Listed On

corporate law firms in Egypt - corporate law firms in Egypt
The Legal 500 EMEA

Cybercrimes under the Anti-Cyber and Information Technology Crimes Law

الجرائم الالكترونية - Cybercrimes

Cybercrimes have become one of the major challenges facing legal systems around the world, including Egypt. With the rapid technological development and the increasing reliance on the Internet in various aspects of daily life, there has become an urgent need to regulate this digital space and protect users from cyber threats. The Egyptian Anti-Cybercrime Law serves as a key instrument for addressing such threats, as it establishes a legal framework defining the penalties and legal procedures necessary to combat various types of cybercrimes.

What are Cybercrimes and Their Concept under Law No. 175 of 2018?

Cybercrimes are unlawful acts committed through the Internet or electronic devices and vary between violations of privacy, electronic fraud, unauthorized access to information systems, cyber hacking, and electronic extortion. These crimes include all activities aimed at causing harm to individuals, institutions, or governments through the exploitation of modern technologies. Under Egyptian law, cybercrimes are classified as criminal offenses, and their perpetrators are subject to severe penalties due to the risks they pose to public security, the national economy, and individual rights.

The Difference Between Cybercrimes and Traditional Crimes:

  • Cybercrimes: They are committed through digital means and require technical evidence.
  • Traditional crimes: They are committed through tangible physical means.
  • The difference: The difference lies in the means of commission and the nature of the evidence and proof.

As for persons outside the country

The difference lies in the fact that traditional crimes require physical presence and are restricted by the territorial boundaries of the State, whereas cybercrimes are committed through the digital space and transcend national borders, whereby the perpetrator or the affected person may commit such crimes or become a victim thereof from anywhere in the world without any physical contact.

Protection of Personal Data and Information

Data protection is a personal data protection grants Egyptian citizens several rights to ensure their control over how their personal data is used. One of the fundamental rights is the right of access, which allows individuals to request a copy of their personal data held by an institution. This ensures transparency and provides individuals with an understanding of how their data is handled.

  1. Securing personal accounts: By using strong passwords and enabling two-factor authentication to ensure the protection of personal data.
  2. Beware of suspicious links: Refraining from clicking on untrusted links that may be used as a means to steal personal data or compromise systems.

Protection of the State’s Information Systems and Government Authorities

Companies and institutions that collect, process, or store personal data in Egypt must comply with strict procedures to protect individuals’ privacy. One of the fundamental obligations is to obtain consent before processing personal data. Institutions must also ensure that individuals expressly consent to the collection and use of their personal information. Such consent must also be clear, informed, and freely given, and individuals must have the ability to withdraw it at any time.

Penalties for Attacks on Information Systems Belonging to the State

Any person who intentionally accesses, or unintentionally accesses and remains without lawful right, or exceeds the limits of the right granted to him in terms of time or level of access, or breaches a website, e-mail, private account, or information system administered by or for the account of the State or any public legal person, or owned by or belonging thereto, shall be punished by imprisonment for a period of not less than two years and a fine of not less than fifty thousand Egyptian Pounds and not exceeding two hundred thousand Egyptian Pounds, or by either of these two penalties.

Technical Requirements to Be Complied with by Service Providers for the Protection of Data

  1. Obtaining or receiving the data from the holder thereof or from the competent authorities responsible for providing such data, as the case may be, after obtaining the consent of the data subject, or in cases permitted by law.
  2. Verifying the accuracy, consistency, and adequacy of the data in relation to the specified purpose for which it was collected.
  3. Establishing the method, manner, and standards of processing in accordance with the specified purpose, unless it is decided to authorize the processor to determine the same pursuant to a written contract.
  4. Ensuring that the specified purpose for collecting personal data applies to the purposes of processing such data.
  5. Performing or refraining from performing any act that would make the data available, except in cases permitted by law.
  6. Taking all technical and organizational measures and applying the necessary standard criteria for the protection and security of personal data in order to preserve its confidentiality and prevent its breach, destruction, alteration, or tampering through any unlawful action.
  7. Erasing the data in its possession immediately upon the expiry of the specified purpose thereof. However, where such data is retained for any legitimate reason after the expiry of such purpose, it must not remain in a form that permits the identification of the data subject.
  8. Correcting any error in the personal data immediately upon being notified thereof or becoming aware thereof.
  9. Maintaining a special data register, which shall include a description of the categories of personal data in its possession, identification of the persons to whom such data will be disclosed or made available and the legal basis thereof, the relevant time periods, restrictions and scope, the mechanisms for erasing or modifying the personal data in its possession, any other data relating to the cross-border transfer of such personal data, and a description of the technical and organizational measures relating to data security.
  10. Obtaining a license or permit from the Center to process the data.

Additional Requirements for Critical Information Infrastructure Systems

1- According to the institution’s needs, cloud service providers may provide additional tools and software to enhance security, load balancing, monitoring, aggregation, access to logs, backup and recovery, redundancy, and serverless infrastructure solutions. These options provide institutions with the required level of control and automation without the need for significant investment in developing and installing them themselves. As explained below, the virtual machines of cloud service providers enable institutions to install the operating system, software, databases, and other components of their choice, while benefiting from the provider’s tools.

2- Networks: Networks consist of elements such as bridges, gateways, routers, and switches that are virtualized for use by cloud computing consumers.

Storage: The most common types of computing storage include the following:

  • Object Storage: An inexpensive method for storing any type of unstructured data, including images, documents, binary blocks, and binary data.
  • Block Storage: Divides data into blocks, allowing it to be distributed across different platforms.
  • File Storage: A storage method oriented toward structured and hierarchical data.
  • Graphics Processing Units: These computing resources process workloads such as algorithm training and embedded systems.

The Egyptian Anti-Cybercrime Law encompasses a variety of crimes committed in cyberspace, the most common of which may be classified as follows:

A) Crimes Related to Violations of Privacy:

These include crimes involving the hacking of personal accounts, spying on private data, or publishing personal information without authorization. The law prescribes strict penalties for anyone who infringes upon the electronic privacy of individuals, and in some cases, the penalty may extend to imprisonment and a fine.

B) Crimes Related to Electronic Fraud:

Electronic fraud includes the use of the Internet or electronic devices to unlawfully obtain money or property. This may include fraud through e-mail, fraudulent online shopping, or fraudulent trading in financial markets. Egyptian law punishes perpetrators of these crimes with penalties that may include imprisonment and a fine, particularly where there is an adverse impact on the national economy.

C) Cyber Hacking Crimes:

Cyber hacking or unauthorized access to information systems is considered among the most serious cybercrimes addressed by Egyptian law. This includes unauthorized access to government systems, banks, or private institutions for the purpose of stealing data or disrupting systems. Perpetrators of these crimes are subject to the maximum penalties prescribed by law, which may extend to life imprisonment in cases that constitute a threat to national security.

D) Electronic Extortion Crimes:

Electronic extortion crimes involve the use of stolen information or data to extort individuals or companies. Electronic extortion may take various forms, such as threatening to publish sensitive personal or commercial information unless a sum of money is paid. Egyptian law imposes severe penalties on perpetrators of electronic extortion, including imprisonment and a fine.

E) Crimes Related to the Publication of Unlawful Content:

This type of crime includes the publication of content that violates the law, such as pornographic materials, incitement to violence, or the dissemination of false information. Egyptian law penalizes the publication of unlawful content over the Internet and imposes more severe penalties where such content has an adverse impact on society or endangers public security.

Legal Penalties for Cybercrimes in Egypt

International Cooperation in Combating Information Technology Crimes:

International cooperation in combating information technology crimes is cross-border security and judicial coordination adopted by states and international organizations for the exchange of digital evidence, the prosecution of perpetrators, and the closing of legislative gaps, in light of the nature of cybercrimes, which are not confined by geographical boundaries.

Penalties prescribed under Egyptian law for perpetrators of cybercrimes, with the aim of deterrence and protection. The penalties vary according to the type and seriousness of the crime and include, pursuant to Articles (13 to 20) of the Law on Combating Cybercrimes:

  1. Imprisonment: The penalty of imprisonment ranges from detention for several months to life imprisonment in cases involving threats to national security or affecting the State’s economic system.
  2. Financial fines: The law imposes financial fines that vary according to the type of crime and may amount to hundreds of thousands of Egyptian Pounds in some cases.
  3. Confiscation of devices and tools used in the crime: The court may order the confiscation of electronic devices or software used in the commission of the crime.

Preventive Measures to Combat Cybercrimes

Egyptian law urges individuals and companies to take preventive measures to protect themselves against cybercrimes, such as:

  • Using protection software: Ensuring the use of antivirus software and advanced security software on electronic devices and networks.
  • Securing personal accounts: By using strong passwords and enabling two-factor authentication to ensure the protection of personal data.
  • Exercising caution regarding suspicious links: Refraining from clicking on untrusted links that may be used as a means to steal personal data or breach systems.

What is the period for retaining information system records under Egyptian law pursuant to Article 2 of the Law on Combating Cybercrimes?

(Article 2) Retaining and storing the information system record or any information technology medium for a continuous period of one hundred and eighty days. The data required to be retained and stored shall consist of.