Skip to content

Insights 6 min read

Egypt's data protection law and enterprise AI: what Law 151 of 2020 means for your AI projects

What Egypt's Law 151 of 2020 and its 2025 regulations mean for AI on customer and staff data: licences, transfers abroad, sensitive data and a checklist.

Egypt's Personal Data Protection Law, No. 151 of 2020, applies to any AI system that reads customer or employee records. Its executive regulations, issued in 2025, turn the law's principles into licences, registers and deadlines. For AI, the first question is where the data goes. A public AI service hosted abroad counts as a cross-border transfer, and the law restricts those.

What does Law No. 151 of 2020 cover?

The law protects personal data processed electronically: anything that identifies a person directly or indirectly, such as a name, national ID number, phone number, voice, photo or location.

If you run an AI model over your customer records, you are the controller: you decide why and how the data is processed. A vendor whose servers do the work is a processor.

Some data falls under other rules. The Central Bank of Egypt and the entities it supervises, for example, are largely excluded, with exceptions, so banks should confirm which regime applies.

Who enforces it?

The Personal Data Protection Center, a public authority affiliated with the Minister of Communications and Information Technology. It issues licences, keeps the registers of controllers, processors and data protection officers, receives breach reports and complaints, and can investigate.

The executive regulations fill in licence types and fees, the transfer rules and the breach procedure. The law gives organisations a period to adjust once the regulations are out. Law-firm briefings put the end of that window in late 2026; check the exact date with your counsel.

This is a summary, not legal advice. The law, its regulations and the Center's decisions are what count, and they can change. Confirm what applies to your sector and data with your own legal team and data protection officer.

What does the law ask of companies?

What Law 151 of 2020 expects, and what it means for an AI project
What the law expectsWhat it means for AI
Licence or permitControllers and processors hold a licence or permit from the CenterCheck that you and any AI vendor processing the data hold the right one
Data protection officerA DPO registered with the CenterBring the DPO in when you pick the use case, not after the build
Purpose and basisConsent or another basis the law allows, for a stated purposeData collected for billing is not automatically available for AI
Transfers abroadOnly with a licence, to countries with adequate protectionA public AI API hosted abroad is a transfer
SecurityTechnical and organisational safeguards, and records of processingAccess control, encryption and logs of prompts and answers
Breach notificationReport to the Center within 72 hours, tell affected people within 3 working daysYour logs must show what was exposed and whose data it was

Which data is sensitive?

The law lists sensitive categories: health data (physical, mental, psychological and genetic), biometric data, financial data, religious beliefs, political opinions and security status. All data about children is sensitive too. Processing sensitive data needs explicit written consent, from a parent or guardian in the case of children, and a licence from the Center.

That covers much of what companies want AI to read: patient files, salaries, transaction histories, student records.

  1. AI draftsReply, memo, or update
  2. Human approvesThe right role signs off
  3. Action runsIn your systems
  4. LoggedWho, what, when

Treat these use cases as your strictest tier. Keep them on infrastructure you control, limit who can query them, and have a person approve anything that leaves the system.

What rights do customers and employees have?

People can ask what data you hold about them and get a copy. They can withdraw consent, correct or erase their data, limit or object to processing, and be told when a breach affects them.

If a customer asks to be erased, can you find every copy, including the search index your assistant reads? A retrieval assistant (RAG) makes this manageable: delete the source and its index entry, and the record stops appearing in answers. A model fine-tuned on personal data is much harder to clean.

Public AI API or private deployment?

Public AI tool

Your organisation

Customer file
Public AI service

Outside your control, often abroad

Data leaves

Private AI with Seekers

Your environment

Customer file
AI core
Answer

Nothing leaves

When an employee pastes a customer record into a public AI service hosted outside Egypt, that record has been transferred abroad. The law then expects a transfer licence from the Center, a destination with adequate protection and, in most cases, the person's explicit consent. Few companies have these in place for an ad-hoc chatbot.

A private deployment runs the model on your own servers, or in a cloud inside Egypt that you control. The data stays in the country, so the transfer question does not come up for that workload. You still need your licence, a lawful basis, safeguards and a DPO. Private hosting removes one hard problem. The rest of the law still applies.

Public AI API compared with a private deployment under Egypt's law
Public AI API abroadPrivate deployment in Egypt
Where data goesProvider's servers, usually outside EgyptYour servers, or an in-country cloud you control
Transfer abroadYes: needs a licence and usually consentNot for this workload
Who processes the dataThe provider, under its termsYou, or a processor you appoint and audit
Erasure requestsDepends on the provider's retentionYou control the index and the logs
Breach investigationLimited to what the provider sharesFull logs inside your environment

What should you check before an AI pilot?

Go through these with your DPO, IT and legal team before anyone builds.

  1. 01ScopeWhich personal data will the AI read, and whose is it?Customers, staff, patients and students come with different conditions.
  2. 02LicenceDo you and your AI vendor hold the right licence or permit?The Center licenses controllers and processors separately.
  3. 03TransferWill any data, prompt or log leave Egypt?Cloud AI APIs, support tools and backups abroad can all count as transfers.
  4. 04TransferIf yes, do you have a transfer licence and consent?If not, keep that workload on infrastructure inside Egypt.
  5. 05RightsCan you find and erase one person's data everywhere the AI touches?Source documents, search index, logs and caches all hold copies.
  6. 06SecurityCould you report a breach to the Center within 72 hours?That needs logs of who asked what and which records came back.

Where should you start?

Seekers AI is headquartered in Cairo and builds private AI for Egyptian enterprises that runs inside the client's own infrastructure. Start with a Readiness Sprint of 2 to 3 weeks. We map the personal data each use case touches, flag sensitive categories and transfers, and recommend where the AI should run. Your DPO and counsel then review a concrete design.

  1. Readiness Sprint · 2–3 weeksUse cases, architecture, costed roadmap
  2. Pilot · 4–8 weeksOne use case live on your systems
  3. Run & Scale · MonthlyOperate, measure, add use cases

The pilot runs 4 to 8 weeks on your own servers, followed by monthly Run & Scale. See how the Private AI Launchpad works, or book a Readiness Sprint.