Health Data Is Sensitive Data: What Egypt's Data Protection Law Requires from Clinics
Clinics process some of the most sensitive personal data there is. This guide explains, in plain language, what Egypt's Law 151/2020 and its 2025 executive regulations mean for clinics and medical centres before the 1 November 2026 deadline, and which system controls help.

Under Egypt's Personal Data Protection Law 151/2020, health data is sensitive personal data, and its executive regulations, issued in November 2025, set stricter conditions for processing it. Published legal analyses describe these conditions as explicit written consent, a licence or permit, necessity for a legitimate purpose, and security controls approved by the regulator. The compliance period ends on 1 November 2026, so clinics and medical centres should be preparing now.
Every clinic handles this data daily: diagnoses, prescriptions, lab results, X-rays, therapy notes, even the fact that a person booked with a psychiatrist or a fertility specialist. Yet many clinics in Egypt still send results over staff WhatsApp, keep files on an unlocked reception PC, and share one password among the whole team.
This article explains, as far as published analyses support, what the law and regulations mean for a clinic, and what practical and technical steps reduce risk. It is not a substitute for advice from a lawyer who has read the official text.
Key takeaways
- Health data is a sensitive category under Law 151/2020, with stricter processing conditions than ordinary personal data.
- Published analyses describe explicit written consent, licensing, necessity and approved security controls as conditions for processing sensitive data.
- Clinics also face the general obligations: Arabic privacy notices, a registered DPO, records of processing, retention periods and breach notification within 72 hours.
- Children's data has extra consent rules involving guardians.
- Most risk sits in daily habits: WhatsApp on personal phones, shared passwords, unlocked screens and uncontrolled exports.
The law and the deadline
Law 151/2020 is Egypt's general data protection law. Its executive regulations were issued by Ministerial Decree 816/2025 on 1 November 2025 and published in the Official Gazette on 25 December 2025, starting a one-year compliance period that ends on 1 November 2026 (CMS, 2026). The regulator is the Personal Data Protection Center (PDPC).
According to CMS and Access Partnership (2026), the general framework includes licences for controllers and processors (usually valid for three years), a registered data protection officer, privacy notices that are concise, intelligible, visible and in Arabic, and breach notification to the PDPC within 72 hours. We do not state penalty amounts here; read them from the official text with your lawyer.
Extra conditions for sensitive health data
Al Tamimi and Company (2025) summarises the regulations' conditions for processing sensitive data as:
- Explicit written consent from the data subject.
- A licence or permit that matches the type of activity.
- Necessity for a legitimate purpose.
- Security controls approved by the Center.
It also notes that processing which harms data subjects is prohibited. Clinics should confirm with their legal adviser how these conditions apply to their specific activities, including which processing can rely on consent and which falls under other bases.
Children's health data
Paediatric, dental and school-health services process children's data. According to the same analysis, children under 15 need explicit written consent from a guardian, and for ages 15 to 18 consent may come from the child or the guardian depending on circumstances. Your registration forms and system should record who gave consent and in what capacity.
What this means in real clinic situations
| Situation | Risk | Better practice |
|---|---|---|
| Sending lab results over a receptionist's personal WhatsApp | Sensitive data on an uncontrolled device, no record of who sent what | Send from the clinic system or an official business account, with a log |
| One shared login for the reception PC | No accountability; anyone can open any file | Personal accounts, role-based permissions, automatic logout |
| Before-and-after photos on social media | Publishing health information about identifiable people | Treat as requiring specific written consent; confirm wording with your lawyer |
| SMS offers to all past patients | Direct marketing without prior consent | Separate marketing consent, sender identification, easy opt-out |
| Files on a USB stick taken home by a doctor | Loss or theft of unencrypted data | Secure remote access to the system instead of copies |
| Old paper files in an open corridor cabinet | Unauthorised access | Locked storage, defined retention, secure destruction |
The general obligations, applied to a clinic
An Arabic privacy notice
Tell patients, in clear Arabic, what data you collect, why, who receives it (labs, insurers, referral doctors), how long you keep it, and how they can exercise their rights. Show it at booking, on the website and at reception.
A data protection officer
The regulations require a DPO registered with the PDPC. For a small clinic this may be a role combined with other duties or an external service, subject to the qualification and independence rules; confirm the options with your adviser.
Records of processing
Document your purposes, categories of patients and data, lawful bases, retention periods, recipients and where data is stored. A clinic system can generate much of this from its configuration.
Patient rights
Patients can request access, correction and erasure, restrict or object to processing, and withdraw consent. Keep a log of requests and outcomes, and remember that deletion must respect any legal duty to keep certain medical or financial records.
Breach notification
Notify the PDPC within 72 hours of becoming aware of a breach, and affected individuals within three working days of that notification, per Al Tamimi. Decide now who leads, who assesses, and how patients will be informed.
Cloud hosting and transfers
If patient data is hosted outside Egypt, cross-border transfer rules apply, including a licence and transfer impact assessment. Include this in your hosting decision; our guide to electronic medical records in Egypt compares hosting options.
Labs, insurers and software vendors
Your clinic rarely processes data alone. Labs, radiology centres, insurers, the software company that hosts your system and the IT person who fixes the reception PC may all touch patient data. The regulations distinguish controllers from processors and license both, so list every partner that receives or hosts patient data, check what they do with it, and put written data protection terms in your contracts: purpose limits, security, confidentiality, breach notice to you, and return or deletion of data at the end.
System controls that make compliance practical
- Consent capture: signed or recorded explicit consent linked to the patient file, with date, purpose and who consented (patient or guardian).
- Separate marketing consent, never bundled with treatment consent.
- Least-privilege roles: clinical notes visible only to treating clinicians; reception limited to scheduling and billing.
- Audit log: who opened, edited, printed or exported each file, and when.
- Export controls: bulk exports disabled or approved by management.
- Secure sharing: results shared through the system with time-limited links rather than personal messaging.
- Encryption and backups: HTTPS, encrypted backups, salted password hashing and tested restores.
- Retention jobs: review dates per record category and secure deletion when periods end.
A clinic checklist before 1 November 2026
- List every place patient data lives: system, paper, WhatsApp phones, email, USB drives.
- Stop using personal devices for patient data; provide official channels.
- Update registration forms with explicit written consent and a separate marketing consent.
- Publish an Arabic privacy notice at booking, on the website and at reception.
- Give every staff member a personal account with a defined role.
- Turn on audit logs and restrict exports.
- Define retention periods and a secure destruction process for paper.
- Write a 72-hour breach response plan.
- Decide hosting location with your adviser and review transfer requirements.
- Review licensing and DPO requirements with a legal specialist.
- Train staff with real examples from your clinic.
How Nilex helps
Nilex builds clinic systems with the controls above designed in: consent records per patient and guardian, role-based access, audit logs, export restrictions, secure result sharing, encrypted backups and salted password hashing. We can review your current system against the checklist and implement the technical side, while your legal adviser handles licensing and interpretation. The PhysioTech Clinic project shows a clinic system with booking, patient records and session notes managed in one place.
Frequently asked questions
Is health data considered sensitive under Egyptian law?
Yes. Law 151/2020 treats health data as sensitive personal data, and the executive regulations set stricter conditions for processing it, including explicit written consent according to published analyses.
Does the law apply to a small private clinic?
If the clinic processes personal data of patients in Egypt, the law is relevant. How licensing and DPO requirements apply to a small clinic should be confirmed with a legal specialist before the 1 November 2026 deadline.
Can we send test results to patients on WhatsApp?
Sending sensitive data from staff's personal phones is a significant risk. Use the clinic system or an official business channel, confirm the patient's number and consent, and keep a record of what was sent.
Can we post before-and-after photos of patients?
Photos that identify a patient and reveal treatment are health information. Treat publication as requiring specific written consent and confirm the consent wording with your lawyer.
What should a clinic do if patient data leaks?
Contain the incident, assess what data was affected, and notify the PDPC within 72 hours of becoming aware of it, then notify affected patients within three working days of that notification. Having a written plan in advance makes this achievable.
Patient trust is a clinic's most valuable asset. Book a free consultation with Nilex to review how your clinic system handles consent, access and security before 1 November 2026.
This article is general information, not legal or tax advice. Confirm the details that apply to your company with a specialist.
Car Protection Center Management Software: 10 Features a PPF, Ceramic and Tint Center Needs30 September 2026 · 7 min
Film Stock by the Meter: How PPF and Tint Centers Stop Losing Money on Film30 September 2026 · 6 min
Car Check-In Reports and Digital Warranties: How Protection Centers Avoid Disputes30 September 2026 · 5 min
