Security

Egypt's Anti-Cyber and IT Crimes Law 175 of 2018: What Companies Must Know

Law 175 of 2018 criminalises attacks on your systems, imposes log retention and security duties on service providers, and makes managers liable for weak security and unreported incidents. A plain-language guide with article numbers and practical steps.

Illustration of a legal scale beside a server rack, audit log and a manager's checklist for Egypt's cybercrime law

Most Egyptian business owners think of the cybercrime law as something that applies to hackers and to people who post offensive content. It does. But Law No. 175 of 2018 also places duties on companies and, importantly, on the people who manage them: a manager whose company system is hit by a cybercrime and who does not report it, or an administrator who leaves a system exposed by ignoring required security precautions, can face criminal penalties.

In short, Egypt's Anti-Cyber and Information Technology Crimes Law 175/2018 does three things that matter to companies: it criminalises attacks on your systems (so you can act against intruders, including insiders), it imposes retention, confidentiality and security duties on "service providers", and it creates personal liability for managers and system administrators. This guide explains those points using the article texts, shows how the law sits beside the Personal Data Protection Law 151/2020, and ends with practical steps.

Key takeaways

  • Unauthorised access, exceeding authorised access, and deleting or altering data are crimes (Arts. 14, 15 and 17), with higher penalties when a private legal entity's email, website or account is attacked (Art. 18).
  • Service providers must retain system logs for 180 continuous days, keep stored data confidential and secure it (Art. 2).
  • Whoever manages a website, account, email or information system can be punished for negligently exposing it by not following the security precautions in the executive regulations (Art. 29).
  • The actual manager of a company must report a cybercrime against the company's systems once aware of it (Art. 35).
  • If personal data is affected, the data protection law adds a 72-hour notification duty to the Personal Data Protection Center.

The law at a glance

The Arabic title is «قانون مكافحة جرائم تقنية المعلومات رقم 175 لسنة 2018». This article relies on the English translation of Law 175/2018 published by Andersen Egypt; the Arabic text in the Official Gazette is the binding version.

  • Timing: the law came into force on the day after its publication in the Official Gazette (Art. 45). Service providers and everyone subject to it had one year to regularise their status (Art. 43).
  • Executive regulations: issued by Prime Minister Decree 1699 of 2020, in August 2020, according to ADSERO's summary. We did not review the decree itself for this article.
  • Regulator: "the Authority" in the law is the National Telecommunications Regulatory Authority (NTRA).

Penalties below are the statutory ranges. Where the law says "or either of these two penalties", we write "and/or".

Service provider duties (Article 2)

Article 1 defines a service provider as any natural or legal person who provides information and communication technology services to users, including those who process or store information directly or on behalf of others. Telecom operators and hosting companies clearly fall inside. Whether a software company, a SaaS platform or a company running a customer portal falls inside is a question to answer with a lawyer, because the definition is broad.

Duty in Article 2What the text requires
Log retentionRetain and store information system logs for a continuous period of 180 days, covering data identifying the user, data on the content of the system when under the provider's control, communications traffic data, data on terminal devices, and any other data the NTRA board sets
ConfidentialityKeep stored data confidential and do not disclose it without a justified order from the competent judicial authorities, including users' personal data
SecuritySecure data and information to ensure confidentiality, prevent unauthorised access and protect against damage
DisclosureMake available to users the provider's name, address, contact details including an electronic address, and licensing data
CooperationProvide national security agencies, on request, with the necessary technical capabilities; hand over data on a reasoned order from the investigating authority (Art. 6)

Breaches carry heavy penalties. Article 33 sets a fine of EGP 5 million to 10 million, doubled on recurrence and with possible licence revocation, for breaching one of the Article 2 (First) clauses, and Article 31 sets at least one year and/or EGP 5,000 to 20,000 for breaching another, with the fine multiplied by the number of affected users. The translation's clause numbering suggests the first applies to retention and the second to confidentiality, but that mapping should be confirmed against the official Arabic text before you rely on it. Breaching the disclosure duties carries EGP 20,000 to 200,000 (Art. 33).

Crimes against your company's systems

The law is also a tool for victims. Offences companies most often meet:

ArticleOffencePenalty
14Intentionally accessing a restricted website, private account or information system without right, or staying in after accidental accessAt least 1 year and/or EGP 50,000–100,000; at least 2 years and/or EGP 100,000–200,000 if data is destroyed, deleted, altered, copied or republished
15Exceeding authorised access in time or levelAt least 6 months and/or EGP 30,000–50,000
17Intentionally destroying, disrupting, altering or deleting software or data on an information systemAt least 2 years and/or EGP 100,000–500,000
18Damaging, disrupting, slowing or hacking an email, website or private accountIndividual's: at least 1 month and/or EGP 50,000–100,000. Private legal entity's: at least 6 months and/or EGP 100,000–200,000
24A fake email, website or account falsely attributed to a natural or legal personAt least 3 months and/or EGP 10,000–30,000; at least 1 year and/or EGP 50,000–200,000 if used to harm that person

Examples from Egyptian workplaces

  • A sales manager leaves a Cairo trading company but keeps logging in to the CRM from home to download the customer list. That is the kind of conduct Articles 14 and 15 address, and it is why accounts must be closed on the last working day.
  • An accountant at a factory in 10th of Ramadan deletes ledger entries before resigning. Article 17 covers deleting or altering data on an information system.

To use these articles you need evidence: login records, audit logs and preserved copies. Without logs, it is hard to show who did what and when.

Liability of managers and administrators

This is the part most companies overlook. The law names two roles: the person responsible for managing a website, private account, email or information system, and the person responsible for the actual management of a legal entity.

ArticleWhoConductPenalty
28Person managing a website, account, email or information systemConcealing or tampering with digital evidence of a crime on that platform, to obstruct the authoritiesAt least 6 months and/or EGP 20,000–200,000
29SameExposing the system to a crime under the lawAt least 1 year and/or EGP 20,000–200,000
29SameNegligently exposing it, through failure to take the security precautions and measures stated in the executive regulationsAt least 6 months and/or EGP 10,000–100,000
35Person responsible for the actual management of a legal entityFailing to report to the competent authorities a crime against the entity's website, account, email or system after becoming aware of itAt least 3 months and/or EGP 30,000–100,000
36SameA crime committed in the name and for the benefit of the company, where the manager knew of it or facilitated itSame penalty as the offender; the court may suspend the entity's licence for up to 1 year and, on recurrence, cancel it or dissolve the entity; the judgment is published in two daily newspapers at the entity's expense

Two further points: a manager's liability does not remove the liability of the individuals who committed the act (Art. 37), and for Articles 29 and 35 reconciliation is accepted only through the NTRA (Art. 42).

What the executive regulations require

Article 29's negligence offence depends on "the security precautions and measures stated in the executive regulations". We have not reviewed the text of those measures for this article, so we do not list them here. Ask your legal adviser for the current text and map each measure to your systems. A documented baseline of good practice helps, but it does not replace checking the regulations.

Reporting a cybercrime: Article 35 in practice

Article 35 does not wait for an investigation to finish; the duty arises once the manager becomes aware of the crime. The article refers to "the competent authorities" without naming a single channel in the text we read, so agree with your lawyer in advance which authority you will report to and who signs.

For technical support, the NTRA hosts EG-CERT, which it describes as responsible for incident response, support, defence and analysis against cyber attacks. EG-CERT's own site lists a "Report an Incident" page; we could not confirm its current contents, so check it directly.

Practical sequence when you discover an incident:

  1. Record the time you became aware and who was informed.
  2. Contain the incident without destroying evidence: isolate, do not wipe. Article 28 penalises tampering with digital evidence.
  3. Preserve logs, screenshots and copies of affected systems.
  4. Call your lawyer and decide the reporting route under Article 35.
  5. Check whether personal data was affected; if so, start the data protection notification clock.

How Law 175 sits beside the Personal Data Protection Law

The two laws overlap but are different. Law 175 is a criminal law about attacks on systems and duties of providers and managers. Law 151/2020 regulates how personal data is collected, processed and protected. Its executive regulations were issued on 1 November 2025, and the one-year grace period ends on 1 November 2026, according to CMS's January 2026 update.

TopicLaw 175/2018Law 151/2020 (PDPL)
Security dutyService providers must secure data (Art. 2); administrators must follow the regulations' precautions (Art. 29)Controllers and processors must apply technical and organisational measures (Arts. 4 and 5)
Incident reportingActual manager reports crimes against the entity's systems (Art. 35)Notify the Personal Data Protection Center within 72 hours of becoming aware of a breach (Art. 7)
Penalty exampleArt. 35: at least 3 months and/or EGP 30,000–100,000Art. 38: EGP 300,000–3,000,000 for breaching Arts. 4, 5 or 7
Manager liabilityArts. 35 and 36Art. 47

The PDPL figures come from the Andersen translation of Law 151/2020. A single ransomware attack on an HR server can trigger both laws. Our guide to data breach notification within 72 hours covers the PDPL side, and our article on website privacy policies under the data protection law covers what to tell users. Note also that Article 25 of Law 175 penalises sending many electronic messages to a person without consent, which matters for bulk WhatsApp and SMS marketing.

Practical compliance steps for companies

  1. Name the responsible people. Write down who manages each website, email domain, social account and business system. Those are the people Articles 28 and 29 address.
  2. Get legal advice on "service provider" status if you host, process or store information for customers, and confirm the Article 2 duties and clause mapping against the Arabic text.
  3. Obtain and apply the executive regulations' security measures, with a documented baseline: multi-factor authentication, least-privilege permissions, patching and backups. See our cybersecurity plan for Egyptian SMEs.
  4. Keep reliable logs and audit trails of logins, exports and admin actions, protected from editing. Our guide to permissions and audit logs in ERP and CRM explains what to record.
  5. Offboard the same day. Disable accounts, VPN and shared passwords when someone leaves.
  6. Write an incident procedure that covers evidence preservation, Article 35 reporting and the PDPL 72-hour notice.
  7. Authorise security testing in writing. Testers need signed permission and a defined scope; see penetration testing vs vulnerability scanning.
  8. Review marketing messages for consent before bulk sending.

How Nilex helps

Nilex is a software company, not a law firm. We build the technical controls that these legal duties depend on: role-based access, tamper-resistant audit logs, configurable log retention, secure authentication and backups, in a custom ERP system or in the systems you already run. Your lawyer defines the obligations; we help you implement and document them. Read more about how we work.

Frequently asked questions

Does my company have to report a hack?

Article 35 punishes the person responsible for the actual management of a legal entity who, after becoming aware that the entity's website, account, email or information system was subjected to a crime under the law, fails to report it to the competent authorities. If personal data is involved, the PDPL also requires notifying the Personal Data Protection Center within 72 hours.

How long must logs be kept under Law 175?

Article 2 requires service providers to retain information system logs for a continuous period of 180 days. Whether your company is a service provider depends on its activities, so confirm with a lawyer.

Can a manager be punished for weak security?

Article 29 punishes a person managing a website, account, email or information system who negligently exposes it to a crime by failing to take the security precautions in the executive regulations, with at least six months and/or EGP 10,000 to 100,000.

Is it a crime if a former employee logs in to our system?

Intentional access without right is covered by Article 14, and exceeding authorised access by Article 15. Keep the logs, disable the account and consult a lawyer about next steps.

Want to check whether your systems keep the logs, permissions and evidence these laws assume? Book a free technical review through our contact page.

This article is general information, not legal or tax advice. Confirm the details that apply to your company with a specialist.

LET'S BUILD

YOUR VISION.
OUR TECHNOLOGY.

Tell us what your business needs. We'll build the system around it.

START A CONVERSATION →

or email us at info@nilexdigitalsystems.com