跳至正文

埃及个人数据保护法:2020年第151号法律为你保障了什么?

自2020年起,埃及拥有了首部完整的个人数据保护法。本文解读第151号法律赋予每位公民哪些权利、对企业提出哪些义务,以及从法律条文到全面落地之间还差些什么。

发布于 2026年8月18日·7 分钟阅读
صفوف من خوادم الحاسوب المضيئة داخل مركز بيانات، في تجسيد للتخزين الرقمي للمعلومات الشخصية.

Every time an Egyptian orders food through an app, opens a bank account, or buys a mobile SIM card, personal information changes hands and travels to places the customer never sees: a name, a phone number, a home address, sometimes far more. For decades, that flow of data went largely unregulated. That changed in the summer of 2020, when Egypt issued Law No. 151 of 2020 on the Protection of Personal Data — the country's first comprehensive legislation governing how companies and institutions may collect, store, process, and use information about individuals.

The law has clear constitutional roots. Article 57 of the 2014 Constitution declares private life inviolable and grants correspondence and communications of all kinds protection that may only be lifted by a reasoned judicial order. Law 151 translates that constitutional principle into practical obligations for anyone handling citizens' data. It also arrived on a global legislative wave that followed Europe's General Data Protection Regulation, the GDPR, which inspired similar statutes in dozens of countries.

So what counts as "personal data" in the eyes of the law? The definition is deliberately broad: any data relating to an identified or identifiable natural person, directly or indirectly — from names and national ID numbers to location data and online identifiers. The law then carves out a more strictly protected category of "sensitive personal data", covering physical and mental health, biometric data, financial data, religious beliefs, political opinions, and criminal records, alongside children's data, which requires a guardian's consent.

The core principle underpinning the whole statute is consent. As a rule, personal data may not be collected, processed, or disclosed without the explicit consent of the person it belongs to, except in cases the law itself permits. Data must be gathered for legitimate, specific purposes declared to the data subject; it must be accurate and kept up to date; and it may not be retained longer than the purpose of collection requires.

The law hands the data subject a set of practically usable rights: the right to know what an organisation holds about you, the right to access it, the right to have inaccurate data corrected or amended, the right to erasure once the purpose has lapsed, the right to object to processing, and the right to withdraw previously given consent. It also establishes the right to be notified when a breach or leak affects your data.

To keep those rights from remaining ink on paper, the law created a dedicated regulator: the Personal Data Protection Center, affiliated with the Ministry of Communications and Information Technology. The Center licenses data controllers and processors, receives citizens' complaints, inspects entities subject to the law, issues guidance, and imposes administrative sanctions on violators.

Companies and institutions, in turn, face concrete obligations: appointing a data protection officer where required, keeping records of processing, taking technical and organisational measures to secure data, and notifying the Center within seventy-two hours of any breach. The law also regulates direct electronic marketing, requiring prior consent from the recipient, disclosure of the sender's identity, and a working way to opt out of messages at any time.

Transferring personal data outside the country is only lawful with a licence or permit from the Center, and on the condition that the receiving country offers a level of legal protection no weaker than Egypt's own. In an era of cloud computing — when Egyptians' data may sit on servers thousands of kilometres from Cairo — that condition carries real weight.

The law did not arrive toothless. Violations expose offenders to fines starting in the hundreds of thousands of pounds and reaching, for certain offences, into the millions, alongside custodial penalties in specific cases such as unlawful disclosure of sensitive data. Yet full application of the law was tied to executive regulations whose issuance lagged for years after the statute came into force — a delay specialists have documented as the clearest gap between the text and reality.

The law does not cover everyone and everything, either. There are defined exemptions, including data individuals process for purely personal use, data governed by special regulatory frameworks such as matters within the Central Bank's remit, and national-security considerations organised by other statutes. Understanding the law's limits is part of understanding your rights within it.

What should the ordinary citizen do with all this? Practically: skim privacy policies before agreeing to them, deny apps permissions their function does not need, ask the organisations you deal with what happens to your data, and keep records of your interactions. The law has given citizens tools that simply did not exist before — but their real value depends on people knowing about them, and on the enforcement machinery maturing in the years ahead.

相关报道

埃及个人数据保护法:2020年第151号法律为你保障了什么? | 公民之声