Business

CRM and Egypt's Data Protection Law: Consent, Marketing and Customer Data Retention

Your CRM holds most of your customers' personal data, so it is where Egypt's Data Protection Law 151/2020 becomes practical. Learn what the 2025 executive regulations mean for consent, marketing messages, retention, access and breaches before 1 November 2026.

Illustration of a CRM customer record with consent status, retention date and access lock icons

If your company keeps customer names, phone numbers, purchase history and chat logs in a CRM, Egypt's Personal Data Protection Law 151/2020 applies to that system. Its executive regulations were issued in November 2025, and the one-year period to comply ends on 1 November 2026. In practice, the CRM is where the law becomes daily work: how you record consent, who may send marketing messages, how long you keep leads, and who can export the customer list.

Most Egyptian companies did not design their CRM, Excel sheets or WhatsApp lists with these questions in mind. The good news is that the required changes are mostly clear system features and simple internal rules, not a rebuild.

This guide explains, in plain language and as far as published legal analyses support, what the regulations mean for a CRM, and gives a checklist you can review with your legal adviser and your software team.

Key takeaways

  • Customer data in your CRM is personal data under Law 151/2020; the executive regulations' compliance period ends on 1 November 2026.
  • Consent must be explicit, informed, specific and freely given, and you need a record of it.
  • Electronic direct marketing requires prior consent, sender identification, a free and simple opt-out, and a specific licence or permit.
  • You must set retention periods by purpose and be able to handle access, correction and deletion requests.
  • Access control, audit logs and a breach process are essential: breaches must be reported to the regulator within 72 hours.

The legal framework in brief

Law 151/2020 is Egypt's general personal data protection law. Its executive regulations were issued by Ministerial Decree 816/2025 on 1 November 2025 and published in the Official Gazette on 25 December 2025, starting a one-year compliance countdown (CMS, 2026). The regulator is the Personal Data Protection Center (PDPC).

According to published analyses by CMS and Al Tamimi and Company (2025), the main building blocks relevant to a CRM are:

  • Licences: controllers and processors need licences or permits from the PDPC, usually valid for three years, with separate permits for cross-border transfers and electronic direct marketing.
  • A data protection officer (DPO) registered with the PDPC.
  • Privacy notices that are concise, intelligible, visible and in Arabic.
  • Records of processing: purposes, categories of data and data subjects, lawful bases, retention periods, recipients and data locations.
  • Breach notification to the PDPC within 72 hours and to affected individuals within three days of that notification.

Penalty amounts are set in the law itself; we do not quote them here because they should be read from the official text with your lawyer.

Consent: what to record and how

CMS describes valid consent under the regulations as "explicit, informed, specific and freely given", collected through granular requests and an affirmative action. It also notes that consent is not suitable where the person has no real choice, or where access to a service is made conditional on consenting.

What this means for CRM fields and screens

  • Separate consent per purpose: for example, "contact me about my enquiry" is different from "send me offers". Use separate checkboxes, never pre-ticked.
  • A consent record on every contact: status, purpose, date and time, channel (website form, WhatsApp, in-store tablet), and the wording shown.
  • Withdrawal: an easy way to withdraw that updates the record immediately and stops related messages.
  • Imported lists: contacts imported from old spreadsheets should be marked "consent unknown" until confirmed.

Not everything needs marketing consent

Processing needed to answer a customer's enquiry or deliver an order is different from marketing. The regulations require you to document the lawful basis for each purpose, so your CRM should know why each piece of data is held. Ask your legal adviser to confirm the lawful basis for each of your processes.

Marketing messages from the CRM

This is the area where Egyptian companies are most exposed, because bulk SMS and WhatsApp offers are common. Based on the analyses above, electronic direct marketing requires:

  1. Prior consent from the recipient.
  2. Clear identification of the sender at the start of the message.
  3. A free, simple way to opt out or withdraw.
  4. A specific licence or permit for electronic direct marketing.
  5. No reuse of data for new purposes without new consent.

WhatsApp adds its own layer: Meta's policy requires opt-in that names your business. Our guide to WhatsApp-integrated CRM for sales teams covers the platform side.

System controls that prevent mistakes

  • Campaign audiences built only from contacts with active marketing consent.
  • Automatic suppression of opted-out contacts across SMS, email and WhatsApp.
  • Opt-out keywords ("stop", "إلغاء") handled automatically.
  • A log of every campaign: who sent it, to which segment, when.

Retention: how long to keep customer data

The regulations require retention periods aligned with the purpose of processing and with sector rules, recorded in your processing documentation (CMS). There is no single number for all data. You decide, document and enforce periods such as:

Data in the CRMTypical purposeWhat to decide
Leads that never boughtFollowing up an enquiryHow long after the last contact before deletion or anonymisation
Active customersService, orders, after-salesKept while the relationship is active
Invoices and transactionsTax and accounting obligationsTax rules may require longer retention; for example e-invoices are kept for 5 years under ETA requirements
Chat and call logsService quality, disputesA defined period, then deletion
Marketing consent recordsProving consentKept as long as you rely on the consent, and for a documented period after

The CRM should store a retention category and review date for each record, and run a scheduled job that deletes or anonymises records once the period ends.

Handling customer requests

Individuals have rights to access, correct, erase and restrict their data, to object, and to withdraw consent (Al Tamimi). The regulations also expect electronic logs of consents and of deletion and correction requests. In the CRM that means:

  • A way to find everything held about a person, including in linked systems such as invoicing and WhatsApp.
  • A request log: date received, type, who handled it, outcome, date closed.
  • Deletion that respects legal holds, such as invoices you must keep for tax purposes.

Access control, audit logs and breaches

Least privilege

A salesperson needs his own customers, not the full database. Role-based permissions, export restrictions and approval for bulk exports are the most effective protection against the common Egyptian scenario of a departing employee taking the customer list.

Audit trail

Record who viewed, edited, exported or deleted each record, and when. This supports investigations and demonstrates accountability.

Technical security

  • HTTPS everywhere, salted password hashing and secure session cookies.
  • Encrypted backups and tested restores.
  • Rate limiting and login protection against brute-force attacks.
  • Separate test data: never copy real customers into test systems.

A 72-hour breach process

Because the regulator must be notified within 72 hours of becoming aware of a breach, write the process now: who decides, who assesses what data was affected, who drafts the notification, and how affected customers will be contacted.

A CRM compliance checklist before 1 November 2026

  1. Map every place customer data lives: CRM, Excel, WhatsApp phones, email lists.
  2. Move customer data from personal phones and sheets into the controlled system.
  3. Add consent fields per purpose, with date, channel and wording.
  4. Rebuild marketing lists from contacts with valid consent.
  5. Define retention periods and automate review and deletion.
  6. Set roles, export restrictions and audit logs.
  7. Publish an Arabic privacy notice on every collection point.
  8. Document a request-handling and breach-response process.
  9. Check hosting location and transfers with your adviser.
  10. Review licensing and DPO requirements with a legal specialist.

How Nilex helps

Nilex builds CRM and ERP systems with privacy features designed in: consent records, marketing suppression, retention jobs, role-based permissions, audit logs and salted password hashing with HttpOnly session cookies. We can also review an existing CRM against the checklist above and plan the technical changes, while legal interpretation stays with your legal adviser. See our custom ERP and CRM development service.

Frequently asked questions

Does Egypt's data protection law apply to my small company's CRM?

If you process personal data of customers in Egypt, the law is relevant to you. Some obligations, such as licensing categories, may depend on your activity and size, so confirm the specifics with a legal adviser before the 1 November 2026 deadline.

Can I send WhatsApp or SMS offers to my existing customers?

Electronic direct marketing requires prior consent, sender identification and an easy opt-out, plus a specific licence or permit, according to published analyses of the regulations. Existing customers without recorded marketing consent should be asked before you send offers.

How long can I keep leads who never bought?

The regulations do not set one period for all data; you must set retention periods aligned with the purpose and document them. Decide a reasonable period after the last contact, then delete or anonymise automatically.

What happens if our customer data leaks?

The regulator must be notified within 72 hours of becoming aware of the breach, and affected individuals within three days of that notification. Prepare the process in advance, because 72 hours pass quickly.

What are the fines for violating the law?

The law sets penalties, but amounts should be read from the official text with your lawyer. Treat compliance as a system design task now rather than a reaction to enforcement.

The deadline is close, and most of the work is practical. Contact Nilex for a free consultation on making your CRM consent-aware, access-controlled and ready for 1 November 2026.

This article is general information, not legal or tax advice. Confirm the details that apply to your company with a specialist.

LET'S BUILD

YOUR VISION.
OUR TECHNOLOGY.

Tell us what your business needs. We'll build the system around it.

START A CONVERSATION →

or email us at info@nilexdigitalsystems.com