Data Protection and Privacy 2025

EGYPT Law and Practice Contributed by: Ibrahim Shehata, Tasneem El-Naggar and Safa Rabea, Shehata & Partners

PDPC conducts inspections, grants licences for data processing activities, and ensures compli - ance with privacy and data security standards. Ministry of Telecommunications and Information Technology (MCIT) The MCIT provides overarching supervision of IoT policy and ensures alignment with Egypt’s digital transformation goals. It collaborates with the NTRA to support IoT development while safeguarding data privacy. Consumer Protection Authority (CPA) The CPA enforces the Consumer Protection Law, ensuring IoT service providers protect consumer rights, including the privacy and confidentiality of personal data. These bodies work collaboratively to ensure IoT services in Egypt operate securely, comply with data regulations, and respect user privacy while advancing technological innovation. Requirements for the Use of Cookies in Egypt Specific cookie regulations akin to those under the EU GDPR (eg, cookie banners) are not explic - itly legislated in Egypt, but cookie usage falls under the broader frameworks of the PDPL and other related privacy laws, as outlined under 1.1 Overview of Data and Privacy-Related Laws . These laws outline the following requirements for data collection and processing that apply to cookies when they involve personal data. • Consent – cookies that collect personal data require the user’s explicit consent before being deployed. This applies to cookies used for purposes beyond what is strictly neces - 4. Sectoral Issues 4.1 Use of Cookies

sary for the website’s basic functionality, such as analytics or marketing. • Transparency – users must be informed about the types of cookies used, their purpose, and how their data will be processed. This can be achieved through a clear and accessible cookie policy. • Purpose limitation – cookies must only collect and process data for legitimate, declared and specific purposes. The data collected should not exceed what is necessary for these pur - poses. • Right to opt-out – users must be provided with a mechanism to manage or decline non- essential cookies. This ensures compliance with the PDPL’s requirement for respecting data subject rights. • Retention and deletion – data collected through cookies must be retained only for the duration necessary to achieve the intended purpose, and deleted or anonymised thereaf - ter. • Security measures – website operators must implement technical and organisational meas - ures to ensure the security of data collected through cookies, preventing unauthorised access or misuse. Practical implementation Website operators using cookies in Egypt should: • provide a cookie banner or similar tool to obtain user consent before activating non- essential cookies; • offer a cookie policy that outlines the types of cookies used, their purpose, and how users can manage or revoke consent; and • regularly review and update cookie practices to align with the evolving regulatory environ - ment.

115 CHAMBERS.COM

Powered by