Egypt's PDPL (Law No. 151 of 2020): awareness, training & human risk

If your organisation processes personal data in Egypt — as a bank, telco, insurer, e-commerce platform, outsourcer or the local arm of a multinational — Law No. 151 of 2020 on the Protection of Personal Data (PDPL) applies to you, with licensing, oversight and sanctions administered by the Personal Data Protection Centre. Like the European regulation that inspired it, most of the law's obligations succeed or fail at the human layer: the employees who collect, handle and occasionally mishandle personal data. This page explains what the PDPL expects of your people, and how AfriPhish produces the records your Data Protection Officer and the Centre will want to see.

What the PDPL requires of your people

Licensing and oversight by the Data Protection Centre. The PDPL establishes the Centre as the national regulator. Controllers and processors must obtain the relevant licences and permits for their processing activities, and remain subject to the Centre's supervision and enforcement. A licence is granted to the organisation, but it is kept by the daily conduct of staff — which is why a demonstrable internal compliance programme, with records, matters as much as the paperwork that obtained the licence.

A mandatory Data Protection Officer. The law requires the appointment of a DPO responsible for ensuring the organisation complies with the law, verifying that internal policies and procedures are actually followed, handling data subjects' requests and acting as the point of contact with the Centre. No DPO can discharge that duty alone: they need a workforce that knows the rules, and documentation proving the workforce was taught them.

Security and confidentiality obligations. Controllers and processors must protect personal data against breach, loss and unauthorised access, and the people processing that data are bound by confidentiality. In practice, phishing and social engineering remain the dominant routes to unauthorised access — so the technical safeguards the law expects presume employees who can recognise an attack aimed at their inbox or their WhatsApp.

Breach notification to the Centre within 72 hours. When a personal data breach occurs, the Centre must be notified within 72 hours of the organisation becoming aware of it. That clock starts inside your organisation: if the first employee to notice something suspicious does not recognise it, or does not know where to report it, the deadline is lost before your legal team ever hears about the incident. Front-line reporting behaviour is the practical foundation of the notification duty.

Real sanctions. The PDPL backs its obligations with significant fines and, for certain violations, criminal liability — exposure that reaches the managers responsible, not only the corporate entity. "We told staff to be careful" is not a defence; documented, verified awareness is.

The obligations AfriPhish helps you evidence

PDPL obligationAfriPhish moduleEvidence produced
Staff awareness of data-protection dutiesAwareness training in English, French and ArabicPer-user completion records, quiz scores, assignment dates
Confidentiality and acceptable-use rules acknowledgedPolicy management with e-signature attestationVersioned, timestamped signature registers per employee
Security obligations vs phishing-led breachesPhishing simulations across realistic scenario familiesClick, credential-submission and report rates per campaign
72-hour notification readinessSimulated incidents plus real-time coachingReport rates and time-to-report trends across campaigns
DPO oversight and accountability to the CentreHuman risk scoring, analytics and reportsExportable programme records scoped to any review period
An ongoing, current programmeScheduled campaigns and training seriesA dated history of recurring awareness activity

Because simulations, training and attestations share one data model, your DPO can show cause and effect: the team that fell for a simulated invoice fraud in one quarter completed remedial training and reported the next attempt instead of clicking it.

What the Centre and your DPO will look for

Whether prompted by a Centre inspection, a licence application or the DPO's own compliance file, the requests are predictable:

  • Training records for everyone who touches personal data — including Arabic-speaking front-line teams, not just head office.
  • Confidentiality and policy acknowledgements — signatures tied to the current version of each policy, not a signature collected once at hiring and never renewed.
  • Evidence of breach-reporting readiness — proof that employees know how to recognise and escalate a suspected incident, which is what makes the 72-hour duty achievable.
  • Testing results — simulation outcomes showing that awareness is verified in practice rather than assumed.
  • Programme continuity — a dated history demonstrating recurring activity, not a single induction session years ago.
  • Follow-up on weaknesses — evidence that repeat clickers and non-completers were identified and retrained.

All of the above export directly from AfriPhish, scoped to the period under review.

See where your organisation stands

Before the regulator — or a large customer's due-diligence questionnaire — asks the question, answer it yourself. Take the free 4-minute Human Risk Maturity Assessment: it benchmarks your awareness programme against what a data-protection compliance file actually needs, and highlights the gaps a DPO would flag.

Preparing a PDPL compliance programme with counsel or an internal team? Book a demo and we will show you the exact reports that go into a Centre-ready evidence file.