Data subject rights constitute the cornerstone of modern personal data protection legislation, foremost among them Egyptian Law No. 151 of 2020. Compliance with these rights is no longer merely a regulatory option; it has become a critical standard for assessing operational readiness and managing the legal risks of local companies and multinational institutions operating in Egypt.
Understanding data subject rights and how to handle access, rectification, and erasure requests enables institutions to build an effective response mechanism that protects them from financial penalties and criminal liability, while maintaining the confidence of investors and customers in the digital environment.
Legal Framework for Data Subject Rights under Egyptian Legislation
Law No. 151 of 2020 concerning personal data protection in Egypt regulates the relationship between the “Data Subject” and the “Data Controller” or “Processor” (Data Controller / Processor). The law grants individuals a set of fundamental rights that may not be restricted except in accordance with the provisions of the law, with the aim of ensuring the individual’s control over his or her personal data.
The principal regulatory frameworks are as follows:
- Right to Knowledge and Information: The controller is required to inform the data subject that his or her data is being collected, the purpose of its processing, and the identity of those responsible for it.
- Right of Access and Availability (Data Access): The ability to review stored data and obtain a copy of it in a readable format.
- Right to Rectification and Updating (Rectification): Requesting the correction of inaccurate data or completion of incomplete data.
- Right to Erasure and Cancellation (Erasure / Right to be Forgotten): Erasure of Personal Data upon completion of the purpose of processing or withdrawal of consent.
- Right to Revoke and Withdraw Consent: The ability to withdraw prior consent to data processing at any time, without affecting the lawfulness of prior processing.
Practical Procedures for Handling Data Subject Requests (DSARs)
Handling Data Subject Access Requests (Data Subject Access Requests – DSARs) requires a well-controlled workflow within the company’s legal affairs and technology departments to avoid any procedural violations.
[Receipt of Request] ➔ [Identity Verification] ➔ [Review of Scope and Grounds of Request] ➔ [Implementation or Reasoned Refusal] ➔ [Formal Notification]
1. Verification of Identity, Capacity, and Request
Before commencing any search for data within the systems, the legal capacity of the applicant must be verified, whether the applicant is the data subject personally or a legal representative acting under an official power of attorney, to ensure that data is not disclosed to unauthorised third parties.
2. Time Limits and Notification Schedule
The controller is required to respond to requests submitted to it within the legally prescribed period, which is specified in detail in the Executive Regulations and instructions issued by the Personal Data Protection Center. The response must be in writing and in a clear format, whether approving and implementing the request or issuing a reasoned refusal.
3. Implementing Erasure and Rectification Mechanisms
Where an erasure or rectification request is received, this must be applied across all backup servers (Backups) and connected databases, with all third parties (Third Parties) or processors with whom the data has been shared being notified so that they also update or delete the data in their possession.
Legal Exceptions and Grounds for Refusing Requests
Data subject rights are not absolute; rather, they are subject to specific exceptions under Law No. 151 of 2020. A company may refuse access or erasure requests in the following circumstances:
- Legal and Tax Obligations: Where retention of the data is mandatory under other laws, such as tax legislation, anti-money laundering laws, and commercial law.
- National Security and Crime Prevention: Where processing is required for purposes relating to national security, pursuant to a court order, or in connection with ongoing criminal investigations.
- Defence of Rights Before the Courts: Retaining data necessary for pursuing legal proceedings or establishing the company’s rights and legal defences.
- Abusive or Repetitive Requests: Where it is established that the request is intended to harm the company, or identical requests are submitted at unreasonable intervals without justification.
Legal Risks and Commercial Consequences for Companies
Failure to handle data subject requests in accordance with legal standards creates dual risks, ranging from legal liability to operational disruption.
- Criminal and Financial Penalties: Egyptian law provides for penalties including financial fines and imprisonment in certain cases involving the deliberate refusal to implement data subject rights or processing data without legal basis.
- Civil Liability and Compensation: A person harmed by the failure to implement his or her requests may bring compensation claims against the company for failure to comply with the legally prescribed duty of care.
- Operational and Commercial Disruption: For shipping, e-commerce, import, and export companies, disorder in managing data requests may disrupt operations, result in the loss of operating licences, and damage the company’s reputation before investors and foreign partners.
Special Considerations for International Clients and Cross-Border Companies
Multinational companies and foreign law firms seeking Local Counsel face additional complexity arising from overlapping legislation.
- Alignment Between GDPR and Egyptian Law: If a company is subject simultaneously to European standards (GDPR) and Egyptian requirements, its mechanisms for responding to access requests must be aligned to maintain dual compliance without legal conflict.
- International Data Transfers: Transferring data outside Egypt in response to a request from the company’s head office abroad requires verification that the necessary permits and licences have been obtained from the Egyptian Personal Data Protection Center and that the legal conditions governing cross-border data transfers have been satisfied.
Common Mistakes and Practical Best Practices
Common Mistakes
- Failure to maintain a specific Record of Processing Activities (Record of Processing Activities – ROPA) identifying where each user’s data is stored.
- Responding to requests verbally or through informal email without evidentiary documentation.
- Random deletion of data that the law requires to be retained for tax or accounting purposes.
Practical Best Practices
- Preparing an Internal DSARs Policy: Establishing SOPs (Standard Operating Procedures) defining the roles of the legal affairs department and the IT department.
- Training Customer Service and Legal Affairs Teams: To ensure rapid identification of a data subject request and its referral to the correct legal process.
- Automation and Data Encryption: Using technical systems that allow data to be extracted and updated easily without affecting the data of other parties.
When Is the Intervention of a Specialist Lawyer or Local Counsel in Egypt Required?
Handling data requests requires precise legal standards for assessing conditions and exceptions. Engaging a specialist lawyer becomes necessary in the following cases:
- Receiving data erasure requests connected with existing or potential disputes involving employees or customers.
- Receiving complex requests from international parties requiring assessment of applicable laws and cross-border transfers.
- Drafting response forms and reasoned refusals to avoid fines or liability before the Personal Data Protection Center.
- Preparing and adapting the internal regulations of foreign companies to comply with the Egyptian legislative environment.
How Can Specialist Legal Support Assist?
El Rouby Law Firm provides an integrated framework to support companies and investment institutions in managing compliance with the Personal Data Protection Law:
- Regulatory Compliance: Designing and developing frameworks and policies for handling data subject requests (DSAR Procedures) in compliance with Law No. 151 of 2020.
- Risk Management: Conducting Data Protection Impact Assessments (DPIA) and reviewing refusal requests to avoid criminal and financial penalties.
- Drafting Contracts and Processing Agreements: Preparing Data Processing Agreements (DPAs) and data subject rights provisions in commercial contracts and shipping and supply agreements.
- Dispute Prevention and Settlement: Addressing data subject complaints at an early stage and negotiating their settlement before escalation to regulatory authorities.
- Representation Before Egyptian Authorities and Courts: Providing legal representation for companies before the Personal Data Protection Center and presenting the defence in related disputes, litigation, and arbitration proceedings.
Conclusion
Prudent management of access, rectification, and erasure requests is no longer merely a procedural requirement; it has become a pillar of corporate governance and the protection of company assets in the digital environment. A legally compliant response provides protection against liability and also ensures business continuity.
For specialist legal advice and a review of your company’s compliance framework, you may contact the team at El Rouby Law Firm for support in our capacity as Local Counsel and as specialists in data protection and corporate legal services in Egypt.
Frequently Asked Questions
Q1: What Is the Legal Time Limit for Responding to a Data Subject Request in Egypt?
The controller is required to respond to a data subject request within the period specified by the regulations and executive instructions issued by the Personal Data Protection Center, which usually falls within a specified number of working days from receipt of the request and verification of the applicant’s identity.
Q2: May a Company Refuse a Data Subject’s Request to Erase Personal Data?
Yes. A company may refuse the request where retention of the data is required under another law, such as tax or commercial laws, or where the data is necessary for pursuing legal proceedings or defending the company’s legal rights.
Q3: May Fees Be Charged for Access and Rectification Requests?
As a general rule, a data subject may exercise his or her rights free of charge, and no fee may be imposed except in cases specified by regulation and only to the extent of the actual administrative cost of abusive or repetitive requests.
Q4: What Is the Penalty for Refusing to Enable a Data Subject to Exercise His or Her Rights?
Law No. 151 of 2020 penalises deliberate refusal or delay with financial fines that are doubled in cases of recidivism, in addition to the possibility of the company being exposed to civil compensation claims before the competent courts.
Q5: How Should Cross-Border Companies Handle Erasure Requests Where Data Is Stored Outside Egypt?
The company must require the external Processor, pursuant to the Data Processing Agreement (DPA), to erase the data immediately upon instruction from the controller in Egypt, in order to ensure compliance with local legislation and international regulations.
References
- Egyptian Official Gazette: Law No. 151 of 2020 promulgating the Personal Data Protection Law.
- Egyptian Ministry of Communications and Information Technology (MCIT): Digital legislation, policies, and governance frameworks.
- Personal Data Protection Center (Egypt): Regulatory controls, guidance, and licences.