Regulations issued on 1 November 2025 gave businesses one year to comply. The law does not mention cookies, but it names online identifiers as personal data and requires explicit consent to process them, so a website's analytics and advertising tags need the visitor's opt-in before they run.
Nov 2026
End of the one-year grace period
EGP 5M
Top fine band · doubled if repeated
72 hours
To report a breach to the PDPC
The short answer
Does Egypt require cookie consent?
Egypt has no cookie-specific rule: neither Law 151 of 2020 nor its Executive Regulations mention cookies. But the law names online identifiers as personal data and requires explicit consent to process personal data unless another legal basis applies, so cookies and pixels that identify a visitor for analytics or advertising need opt-in consent before they run.
DLA Piper's Egypt chapter says the same: the law "does not provide any specific rules for governing cookies". Strictly necessary cookies that a site needs to work are a different case from tracking. Two dates matter for a website: the law has applied since October 2020, and the one-year grace period under the Executive Regulations ends on 1 November 2026.
DLA Piper: Data Protection Laws of the World, EgyptWhat the law is
Law No. 151 of 2020 on the Protection of Personal Data is Egypt's general data protection law: issued on 13 July 2020, published in the Official Gazette on 15 July 2020, and in force since October 2020.
For five years it set no practical deadline, because its Executive Regulations had not been issued. They arrived as Decision No. 816 of 2025 of the Minister of Communications and Information Technology, published on 1 November 2025 and in force from 2 November, which started the one-year period businesses have to bring their processing into line.
That period ends on 1 November 2026; some firms write it as 31 October 2026, which is the same year. The regulations only became public on 25 December 2025, and CMS has noted the regulator could take a later view, but no extension has been announced.
The law is supervised by the Personal Data Protection Center (PDPC), a public authority under the Ministry of Communications and IT that issues licences, sets standards, receives complaints and inspects. Two things set it apart from the GDPR: controllers and processors need a licence or permit from the PDPC, and violations are criminal offences tried by the Economic Courts.
Controllers and processors outside Egypt must appoint a representative in Egypt.
What the law requires of a website
- 01
Explicit consent before tracking
The law requires explicit consent to collect or process personal data unless another legal basis applies (Arts 2 and 6), and its definition of personal data names online identifiers (Art. 1). Cookie, device and pixel identifiers that can be linked to a person are covered, so analytics and advertising tags need opt-in consent first. Neither the law nor the regulations mention cookies by name.
- 02
Inform first, and keep the record
Tell people the purpose clearly before collecting, keep a secure electronic record of each consent with its date and form, and let them withdraw it (Executive Regulations, Art. 2). The regulations also give the PDPC the power to approve the mechanisms used to obtain consent.
- 03
A licence or permit from the PDPC
Controllers and processors need a PDPC licence (legal entities, three years) or a permit (up to one year). Up to 100,000 records the licence fee is zero, but the licence is still required: no source exempts small businesses. Direct electronic marketing, sensitive data and transfers abroad each need their own licence.
- 04
Marketing only with prior consent
Electronic marketing sent to individuals needs prior consent, a clear sender identity and an easy way to opt out (Art. 17), and consent records must be kept for three years from the last message (Art. 18).
- 05
A data protection officer
Every legal entity acting as a controller or processor must appoint a qualified data protection officer and register them with the PDPC (Art. 8).
- 06
Breaches and transfers abroad
Report a breach to the PDPC within 72 hours and tell the people affected within three working days after that (Art. 7). Sending data abroad, including to analytics or advertising platforms outside Egypt, needs a destination whose protection is not lower than Egypt's and a PDPC licence (Art. 14).
Penalties are criminal
Fines under Law 151 are imposed by the Economic Courts, not by the regulator. The PDPC's own powers are a warning first, then suspending or withdrawing a licence, publishing the violation, or placing the business under technical supervision (Art. 30).
- 01
Processing without consent
EGP 100,000 to 1,000,000 for collecting, processing or disclosing personal data without consent or another legal basis (Art. 36). Done for gain or to cause harm: at least six months' imprisonment and/or EGP 200,000 to 2,000,000.
- 02
Sensitive data and transfers abroad
At least three months' imprisonment and/or EGP 500,000 to 5,000,000, for processing sensitive data without consent (Art. 41) or breaking the cross-border transfer rules (Art. 42).
- 03
Marketing and licences
EGP 200,000 to 2,000,000 for electronic marketing violations (Art. 43), and EGP 500,000 to 5,000,000 for operating without the licence or permit the law requires (Art. 45).
- 04
Repeat offences and managers
Penalties double for a repeat offence, and the person actually managing the business is liable if they knew of the violation (Arts 47 and 48). So EGP 5,000,000 is not the absolute ceiling.
What Arqam360 does for an Egyptian website
- 01
Opt-in before tags run
By default the banner asks every visitor before analytics and advertising tags run, and Google tags stay denied through Consent Mode v2 until the visitor chooses. Switch on regime detection and visitors in Egypt get the opt-in model with Arabic as the banner's default language.
- 02
Consent records you can export
Each choice, including a later change, is stored with its date, time and the categories accepted or refused, ready to export as a CSV file when the PDPC or a customer asks.
- 03
Arabic first, and English
A native right-to-left Arabic banner with an English version, plus a free privacy policy generator that lists Egypt and Law 151 as an option, and a cookie policy template in both languages.
- 04
Holding tags that ignore Consent Mode
For the Meta Pixel, TikTok and other tags that do not read Consent Mode, an optional setting holds the script until consent. It is off by default, because blocking scripts can break a site, so switch it on and then check your pages.
Timeline
Law issued
Law No. 151 of 2020 issued on 13 July and published in the Official Gazette on 15 July 2020.
Law in force
In force three months after publication. Without Executive Regulations, it set no practical deadline for businesses.
Executive Regulations issued
Decision No. 816 of 2025 of the Minister of Communications and IT, published on 1 November 2025 and in force from 2 November. The one-year compliance period starts.
Text made public
The Executive Regulations became publicly available on 25 December 2025.
Grace period ends
Businesses are expected to comply by 1 November 2026. No extension has been announced.
Check what your site does before consent
The free scanner loads your site in a real browser and lists the cookies and trackers that run before a visitor chooses. It is the part of compliance anyone can check from outside.
Scan your siteDone for you
We set it up on your website
We install the consent banner, wire Google Consent Mode v2, test your Google and Meta tags, and publish your bilingual privacy policy. $299 to install, then $99.99 a month per domain.
Regulations
Compliance guides for GDPR, PDPL, and moreregulations.egyptPdpl.faq.title
regulations.egyptPdpl.faq.subtitle
Neither Law 151 of 2020 nor its Executive Regulations mention cookies. But the law defines online identifiers as personal data and requires explicit consent to process them, so non-essential cookies and pixels used for analytics or advertising need the visitor's opt-in first.
Put an Arabic consent banner on your site before November
The banner takes minutes on WordPress, Shopify, Zid or any custom site. The licence, records and officer are yours to arrange; the banner is the part your visitors see first. Start free, or let our team install it and test your tags.











