EGYPT Law and Practice Contributed by: Ibrahim Shehata, Tasneem El-Naggar and Safa Rabea, Shehata & Partners
Data processors’ obligations under the PDPL in the context of IoT When applied to IoT services, the PDPL estab - lishes specific rights and obligations for data processors, ensuring the secure and responsi - ble handling of personal data processed by IoT devices. These obligations include: • conducting and implementing data process - ing pursuant to the PDPL and its executive regulations in accordance with legitimate and legal cases and based on the provisions stipulated under the PDPC; • ensuring the legitimacy of the purpose of the data processing and the practice thereof, and the non-violation of public order or morals; • not exceeding the purpose and period required for data processing, and notify - ing the controller, the data subject or each relevant person, as the case may be, of the period necessary for the data processing; • deleting the personal data following the lapse of the period for processing or delivering the data to the data controller; • undertaking or refraining from undertaking an action that would result in disclosing the personal data or disclosing the outcome of the data processing; • not undertaking any processing of personal data that contradicts the purpose or the activ - ity of the data controller unless such process - ing is for a statistical or educational purpose that is non-profit and without prejudice to the inviolability of private life; • protecting and securing the processing activ - ity, the mediums and the electronic devices used in processing, as well as the personal data thereon; • not causing harm, whether directly or indi - rectly, to the data subject; • maintaining a detailed record of data process - ing activities, including processing categories,
contact details, the DPO, processing scope and duration, mechanisms for data deletion or modification, and descriptions of security measures and procedures; • providing the means to prove the data pro - cessor’s compliance with the provisions of the PDPL, at the request of the data con - troller, and enabling the PDPC to conduct inspections and supervision to ensure compli - ance with the provisions of the PDPL; • obtaining a licence or permit from the PDPC in order to handle personal data; and • appointing a local representative when the data processor is outside Egypt. By integrating these obligations into their opera - tions, IoT service providers can build trust with users, ensure data protection and align with Egypt’s regulatory requirements for IoT and data processing activities. This ensures that, while IoT services advance connectivity and innovation, they also uphold the privacy and security of indi - viduals’ data. 3.4 Regulators and Enforcement Bodies Enforcing Data Regulation in Egypt in Relation to IoT National Telecommunications Regulatory Authority The NTRA oversees the regulatory framework for IoT services, including licensing, compli - ance with technical standards and adherence to national security requirements. It enforces rules on data confidentiality, operational transparency and the secure handling of IoT-generated data by service providers. Personal Data Protection Centre Established under the PDPL, the PDPC is respon - sible for enforcing data protection requirements, including the processing, retention and security of personal data generated by IoT devices. The
114 CHAMBERS.COM
Powered by FlippingBook