On August 23, 2026, the Central Bank of Egypt (CBE) issued a circular to banks setting rules for a CBE-approved Digital Financial Identity (DFI) system, run through the Haweya platform. According to Baker McKenzie's summary, each retail customer gets one unique digital identity used for eKYC and electronic authentication across banks. Haweya must support liveness detection and reading of national ID documents, and it must keep its records inside Egypt. Banks stay primarily responsible for AML/CFT customer identification, must align their cybersecurity and fraud frameworks with the rules, and need CBE authorisation before launch. (We found no source connecting the circular to Takamol, so this analysis does not assume any such link.)
The case for the system
The strongest argument for Haweya is practical. Remote onboarding with liveness checks is harder to spoof than a photocopied ID at a branch counter. A single verified identity means a customer is not re-verified, and re-exposed, at every bank. Data localisation keeps the records under Egyptian jurisdiction. Governor Hassan Abdalla described the platform as "a transformative milestone in expanding citizens' access to digital banking services." The inclusion stakes are real: Biometric Update reports that financial inclusion stood at 79 percent in June 2026, and that the Haweya initiative launched in 2025 to serve about 37 banks. Baker McKenzie also notes that the circular fills a regulatory gap that digital banks needed closed before they could operate.
This is the kind of infrastructure a pro-innovation publication should welcome. Banks get a shared utility instead of 37 separate biometric stacks. Customers avoid branch visits. Regulators get a common standard for penetration testing and 24/7 monitoring, which Baker McKenzie says the rules require of Haweya.
Where the design creates risk
The worry is not that eKYC exists. It is that a single, central, biometric-backed identity is a high-value asset, and the legal perimeter around it is unusually loose.
Egypt's Personal Data Protection Law, Law No. 151 of 2020, defines biometric and financial data as "sensitive personal data" and requires explicit consent for processing. But Article 3 of the issuing law lists exclusions. Item 6 exempts "personal data which is held by the Central Bank of Egypt and entities subject to its control and supervision" (money transfer and currency exchange companies excepted), provided that the CBE's own rules on handling personal data are observed. Item 5 exempts data held by national security authorities, and lets the Personal Data Protection Center instruct controllers to modify, delete, hide or make available data on their request.
Taken together, the effect is that the regulator writing the Haweya rules is also the reference standard for how Haweya's data is handled. Whether the Personal Data Protection Center can audit it independently is, on the text, doubtful. The CBE circular does cover data protection and cybersecurity controls, and the CBE has real supervisory capacity. But a sector regulator focused on financial stability and AML is not a privacy authority, and its incentives point toward more verification, longer retention and easier access for investigators.
The timing compounds this. The executive regulations were issued as Decree No. 816 of 2025, which gives the Center powers over licensing, inspections and cross-border transfer approvals. Under Article 6 of the issuing law, addressees have one year from the regulations' issuance to comply. So the general regime is only now reaching full application, and the Center has little enforcement track record to point to. Haweya's rules arrive first.
What proportionate safeguards look like
None of this requires scrapping the system. It requires closing the gaps that the exemption leaves open:
- Publish the CBE's personal-data rules for Haweya. Article 3(6) conditions the exemption on the CBE's rules being observed, so those rules should be public and testable.
- Independent audit. Annual third-party security and privacy audits of Haweya, with summaries published, would substitute for the oversight the exemption removes.
- Purpose limitation and retention caps. Biometric templates should be used only for authentication and not repurposed. Retention should be tied to the account relationship, as Law 151's own Article 3 principles of purpose and necessity already require.
- A written access protocol. Requests from national security bodies should be logged, narrow and reviewable, with aggregate statistics published.
- Breach notification to the Center. Even if the CBE is the primary supervisor, the Center should be told when Haweya or a bank leaks identity data.
Minimising what is centralised also matters. A platform that returns a yes/no match to banks, rather than handing over raw face templates and ID images, gives fraud teams what they need while shrinking the prize for attackers and the surface for misuse.
The bottom line
Haweya is a defensible answer to real problems in onboarding and fraud, and the localisation and bank-liability provisions are sensible. The concern is institutional: identity infrastructure with biometric matching is being stood up inside a sector the data protection statute largely excludes, just as the general enforcement regime is starting up. Egypt can keep the innovation and add the accountability by publishing the rules, auditing the platform and limiting what is kept and who can ask for it. Without that, the safeguard for Egyptians' faces and identity records is the regulator's own restraint.