Egypt’s new child safety rules require platforms to verify that users are old enough to have a social media account. The checks will operate within a legal system that gives security agencies exceptional access to personal information and uses family protection to justify prosecuting online expression.
Acting on president Abdel-Fattah El-Sisi’s instructions, the Supreme Council for Media Regulation (SCMR) and National Telecom Regulatory Authority (NTRA) announced on September 17 that children under 13 cannot hold independent accounts. Users aged 13 to under 15 have a compulsory “safe mode,” which they cannot disable alone. Platforms must review existing accounts, verify ages, and comply within three months of the decision taking effect.
Two days later, Sisi reviewed the measures with prime minister Mostafa Madbouly, communications minister Raafat Hindy and Major General Hany Mahmoud Mansour, head of the Armed Forces’ Signals Department. In this setting, which has become the norm in The New Republic, children’s safety shared the agenda with integrating government databases and expanding investment in cloud computing and data centers. The military’s presence reflected its established authority over the infrastructure through which digital services reach Egyptians.
What this regulatory push will look like in practice remains unsettled, as the state has neither published a concrete executive framework nor clarified whether these directives will materialize as standalone legislation, executive decrees, or an administrative mandate enforced through the licensing of platforms. But while the statutory vehicle is still unwritten, the apparatus that will inherit it is already operational. Examining the legal statutes, biometric pilots, and state-backed corporate entities that form the country’s digital communications architecture offers a peek into the actual machinery awaiting any new mandate—and the interests that will inevitably govern it.
Enforcing protective defaults might reduce children’s exposure to unwanted approaches. However, the policy focuses on classifying users, while actual protection depends on how platforms distribute harmful material and how officials treat complainants.
Egypt’s record makes those institutional questions central to whether the new rules will work.
The minimum age itself is hardly new. Facebook and Instagram already require users to be at least 13, as does TikTok, which United Media Services (UMS), the General Intelligence Service (GIS)–run media conglomerate, penned a partnership with last year. Egypt is adding a government enforcement requirement to an existing corporate promise.
Its special protections also stop at 15, while Meta announced in April that it was expanding default content restrictions for Instagram users under 18 internationally.
So the question is what Egyptian regulation will make companies do that they don’t already claim to do.
Sisi cited Australia as a model, but Australia’s approach conflates enforcement with results.
Its regulator, eSafety, reported in July that three months after its under-16 restrictions took effect, account ownership among under-16s had fallen from 52.4% to 42.1%. Yet most children who previously had accounts had retained them or created new ones. Overall platform use, including without an account, fell only from 85.9% to 81.5%.
Still, the case for protecting Egyptian children online is not frivolous.
An investigation by Arab Reporters for Investigative Journalists, published by Raseef22 in March, found that Egypt’s school disciplinary rules already classified bullying, online defamation, and circulating photographs without permission as serious violations, with one teacher describing social workers whose administrative and clerical duties left insufficient time to handle difficult cases.
Another obstacle identified earlier by the founder of the feminist initiative Speak Up, Jihad Hamdy, was the force of social stigma and fear of family reactions.
Similarly, lawyer Azza Soliman described police officers dismissing complaints or blaming complainants for sharing photographs, which effectively incentivizes blackmailers to exploit the expectation that exposure will bring punishment from the very people and institutions supposed to provide protection.
This was the particular case of Basant Khaled, whose suicide became national news in 2022. The schoolgirl’s father and sister told prosecutors that two men had obtained photographs from her phone, attached her face to a naked body, and threatened to circulate the fabricated images to coerce her into performing sexual acts
When she refused, they distributed them in her village.
Her death followed a threat whose force depended on other people seeing and judging her.
On the corporate front, a recent US Federal Trade Commission report found that advertising-based business models encouraged extensive data collection and engagement, alongside inadequate safeguards for young users.
Requiring companies to stop repeatedly recommending harmful material would cut against how they capture attention, whereas requiring them to classify users fits comfortably into how they already operate.
Regardless of the enforcement, the business model resumes on the other side of the age check. Unless Egypt specifies what a “safe mode” must change, a platform can obey the account rules while still competing to exploit teenagers as long as possible, and turning 15 would end the policy’s special protection without changing those incentives.
The new policy carries that problem into account regulation. NTRA spokesperson Mohamed Ibrahim said safe mode will restrict contact with strangers and give parents greater control. These measures cannot establish that a known contact is harmless, or prevent an image circulating through other people’s accounts. Removing a child’s account does not remove the child from the story others are spreading.
That requires platforms to interrupt distribution and authorities to act on threats without turning the complainant’s private life into evidence against them, and Egyptian law makes that distinction precarious. Article 25 of the 2018 cybercrime law criminalizes violations of privacy and violations of “family values” in the same breath, though the latter is never defined, and it carries penalties that include imprisonment.
The same provision can protect someone against unwanted exposure and punish conduct authorities consider “improper.”
The Egyptian Initiative for Personal Rights (EIPR) documented at least 626 people, including 392 women, prosecuted in “family values” cases between 2020 and July 2026, in a campaign disproportionately targeting poorer women over their appearance, expression, and online content.
The Interior Ministry has publicized arrests with photographs of those detained, and official protection of reputation has included publicly humiliating the people arrested in its name.
Madbouly’s July 29 announcement on social media regulation proposed raising penalties and activating an NTRA monitoring unit, invoking public morals and family reputation.
The regulator now overseeing child protection was already assigned a broader role in policing acceptable expression.
This matters to the practical effectiveness of Sisi’s initiative, as blackmail works by making exposure frightening. If seeking help risks scrutiny of the victim’s clothes, relationships or photographs, official morality policing can strengthen that threat.
Confidential reporting and protection against such prosecution would weaken the blackmailer’s leverage. An age check leaves it intact.
It also reveals a choice about investigative priorities. Monitoring citizens for moral offenses gives officials a continuing supply of accounts to investigate, regardless of whether anyone has suffered an identifiable injury, and giving the regulator more information will not, by itself, change what the authorities decide to pursue or how they decide to do so.
The NTRA spokesperson has also suggested using artificial intelligence to infer age from interactions with videos, photographs, games, and advertisements. Behavior already used to predict what someone might watch or buy would also help determine whether they may keep an account. An adult incorrectly classified as a child would somehow have to challenge the decision to recover access.
This expansion wouldn’t need to begin with a demand for an identity document. Under the approach he described, existing commercial profiling would become part of regulatory enforcement, which, if anything, makes restrictions on how information is reused as important as restrictions on how much is collected.
At the same time, the decision also promises “data minimization” and an appeal mechanism.
The difficulty is enforcing those limits against Egypt’s existing security powers.
Article 2 of the cybercrime law requires service providers to retain identifying, traffic, and device data, and content under their control, for 180 days.
Disclosure requires a reasoned judicial order; a separate obligation requires technical assistance requested by national security bodies.
Collecting less would reduce the information available through these channels, but would not abolish them.
The 2020 Personal Data Protection Law contains a more fundamental exception. It exempts information held by national security authorities and other data they designate.
At their request, the Data Protection Center must direct data handlers to modify, conceal, disclose, or circulate information without needing prior judicial authorization.
Representatives of Defense, Interior, the GIS, and the Administrative Control Authority—defined as a national security body—also sit on the center’s board, meaning that the bodies granted exceptional access help govern the institution responsible for protecting personal information.
Under the 2003 Telecommunications Regulation Law, NTRA’s board includes a representative of the Defense Ministry and representatives of designated national security bodies. Telecommunications operators and providers must also, at their own expense, supply the equipment, systems, software, and communications facilities that enable the Armed Forces and national security entities to exercise their legal powers. Encryption equipment, in turn, requires approval from NTRA, the Armed Forces, and national-security bodies.
The electronic-signature system developed under Law 15 of 2004 follows a similar institutional form.
The Information Technology Industry Development Agency (ITIDA) regulates the certificates that connect an electronic act to a legally identified person. Its governance also includes representatives of the Defense and Interior ministries, the Presidency, and the GIS.
A promise of privacy under such laws leaves a substantial part of state power beyond ordinary privacy protections.
The danger extends beyond a stolen database.
Information can acquire a security use through powers written into the law. Even a technically secure system can protect records against hackers while making them available to the state. For Egyptians subject to these checks, limits on official access matter as much as the software’s security.
Egypt is one of the most surveilled places on earth, with 47 surveillance entities operating within its borders—most of which, if not all, have been contracted by the state.
A recent case shows what control over communications can accomplish.
In 2023, Citizen Lab investigated attempts to infect Ahmed Eltantawy’s phone with Predator spyware after the former MP announced plans to challenge Sisi for the presidency. Researchers found that Sandvine network equipment was used to redirect his browsing to malicious sites through his Vodafone Egypt connection. They attributed the operation to the Egyptian government.
Sandvine’s successor, AppLogic Networks, said it ended all Egyptian customer relationships by the end of 2025.
Still, the case remains relevant because it shows authorities using communications infrastructure against a political opponent. Any new collection of information must be judged against that record, including when its stated purpose is protecting children.
The security institutions involved also have a place in the business of digital expansion. Sisi’s 2022 decree reorganizing the Supreme Council for Digital Society assigned its digital operations committee to the GIS and its data centers committee to Defense, which is why Mansour’s presence at the September meeting reflected an established hierarchy.
Sisi explained his approach at the inauguration of the government data and cloud computing center in April 2024. Ministries would connect to “one main center,” with only “a keyboard and a screen” at their end.
On outsourcing digital public services, he asked: “Can the private sector do this and we buy the service from it?” Then-Communications Minister Amr Talaat said yes. Centralization would create contracts and administrative power.
One of the suppliers created by the state is cybersecurity company CyShield.
On August 27, NTRA presented a biometric verification system developed with the Interior Ministry, ITIDA, and the Egyptian cybersecurity company. A pilot involving all four mobile operators supports remote SIM purchases, mobile wallets, and electronic signatures. CyShield chief Mostafa Issa emphasized that the technology was entirely Egyptian, arguing that domestic development strengthened users’ privacy.
The company’s ownership history gives that assurance a particular meaning.
Commercial records examined by Saheeh Masr identify CyShield’s founding chairman in 2016 as Hassan Rashad, now head of the GIS.
He represented the Egyptian Company for Investment Projects (ECIP), which had been publicly identified as an intelligence subsidiary in 2013.
Three industry sources told Saheeh Masr that CyShield remained affiliated with a security body, and a former employee said government entities were directed to contract with it through direct awards.
ECIP’s position, however, is not confined to CyShield’s founding board.
It owns 6.7% of E-Finance Investment Group, the company at the centre of government electronic payments and several state data systems, and the military’s role was not limited to watching this take place from outside.
The Armed Forces Signal Department helped construct its communications infrastructure.
In 2023, Sisi discussed the unified government network with Madbouly, Talaat, Armed Forces Financial Affairs Authority head Lieutenant General Ahmed El-Shazly, and Signal Department director Major General Bakr El-Bayoumi.
Domestic ownership therefore does not answer the question of who protects Egyptians from domestic surveillance. The arrangement gives security interests a position on both sides of digital expansion: public institutions help organize demand, while an affiliated business is positioned to supply it.
Direct awards convert political access into commercial advantage, and the people whose identities are processed have little say in that relationship, even as officials invoke their privacy to defend it.
The emerging relation joins policy, capital, and information.
That helps explain one side of the September meeting’s apparently disparate agenda.
Among many things, the state wants more transactions and services online, creating demand for digital infrastructure.
It also wants authority over Egyptians’ ability to reach an audience independently. Investment in digital participation and restrictions on expression can advance together. The resulting system offers commercial opportunities to approved suppliers while making citizens’ participation increasingly subject to official conditions.
The September announcement was made in a system where security institutions help organize digital administration, security-linked companies supply identification technology, and the law preserves privileged access to the resulting data. Calling the objective “child protection” changes none of those relationships.
Nor does it resolve the central problem facing a child subjected to abuse.
So far, everything the government has decided to pursue does and says considerably more about classifying an account than about securing a remedy.
For adults, the same decision concerns the conditions of participation: what they must reveal to remain online, who may reuse it, and how they challenge an error. For children, the danger is that a successful verification system becomes the government’s evidence of successful protection.



