EGYPT Law and Practice Contributed by: Ibrahim Shehata, Tasneem El-Naggar and Safa Rabea, Shehata & Partners
end users, as per the general obligations pre - scribed by the NTRA IoT regulatory framework, the Telecommunications Law and particularly the Data Protection Law. Therefore, the condi - tions discussed under 1.1 Overview of Data and Privacy-Related Laws must be met. Data processing entities The NTRA IoT regulatory framework further grants several rights to data processing entities to facilitate their operation within the IoT eco - system while ensuring regulatory compliance. Entities are allowed to establish and operate IoT platforms for personal use, subject to obtaining the necessary permits from the NTRA. Licensed IoT service providers have the right to offer IoT services to end users through agreements with network operators, in adherence with the NTRA’s technical rules. Data processing entities also have the right to own and manage the data collected through their IoT platforms, provided they implement robust organisational and technical measures to protect user information and comply with applicable data protection laws. These rights are coupled with obligations, such as obtaining legal approvals, adhering to technical standards and safeguarding national security. By balancing these rights with responsibilities, the framework supports the growth of IoT services while ensur - ing the protection of user data and alignment with Egypt’s legal and regulatory environment. 3.2 Interaction of Data Regulation and Data Protection The interplay between data regulation and data protection requirements in Egypt reflects a structured approach to balancing technological advancement with individual privacy rights. Data regulation frameworks such as the Telecom - munications Law and the NTRA IoT regulatory
framework set operational standards for the law - ful collection, transmission and storage of data, ensuring that entities handling data comply with technical and procedural requirements. These regulations often apply to entities operating within specific industries, such as telecommu - nications or IoT service providers, with a focus on maintaining data integrity, security and lawful usage. On the other hand, the PDPL complements these regulations by addressing the rights of individu - als whose data is being processed. The PDPL ensures that personal data is handled transpar - ently and securely, with clear obligations on data controllers and processors to obtain consent, protect data from breaches, and limit processing to legitimate and declared purposes. Together, these regulations ensure that data is managed in compliance with operational standards, and also that it is protected against misuse or unau - thorised access. A practical example of this interplay is seen in IoT services, where providers must comply with the technical requirements set out by the NTRA while ensuring adherence to PDPL safeguards. For instance, while the IoT regulatory frame - work mandates the secure transmission of data through authorised networks, the PDPL requires service providers to obtain explicit user consent for data collection and processing, thus ensur - ing both operational compliance and privacy protection. This interplay is enforced through various regula - tory bodies, such as the PDPC and the NTRA, which monitor compliance with data protection laws and operational regulations. Such co-ordi - nation enables a comprehensive governance model that supports the growth of technology- driven services while ensuring that individual
112 CHAMBERS.COM
Powered by FlippingBook