
Introduction
In February of this year, the Egyptian Parliament began discussing proposed amendments to the Anti-Cyber and Information Technology Crimes Law (Cybercrime Law), issued in 2018. These amendments reveal a problem in the way Parliament and the government approach the digital sphere. Whenever a painful incident or a social risk connected to technology emerges, the legislative debate returns to the same tools, which include increasing penalties, expanding criminalization, relying on blocking, and adding vague concepts to a law that is already problematic by design.
This paper proceeds from the position that protecting children and young people from online extortion, gambling, commercial exploitation, and harmful digital designs is a legitimate and necessary objective. However, that protection will not be achieved by expanding the Cybercrime Law or by adding another layer of punitive provisions to legislation whose clarity and scope of application have already raised serious concerns in practice.
Parliament has previously considered proposals that were close in substance and legislative philosophy to those currently being discussed, and the reasons advanced at the time support not proceeding with the present approach. In 2023, the Constitutional and Legislative Affairs Committee discussed four draft laws to amend Cybercrime Law No. 175 of 2018. These drafts focused on increasing penalties and introducing new forms of criminalization, particularly regarding online extortion.
During those discussions, the Ministries of Communications and Justice expressed clear reservations. A representative of the Ministry of Communications noted that existing laws already contain multiple punitive provisions and that the drafts under review focused mainly on harsher penalties, while acknowledging that increasing penalties does not necessarily achieve deterrence. A representative of the Ministry of Justice also considered the existing legislative framework sufficient to address these crimes. The committee ultimately rejected the drafts, noting that it was not legislatively sound and overlapped with several other laws.
That earlier rejection should not be treated as a passing procedural detail. It showed that the Cybercrime Law is not an appropriate vessel into which every new social anxiety arising in the digital space can be inserted. If the reasons for rejection were legislative overlap, lack of precision, the sufficiency of existing provisions, and the limited value of harsher penalties, then returning to the same approach raises questions about the consistency of the legislative process. Parliament, or at least its relevant committees, rejected the logic of partial amendment and punitive escalation when it appeared in a parliamentary bill. Yet, the same path has returned when framed through a governmental discourse about protecting children and young people from dangerous applications, gambling, and games.
The problem is that the new discourse attempts to present the amendment as a response to child protection concerns, while at the same time combining very different issues: online extortion, games, gambling, children’s use of phones, the blocking of specific applications, and the fight against rumors and falsehoods disseminated to the public. This combination produces a confused legislative expansion.
Online extortion requires victim protection and safe, rapid reporting channels. Online gambling requires regulation of advertising and payments, and a prohibition on targeting minors. Games and applications require duties of care imposed on companies and safer default designs for children. By contrast, rumors and falsehoods belong to a different field, freedom of expression and the circulation of information. They should not be inserted into a legislative package presented as protecting children and young people.
Accordingly, the debate should not begin with the question of what new penalties can be added. It should begin with a legislative question: What is the value of adding new provisions to a troubled law instead of reviewing it? Since its enactment, the Cybercrime Law has exhibited substantive and procedural defects, including the absence of a clear legislative philosophy, broad forms of criminalization, conflating newly emerging crimes with the technical dimensions of traditional crimes, and vague provisions that may affect fundamental rights and freedoms.
On that basis, this paper rejects the proposed amendments in their current form. This rejection does not minimize the seriousness of extortion, gambling, or the exploitation of children. Rather, it rejects using those risks as an entry point to reproduce the same punitive logic.
Why the Proposed Amendments to the Cybercrime Law Should Be Rejected
The proposed amendments to the Cybercrime Law should be rejected in their current form because the problem does not lie in a shortage of punitive provisions. It lies in the nature of the law itself and in the way it is used as a permanent container for every new concern linked to technology. The law is increasingly treated as an open space to which crimes, penalties, and exceptional powers can be added whenever a crisis or incident creates public anxiety about the use of technology. This legislative approach expands the state’s power to criminalize, monitor, and block, rather than building a digital policy grounded in rights protection, precise risk identification, and regulatory and legal tools proportionate to those risks.
The Existing Cybercrime Law Is Flawed and Should Not Be Used to Expand Criminalization
The problem with the Cybercrime Law is not that it is incomplete and needs to be supplemented or updated through new provisions. Since its enactment, the law has suffered from structural defects relating to its philosophy, scope, and tools. It combines broad criminal provisions, blocking powers, heavy obligations on service providers, data retention rules, and concepts that are open to expansive application. Adding new crimes to it, therefore, broadens the effect of a troubled law rather than addressing a specific legislative gap.
Egypt’s legislative experience in this area has been built on conflating two types of conduct: technical incidents that may require specific procedural regulation, and traditional crimes that have been re-committed through digital tools. This conflation has led to unnecessary expansion of criminalization and to the absence of a clear legislative philosophy capable of determining whether the objective is to protect privacy, safeguard information systems, regulate the public sphere, or grant law enforcement broader powers in the digital environment.
The issue, therefore, is not the existence of a legal vacuum so much as the absence of a clear legal philosophy and the dominance of punitive responses over other regulatory and protective tools. This framework may produce provisions that affect fundamental rights rather than protecting them, which is directly relevant to assessing the proposed amendments.
When the law itself is burdened by ambiguity and overbreadth, it should not be treated as a suitable foundation for adding new crimes. The priority should be a comprehensive review that narrows its punitive scope, reassesses blocking powers, revises data retention obligations, and establishes clearer safeguards for digital searches and data requests.
Expanding a law built around the concept of cybercrime also reinforces the inaccurate assumption that every online risk requires a separate cybercrime. This approach weakens the coherence of the legal system, creates duplication between the Penal Code and special laws, and opens the door to different penalties simply because the means used are different.
Extortion remains extortion whether it takes place through a paper letter, a phone call, or a social media account. Fraud remains fraud whether it takes place in an office or through an application. What is needed is the modernization of evidentiary tools, protection mechanisms, and procedures, not the addition of new punitive layers with every new technological medium.
The Proposed Amendments Conflate Different Crimes and Different Public Policies
As reflected in parliamentary statements, the proposed amendments do not address one clearly defined problem. They combine online extortion, games, gambling, blocking applications such as Roblox, restricting phone use among younger age groups, and confronting rumors and falsehoods disseminated to the public. This combination reveals confusion in defining the problem that legislative intervention is meant to address. Many aspects of these issues can also be addressed through existing laws without creating new provisions specifically for them.
Each of these issues requires a different policy, different tools, and different safeguards. The following sections address the issues raised in connection with the proposed amendments and explain how existing laws already apply to them.
Online extortion
Online extortion requires a victim-protection system that provides safe and confidential reporting channels, protection from stigma, urgent judicial orders to prevent the publication of content or secure its removal, psychological and legal support, and training for law enforcement agencies on dealing with victims, especially women and children, without blame, threats, or counter-extortion. Addressing extortion solely through harsher penalties ignores the fact that many victims never reach the reporting stage in the first place. Judicial practice also shows that severe sentences are already being issued in these cases.
From a criminalization and punishment perspective, online extortion is already criminalized and punishable under Article 327 of the Penal Code. Extortion is classified as a serious felony, and, where aggravating circumstances are present, its penalty may range from three to fifteen years’ imprisonment. These aggravating circumstances include threatening the victim with the disclosure of matters or the attribution of matters that are offensive to honor. The criminalization encompasses traditional means as well as methods that use modern communications and information technology.
Criminal liability for online extortion also extends to existing provisions of the Cybercrime Law, which criminalize certain forms and means of extortion. Article 24 criminalizes the fabrication of websites, private accounts, or email accounts and the false attribution of them to another person, punishable by imprisonment, a fine, or either penalty. If the fabricated account, website, or email is used in a way that harms the person to whom it is falsely attributed, this becomes an aggravating circumstance, raising the minimum penalty to imprisonment for at least one year and up to three years, and a fine of not less than EGP 50,000 and not more than EGP 200,000, or either penalty.
In addition, Article 25 criminalizes the publication of news or images that violate a person’s privacy without their consent via the internet or other information technology. The penalty is imprisonment for at least six months and up to three years, and a fine of not less than EGP 50,000 and not more than EGP 100,000, or either penalty.
Article 26 further criminalizes the use of an information program or information technology to process another person’s personal data to link it to content that is contrary to public morals, or to display it in a manner that damages that person’s reputation or honor. The penalty is imprisonment for at least two years and up to five years, and a fine of not less than EGP 100,000 and not more than EGP 300,000, or either penalty.
Online Gambling
Online gambling is linked to advertising, payment systems, consumer protection, money laundering, the targeting of minors, and exploitative application design. Addressing it, therefore, requires financial, advertising, and regulatory controls, strict limits on targeting children and young people, and accountability for companies, payment networks, and advertising intermediaries. It should not be inserted into the Cybercrime Law as a new cybercrime.
Gambling in its traditional form is already criminalized under Articles 352 and 353 of the Penal Code, which criminalize gambling games and what was historically referred to as lotteries. The offense is punishable by imprisonment for up to three years and a fine not exceeding EGP 1,000, with the confiscation of all money, games, and equipment used in the commission of the offense.² ³
Games and Applications
Games and applications require a different approach, based on clear age ratings, safe default privacy settings, restrictions on communication between children and strangers, effective reporting tools, transparency regarding in-app purchases, and digital safety standards that impose duty of care obligations on companies toward children.
These are not primarily criminal matters. They are regulatory, design, and educational issues. Criminal law should therefore not be used where less intrusive regulatory tools are sufficient and better suited to addressing the specific source of risk.
Rumors and Falsehoods
Including rumors and falsehoods in the same legislative package is one of the most troubling aspects of the proposed amendment. The terms “rumors” and “falsehoods” do not belong to child-protection policy. They belong to the sphere of freedom of expression and the circulation of information. Including them in a discussion about protecting children and young people creates a justification for expanding restrictions on public speech. These terms are inherently vague and may be used against journalism, political criticism, public debate, and human rights content, rather than against a specific risk threatening children.
The Penal Code already contains several provisions criminalizing the publication of “rumors” and “falsehoods,” including, but not limited to, the offenses set out in Articles 80(d), 102 bis, and 188. Penalties under these provisions may reach five years’ imprisonment and may be increased further where aggravating circumstances are present.
Online Fraud
Introducing new punitive provisions for what is described as online fraud or cyber-enabled fraud is another clear example of conflating the crime with the means used to commit it. Fraud, at its core, involves deceiving the victim to obtain money, a benefit, or data, or to induce the victim to act in a way that harms their interests. That core does not change because the deception occurs via a text message, a fake link, an application, or a page impersonating a financial institution. Technology expands the scale of the crime and makes it harder to trace, but it does not always create a new crime in legal terms.
For that reason, the response to online fraud should not begin with adding a new article to the Cybercrime Law. The priority should be to review existing provisions in the Penal Code, financial legislation, consumer protection laws, and telecommunications regulation, determine whether they already criminalize the conduct, and then develop investigative and evidentiary tools. If a person deceives another into handing over money through a fake payment link, the problem is not that the law does not recognize fraud. The problem is that investigative authorities need greater capacity to trace transfers, preserve digital evidence, and cooperate with service providers, all within clearly defined legal safeguards.
In this context, the Penal Code already criminalizes fraud in all its forms, regardless of the fraudulent means used, and punishes the offender with imprisonment for up to three years.⁴ Article 23 of the Cybercrime Law also criminalizes certain means of fraud involving bank cards and electronic payment services and tools. The penalty is imprisonment for at least three months and up to three years, and a fine of not less than EGP 30,000 and not more than EGP 50,000, or either penalty, in addition to the penalty provided for under the Penal Code.
Creating a broad new offense under the label “online fraud” may result in duplication of criminalization. A person could be prosecuted for the same act as fraud, online fraud, and possibly as an offense under other laws if the conduct involved personal data or payment instruments. This creates confusion in legal characterization and gives investigative authorities room to select the harshest available description.
This does not diminish the seriousness of phishing, impersonation, fake payment links, or misleading investment and gambling applications. The more effective response lies in requiring banks, payment companies, and platforms to establish early-warning mechanisms, rapidly freeze suspicious transactions subject to legal safeguards, provide clear dispute channels, and run digital awareness campaigns. It does not lie in opening the door to vague criminalization of every “suspicious” use of technology.
Parliament should therefore apply a clear standard: no new crime should be created merely because the means used are digital. If the act is already criminalized, the priority should be to address gaps in enforcement, evidence, and protection, not to multiply punitive provisions.
Harsher Penalties Do Not Address the Causes of Risk
One of the recurring arguments in discussions on amending the Cybercrime Law is that existing penalties are not deterrents. This assumption is rarely based on a clear assessment of the law’s impact or on data concerning the reasons for underreporting, weak investigations, or slow responses. It reflects a method that can be summarized as follows: if the problem persists, raise the penalty; if a painful incident occurs, add a new crime; if public fear grows, expand the scope of the law.
Previous parliamentary discussions on draft amendments to the law show that this logic was not persuasive even to some representatives of official bodies. The representative of the Ministry of Communications explained that the draft under review focused mainly on increasing penalties and that harsher penalties do not necessarily achieve deterrence. The Ministries of Communications and Justice also considered the existing legislative framework sufficient to address these crimes. The committee ultimately rejected the draft, citing legislative overlap and lack of precision.
If government bodies previously considered existing laws sufficient and found that the problem was not the absence of a legal text, Parliament’s return to the same path today requires a clear justification. In crimes such as online extortion, the problem is often not that the penalty is too low. The problem is that the victim may be afraid to report for various reasons: fear of being turned from a victim into a subject of moral accusation; lack of confidence in the confidentiality of procedures; uncertainty about where to seek help; delays in removing content or stopping threats; or the absence of psychological and legal support. In such cases, a harsher penalty written into law does not benefit the victim if the victim still cannot access protection.
Deterrence is not achieved simply by increasing years of imprisonment or fines. It depends on whether the offender knows that reporting will be easy and safe, that the response will be swift, that digital evidence will be preserved properly, and that the victim will not be socially or legally punished for seeking protection.
Blocking Is Not a Legislative Policy for Protecting Children
Blocking an application or game, as with Roblox, may be presented as a quick measure to protect children. Yet general blocking does not distinguish between harmful and legitimate uses. It affects all users and does not necessarily address the harmful behavior, design features, abusive accounts, or exploitation mechanisms associated with the application. As a result, it may restrict access to the entire service rather than address the specific source of risk.
Technically, blocking is not necessarily a stable solution. It can be circumvented in various ways and may push some children and adolescents toward unofficial versions, alternative links, or less secure circumvention tools. In such cases, the risk may move into less transparent environments that are less subject to family or regulatory oversight.
Legally, blocking restricts freedom of expression, access to information, and participation in cultural and digital life. It should therefore not be based on administrative decisions or broad, undisclosed justifications. If there is specific unlawful content or a particular function within an application that creates a defined risk, intervention should be targeted at that risk and limited to what is necessary to address it.
Any blocking power should be subject to a reasoned judicial order, limited in scope and duration, open to appeal, and accompanied by sufficient transparency regarding the reasons for the decision, the authority that requested it, and its necessity. Blocking decisions should also be subject to periodic review.
Without these safeguards, blocking may shift from an exceptional measure into a permanent tool for controlling the digital space. Moreover, expanding blocking under the banner of child protection may, over time, extend to entertainment platforms, social media platforms, news websites, or other forms of critical or human rights content.
Amending the Cybercrime Law Must Begin with an Impact Assessment
Parliament should not discuss a punitive amendment to the Cybercrime Law without a clear, published impact assessment. Criminal legislation is not a symbolic tool for reassuring public opinion, nor should it move in response to a painful incident, a wave of media concern, or temporary political pressure. Every new criminal provision gives the state additional power, creates a potential risk to individuals, and redraws the boundaries of what is permissible in the digital environment.
The minimum standard of legislative responsibility, therefore, requires that any amendment be preceded by an assessment that explains the scale and causes of the problem, the adequacy of existing laws, and the expected impact of the proposed intervention on rights and freedoms.
If the government or Parliament seeks to address online extortion, it should first publish data on the number of reports, the nature of the incidents, the groups most affected, where reports break down, the percentage of cases that reach court, the average response time, and the reasons victims refrain from reporting.
In the case of online gambling, data should be published on the number of cases, the nature of the applications or websites used, the role of advertisements, influencers, and payment companies, the scale of targeting minors, and the regulatory gaps that allowed these practices to spread.
In the context of games or applications that may pose risks to children, the type of risk must be identified precisely. Does it relate to communication with strangers, in-app purchases, content, addictive design, disguised gambling, or grooming? Each risk requires a different tool. They should not be grouped under a single heading and then answered with a single penalty or a broad blocking power.
The absence of an impact assessment makes the proposed amendment impression-based rather than evidence-based. This is especially serious in criminal law, which should be a last resort rather than the first tool of choice. If the problem is weak reporting, the solution lies in protecting victims and ensuring confidentiality. If the problem is platform design, the solution lies in imposing duty-of-care obligations and safety standards on companies. If the problem is advertising and payments, the solution lies in market regulation and intermediary accountability. Adding a new crime or increasing an existing penalty without knowing where the failure lies is closer to a political response than to legislative reform.
An impact assessment must also consider social effects. Expanding criminalization does not necessarily expand protection. In extortion cases, for example, a harsh punitive discourse may increase victims’ fear of reporting unless it is accompanied by a clear message protecting them from stigma and accountability.
In child-protection cases, general bans may deprive children of spaces for entertainment, learning, and communication, or push them to use the internet in secret, rather than building trust and the capacity to use it safely.
In information-related cases, inserting rumors into a child-protection package may have a restrictive effect on journalism and public debate. These effects manifest in the application of legal texts and must be assessed before legislation is enacted, not after harm has occurred.
The impact assessment process should also be public and participatory. It is not enough for a government body to prepare an unpublished internal memorandum and then ask Parliament to pass the amendment. The full bill, its explanatory memorandum, the data on which it relies, the previous and current views of government bodies, and the reasons for departing from the grounds that led to the rejection of similar proposals in the past should all be published. Hearings should be held with civil society organizations, child protection experts, lawyers, judges, technologists, psychologists, social workers, representatives of schools and families, journalists, and relevant companies and platforms.
Before discussing the wording of any new penalty, Parliament should require the government to provide a comprehensive impact assessment that demonstrates the need for the amendment, identifies alternatives, explains the risks, and sets out safeguards. Without that, amending the Cybercrime Law will reproduce the same approach: fast, broad, punitive legislation that can be used against the very rights it is supposed to protect.
Criminal Law Is Not a Care Policy
The proposed amendments treat complex social, educational, psychological, and economic problems as though they were essentially criminal problems. This is the central flaw in the legislative logic on offer. Online extortion, digital gambling, bullying, grooming, addictive design features in applications, and children’s exposure to harmful content or communication are not detached from the social, economic, and educational environment in which children and young people live. These problems occur in the digital space, but they do not arise from technology alone, nor are they solved by adding a new penalty or expanding blocking powers. Reducing these problems to the Cybercrime Law turns criminal law into an unsuitable substitute for care, protection, education, and regulatory policies.
Criminal law, by its nature, intervenes after harm has occurred or when harm is suspected. It is a tool of punishment and prosecution, not a tool for building social capacity to prevent harm. It may be necessary in specific cases to hold accountable those who extort, groom, exploit, or defraud a child. But relying on it as the primary instrument for protecting children means that state intervention often begins after the risk has materialized and after the victim has already suffered part of the psychological and social harm.
For example, treating online gambling as a cybercrime ignores the fact that it is a market built on advertising, electronic payments, interface designs that encourage repeated risk-taking, and, at times, influencers or marketing messages that reach minors and young people. Addressing this risk begins with dismantling the economic structure that allows it to spread. This includes regulating advertising, prohibiting marketing directed at minors, requiring platforms to remove or prevent the promotion of gambling, and providing channels for objection and restitution where children have been exploited or deceived.
The problem with excessive reliance on criminal law is that it gives the state the appearance of swift action without building real preventive capacity. It is easy to announce a new penalty or block an application and present it to the public as decisive action. What is more effective, however, is to build sustained policies that include training, institutional coordination, corporate oversight, victim support, data protection, and periodic impact review. Criminal law gives the state a tool for punishment, but it does not, on its own, provide the conditions for care. When it is used as a substitute for care, the result is victims who do not report, children who move to less safe spaces, and families left alone to face powerful platforms.
Turning care issues into criminal matters also expands the intervention of policing authorities in the lives of children and young people. The broader the definition of risk, the broader the powers to search, collect data, block, prosecute, and control content. In the name of protecting children, this may lead to tools that monitor children, collect their data, and restrict their access to knowledge, communication, and entertainment. In the name of combating gambling or dangerous games, broad age-verification mechanisms may be imposed that collect sensitive data about everyone.
Conclusion
Egypt does not need a new amendment that adds yet another layer of criminalization to the Cybercrime Law. Before that, it needs a serious review of the existing laws, how they are used, and the legislative logic that turns every digital risk into a penalty, every social crisis into a source of blocking power, and every painful incident into a justification for expanding state authority.
Protecting children and young people from extortion, gambling, commercial exploitation, and harmful digital designs is a legitimate and necessary objective. But that protection will not be achieved through rushed legislation that conflates different problems, imposes harsher penalties without an impact assessment, blocks entire platforms without safeguards, or inserts vague terms such as “rumors” and “falsehoods” into a legislative package framed as protecting children and young people.
This paper, therefore, calls on the Parliament to reject the proposed amendments in their current form and to stop treating the Cybercrime Law as the default tool for every digital risk. A fairer and more effective path begins with a comprehensive review of the law, a published impact assessment, the separation of legislative tracks based on the nature of each problem, and the development of a digital protection framework grounded in prevention, safeguards, transparency, corporate accountability, and victim support.
Notes
1. Court of Cassation, Criminal Chambers, hearing of 12 February 2024, Appeal No. 5043 of Judicial Year 93. The Court reaffirmed its settled jurisprudence that the term “writing” in Article 327 was used illustratively and in broad terms to include all forms of writing, whether traditional or by modern electronic means. Where the judgment established that the defendant sent threatening phrases through modern electronic means, namely a keyboard, with the intent of instilling fear in the victim in order to compel her to do what was demanded, it had established the material element of the offense of threat as defined by law.
2. Article 352 of the Penal Code provides that anyone who prepares a place for gambling games and makes it available for people to enter shall, together with the cashier of that place, be punished by imprisonment and a fine not exceeding EGP 1,000. All money and items in the places where such games are conducted shall be seized and confiscated.
3. Article 353 of the Penal Code provides that the same penalties apply to anyone who offers for sale anything in what was known as a lottery without government authorization, and that all money and items placed in the lottery shall also be seized by the government.
4. Article 336 of the Penal Code provides for imprisonment for anyone who obtains money, goods, debt instruments, releases, or any movable property by fraud in order to deprive another person of all or part of their wealth, whether by fraudulent means intended to lead people to believe in a false project or fabricated event, create hope of imaginary profit, suggest repayment of money obtained by fraud, create the belief in a false debt instrument or forged release, dispose of immovable or movable property that the offender does not own and has no right to dispose of, or assume a false name or incorrect capacity. Attempted fraud is punishable by imprisonment for a period not exceeding one year.