A regulated firm must be able to attribute activity to an identified person, and assets or accounts that make that impossible are barred at the licensed perimeter. This is a rule about attribution, not about whether amounts are public.
What Egypt actually says
Egypt inverts the usual shape of an entry in this section. There is no crypto privacy regime to describe because there is no lawful crypto activity: the banking law requires central bank approval to issue, trade or promote cryptocurrencies, and no approval has ever been granted. What is live instead is data protection. The 2020 personal data law sat without executive regulations for years and finally received them in 2025, turning it into a working supervisory regime with licensing requirements attached, including for cross-border transfers of personal data. For any firm handling Egyptian personal data, that transfer licence is the real compliance surface, and the grace period closes at the end of October 2026.
The instruments that matter
- Banking Law No. 194 of 2020
- prohibits issuing, trading or promoting cryptocurrencies without central bank approval, and the central bank has confirmed no licence has ever been issued, making it a prohibition in practice
- Personal Data Protection Law No. 151 of 2020
- its executive regulations were finally issued by ministerial decree in 2025, converting a statement of principles into a supervisory regime
- Licensing for data, not for crypto
- the regulations introduce specific licences including for cross-border personal data transfers, which is the binding constraint for any crypto-adjacent business operating there
- Grace period ends 31 October 2026
- giving roughly a year from issuance for organisations to comply
What this means for confidential transactions
Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.
Related entries
- BahrainMiddle East & Africa · A listing test written against effects, not asset names
- KenyaMiddle East & Africa · The ban written into primary legislation, not a rulebook
- KuwaitMiddle East & Africa · A ban whose stated reason is anonymity itself
- OmanMiddle East & Africa · The only rule found that names privacy wallets
- QatarMiddle East & Africa · Exclusion by perimeter rather than prohibition
- South AfricaMiddle East & Africa · A travel rule that starts at any value above zero
Compliant by default.
See how selective disclosure satisfies a supervisor without publishing your book to the world.