---
title: Data-Centric Security and Local Data Protection Laws in MENA
description: "Here’s a quick breakdown of the key data protection laws in three major MENA markets: the United Arab Emirates (UAE), Egypt and Saudi Arabia."
image: https://insights.comforte.com/hubfs/blog%20header%20compliance%20magnifying%20glass.jpeg
---

[![Hubspot_blog_logo](https://insights.comforte.com/hs-fs/hubfs/Hubspot_blog_logo.png?width=295&name=Hubspot_blog_logo.png)](http://www.comforte.com)

[![Subscribe](https://no-cache.hubspot.com/cta/default/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0)

[![blog header compliance](https://insights.comforte.com/hubfs/blog%20header%20compliance%20magnifying%20glass.jpeg)](https://insights.comforte.com/data-centric-security-and-local-data-protection-laws-in-mena)

[Thomas Stoesser](https://insights.comforte.com/author/thomas-stoesser) l Apr 21, 2022 l [Data Protection](https://insights.comforte.com/tag/data-protection), [Compliance](https://insights.comforte.com/tag/compliance)

# Data-Centric Security and Local Data Protection Laws in MENA

For today’s organizations, data security isn’t just a matter of mitigating financial and reputational risk. There are also major regulatory compliance hurdles to clear in virtually every jurisdiction. Understanding these competing requirements can be a complex, time consuming and expensive endeavor—especially for multi-nationals with outposts in many countries.

Perhaps among the least well understood regions is the Middle East and North Africa (MENA). Impressive GDP [growth predictions](https://ihsmarkit.com/research-analysis/mena-economic-outlook-2022-global-headwinds.html) of 5.2% in 2022 and 4.6% in 2023 might be attracting new investment in the region. But businesses must also be aware of the implications of processing the personal data of citizens and residents in MENA countries, even if they don’t have offices there.

To that end, here’s a quick breakdown of the key data protection laws in three major MENA markets: the United Arab Emirates (UAE), Egypt and Saudi Arabia.

## An opportunity to grow

The EU General Data Protection Regulation (GDPR) is the progenitor of most [new data protection laws that have sprung up](https://insights.comforte.com/countries-with-gdpr-like-data-privacy-laws?hsLang=en) around the world since it was rolled out in early 2018. Some are very similar to the regulation, others less so. Ideally, compliance should be treated not as an obligation, but an opportunity to enhance customer trust and provide a firm foundation for digital transformation and growth.

### Egypt

Egypt’s Data Protection Law (law no. 151 of 2020) came into force in October 2020, although organizations have a further 21 months grace period from this date to get their house in order. It applies to any data controller or processer managing personal data, and all personal data except for that handled by the Central Bank of Egypt. The data of non-Egyptians living in the country is also in scope. [Key principles](https://www.dataguidance.com/notes/egypt-data-protection-overview#:~:text=According%20to%20Article%206%20of,freedoms%20of%20the%20data%20subjects.) of the law align with the GDPR, including data minimization, accuracy and security, lawfulness and storage limitations.

Also like the GDPR, all breaches must be reported within 72 hours of discovery, dropping to 24 hours for incidents affecting national security. Companies failing to appoint a Data Protection Officer (also a GDPR requirement) could be fined two million Egyptian pounds ($109,000 USD), but there are lower fines for other infractions, such as processing personal info without the consent of the data subject. However, minimum prison sentences of three months are also possible for various offenses.

### The United Arab Emirates (UAE)

The [UAE Personal Data Protection Law](https://u.ae/en/about-the-uae/digital-uae/data/data-protection-laws) took effect on 2 January 2022, but the expectation is that businesses have until September 2022 to ensure they’re compliant. It applies to any private business processing personal information of UAE nationals and residents, whether they’re based inside or outside the country. Similarities with the GDPR include the concepts of “personal data,” “sensitive personal data,” “controllers,” “processors” and “consent.” The law also shares the GDPR principles of fairness, transparency and lawfulness, purpose limitation, data minimization, accuracy, security and confidentiality, and storage limitation.

However, [unlike the GDPR](https://www.whitecase.com/publications/alert/uae-issues-first-federal-sector-wide-data-protection-law), there’s no justification for processing personal data according to “legitimate interest.” Instead, it’s expected that consent will be obtained from individuals unless exceptions apply, such as that data processing is necessary to protect the public interest, defend a legal claim, protect the interests of the individual, fulfill UAE legal obligations, or perform a contract. Breaches must be reported to the UAE Data Office of Personal Data Breaches “immediately on becoming aware” of them. There’s no information yet available on how large financial penalties will be under the new law.

### Saudi Arabia

The kingdom’s [Personal Data Protection Law](https://www.squirepattonboggs.com/-/media/files/insights/publications/2021/12/saudi-arabias-new-personal-data-protection-law-key-action-points/saudi-arabias-new-personal-data-protection-law.pdf) came into force on March 23, 2022 although organizations will have a year’s grace period. It applies to all Saudi nationals and residents and applies to businesses outside the country processing the personal info of these individuals. There are similarities to the GDPR, including the definition of personal data and how it can be used, processed and retained. Foreign companies processing Saudi citizen and resident data must also appoint a local licensed representative.

However, like the UAE, the Saudi law requires “immediate” breach notification to the Saudi Data & Artificial Intelligence Authority (SDAIA) and data subjects. There are also stricter rules governing data transfers outside the kingdom. Fines top out at five million riyals ($1.3m USD), and some infractions could lead to imprisonment of up to two years.

## Why data-centric security?

GDPR and its regional variants were intended to empower consumers and drive increased confidence in brands. With [consumer trust in global brands at rock bottom](https://www.entrust.com/newsroom/press-releases/2021/data-from-entrust-reveals-contradictions-in-consumer-sentiment-toward-data-privacy-and-security), there’s a greater need for this approach today than ever. Viewed through this lens, compliance with local data protection laws can actually be a driver of business growth, rather than simply a mitigator of financial, reputational and regulatory risk.

The good news is that a data-centric security strategy can take a lot of the pain out of data protection compliance—in MENA and elsewhere. Rather than try to secure data at the perimeter, which can be ineffective against many modern cyber-threats, organizations should encrypt or tokenize it. This makes any data unreadable for attackers, even if they do manage to access it. By ensuring they have a continuous process in place for data discovery, classification and protection, organizations can reduce much of the risk associated with compliance in an increasingly complex global regulatory environment.

Encryption and pseudonymization are the only two data security controls mentioned by name in the GDPR. It makes sense to start any data compliance strategy here.

---

| Share this:  | [![LinkedIn](https://insights.comforte.com/hubfs/Social%20Icons/linkedin%20icon.png)](https://www.linkedin.com/shareArticle?mini=true&url=https://insights.comforte.com/data-centric-security-and-local-data-protection-laws-in-mena&utm_medium=social&utm_source=linkedin) | [![Bluesky](https://insights.comforte.com/hubfs/Social%20Icons/bluesky_logo.png)](https://bsky.app/intent/compose?url=https://insights.comforte.com/data-centric-security-and-local-data-protection-laws-in-mena&utm_medium=social&utm_source=Bluesky) | ![Twitter](https://insights.comforte.com/hubfs/Social%20Icons/twitter_x_logo-1.png) | [![XING](https://insights.comforte.com/hubfs/Social%20Icons/xing-color2.png)](https://www.xing.com/spi/shares/new?url=https://insights.comforte.com/data-centric-security-and-local-data-protection-laws-in-mena&utm_medium=social&utm_source=xing) | [![Email](https://insights.comforte.com/hubfs/Social%20Icons/email%20icon.png)](mailto:?subject=Check%20out%20https://insights.comforte.com/data-centric-security-and-local-data-protection-laws-in-mena&utm_medium=social&utm_source=email%20&body=Check%20out%20https://insights.comforte.com/data-centric-security-and-local-data-protection-laws-in-mena&utm_medium=social&utm_source=email) |
| --- | --- | --- | --- | --- | --- |

## Can you say for certain you know where all PANs are being stored?

Sometimes the hardest part about securing PANs wherever they're stored is actually knowing where they're stored. Check out the fact sheet below to learn more about data discovery and classification from comforte:

[![Download Fact Sheet](https://no-cache.hubspot.com/cta/default/4026697/49cc9442-9de2-4bbf-a42a-d41e2b8ec02c.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/49cc9442-9de2-4bbf-a42a-d41e2b8ec02c)

### Related posts

![Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/hubfs/comforte%20AG_%20Reuse%20Reward_%20How%20Banks%20Can%20Safely%20Unlock%20the%20Value%20of%20Their%20Data_03.2025.png)

 Mar 12, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Payments Transformation](https://insights.comforte.com/tag/payments-transformation) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

The financial world is awash with data. But too few organizations are able to use it effectively. In [Bank Director’s *2025 Technology Survey*](https://www.bankdirector.com/wp-content/uploads/2025/09/2025TechReport-OpenVersion.pdf), one-third of US banking leaders cite an inability to harness data as a top technology challenge facing their...

[Read more](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

![Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/hubfs/comforte%20AG_Delivering%20a%20Secure%2c%20Trusted%20Foundation%20for%20Cloud%20Growth%20at%20LGT_01.2026.png)

 Jan 15, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

There’s a world of difference between retail and private banking. While the former is transactional and focused on the mass market, the latter is built on trust and personal relationships. That trust can be hard won, but is easily lost, especially...

[Read more](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

![Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/hubfs/comforte%20AG_Top%20Indicators%20You%20Have%20a%20Cybersecurity%20Problem_and%20What%20to%20Do%20About%20It.png)

 May 22, 2025 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Digital Enablement](https://insights.comforte.com/tag/digital-enablement)

### [Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

Data is both blessing and curse to the modern enterprise. Yes, when analyzed effectively it can surface intelligence to improve decision making, customer engagement, process efficiency and, ultimately, drive revenue. But it also represents a major...

[Read more](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

### Service

- [Contact](https://www.comforte.com/contact/)
- [About us](https://www.comforte.com/company/)
- [Blog](https://insights.comforte.com/)
- [Press Releases](https://www.comforte.com/company/press-releases/)
- [Career](https://www.comforte.com/company/career/)
- [Resources](https://www.comforte.com/resources/)

### Germany

comforte AG  
Abraham-Lincoln-Str. 22   
65189 Wiesbaden  
Germany

Phone: + 49 611 93199 00  
Fax: + 49 611 93199 05

### Australia

comforte PTY  
Suite 20, 1 Rivett Road  
North Ryde  
NSW 2113  
Australia

Postal Address:   
PO Box 1710  
Lane Cove  
NSW 1595  
Australia

Phone: +61 2 8197 0272

### USA

comforte Inc.  
30 Wall Street, 8th Floor  
New York, NY 10005-2205  
USA

Phone: +1-646-438-5716

### Singapore

comforte Asia Pte. Ltd.   
1 Raffles Place, #19-61 Tower 2   
Singapore 048616

Phone: +65 6808 5507

- [Sitemap](https://www.comforte.com/sitemap/)
- [Legal Notice](https://www.comforte.com/legal-notice/)
- [Privacy Policy](https://www.comforte.com/privacy-policy/)

© comforte AG 2026

<https://x.com/comforteag> <https://www.youtube.com/c/comforte-ag> <https://www.linkedin.com/company/comforte-ag/>