Business

Your Website and Egypt's Data Protection Law: Privacy Notices and Consent Before 1 November 2026

The grace period under Egypt's Personal Data Protection Law ends on 1 November 2026. What your website needs: an Arabic privacy notice, valid consent, marketing opt-ins, security, breach reporting and a checklist.

Illustration of a website contact form with an unticked consent box, an Arabic privacy notice and a padlock, next to a calendar marked 1 November 2026

Almost every company website in Egypt collects personal data: a contact form asks for a name and phone number, a careers page receives CVs, a newsletter box collects emails, and analytics tools record visitor behaviour. Until recently, many sites handled this with a copied privacy page in English or no page at all. That is changing. Egypt's Personal Data Protection Law No. 151 of 2020 now has Executive Regulations, and the one-year grace period to comply ends on 1 November 2026.

The short answer: before 1 November 2026, your website should have a privacy notice that is concise, clear, visible and in Arabic; collect only the data each form needs; obtain explicit, specific consent where consent is your legal basis, with an easy way to withdraw it; get prior consent before sending marketing messages; secure the data you collect; and know where your website tools store data, because transfers outside Egypt need authorisation. Behind the website, your company will also need to look at licensing with the Personal Data Protection Center and appointing a data protection officer.

This guide focuses on what shows up on your website and in the systems connected to it, in plain language. It is not a substitute for legal advice on your specific case.

Key takeaways

  • The Executive Regulations were issued by Ministerial Decree 816/2025 on 1 November 2025 and published in the Official Gazette on 25 December 2025. The grace period ends on 1 November 2026.
  • Privacy notices must be concise, intelligible, visible and in Arabic, and cover who you are, why you collect data, the legal basis, retention, rights and transfers.
  • Consent must be explicit, informed, specific and freely given, through an active choice, with easy withdrawal. Sensitive data and children's data need written consent.
  • Direct electronic marketing needs prior consent, clear sender identification, a simple opt-out, and a specific licence.
  • Breaches must be reported to the Personal Data Protection Center within 72 hours.

The timeline: why 1 November 2026 matters

Law 151/2020 was passed in 2020, but most of its practical detail depended on Executive Regulations. According to analyses published by CMS and Al Tamimi & Company, the regulations were issued by Ministerial Decree 816/2025 on 1 November 2025, published in the Official Gazette on 25 December 2025, and gave organisations a one-year period to comply. Enforcement is expected from 1 November 2026.

A website is usually the most visible part of a company's data handling. It is where customers, job applicants and regulators first see how you treat personal data, which makes it a sensible place to start.

Step 1: Map what your website collects

Before writing any policy, list every place your site touches personal data. A typical Egyptian company site has:

TouchpointData collectedWhere it goes
Contact or quote formName, phone, email, messageEmail inbox, CRM, WhatsApp
Careers pageCV, education, work history, sometimes ID or photoHR inbox or system
Newsletter signupEmail, sometimes nameEmail marketing tool
Booking form (clinics, services)Name, phone, appointment reason, sometimes health detailsBooking system
Chat or WhatsApp widgetPhone number, conversationChat provider, sales team
Analytics and ad pixelsDevice identifiers, IP address, browsing behaviourAnalytics and ad platforms, often abroad

For each row, note why you need the data, who can access it, how long you keep it, and whether it leaves Egypt. This map is the basis for your privacy notice, and it often reveals data you collect for no reason.

Step 2: Publish an Arabic privacy notice people can understand

CMS summarises the regulations as requiring privacy notices that are "concise, intelligible, visible, and in Arabic", including controller and DPO details, purposes, lawful bases, retention, rights and transfer information. In practice, your notice should answer:

  1. Who is the company responsible for the data, and how to contact its data protection officer.
  2. What data you collect through each form or tool.
  3. Why you collect it and on what legal basis.
  4. Who receives it, including service providers.
  5. Whether any data is transferred outside Egypt.
  6. How long you keep each type of data.
  7. How people can exercise their rights, and how to withdraw consent.

Write the Arabic version first, in plain language, then the English one. Link the notice from the footer of every page and place a short summary next to each form: one or two sentences with a link, not a wall of legal text.

Step 3: Design consent properly

What valid consent looks like

The regulations describe consent as explicit, informed, specific and freely given, through prominent, affirmative-action interfaces, with frictionless withdrawal. Written consent is required for sensitive data and for children's data (from a guardian). On a website that means:

  • Unticked boxes. The visitor ticks the box. A pre-ticked box is not an affirmative action.
  • Separate purposes. Consent to be contacted about a quote is not consent to receive marketing. Use a separate, optional checkbox for marketing.
  • Specific wording. "I agree to receive offers by WhatsApp and email from [company]" is specific. "I agree to the terms" is not.
  • Proof. Store when and how consent was given, and the wording shown at the time.
  • Easy withdrawal. An unsubscribe link in every email, a stop option in messages, and a contact point in the privacy notice.

Cookies and analytics

The public analyses of the regulations we reviewed do not set out a separate, detailed cookie rule. However, analytics identifiers and ad pixels can involve personal data, and many of these tools send data outside Egypt. A prudent approach is to load non-essential analytics and advertising tags only after the visitor agrees, explain them in the privacy notice, and confirm the exact requirements with a specialist as the Personal Data Protection Center issues further guidance.

Step 4: Marketing messages, WhatsApp and email lists

According to CMS and Al Tamimi, direct electronic marketing under the regulations requires prior consent, messages that identify the sender, and a free, simple way to opt out, and it requires a specific licence or permit. For Egyptian companies that rely on WhatsApp broadcasts or SMS offers, this is one of the biggest practical changes:

  • Collect marketing consent through a separate opt-in on your forms.
  • Start each message by identifying your company.
  • Honour opt-outs quickly and keep a suppression list.
  • Do not use numbers collected for support or quotes for promotions without consent.

Step 5: Security, retention and transfers outside Egypt

Security basics for website data

  • HTTPS on every page, with valid SSL certificates, so form data is encrypted in transit.
  • Access control: only the people who need form submissions or CVs can see them.
  • Form submissions stored in a secure system, not forwarded to personal email or shared phones.
  • Rate limiting and spam protection on forms and logins.
  • Backups, updates and logging, so you can detect and investigate incidents.

Breach notification

The regulations require controllers and processors to notify the Personal Data Protection Center within 72 hours of becoming aware of a personal data breach. CMS also notes a duty to inform affected individuals within three days of notifying the Center. Decide in advance who does what, because 72 hours pass quickly.

Retention

Set clear retention periods for each type of data, aligned with its purpose. For example, delete unsuccessful CVs after a defined period, and archive or delete old enquiries you no longer need.

Transfers outside Egypt

Transfers, storage or processing of personal data outside Egypt require a licence or permit and are allowed only to jurisdictions with adequate protection, according to Al Tamimi's summary. Hosting servers abroad, international CRM or email tools, and analytics platforms can all involve transfers. List them in your data map and discuss them with your legal adviser.

Beyond the website: licences and a DPO

Some obligations sit at company level rather than on the website, but you should know they exist:

  • Controllers and processors must obtain licences or permits from the Personal Data Protection Center, usually valid for three years. The Center has 90 working days to decide on complete applications.
  • Legal entities must appoint a data protection officer, registered with the Center.
  • People have rights to access, correct, erase, restrict and object to processing, and to withdraw consent, and you need a way to receive and log these requests.

Website compliance checklist

  1. Data map of all forms, tools and where data goes.
  2. Arabic privacy notice, linked in the footer and next to each form.
  3. Minimum fields on each form; no ID numbers unless truly needed.
  4. Unticked, separate consent boxes for marketing; consent records stored.
  5. Non-essential analytics and ad tags reviewed, and consent-based where appropriate.
  6. HTTPS everywhere; restricted access to submissions and CVs.
  7. Retention periods defined and applied.
  8. Transfers abroad identified and discussed with a legal adviser.
  9. A breach response plan with named people and a 72-hour timeline.

How Nilex helps

Nilex builds business websites with data protection designed in: minimal forms, separate consent options with stored records, Arabic and English privacy pages, secure storage of submissions, HTTPS and rate limiting. We work alongside your legal adviser, who defines the policy, while we implement it correctly on the site and in connected systems.

Frequently asked questions

When do companies in Egypt need to comply with the data protection law?

The Executive Regulations of Law 151/2020 were issued on 1 November 2025 with a one-year grace period, so enforcement is expected from 1 November 2026. Companies should be ready before that date.

Does my privacy policy have to be in Arabic?

According to published analyses of the regulations, privacy notices must be concise, intelligible, visible and in Arabic. You can also publish an English version, but the Arabic notice should not be missing.

Do I need consent for a simple contact form?

That depends on the legal basis for processing, which a legal adviser should confirm. Whatever the basis, tell people clearly what you will do with their data, and never treat a contact request as consent to marketing.

Can I send WhatsApp offers to customers who contacted us before?

Direct electronic marketing requires prior consent, sender identification, an easy opt-out and a specific licence under the regulations. Contacting you for a quote is not, by itself, consent to receive promotions.

What are the fines for violating the data protection law?

The law sets penalties, but we have not verified the exact amounts for this article. Check the current text of Law 151/2020 with a lawyer rather than relying on figures quoted online.

Get your website ready before the deadline

With the grace period ending on 1 November 2026, now is the time to review your forms, notices and tools. Contact Nilex for a free website data protection review, and we will give you a clear list of technical changes to discuss with your legal adviser.

This article is general information, not legal or tax advice. Confirm the details that apply to your company with a specialist.

LET'S BUILD

YOUR VISION.
OUR TECHNOLOGY.

Tell us what your business needs. We'll build the system around it.

START A CONVERSATION →

or email us at info@nilexdigitalsystems.com