Egypt Egypt digital ID Takamol surveillance

Egypt's Haweya ID Rules Are a Sound Fraud Fix, but the Data Law Carves Out the Central Bank's Own Sector

The CBE's Haweya eKYC circular could cut onboarding friction, but Law 151's Article 3(6) exemption leaves biometric safeguards to the regulator running the system.

Egypt's Haweya Digital ID at a Glance People of Internet Research · Egypt ~37 Banks targeted by Haweya Initiative launched in 2025 to ser… 79% Financial inclusion, June 2026 The inclusion rate the platform ai… 1 year Compliance window after regulations Law 151 Article 6 gives addressees… peopleofinternet.com
Egypt's Haweya Digital ID at a Glance People of Internet Research · Egypt ~37 Banks targeted by Haweya 79% Financial inclusion, June … 1 year Compliance window after regulations peopleofinternet.com

Key Takeaways

On August 23, 2026, the Central Bank of Egypt (CBE) issued a circular to banks setting rules for a CBE-approved Digital Financial Identity (DFI) system, run through the Haweya platform. According to Baker McKenzie's summary, each retail customer gets one unique digital identity used for eKYC and electronic authentication across banks. Haweya must support liveness detection and reading of national ID documents, and it must keep its records inside Egypt. Banks stay primarily responsible for AML/CFT customer identification, must align their cybersecurity and fraud frameworks with the rules, and need CBE authorisation before launch. (We found no source connecting the circular to Takamol, so this analysis does not assume any such link.)

The case for the system

The strongest argument for Haweya is practical. Remote onboarding with liveness checks is harder to spoof than a photocopied ID at a branch counter. A single verified identity means a customer is not re-verified, and re-exposed, at every bank. Data localisation keeps the records under Egyptian jurisdiction. Governor Hassan Abdalla described the platform as "a transformative milestone in expanding citizens' access to digital banking services." The inclusion stakes are real: Biometric Update reports that financial inclusion stood at 79 percent in June 2026, and that the Haweya initiative launched in 2025 to serve about 37 banks. Baker McKenzie also notes that the circular fills a regulatory gap that digital banks needed closed before they could operate.

This is the kind of infrastructure a pro-innovation publication should welcome. Banks get a shared utility instead of 37 separate biometric stacks. Customers avoid branch visits. Regulators get a common standard for penetration testing and 24/7 monitoring, which Baker McKenzie says the rules require of Haweya.

Where the design creates risk

The worry is not that eKYC exists. It is that a single, central, biometric-backed identity is a high-value asset, and the legal perimeter around it is unusually loose.

Egypt's Personal Data Protection Law, Law No. 151 of 2020, defines biometric and financial data as "sensitive personal data" and requires explicit consent for processing. But Article 3 of the issuing law lists exclusions. Item 6 exempts "personal data which is held by the Central Bank of Egypt and entities subject to its control and supervision" (money transfer and currency exchange companies excepted), provided that the CBE's own rules on handling personal data are observed. Item 5 exempts data held by national security authorities, and lets the Personal Data Protection Center instruct controllers to modify, delete, hide or make available data on their request.

Taken together, the effect is that the regulator writing the Haweya rules is also the reference standard for how Haweya's data is handled. Whether the Personal Data Protection Center can audit it independently is, on the text, doubtful. The CBE circular does cover data protection and cybersecurity controls, and the CBE has real supervisory capacity. But a sector regulator focused on financial stability and AML is not a privacy authority, and its incentives point toward more verification, longer retention and easier access for investigators.

The timing compounds this. The executive regulations were issued as Decree No. 816 of 2025, which gives the Center powers over licensing, inspections and cross-border transfer approvals. Under Article 6 of the issuing law, addressees have one year from the regulations' issuance to comply. So the general regime is only now reaching full application, and the Center has little enforcement track record to point to. Haweya's rules arrive first.

What proportionate safeguards look like

None of this requires scrapping the system. It requires closing the gaps that the exemption leaves open:

Minimising what is centralised also matters. A platform that returns a yes/no match to banks, rather than handing over raw face templates and ID images, gives fraud teams what they need while shrinking the prize for attackers and the surface for misuse.

The bottom line

Haweya is a defensible answer to real problems in onboarding and fraud, and the localisation and bank-liability provisions are sensible. The concern is institutional: identity infrastructure with biometric matching is being stood up inside a sector the data protection statute largely excludes, just as the general enforcement regime is starting up. Egypt can keep the innovation and add the accountability by publishing the rules, auditing the platform and limiting what is kept and who can ask for it. Without that, the safeguard for Egyptians' faces and identity records is the regulator's own restraint.

Sources & Citations

  1. Law No. 151 of 2020 (Personal Data Protection Law), text
  2. CBE: Regulations for the Digital Financial Identity Platform (eKYC)
  3. Baker McKenzie: Egypt's new DFI system rules for eKYC
  4. Zawya: CBE approves eKYC regulations
  5. Biometric Update: Egypt approves banking eKYC framework
  6. Legal 500: Executive Regulations of Egypt's PDPL