Egypt's PDPL (Law No. 151 of 2020): awareness, training & human risk
If your organisation processes personal data in Egypt — as a bank, telco, insurer, e-commerce platform, outsourcer or the local arm of a multinational — Law No. 151 of 2020 on the Protection of Personal Data (PDPL) applies to you, with licensing, oversight and sanctions administered by the Personal Data Protection Centre. Like the European regulation that inspired it, most of the law's obligations succeed or fail at the human layer: the employees who collect, handle and occasionally mishandle personal data. This page explains what the PDPL expects of your people, and how AfriPhish produces the records your Data Protection Officer and the Centre will want to see.
What the PDPL requires of your people
Licensing and oversight by the Data Protection Centre. The PDPL establishes the Centre as the national regulator. Controllers and processors must obtain the relevant licences and permits for their processing activities, and remain subject to the Centre's supervision and enforcement. A licence is granted to the organisation, but it is kept by the daily conduct of staff — which is why a demonstrable internal compliance programme, with records, matters as much as the paperwork that obtained the licence.
A mandatory Data Protection Officer. The law requires the appointment of a DPO responsible for ensuring the organisation complies with the law, verifying that internal policies and procedures are actually followed, handling data subjects' requests and acting as the point of contact with the Centre. No DPO can discharge that duty alone: they need a workforce that knows the rules, and documentation proving the workforce was taught them.
Security and confidentiality obligations. Controllers and processors must protect personal data against breach, loss and unauthorised access, and the people processing that data are bound by confidentiality. In practice, phishing and social engineering remain the dominant routes to unauthorised access — so the technical safeguards the law expects presume employees who can recognise an attack aimed at their inbox or their WhatsApp.
Breach notification to the Centre within 72 hours. When a personal data breach occurs, the Centre must be notified within 72 hours of the organisation becoming aware of it. That clock starts inside your organisation: if the first employee to notice something suspicious does not recognise it, or does not know where to report it, the deadline is lost before your legal team ever hears about the incident. Front-line reporting behaviour is the practical foundation of the notification duty.
Real sanctions. The PDPL backs its obligations with significant fines and, for certain violations, criminal liability — exposure that reaches the managers responsible, not only the corporate entity. "We told staff to be careful" is not a defence; documented, verified awareness is.
The obligations AfriPhish helps you evidence
| PDPL obligation | AfriPhish module | Evidence produced |
|---|---|---|
| Staff awareness of data-protection duties | Awareness training in English, French and Arabic | Per-user completion records, quiz scores, assignment dates |
| Confidentiality and acceptable-use rules acknowledged | Policy management with e-signature attestation | Versioned, timestamped signature registers per employee |
| Security obligations vs phishing-led breaches | Phishing simulations across realistic scenario families | Click, credential-submission and report rates per campaign |
| 72-hour notification readiness | Simulated incidents plus real-time coaching | Report rates and time-to-report trends across campaigns |
| DPO oversight and accountability to the Centre | Human risk scoring, analytics and reports | Exportable programme records scoped to any review period |
| An ongoing, current programme | Scheduled campaigns and training series | A dated history of recurring awareness activity |
Because simulations, training and attestations share one data model, your DPO can show cause and effect: the team that fell for a simulated invoice fraud in one quarter completed remedial training and reported the next attempt instead of clicking it.
What the Centre and your DPO will look for
Whether prompted by a Centre inspection, a licence application or the DPO's own compliance file, the requests are predictable:
- Training records for everyone who touches personal data — including Arabic-speaking front-line teams, not just head office.
- Confidentiality and policy acknowledgements — signatures tied to the current version of each policy, not a signature collected once at hiring and never renewed.
- Evidence of breach-reporting readiness — proof that employees know how to recognise and escalate a suspected incident, which is what makes the 72-hour duty achievable.
- Testing results — simulation outcomes showing that awareness is verified in practice rather than assumed.
- Programme continuity — a dated history demonstrating recurring activity, not a single induction session years ago.
- Follow-up on weaknesses — evidence that repeat clickers and non-completers were identified and retrained.
All of the above export directly from AfriPhish, scoped to the period under review.
See where your organisation stands
Before the regulator — or a large customer's due-diligence questionnaire — asks the question, answer it yourself. Take the free 4-minute Human Risk Maturity Assessment: it benchmarks your awareness programme against what a data-protection compliance file actually needs, and highlights the gaps a DPO would flag.
Preparing a PDPL compliance programme with counsel or an internal team? Book a demo and we will show you the exact reports that go into a Centre-ready evidence file.