Egypt's Personal Data Protection Center (PDPC) has set out, across a 23-page self-assessment checklist, what it expects from controllers and processors under Law No. 151 of 2020, ranging from a 72-hour breach notification clock to cookie banners that keep non-essential trackers switched off until users opt in. The document carries no publication date. It drew wider attention this week after Youssef M. Elkased, a data privacy and governance specialist and data protection officer at geidea, shared it on LinkedIn as the one-year grace period under the law's Executive Regulation nears its end.
In Short
Egypt's privacy regulator has put out a long checklist that companies can use to grade themselves, question by question, on whether they follow the country's data protection law. It affects anyone handling information about people in Egypt, including websites with cookie banners and firms sending marketing emails or text messages, and the grace period for getting ready ends around November 1, 2026. The list spells out what the regulator expects: a license before processing data, an opt-in before any non-essential tracking, and a 72-hour deadline for reporting a data breach.
Eleven sections, four possible answers
The document is titled "Data Protection Compliance Plan Checklist" and is divided into 11 sections numbered I to XI. The first establishes whether the law applies at all. The last deals specifically with websites and mobile applications. Between them sit the data protection principles, data subject rights, the data protection officer (DPO), licensing, cross-border transfers, electronic direct marketing, visual surveillance, vendor management and breach response.
Almost every question is answered on a four-point scale: Yes, No, Partial or NA. The licensing section is the exception. There, only Yes and No columns appear, leaving no room for partial readiness on whether an organization holds, or has prepared for, a PDPC license. Some items are open fields rather than scored questions. A block on information security certifications, for instance, offers four blank lines to fill in.
The PDPC logo appears on each page. No date, version number, author or signature does. The text also shows signs of limited final editing: item lettering restarts mid-table in several places, and one disclaimer in the DPO section says the role "has been approved by PDPC has approved the role during the registration process," repeating itself within a single clause.
Elkased's post described the document as more than a restatement of the statute. "What makes it stand out is that it doesn't just restate the Law," he wrote. "It translates it into 11 practical assessment areas with Yes/No/Partial/NA scoring, which makes it usable for both gap analysis and board reporting." He went further: "I see this checklist as a mandatory document for the licensing process."
The checklist itself does not say that. Its licensing section asks whether an organization has prepared "the necessary documentation (e.g., data inventory, security measures, DPO designation) to support a license or permit application." Nowhere in the 23 pages is the checklist described as a required part of that application.
Who the law reaches
The opening section splits scope into two parts. On material scope, the checklist asks whether personal data is processed "through fully or partially automated means" and whether any data is held solely on paper. According to the PDPC, data kept only in manual or paper formats, with no associated electronic processing, falls outside the law.
Territorial scope takes five questions. They cover Egyptian controllers and processors established inside Egypt, Egyptian controllers and processors established outside it, and foreign controllers or processors located within Egypt, the last irrespective of where data subjects live or which passport they hold. Two further questions turn on the people whose data is processed: Egyptian citizens "residing inside or outside Egypt," and foreign nationals residing in the country. Read together, the questions reach an Egyptian company processing data abroad, a foreign company present in Egypt, and any organization handling data about Egyptian citizens wherever they live.
That breadth matters for advertising supply chains that already treat Egypt as an addressable market. Amazon DSP added Egypt to its unified in-market audience definitions in November 2025, alongside Saudi Arabia, the United Arab Emirates, Morocco and other Middle Eastern markets. Cairo is the only African city in a 2025 ranking of the world's largest citiesand remains the largest non-Asian city in every projected column to 2100.
Consent, tested nine ways
Question eight asks whether a valid lawful basis is determined and documented "for each processing activity," giving consent, contract, legal obligation and legitimate interest as examples. The list is not exhaustive. The PDPC's separate consent guidelines confirm six lawful bases under Article 6 of the law, according to law firm Kennedys, adding the claim or defense of a legal right and the execution of court judgments or orders from investigative authorities.
Where consent is relied upon, the standard sits at the top of the table: consent "must be explicit, freely given, specific, informed, and unambiguous, and obtained through a clear affirmative action." Nine sub-questions then break that down. Requests must be presented separately from general terms and conditions, "in plain, intelligible, and accessible language," with the checklist adding in bold that consent is not bundled with other terms. Individuals must take a positive action to opt in. Distinct purposes require separate consents, each explaining the type of processing involved. People must be told they can refuse or withdraw "at any time, without detriment," and the withdrawal mechanism has to be effective and simple. Declining optional processing cannot cost a user the service itself.
Records of consent must be documented and securely maintained. The checklist also asks whether consent practices are reviewed and updated regularly, defining the term as the policies, procedures and operational measures an organization uses to "obtain, manage, and demonstrate valid consent from data subjects."
The unbundling test tracks a principle other regulators have recently hardened. Turkey's data protection board ruled in February 2026 that explicit consent texts and clarification texts must be presented as separate documents under distinct headings. The withdrawal test targets a known weak point as well. IAB Europe's 2025 compliance report found that 53% of its audits flagged the absence of an equally easy mechanism for withdrawing consent.
The other lawful bases get blocks of their own. Contract-based processing must be limited to "what is strictly required" to fulfil the contract or pre-contractual obligation. Legal obligation requires the specific provision to be identified and documented. Legitimate interest carries five questions: whether the interest is clearly identified and documented, whether there is "no less intrusive, reasonable alternative," whether the data subject would reasonably expect the processing, whether processing stops on objection "unless compelling legitimate grounds are demonstrated," and whether accountability for the choice can be shown through internal documentation and review.
Sensitive data and minors
For sensitive personal data, broadly the Egyptian counterpart to what European law calls special category data, the checklist applies a stricter test. Consent must be "explicit, written, and obtained directly from the data subject or their authorized representative," though it may be collected in physical or electronic form.
Children are handled in two age bands, beneath a heading that applies additional safeguards to all data subjects under 18. For those under 15, explicit consent must come from a parent or legal guardian and must specify "the purpose and duration of the processing." For those aged 15 to 18, the child or the guardian must submit the guardian's explicit consent. In neither band does a minor's own agreement suffice. The GDPR takes a different route under Article 8, letting EU member states set a digital consent age between 13 and 16. The checklist's website section adds that services which target children, or which "may be used by children," need age verification mechanisms and "verifiable parental consent" before collecting personal data.
Principles, security and the paper trail
Beyond lawful basis, the principles section runs through fairness, transparency, purpose limitation, data minimization, storage limitation and accuracy. Some items are general. Others are operational. The minimization block asks whether "all data collection mechanisms (including forms, systems, and datasets)" have been reviewed to remove unnecessary or excessive fields. Storage limitation requires documented retention periods for each processing activity, secure deletion or anonymization once they expire, and periodic reviews. Transparency covers a public-facing privacy notice, an internal privacy policy for staff and a policy on compelled disclosure to law enforcement or regulators.
Security is the longest block in the principles section, moving from encryption, access controls and intrusion detection to governance questions such as whether a steering committee oversees privacy and whether segregation of duties is in place. Under privacy by design and by default, the checklist asks whether "privacy settings are set to the most privacy-friendly options by default" and whether the organization conducts Data Protection Impact Assessments (DPIAs), risk assessments and vendor assessments. Questions on pseudonymization, physical security, vulnerability management, secure disposal of data media and secure transmission follow.
Accountability then ties the principles to documents. A controller must be able to demonstrate compliance "through verifiable documentation," which the checklist lists as Records of Processing Activities (ROPA), DPIAs, internal policies, audit logs, consent logs and training records. Elkased put the point bluntly in his post: "It's not enough to have policies; you need verifiable documentation."
The Record of Processing Activities is required of controllers by Article 4-9 and of processors by Article 5-9, according to the checklist. A preliminary data inventory asks organizations to define personal and sensitive data in line with Article 1 of the law, to record storage locations including "geographic server locations, and data centers," to map data flows out to vendors and third parties, and to classify data at levels such as public, confidential and restricted. The controller record itself carries 15 elements, running from the contact details of the controller, its representative and the DPO through a "Record of consent," access control mechanisms, transfers to third countries with their safeguards, retention periods for each data category and the data subject rights available. The processor record carries eight. The PDPC has also published two ROPA templates, one for controllers and one for processors, according to law firm CMS.
European organizations received comparable tooling only recently. The European Data Protection Board adopted its first standardized DPIA template on March 10, 2026, almost eight years after the GDPR became applicable.
Six working days and an independent DPO
Section III asks whether acknowledgement of a data subject request is issued "within six working days, as legally required." That is a deadline for acknowledging a request, not for answering it; the checklist gives no figure for the substantive response. Internal procedures must cover nine rights: to be informed, access, withdrawal of consent, erasure, restriction of processing, data portability, objection, rectification and notification in the event of a data breach.
Other recently finalized regimes run on shorter clocks. Indonesia's implementing regulation, signed on July 16, 2026, gives controllers 72 hours to answer access, erasure and objection requests. Failures in request handling carry a cost where enforcement is established: France's regulator fined EXTIA 300,000 euros over 204 mishandled erasure requests.
The DPO section is among the most detailed in the document. It records whether the DPO is Egyptian or a foreign national, and whether the post-holder is an existing employee, a new hire or an external consultant. An existing employee may keep previous responsibilities, according to the checklist, provided "the conditions of independence are upheld" and the PDPC approved the role during registration. Where one DPO serves several controllers or processors, prior approval is needed and every entity involved must give written consent to the arrangement.
The DPO's duties, which the checklist bases on Article 9 of Law No. 151 of 2020, fill eight monitoring and evaluation questions. They include whether the DPO determines "the scope and frequency of compliance assessments" and ensures DPIAs and Transfer Impact Assessments (TIAs) are carried out. The DPO also notifies data subjects of a breach, oversees the ROPA and organizes staff training. The position tests are specific: a sufficiently senior post, independence, protection "against dismissal or disciplinary action" for performing the role, and a direct reporting line to "the highest level of management (e.g., CEO, Board of Directors)." A final box asks for professional certifications and names three: CIPP/E, CIPM and CIPT.
Timing is the practical constraint here. "With the compliance grace period running until 1 November 2026, there is still time, but the licensing and DPO registration processes are not instant," Elkased wrote.
A license before processing
Section V is where the Egyptian framework departs most visibly from European practice. Law firm CMS has described the regime as more formal than what multinational organizations meet elsewhere, with Egypt opting for prior authorization where the GDPR relies largely on accountability and self-assessment. The first question asks organizations to identify whether they qualify as a "Controller/Processor, or Processor" for licensing purposes. The second asks whether they are aware that "obtaining a license or a permit from the PDPC is required before processing personal data under the PDPL." A note defines processing in terms close to the GDPR's, running from collection and recording through retrieval, use and disclosure to "erasure or destruction."
Separate licensing questions follow for three activities. International transfers require a license or permit "once such procedures are formally issued," wording that indicates the transfer licensing procedure did not yet exist when the checklist was drafted. Conducting electronic marketing is "subject to obtaining a license or permit from PDPC." So is the installation and operation of visual surveillance tools in public places.
The checklist contains no fee figures. According to Elkased, the Executive Regulation set a tiered licensing fee structure based on the number of personal data records processed, and PPC Land's December 2025 coverage of the decreedescribed Article 19 fee tables that scale with database size. Smaller databases benefit from exemptions, according to law firm Clyde & Co. Recording Law, a legal reference website, put the fee exemption threshold at 100,000 records or fewer, noting that such entities still need the license or permit itself. The same site stated that, as of September 10, 2026, the PDPC had published no launch announcement for an online licensing portal. PPC Land has not independently verified the portal's status.
Transfers, adequacy and derogations
Section VI asks eight questions about data leaving Egypt. Organizations must identify the transfer basis for each external transfer and record every relevant jurisdiction together with its current adequacy status, an exercise the checklist frames as preparation "in anticipation of future PDPC determinations." The phrasing suggests the regulator has not yet published its own findings on which countries offer adequate protection. In Europe, by contrast, such decisions are adopted destination by destination by the European Commission.
Without an adequacy decision, organizations must apply "appropriate safeguards" under the PDPL and its Executive Regulation and ensure the data importer applies protection "equivalent to those under the PDPL." Where neither route is available, transfers may rest on "one of the limited derogatory cases permitted under the PDPL," each documented. The final question asks whether a transfer impact assessment has been "carried out and documented" to evaluate legal and technical risk.
For advertising technology, transfer rules operate at the level of individual data flows. Under the GDPR, a bid request carrying an IP address or device identifier to a demand-side platform bidding from another continent counts as a transfer. The Egyptian checklist does not address programmatic flows directly, though its website section requires organizations to identify every hosting, analytics and marketing vendor involved in their digital operations.
Electronic direct marketing
Section VII sits closest to day-to-day campaign work. It asks whether consent is obtained and verified "before sending any electronic communication for direct marketing," and whether messages go only to people who "have explicitly opted in." Organizations must also keep electronic records "evidencing the Data Subject's consent or non-objection to receive e-marketing communications, including any amendments, for a period of three years from the date of the last communication."
That retention clause adds "non-objection," a looser standard than the explicit opt-in required two questions earlier. Does non-objection suffice in some cases, and if so which? The checklist does not say.
Content rules are specific. Each message must identify "the sender and creator," carry a valid contact address and indicate that its purpose is direct marketing. Each communication needs a defined marketing objective. Recipients must be offered a clear option to decline from the outset, cannot be made to accept marketing as a condition of a service unless the communication is "objectively necessary" for that service, and must be able to opt out at any time through an accessible mechanism. A separate question asks whether people can manage the frequency, channel or type of content they receive. Another asks whether "the contact details of the Data Subject are not disclosed" in marketing messages, a test that bulk sends with visible recipient lists would fail.
The licensing requirement sits on top of all this. Regulators elsewhere have been tightening the measurement side of the same channel: France's CNIL adopted its final recommendation on email tracking pixels on March 12, 2026, requiring prior consent for open-rate tracking and audience profiling in most cases.
Cookies, pixels and SDKs
The final section applies to controllers, and processors acting on their behalf, that operate websites or mobile applications. According to the PDPC, these obligations are "complementary to, and must be implemented alongside" the rest of the checklist.
The cookie requirements sit close to the strictest reading of European practice. A banner must explain the use and purposes of "cookies, pixels, SDKs, or similar tracking technologies" and distinguish essential from non-essential types. Non-essential trackers must be "disabled by default and only activated after obtaining the user's explicit, informed consent." The consent interface must offer "granular options by category (e.g., performance, analytics, marketing), rather than relying solely on general acceptance or refusal." Choices must be recorded and "enforced across future sessions," users must be able to review, modify or withdraw them at any time, and the site or app must remain "fully usable and accessible" when every non-essential cookie is declined. The banner must link to the privacy notice, which in turn must be reachable from every page, for example through the footer or menu.
In European markets these functions are typically performed by a consent management platform that passes signals to downstream vendors. The Egyptian checklist names no framework or signal standard. Nor does it require a single-click reject button in so many words; its test is category-level granularity.
Enforcement of stored choices is where implementations have failed elsewhere. A class action filed in March 2026 alleges that Ace Hardware kept collecting and transmitting user data after visitors rejected all non-essential cookies. PPC Land has also documented a case in which a client's Google Ads conversions fell 90% overnight because a banner was collecting choices without transmitting them.
The reference to SDKs carries the same rules into apps, where tracking SDKs compiled into the code send session and event data to third-party servers. Further questions require organizations to identify every third party involved in website or app operations, bind processors contractually to PDPL obligations, check that each third party aligns with the published privacy notice and review third-party scripts and plugins for vulnerabilities. Content management systems must be "regularly updated and patched," and plugins "kept up to date and legally reviewed." A closing block requires a visible channel for privacy requests, such as a dedicated email address, contact form or in-app feature, backed by procedures to acknowledge receipt, verify the requester's identity and log the request, the steps taken, the outcome and the timeline.
A breach clock awaiting the regulator
Section X separates present obligations from future ones. The first block asks whether an incident response plan exists, whether it names every notification recipient, including the controller where the organization is a processor, and whether it sets procedures and timelines triggered on becoming aware of a breach.
The second block is headed "Anticipated Obligations upon Official Launch of PDPC." It asks whether the plan already provides for notifying the PDPC "within seventy-two (72) hours of becoming aware of a personal data breach," notifying the PDPC immediately where a breach affects national security, and notifying affected data subjects "within three (3) working days of notifying the PDPC." A note explains that the block tests "whether the current plan already reflects the statutory obligations (even if not yet enforceable)." Taken with the heading, the note indicates that the regulator did not regard its own official launch as complete when the document was written.
An annex draws a line between two terms. An incident is an event that may compromise the confidentiality, integrity or availability of personal data but "does not necessarily trigger notification obligations." A breach is defined as a "confirmed unauthorized disclosure of personal data, which requires notification to external parties under the PDPL." On its face, that definition is narrower than the GDPR's, which also covers the destruction, loss or alteration of personal data and unauthorized access to it. The checklist further asks for a designated Incident Response Team, documentation of each incident covering its description, the response and lessons learned, and employee training on reporting procedures.
The Egyptian sequence, 72 hours to the regulator followed by three working days to individuals, combines two existing models. An eight-year review of GDPR enforcement counted six jurisdictions with a 72-hour regulator deadline: the European Union, the United Kingdom, Thailand, Kenya, Nigeria and South Korea. Brazil allows three working days. India requires notification within six hours for significant data fiduciaries. Europe's clock may lengthen: the European Commission's Digital Omnibus draft would extend it from 72 to 96 hours and limit it to high-risk breaches.
Cameras and vendors
Two shorter sections cover ground that sits partly outside marketing operations. Section VIII, on visual surveillance in public places, asks for clear and visible notices, bars transferring or processing recordings outside Egypt "except where expressly permitted by law," and rules out facial recognition or similar identification technologies on personal images and video unless the law expressly permits it or the data subject has given explicit consent. Personnel operating the systems must be bound to confidentiality. The section does not mention digital out-of-home screens that estimate audiences with cameras.
Section IX, on vendors, asks whether assessment policies are followed across departments, whether vendor activities are monitored and audited, whether a clear termination process exists, and whether a risk assessment precedes engagement. Compliance certifications, privacy policies and information security policies are to be reviewed "before finalizing agreements," and privacy risks must be addressed in the contract. Vendor terms can shift quickly. Microsoft cut its notice period for new AI subprocessors to 30 days in a May 2026 update to its data protection addendum.
Dates that do not line up
The deadline itself is reported inconsistently. Elkased's post refers to a "compliance grace period running until 1 November 2026." Omar Sherif, a senior associate at Sharkawy & Sarhan, told OneTrust DataGuidance in February that the one-year grace period ends on October 31, 2026. Helmy, Hamza and Partners, Baker McKenzie's member firm in Egypt, put the compliance deadline at November 1, 2026. Counted from September 23, those dates are 38 and 39 days away. Sherif also said he expected the PDPC to show some flexibility, because the market only became aware of the regulation in late December, when the regulator posted it on its website.
The instrument is described in different ways too. Elkased refers to "Ministerial Decree No. 816 of 2025." Baker McKenzie describes it as a decree of the Minister of Telecommunications; Kennedys calls it a Prime Ministerial decree. Several law firms date its issuance to November 1, 2025, while PPC Land's December 2025 report dated its publication in Official Gazette Issue 244 to November 10, 2025. The checklist references none of these dates, and neither it nor Elkased's post resolves the differences.
Why the checklist matters to marketers
Egypt's regime is going live amid a cluster of national frameworks arriving within months of one another. India published its Digital Personal Data Protection Rules on November 13, 2025, with enforcement expected around May 2027. Vietnam issued Decree 356/2025/ND-CP on December 31, 2025. Indonesia's rules apply from January 2027. Each uses its own consent standard, transfer mechanics and timetable.
Much of the Egyptian checklist reads as GDPR-derived: lawful bases, minimization, DPIAs, a processing record, rights to portability and objection. The differences sit in the layers European compliance teams are least used to, above all prior licensing for processing, for transfers and for electronic marketing, and a guardian requirement that covers every data subject under 18. A campaign running in Egypt and the European Union at once puts the same cookie banner and the same email list under two regimes whose consent tests overlap without matching.
How quickly enforcement follows is a separate question. European experience counsels caution in reading rules as outcomes: the same eight-year review found close to 40% of the 7.1 billion euros in GDPR fines announced since 2018 annulled or under challenge by May 2026. The Egyptian checklist, by its own wording, was written for a regulator awaiting its official launch.
What the document does establish is the PDPC's reading of its own law, question by question, and the evidence it expects organizations to hold. Elkased closed his post with an open question to other practitioners: "Curious to hear where teams are finding the biggest gaps."
Timeline
- 2020: Egypt enacts Law No. 151 of 2020 on personal data protection
- November 2025: The European Commission's Digital Omnibus draft proposes extending GDPR breach notification from 72 to 96 hours
- November 10, 2025: Executive Decree 816 of 2025 appears in Egypt's Official Gazette, Issue 244; several law firms date its issuance to November 1
- November 2025: Amazon DSP adds Egypt to its unified in-market audience definitions
- November 13, 2025: India publishes its Digital Personal Data Protection Rules 2025
- December 31, 2025: Vietnam issues Decree 356/2025/ND-CP implementing its personal data law
- February 18, 2026: Turkey's data protection board rules that explicit consent and clarification texts must be separate
- March 10, 2026: The European Data Protection Board adopts its first standardized DPIA template
- March 12, 2026: France's CNIL adopts its final recommendation on email tracking pixels
- March 12, 2026: A class action alleges Ace Hardware tracked users who rejected non-essential cookies
- March 2026: IAB Europe's 2025 TCF compliance report finds 53% of audits flagging missing easy withdrawal
- May 2026: Analysis finds close to 40% of 7.1 billion euros in GDPR fines annulled or under challenge
- May 22, 2026: Microsoft cuts its AI subprocessor notice period to 30 days
- July 16, 2026: Indonesia signs Government Regulation No. 33 of 2026, with 72-hour response deadlines
- Week of September 21, 2026: Youssef M. Elkased shares the PDPC's undated 23-page compliance plan checklist on LinkedIn
- October 31 or November 1, 2026: The one-year grace period under the Executive Regulation ends, with sources differing on the exact date
Related PPC Land coverage
- Egypt finally implements data protection law after five-year delay - The December 2025 report on Executive Decree 816, its fee tables and its cross-border transfer rules.
- Data controllers face 2% revenue fines under Indonesia's new data rules - A 225-article implementing regulation with 72-hour deadlines for rights requests and breach notification.
- India launches comprehensive data protection rules with consent managers - India's registered consent manager model and its phased timeline to 2027.
- Vietnam implements comprehensive personal data decree on final day of 2025 - The decree that completed Vietnam's personal data regime.
- Turkey's DPA bans bundled consent texts in a ruling that reshapes data collection - A binding decision separating consent texts from information notices.
- TCF enforcement more than doubled in 2025, IAB Europe report shows - Audit failure rates for consent tools, including withdrawal mechanisms.
- Ace Hardware sued for tracking users who opted out of cookies - A lawsuit over data collection that allegedly continued after rejection.
- 19 groups ask EU to re-insert the cookie banner fix Google lobbied out - The fight over automated consent signals and the cost of banners that fail to transmit choices.
- CNIL's final rules on email tracking pixels are here - what changes - Which email tracking purposes now require consent in France.
- EDPB's first-ever DPIA template finally lands - but experts want more - The European template for impact assessments and its gaps.
- Eight years of GDPR: 40% of the EUR7.1B in fines annulled or under challenge - Enforcement durability and a cross-jurisdiction comparison of breach notification deadlines.
- European Commission proposes major GDPR changes for AI and data processing - The Digital Omnibus draft, including the 96-hour breach notification proposal.
- CNIL fines EXTIA 300,000 euros over 204 mishandled erasure requests - A penalty tied to the handling of data subject requests.
- Microsoft's DPA update cuts AI subprocessor notice to 30 days - How vendor contract changes compress third-party risk reviews.
- Amazon DSP expands in-market audiences to 32 countries with unified targeting - The November 2025 expansion that included Egypt.
Summary
Who: Egypt's Personal Data Protection Center (PDPC), the regulator under Law No. 151 of 2020, authored the checklist. Youssef M. Elkased, a data privacy and governance specialist and DPO at geidea, circulated it on LinkedIn. It concerns controllers and processors handling personal data connected to Egypt, including advertisers, publishers, email marketers, app operators and ad tech vendors.
What: An undated 23-page "Data Protection Compliance Plan Checklist" in 11 sections, scored Yes, No, Partial or NA. It covers scope, lawful basis and consent, children's and sensitive data, security, ROPA, data subject rights with a six-working-day acknowledgement, DPO independence, licensing, cross-border transfers, electronic marketing with three-year consent records, surveillance, vendors, breach response with 72-hour and three-working-day deadlines, and website and app rules requiring non-essential cookies to stay off until explicit consent.
When: The checklist circulated on LinkedIn during the week of September 21, 2026. It carries no publication date. The one-year grace period under the Executive Regulation ends on October 31 or November 1, 2026, depending on the source.
Where: Egypt, with reach extending to foreign controllers and processors located in Egypt and to any organization processing data about Egyptian citizens, wherever they reside.
Why: The checklist translates the law and its Executive Regulation into operational tests shortly before the grace period ends, and shows that several procedures, including transfer licensing and breach notification, were still anticipated rather than in force when it was written. For marketers, it sets out a prior-licensing model for data processing and electronic marketing that differs from the GDPR's accountability approach.
Discussion