
The publications in this issue explore the intersection of privacy, public participation, and technology regulation, raising a broader question about who sets the rules governing digital spaces and who bears the consequences of those rules. In Egypt, Masaar’s publications examine restrictions on women’s participation in public debate on social media, the risks of addressing problems with SIM registration through expanded biometric verification, and regulatory alternatives that could strengthen oversight of registration outlets and operator accountability without requiring the collection of more sensitive data. Other publications address privacy policies, digital identity, consent to data processing, standards in telecommunications legislation, mechanisms for challenging website-blocking orders, and legal defense strategies in cases involving the unauthorized use of telecommunications services.
Across the region, publications by Arab digital rights organizations examine different ways digital infrastructure and technologies are used for surveillance, control, and violence. They address what to do after discovering a spyware infection, how recommendation algorithms can recirculate content related to crime and violence, and the roles of companies and governments in developing, testing, and deploying military and surveillance technologies. Other publications examine the impact of platform regulation and cybercrime laws when applied in contexts lacking effective safeguards for freedom of expression and for the independence of regulators and the judiciary. They also explore how digital violence against women restricts political participation and reproduces forms of discrimination that already exist offline.
Masaar Publications
Implicit Consent as a Gateway to Expanded Personal Data Collection and Processing in the Executive Regulations of the Data Protection Law

The Executive Regulations of the Personal Data Protection Law, issued in November 2025, clarified how the law should be implemented but also reformulated one of its key concepts: consent to the collection and processing of personal data. This paper examines the shift from the law’s requirement for explicit consent to the Executive Regulations’ treatment of providing personal data when requesting a service or completing a transaction as consent to its collection and processing. It also examines how this shift can blur the distinction between data necessary to provide a service and data processed for other purposes, and what this means for data subjects’ ability to exercise control over their personal data.
Publication link
Women’s Issues on Social Media in Egypt: Dynamics and Limits of the Debate

The paper examines how social media platforms shape Egypt’s digital public sphere, where women’s issues are influenced by overlapping social, cultural, technological, and institutional factors. It starts from the premise that the internet has expanded access to the public sphere without eliminating its boundaries. Language, location, interests, and content recommendation mechanisms divide platforms into smaller spaces, while discussions about women in Egypt are particularly sensitive because they are closely tied to gender roles, social expectations, and economic and cultural inequalities.
The paper focuses on three key factors: how Egyptians use social media platforms and how these patterns interact with platform design; the social constraints surrounding women’s issues; and the role of state institutions in shaping the boundaries of public debate.
Publication link
Non-Biometric Alternatives to the SIM Registration Crisis in Egypt — Policy Paper

The paper examines complaints about mobile lines being registered using individuals’ personal data without their knowledge, followed by the referral of Egypt’s four mobile operators to the Public Prosecution. It considers whether biometric verification addresses the underlying problem. Masaar argues that the available information does not establish that the problem is primarily caused by identity impersonation at the point of sale. Errors or misuse may instead occur at different stages of the registration and activation process or within account and record systems. Facial or fingerprint verification may therefore add another layer of identity verification without preventing internal manipulation, while increasing the collection of sensitive data and creating risks that are difficult to address if such data is leaked.
The paper proposes an alternative approach focused on tighter controls over sales outlets, staff permissions, and activation devices; immutable audit logs; monitoring for unusual patterns; immediate notification whenever a person’s identity is used; and documented procedures for submitting objections and correcting records. It also calls for keeping the Arqami (“My Numbers”) service and ownership correction procedures accessible through both in-person and remote channels that do not require biometric data, holding operators accountable for their agents and registration errors, and publishing periodic data that allows the scale of the problem and the effectiveness of the response to be assessed.
Publication link
Related statement:
Joint Statement: Rights Organizations Call for an End to Mandatory Biometric Data Requirements for Telecommunications Users in Egypt | Statement link
Before You Click “Agree”: A Guide to Reading Privacy Policies

The guide turns reading privacy policies from a burdensome legal task into a practical way to understand what a digital service can do with users’ data. It starts with the moment a user clicks “Agree,” which may give a company permission to collect data beyond what is directly needed to provide the service, link user activity to other sources, use the information for advertising, analytics, or developing tools, and later change the terms while the user continues to use the service. The guide explains that the problem is not simply that users fail to read privacy policies. These policies are often long and spread across multiple pages, while many individuals and organizations rely on services for which they have few practical alternatives.
The guide therefore proposes a set of specific questions to consider, including what data is collected, why it is used, who it is shared with, how advertising and tracking work, whether content is used to train AI systems or reviewed by humans, what rights users have to delete their data or object to its processing, how children’s data is handled, and how the terms may change. It also highlights the imbalance of power between the company that sets the rules and designs the interface and the user who needs the service. Rather than simply deciding whether an application is safe or unsafe, the guide encourages users to limit the data they provide and identify terms that may pose significant risks.
Publication link
Other Publications from Masaar:
- Digital Identity in Egypt: Between Expanding Access to Services and Threatening Fundamental Rights | Publication link
- Before Enacting the Law: Human Rights Standards for Drafting Telecommunications and Information Technology Legislation | Publication link
- Template Grievance Against Website Blocking Orders | Publication link
- Substantive Defense Memorandum on the Offense of Unauthorized Use of Telecommunications and Broadcasting Services | Publication link
From the Arab Region
What Should Happen After We Detect a Spyware Infection on a Device? (SMEX)
SMEX argues that discovering a commercial spyware infection on a phone should be the beginning of a process of accountability, not simply the end of a technical investigation. The paper emphasizes the importance of preserving digital forensic evidence, as resetting the device, deleting messages, removing applications, or immediately updating the system after an infection is suspected may alter traces needed for forensic examination. Once an infection is confirmed, it recommends examining the technical evidence in the context of the targeting, since a compromised phone may point to a broader operation involving journalists, activists, human rights defenders, and their networks of sources and colleagues.
Responsible documentation enables comparison of infrastructure, indicators, and targeting patterns, helping identify broader surveillance patterns rather than treating each case as an isolated incident. Responsibility for such surveillance may extend across software developers, purchasers, and operators. The paper also stresses that the harm can extend beyond the device owner, as a compromise may expose communications, sources, and entire professional networks. SMEX therefore connects accountability with digital forensics, documentation, investigative journalism, legal and regulatory action, and export controls, so that evidence can be used to protect affected communities and hold governments and companies accountable, rather than serving only as a technical record of an incident.
Publication link
A 7amleh Study Examines the Role of TikTok Algorithms in Reproducing a Culture of Organized Crime in the Palestinian Community in Israel (7amleh — The Arab Center for the Advancement of Social Media)
7amleh examines how TikTok can become part of an environment that reinforces the presence of organized crime within the Palestinian community in Israel, rather than simply serving as a neutral platform for sharing content. The study uses a mixed-methods approach that combines interviews with specialists in criminology and digital media, a focus group with youth workers, and an analysis of crime-related content using a model developed by 7amleh to examine videos, images, and text. The study finds that accounts associated with criminal activity do more than display violence. They use the platform to construct a criminal identity, showcase weapons and money, issue threats, promote illegal activities, and recruit others.
The study argues that recommendation algorithms that reward sensational content and high engagement may increase its reach, particularly among young people. Repeated exposure can normalize violence and portray those who engage in it as symbols of power. However, the study does not attribute the phenomenon to algorithms alone, linking it instead to broader factors including marginalization, inadequate protection, and discriminatory policies.
The Militarization of Technology in Southwest Asia and North Africa: Produced, Tested, Deployed (SMEX)
The SMEX report examines how military and quasi-military technologies are produced, tested, sold, and used across Southwest Asia and North Africa, focusing on the human cost obscured by the increasingly blurred line between civilian and military uses. It examines six countries—Sudan, Syria, Saudi Arabia, the United Arab Emirates, Israel, and Egypt—and compares their domestic legal frameworks with the role each plays in the technology market, whether as a producer, purchaser, or a place where technologies are tested on populations.
The report also examines how major technology companies, specialized surveillance firms, and suppliers of dual-use technologies are connected to cross-border government and military networks. It shows how occupation, war, and domestic repression can create environments in which these technologies are tested and marketed.
Publication link
How Social Media Regulations in the Middle East and North Africa Could Become Tools of Censorship and Control (Access Now)
An Access Now analysis examines a wave of laws and draft laws regulating social media platforms across the Middle East and North Africa. It warns that adopting elements of the European Union’s Digital Services Act does not automatically lead to the same human rights outcomes. The analysis begins with the Arab League’s 2023 strategy and then examines regulatory approaches in Jordan, Egypt, Morocco, Algeria, and Saudi Arabia, where proposals tend to require companies to establish a local presence, respond quickly to content removal orders, and apply broad national definitions of illegal content.
The analysis argues that the problem is not platform regulation itself, but rather the use of regulatory procedures in contexts that lack essential safeguards, including effective legal protections for freedom of expression and personal data, independent regulators and judiciaries, and a safe civic space. Without these safeguards, trusted flagger systems and content removal obligations may become tools for accelerating government censorship rather than holding companies accountable. The analysis also argues that platforms have a responsibility to conduct human rights due diligence, publish detailed information about content removal requests, resist overly broad orders, and challenge them whenever possible.
Publication link
Understanding and Analyzing the Tactics and Narratives of Online Gender-Based Violence During Iraq’s November 2025 Parliamentary Elections (INSM for Digital Rights)
The INSM report documents patterns of technology-facilitated gender-based violence targeting women candidates in Iraq’s 2025 parliamentary elections. It examines this violence as part of the conditions shaping women’s political participation, rather than as abuse separate from the electoral process. The research team used qualitative monitoring and quantitative analysis of publicly available content from 160 pages in Arabic and Kurdish between October 2025 and January 2026. It identified 137 Arabic-language posts and 83 Kurdish-language posts targeting women candidates and analyzed approximately 33,000 comments to understand how gender-based hostility takes shape around women’s political participation.
The findings show that attacks focused more on morality, appearance, honor, allegations of corruption, and manipulation of quota systems than on candidates’ political programs and qualifications. The report also identifies differences between the Arabic and Kurdish contexts. Arabic-language content relied more heavily on harassment and sexual insults, while Kurdish-language content made greater use of discriminatory narratives, including accusations of betrayal and dehumanizing language. Although explicit calls for violence appeared in only a small proportion of comments, those that did appear included incitement to violence and severe sexual threats. The report links this environment to structural weaknesses in the political system and recommends coordinated responses from government, political parties, platforms, and civil society to protect women’s digital safety and their ability to participate in democratic processes.
More Publications from the Arab Region
- How Governments Design Laws Against You and Call It Cybersecurity (SMEX) | Publication link
- Position Paper and Legal Opinion on the Draft Iraqi Cybercrime Law of 2026 (INSM for Digital Rights) | Publication link
- Final Statement of the Consultative Meeting on the State of Digital Rights and Digital Violence in Iraq (INSM for Digital Rights) | Publication link