Hire Nile

Hire Nile Guide: GDPR, UK Transfer Rules, and Egypt's PDPL When You Hire in Egypt

Whether a remote hire in Egypt can touch EU customer data turns on a question most guides skip: whether it is a transfer under Chapter V at all. This guide works the EDPB's three cumulative criteria, the employee reasoning in Example 8 of Guidelines 05/2021, the standard contractual clauses and transfer impact assessment path when it is a transfer, the UK's new not-materially-lower test in force since 5 February 2026, and Egypt's own PDPL now that Executive Regulations landed on 1 November 2025 with a 31 October 2026 compliance deadline.

By Hire Nile Editorial Team
19 min read
Hire Nile Guide: GDPR, UK Transfer Rules, and Egypt's PDPL When You Hire in Egypt

Published: August 13, 2026

Updated: August 13, 2026

There is a predictable moment in an offshore hiring process, and it usually arrives after everyone has already agreed the hire is a good idea. The candidate is strong, the rate works, the time zone lines up. Then someone from legal, security, or a customer's procurement team asks a question that stops the whole thing: can a person sitting in Egypt access our EU customer data at all?

The answers people get are usually bad in one of two directions. One camp says it is fine because everyone offshores and nobody has ever been fined for it. The other camp says Egypt has no adequacy decision, so the answer is no. Both are wrong, and the second one is expensive, because it kills good hires over an analysis that was never done properly.

The real answer depends on a question most guides never ask: whether what you are doing counts as a transfer under Chapter V of the GDPR in the first place. Under the European Data Protection Board's own guidance, a large share of Egypt hiring arrangements are not restricted transfers at all, and the ones that are can be handled with paperwork that is well understood. Which category you land in is decided almost entirely by the commercial model you choose, which means it is a decision you control rather than a fact you inherit.

This guide covers both directions of the problem, because there are two separate legal regimes pointing opposite ways and most write-ups only cover one. Going out from Europe, the EU and UK rules govern personal data moving toward Egypt. Coming out of Egypt, Egypt's own Personal Data Protection Law governs data leaving the country, and that law stopped being theoretical in November 2025. Its compliance deadline is 31 October 2026.

One thing this guide is not. It is not legal advice and it is not a substitute for counsel in your own jurisdiction or in Egypt. Data protection analysis is fact-dependent, it turns on contract wording this page cannot see, and the Egyptian regime is in its first year of real operation with practice still settling. Every substantive claim below has a link to a primary source and a date attached, and where published sources disagree with one another this guide says so rather than picking whichever version reads more cleanly.

Start here: is it even a transfer?

This is the step that gets skipped, and skipping it is what produces the wrong answer.

The EDPB settled the question in Guidelines 05/2021 on the interplay between the application of Article 3 and the provisions on international transfers under Chapter V, whose final version 2.0 was adopted on 14 February 2023. The guidance sets out three criteria, and it is explicit that all three must be met together:

1) A controller or a processor ("exporter") is subject to the GDPR for the given processing. 2) The exporter discloses by transmission or otherwise makes personal data, subject to this processing, available to another controller, joint controller or processor ("importer"). 3) The importer is in a third country, irrespective of whether or not this importer is subject to the GDPR for the given processing in accordance with Article 3, or is an international organisation.

If the three are met there is a transfer and Chapter V applies. If they are not met, in the EDPB's words, "there is no transfer and Chapter V of the GDPR does not apply."

Criterion three is not in doubt. Egypt is a third country with no adequacy decision. The European Commission's adequacy list currently runs to Andorra, Argentina, Brazil, Canada for commercial organisations, the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, the United Kingdom, the United States under the Data Privacy Framework, Uruguay, and the European Patent Organisation. Brazil was added on 26 January 2026 and the UK's decision was renewed on 19 December 2025. Egypt is not on it and there is no live application that would put it there soon.

Criterion one is usually not in doubt either. If you are an EU or UK company processing customer or employee data, you are the exporter and you are subject to the rules.

So the whole analysis rests on criterion two, and specifically on four words in it: to another controller or processor. That is where the Egypt hiring question is actually decided.

The employee example, and why it matters so much here

The EDPB works this through directly. Example 8 in the guidelines is about an employee of an EU controller accessing company data while physically in a third country:

George, employee of A, a company based in Poland, travels to a third country for a meeting bringing his laptop. During his stay abroad, George turns on his computer and accesses remotely personal data on his company's databases to finish a memo. This bringing of the laptop and remote access of personal data from a third country, does not qualify as a transfer of personal data, since George is not another controller, but an employee, and thus an integral part of the controller (A). Therefore, the transmission is carried out within the same controller (A).

Read that carefully, because the reasoning generalises well beyond business trips. The reason there is no transfer is not that George is only away for a week. It is that an employee is legally part of the controller rather than a separate recipient. Nothing in the analysis depends on how long he stays or where he is sitting. The EDPB reinforces this in the section heading it gives to the discussion that follows, which is titled "Safeguards to be provided if personal data are processed outside the EEA but no transfer takes place."

The guidance also marks the boundary in the same example. If George, acting as an employee of A, "would send or make data available to another controller or processor in the third country, the data flow in question would amount to a transfer under Chapter V." The moment a separate legal person receives the data, you are back in Chapter V.

And there is a trap immediately next to it that catches companies who think having a local entity makes things simpler. The guidelines note that "entities which form part of the same corporate group may qualify as separate controllers or processors. Consequently, data disclosures between entities belonging to the same corporate group (intra-group data disclosures) may constitute transfers of personal data." Setting up an Egyptian subsidiary and employing people through it does not put you inside Example 8. It creates a separate legal person, and sending data to it is a transfer.

Which arrangement are you actually in?

Four common ways of engaging someone in Egypt, and the very different compliance positions they produce. The analysis below is the framework to take to your counsel, not a conclusion you can adopt without them, because the answer turns on how your specific contracts are written and on how the working relationship operates in practice rather than on what the paperwork is titled.

Someone employed directly by your existing foreign entity, working from Egypt. This is the arrangement that maps most closely onto Example 8. The person is your employee and, on the EDPB's reasoning, an integral part of the controller rather than a separate importer, so Chapter V is not engaged. This is the lightest compliance position available. It is also the arrangement with the most Egyptian employment law attached to it, which is a separate problem and a real one. Our guide to Egypt's Labour Law No. 14 of 2025 covers what that means for a foreign employer.

An independent contractor who invoices you. A self-employed contractor is a separate legal person. Where they process your customers' personal data on your instructions, they will generally sit as a processor, and disclosing data to them is a transfer requiring an Article 46 safeguard plus an Article 28 processing agreement. Note the tension here that catches people out: the contractor model is often chosen precisely because it feels lighter, but on the data protection side it is heavier than direct employment, not lighter. It also carries misclassification risk under Egyptian law. The contractor versus employee calculator prices the commercial side of that choice, and the data protection consequence belongs in the same decision.

An employer of record or a staffing agency that employs the person. The provider is a separate legal person in Egypt, so data you disclose to the provider is a transfer. Whether the worker themselves is a separate importer from you depends on how the arrangement is structured and who directs their work on your data, which is exactly the kind of question to put to counsel in writing rather than assume.

Your own Egyptian subsidiary. A transfer, per the intra-group point above. Group companies commonly handle this with a set of SCCs between entities or with binding corporate rules if the group is large enough to justify the process.

The practical takeaway is that this is a design decision. If a customer contract or an internal policy makes restricted transfers genuinely painful for you, direct employment of the individual by your own entity is the arrangement that avoids creating one. That is a legitimate reason to prefer it, and it is worth knowing before you pick a model rather than after.

What you still owe when there is no transfer

Here is where honest guidance separates from convenient guidance. Concluding that Chapter V does not apply is not a finish line, and anyone who tells you it is has not read past the example. The EDPB is direct about it:

the controller must comply with the GDPR and remains accountable for its processing activities, regardless of where they take place. This also means that the controller or processor should pay particular attention to the legal frameworks of the third country that may have an impact on its ability to respect the GDPR.

The guidance then names the obligations that continue to apply: Article 5 on processing principles, Article 24 on controller responsibility, Article 32 on security of processing, Article 33 on breach notification, Article 35 on data protection impact assessments, and Article 48 on transfers or disclosures not authorised by Union law. It goes further and says a controller "may very well conclude that extensive security measures are needed, or even that it would not be lawful, to conduct or proceed with a specific processing operation in a third country although there is no transfer situation."

There is also a transparency obligation that is easy to miss. Where a controller intends to process personal data outside the EU even though no transfer takes place, the EDPB says "this information should as a rule be provided to individuals as part of the controller's transparency obligations." In plain terms: if your support team is in Egypt and they can see customer records, your privacy notice should say that processing happens outside the EEA. Many companies in this position have never updated the notice, and it is a cheap fix.

So the correct summary of the no-transfer position is not "nothing to do." It is "no Article 46 instrument required, and the same security, accountability, and transparency work you would do anyway, done properly and documented."

If it is a transfer, the work is well-mapped

None of this is uncharted. Restricted transfers to countries without adequacy are routine and the tooling is mature.

The standard instrument is the set of standard contractual clauses in Commission Implementing Decision (EU) 2021/914 of 4 June 2021, adopted under Article 46(2)(c). The clauses are modular, with four modules covering controller to controller, controller to processor, processor to processor, and processor to controller. Picking the wrong module is one of the more common errors, and for a typical Egypt engagement where the counterparty handles your data on your instructions, the controller to processor module is usually the starting point.

Signing the clauses is not the whole job. Following the Court of Justice's judgment in Schrems II (C-311/18, 16 July 2020), an exporter has to assess whether the safeguard will actually be effective given the law and practice of the destination country, and to add supplementary measures where it would not be. The EDPB set out the method in Recommendations 01/2020 on measures that supplement transfer tools, final version 2.0 adopted on 18 June 2021, as a six-step roadmap: map your transfers, identify the transfer tool you rely on, assess whether that tool is effective in the circumstances of the transfer, adopt supplementary measures where needed, take any formal procedural steps, and re-evaluate at intervals.

For a staffing arrangement, the supplementary measures that tend to do real work are unglamorous and mostly technical rather than contractual. Give the person access to the minimum data the role genuinely needs rather than a general grant. Pseudonymise where the work does not require identifying anyone. Keep the data in your systems and have them work through managed access rather than exporting extracts to a personal machine. Encrypt in transit and at rest with keys you hold. Log access. Write a clear commitment on how government access requests are handled and escalated. Most of these are things a competent security team wants regardless of where the person sits, which is why this step is usually less painful than it sounds.

The UK is now a different question from the EU

If you are a UK business, the framework has moved and some of the advice circulating online predates the change.

The UK's own transfer instruments are the International Data Transfer Agreement and the Addendum to the EU clauses, both of which came into force on 21 March 2022. Alongside them the ICO expects a transfer risk assessment, the UK counterpart to the exercise Schrems II requires.

What changed is the standard those assessments are measured against. The Data (Use and Access) Act 2025, which received royal assent on 19 June 2025, amends Chapter V of the UK GDPR through Schedule 7 and replaces the "essentially equivalent" test with a data protection test asking whether protection in the destination country is not materially lower than under UK standards. The bulk of the data protection provisions came into force on 5 February 2026. The change is meaningful for a country like Egypt: a materially-lower threshold invites a holistic view of a third country's regime rather than a clause-by-clause comparison against UK law, and it applies both to government adequacy decisions and to the risk assessments businesses run themselves.

Two practical notes. A transfer risk assessment written before February 2026 was written against a standard that no longer applies, so it is worth revisiting. And Egypt's regime is now considerably more developed than it was when most existing assessments of it were drafted, which is the subject of the next section and which cuts in favour of the destination rather than against it.

Egypt's own law stopped being theoretical

Almost every English-language summary of Egyptian data protection written before late 2025 says some version of "Egypt has a law but no executive regulations, so it is not really enforced." That is now out of date, and anyone relying on it is working from a stale picture.

Egypt's Personal Data Protection Law No. 151 of 2020 sat for five years without the implementing regulations needed to make it operational. On 1 November 2025 the Ministry of Communications and Information Technology issued Decree No. 816 of 2025 enacting the Executive Regulations, which entered into force the following day. The Personal Data Protection Centre was confirmed as the supervisory authority. That started a one-year reconciliation period, and from 31 October 2026 entities within scope are expected to be in full compliance with the substantive obligations.

A note on sourcing before the detail. Published summaries of the decree do not all agree. Several firms report the instrument as Decision No. 81 of 2025 rather than 816, and issuance is variously dated to November and December 2025, most likely because the regulations were issued on 1 November and circulated more widely in December. Reports of when the PDPC's online licensing portal opens also differ, with some pointing to mid-2026 and others to the October deadline. The figures below come from published legal analysis rather than from the Arabic text of the regulations, which this guide has not read in the original. Treat them as a map of the terrain and verify the specifics with Egyptian counsel before you act on them.

With that caveat, the shape of the regime as reported in the ICLG Egypt chapter for 2026 and in law firm analysis of the regulations:

  • Licensing. Controllers and processors need a licence or permit to process personal data. Fees are tiered by record volume, with entities holding up to 100,000 records reported as exempt from fees and the top band reaching EGP 2 million for a three-year licence above five million records. The Centre is reported to have 90 days to decide an application, with non-response treated as rejection.
  • Cross-border transfers. Article 14 of the Law requires a licence or permit from the Centre before personal data is transferred, stored, or shared outside Egypt, and requires the destination to offer protection at least equivalent to Egypt's own. The transfer licence fee is reported at 50 percent of the applicable controller or processor licence fee. Limited exceptions with explicit consent exist for matters such as protecting life or medical care, exercising legal rights, performing a contract benefiting the data subject, judicial cooperation, and monetary transfers under applicable law.
  • Data protection officers. Appointment is reported as mandatory for legal entities acting as controllers or processors, with qualification, experience, and examination requirements attached to the role.
  • Breach notification. 72 hours to notify the Centre, and three working days to notify affected individuals after notifying the Centre.
  • Penalties. Fines reported in the range of EGP 500,000 to 5 million for processing without a licence, EGP 300,000 to 3 million for data security and breach notification failures, and EGP 200,000 to 2 million for failure to appoint a DPO, with imprisonment attached to certain offences including unlawful cross-border transfer.

Why an employer outside Egypt should care about an Egyptian statute

The instinct is to treat this as the Egyptian side's problem. That instinct is wrong in at least three ways, and each of them can reach a foreign employer.

Your hire's own data is Egyptian personal data. The HR file, the identity documents, the bank details, the performance notes. If you hold and process that abroad, you are processing personal data of a person in Egypt. The PDPL is reported to reach non-Egyptian businesses outside Egypt that process data of Egyptian nationals or of foreign residents in Egypt, subject to a dual-criminality condition, which is a meaningful limit but not one you should assume protects you without advice.

Data leaving Egypt is a licensed activity. This is the one that surprises people, because it is the mirror image of the question they started with. If your Egyptian contractor or your Egyptian entity holds personal data in Egypt and sends it to you abroad, that is an outbound transfer from Egypt under Article 14 and it needs a licence from the Centre. Companies focused entirely on the inbound GDPR question routinely miss the outbound Egyptian one.

The deadline is close and the counterparty may not be ready. 31 October 2026 is not far away, and licensing takes time when the reported decision window is 90 days. If you work with an Egyptian entity, whether a staffing partner, a subsidiary, or a supplier, their licensing status is a question worth asking now rather than in October. A partner who can describe where they are in the process has been paying attention. A partner who has not heard of Decree 816 has not.

There is a constructive reading here too. A destination country that has just stood up a supervisory authority, a licensing regime, breach notification duties, and criminal penalties is a stronger case in a transfer risk assessment than one with nothing on the books. Under the UK's new "not materially lower" test in particular, a maturing Egyptian regime is a fact in favour of the transfer, not against it. Egypt's compliance build-out is genuinely useful to the buyer's own paperwork.

What to actually do

A practical sequence for a company evaluating an Egypt hire with a data protection question attached.

  1. Decide what the person will actually touch. Most roles do not need production customer data. A support role might need a scoped view. An engineer might need none at all if the environment is set up sensibly. This single question changes the size of everything downstream, and it is worth answering before any legal analysis begins.
  2. Run the three criteria deliberately and write down the answer. Not as a formality. The result determines whether you need an Article 46 instrument, and the reasoning is what you will show a customer or a regulator who asks.
  3. Choose the engagement model with this in view. Employment by your own entity, an independent contractor, an employer of record, and a local subsidiary produce different answers. Pick deliberately rather than defaulting to whichever is administratively easiest.
  4. If it is a transfer, put the 2021/914 clauses in place with the correct module, add an Article 28 processing agreement where the counterparty is a processor, and complete a transfer impact assessment using the EDPB six-step method. UK exporters use the IDTA or the Addendum and a transfer risk assessment against the post-February 2026 standard.
  5. Do the technical measures regardless of the answer. Least-privilege access, pseudonymisation where possible, managed access instead of local extracts, encryption with your keys, and access logging. These are the measures that reduce actual risk, as opposed to the ones that produce documents.
  6. Update your privacy notice. If processing happens outside the EEA or UK, say so, including in the no-transfer case where the EDPB expects it as a matter of transparency.
  7. Ask your Egyptian counterparty about PDPL licensing. Their controller or processor licence, any cross-border transfer licence, their DPO, and their breach notification process. Ask before 31 October 2026.
  8. Have counsel check it. Data protection counsel where you are established, and Egyptian counsel for the PDPL side. This guide is a map of the questions, not an answer to them.

Sources and dates

Every factual claim above is dated, because compliance material ages badly and an undated assertion about a regulatory regime is worth very little. The EU analysis rests on EDPB Guidelines 05/2021 version 2.0 adopted 14 February 2023, EDPB Recommendations 01/2020 version 2.0 adopted 18 June 2021, Commission Implementing Decision (EU) 2021/914 of 4 June 2021, the CJEU judgment in C-311/18 of 16 July 2020, and the European Commission's adequacy list as it stood in August 2026. The UK analysis rests on the Data (Use and Access) Act 2025, which received royal assent on 19 June 2025 with the bulk of its data protection provisions in force from 5 February 2026, and on the IDTA and Addendum in force from 21 March 2022. The Egyptian analysis rests on Law No. 151 of 2020, Executive Regulations issued by ministerial decree on 1 November 2025, and published legal analysis of those regulations, with the divergences between sources noted in the section above rather than smoothed over.

Where this guide says something is "reported," that is deliberate. It marks a claim drawn from secondary legal analysis rather than from a primary text this guide has read directly, and it is a signal to verify before relying on it.

The practical bottom line

The compliance question is real and it deserves a real answer, but it is far more often a reason to structure an engagement carefully than a reason to abandon it. The three-criteria test does genuine work here, the no-transfer path is available in the arrangement many buyers would have chosen anyway, and the transfer path is a known set of documents rather than an obstacle. Meanwhile the destination country has spent the last year building the supervisory apparatus that makes the paperwork easier to defend.

What tends to go wrong is not the law. It is a company reaching a vague conclusion early, never writing it down, and then discovering during a customer security review that it cannot explain its own position. An afternoon spent on the three criteria and a short memo prevents that.

If you are working through this for a specific role, we are happy to have the detailed version of the conversation, including what a candidate would and would not need access to and how the engagement can be structured around that. Tell us what you are hiring for and we will introduce you to vetted Egyptian candidates. If you would rather talk it through first, book a meeting and bring your security team's hardest question. For the wider context on hiring into Egypt, our Labour Law No. 14 of 2025 guide covers the employment side and our guide to paying remote employees and contractors in Egypt covers getting money to them once they start.

Take the Delegation Quiz

Most founders are shocked by their results. Some get defensive. Others get motivated. All of them get clarity.

Ready to Work Smarter?

Turn recurring admin and support work into a clear role, then request vetted Egyptian candidates matched to the way your team actually operates.