AI LAW RADAR · Daily Last verified 14 Sep 2026

Jurisdiction dossier

Egypt: AI regulation & deadlines

An AI obligation is in force, inside the data-protection framework rather than in a dedicated AI statute. Law No. 151 of 2020 on the Protection of Personal Data was gazetted on 15 July 2020 and entered into force on 16 October 2020, but stayed inoperative until its Executive Regulations were made by Ministerial Decree No. 816 of 2025, published in الوقائع المصرية No. 244 bis (A) of 1 November 2025 and applying from the day following publication, so from 2 November 2025; the Personal Data Protection Centre states that a one-year compliance period runs to 2 November 2026, which is the regulator's statement rather than anything the gazetted Regulations say. Two rules are tracked. Art. 4, first limb, item 7 binds the processor, when handling personal data for artificial-intelligence training operations and emerging and innovative technologies, to follow the principles recognised locally, regionally and internationally and to ensure the technologies are used in a way that causes the data subject no harm; the parallel controller article has no equivalent limb. Art. 14, item 5 bars data obtained from a child taking part in a game, competition or other activity from being used in classification, tracking or behavioural-monitoring operations, with no consent or parental-authorisation route out of it. Egypt has no GDPR art. 22 analogue: the Regulations' own index carries no automated-decision or profiling heading, and the Centre's own published framework enumerates nine data-subject rights under PDPL art. 2 — to be informed, of access, of withdrawal, of rectification, to erasure, to restrict, to object, of portability and to breach notification — none of which is an automated-decision right. The Centre's guidance treats automated decision-making as a fairness factor rather than a standalone right. The soft-law layer sits alongside: the National Council for Artificial Intelligence (2019), the Egyptian Charter for Responsible AI (2023), the National AI Strategy 2025-2030 and the Egyptian Center for Responsible AI with its AI Audit Lab; in January 2026 the Council became the National Council for Artificial Intelligence, Quantum Computing and Emerging Technologies. 2 obligations tracked — 2 in force.

None — No AI-specific law Flagship law: Executive Regulations of the PDPL arts. 4 and 14 (Ministerial Decree 816/2025)

An AI obligation is in force, inside the data-protection framework rather than in a dedicated AI statute. Law No. 151 of 2020 on the Protection of Personal Data was gazetted on 15 July 2020 and entered into force on 16 October 2020, but stayed inoperative until its Executive Regulations were made by Ministerial Decree No. 816 of 2025, published in الوقائع المصرية No. 244 bis (A) of 1 November 2025 and applying from the day following publication, so from 2 November 2025; the Personal Data Protection Centre states that a one-year compliance period runs to 2 November 2026, which is the regulator's statement rather than anything the gazetted Regulations say. Two rules are tracked. Art. 4, first limb, item 7 binds the processor, when handling personal data for artificial-intelligence training operations and emerging and innovative technologies, to follow the principles recognised locally, regionally and internationally and to ensure the technologies are used in a way that causes the data subject no harm; the parallel controller article has no equivalent limb. Art. 14, item 5 bars data obtained from a child taking part in a game, competition or other activity from being used in classification, tracking or behavioural-monitoring operations, with no consent or parental-authorisation route out of it. Egypt has no GDPR art. 22 analogue: the Regulations' own index carries no automated-decision or profiling heading, and the Centre's own published framework enumerates nine data-subject rights under PDPL art. 2 — to be informed, of access, of withdrawal, of rectification, to erasure, to restrict, to object, of portability and to breach notification — none of which is an automated-decision right. The Centre's guidance treats automated decision-making as a fairness factor rather than a standalone right. The soft-law layer sits alongside: the National Council for Artificial Intelligence (2019), the Egyptian Charter for Responsible AI (2023), the National AI Strategy 2025-2030 and the Egyptian Center for Responsible AI with its AI Audit Lab; in January 2026 the Council became the National Council for Artificial Intelligence, Quantum Computing and Emerging Technologies.

checked 14 Sep 2026 primary source ↗

The Register

2 obligations
Egypt Binding

Executive Regulations of the Personal Data Protection Law (Ministerial Decree 816/2025) art. 4 — a processor using personal data for AI training or emerging technologies must follow recognised local, regional and international principles and cause the data subject no harm

Binds المعالج, the processor, defined by Law 151/2020 as any natural or legal person who by virtue of their profession or expertise is authorised to process personal data on behalf of the controller under an agreement and on the controller's instructions; مادة (١) of the Regulations takes the Law's definitions unchanged. The duty is unqualified as to size, sector or data volume: it attaches to any processor that puts personal data through AI-training operations or emerging and innovative technologies. A processor established outside Egypt without a branch or representative office inside the country must, under مادة (٤) أولاً item 5, appoint a representative in Egypt approved by the Centre for the duration of its licence or permit, and a natural-person processor must appoint an agent inside Egypt, so the duty reaches extraterritorial AI-training work carried out on Egyptian personal data. Supervision is by المركز, the Personal Data Protection Centre, whose inspectors hold judicial-officer status under مادة (٤) أولاً item 4. Impact tier: all entities.. Article 4 of the Executive Regulations of Law No. 151 of 2020, headed «السياسات والإجراءات والضوابط والشروط والتعليمات والمعايير القياسية لالتزامات معالج البيانات الشخصية», sets out the processor's obligations in two limbs, أولاً the controls and technical standards and ثانيًا the procedures and policies. The seventh item of the first limb is Egypt's only express artificial-intelligence obligation: «٧- التزام المعالج بالتعامل مع البيانات الشخصية ، حال معالجتها واستخدامها لعمليات تدريب الذكاء الاصطناعى والتقنيات الناشئة والمبتكرة ، وفقًا للمبادئ المتعارف عليها محليًا وإقليميًا ودوليًا ، بما يضمن استخدام تلك التقنيات بالصورة التى لا يترتب عليها ثمة ضرر بالشخص المعنى بالبيانات .» — the processor is bound, when handling personal data in the course of processing it and using it for artificial-intelligence training operations and emerging and innovative technologies, to do so in accordance with the principles recognised locally, regionally and internationally, in a way that ensures those technologies are used in a form that entails no harm to the data subject. The clause is a duty of conduct with two components: an external-standards component, which imports whatever principles are «recognised» at the three named levels without naming an instrument, and a no-harm component, which is an outcome test on the data subject. It is not a right the data subject exercises, it is not conditioned on consent, and it carries no notice, reconsideration or human-review machinery. The sentence is the only occurrence of الذكاء الاصطناعى in the Regulations. Its placement matters and is reproduced here rather than smoothed over: the parallel controller article, مادة (٣) أولاً, runs to eight items and has no equivalent limb — its item 7 is the inspector-access duty and its item 8 the volume-and-quality duty — so on the face of the gazetted text the AI-training duty binds المعالج alone.

Primary source read: the certified gazette copy of the Executive Regulations published by the Personal Data Protection Centre itself, i.e. الوقائع المصرية — العدد ٢٤٤ تابع (أ) فى أول نوفمبر سنة ٢٠٢٥. The file is an MRC scan whose page text is JBIG2-coded with a /JBIG2Globals segment, which is why three earlier passes on this issue recorded it as unreadable; it is readable once the globals stream is prepended to the JBIG2 chunk list, and all 41 pages were decoded and read in the Arabic. Printed page 2 carries the enacting instrument, قرار وزير الاتصالات وتكنولوجيا المعلومات رقم ٨١٦ لسنة ٢٠٢٥ بإصدار اللائحة التنفيذية لقانون حماية البيانات الشخصية الصادر بالقانون رقم ١٥١ لسنة ٢٠٢٠; printed page 3 carries its المادة الأولى (the annexed Regulations are put into effect) and its المادة الثانية, «يُنشر هذا القرار فى الوقائع المصرية ، ويُعمل به من اليوم التالى لتاريخ نشره», signed د/ عمرو سميح طلعت. Gazette date 1 November 2025 and entry into force 2 November 2025 are therefore taken from the gazette, not from the regulator's website prose. The Regulations therefore bind from 2 November 2025, and that is the date carried on this row. Separately, the Centre states on its own site that a one-year compliance period runs from entry into force, i.e. to 2 November 2026. That period is reported rather than verified: it is not in the enacting decree's two articles and not in the Regulations' own text as gazetted, it derives from the transitional provision of Law 151/2020, and the Law's gazetted Arabic could not be read this run, so the 2 November 2026 date is stated here as the regulator's statement and is not relied on for the lifecycle. Checked negative, recorded so no later pass re-derives it: the Egyptian framework has NO GDPR art. 22 analogue. The Regulations' own الفهرس (printed pages 4 to 6) lists every heading through printed page 41 and contains no automated-decision or profiling heading; مادة (١) is a purely referential definitions article that takes the Law's definitions and adds none of its own; and the substantive articles 2 to 18 were read in full without finding a right not to be subject to a solely-automated decision. On the Law side, مادة (٢) of the Regulations, ثانيًا, item 1 confirms that PDPL art. 2 is the data-subject-rights article («إعلام الشخص المعنى بالبيانات بحقوقه وفق المادة (٢) من القانون»), and the Centre's own «Egypt's Personal Data Protection Framework» deck states at its page 12 that «the PDPL establishes nine fundamental rights for data subjects (PDPL Article 2)» and enumerates all nine — to be informed, of access, of withdrawal, of rectification, to erasure, to restrict, to object, of portability, and to be notified in case of data breach. No automated-decision or profiling right appears. The gazetted Arabic of the Law itself remains unreadable in this environment (the Centre's PDPL PDF draws every glyph as vector outlines, carries no text layer, no ToUnicode CMap and no page raster, and a full Wayback CDX sweep of mcit.gov.eg returns no copy of Law 151/2020), so the nine-rights list rests on a regulator publication rather than on statutory text and the absence of an art. 22 analogue is stated at that strength. The Centre's guidance treats automated decision-making as a factor inside the fairness principle rather than as a standalone right: its Data Protection Principles guideline lists «the use of automated decision-making and profiling: whether the processing involves automated decisions producing legal or significant effects on the data subject without human oversight» among the matters that bear on whether processing is fair. Coverage symmetry against the African rows already live — za-popia-s71, ke-dpa-s35, ng-ndpa-s37, gh-dpa-s41, rw-law058-2021-art21, tz-pdpa-s36, ma-loi0908-art11 and ug-dppa-s27 — Egypt is the odd one out and is deliberately not shaped like them. Every one of those eight is an automated-decision right sitting in a data-subject-rights chapter, whether of the UK Data Protection Act 1998 s. 12 lineage (Ghana, Tanzania, Uganda) or of the GDPR art. 22 lineage (Kenya, Nigeria, Rwanda, Morocco, South Africa). Egypt has no such right at all. What it has instead is a duty of conduct on the processing side, which is why this row is filed on the AI-training clause rather than on a rights article. One further AI-adjacent rule exists in the same instrument and is carried separately as eg-erpdpl-art14-children.

Stated maximum penalty — Not quantified here, deliberately. The Regulations create the duty but carry no fine of their own: enforcement runs through the licence and permit regime they build, under which a متحكم or معالج must hold a licence or تصريح from the Centre before collecting or processing at all (مادة (٢) أولاً item 1, مادة (٣) أولاً item 1 and مادة (٤) أولاً item 1), the Centre's inspectors are مأمورو الضبط القضائى with a right of access to the electronic records (مادة (٣) أولاً item 7, مادة (٤) أولاً item 4), and every licence application must carry an إقرار بالوفاء بالجزاءات المالية والتعويضات التى يقرها المركز (printed page 42, item 8). The monetary scale sits in the penalties chapter of Law 151/2020 itself, and that text could not be read from any reachable official host this run, so no figure is published rather than a figure taken from a secondary summary.

In force · 2 Nov 2025 checked 14 Sep 2026 Executive Regulations of the PDPL art. 4 (Ministerial Decree 816/2025) ↗ high confidence
Egypt Binding

Executive Regulations of the Personal Data Protection Law (Ministerial Decree 816/2025) art. 14 — data taken from a child who takes part in a game, competition or other activity may not be used to classify, track or behaviourally monitor children

Binds كل من المتحكم أو المعالج، بحسب الأحوال، سواء كان شخصًا طبيعيًا أو اعتباريًا — the controller or the processor as the case may be, natural or legal person — in the terms of the opening words of مادة (١٤). The trigger is the child's participation in a game, competition or other activity, so the duty reaches games publishers, competition and promotion operators, ad-tech and analytics recipients of that data, and education and entertainment platforms, without any size or sector threshold. «الطفل» takes its meaning from the Egyptian Child Law No. 12 of 1996, which the enacting decree recites among its legal bases; مادة (١٥) of the Regulations treats under-15s and the 15-to-18 band differently for consent purposes but مادة (١٤) item 5 draws no such line and refers simply to الأطفال. Supervision is by the Personal Data Protection Centre. Impact tier: all entities.. Article 14 of the Executive Regulations, headed «المعايير والضوابط الخاصة بالتعامل على البيانات الشخصية الحساسة», binds the controller and the processor alike, natural or legal person, whenever sensitive personal data is collected, transferred, stored, kept, processed or made available. Its fifth item is the closest thing in Egyptian law to a profiling prohibition: «٥- فى حالة مشاركة الطفل فى لعبة أو مسابقة أو أى نشاط آخر يجب ألا يتحصل منه على أكثر مما هو ضرورى للمشاركة وألا تُستخدم هذه البيانات فى عمليات تصنيف أو تتبع أو مراقبة سلوكية للأطفال .» — where a child takes part in a game, a competition or any other activity, no more may be obtained from the child than is necessary for the participation, and that data may not be used in classification, tracking or behavioural-monitoring operations on children. The rule has two limbs that operate independently: a data-minimisation limb tied to the purpose of participating, and a flat use prohibition on three named operations. The prohibition is absolute on its face — it is not subject to consent, not subject to a legitimate-interest balance, and carries no exception for a parent's or guardian's authorisation, which is a notable contrast with the rest of the children's regime in مادة (١٥), where written parental consent is what unlocks processing for under-15s and the child's own consent joins it from 15 to 18. «تصنيف» (classification), «تتبع» (tracking) and «مراقبة سلوكية» (behavioural monitoring) are not defined in the Regulations, and the Centre's published bilingual glossary is a term list without definitions, so the scope of the three operations is not further specified in any primary text read here.

Primary source read: the certified gazette copy of the Executive Regulations published by the Personal Data Protection Centre itself, i.e. الوقائع المصرية — العدد ٢٤٤ تابع (أ) فى أول نوفمبر سنة ٢٠٢٥. The file is an MRC scan whose page text is JBIG2-coded with a /JBIG2Globals segment, which is why three earlier passes on this issue recorded it as unreadable; it is readable once the globals stream is prepended to the JBIG2 chunk list, and all 41 pages were decoded and read in the Arabic. Printed page 2 carries the enacting instrument, قرار وزير الاتصالات وتكنولوجيا المعلومات رقم ٨١٦ لسنة ٢٠٢٥ بإصدار اللائحة التنفيذية لقانون حماية البيانات الشخصية الصادر بالقانون رقم ١٥١ لسنة ٢٠٢٠; printed page 3 carries its المادة الأولى (the annexed Regulations are put into effect) and its المادة الثانية, «يُنشر هذا القرار فى الوقائع المصرية ، ويُعمل به من اليوم التالى لتاريخ نشره», signed د/ عمرو سميح طلعت. Gazette date 1 November 2025 and entry into force 2 November 2025 are therefore taken from the gazette, not from the regulator's website prose. The item was read at printed page 20 of that issue, where مادة (١٤) items 5 to 7 continue from items 1 to 4 at printed page 19. It is carried as a separate row from eg-erpdpl-art4-ai-training because it binds a different set of actors (controller and processor, not the processor alone), rests on a different trigger (a child's participation, not the use of a training technique), and is a prohibition rather than a standard of conduct. Checked negative, recorded so no later pass re-derives it: the Egyptian framework has NO GDPR art. 22 analogue. The Regulations' own الفهرس (printed pages 4 to 6) lists every heading through printed page 41 and contains no automated-decision or profiling heading; مادة (١) is a purely referential definitions article that takes the Law's definitions and adds none of its own; and the substantive articles 2 to 18 were read in full without finding a right not to be subject to a solely-automated decision. On the Law side, مادة (٢) of the Regulations, ثانيًا, item 1 confirms that PDPL art. 2 is the data-subject-rights article («إعلام الشخص المعنى بالبيانات بحقوقه وفق المادة (٢) من القانون»), and the Centre's own «Egypt's Personal Data Protection Framework» deck states at its page 12 that «the PDPL establishes nine fundamental rights for data subjects (PDPL Article 2)» and enumerates all nine — to be informed, of access, of withdrawal, of rectification, to erasure, to restrict, to object, of portability, and to be notified in case of data breach. No automated-decision or profiling right appears. The gazetted Arabic of the Law itself remains unreadable in this environment (the Centre's PDPL PDF draws every glyph as vector outlines, carries no text layer, no ToUnicode CMap and no page raster, and a full Wayback CDX sweep of mcit.gov.eg returns no copy of Law 151/2020), so the nine-rights list rests on a regulator publication rather than on statutory text and the absence of an art. 22 analogue is stated at that strength. The Centre's guidance treats automated decision-making as a factor inside the fairness principle rather than as a standalone right: its Data Protection Principles guideline lists «the use of automated decision-making and profiling: whether the processing involves automated decisions producing legal or significant effects on the data subject without human oversight» among the matters that bear on whether processing is fair. The practical effect is that Egypt regulates profiling only where children are concerned and only as a use prohibition, with no general profiling right or general profiling ban for adults anywhere in the Law or the Regulations as read.

Stated maximum penalty — Not quantified here, deliberately. The Regulations create the duty but carry no fine of their own: enforcement runs through the licence and permit regime they build, under which a متحكم or معالج must hold a licence or تصريح from the Centre before collecting or processing at all (مادة (٢) أولاً item 1, مادة (٣) أولاً item 1 and مادة (٤) أولاً item 1), the Centre's inspectors are مأمورو الضبط القضائى with a right of access to the electronic records (مادة (٣) أولاً item 7, مادة (٤) أولاً item 4), and every licence application must carry an إقرار بالوفاء بالجزاءات المالية والتعويضات التى يقرها المركز (printed page 42, item 8). The monetary scale sits in the penalties chapter of Law 151/2020 itself, and that text could not be read from any reachable official host this run, so no figure is published rather than a figure taken from a secondary summary.

In force · 2 Nov 2025 checked 14 Sep 2026 Executive Regulations of the PDPL art. 14 (Ministerial Decree 816/2025) ↗ high confidence

Questions & answers

From the data

When does Executive Regulations of the PDPL arts. 4 and 14 (Ministerial Decree 816/2025) take effect in Egypt?

Executive Regulations of the PDPL arts. 4 and 14 (Ministerial Decree 816/2025) is already in force, with obligations live since November 2, 2025. An AI obligation is in force, inside the data-protection framework rather than in a dedicated AI statute. Law No. 151 of 2020 on the Protection of Personal Data was gazetted on 15 July 2020 and entered into force on 16 October 2020, but stayed inoperative until its Executive Regulations were made by Ministerial Decree No. 816 of 2025, published in الوقائع المصرية No. 244 bis (A) of 1 November 2025 and applying from the day following publication, so from 2 November 2025; the Personal Data Protection Centre states that a one-year compliance period runs to 2 November 2026, which is the regulator's statement rather than anything the gazetted Regulations say. Two rules are tracked. Art. 4, first limb, item 7 binds the processor, when handling personal data for artificial-intelligence training operations and emerging and innovative technologies, to follow the principles recognised locally, regionally and internationally and to ensure the technologies are used in a way that causes the data subject no harm; the parallel controller article has no equivalent limb. Art. 14, item 5 bars data obtained from a child taking part in a game, competition or other activity from being used in classification, tracking or behavioural-monitoring operations, with no consent or parental-authorisation route out of it. Egypt has no GDPR art. 22 analogue: the Regulations' own index carries no automated-decision or profiling heading, and the Centre's own published framework enumerates nine data-subject rights under PDPL art. 2 — to be informed, of access, of withdrawal, of rectification, to erasure, to restrict, to object, of portability and to breach notification — none of which is an automated-decision right. The Centre's guidance treats automated decision-making as a fairness factor rather than a standalone right. The soft-law layer sits alongside: the National Council for Artificial Intelligence (2019), the Egyptian Charter for Responsible AI (2023), the National AI Strategy 2025-2030 and the Egyptian Center for Responsible AI with its AI Audit Lab; in January 2026 the Council became the National Council for Artificial Intelligence, Quantum Computing and Emerging Technologies.

Who must comply with AI rules in Egypt?

Current obligations bind, among others, المعالج, the processor, defined by Law 151/2020 as any natural or legal person who by virtue of their profession or expertise is authorised to process personal data on behalf of the controller under an agreement and on the controller's instructions; مادة (١) of the Regulations takes the Law's definitions unchanged. The duty is unqualified as to size, sector or data volume: it attaches to any processor that puts personal data through AI-training operations or emerging and innovative technologies. A processor established outside Egypt without a branch or representative office inside the country must, under مادة (٤) أولاً item 5, appoint a representative in Egypt approved by the Centre for the duration of its licence or permit, and a natural-person processor must appoint an agent inside Egypt, so the duty reaches extraterritorial AI-training work carried out on Egyptian personal data. Supervision is by المركز, the Personal Data Protection Centre, whose inspectors hold judicial-officer status under مادة (٤) أولاً item 4. Impact tier: all entities.; كل من المتحكم أو المعالج، بحسب الأحوال، سواء كان شخصًا طبيعيًا أو اعتباريًا — the controller or the processor as the case may be, natural or legal person — in the terms of the opening words of مادة (١٤). The trigger is the child's participation in a game, competition or other activity, so the duty reaches games publishers, competition and promotion operators, ad-tech and analytics recipients of that data, and education and entertainment platforms, without any size or sector threshold. «الطفل» takes its meaning from the Egyptian Child Law No. 12 of 1996, which the enacting decree recites among its legal bases; مادة (١٥) of the Regulations treats under-15s and the 15-to-18 band differently for consent purposes but مادة (١٤) item 5 draws no such line and refers simply to الأطفال. Supervision is by the Personal Data Protection Centre. Impact tier: all entities.. Scope and thresholds vary per instrument — see each row's source for the legal text.

What are the penalties for AI non-compliance in Egypt?

Stated statutory maxima include: Executive Regulations of the PDPL art. 4 (Ministerial Decree 816/2025) — Not quantified here, deliberately. The Regulations create the duty but carry no fine of their own: enforcement runs through the licence and permit regime they build, under which a متحكم or معالج must hold a licence or تصريح from the Centre before collecting or processing at all (مادة (٢) أولاً item 1, مادة (٣) أولاً item 1 and مادة (٤) أولاً item 1), the Centre's inspectors are مأمورو الضبط القضائى with a right of access to the electronic records (مادة (٣) أولاً item 7, مادة (٤) أولاً item 4), and every licence application must carry an إقرار بالوفاء بالجزاءات المالية والتعويضات التى يقرها المركز (printed page 42, item 8). The monetary scale sits in the penalties chapter of Law 151/2020 itself, and that text could not be read from any reachable official host this run, so no figure is published rather than a figure taken from a secondary summary.; Executive Regulations of the PDPL art. 14 (Ministerial Decree 816/2025) — Not quantified here, deliberately. The Regulations create the duty but carry no fine of their own: enforcement runs through the licence and permit regime they build, under which a متحكم or معالج must hold a licence or تصريح from the Centre before collecting or processing at all (مادة (٢) أولاً item 1, مادة (٣) أولاً item 1 and مادة (٤) أولاً item 1), the Centre's inspectors are مأمورو الضبط القضائى with a right of access to the electronic records (مادة (٣) أولاً item 7, مادة (٤) أولاً item 4), and every licence application must carry an إقرار بالوفاء بالجزاءات المالية والتعويضات التى يقرها المركز (printed page 42, item 8). The monetary scale sits in the penalties chapter of Law 151/2020 itself, and that text could not be read from any reachable official host this run, so no figure is published rather than a figure taken from a secondary summary.. These are the maximum amounts in the instruments; actual enforcement is at the regulator's discretion.