A Prosecution, Then a Mandate
On August 10, 2026, Egypt's National Telecommunications Regulatory Authority (NTRA) referred all four of the country's mobile operators — Vodafone Egypt, Orange Egypt, e& Egypt, and Telecom Egypt's WE — to the Public Prosecution, over mobile lines "registered under citizens' personal data without their knowledge or actual possession" (NTRA, Aug 10, 2026). The regulator said it acted on roughly 4,000 complaints, after more than 1.5 million people used its restored "My Numbers" self-check tool to see how many lines sat under their national ID (Middle East Observer, Aug 12, 2026).
Alongside the referral, NTRA ordered operators to suspend bulk line sales to private and government entities, force existing subscribers to re-sign contracts in person under their real names or lose the line, and — critically — accelerate biometric identity verification, using facial matching through operator apps, for registering, recovering, or disputing a mobile line (Daily News Egypt, Aug 10, 2026).
On August 24, a coalition of 19 rights organizations, coordinated through the Cairo Institute for Human Rights Studies, published a joint statement calling on NTRA to withdraw the biometric requirement entirely (CIHRS, Aug 24, 2026).
The Case for Tightening Registration
Start with what NTRA got right. The underlying fraud is not abstract. Reporting around this episode surfaced a university student sentenced to prison in a drug case built partly around a line registered in his name that he never controlled, and a woman whose stolen identity was used to activate a replacement SIM later used to send defamatory messages and file suit against her. Fraudulent SIM registration in Egypt has put real people in courtrooms for things they did not do. A regulator that discovers thousands of such complaints, plus four operators whose control failures let it happen at scale, has a legitimate basis to intervene — including requiring stronger proof of identity at the point of sale. If a selfie-versus-national-ID facial match at registration screens out someone using a stolen or borrowed ID to open a line, that is a proportionate, narrowly targeted use of biometrics, and privacy advocates elsewhere have generally accepted similar point-of-sale checks when bounded and consensual.
Where the Mandate Outruns the Diagnosis
But NTRA's own account of the fraud complicates that justification. Lines were registered "without knowledge or possession" — meaning the victim was never present to be biometrically matched against anything. That pattern points toward dealer- or agent-side failures: employees or resellers pushing through registrations on stolen data with no live customer in front of them. A biometric check on the general subscriber base, including people who already have a line and are not registering anything new, does little to fix an internal control failure at the point of sale. NTRA's own measures — suspending bulk sales, forcing rebadged contracts — actually target that root cause. The biometric mandate, layered on top and extended into disputing and recovering lines, does something different: it asks people who were victimized by an operator's sloppy verification to now hand that same operator irrevocable biometric data in order to get their name off a fraudulent line.
The 19 organizations make a sharper version of this point, and ground it in Egyptian statute rather than abstract privacy principle: Law No. 151 of 2020, Egypt's Personal Data Protection Law, classifies biometric data as "sensitive personal data" subject to heightened processing requirements (CIHRS statement; Law No. 151 of 2020 text). NTRA has published no data protection impact assessment showing the four operators — the same four just referred to prosecutors for failing basic registration controls — are equipped to secure biometric templates, and has not said who is liable if that data leaks. The timing sharpens the problem: Law 151's executive regulations only took effect via Prime Ministerial Decree No. 816 on November 1, 2025, with a one-year compliance grace period running into October 2026. Egypt is rolling out mandatory biometric telecom verification in the same weeks its own data protection regime is still phasing into full enforcement.
The Proportionality Test Egypt Is Skipping
There is precedent for how this plays out under judicial scrutiny. In Justice K.S. Puttaswamy v. Union of India (September 2018), India's Supreme Court struck down mandatory Aadhaar-to-SIM linking specifically because a regulatory circular, not legislation, had imposed a sweeping biometric condition on telecom access without meeting the proportionality test. Egypt's biometric SIM mandate arrived the same way — as an NTRA operational directive following operator meetings, not as legislation debated and passed with defined purpose limitation, retention limits, and breach liability.
A pro-innovation position does not mean opposing stronger identity verification; weak SIM registration genuinely enables fraud, harassment, and wrongful prosecution, and Egypt's telecom sector benefits from subscribers trusting that a line in their name is actually theirs. But durable digital-identity infrastructure is built on legislative backing, published risk assessments, and clear liability — not emergency directives issued days after a prosecutorial referral. NTRA can keep the parts of its order that fix the real failure (bulk-sale suspensions, forced re-verification, operator audit trails) while adopting what the 19 organizations are actually asking for: non-biometric alternatives for registering and disputing lines, published findings on how the fraud occurred, and a biometric system, if one is built at all, that goes through the same statutory guardrails Law 151 already exists to provide.