Egypt's Anti-Cyber and IT Crimes Law 175 of 2018: What Companies Must Know
Law 175 of 2018 criminalises attacks on your systems, imposes log retention and security duties on service providers, and makes managers liable for weak security and unreported incidents. A plain-language guide with article numbers and practical steps.

Most Egyptian business owners think of the cybercrime law as something that applies to hackers and to people who post offensive content. It does. But Law No. 175 of 2018 also places duties on companies and, importantly, on the people who manage them: a manager whose company system is hit by a cybercrime and who does not report it, or an administrator who leaves a system exposed by ignoring required security precautions, can face criminal penalties.
In short, Egypt's Anti-Cyber and Information Technology Crimes Law 175/2018 does three things that matter to companies: it criminalises attacks on your systems (so you can act against intruders, including insiders), it imposes retention, confidentiality and security duties on "service providers", and it creates personal liability for managers and system administrators. This guide explains those points using the article texts, shows how the law sits beside the Personal Data Protection Law 151/2020, and ends with practical steps.
Key takeaways
- Unauthorised access, exceeding authorised access, and deleting or altering data are crimes (Arts. 14, 15 and 17), with higher penalties when a private legal entity's email, website or account is attacked (Art. 18).
- Service providers must retain system logs for 180 continuous days, keep stored data confidential and secure it (Art. 2).
- Whoever manages a website, account, email or information system can be punished for negligently exposing it by not following the security precautions in the executive regulations (Art. 29).
- The actual manager of a company must report a cybercrime against the company's systems once aware of it (Art. 35).
- If personal data is affected, the data protection law adds a 72-hour notification duty to the Personal Data Protection Center.
The law at a glance
The Arabic title is «قانون مكافحة جرائم تقنية المعلومات رقم 175 لسنة 2018». This article relies on the English translation of Law 175/2018 published by Andersen Egypt; the Arabic text in the Official Gazette is the binding version.
- Timing: the law came into force on the day after its publication in the Official Gazette (Art. 45). Service providers and everyone subject to it had one year to regularise their status (Art. 43).
- Executive regulations: issued by Prime Minister Decree 1699 of 2020, in August 2020, according to ADSERO's summary. We did not review the decree itself for this article.
- Regulator: "the Authority" in the law is the National Telecommunications Regulatory Authority (NTRA).
Penalties below are the statutory ranges. Where the law says "or either of these two penalties", we write "and/or".
Service provider duties (Article 2)
Article 1 defines a service provider as any natural or legal person who provides information and communication technology services to users, including those who process or store information directly or on behalf of others. Telecom operators and hosting companies clearly fall inside. Whether a software company, a SaaS platform or a company running a customer portal falls inside is a question to answer with a lawyer, because the definition is broad.
| Duty in Article 2 | What the text requires |
|---|---|
| Log retention | Retain and store information system logs for a continuous period of 180 days, covering data identifying the user, data on the content of the system when under the provider's control, communications traffic data, data on terminal devices, and any other data the NTRA board sets |
| Confidentiality | Keep stored data confidential and do not disclose it without a justified order from the competent judicial authorities, including users' personal data |
| Security | Secure data and information to ensure confidentiality, prevent unauthorised access and protect against damage |
| Disclosure | Make available to users the provider's name, address, contact details including an electronic address, and licensing data |
| Cooperation | Provide national security agencies, on request, with the necessary technical capabilities; hand over data on a reasoned order from the investigating authority (Art. 6) |
Breaches carry heavy penalties. Article 33 sets a fine of EGP 5 million to 10 million, doubled on recurrence and with possible licence revocation, for breaching one of the Article 2 (First) clauses, and Article 31 sets at least one year and/or EGP 5,000 to 20,000 for breaching another, with the fine multiplied by the number of affected users. The translation's clause numbering suggests the first applies to retention and the second to confidentiality, but that mapping should be confirmed against the official Arabic text before you rely on it. Breaching the disclosure duties carries EGP 20,000 to 200,000 (Art. 33).
Crimes against your company's systems
The law is also a tool for victims. Offences companies most often meet:
| Article | Offence | Penalty |
|---|---|---|
| 14 | Intentionally accessing a restricted website, private account or information system without right, or staying in after accidental access | At least 1 year and/or EGP 50,000–100,000; at least 2 years and/or EGP 100,000–200,000 if data is destroyed, deleted, altered, copied or republished |
| 15 | Exceeding authorised access in time or level | At least 6 months and/or EGP 30,000–50,000 |
| 17 | Intentionally destroying, disrupting, altering or deleting software or data on an information system | At least 2 years and/or EGP 100,000–500,000 |
| 18 | Damaging, disrupting, slowing or hacking an email, website or private account | Individual's: at least 1 month and/or EGP 50,000–100,000. Private legal entity's: at least 6 months and/or EGP 100,000–200,000 |
| 24 | A fake email, website or account falsely attributed to a natural or legal person | At least 3 months and/or EGP 10,000–30,000; at least 1 year and/or EGP 50,000–200,000 if used to harm that person |
Examples from Egyptian workplaces
- A sales manager leaves a Cairo trading company but keeps logging in to the CRM from home to download the customer list. That is the kind of conduct Articles 14 and 15 address, and it is why accounts must be closed on the last working day.
- An accountant at a factory in 10th of Ramadan deletes ledger entries before resigning. Article 17 covers deleting or altering data on an information system.
To use these articles you need evidence: login records, audit logs and preserved copies. Without logs, it is hard to show who did what and when.
Liability of managers and administrators
This is the part most companies overlook. The law names two roles: the person responsible for managing a website, private account, email or information system, and the person responsible for the actual management of a legal entity.
| Article | Who | Conduct | Penalty |
|---|---|---|---|
| 28 | Person managing a website, account, email or information system | Concealing or tampering with digital evidence of a crime on that platform, to obstruct the authorities | At least 6 months and/or EGP 20,000–200,000 |
| 29 | Same | Exposing the system to a crime under the law | At least 1 year and/or EGP 20,000–200,000 |
| 29 | Same | Negligently exposing it, through failure to take the security precautions and measures stated in the executive regulations | At least 6 months and/or EGP 10,000–100,000 |
| 35 | Person responsible for the actual management of a legal entity | Failing to report to the competent authorities a crime against the entity's website, account, email or system after becoming aware of it | At least 3 months and/or EGP 30,000–100,000 |
| 36 | Same | A crime committed in the name and for the benefit of the company, where the manager knew of it or facilitated it | Same penalty as the offender; the court may suspend the entity's licence for up to 1 year and, on recurrence, cancel it or dissolve the entity; the judgment is published in two daily newspapers at the entity's expense |
Two further points: a manager's liability does not remove the liability of the individuals who committed the act (Art. 37), and for Articles 29 and 35 reconciliation is accepted only through the NTRA (Art. 42).
What the executive regulations require
Article 29's negligence offence depends on "the security precautions and measures stated in the executive regulations". We have not reviewed the text of those measures for this article, so we do not list them here. Ask your legal adviser for the current text and map each measure to your systems. A documented baseline of good practice helps, but it does not replace checking the regulations.
Reporting a cybercrime: Article 35 in practice
Article 35 does not wait for an investigation to finish; the duty arises once the manager becomes aware of the crime. The article refers to "the competent authorities" without naming a single channel in the text we read, so agree with your lawyer in advance which authority you will report to and who signs.
For technical support, the NTRA hosts EG-CERT, which it describes as responsible for incident response, support, defence and analysis against cyber attacks. EG-CERT's own site lists a "Report an Incident" page; we could not confirm its current contents, so check it directly.
Practical sequence when you discover an incident:
- Record the time you became aware and who was informed.
- Contain the incident without destroying evidence: isolate, do not wipe. Article 28 penalises tampering with digital evidence.
- Preserve logs, screenshots and copies of affected systems.
- Call your lawyer and decide the reporting route under Article 35.
- Check whether personal data was affected; if so, start the data protection notification clock.
How Law 175 sits beside the Personal Data Protection Law
The two laws overlap but are different. Law 175 is a criminal law about attacks on systems and duties of providers and managers. Law 151/2020 regulates how personal data is collected, processed and protected. Its executive regulations were issued on 1 November 2025, and the one-year grace period ends on 1 November 2026, according to CMS's January 2026 update.
| Topic | Law 175/2018 | Law 151/2020 (PDPL) |
|---|---|---|
| Security duty | Service providers must secure data (Art. 2); administrators must follow the regulations' precautions (Art. 29) | Controllers and processors must apply technical and organisational measures (Arts. 4 and 5) |
| Incident reporting | Actual manager reports crimes against the entity's systems (Art. 35) | Notify the Personal Data Protection Center within 72 hours of becoming aware of a breach (Art. 7) |
| Penalty example | Art. 35: at least 3 months and/or EGP 30,000–100,000 | Art. 38: EGP 300,000–3,000,000 for breaching Arts. 4, 5 or 7 |
| Manager liability | Arts. 35 and 36 | Art. 47 |
The PDPL figures come from the Andersen translation of Law 151/2020. A single ransomware attack on an HR server can trigger both laws. Our guide to data breach notification within 72 hours covers the PDPL side, and our article on website privacy policies under the data protection law covers what to tell users. Note also that Article 25 of Law 175 penalises sending many electronic messages to a person without consent, which matters for bulk WhatsApp and SMS marketing.
Practical compliance steps for companies
- Name the responsible people. Write down who manages each website, email domain, social account and business system. Those are the people Articles 28 and 29 address.
- Get legal advice on "service provider" status if you host, process or store information for customers, and confirm the Article 2 duties and clause mapping against the Arabic text.
- Obtain and apply the executive regulations' security measures, with a documented baseline: multi-factor authentication, least-privilege permissions, patching and backups. See our cybersecurity plan for Egyptian SMEs.
- Keep reliable logs and audit trails of logins, exports and admin actions, protected from editing. Our guide to permissions and audit logs in ERP and CRM explains what to record.
- Offboard the same day. Disable accounts, VPN and shared passwords when someone leaves.
- Write an incident procedure that covers evidence preservation, Article 35 reporting and the PDPL 72-hour notice.
- Authorise security testing in writing. Testers need signed permission and a defined scope; see penetration testing vs vulnerability scanning.
- Review marketing messages for consent before bulk sending.
How Nilex helps
Nilex is a software company, not a law firm. We build the technical controls that these legal duties depend on: role-based access, tamper-resistant audit logs, configurable log retention, secure authentication and backups, in a custom ERP system or in the systems you already run. Your lawyer defines the obligations; we help you implement and document them. Read more about how we work.
Frequently asked questions
Does my company have to report a hack?
Article 35 punishes the person responsible for the actual management of a legal entity who, after becoming aware that the entity's website, account, email or information system was subjected to a crime under the law, fails to report it to the competent authorities. If personal data is involved, the PDPL also requires notifying the Personal Data Protection Center within 72 hours.
How long must logs be kept under Law 175?
Article 2 requires service providers to retain information system logs for a continuous period of 180 days. Whether your company is a service provider depends on its activities, so confirm with a lawyer.
Can a manager be punished for weak security?
Article 29 punishes a person managing a website, account, email or information system who negligently exposes it to a crime by failing to take the security precautions in the executive regulations, with at least six months and/or EGP 10,000 to 100,000.
Is it a crime if a former employee logs in to our system?
Intentional access without right is covered by Article 14, and exceeding authorised access by Article 15. Keep the logs, disable the account and consult a lawyer about next steps.
Want to check whether your systems keep the logs, permissions and evidence these laws assume? Book a free technical review through our contact page.
This article is general information, not legal or tax advice. Confirm the details that apply to your company with a specialist.
Cybersecurity for Egyptian SMEs: A Practical 90-Day Plan26 September 2026 · 10 min
Ransomware Protection for Egyptian Companies: Prevent, Contain and Recover26 September 2026 · 9 min
Phishing and Fake Payment Requests: Protecting Egyptian Businesses from Email and WhatsApp Scams26 September 2026 · 10 min
