Why Computer Access Offenses Matter for Expats
Many expats working in Egypt hold roles that involve accessing corporate networks, shared databases, client accounts, or government portals. Egypt's cybercrime law draws sharp distinctions between authorized access, exceeded access, and unauthorized access — and each carries its own criminal penalties. The law also applies to inadvertent access if you remain in a system after realizing you should not be there.
The Three Core Access Offenses
1. Unauthorized Access (Article 14)
Article 14 covers two scenarios:
- Intentional unauthorized access to a restricted website, private account, or information system.
- Unintentional access where the person remains in the system unlawfully after realizing they should not be there.
The penalty is:
- Minimum 1 year imprisonment
- Fine between EGP 50,000 and EGP 100,000
- Or either of these penalties
This is one of the most important provisions for expats to understand. If you accidentally access a system you are not authorized to use — for example, by following a misconfigured link or using cached credentials — the crime is not in the initial access but in staying once you know you are unauthorized.
2. Exceeding Authorized Access (Article 15)
Article 15 targets a subtler offense: accessing a system you are legitimately permitted to use but going beyond the boundaries of that permission — either by accessing it for longer than allowed, or by accessing higher-privilege areas than your authorization covers.
The penalty is:
- Minimum 6 months imprisonment
- Fine between EGP 30,000 and EGP 100,000
- Or either of these penalties
This is especially relevant for expat employees. If your employment contract or IT access policy limits your system access to specific modules, exceeding those limits — even unintentionally — can constitute a criminal offense, not merely an HR matter.
3. Attacks on State-Owned or State-Linked Systems (Article 20)
Article 20 applies to anyone who intentionally or inadvertently (and without lawful justification) accesses, remains in, or exceeds authorized access levels on any website, email, account, or information system that is:
- Managed by or on behalf of the State
- Owned by or related to the State
Penalties under Article 20 are significantly more severe than those under Articles 14 and 15. This provision is particularly relevant for expats working with government ministries, state-owned enterprises, or regulated utilities in Egypt.
Intercepting Data and Communications (Article 16)
Beyond access offenses, Article 16 criminalizes the unlawful interception of any information, data, or communication transmitted via an information network or computer device. This includes:
- Packet sniffing on a shared network
- Intercepting emails or messages in transit
- Monitoring network traffic without authorization
The penalty is minimum 1 year imprisonment and fines between EGP 50,000 and EGP 250,000. Expats working in network administration or cybersecurity roles must ensure all monitoring activities are explicitly authorized in writing.
Damaging or Disrupting Systems and Accounts (Articles 17–19)
- Article 17: Intentionally destroying, disrupting, or deleting software or data on an information system — minimum 2 years imprisonment.
- Article 18: Damaging, disrupting, or hacking an individual's email or private account — minimum 1 month imprisonment, fines between EGP 50,000–100,000.
- Article 19: Defacing or altering a website belonging to a company or individual — minimum 3 months imprisonment, fines between EGP 20,000–100,000.
Possession of Hacking Tools (Article 22)
Article 22 makes it a criminal offense to possess, import, manufacture, sell, or circulate any:
- Device or equipment designed to enable unauthorized access
- Software, access codes, passwords, or encryption keys used to commit offenses under this law
- Any tools intended to facilitate cybercrimes
Expats in cybersecurity roles should ensure they hold explicit written authorization from the competent Egyptian authority for any tools that could fall under this definition. Penetration testing or vulnerability assessment work in Egypt requires careful legal clearance.
Practical Advice for Expats in IT and Business Roles
- Document your access authorizations in writing. A verbal instruction from a manager is not a legal defense under Egyptian law.
- Log off systems you should not be in immediately. The law penalizes remaining in an unauthorized system, so exit promptly and document the incident.
- Review your employment contract's IT access clauses. Access beyond your defined role could constitute an Article 15 offense.
- Never use colleagues' credentials, even to help them. This constitutes unauthorized access.
- Cybersecurity professionals must obtain local legal clearance before conducting any form of penetration testing or network monitoring in Egypt.
- Assume electronic evidence will be used against you. Article 11 gives digital evidence the same weight as physical evidence in Egyptian criminal proceedings.
Summary
Egypt's access offense framework is detailed and unforgiving. Both intentional hackers and careless employees face criminal exposure. Expats should treat digital access in Egypt as a strictly regulated activity and ensure all their authorizations are current, documented, and respected.