EGYPT Law and Practice Contributed by: Ibrahim Shehata, Tasneem El-Naggar and Safa Rabea, Shehata & Partners
by the National Telecommunications Regula - tory Authority (NTRA) issued in connection with users’ rights protection. These same regulations also penalise telecommunica - tions service providers for infringing the data privacy requirements provided in the service provider’s licence. • NTRA regulations in connection with obtain - ing a communication licence and providing communications services in Egypt. • NTRA general rules in connection with pro - tecting internet users’ rights – Article (12) obliges communication service provider to preserve the secrecy of customers’ informa - tion and not to disclose such information except in the cases permitted by law. • NTRA general rules in connection with pro - tecting mobile and telephone users – Article (22) obliges communication service providers to preserve the secrecy of customers’ infor - mation and not to disclose such information except in cases permitted by law. • NTRA guidelines on consumers’ rights and obligations. Interplay Between the Egyptian Privacy and Data Protection Legal Framework and the GDPR The main intention of the authorities issuing the PDPL is twofold: to keep pace with current developments in the field of communications technology and to protect the right to privacy. Most importantly, the PDPL reflects significant influence from the European General Data Pro - tection Regulation (GDPR), incorporating many of its key principles, including the following. Definitions for data protection The PDPL outlines a list of definitions for data protection that are binding and are included in the legal framework. According to this prin - ciple, the law must contain clear concepts for
personal data and sensitive personal data, and must include the procedures followed to protect personal data during communications, which preserves the privacy of those communications and the privacy of the data that is exchanged. The PDPL has provided clear definitions of per - sonal data and sensitive personal data, as well as a definition of the holder of information and the processor, and seeks to preserve the right of the data subject, whether the processor is represented by an individual or a company. This is done by criminalising, for instance, the use of data without the knowledge of its owner or non-compliance with the data owner’s right to view their data. Legal basis for processing The PDPL determines the legal basis that allows the data to be processed. This principle oblig - es the law to define a legal basis for any entity that processes personal data to guarantee its safety by implementing the terms of the contract according to the user’s consent, as well as the user’s rights, such as giving the user the right to withdraw consent. In this regard, Article (2) of the PDPL guarantees “the right to withdraw prior consent to the retention or processing of personal data”. Binding users’ rights The PDPL includes a list of users’ rights that are binding under the law. This principle guarantees users rights and control over their data, such as the right of objection, erasure or correction, the right to receive information, and the right to enquire. The PDPL guarantees all these rights, but sets a fee for exercising these rights, with the exception of the right to enquire in the event of personal data violation. The fee may not exceed EGP20,000, with the Data Protection Centre being responsible for issuing decisions related
103 CHAMBERS.COM
Powered by FlippingBook