A genuine problem, a heavy remedy
On 10 August 2026, Egypt's National Telecom Regulatory Authority (NTRA) said it had referred the country's four mobile operators to the Public Prosecution after inspections tied to complaints about mobile lines and mobile wallets registered in people's names without their knowledge. It also directed the operators to accelerate biometric identity checks inside their apps. A pilot of a National Electronic Biometric Verification System followed on 26 August, according to ID Tech. The system was built with the Interior Ministry, the IT Industry Development Agency (ITIDA) and the Cairo firm CyShield. It lets users verify identity and sign electronically inside operator apps instead of visiting a branch, and it connects to the Interior Ministry's Civil Status Sector.
The strongest case for the policy deserves a fair hearing. Identity fraud on SIMs and mobile wallets is real harm: victims can be tied to lines they never opened, and wallets hold money. Remote identity checks also spare people a trip to a branch, and a verified digital identity can lower the cost of financial inclusion. A regulator that moves against impersonation is doing its job.
The question is whether this design is a proportionate way to do it.
What is known, and what is not
On 24 August, 19 organizations, including Access Now, the Cairo Institute for Human Rights Studies (CIHRS) and the Egyptian Initiative for Personal Rights, urged NTRA to withdraw any directive making biometric data a condition of registering or managing a phone line. Their central objections were specific:
- Authorities have not said how many unauthorized registrations occurred, where the failures arose, or whether they came from point-of-sale impersonation, employee misconduct or system manipulation.
- Biometric matching can confirm that a person matches a reference record. It cannot stop insider abuse or internal system failure, which may be what happened.
- NTRA referred the operators to prosecutors while asking those same operators to handle sensitive biometric data.
- Faces and fingerprints cannot be changed after a breach, unlike passwords or documents.
The public record also leaves out the details that matter most. Retention periods and access rules for the facial data have not been disclosed. CyShield has been reported as linked to the General Intelligence Service, a report I could not independently confirm. NTRA named CyShield as a partner around 25–26 August. Whatever the truth of that link, the right answer is published rules, not reassurance.
Parliament has asked similar questions. On 17 August, MP Amira al-Adly asked on television why biometric data would be collected, how it would be protected and who would oversee it. She also asked whether the checks would stay limited to SIM misuse or become part of a wider state digital identity programme. She called for a defined framework covering collection, storage, use, access and security.
The legal clock is already running
Egypt has a framework for exactly these questions. The Personal Data Protection Law (Law No. 151 of 2020) classes biometric data as sensitive. Its Executive Regulations were issued on 1 November 2025, which started a one-year grace period, according to CMS. Baker McKenzie reports that the period expires on 31 October 2026. The Personal Data Protection Centre has launched an electronic portal for accreditation, licences and permits. The CMS note adds that the regulations require written consent for sensitive data.
That creates an awkward sequence. A national biometric system is going live three weeks before the data-protection regime it must satisfy becomes enforceable. Secondary commentary also notes that the law exempts personal data held by national security bodies. If facial data flows to security-linked systems, the protections that apply to a private operator may not apply to the state, and no public document says which regime governs this dataset.
A proportionate alternative
A pro-innovation reading does not require opposing digital identity. Verified remote onboarding is useful and, built well, can reduce fraud. The test is whether the design is narrow, transparent and accountable. Egypt can meet it by doing five things before the 31 October deadline:
- Publish the fraud evidence. Say how many unauthorized registrations occurred and where they originated, so the measure can be tested against the problem.
- Prefer match-and-discard. The system can confirm a live face against the civil registry and return a yes or no, without operators storing templates.
- Set retention and access rules in writing. These should cover who can query the data, for what purpose, under what judicial or regulatory authorisation, and for how long it is kept.
- Keep the sensitive-data regime in force. The Personal Data Protection Centre, not an agency with enforcement interests, should supervise the system, and no purpose should be exempt by default.
- Offer a non-biometric route. Document-based verification should remain available, particularly for people who fail face matching or object to it.
None of this slows legitimate innovation. Clear rules are what let operators, fintechs and signature providers build services that citizens will trust enough to use.
The takeaway
SIM fraud is real, and a remote identity check is a reasonable tool against it. A programme that collects irreversible biometric identifiers at national scale, with undisclosed retention, undefined access and no published evidence of necessity, is not proportionate. Egypt's own data law gives it the vocabulary to fix that. The first test comes on 31 October.