EGYPT Law and Practice Contributed by: Ibrahim Shehata, Tasneem El-Naggar and Safa Rabea, Shehata & Partners
mous amounts of personal data. Such advanced technologies are generally subject to the PDPL, which provides a comprehensive framework for protecting personal data. However, the Telecommunications Law adds an additional layer of protection specific to the telecommunications sector. For example, the Telecommunications Law requires licensed operators to ensure the confidentiality of the communications and private calls of their cus - tomers, and mandates the establishment of necessary rules to guarantee this confidential - ity, further reinforcing privacy protections in this sector. This sector-specific law reinforces the privacy protections already granted under the PDPL, ensuring robust safeguards tailored to the unique risks posed by telecommunications and The Cybercrimes Law No 175/2018 on combat - ting IT crimes and its executive regulation No 1699/2020 regulate online activities and aim to penalise, inter alia, unlicensed online activity and content violations, such as illegally accessing a private device or account, which is a very pos - sible crime under sensitive digital technologies. Under the Cybercrimes Law, service providers have a number of obligations that, to a great extent, protect service users, such as: • keeping and storing the record of the informa - tion system or any means of IT, for a continu - ous period of 180 days; • maintaining the confidentiality of the data that has been saved and stored; • not disclosing the data without a justified order from a competent judicial authority; and emerging technologies. The Cybercrimes Law
• securing data and information in a manner that preserves its confidentiality, and does not penetrate or damage it. Service providers are also required to under - take technical and control measures to prevent cyber-attacks and safeguard the security of the technology and information system, such as encryption, multi-factor authentication, and other security alerts. Other regulations Fundamental privacy and data protection provi - sions to regulate sensitive digital technologies and penalise infringements are further specified in a number of dispersed regulations, which apply whenever they are applicable to the case in hand, such as the following. • Law No 58/1937 issuing the Criminal Law, as amended (the “Penal Code”) – Articles 309 (bis) and 309 bis (A) penalise invasion of privacy and the obtaining and disclosing of personal information without lawful means. • Law No 15/2004 regulating e-signatures and establishing the Information Technology Industry Development Agency (ITIDA) and its executive regulations provides that applicants for e-signature services must ensure, among other things, a secured system to preserve the secrecy and privacy of the information as per legal standards, and a system to preserve the confidentiality of information relating to the performance of licensed services and customers’ data. • Decree No 667/2017 by the Minister of Telecommunications and Information Tech - nology issuing the contravention and penalty regulations on communication service provid - ers – generally, these regulations set out the penalties to be applied when telecommuni - cations service providers breach regulations
102 CHAMBERS.COM
Powered by FlippingBook