Skip to content
Make AI Good

Graph · Event

Masaar civil society proposal on executive regulations for Egypt's Personal Data Protection Law (2022)

01 · In focus

One event, in the field.

The structured facts the source records about Masaar civil society proposal on executive regulations for Egypt's Personal Data Protection Law (2022), the count of declared adjacencies in the corpus, and the federation map zoomed on this node and its neighbours.

event

1 declared connection

Kind
Event
Status
historical
Confidence
high
Type
civil society regulatory proposal
Date
2022
Location
Cairo, Egypt
Entity ID
event-masaar-egypt-pdpl-executive-regulations-proposal-2022
Network
View in network

Tags egypt, cairo, mena, arabic-language, civil-society, digital-rights, privacy, data-protection, pdpl, regulatory-advocacy, policy-proposal, data-protection-center, independence, executive-regulations, masaar

Masaar civil society proposal on executive regulations for Egypt's Personal Data Protection Law (2022) · 1 direct neighbour visible

02 · Connections

1 adjacency, by relation.

Split by direction. Direct links are the ones Masaar civil society proposal on executive regulations for Egypt's Personal Data Protection Law (2022)’s source record names; inferred backlinks are records elsewhere in the corpus that point at this entity.

Direct from this record

1 link

Links named in this entity's structured fields.

03 · Background

From the source record.

Body prose as it appears in movement-graph’s published markdown for this entity. Links to other corpus entities resolve to their graph page; links to deeper repo paths are kept as text so the page does not invent a route.

In 2022, Masaar — Technology and Law Community published a coordinated package of civil society policy proposals on the executive regulations for Egypt's Personal Data Protection Law (Law No. 151 of 2020) — the most substantial civil society intervention in the regulatory development of Egypt's data protection framework during the years-long gap between the law's enactment and the eventual issuance of its implementing rules.

Background: the PDPL's suspended implementation

Egypt enacted Law No. 151 of 2020 on the protection of personal data in July 2020, drawing heavily on the European General Data Protection Regulation (GDPR) while adapting it to the Egyptian institutional context. The law entered into force in October 2020 but was functionally suspended from its first day: a large portion of its articles delegated procedural and substantive implementation to executive regulations that the law required to be issued within six months of coming into force — by the second quarter of 2021. Those regulations were not issued by that deadline, nor in the two years that followed.

The delay had concrete consequences. The Personal Data Protection Center — the law's planned regulatory body, with power to enforce the law, issue licenses, and receive complaints — could not be formed without the executive regulations. Entities collecting and processing personal data could not obtain the legally required licenses. Sensitive-data protections, which the PDPL treated as a stricter category, remained unenforceable because their procedural implementation was entirely delegated to the missing regulations. Multiple members of the Egyptian Parliament filed formal queries to the Prime Minister and the Minister of Communications and Information Technology (CIT) demanding the regulations' issuance. In August 2022, Senator Hassanin Tawfik filed a formal demand to the Minister of CIT, characterising the multi-year delay as a violation of the law's own statutory deadline and as a jeopardising of Egyptian citizens' data protection rights.

Masaar's proposal package

Against this backdrop, Masaar published a coordinated set of policy papers in 2022 that together constitute the most technically detailed civil society position on what the executive regulations should contain.

"Data Protection Center: Masaar's Proposal on the Executive Regulations for the Data Protection Law" is the core document, presenting a formal civil society position on the structure and governance of the Personal Data Protection Center. The PDPL established the Center as a public economic authority under the Ministry of Communications — a design that, in Masaar's analysis, created a structurally dependent regulatory body rather than an independent data protection authority. The Center's board must include representatives from the Ministry of Defence, the Ministry of Interior, and the Intelligence Services alongside seven other members, and follows the Minister rather than operating at arm's length from executive power. Masaar's proposal argues that the executive regulations should include explicit guarantees of the Center's independence — drawing on the European Data Protection Board model — and protective provisions for employees and whistleblowers facing political interference. The proposal recommends that any changes to the Center's operation or enabling legislation require the Center's own approval, preventing unilateral executive interference in its governance.

"A Suspended Law: Two Years After the Issuance of the Personal Data Protection Law, Its Executive Regulations Haven't Been Issued" documents the practical consequences of the delay: the absence of implementing rules for sensitive-data protections, the suspended formation of the Data Protection Center, the lack of a licensing regime for data controllers and processors, and the resulting gap between formal rights on the statute book and enforceable protection in practice.

"Possible Legislative Alternatives: About the Executive Regulations of the Personal Data Protection Law" analyses the legislative design of the executive regulations process, proposing alternative frameworks for the scope of data protection exceptions, user-rights mechanisms, and the powers and composition of the regulatory body — situating Egyptian design choices against international best practices and arguing for formulations that would bring the eventual regulations closer to GDPR standards.

"Unwritten Rules: Impacts of the Delayed Executive Regulations of Data Protection Law on Sensitive Data" examines how the regulatory vacuum most severely affected sensitive data categories: the PDPL imposed heightened protections for sensitive data but left their procedural implementation entirely to the executive regulations, so the delay left these stronger protections effectively unenforceable for Egyptian data subjects.

Significance

The 2022 Masaar proposal package represents the corpus's primary documented instance of Egyptian civil society making a formal, technically grounded case for how the implementing regulations of a national data protection law should be structured — engaging with governance architecture, enforcement mechanisms, whistleblower protections, and GDPR-comparative analysis rather than simply calling for the regulations to be issued. Masaar identified a structural problem in Egypt's data protection regulatory design — a Center formally under the Ministry of Communications, with security-sector representation on its board, governed by ministerial appointment — that was not adequately addressed in the law itself and required the executive regulations to remedy.

The executive regulations were ultimately issued in November 2025, five years after the law entered into force, as Executive Decree No. 816 of 2025 by the Ministry of Communications. The long-delayed regulations transformed the PDPL from a framework of general principles into an operational system by introducing licensing requirements, breach notification procedures, data-subject rights mechanisms, and cross-border transfer rules. Whether and to what extent Masaar's 2022 independence proposals were incorporated into the final 2025 regulations remains an open empirical question in the post-issuance literature. For the corpus, the event marks Masaar's establishment as Egypt's most substantive civil society voice on data protection regulatory design — a role that continues through its analysis of the 2025 Orange Egypt telecom compensation ruling, the first significant judicial application of the PDPL against a corporate actor.

04 · Sources

Where this came from.

4 sources listed from the pinned corpus. Links are shown only when the source URL is a valid HTTP(S) address.

  1. masaar.net

    Checked 2026-06-12

    Masaar's core proposal on the formation and independence of the Personal Data Protection Center — primary source for the governance recommendations, the analysis of the Center's structural dependence under the Ministry of Communications, the security-sector board representation, and the GDPR-comparative independence framework

  2. masaar.net

    Checked 2026-06-12

    Masaar's "A Suspended Law" article documenting two years of PDPL executive-regulations delay — primary source for parliamentary demands, Senator Hassanin Tawfik's August 2022 demand to the Minister of CIT, suspended formation of the Personal Data Protection Center, and the violation of the law's own deadline

  3. masaar.net

    Checked 2026-06-12

    Masaar's "Possible Legislative Alternatives" policy paper — primary source for legislative-design analysis of the executive regulations, scope-of-protection alternatives, user-rights mechanisms, and proposed regulatory body governance frameworks

  4. masaar.net

    Checked 2026-06-12

    Masaar's "Unwritten Rules" policy paper — primary source for the analysis of how the regulatory delay left sensitive-data categories without enforceable protections and the cascading impact on data subjects in the absence of implementing rules

Source: entities/events/event-masaar-egypt-pdpl-executive-regulations-proposal-2022.md — movement-graph pin 5d136ad.