Data Protection and Privacy 2025

EGYPT Law and Practice Contributed by: Ibrahim Shehata, Tasneem El-Naggar and Safa Rabea, Shehata & Partners

Consent and legal basis Although not explicitly mentioned for asset deals, the PDPL requires personal data to be processed only with the explicit consent of the data subjects. Personal data must be processed for legitimate and declared purposes directly related to the asset deal, such as due diligence or transaction implementation. Transparency and notification Data subjects should be informed about the nature of the transaction, the purpose of data processing, the identity of the acquiring party, and any potential impact on their privacy rights. Data security Entities must implement robust security meas - ures to ensure personal data is protected during the transfer process, preventing unauthorised access or breaches. Personal data should only be accessible to authorised individuals directly involved in the transaction. Retention and deletion Data should only be retained for the duration necessary to complete the transaction or fulfil legal requirements. Any redundant or unnecessary data must be securely deleted after the transaction is finalised, unless retention is required by law. Compliance with data subject’s rights Data subjects retain the right to access, correct or delete their data. They may also object to its processing if it conflicts with their fundamental rights and freedoms.

Data subjects must be notified of any breach involving their personal data. Third-party agreements If third-party advisers or consultants are involved, clear data-sharing agreements must be estab - lished to ensure confidentiality and compliance with the PDPL. Although the PDPL does not explicitly address data processing during asset deals, its general principles apply to ensure the lawful and secure handling of personal data. By adhering to the PDPL’s requirements for consent, security and transparency, parties can manage personal data responsibly during such transactions while mini - mising legal risks. 5. International Considerations 5.1 Restrictions on International Data Transfers The PDPL introduces restrictions and controls on the cross-border or international transfer of data as a means to protect the subject whose data is being transferred. Articles (14–16) of the PDPL are concerned with the cross-border transfer of data. The main restriction stated by the law is ensuring that the level of protection of data implemented in the state to which the data is being transferred is the same or exceeds the level of protection required in Egypt. The level of protection of the foreign state will be examined by the PDPC, which will be established pursuant to Articles 19–25 of the PDPL. Consequently, if the level of protection is found adequate and conforms with that of the PDPL, a licence or permit will be granted by the PDPC in order to be able to transfer the data.

118 CHAMBERS.COM

Powered by