← Back to ResourcesStorage abroad is a transfer: what Egypt's PDPL Executive Regulations ask of your architecture
10 August 2026 · Raversys · 9 min read

Storage abroad is a transfer: what Egypt's PDPL Executive Regulations ask of your architecture

Egypt's PDPL Executive Regulations define cross-border transfer to include storage. That single clause turns compliance from a legal workstream into an infrastructure decision — and the usable runway is about five months, not twelve.

Egypt's Personal Data Protection Law has been on the books since 2020, but it was largely unenforceable without implementing rules. Those rules now exist. The Executive Regulations were issued on 1 November 2025 and came into force the following day, opening a transition period of roughly twelve months.

Most of the commentary since has treated this as a legal workstream — update the privacy notice, paper the vendor contracts, appoint someone to own it. That reading misses the part that costs money. Buried in the definitions is a clause that turns compliance into an infrastructure problem: cross-border transfer is defined to include storage.

If your customer records sit on a server outside Egypt, you are not merely holding data. Under this regime you are conducting a continuous cross-border transfer, every second of every day, whether or not a single byte moves. That is a question about where your systems live, and no amount of policy drafting answers it.

Storage location determines transfer status under Egypt's PDPL Personal data stored on infrastructure inside Egypt is ordinary storage. The same data stored on infrastructure outside Egypt is treated as a continuous cross-border transfer, requiring adequate destination protection and authorisation from the Personal Data Protection Center. Hosted inside Egypt Hosted outside Egypt Storage No transfer. No licence needed on residency grounds. Continuous cross-border transfer Even at rest. Even if nothing moves. Article 14 authorisation required.

The clause that changes the scope

Article 14 prohibits transferring personal data outside Egypt without two things: adequate protection at the destination, and authorisation from the Personal Data Protection Center. Read alongside the definition above, this means foreign hosting requires a licence.

The consequences are not administrative. Article 42 makes violation a criminal matter, carrying imprisonment of no less than three months and fines between EGP 500,000 and EGP 5,000,000. Penalties double on repeat offence, and convictions must be published in two newspapers and on electronic networks — at the convicted party's own expense.

For most Egyptian organisations, the practical translation is blunt. Your CRM, your helpdesk, your payroll platform, your analytics warehouse, your object storage, your backup targets, your disaster-recovery region — each one is either inside Egypt, or licensed, or a live exposure.

Six places it diverges from GDPR

Teams that invested in GDPR programmes often assume they are substantially covered. They are not. The divergences are structural rather than cosmetic:

GDPR Egypt PDPL
Licensing No general licence to process Every legal entity requires a licence; no small-business exemption
Subject request window One month, extendable Six working days
DPO Required only in defined cases Mandatory, and the individual must be qualified, examined and registered in Egypt
Transfer mechanisms SCCs, BCRs, adequacy decisions None of these exist; each transfer is licensed individually
Language Plain language, any official language Notices and forms must be in Arabic
Regulator silence Varies Non-response to an application means rejection, not approval

Two of these deserve emphasis. The six working day response window is the one most existing processes cannot survive; teams built around a thirty-day clock typically discover that simply locating every record about one person takes longer than the entire statutory period. And a group DPO sitting in London or Dubai does not satisfy the requirement — the certification is Egyptian and personal, and it cannot be delegated across a corporate structure.

There is also a live question over whether the regime provides anything equivalent to a legitimate interests basis. If it does not, common security and fraud-prevention processing loses the lawful basis most European programmes rely on. We flag this as unresolved rather than settled — see the open questions below.

Seven questions your architecture has to answer

Compliance here reduces to whether your systems can answer a specific set of questions on demand. We use this list as the opening diagnostic:

  1. Where is every copy? Not just production — replicas, nightly backups, DR standby, the analytics warehouse, and every SaaS tool holding customer records in a field someone forgot about.
  2. Will you notice when a vendor moves? SaaS providers change regions and swap sub-processors. Does your contract give you notice, and would anyone act on it?
  3. Can the regulator read your records unaided? Processing records must be electronic and accessible such that the Center can inspect them without a third party interpreting them. An internal spreadsheet with bespoke abbreviations does not clear this bar.
  4. Can you find one person in six working days? Across every system, including the ones not connected to your identity provider.
  5. Can you prove erasure? Deletion everywhere, backups included, with documented confirmation. Most backup architectures are designed specifically to make this hard.
  6. Would you know about a breach within seventy-two hours? Notification to the Center follows within three days of awareness, so detection latency consumes your notification budget.
  7. How many records do you hold, in total? This determines your fee band and your DPO tier. Organisations are routinely wrong about this by an order of magnitude.

If the answer to any of these requires a week of manual work, that is not a documentation gap. It is an integration gap.

Banking, and the carve-outs that are narrower than they look

The Central Bank of Egypt and the entities it supervises are exempt from the PDPL — with an express exception for money transfer and currency exchange companies, which are pulled back in.

Banks should not read this as relief. The CBE's own outsourcing framework prohibits using service providers located outside Egypt, which arrives at the same destination by a different road. Regulated banks keep data domestic either way.

Other exemptions cover personal data held for genuinely personal use, official statistics, exclusively journalistic work, judicial records, and the national security authorities. Note what is not on that list: medical records are not exempt, and they carry the heightened obligations attaching to sensitive data. Healthcare providers and the platforms serving them have the strictest version of this problem, not the loosest.

The exposure with no ceiling

An EGP 5,000,000 maximum fine reads as survivable for a mid-sized enterprise. That figure is the wrong number to plan against, for two reasons.

The first is the publication requirement. A conviction that must be advertised in two newspapers and online, paid for by the convicted party, is a reputational event priced well above the fine.

The second is civil liability, which carries no statutory cap. In a case before the Alexandria Economic Court, an individual was awarded EGP 10,000,000 against a telecom operator over an unauthorised SIM replacement. The court treated the PDPL as establishing strict liability under Article 178 of the Civil Code, requiring only proof of a hazardous object — and rejected defences based on third-party fraud, employee error and technical failure alike.

If that reasoning holds and is followed, the civil channel is the larger number, and the defences most incident response plans are built around do not apply.

The runway is shorter than the calendar suggests

Twelve months of transition sounds comfortable. The arithmetic disagrees.

The Center is expected to be fully operational around November 2026, with licensing applications opening then and its application portal anticipated during 2026. Licensing decisions take up to ninety working days — roughly four and a half calendar months.

Egypt PDPL transition period and the compressed filing window The Executive Regulations came into force in November 2025 with a transition period ending in late 2026. Because licensing decisions take up to ninety working days, roughly four and a half months, the window in which an application can realistically be filed and decided before the deadline is far shorter than the full transition period. USABLE FILING WINDOW 90 WORKING DAYS Nov 2025 Regulations in force Nov 2026 Center fully operational, licensing opens Portal expected Applications open Transition ends Late 2026 A twelve-month transition, but a late application may never be decided in time. Realistic runway: closer to five months than twelve.

Work backwards from a transition period ending in late 2026 and the usable window for filing, receiving a decision, and remediating anything the decision surfaces is closer to five months than twelve. An application filed late in the period may simply not be decided before the deadline passes. Any system relocation you discover you need has to happen before that, not after.

What we would do in the next twelve weeks

Sequence matters more than effort here. Our recommended order:

  1. Count the records. Everything else — fee band, DPO tier, scope of the licensing application — depends on a number most organisations do not have.
  2. Map the systems. Physical location, vendor, sub-processors, and what your contract says about notice of change. This is the artefact the whole programme runs on.
  3. Appoint and accredit the DPO now. Longest lead time of anything on this list, gated on an Egyptian examination, and not delegable to an overseas colleague. Start it in week one.
  4. Fix the six-day clock before anything else technical. If you cannot answer a subject request in six working days, every other control is theatre.
  5. Audit SaaS contracts for region and sub-processor terms. Raise the problematic clauses in writing at renewal, not by phone.
  6. Only then decide what moves. Some systems have to come back to Egypt. Others can stay abroad under licence. The split is almost never where teams expect it before the mapping is done.

Note the ordering: the decision about what to relocate comes last, because it is the only expensive step and the first five determine its scope.

Where this is still uncertain

We would rather publish the open questions than imply more certainty than exists:

  • The exact end date of the transition period (31 October versus 1 November 2026) is reported inconsistently.
  • Whether the Center's portal has opened on the projected timetable, and whether any licences have actually issued.
  • Sources conflict on whether controllers may charge data subjects for rights requests, and at what ceiling.
  • Whether a legitimate interests basis exists rests on limited practitioner commentary.
  • Whether sensitive-data processing requires a standalone licensing instrument.
  • No adequacy list has been published. This is the single most commercially consequential gap, because Egyptian enterprises are heavily dependent on US-hosted SaaS, and nobody yet knows how that infrastructure will be treated.

We will date and correct this piece as those resolve.

How we work on this

Raversys is the group parent, and we split this work along its natural seam.

The advisory half sits with us. Record counting, system mapping, the licensing position, DPO accreditation planning, contract review, and the judgement call about which systems have to move — that is a consulting engagement, and it produces the decisions.

The build half sits with Raqmix Delta. Our group company Raqmix runs Delta as a governance and decision layer over existing business systems — ERPs, POS, accounting platforms, bank feeds, e-invoicing — unifying them into a single governed data model without ripping anything out. Its positioning, "your systems, unified; your data, inside Egypt", was built for exactly this constraint. Delta deploys on Egyptian cloud infrastructure, in a private data centre, or on-premise, and its audit logging and permission controls address the inspectable-records requirement directly.

That combination matters because the two halves fail separately. Advice that ends at a PDF leaves you with a map and no route. Technology deployed before the mapping is done relocates the wrong systems at considerable cost.

If you want a starting point, the fastest one is an inventory: what personal data you hold, how much of it, and which side of the border it currently sits on. Everything in this article follows from that answer.


This article addresses Egypt's PDPL Executive Regulations as at the date of review. It is general information about a regime that is still settling, not legal advice — verify the current position with Egyptian counsel before acting. If you believe something here is wrong, tell us and we will correct it publicly and date the correction.