# Egypt

> Egypt (Central Bank of Egypt · Personal Data Protection Center): Crypto barred, so data protection is the live constraint. Region: Middle East & Africa. Attribution required: A regulated firm must be able to attribute activity to an identified person, and assets or accounts that make that impossible are barred at the licensed perimeter. This is a rule about attribution, not about whether amounts are public.

Part of the Soda Labs Privacy Hub regulation map, which reads the instruments
themselves rather than summarising the summaries: https://www.sodalabs.xyz/privacy-hub/regulation

## Key facts

- Entry type: Jurisdiction
- Region: Middle East & Africa
- Subject: Crypto barred, so data protection is the live constraint
- Authority: Central Bank of Egypt · Personal Data Protection Center
- Stance on on-chain confidentiality: Attribution required. A regulated firm must be able to attribute activity to an identified person, and assets or accounts that make that impossible are barred at the licensed perimeter. This is a rule about attribution, not about whether amounts are public.
- Tags: de facto ban, PDPL 151/2020, cross-border licence, deadline 2026
- Canonical page: https://www.sodalabs.xyz/privacy-hub/regulation/jur-egypt

## What it actually says

Egypt inverts the usual shape of an entry in this section. There is no crypto privacy regime to describe because there is no lawful crypto activity: the banking law requires central bank approval to issue, trade or promote cryptocurrencies, and no approval has ever been granted. What is live instead is data protection. The 2020 personal data law sat without executive regulations for years and finally received them in 2025, turning it into a working supervisory regime with licensing requirements attached, including for cross-border transfers of personal data. For any firm handling Egyptian personal data, that transfer licence is the real compliance surface, and the grace period closes at the end of October 2026.

## The instruments that matter

- **Banking Law No. 194 of 2020**: prohibits issuing, trading or promoting cryptocurrencies without central bank approval, and the central bank has confirmed no licence has ever been issued, making it a prohibition in practice
- **Personal Data Protection Law No. 151 of 2020**: its executive regulations were finally issued by ministerial decree in 2025, converting a statement of principles into a supervisory regime
- **Licensing for data, not for crypto**: the regulations introduce specific licences including for cross-border personal data transfers, which is the binding constraint for any crypto-adjacent business operating there
- **Grace period ends 31 October 2026**: giving roughly a year from issuance for organisations to comply

## Sources

- [Egypt data protection update](https://www.bakermckenzie.com/en/insight/publications/2026/01/egypt-important-data-protection-update)

## Related entries

- [Bahrain](https://www.sodalabs.xyz/privacy-hub/regulation/jur-bahrain): A listing test written against effects, not asset names
- [Kenya](https://www.sodalabs.xyz/privacy-hub/regulation/jur-kenya): The ban written into primary legislation, not a rulebook
- [Kuwait](https://www.sodalabs.xyz/privacy-hub/regulation/jur-kuwait): A ban whose stated reason is anonymity itself
- [Oman](https://www.sodalabs.xyz/privacy-hub/regulation/jur-oman): The only rule found that names privacy wallets
- [Qatar](https://www.sodalabs.xyz/privacy-hub/regulation/jur-qatar): Exclusion by perimeter rather than prohibition
- [South Africa](https://www.sodalabs.xyz/privacy-hub/regulation/jur-south-africa): A travel rule that starts at any value above zero
