Insights 6 min read
Egypt's data protection law and enterprise AI: what Law 151 of 2020 means for your AI projects
What Egypt's Law 151 of 2020 and its 2025 regulations mean for AI on customer and staff data: licences, transfers abroad, sensitive data and a checklist.
Egypt's Personal Data Protection Law, No. 151 of 2020, applies to any AI system that reads customer or employee records. Its executive regulations, issued in 2025, turn the law's principles into licences, registers and deadlines. For AI, the first question is where the data goes. A public AI service hosted abroad counts as a cross-border transfer, and the law restricts those.
What does Law No. 151 of 2020 cover?
The law protects personal data processed electronically: anything that identifies a person directly or indirectly, such as a name, national ID number, phone number, voice, photo or location.
If you run an AI model over your customer records, you are the controller: you decide why and how the data is processed. A vendor whose servers do the work is a processor.
Some data falls under other rules. The Central Bank of Egypt and the entities it supervises, for example, are largely excluded, with exceptions, so banks should confirm which regime applies.
Who enforces it?
The Personal Data Protection Center, a public authority affiliated with the Minister of Communications and Information Technology. It issues licences, keeps the registers of controllers, processors and data protection officers, receives breach reports and complaints, and can investigate.
The executive regulations fill in licence types and fees, the transfer rules and the breach procedure. The law gives organisations a period to adjust once the regulations are out. Law-firm briefings put the end of that window in late 2026; check the exact date with your counsel.
This is a summary, not legal advice. The law, its regulations and the Center's decisions are what count, and they can change. Confirm what applies to your sector and data with your own legal team and data protection officer.
What does the law ask of companies?
| What the law expects | What it means for AI | |
|---|---|---|
| Licence or permit | Controllers and processors hold a licence or permit from the Center | Check that you and any AI vendor processing the data hold the right one |
| Data protection officer | A DPO registered with the Center | Bring the DPO in when you pick the use case, not after the build |
| Purpose and basis | Consent or another basis the law allows, for a stated purpose | Data collected for billing is not automatically available for AI |
| Transfers abroad | Only with a licence, to countries with adequate protection | A public AI API hosted abroad is a transfer |
| Security | Technical and organisational safeguards, and records of processing | Access control, encryption and logs of prompts and answers |
| Breach notification | Report to the Center within 72 hours, tell affected people within 3 working days | Your logs must show what was exposed and whose data it was |
Which data is sensitive?
The law lists sensitive categories: health data (physical, mental, psychological and genetic), biometric data, financial data, religious beliefs, political opinions and security status. All data about children is sensitive too. Processing sensitive data needs explicit written consent, from a parent or guardian in the case of children, and a licence from the Center.
That covers much of what companies want AI to read: patient files, salaries, transaction histories, student records.
- AI draftsReply, memo, or update
- Human approvesThe right role signs off
- Action runsIn your systems
- LoggedWho, what, when
Treat these use cases as your strictest tier. Keep them on infrastructure you control, limit who can query them, and have a person approve anything that leaves the system.
What rights do customers and employees have?
People can ask what data you hold about them and get a copy. They can withdraw consent, correct or erase their data, limit or object to processing, and be told when a breach affects them.
If a customer asks to be erased, can you find every copy, including the search index your assistant reads? A retrieval assistant (RAG) makes this manageable: delete the source and its index entry, and the record stops appearing in answers. A model fine-tuned on personal data is much harder to clean.
Public AI API or private deployment?
Public AI tool
Your organisation
Outside your control, often abroad
Data leaves
Private AI with Seekers
Your environment
Nothing leaves
When an employee pastes a customer record into a public AI service hosted outside Egypt, that record has been transferred abroad. The law then expects a transfer licence from the Center, a destination with adequate protection and, in most cases, the person's explicit consent. Few companies have these in place for an ad-hoc chatbot.
A private deployment runs the model on your own servers, or in a cloud inside Egypt that you control. The data stays in the country, so the transfer question does not come up for that workload. You still need your licence, a lawful basis, safeguards and a DPO. Private hosting removes one hard problem. The rest of the law still applies.
| Public AI API abroad | Private deployment in Egypt | |
|---|---|---|
| Where data goes | Provider's servers, usually outside Egypt | Your servers, or an in-country cloud you control |
| Transfer abroad | Yes: needs a licence and usually consent | Not for this workload |
| Who processes the data | The provider, under its terms | You, or a processor you appoint and audit |
| Erasure requests | Depends on the provider's retention | You control the index and the logs |
| Breach investigation | Limited to what the provider shares | Full logs inside your environment |
What should you check before an AI pilot?
Go through these with your DPO, IT and legal team before anyone builds.
- 01ScopeWhich personal data will the AI read, and whose is it?Customers, staff, patients and students come with different conditions.
- 02LicenceDo you and your AI vendor hold the right licence or permit?The Center licenses controllers and processors separately.
- 03TransferWill any data, prompt or log leave Egypt?Cloud AI APIs, support tools and backups abroad can all count as transfers.
- 04TransferIf yes, do you have a transfer licence and consent?If not, keep that workload on infrastructure inside Egypt.
- 05RightsCan you find and erase one person's data everywhere the AI touches?Source documents, search index, logs and caches all hold copies.
- 06SecurityCould you report a breach to the Center within 72 hours?That needs logs of who asked what and which records came back.
Where should you start?
Seekers AI is headquartered in Cairo and builds private AI for Egyptian enterprises that runs inside the client's own infrastructure. Start with a Readiness Sprint of 2 to 3 weeks. We map the personal data each use case touches, flag sensitive categories and transfers, and recommend where the AI should run. Your DPO and counsel then review a concrete design.
2–3 weeksUse cases, architecture, costed roadmap
4–8 weeksOne use case live on your systems
MonthlyOperate, measure, add use cases
- Readiness Sprint · 2–3 weeksUse cases, architecture, costed roadmap
- Pilot · 4–8 weeksOne use case live on your systems
- Run & Scale · MonthlyOperate, measure, add use cases
The pilot runs 4 to 8 weeks on your own servers, followed by monthly Run & Scale. See how the Private AI Launchpad works, or book a Readiness Sprint.