Egypt's Personal Data Protection Law (PDPL) No. 151 of 2020 is the legal framework governing the processing of personal data in Egypt. Diarak complies with this law fully.
1. Core principles
- Lawfulness: we process your data only on the basis of explicit consent, legitimate interest, or legal obligation.
- Purpose limitation: we collect data for defined purposes and do not repurpose without informing you.
- Data minimization: we collect only what we need to deliver the service.
- Accuracy: we keep your data accurate and update it on request.
- Limited retention: we delete data when we no longer need it.
- Confidentiality and security: technical and organizational safeguards against unauthorized access.
2. Your rights under the law
- Right of access: request a copy of the data we hold about you.
- Right to rectification: correct inaccurate data.
- Right to erasure: request deletion (with limited legal exceptions).
- Right to restrict: temporarily halt processing of your data.
- Right to portability: receive your data in a structured, machine-readable format.
- Right to object: refuse processing for marketing or automated decisions.
- Right to withdraw consent: at any time, without affecting prior processing.
To exercise any right: dpo@diarak.com — we respond within 30 days.
3. Data Protection Officer (DPO)
We have appointed a dedicated officer to oversee compliance. Reach them directly at dpo@diarak.com.
4. Security measures
- TLS 1.3 encryption for all traffic.
- Field-level encryption for sensitive data (ID documents, licenses).
- Passwords stored with bcrypt.
- Regular security reviews and penetration tests.
- Audit logs for every change to sensitive data.
- Ongoing staff training on data-protection protocols.
5. Data breaches
If a breach occurs that may affect your rights, we notify you within 72 hours of discovery and report to the competent regulator under Article 40 of the law.
6. International transfers
Some data is stored with cloud providers that may have servers outside Egypt. We ensure such transfers are governed by binding Data Processing Agreements (DPAs) providing the legally required level of protection.
7. Filing a complaint
You have the right to file a complaint with the Personal Data Protection Center of the Ministry of Communications and Information Technology if you believe your rights have been violated.
8. Retention periods
- Account data: duration of account activity + 3 years.
- Broker verification documents: 5 years after approval ends.
- Deal records: 7 years (for tax purposes).
- Audit logs: 2 years.
Note: This document is a general compliance description. For an official PDF copy for your records, email dpo@diarak.com.