Article (59) The service provider shall identify, at or before collection of such information, the purposes for which personal information about the customer is collected. The service provider shall not, except as permitted or required by law, or with the consent of the customer to which the personal information relates, collect, use, retain or disclose customer personal information for undisclosed or unauthorised purposes. The service provider shall be responsible for any records of customer personal information or any records of customer electronic communications, in the custody or control of the service provider or its agents. The service provider shall take reasonable steps to ensure that the personal information of the customer and related records are protected by security safeguards that are appropriate to their importance. Chapter Nine Powers of the Supreme Council Article (60) The Supreme Council, in its capacity as the supreme authority entrusted with regulating the telecommunications and information technology matters, shall act to enable the use of electronic commerce and transactions in a simple manner and may in particular, for the purposes of achieving this, carry out the following: (1) oversee the provision, use and development of electronic commerce and transactions means. (2) issue licenses and authorisations necessary in accordance with the provisions of this Law and renew, suspend and terminate them. (3) oversee the development of codes of conduct for the information technology sector and the practices of the service providers. (4) take appropriate legal actions and measures to ensure that service providers and other persons falling under the jurisdiction of this Law comply with the provisions of this Law, its regulations and its implementing decisions. (5) establish the criteria and framework for the protection of information including the personal information of the customer. 24

Select target paragraph3