Skip to content
HUJJAحجةHUJJA — law firm

Data Protection & Technology

Compliance with Egypt’s Personal Data Protection Law, technology contracting, and the licensing that sits around digital businesses.

Request a consultation on this practice

What we do

  • PDPL gap assessments and compliance programmes
  • Privacy notices, consent flows and records of processing
  • Cross-border transfer arrangements and licences
  • Data processing agreements with vendors
  • Breach response and notification
  • Software development, SaaS and licensing agreements
  • E-commerce and fintech regulatory advice
  • Telecoms and NTRA licensing

How a matter runs

  1. 01

    What we do

    A gap assessment against the PDPL and its executive regulations, delivered as a prioritised list.

    What you provide

    Access to your systems inventory and vendor list.

    Typical duration

    2–4 weeks

  2. 02

    What we do

    Documentation: privacy notice, consent mechanics, processing records, DPA templates.

    What you provide

    Sign-off from whoever owns the product and the marketing stack.

    Typical duration

    3–5 weeks

  3. 03

    What we do

    Licences and registrations where the activity requires them, including cross-border transfer.

    What you provide

    Corporate documents and a named data protection officer.

    Typical duration

    6–16 weeks

What it typically costs

What it typically costsData Protection & Technology
StructureIndicative band
Fixed fee — gap assessmentA scoped review with a prioritised remediation plan.EGP 45,000 – 140,000 by organisation size
Monthly retainerFor ongoing advisory work where volume is steady and predictable.EGP 15,000 – 60,000 per month, by scope
HourlyFor matters whose shape is not known at the outset. We agree a cap before starting.Partner EGP 3,500–5,500 · Associate EGP 1,200–2,200 per hour

What moves the number

  • The number of systems and vendors processing personal data
  • Whether data leaves Egypt, and to where
  • Whether the business handles sensitive data or children’s data
  • Whether a breach has already occurred

These are indicative ranges, published so you can budget before you call. A fixed quote follows the first meeting, once we know the facts. Fees are agreed in writing before any work begins.

Questions we're asked

Does the PDPL apply to us if we are not established in Egypt?

It can, where you process the data of individuals in Egypt. Establishment is not the only trigger.

Do we need a licence to transfer data abroad?

Cross-border transfer requires a permit from the data protection centre, subject to conditions. Build the timeline into any migration plan.

What are the penalties?

Administrative fines and, for some breaches, criminal liability for the responsible individual. That second point is what usually moves a board.

We had a breach. What is the first step?

Contain it, preserve the logs, and call us before notifying anyone. Notification obligations have short deadlines, and what you say in the first notice constrains everything afterwards.

Is our cookie banner compliant?

If it sets non-essential cookies before the visitor consents, no. This is the most common and most visible failure — and it is on the page a regulator will look at first.

Can you review a SaaS contract quickly?

Yes — a standard vendor agreement is usually a two to three day turnaround with a marked-up version and a short note on what to push back on.

Lawyers in this practice

Sectors

Tell us what happened. We'll tell you what your options are.

Request a consultation
Request a consultation