Skip to main content

Recipe Codes

If your website collects names, phone numbers, emails or browsing data from people in Egypt or Saudi Arabia, data protection law applies to you. Egypt’s Personal Data Protection Law (Law No. 151 of 2020) and Saudi Arabia’s Personal Data Protection Law (PDPL) both expect you to collect only what you need, tell people clearly what you do with it, get valid consent where required, keep it secure and respond to their requests. This checklist walks through the practical website steps; it is general guidance, not legal advice.

Why this matters for websites in Egypt and Saudi Arabia

Both laws are built on the same core ideas found in modern privacy laws worldwide: transparency, purpose limitation, data minimisation, security and individual rights. In Egypt, the law establishes a Personal Data Protection Center as the regulator. In Saudi Arabia, the PDPL is overseen by the Saudi Data and Artificial Intelligence Authority (SDAIA) and has been in force since 2023.

The details differ between the two countries, including licensing, registration and cross-border rules, and implementing regulations continue to develop. If you serve customers in both markets, plan to meet the stricter requirement on each point and confirm the specifics with a lawyer who practises in that country.

Step 1: Map the personal data your website collects

You cannot protect what you have not listed. Start with a simple inventory of every place your site touches personal data:

  • Forms: contact forms, quote requests, newsletter sign-ups, job applications, account registration and checkout.
  • Cookies and similar technologies: session cookies, preference cookies, advertising cookies and local storage.
  • Analytics and tracking: tools such as web analytics, advertising pixels, heatmaps and session recording.
  • Third-party embeds: chat widgets, maps and videos, which often set their own cookies.
  • Server logs and backups: IP addresses, user agents and copies of your database.

For each item, note what data is collected, why, where it is stored, who can access it and how long it is kept.

Step 2: Collect less (data minimisation)

Review every form field and ask whether you genuinely need it for the stated purpose.

  • Remove optional fields that nobody uses, such as date of birth on a contact form.
  • Avoid collecting sensitive data, for example national ID numbers, health information or religious affiliation, unless it is strictly necessary. Sensitive data carries stricter rules under both laws.

Step 3: Write a clear privacy notice in Arabic and English

Your privacy notice should explain, in plain language, what you collect, why, the legal basis or consent you rely on, who you share it with, whether data leaves the country, how long you keep it and how people can exercise their rights.

  • Publish it in both Arabic and English if your audience includes Arabic speakers. A notice people cannot read does not inform them.
  • Link to it from the footer of every page and next to every form.
  • Keep it consistent with what the site actually does. A notice that says “we do not use tracking” while a pixel fires on every page is worse than no notice.

Step 4: Get valid consent where it is required

Consent is not the only legal basis for processing, but on websites it is often the relevant one, especially for marketing and non-essential cookies. Good consent is:

  • Specific: separate checkboxes for separate purposes, for example “contact me about my request” and “send me marketing emails”.
  • Active: unticked by default. Pre-ticked boxes are not meaningful consent.
  • Recorded: store the date and time, what was agreed to and which version of the notice was shown.
  • Easy to withdraw: as easy to withdraw as it was to give, for example a one-click unsubscribe link in every marketing email.

Step 5: Load tracking scripts and cookies only after consent

This is one of the most common gaps on business websites. Analytics tags, advertising pixels and session recording tools often load the moment the page opens, before the visitor has agreed to anything.

  • Use a cookie banner that actually blocks non-essential scripts until the visitor accepts, not one that only displays a message.
  • Offer a clear “Reject” option alongside “Accept”, plus a way to change the choice later.
  • Configure session recording tools to mask form inputs, especially passwords, phone numbers, ID numbers and payment details.
  • Test it: open your site in a private window, do not accept cookies, and check your browser’s developer tools to confirm no tracking requests are sent.

Step 6: Secure the basics

Both laws require appropriate technical and organisational security measures. For most websites, the essentials are:

  • HTTPS everywhere with a valid certificate and redirects from HTTP.
  • Access control: unique accounts for each admin, strong passwords, two-factor authentication and the minimum permissions each person needs. Remove accounts for people who have left.
  • Updates: keep your CMS, plugins, themes and server software patched, and remove plugins you no longer use.
  • Backups: regular, encrypted, stored separately and tested by actually restoring them.
  • No personal data in URLs or logs: do not pass emails, phone numbers or tokens in query strings, as URLs end up in logs and analytics.

Step 7: Set retention periods and delete old data

Keeping data “just in case” increases risk without adding value.

  • Set a retention period for form submissions, leads, job applications and customer records.
  • Automate deletion where your tools allow it, for example form entries older than a set period.
  • Remember that backups and email inboxes also hold personal data. Your retention plan should cover them too.

Step 8: Be ready for data subject requests

Individuals have rights over their data, including the right to know what you hold, to access it, to correct it and, in many cases, to have it deleted. Prepare before the first request arrives:

  • Provide a clear contact method in your privacy notice, such as a dedicated email address.
  • Know where to search: database, form plugin, CRM and email tools.
  • Verify the person’s identity before releasing or deleting data.

Step 9: Check where your data goes (cross-border transfers)

Many website tools store data outside Egypt and Saudi Arabia: hosting, email marketing, CRM, analytics and chat tools are often based in Europe or the United States. Both laws place conditions on transferring personal data abroad, and the conditions are not identical.

  • List each external service and the country where it stores and backs up data.
  • Mention international transfers in your privacy notice.
  • Ask a qualified lawyer whether your specific transfers need additional safeguards, approvals or contracts in each country.

Step 10: Prepare a breach response plan

Both frameworks expect organisations to notify the regulator, and in some cases affected individuals, within a short time after discovering a personal data breach.

  • Name a person responsible for handling incidents.
  • Write down the first steps: contain the problem, preserve evidence, assess what data was affected.
  • Confirm the exact notification deadlines and procedures with a lawyer in each country you operate in.

Frequently asked questions

Does a small business website need to follow these laws?

If the site collects personal data from people in Egypt or Saudi Arabia, the laws can apply regardless of company size. Some obligations, such as registration or appointing a data protection officer, may depend on the type and volume of processing, so confirm your situation with a qualified lawyer.

Is a cookie banner enough on its own?

No. A banner only helps if it actually blocks non-essential cookies and scripts until the visitor agrees, offers a real choice to reject, and is backed by an accurate privacy notice.

Do I need my privacy notice in Arabic?

If your audience includes Arabic speakers, providing the notice in Arabic as well as English is the practical way to make sure people understand it.

Can I use analytics tools hosted outside Egypt or Saudi Arabia?

Often yes, but transfers abroad are subject to conditions under both laws. List the tools you use, mention transfers in your notice and ask a lawyer whether further safeguards are needed.

Need help making your website privacy-ready?

Recipe Codes designs and builds websites for businesses in Egypt and Saudi Arabia and can help you set up consent-aware tracking, secure forms and bilingual Arabic and English layouts. Learn more about our website design and development services or see our privacy and cookie policy as an example. If you would like us to review your site’s forms, cookies and tracking setup, get in touch with our team.