Egypt Personal Data Protection Law, Personal Data Infringement notification
Law No. 151 of 2020, Article 7 (Personal Data Infringement notification)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 16 October 2020.
A breach notification rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Notify the Personal Data Protection Center of any personal data breach within 72 hours of discovering it, and notify immediately where the breach concerns national security.
- Notify the Data Subject within 3 days of the date you notified the Center, telling them of the infringement and the procedures you have adopted about it.
- Be ready to give the Center a description of the infringement's nature, form and reasons and the approximate number of Personal Data and records affected, the Data Protection Officer's information, the potential consequences, the procedures followed and proposed to minimise the impact, and evidence documenting the infringement and the corrective actions taken.
What it reaches
Obligation class
Breach notice, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 7 requires the Controller and the Processor, as the case may be, to notify the Personal Data Protection Center of any Personal Data Infringement within seventy-two hours of the infringement, and to notify immediately where the infringement relates to national security protection concerns.
The Center then notifies the National Security Authorities immediately and, within seventy-two hours of becoming aware of the infringement, supplies them with a description of its nature, form and reasons and the approximate number of Personal Data and records affected, the Data Protection Officer's information, the potential consequences, a description of the procedures followed and proposed to minimise the negative impacts, evidence documenting the infringement and the corrective actions taken, and any further documents the Center requests.
In all events the Controller or Processor must notify the Data Subject within three days from the date it notified the Center, with the infringement and the procedures adopted about it. The Executive Regulations determine the procedures for that duty to notify and inform.
Article 7 of the promulgating law brings the annexed Personal Data Protection Law into force three months after the day following its publication in the Official Gazette, and the law was issued at the Presidency on 13 July 2020, so these provisions have bound since 16 October 2020.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometricsoperates_essential_service
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.