Solutions
Product
Pricing
Resources
Start free trial

Egypt PDPL Child Consent Rules: 2026 School Checklist

Egypt PDPL Child Consent Rules: 2026 School Checklist

Egypt’s PDPL splits child consent into two age tiers, and schools have until roughly November 2026 to get their enrollment and communication systems compliant. Under 15, a school needs explicit written guardian consent before collecting any personal data; from 15 to 18, either the student or the guardian can give it. Nothing in the Regulations carves out a lighter rule for schools, so these tiers apply to any school running an enrollment form, attendance app, or parent-communication platform — Egypt’s Executive Regulations classify children’s data as a heightened category of sensitive personal data, and the grace period to get compliant closes around the end of October or start of November 2026.

That deadline is close enough that “get to it next term” is no longer a safe plan. Here is what the rule actually requires, why it lands squarely on schools, and what to check before the countdown runs out. Jump straight to the 8-point checklist ↓

Egypt’s Personal Data Protection Law (No. 151/2020) has been in force since 2020, but its Executive Regulations — the instrument that operationalizes the law — were only issued via ministerial decree in late 2025 (sources cite the instrument as Decree No. 816/2025 or a related Minister of Communications Decision; the exact numbering is still inconsistently reported across legal trackers, so treat the decree number as unsettled rather than commit to one figure). The Regulations operationalized the law and started a one-year compliance clock Kennedys Law.

Article 15 of the Regulations sets the child-consent standard directly:

For any child under 15, a school (or any organization) must obtain “explicit written consent from the child’s legal guardian before any collection or processing of their data” Chambers and Partners. That consent must include time limitations and withdrawal rights, meaning a guardian can revoke it later — which in practice would require a school’s system to have a way to honor that revocation, not just record the original signature ICLG.

Between 15 and 18, the law allows either the student or the guardian to provide written consent ICLG. Practically, this would mean a school’s enrollment system needs to know a student’s age at the point of data collection and route the consent request differently depending on which side of that line the student falls — a single blanket consent checkbox for “parents” would no longer cover the full student body correctly.

The Regulations don’t stop at who signs. Egypt’s data protection authority (the PDPC) issued Data Subject Consent Guidelines specifying that consent must be personal, explicit, informed, specific, and freely given — presented primarily in Arabic, kept separate from privacy notices and general terms and conditions, and captured through a clear affirmative action rather than any implied or pre-ticked box Kennedys Law. For sensitive data — and children’s data is explicitly sensitive data under the Regulations — consent must also be in writing, paper or electronic Kennedys Law. One further requirement that changes how schools should build this, not just what they collect: the consent mechanism itself needs the PDPC’s approval before it goes live — a school (or its software vendor) cannot design a custom consent flow and simply deploy it Baker McKenzie.

Why this hits schools specifically

No source in this analysis identifies a school-specific carve-out in the Regulations — schools fall under the general children’s-data regime, with no sector exception written in GLA & Company. That absence of a carve-out is itself the operative fact: a school collecting enrollment details, attendance records, health notes, or payment information from a student under 18 is processing exactly the category of data the Regulations were written to protect, with no lighter-touch education exemption to fall back on.

Three details make the rule more consequential for schools than for a typical consumer app:

  • Children’s data is explicitly a heightened sensitive category, not merely data that “needs extra care” — the Regulations state this directly ADSERO, which triggers the written-consent-plus-guardian rule rather than the lighter standard that applies to ordinary personal data.
  • Data from child activities is capped at what’s strictly necessary and cannot be used for profiling, tracking, or behavioral monitoring ICLG. A school running a points-based rewards feature, a leaderboard, or an activity-streak tracker would want to check whether the feature ends up functioning as a behavioral profile of individual students.
  • Heightened protections extend to health and biometric data Chambers and Partners — relevant for any school that records allergies, medical conditions, or immunization status.

The compliance countdown: when does the deadline actually land?

The Regulations were formally issued on 1 November 2025, and the grace period was written as one year from that date — pointing to a deadline around 31 October or 1 November 2026, depending on how the count is applied ICLG Kennedys Law. But there’s a wrinkle worth planning around rather than ignoring: the Regulations weren’t made publicly available until 25 December 2025, nearly two months after the formal issuance date. That gap has created genuine uncertainty over whether Egypt’s regulator will hold organizations to the strict 1 November 2026 reading, or effectively extend the practical deadline toward the end of 2026 CMS Law. One Egypt-based advisory puts it plainly: “clarity on the exact calculation date remains pending” ADSERO.

The practical takeaway for a school administrator: don’t build a compliance plan around whichever date is most convenient. Treat 31 October 2026 as the working deadline, and treat any later date as a buffer you might get, not a date you’re entitled to.

A compliance checklist for schools

Match the checklist against what your enrollment system, communication app, and any third-party vendor actually do today:

  1. Age-tier your consent flow. Capture date of birth at enrollment and route students under 15 to a mandatory guardian-signature step; route students 15–18 to either a student or guardian consent step. Example: an enrollment form where entering a birthdate under the 15-year threshold automatically locks the “submit” button until a guardian’s own login or e-signature completes a separate consent screen — the student’s own click doesn’t count for that age group.
  2. Separate consent from your terms of service. A single checkbox reading “I agree to the Terms and Privacy Policy” does not meet the “separate from privacy notices and general terms” standard. Example: a standalone Arabic-first consent screen during enrollment, presented after the general terms screen, listing each data category collected (attendance, grades, health notes, payment records) with its own toggle rather than one combined agreement.
  3. Log withdrawal, not just signature. Under-15 guardian consent carries a right of withdrawal. Example: a “manage my consent” section in the parent portal where a guardian can revoke consent for a specific data category (e.g., photo/media use) and the system stops processing that category going forward, with a timestamped record of the change.
  4. Re-consent when you add a feature. A change in processing purpose requires an updated legal basis and fresh consent Access Partnership. Example: if a school adds a cafeteria payment module mid-year, trigger a targeted in-app banner or push notification asking parents to actively re-consent to the new data category before the feature activates — not a silent update to the original enrollment agreement.
  5. Check your activity and rewards features for profiling. If any feature ranks, scores, or tracks student behavior over time, confirm it isn’t collecting more than what’s strictly necessary for the activity itself, and isn’t being repurposed for behavioral analysis ICLG.
  6. Confirm your consent mechanism has (or can get) PDPC approval, since the Regulations require sign-off on the consent design itself, not just its content Baker McKenzie.
  7. Check where student data is stored. If your platform or vendor stores data outside Egypt, cross-border transfer licensing requires specifying the destination, purpose, data categories, and protective measures Access Partnership.
  8. Know your breach-notification clock. Organizations must notify the PDPC within 72 hours of a breach and affected individuals within 3 working days via their registered contact method Chambers and Partners; confirm your school (or vendor) can actually meet that window.

What happens if a school misses the deadline

Egypt’s PDPL backs these requirements with real financial exposure. Fines range from roughly EGP 200,000 to EGP 2 million depending on the violation, with certain offenses attracting fines of up to EGP 5 million, alongside criminal sanctions under Articles 35–40 of the law Kennedys Law. Specific tiers reported include operating without a required license (EGP 500,000–5 million), failing to appoint a data protection officer (EGP 200,000–2 million), and security breaches (EGP 300,000–3 million) ICLG. The law also has extraterritorial reach under Article 2, so an international school group processing Egyptian students’ data from outside the country isn’t automatically out of scope Kennedys Law.

None of the sources behind this article single out schools for special enforcement attention — the penalty structure applies to any regulated organization. But a school holding health records, payment data, and daily attendance on hundreds of minors is, by the Regulations’ own definition, handling exactly the sensitive category the law was built around.

What this means for your enrollment and communication system

Strip away the legal language and Egypt’s Executive Regulations reduce to one operational requirement for any school running a digital enrollment or communication system: capture consent by age tier, in Arabic, separate from your general terms, with a record of what was agreed to and the ability to withdraw it — and be ready to show that consent mechanism meets regulatory scrutiny before the 2026–2027 school year opens.

Building that logic into a spreadsheet or a generic form builder is possible, but it puts the burden of tracking two different consent thresholds, guardian relationships, and change-of-purpose re-consent entirely on office staff, term after term. Purpose-built school communication platforms exist specifically to model guardian-child relationships and consent state as structured data rather than paper trails. BeeNet is one implementation path: it ties parent accounts to verified guardian records and handles data protection as a core design constraint rather than an add-on, an approach that extends naturally to age-tiered consent requirements like Egypt’s. If your school is mapping enrollment and communication data flows against the 2026 deadline, see how BeeNet supports schools day to day.

References

  1. Kennedys Law LLP, “Egypt’s Personal Data Protection Law – the compliance countdown has begun,” 25 March 2026. https://www.kennedyslaw.com/en/thought-leadership/article/2026/egypt-s-personal-data-protection-law-the-compliance-countdown-has-begun/
  2. CMS Law, “Egypt’s PDPL: Executive regulations issued – one year compliance countdown begins,” 13 January 2026. https://cms.law/en/int/legal-updates/egypt-s-pdpl-executive-regulations-issued-one-year-compliance-countdown-begins
  3. ICLG / Global Legal Group, “Data Protection Laws and Regulations Report 2025–2026: Egypt,” 20 July 2026. https://iclg.com/practice-areas/data-protection-laws-and-regulations/egypt/
  4. Baker McKenzie (Connect on Tech), “Egypt: Important Data Protection Update,” 12 January 2026. https://connectontech.bakermckenzie.com/egypt-important-data-protection-update/
  5. Chambers and Partners, “A First Look at Egypt’s Personal Data Protection Executive Regulations,” 19 January 2026. https://chambers.com/articles/a-first-look-at-egypt-s-personal-data-protection-executive-regulations
  6. Access Partnership, “Egypt Finalises Executive Regulations to the Personal Data Protection Law (PDPL),” 11 February 2026. https://accesspartnership.com/opinion/egypt-finalises-executive-regulations-to-the-personal-data-protection-law-pdpl/
  7. ADSERO, “Executive Regulations Issued for Egypt’s Personal Data Protection Law: Business Impact and Compliance Considerations,” 8 January 2026. https://adsero.me/executive-regulations-issued-for-egypts-personal-data-protection-law-business-impact-and-compliance-considerations/
  8. GLA & Company, “A First Look at Egypt’s Personal Data Protection Executive Regulations,” 25 December 2025. https://www.glaco.com/blog/a-first-look-at-egypts-personal-data-protection-executive-regulations/

Ready to Transform Your School Communication?

Start saving time and increasing parent engagement with BeeNet.

Request Demo