What the PDPL is, in plain terms
Egypt's Personal Data Protection Law (Law No. 151 of 2020, commonly called the PDPL) sets out how businesses may collect, store and use people's personal data. For a restaurant, that data is not abstract: it is the customer's name, phone number, delivery address and order history — the things you need to take an order and the things a customer trusts you to look after.
This article is a plain-language explainer, not legal advice — for your specific obligations you should speak to a qualified professional. But the core idea is simple and worth understanding: personal data belongs to the person, you are looking after it, and you are expected to keep it safe and use it for what the customer reasonably expects.
What counts as customer data in a restaurant
It is easy to think 'we don't hold sensitive data — we sell food'. But the moment you take a delivery order, you are holding a name tied to a phone number tied to a home address tied to a purchase history. Put together, that is exactly the kind of personal data the law is about, and exactly the kind of data customers care about.
The practical questions the PDPL pushes you to ask are reasonable ones any customer would want answered: where is this data kept, who can see it, is it protected, and is it being used for what I agreed to? Having a clear answer is good practice regardless of the letter of the law.
The hidden cost of renting your customers from aggregators
Here is a point owners often miss: when orders come through a delivery aggregator, the customer's details usually belong to the platform, not to you. You served the food, but you may never hold the name, the number or the history — the platform does. That is convenient until you want to bring a regular back directly, and it also means the data relationship with your own customer sits with someone else.
Owning your customer channel changes that. When a customer orders on your own WhatsApp, their details land in your own dashboard — yours to look after, yours to serve them better with, and not rented back to you a slice at a time. Owning the relationship is also owning the responsibility, which is the honest trade: more control, and the duty to handle it well.
How good software helps you handle data responsibly
Software can't make you compliant on its own — that depends on how you run your business — but it can be built so the responsible path is the default. Orderlya is designed with a few privacy-minded foundations: each restaurant's data is kept strictly separated from every other restaurant on the platform, so one tenant can never see another's customers.
It is also careful with the most sensitive fields in its own internal logs: customer phone numbers, message contents and location are redacted from the platform's diagnostic logs, so the details needed to run your restaurant aren't scattered where they don't belong. These are foundations that make good data hygiene easier — not a substitute for your own policies and your own legal advice.
Trust is part of the product
Customers increasingly notice how their data is treated, and a restaurant that owns its customer relationship and looks after it carefully has an advantage over one that quietly hands everything to a marketplace. Handling data well isn't just about avoiding a fine — it is part of why a regular trusts you enough to order direct next time.
If you want to bring your customer relationships in-house on a platform built with separation and privacy foundations from the start, you can try it on a 14-day free trial, no credit card. Own the relationship, and look after it properly.