Law / Egypt

Law No. 175 of 2018 on Anti-Cyber and Information Technology Crimes, System-Security Duty on a System Manager

Law No. 175 of 2018 on Anti-Cyber and Information Technology Crimes, Arts. 29, 42, 44

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 15 August 2018.

A security baseline statutes rule binding public and private bodies.

As of 17 September 2026.

What it requires

  • This binds any person responsible for managing a website, private account, email account, or information system in Egypt, whether or not any personal data is involved.
  • Do not intentionally expose a website, private account, email account, or information system you manage to the commission of a crime under this Law; doing so carries imprisonment of not less than one year plus a fine of EGP 20,000 to 200,000.
  • Take the security precautions and measures the executive regulations of this Law prescribe. A negligent failure to do so that results in your website, private account, email account, or information system being exposed to a crime under this Law carries imprisonment of not less than six months plus a fine of EGP 10,000 to 100,000.
  • No reachable source confirms whether the Prime Minister has issued the Executive Regulations Article 44 requires, or what specific security precautions and measures they define; WIPO Lex's own record of this Law lists no related implementing text, so treat the 'security precautions and measures' standard as unconfirmed rather than absent.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Imprisonment of not less than one year plus a fine of EGP 20,000 to 200,000 for intentionally exposing a website, private account, email account, or information system you manage to the commission of a crime under this Law (Art. 29, first paragraph); imprisonment of not less than six months plus a fine of EGP 10,000 to 100,000 where the exposure is negligent, arising from a failure to take the security precautions and measures the executive regulations are to prescribe (Art. 29, second paragraph). Reconciliation before a final judgment, which requires the Authority's own approval for an Article 29 charge (Art. 42), extinguishes the criminal case but does not affect a victim's separate civil claim.

Penalty structure

Two tiers within Article 29: EGP 10,000 to 100,000 (plus imprisonment of not less than six months) for the negligent-failure paragraph, EGP 20,000 to 200,000 (plus imprisonment of not less than one year) for the intentional-exposure paragraph. The figures here span both tiers; the negligent-failure paragraph is the one this row's security duty rests on.

Rule
Fixed only
As of
17 September 2026
Minimum
10,000
Currency
EGP
Fixed cap
200,000

Who enforces it

Enforcement body

Egyptian Public Prosecution and the criminal courts; the National Telecommunications Regulatory Authority (the Authority) additionally holds an approval role over any reconciliation of an Article 29 charge.

What it reaches

Obligation class

Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 29 of Law No. 175 of 2018 on Anti-Cyber and Information Technology Crimes punishes any person responsible for managing a website, private account, email account, or information system who intentionally exposes it to the commission of a crime under this Law, with imprisonment of not less than one year plus a fine of EGP 20,000 to 200,000.

It separately punishes the same person for negligently causing that kind of exposure through a failure to take the security precautions and measures the Law's own executive regulations are to prescribe, with imprisonment of not less than six months plus a fine of EGP 10,000 to 100,000. The duty is general.

It does not turn on whether personal data is involved and does not require a telecommunications licence, unlike the separate service-provider duties Article 2 of the same Law places on a licensed 'Service Provider'. Reconciliation of an Article 29 charge requires the National Telecommunications Regulatory Authority's own approval. Reconciliation extinguishes the criminal case without affecting a victim's civil claim.

No source located confirms whether the Prime Minister issued the Article 44 executive regulations, or what specific security precautions and measures they set. WIPO Lex's own record of this Law lists no related implementing text.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Anti-Cyber and Information Technology Crimes Law, English translation published by Andersen's Egypt office
entry-into-force date and the absence of a listed implementing regulation from WIPO Lex's own metadata record for this Law

Back to the example  ·  Lint your app