A Fast-Moving Rollout, A Slow-Moving Law
On August 11, 2026, Egypt's National Telecommunications Regulatory Authority (NTRA) announced it would accelerate biometric facial verification for mobile SIM registration, working through the four licensed operators' own apps (Cairo Scene). Users will scan their face against their national ID photo from home, or verify in person at an operator branch; officials have floated early September as the rollout target, though NTRA has not published a binding technical date. The stated goal is narrow: stop lines being registered in a citizen's name without their knowledge.
The trigger is concrete. NTRA says it has fielded roughly 4,000 complaints from citizens who discovered mobile lines registered under their identities without consent, and on August 10 it referred all four operators to the Public Prosecution over the practice, citing evidence gathered from an inspection of user complaints (Daily News Egypt). A separate case sharpened the stakes further: a university student was sentenced to 25 years in a drug-trafficking case built partly around a mobile line he had allowed a friend to register on his national ID (Biometric Update). That is a real harm, and it is reasonable for a regulator to want a stronger check on who is actually standing behind a SIM purchase than a photocopied ID card a telecom clerk may or may not scrutinize.
The MP's Questions
MP Amira al-Adly, in a televised interview on the program "Kalema Akhera," put the harder question to NTRA directly: is facial verification limited to fixing SIM-registration fraud, or is it a first step toward a broader state digital-identity system built on biometric data (Egypt Independent)? She called biometric data "important and sensitive," treated its handling as a matter of national security, and argued that Egypt's Personal Data Protection Law (Law No. 151 of 2020) already requires a specialized data protection center to supervise exactly this kind of collection — so the government should say, before rollout, who oversees the system, how long data is retained, and who can access it. Her underlying point is not that fraud shouldn't be fixed; it is that the actual failure mode in the cases NTRA cites was staff and intermediaries misusing citizens' existing ID documents, a problem facial recognition doesn't obviously solve if a legitimate registrant simply hands the verified SIM to someone else afterward.
A Regulator Ahead of Its Own Statute
Al-Adly's timing argument is the strongest part of her case. Law 151/2020 has been on the books since October 2020, but its Executive Regulations — the rules that actually operationalize the Personal Data Protection Center's licensing and enforcement powers — were only issued in December 2025 via Minister of Telecommunications Decree No. 816 (Baker McKenzie). The Center itself, per the law's own text hosted by the Ministry of Communications and Information Technology, is meant to license and monitor exactly the kind of large-scale biometric processing NTRA is now asking four private operators to run (MCIT, Law No. 151/2020; MCIT press release). NTRA has said biometric templates won't be stored by operators and won't be accessible to their staff — a real, verifiable technical safeguard, not a vague promise. But NTRA is a telecoms regulator, not the data protection authority the 2020 law created for precisely this purpose. Nothing public so far shows the Personal Data Protection Center has formally signed off on the SIM-verification architecture, set retention limits, or been named as the oversight body al-Adly is asking for.
Where This Sits Globally — and What Should Happen Next
Egypt is not inventing this model. India's Aadhaar-linked SIM verification and Mexico's short-lived national mobile registry both tied telecom access to biometric identity, with mixed records on both fraud reduction and mission creep. That comparison cuts both ways: it shows biometric SIM checks can work at scale, but also that once a verification layer exists, the temptation to fold it into a broader digital-ID system is real and has happened elsewhere.
The fix here isn't to block the rollout — reducing identity-document fraud is a legitimate, proportionate goal, and an automated face-match that never reaches a human employee is a genuinely privacy-protective design choice compared to manual ID checks. The fix is sequencing: Egypt should publish the retention policy, name the Personal Data Protection Center as supervisory authority with public reporting obligations, and state explicitly — in regulation, not a spokesperson's assurance — that facial templates collected for SIM verification cannot be repurposed for an unrelated digital-ID program without a fresh legal basis and public notice. Al-Adly is not asking NTRA to stop; she is asking it to show its work under a law Egypt already passed. A biometric system built without that paperwork is one court challenge or leaked dataset away from becoming the story, rather than the SIM fraud it was built to fix.