EGYPT Law and Practice Contributed by: Ibrahim Shehata, Tasneem El-Naggar and Safa Rabea, Shehata & Partners
claims related to data breaches or misuse by companies. • Consumer Protection Authority – under the Consumer Protection Law, the Consumer Protection Authority is empowered to file lawsuits on behalf of consumers harmed by widespread violations, including cases of unlawful data collection or misuse of, or insufficient safeguards for, personal data. This provides a practical avenue for consumers affected by systemic data protection viola - tions to pursue remedies collectively. Although not as robust as formal class action systems, these mechanisms offer pathways for collective action in data protection cases. For instance, if a company mishandles or unlaw - fully processes the personal data of multiple consumers, a consumer protection association could take legal action on their behalf, ensuring access to justice and promoting accountability. Egypt currently lacks a formal collective redress framework, but these tools indicate a growing recognition of collective interests in areas such as consumer rights and labour protections. As awareness of data protection laws increases, these mechanisms could play a significant role in addressing violations, paving the way for poten - tial legal reforms to establish a more comprehen - sive system for collective redress in the future. 3. Data Regulation on IoT Providers, Data Holders and Data Processing Services 3.1 Objectives and Scope of Data Regulation IoT Regulations in Egypt The NTRA issued the first regulatory framework addressing the IoT in January 2022. This frame -
work aligns with Egypt’s 2030 vision and the establishment of smart cities such as the New Administrative Capital. The framework outlines the objectives, scope and obligations for IoT services and data processing entities to ensure responsible use and governance of IoT tech - nologies. Main objectives and scope • Facilitating IoT growth – the framework aims to advance the spread and adoption of IoT services in Egypt by removing obstacles, creating a structured regulatory environment, and fostering innovation. • Defining IoT services – IoT is defined as a service enabling automatic communica - tion between objects or “things” through digital/electronic identities, facilitating data exchange, analysis and processing. Examples include connected devices such as refrig - erators, cars, power stations and sensors embedded in smart infrastructure. • Classifying IoT services – IoT services are classified into five categories based on their use. For instance, “consumer applications” include devices such as wearable technology and smart home systems, allowing users to monitor and manage their homes, whereas, “commercial applications” encompass intel - ligent transportation systems (ITS), surveil - lance systems and vehicle-to-vehicle (V2V) connections. Rights and Obligations of Data Holders and Data Processing Entities Data holders IoT technology mainly depends on the collection of data and its exchange, analysis and process - ing. Therefore, an IoT service provider is obliged to fulfil all necessary institutional and technical procedures and steps to protect the confiden - tiality of information and data of the service or
111 CHAMBERS.COM
Powered by FlippingBook