Anti-Cyber and Information Technology Crimes Law No. 175 of 2018
eg-cyber-2018 · Act
The Anti-Cyber and Information Technology Crimes Law No. 175 of 2018 is Egypt's principal cybercrime statute. Ratified by the President and published in the Official Gazette in August 2018, the law comprises 45 articles arranged in four parts: general provisions, procedural rules, crimes and penalties, and concluding provisions. It establishes both a broad catalogue of information-technology offences and an extensive regime of obligations on service providers and powers for the investigative authorities. The law criminalises unlawful access to information systems, websites and private accounts (with aggravated penalties where access results in damage, deletion, alteration, copying or redistribution of data), unlawful use of networks and broadcasting channels, interception of communications, and interference with information systems. It contains computer-related fraud and forgery offences, including the fraudulent use of bank-card and electronic-payment data, giving it a clear fintech-fraud dimension. A significant body of content and privacy offences includes the creation of fake accounts or websites impersonating individuals or bodies, the unlawful capture or publication of private images and communications in violation of privacy, and offences relating to content deemed to harm family values or national security. Identity-related and unauthorised-data offences give the law a data-protection overlap. On procedure, the law imposes data-retention duties on telecommunications and service providers (retaining and storing user and traffic data for 180 days to assist in identifying users, metadata and IP addresses) and obligations to assist the authorities. It confers powers on investigative authorities to order the blocking of websites whose content is deemed to threaten national security or the national economy (with a limited appeal mechanism for affected parties and ISPs), to conduct searches and seizures of digital evidence, and to undertake surveillance, raising substantial digital-rights and free-expression concerns. It provides for international cooperation in cross-border investigations. Institutionally, enforcement is led by the Public Prosecution and the Ministry of Interior's specialised units, with the National Telecommunications Regulatory Authority (NTRA) and the Supreme Cybersecurity Council playing coordinating and oversight roles. The website-blocking, surveillance and data-retention provisions have been widely criticised by human-rights observers, and the law operates alongside the Personal Data Protection Law No. 151 of 2020.
- Criminalises unlawful access to information systems, websites and accounts, with aggravated penalties where data is damaged, altered, copied or redistributed.
- Creates computer-related fraud and forgery offences, including fraudulent use of bank-card and electronic-payment data.
- Establishes content/privacy offences, including impersonation via fake accounts/websites and unlawful capture or publication of private images and communications.
- Imposes 180-day data-retention duties on telecommunications and service providers and obligations to assist investigations.
- Empowers investigative authorities to order website blocking on national-security/economic grounds (with limited appeal) and to conduct digital search, seizure and surveillance.
- Provides for international cooperation in cross-border cybercrime investigations.