Law No. 175 of 2018 on Anti-Cyber and Information Technology Crimes, System-Security Duty on a System Manager
Law No. 175 of 2018 on Anti-Cyber and Information Technology Crimes, Arts. 29, 42, 44
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 15 August 2018.
A security baseline statutes rule binding public and private bodies.
As of 17 September 2026.
What it requires
- This binds any person responsible for managing a website, private account, email account, or information system in Egypt, whether or not any personal data is involved.
- Do not intentionally expose a website, private account, email account, or information system you manage to the commission of a crime under this Law; doing so carries imprisonment of not less than one year plus a fine of EGP 20,000 to 200,000.
- Take the security precautions and measures the executive regulations of this Law prescribe. A negligent failure to do so that results in your website, private account, email account, or information system being exposed to a crime under this Law carries imprisonment of not less than six months plus a fine of EGP 10,000 to 100,000.
- No reachable source confirms whether the Prime Minister has issued the Executive Regulations Article 44 requires, or what specific security precautions and measures they define; WIPO Lex's own record of this Law lists no related implementing text, so treat the 'security precautions and measures' standard as unconfirmed rather than absent.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Imprisonment of not less than one year plus a fine of EGP 20,000 to 200,000 for intentionally exposing a website, private account, email account, or information system you manage to the commission of a crime under this Law (Art. 29, first paragraph); imprisonment of not less than six months plus a fine of EGP 10,000 to 100,000 where the exposure is negligent, arising from a failure to take the security precautions and measures the executive regulations are to prescribe (Art. 29, second paragraph). Reconciliation before a final judgment, which requires the Authority's own approval for an Article 29 charge (Art. 42), extinguishes the criminal case but does not affect a victim's separate civil claim.
Penalty structure
Two tiers within Article 29: EGP 10,000 to 100,000 (plus imprisonment of not less than six months) for the negligent-failure paragraph, EGP 20,000 to 200,000 (plus imprisonment of not less than one year) for the intentional-exposure paragraph. The figures here span both tiers; the negligent-failure paragraph is the one this row's security duty rests on.
- Rule
- Fixed only
- As of
- 17 September 2026
- Minimum
- 10,000
- Currency
- EGP
- Fixed cap
- 200,000
Who enforces it
Enforcement body
Egyptian Public Prosecution and the criminal courts; the National Telecommunications Regulatory Authority (the Authority) additionally holds an approval role over any reconciliation of an Article 29 charge.
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 29 of Law No. 175 of 2018 on Anti-Cyber and Information Technology Crimes punishes any person responsible for managing a website, private account, email account, or information system who intentionally exposes it to the commission of a crime under this Law, with imprisonment of not less than one year plus a fine of EGP 20,000 to 200,000.
It separately punishes the same person for negligently causing that kind of exposure through a failure to take the security precautions and measures the Law's own executive regulations are to prescribe, with imprisonment of not less than six months plus a fine of EGP 10,000 to 100,000. The duty is general.
It does not turn on whether personal data is involved and does not require a telecommunications licence, unlike the separate service-provider duties Article 2 of the same Law places on a licensed 'Service Provider'. Reconciliation of an Article 29 charge requires the National Telecommunications Regulatory Authority's own approval. Reconciliation extinguishes the criminal case without affecting a victim's civil claim.
No source located confirms whether the Prime Minister issued the Article 44 executive regulations, or what specific security precautions and measures they set. WIPO Lex's own record of this Law lists no related implementing text.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
Anti-Cyber and Information Technology Crimes Law, English translation published by Andersen's Egypt office
entry-into-force date and the absence of a listed implementing regulation from WIPO Lex's own metadata record for this Law