cross-border-personal-data-transfer-in-digital-company-formation
Does Egyptian Law No. 151 of 2020 apply to a foreign client’s personal data even though the client is not an Egyptian national?
Generally yes — Egyptian data protection law typically applies based on where the processing occurs, not the nationality of the data subject. If the Egyptian lawyer collects, stores, or transmits the foreign client’s identity and signature data from within Egypt, that processing generally falls within the law’s scope, regardless of the client’s own nationality or residence status.
Who bears responsibility if a Chinese electronic signature or registration platform mishandles the client’s personal data — the Egyptian lawyer or the Chinese platform?
This depends on the specific role each party plays in the data processing, which should be clarified rather than assumed. Where the Egyptian lawyer collects and transmits the data, and the Chinese platform independently processes it for its own registration purposes, each party may bear separate, independent obligations under its own jurisdiction’s law — the Egyptian lawyer’s compliance under Egyptian law does not transfer liability for what the Chinese platform subsequently does with the data, and vice versa.
Should the client’s consent to data transfer be built into the main contract, or handled as a separate document?
Best practice is generally to document data transfer consent separately and explicitly, rather than burying it within the substantive contract, because data protection law typically requires consent (or another legal basis) to be specific, informed, and tied clearly to the particular transfer and purpose — a general contractual clause referencing “cooperation” or “necessary disclosures” is unlikely to satisfy this standard on its own.
Does using apostille or embassy legalization for the underlying documents (as discussed previously) also address the data protection questions, or are these completely separate compliance tracks?
These are completely separate compliance tracks. Apostille and legalization authenticate the origin and official status of a document; they say nothing about whether the personal data contained within that document was lawfully collected, processed, or transferred under any jurisdiction’s data protection law. A document can be perfectly legalized and still represent a data protection violation in how it was compiled or transmitted.
What is the most practical first step for an Egyptian lawyer handling this kind of file to manage the data protection dimension?
Map the data flow before the engagement begins: identify every point at which the client’s personal data will be collected, stored, or transmitted across a border, confirm the legal basis required at each point under Egyptian law, and separately confirm the receiving jurisdiction’s import requirements — ideally in writing from the receiving registrar or platform — rather than treating data protection as implicitly covered by the contract’s general confidentiality clause.