Saturday to Thursday, 9:00 am – 6:00 pm

Legal Insights

Privacy Policy and Cookies

Amid the rapid digital transformation taking place in the Egyptian market and the growth of the investment environment in the digital commerce and financial technology sectors, data protection has become one of the foremost legislative and security requirements for companies and investors.

Preparing a Privacy Policy and Cookies Policy is no longer merely a supplementary step for building trust with users; it has become a legal obligation imposed by modern Egyptian legislation on both local and multinational companies. Compliance with data protection requirements in Egypt is a fundamental pillar for avoiding criminal penalties and substantial financial fines that may affect business continuity and the corporate reputation of institutions.

This article provides a legal analysis for foreign companies, investors, shipping, import and export companies, as well as international law firms seeking Local Counsel in Egypt. It focuses on the legislative frameworks governing data privacy and user tracking technologies, and on how the relevant policies should be drafted in compliance with Egyptian laws and international standards.

Legislative Framework Governing Data Privacy in Egypt

The drafting of a Privacy Policy and Cookies Policy cannot be separated from the Egyptian legislative framework, which has evolved in recent years to protect the digital environment and user data. This matter is governed by three principal pieces of legislation.

1. Personal Data Protection Law No. 151 of 2020

This Law represents a significant development in the Egyptian legislative environment and mirrors the European General Data Protection Regulation (GDPR) in many of its provisions. It imposes strict obligations on data “controllers” and “processors” and requires the explicit and informed consent of the data subject before their data may be collected, processed, or retained.

The Law also provides for the establishment of the “Personal Data Protection Center” as the regulatory authority responsible for enforcing its provisions and issuing the necessary licences.

2. Anti-Information Technology Crimes Law No. 175 of 2018

This Law requires information technology service providers and companies operating digital platforms to retain and store communications and information system data for 180 days. Such data includes information identifying the user, the type of service, and Traffic Data, together with strict rules intended to prevent breaches of stored data or its unauthorised use.

3. Consumer Protection Law No. 181 of 2018

Article (25) of the Law expressly requires suppliers and advertisers operating in e-commerce to respect consumer privacy. It also prohibits the sending of promotional or advertising messages through electronic means of communication without the consumer’s prior and explicit consent, while requiring an easy and free means of withdrawing such consent at any time.

Legal Distinction Between a Privacy Policy and a Cookies Policy

From the perspective of drafting corporate contracts and digital documents, a precise distinction must be drawn between the two documents, notwithstanding their close connection.

  • Privacy Policy: A legal statement explaining how a company collects personal data, such as names, addresses, national identification numbers, and credit card details, as well as the mechanisms for processing, storing, and sharing such data with third parties, in addition to users’ rights to amend or delete their data.
  • Cookies Policy: This policy focuses on the small text files stored on users’ devices when they visit a digital platform. These files are used to track browsing behaviour and user preferences and to analyse marketing performance. Under Egyptian law, certain cookies, particularly advertising tracking cookies, are classified as tools for collecting behavioural data and therefore require explicit consent.

Practical Requirements for Drafting a Compliant Privacy Policy in Egypt

For a Privacy Policy and Cookies Policy to satisfy the legal requirements applicable before the regulatory and judicial authorities in Egypt, the drafting should address several essential elements.

Explicit and Informed Consent (Explicit Consent)

Digital platforms must discontinue the use of “implied consent” or Pre-ticked boxes. Egyptian law requires users to express their consent through a clear and explicit affirmative action after reviewing the privacy terms.

Purpose and Retention Periods (Purpose Limitation & Retention)

The specific purpose for collecting data, such as completing a shipping transaction, improving the user experience, or processing an electronic payment, must be clearly stated. The data retention period should also be specified, together with an undertaking to destroy the data once the purpose for which it was collected has been fulfilled, unless other legal obligations require its retention, including tax laws or the Anti-Money Laundering Law.

Appointment of a Data Protection Officer (DPO)

Article (8) of Law No. 151 of 2020 requires companies and institutions to appoint a Data Protection Officer within the organisation and to register that officer in the register maintained by the Personal Data Protection Center. The officer’s contact details must also be included in the Privacy Policy, enabling users and public authorities to contact them.

Mechanisms for Exercising Data Subject Rights

The policy should provide clear and practicable mechanisms enabling Egyptian or international users to exercise their legal rights.

  1. The right to access and review data.
  2. The right to rectify or amend data.
  3. The right to object to or restrict data processing.
  4. The right to erasure, also known as the “right to be forgotten.”

Legal Risks and Commercial Consequences of Non-Compliance

Failure to draft a Privacy Policy and Cookies Policy accurately, or copying ready-made policies from foreign websites without adapting them to the Egyptian legislative environment, exposes companies to complex operational and commercial risks.

1. Criminal and Financial Penalties

The penalties prescribed under Egyptian Personal Data Protection Law No. 151 of 2020 are stringent. They are not limited to financial fines that may reach millions of Egyptian pounds but may also extend to imprisonment in certain cases, including collecting or processing data without consent or intentionally breaching such data.

Liability may also extend to the executive responsible for the actual management of the legal entity where it is established that they were aware of the offence and that their breach of managerial duties contributed to its occurrence.

2. Suspension of Activities and Revocation of Licences

The Personal Data Protection Center has administrative authority to suspend processing licences or digital data flows of non-compliant companies. This may disrupt digital platforms and e-commerce services, resulting in commercial losses for investors.

3. Civil Liability and Compensation

Consumers and customers harmed by the leakage or unlawful use of their data are entitled to bring proceedings before the Egyptian Economic Courts and claim compensation for the material and moral damage they have sustained.

Considerations for International Clients and Cross-Border Companies

Multinational companies and foreign law firms representing investors in Egypt face challenges in reconciling international laws, such as the GDPR or CCPA, with Egyptian law. In this context, two principal issues arise.

Cross-Border Data Transfers (Cross-Border Data Transfer)

Article (14) of Law No. 151 of 2020 prohibits the transfer of personal data collected within Egypt to a foreign country, or its storage on Servers located outside Egypt, unless an official licence or permit has first been obtained from the Personal Data Protection Center and provided that the recipient country affords a level of protection no lower than that prescribed by Egyptian law.

Accordingly, the operations of international shipping companies and cross-border e-commerce businesses require Data Transfer Agreements to be drafted with a high degree of precision.

Conflict of Jurisdiction and Competent Courts

The Egyptian legislature subjects data processing operations conducted within Egypt, or relating to Egyptian citizens or residents, to the jurisdiction of the Egyptian courts, specifically the Economic Courts. Accordingly, any provision in a Privacy Policy that assigns exclusive jurisdiction over data disputes to foreign courts may be deemed absolutely void for contravening economic public policy in Egypt.

Common Errors in Drafting Privacy Policies and Cookies Policies

In the course of El Rouby Law Firm’s legal practice, several recurring errors have been identified among start-ups and international companies entering the Egyptian market.

  • Copying and Pasting (Plagiarism): Relying on translated Privacy Policy templates designed for US or European markets without observing the obligations imposed by Egyptian information technology legislation, such as the 180-day data retention period.
  • Ambiguous Language: Using broad statements such as “we may use your data to improve our services without further notice,” which conflicts with the principles of transparency and specific consent required by the Egyptian legislature.
  • Omission of Third-Party Cookies Provisions: Failing to disclose tracking cookies used by major advertising companies or analytics tools, which may constitute the covert collection of users’ behavioural data.

Practical Best Practices for Digital Compliance

To secure digital platforms and strengthen their compliance with Egyptian regulatory requirements, practical measures should be implemented, beginning with a comprehensive understanding of the data lifecycle and extending beyond merely publishing a Privacy Policy on the website.

  1. Conducting a Comprehensive Data Audit: Identifying all data collected by the platform and determining its flow paths and storage locations, whether inside or outside Egypt.
  2. Designing an Interactive Cookie Banner (Compliant Cookie Banner): Displaying a clear banner that allows users to accept or reject non-essential cookies, including advertising tracking cookies, before they are used.
  3. Regularly Updating Policies: Reviewing and updating the Privacy Policy and Cookies Policy to keep pace with regulatory decisions and amendments to the Executive Regulations as soon as they are issued.

How Can Specialist Legal Support Help?

The interrelated technical and legal aspects of data protection make it necessary to engage Local Counsel with practical experience in the Egyptian market. El Rouby Law Firm provides a comprehensive range of legal services to local and international companies in this field.

  • Regulatory Compliance: Reviewing companies’ digital structures and adapting them to comply with Personal Data Protection Law No. 151 of 2020 and the Anti-Information Technology Crimes Law.
  • Risk Management and Remediation of Gaps: Conducting a Data Protection Impact Assessment (DPIA) to identify operational vulnerabilities before they develop into legal violations or judicial disputes.
  • Drafting Contracts and Digital Documents: Preparing Privacy Policies, Terms of Use, Cookies Policies, and Data Processing Agreements (DPAs) between companies and cloud computing service providers or shipping companies.
  • Representation Before Egyptian Public Authorities: Handling the procedures for obtaining the licences and permits required for “controllers and processors” from the Personal Data Protection Center and addressing data breach notifications.
  • Defence, Litigation, and Arbitration: Representing and defending companies before the Egyptian Economic Courts and arbitral tribunals in disputes arising from data breaches, consumer compensation claims, or administrative penalties.

Conclusion

Drafting a Privacy Policy and Cookies Policy is not merely a matter of placing legal text at the bottom of a website. It is a means of protecting a company against legal proceedings and fines that may impede the growth of its business in the Egyptian market, while the protection of customer data is directly connected to the sustainability of the investment project.


FAQ

What Is the Legal Penalty for Collecting User Data in Egypt Without Consent?

Under Personal Data Protection Law No. 151 of 2020, any controller or processor that collects or processes personal data without the consent of the data subject is punishable by imprisonment for a term of not less than one year, a fine of not less than EGP 100,000 and not exceeding EGP 1 million, or either of these penalties.

Do Cookies Policy Requirements in Egypt Differ From Those in the European Union (GDPR)?

The general principles are largely similar, as Egyptian law requires explicit and informed consent before tracking user behaviour. However, Egyptian law imposes additional local obligations relating to data retention periods and licences issued by the Personal Data Protection Center.

Are Foreign Companies Not Resident in Egypt Subject to Egyptian Data Protection Laws?

Yes, where the processing operation relates to Egyptian citizens or persons residing in the Arab Republic of Egypt, or where the company uses means or servers located in Egypt to conduct processing operations.

What Is the Role of the Data Protection Officer (DPO) Under Egyptian Law?

The DPO monitors the organisation’s compliance with applicable laws, acts as the principal point of contact with the Personal Data Protection Center, receives and responds to data subjects’ requests and complaints, and conducts periodic assessments of the digital security system.

Can Egyptian Users’ Data Be Transferred for Storage on a Cloud Service Outside Egypt?

As a general rule, the Law prohibits this unless an official licence has been obtained from the Personal Data Protection Center and it has been verified that the host country provides legal protection equivalent to Egyptian standards.

References

  • Egyptian House of Representatives: Personal Data Protection Law No. 151 of 2020.
  • Egyptian Ministry of Communications and Information Technology (MCIT): Regulatory decisions implementing Anti-Information Technology Crimes Law No. 175 of 2018.
  • Egyptian Consumer Protection Agency (CPA): Regulations governing e-commerce and digital advertising under Law No. 181 of 2018.