A coalition of Egyptian rights organizations, including the Cairo Institute for Human Rights Studies, issued a joint statement on August 24, 2026 demanding that the National Telecommunications Regulatory Authority (NTRA) withdraw its directive requiring telecom users to submit facial biometric verification through mobile operator apps. Their core objection is procedural rather than principled: NTRA, they argue, has not disclosed how many unauthorized registrations it actually confirmed or identified where in the registration pipeline the failures occurred — and without that diagnosis, there is no shown basis for concluding that biometric face-matching fixes the problem at all.
The Problem NTRA Says It's Solving
The directive did not emerge from nowhere. On August 10, 2026, NTRA announced it had referred Egypt's four licensed mobile operators — Vodafone Egypt, Orange Egypt, e& Egypt, and Telecom Egypt's WE — to the Public Prosecution over violations tied to lines registered in citizens' names without their knowledge. By August 26, NTRA chairman Mohamed Shamroukh put a number on the scale of the problem: roughly 23,000 complaints involving nearly 700,000 mobile lines linked to people who said they never registered them (Techno Time). The same NTRA order suspended bulk corporate-line activation, required existing subscribers to re-sign contracts in person or face deactivation, and directed operators to accelerate biometric identity checks through their apps.
The underlying harm is real and worth taking seriously. Egyptian outlets have reported cases where phone lines silently registered under someone else's identity were later used in criminal activity, leaving the identity-theft victim to untangle the mess after the fact. A regulator responding to 23,000 complaints and a system that let three-quarters of a million lines be registered against people's will is not manufacturing a crisis. Some tightening of SIM registration is a defensible, even necessary, response.
Where the Logic Breaks Down
The coalition's argument is narrower than a blanket objection to identity verification — it's that NTRA hasn't shown biometric matching targets the actual failure mode. If lines were registered without owners' knowledge, the likely culprits are retail-agent fraud, forged documents accepted at point of sale, or backend database manipulation — failures on the operator's side of the transaction, not failures in confirming that the person standing at the counter is who their ID says they are. Facial verification does nothing to stop an operator employee from registering a line against a stolen or duplicated ID using the biometric system, if the fraud runs through insiders with access to the verification pipeline rather than through impersonation at signup. NTRA has not published a breakdown of the 23,000 complaints by cause, so the public has no way to check whether biometric matching addresses the majority of cases or a small subset.
That gap sharpens the coalition's second point: NTRA is asking the same four operators it just referred to prosecutors to become custodians of a new, more sensitive dataset — facial biometric templates — collected from every subscriber. NTRA's spokesperson has said the biometric data itself won't be accessible to mobile-company employees, per reporting on the rollout, with the matching system built alongside the IT Industry Development Agency and the firm CyShield. That's a meaningful technical mitigation, but it doesn't resolve the accountability question the coalition is raising: the operators alleged to have mishandled registration data are still the collection point and app operators for the new biometric layer, and NTRA has offered no independent audit of that separation.
A Legal Basis Still Being Built
Egypt's Personal Data Protection Law No. 151 of 2020 classifies biometric data as sensitive personal data, generally requiring explicit consent for processing. But the Ministry of Communications and Information Technology only issued the law's Executive Regulations on November 1, 2025, and full enforcement — including the Personal Data Protection Center's oversight capacity — doesn't begin until October 31, 2026, per Clyde & Co's regulatory summary. NTRA's biometric mandate is rolling out through this grace period, before the one body statutorily positioned to police sensitive-data handling is fully operational. Egyptian MP Amira al-Adly raised the same concern in a televised interview on August 17, calling on the government to establish the system's legal basis, name a supervisory authority, and define access controls before facial verification expands further (ID Tech) — a request from inside Egypt's own political system, not just from rights groups.
The Proportionate Path
None of this requires abandoning identity verification in telecom — SIM-swap fraud and impersonation are genuine, global problems, and other regulators have reached for biometric tools too. But proportionate regulation asks a sequencing question NTRA has skipped: diagnose the failure publicly, let the newly-empowered Data Protection Center actually stand up before layering a sensitive biometric mandate onto the operators already under prosecutorial scrutiny, and build the independent audit trail before, not after, 100+ million subscribers hand over their faces. NTRA can still hit its stated goal — a phone line that belongs to the person who registered it — without becoming the reason a data-protection regime built in 2020 gets tested for the first time on the least favorable possible facts.