Privacy and Technology Policies

Data Mapping and Transfer Risk Assessment: Vodafone Egypt’s Practices for Protecting Cloud Data

Dina Mostafa, Data Protection and Privacy Officer at Vodafone Egypt, explains that compliance does not begin after contracting, but with knowing where data is located, which parties can access it, and the countries to which it is transferred. The practices presented by the company include assessing the impact of data transfers, building a data map, and organizing relationships with processors through clear agreements.

2026-09-07
5 min read
8 views
certi.news
Data Mapping and Transfer Risk Assessment: Vodafone Egypt’s Practices for Protecting Cloud Data

Data protection within companies is no longer limited to a subsequent legal review of contracts or handling customer requests after they arise, according to Dina Mostafa, Data Protection and Privacy Officer at Vodafone Egypt. With the growing reliance on cloud computing services and the transfer of data between systems and countries, compliance begins with a direct operational and technical question: Where is the customer’s data located, who can access it, and how does it move within and outside the company’s environment?

During her participation in Tech Invest 6 events, Mostafa presented Vodafone Egypt’s experience in addressing the requirements of the Personal Data Protection Law, explaining that the role of the data protection team is to help the company’s various departments turn legal requirements into applicable procedures, while taking into account the nature of the data and the parties that handle it.

First point: Understanding the data life cycle

The experience presented shows that knowing that data exists within the company’s systems is not enough. The country or countries in which it is stored, the systems through which it passes, the parties that can access it, and the purpose for which it is used must be identified. This knowledge becomes more important when cloud services are used, as data may be distributed across more than one system or data center and in more than one country.

For this reason, the company is working to build what Mostafa described as a Data Store or Data Map, a map that helps data protection and cybersecurity teams form a clearer picture of where information is stored, the paths through which it is transferred, and the permissions governing access to it. This picture provides a basis for making more precise decisions about the necessary controls, rather than treating the data as if it were located in a single site that could be easily identified.

How is data transfer assessed?

When there is a request to transfer or share data, Mostafa indicated that a Transfer Impact Assessment is used. The process begins by identifying the nature of the data, the entity or company that will handle it, the purpose of its use, and the country to which the data will be transferred.

The assessment then includes studying the risks associated with the transfer and verifying the existence of appropriate security measures and controls throughout the data-handling life cycle. Thus, the transfer decision is not separate from the legal, technical, and operational context of the data, but rather forms part of a prior risk review before processing or sharing begins.

Contracts are not a formality

The practices presented by Mostafa emphasize the importance of Data Processing Agreements when dealing with companies that process data on behalf of the organization. These agreements define the rules, obligations, and responsibilities of each party, giving the relationship a clearer legal framework for protecting information.

However, according to what she presented, compliance should not begin after the contract is signed. The review should precede contracting and cover the data concerned, processing risks, the parties that will access it, and the countries to which it may be transferred. This point connects the legal decision to the design of the process itself, rather than leaving data protection as a subsequent addition to a path that has already been defined.

What changes in practice for teams and companies?

Companies need the practical ability to handle customer requests related to their data, including requests to learn what data is recorded about them, obtain it, correct it, or exercise the rights provided by law, even when the information exists in systems or cloud services outside the country.

This makes data protection a shared responsibility among legal, technical, and cybersecurity teams, rather than a standalone legal task. Mostafa believes that legal knowledge alone is not sufficient for a data protection officer, just as technical knowledge alone is not sufficient; the officer must understand the nature of the company, its business model, and the data it handles, and then translate legal requirements into controls that do not disrupt operations or unnecessarily increase their complexity.

The article indicates that suitable professional backgrounds for the position of data protection officer may include law, auditing, compliance, or technology, along with the importance of a willingness to learn and develop. Mostafa also emphasized continuous training, interdisciplinary cooperation, and communication with the Personal Data Protection Center as necessary elements for building an implementable compliance framework.

certi.news analysis: The practical value of this experience lies not in adding a standalone tool, but in moving data protection from the stage of paper-based verification to management of the data life cycle: identifying its locations, understanding its paths, controlling access to it, and assessing the risks of transferring it before implementation. However, the article does not provide details about the tools used to build the data map, the risk acceptance criteria, or the operational outcomes of applying these procedures; therefore, these aspects remain open questions for companies seeking to turn principles into measurable controls.

News source
ICT Business Egypt
Open original source ↗
c
Author

certi.news

In the same category

You may also like

View all news