AI

Using ChatGPT at Work in Egypt: Data Protection Limits on Customer Data

Your staff are probably already pasting emails, spreadsheets and customer chats into ChatGPT. Here is what Egypt's Personal Data Protection Law means for that habit, which accounts and settings matter, and how to write a practical AI use policy before 1 November 2026.

Illustration of an office laptop with ChatGPT open and a shield separating customer data from the chat window

In many Egyptian offices, ChatGPT has become a daily tool without anyone deciding it should. A sales rep pastes a customer's complaint to draft a polite reply. An accountant uploads a supplier statement to find a mismatch. HR asks for help summarising CVs. Each of these can move personal data outside your company, and often outside Egypt.

The short answer: Egypt's Personal Data Protection Law 151/2020 applies whenever employees put identifiable customer, patient or employee data into an AI tool. Its executive regulations were issued in November 2025, and the one-year grace period ends on 1 November 2026. You do not have to ban AI, but you need approved accounts, clear rules on what data may be used, and controls. This guide explains how, in plain language.

Key takeaways

  • Names, phone numbers, national IDs, addresses, order histories, health details and chat transcripts are personal data under Egyptian law.
  • Pasting them into an AI tool is processing, and when the service runs outside Egypt it can also be a cross-border transfer, which the regulations subject to licensing.
  • Consumer ChatGPT accounts may use conversations for model training by default; ChatGPT Business, Enterprise and the API do not by default, according to OpenAI.
  • The safest pattern: approved business accounts, anonymised or minimised inputs, and a written AI use policy that staff actually know.
  • Health and financial data need the strictest handling; keep them out of general AI chats unless a proper, approved integration exists.

Why this matters now

AI use is already widespread. Similarweb ranked chatgpt.com as Egypt's seventh most visited website in August 2026, and Microsoft's AI Economy Institute reported that 14.8% of Egypt's working-age population used generative AI tools in the first quarter of 2026. Much of that use happens at work, often on personal accounts.

At the same time, the data protection framework became enforceable in practice. According to CMS's January 2026 update, the executive regulations of Law 151/2020 were issued by Ministerial Decree 816/2025 on 1 November 2025, published in the Official Gazette on 25 December 2025, and gave companies one year to comply, until 1 November 2026.

What Egypt's data protection law means for AI use

Personal data and processing

Personal data is any information that identifies a person directly or indirectly. Almost everything your team handles about customers qualifies. Copying it into an AI tool, asking the tool to analyse it or storing the output are all forms of processing that must have a lawful basis and a specific purpose.

Licences, a DPO and Arabic notices

Under the executive regulations, controllers and processors must obtain licences or permits from the Personal Data Protection Center before processing, appoint a registered data protection officer, and give privacy notices that are clear and in Arabic. Al Tamimi's 2025 analysis also notes that controllers must keep a secure electronic register of consents, data categories, processing scope and retention schedules. If AI tools process customer data, they belong in that register.

Cross-border transfers

Major AI services are generally hosted outside Egypt. The regulations allow international transfers only with a licence, to jurisdictions assessed as offering adequate protection, with the data subject's consent and strong technical and organisational measures, according to the same Al Tamimi analysis. A company that sends customer data to a foreign AI service as a routine part of its work should treat that as a transfer question and take specialist advice.

Special category data

Health data and other special categories need explicit written consent, a licence suited to the activity and processing limited to what is necessary. A clinic receptionist pasting a patient's symptoms into a consumer chatbot is exactly the kind of use to prevent.

Breaches

If customer data leaks, for example through a shared chat link or a compromised employee account, controllers must notify the Center within 72 hours of becoming aware. Our guide on the 72-hour breach notification rule covers the response plan.

Not all ChatGPT accounts are the same

OpenAI treats individual and business products differently. According to OpenAI's help centre, content in individual ChatGPT accounts (Free, Plus, Pro) may be used to train models unless the user turns off "Improve the model for everyone" in Data controls. By default, OpenAI does not use inputs or outputs from ChatGPT Business, ChatGPT Enterprise, ChatGPT Edu or the API to improve its models.

OptionTraining on your data by defaultCompany controlSuitable for
Personal free or paid accountMay be used unless the user opts outNone; the employee owns the accountPublic, non-personal information only
ChatGPT Business or EnterpriseNo, per OpenAIAdmin controls, company-owned workspaceGeneral office work under a company policy
API inside your own systemNo, per OpenAI; abuse-monitoring logs kept up to 30 days by defaultFull: you decide what data is sentChatbots and automations built on your data

Business terms reduce risk but do not make every use lawful. The purpose, the data minimisation, the transfer question and your notices to customers still apply.

A traffic-light rule staff can remember

Green: fine on approved tools

  • Public information: published prices, website texts, general questions.
  • Drafting emails, posts or proposals without customer identifiers.
  • Internal documents that contain no personal data.

Amber: only after anonymising, on business accounts

  • Customer complaints with names, phone numbers and order numbers removed.
  • Sales figures aggregated by region rather than by named customer.
  • HR policy questions without any employee details.

Red: never in a general AI chat

  • National ID numbers, card or bank details, passwords.
  • Health information, lab results or diagnoses.
  • Full customer lists, CRM exports or payroll files.
  • Confidential contracts and legal disputes.

Practical controls that work

  1. Provide approved tools. If you ban AI without an alternative, staff will use personal accounts anyway. Give them a business workspace or an internal assistant.
  2. Minimise and anonymise. Teach staff to replace names with "Customer A" and remove numbers before pasting. For internal systems, strip identifiers automatically before text reaches the AI model.
  3. Control access. Use company accounts with single sign-on where possible, remove access when employees leave, and restrict shared chat links.
  4. Update your records and notices. Add AI tools to your processing register and review your Arabic privacy notice so customers know how their data is handled.
  5. Check the vendor terms. Review where data is processed, how long it is retained, and whether a data processing agreement is available.
  6. Train with real examples. A 30-minute session showing green, amber and red examples from your own business changes behaviour more than a long policy.

Building AI into your own systems

For recurring tasks such as answering customer questions or reading invoices, a controlled integration is safer than staff copy-pasting. Your system decides exactly which fields are sent, masks identifiers, logs every request and keeps customer records inside your own database, protected with measures like encryption and salted hashing. See ten practical uses of AI automation for where this pays off.

Three everyday scenarios

  • A real estate sales team in New Cairo wants AI to summarise leads. Safe route: an assistant inside the CRM that sends only the enquiry text with the name and number masked, not a CRM export pasted into a personal chat.
  • A clinic in Alexandria wants help drafting appointment reminders. Safe route: templates written once with AI, then filled by the booking system, with no patient details ever entering a chatbot.
  • A factory's HR department wants to compare CVs. Safe route: agree the criteria first, remove contact details, and keep final decisions with people.

What your AI use policy should cover

  • Which AI tools are approved, and for which roles.
  • The green, amber and red data categories, with examples from your business.
  • Who reviews AI output before it reaches a customer, and in which cases.
  • Rules for uploading files, sharing chats and using plugins or connectors.
  • How to report a mistake, such as personal data pasted into the wrong tool.
  • Who owns the policy (often the DPO) and when it is reviewed.

How Nilex helps

Nilex builds AI chatbots and assistants that run inside your own systems through the OpenAI API, so you control which data is sent, how identifiers are masked, and how long logs are kept. We design these integrations with access control, audit logs and data minimisation from the start.

Frequently asked questions

Is it legal for employees to use ChatGPT in Egypt?

Using ChatGPT is not prohibited. The legal questions start when employees enter personal data about customers, patients or colleagues. Then Egypt's Personal Data Protection Law applies, including its rules on purpose, consent, security and cross-border transfer.

Does ChatGPT train on what my employees type?

For individual accounts, OpenAI says content may be used for training unless the user opts out in Data controls. For ChatGPT Business, Enterprise, Edu and the API, OpenAI says it does not train on your data by default.

Can I paste a customer complaint into ChatGPT to draft a reply?

Only after removing the name, phone number, order number and anything else that identifies the customer, and preferably on an approved business account. Better still, use a reply assistant built into your CRM that masks data automatically.

Is sending data to ChatGPT a cross-border transfer?

It can be, because the service is generally hosted outside Egypt, and the executive regulations subject international transfers to licensing and safeguards. Ask a data protection specialist to assess your specific use.

What is the deadline to comply with the data protection regulations?

The executive regulations were issued on 1 November 2025 with a one-year grace period, which ends on 1 November 2026.

If you want AI in your workflows without putting customer data at risk, we can map your current use and propose a controlled setup. Book a free consultation through our contact page.

This article is general information, not legal or tax advice. Confirm the details that apply to your company with a specialist.

LET'S BUILD

YOUR VISION.
OUR TECHNOLOGY.

Tell us what your business needs. We'll build the system around it.

START A CONVERSATION →

or email us at info@nilexdigitalsystems.com