
Masaar and the Egyptian Initiative for Personal Rights (EIPR) have published a joint legal commentary entitled “Executive Regulations of the Personal Data Protection Law: Assessing the Translation of General Rules into Enforceable Obligations”.
The commentary offers an early analysis of the Executive Regulations as the instrument governing how the rights to privacy and personal data protection are implemented in practice in the digital sphere. It examines how public and private entities manage the life cycle of personal data, how data subjects exercise their rights, the scope of controllers’ and processors’ obligations, and the oversight and enforcement mechanisms available to the state.
The commentary is published as Personal Data Protection Law No. 151 of 2020 moves from a broad legislative framework to a detailed operational regime following the issuance of its Executive Regulations under Minister of Communications and Information Technology Decree No. 816 of 2025.
The Regulations set out detailed rules on key issues, including consent, licences and permits, record-keeping and documentation, data-breach notification, cross-border data transfers, sensitive personal data, children’s data, and direct electronic marketing. The absence of these rules had left much of the Law’s practical implementation stalled for several years.
The two organisations approach the Regulations as the operational instrument that gives effect to the Law. Rather than merely repeating its general provisions, the Regulations translate them into procedures, standards, institutional roles, and administrative processes against which compliance can be assessed and legal responsibility established.
The importance of the Regulations therefore extends beyond filling in the details left by the Law. In practice, they define the requirements for compliance and the boundaries of accountability by specifying what entities subject to the Law must do and what conduct constitutes non-compliance.
The commentary also considers the wide variation among entities subject to the Law. They range from large organisations with advanced legal and technical infrastructure to start-ups, civil society organisations, media outlets, and local initiatives that may face compliance costs disproportionate to the scale of their activities. At the same time, the Regulations must establish practical means for individuals to exercise their rights, so that those rights do not remain legal promises without clear routes to implementation.
Against this background, the commentary follows two parallel lines of analysis. The first examines whether the Regulations adequately address the matters delegated to them under the Law. These include licences, permits, and accreditation; data-security standards; the registration and responsibilities of Data Protection Officers; rules governing cross-border data transfers; and the conditions governing the evidentiary weight of digital evidence derived from personal data.
The second identifies problems in the Regulations’ design, their safeguards for rights, and the feasibility of compliance, as well as the direct consequences of those problems for data subjects and entities subject to the Law.
On the basis of these two lines of analysis, the commentary concludes with procedural and legislative recommendations designed to strengthen data protection, improve compliance, and ensure accountability.
Although the Regulations address a significant proportion of the matters referred to them by the Law, the commentary finds that some provisions amount to little more than formal compliance with the legislative mandate. They do not provide the degree of legal certainty required for a data-protection framework to operate fairly, consistently, and effectively.
The commentary identifies the effectiveness of consent as a central issue in personal data protection. While the Law affirms the principle of explicit consent, the Regulations effectively recognise implied consent when an individual provides personal data to obtain a service or complete a transaction.
This approach may undermine informed consent unless it is accompanied by clear safeguards, binding minimum standards for notice and comprehension, and limits preventing the collection of unnecessary data on the broad ground that they are “necessary to provide the service”.
From the perspective of data subjects’ rights, the practical value of the Regulations cannot be measured simply by the rights listed in their provisions. It must be assessed by whether those rights can genuinely be exercised. This requires a unified and binding procedural framework that identifies a clear point of contact within each entity for receiving requests from data subjects; specifies the accepted form of those requests and the applicable response deadlines; establishes the consequences of non-response and the available escalation mechanisms; and requires responses to be documented in a manner that enables oversight and accountability.
The commentary finds that the Regulations do not establish a coherent general framework governing requests for access, rectification, erasure, restriction of processing, objection, or withdrawal of consent. As a result, the procedures available to data subjects may differ from one entity to another, weakening the ability to verify compliance and establish responsibility when violations occur.
These concerns are compounded by the Regulations’ failure to determine clearly the cost of exercising data subjects’ rights or the criteria for calculating any applicable fees. This leaves room for future regulatory decisions that could create financial barriers to the exercise of the rights to privacy and personal data protection, with a disproportionate impact on people with lower incomes.
The commentary also examines the broad exemptions that undermine the principle of comprehensive protection. These include the broadly worded exemption for national security bodies and the binding powers associated with it, as well as the exemption applying to the Central Bank and the banking sector. Such exemptions risk creating unequal levels of protection, under which individuals’ rights and enforcement mechanisms vary according to the entity holding their data.
The commentary stresses that any exemption affecting the right to privacy must, in accordance with constitutional and human rights standards, be subject to clear substantive, procedural, and oversight safeguards. Otherwise, it may create areas effectively beyond the reach of the Law, in which the limits of interference are unclear and meaningful accountability is unavailable.
The commentary notes that the Regulations make a prior licence or permit the principal gateway for cross-border data transfers, even when the receiving country provides an adequate level of protection. They also restrict transfers to the countries specified in the relevant licence or permit and require it to be updated whenever another country is added.
This approach may impose significant operational burdens on cross-border services. The commentary therefore calls for clearer rules governing the application and interpretation of exceptions.
The commentary pays particular attention to the governance and enforcement structure established by the Law and elaborated by the Regulations. The Personal Data Protection Centre is the central institution responsible for implementing the framework. Its broad powers include issuing licences and permits, registering Data Protection Officers, accrediting consultants, receiving and deciding complaints, and carrying out inspections and oversight.
However, the Centre’s place within the executive branch and its institutional subordination directly affect how these powers are exercised, raising practical concerns about its independence, transparency, and ability to avoid conflicts of interest.
The commentary emphasises that the effectiveness of a regulatory authority does not depend solely on the breadth of its powers; it also requires procedural safeguards ensuring that those powers are exercised fairly and consistently.
It also requires publication of the standards governing regulatory decisions, meaningful stakeholder participation in the development of guidance and technical standards, and a risk-based approach that balances the scale and sensitivity of processing against the burden of compliance. Without these safeguards, the data-protection framework risks becoming a bureaucratic system focused on paperwork and formal procedures rather than the effective protection of rights.
The commentary also identifies gaps in the transparency obligations of the Personal Data Protection Centre. These include the absence of a binding framework for annual reporting on the state of data protection and the publication of aggregated data, as well as the inadequate regulation of the Centre’s awareness-raising and training functions.
The effective exercise of rights depends on individuals knowing what those rights are and on entities understanding how to implement their technical and procedural obligations. Without these frameworks, enforcement may become selective, levels of compliance may vary widely, and the public, researchers, journalists, and Parliament may be unable to assess the performance of the data-protection system objectively.
The use of personal data to train artificial intelligence models and other emerging technologies is one of the clearest tests of the framework’s readiness. The Regulations impose a general obligation to avoid harm and refer to “principles generally recognised locally, regionally and internationally”. The commentary argues, however, that these broad references must be translated into operational standards that can be verified, audited, and enforced.
Such standards should specify when impact assessments are required, define limits on the scope and purpose of data processing, regulate the reuse of personal data, and enable the exercise of rights such as objection, erasure, and withdrawal of consent within current technological constraints. They should also address broader societal harms, including discrimination, exclusion, and stigmatisation, rather than focusing solely on direct harm to individuals.
The two organisations conclude the commentary with recommendations for addressing gaps in the Regulations and strengthening the framework’s consistency with the constitutional and human rights foundations of privacy protection. Many of these recommendations could be implemented immediately through binding regulatory decisions and guidance issued by the Personal Data Protection Centre.
They include standardising procedures for exercising data subjects’ rights, establishing clear standards for consent and notice, adopting uniform data-breach notification forms, and introducing a risk-based approach to inspections and regulatory requirements.
The commentary also proposes medium-term legislative reforms, including strengthening the independence of the regulatory authority, reviewing overly broad exemptions, ensuring greater proportionality between penalties and the nature of violations, and strengthening individuals’ rights to compensation and effective remedy.
Masaar and EIPR affirm that this legal commentary forms part of their commitment to advancing privacy and personal data protection as fundamental rights inseparable from freedom of expression, personal security, and economic and social rights in the digital age.
The protection of these rights should not be reduced to bureaucratic compliance requirements or market considerations. It must rest on clear rules that enable individuals to understand how their data are used, exercise their rights without undue barriers, and ensure that entities’ obligations are enforceable and subject to meaningful accountability.
The two organisations call on regulatory authorities, policymakers, entities subject to the Law, media outlets, professionals, and researchers to treat the Regulations as a living framework open to evaluation and improvement. They also call for transparent consultation on the guidance and technical standards that will shape the future of data protection in Egypt.
This process must balance the requirements of digital transformation with the protection of the substance of the right to privacy. It must also prevent data protection from becoming a broad regulatory label under which bureaucratic procedures expand while individuals remain without clear routes for exercising their rights or effective safeguards against violations.