Egypt Egypt digital ID Takamol surveillance

Egypt's NFC Passport Sandbox Is the Right Way to Build Digital ID, but Only If Its Data Rules Are Ready by October

Egypt's FRA sandbox tests passport-chip onboarding for foreign investors while telecom biometrics draw a rights-group backlash and data-protection enforcement nears.

Egypt's Digital ID Build-Out People of Internet Research · Egypt 4.3M Egyptian identities validated VLens's reported total since Decre… ~49 Sandbox applications, year one Only 2 reached live testing by mid… 19 Rights groups opposing telecom biometrics Joint statement of August 24, 2026… peopleofinternet.com
Egypt's Digital ID Build-Out People of Internet Research · Egypt 4.3M Egyptian identities valid… ~49 Sandbox applications, ye… 19 Rights groups opposing telecom… peopleofinternet.com

Key Takeaways

On September 7, 2026, EFG Holding received preliminary approval from Egypt's Financial Regulatory Authority (FRA) to test an NFC e-passport verification platform built with VLens. Foreign nationals could open EFG Hermes ONE trading accounts remotely, using the encrypted biographical and biometric data stored on their passport chips. According to ID Tech, it is the second NFC passport project in the sandbox, after Lumin Soft moved to live testing in August.

This is a good model for identity infrastructure. But it lands in a country where other identity projects are moving faster and with less scrutiny.

The case for the state's approach

The strongest argument for Egypt's push is practical. Paper-based onboarding shuts out foreign investors and expatriates, and photo-of-a-document checks are easy to forge. Identity fraud is a real harm. Egypt's telecom regulator says it received around 23,000 complaints covering nearly 700,000 mobile lines registered to people who did not know about them, as Biometric Update and other outlets report. In one case a student was sentenced to 25 years in a drug case involving a line registered in his name. A regulator facing that record has a legitimate reason to want stronger verification, and the Central Bank of Egypt (CBE) is right that remote onboarding can widen financial inclusion.

Why the sandbox route deserves credit

The FRA sandbox is the most defensible part of the stack. The FRA said in its August 17 announcement that it received about 49 applications in the first year, granted 7 preliminary approvals and moved 2 to live testing. That is a filter, not a rubber stamp.

The technology itself is also relatively privacy-respecting. The Daily News Egypt report on the Lumin Soft and Azimut project says it verifies electronic passports to the standards of the International Civil Aviation Organization's Public Key Directory (PKD). The chip is signed by the issuing state, so the check is cryptographic rather than a guess from a photo. The Lumin Soft live test was granted for an initial three months, with an extension depending on compliance and committee approval.

The scope is also narrow. It covers foreign nationals opening non-banking financial accounts, not a national population. That is proportionate: a bounded test, a defined regulator, a time limit and a stated purpose.

The contrast: biometrics without a demonstrated need

The telecom track looks different. The National Telecommunications Regulatory Authority (NTRA) launched a biometric verification framework for remote telecom services, connected to the Ministry of Interior's civil status records. On August 24, 2026, a coalition of 19 organizations, including Access Now, EIPR and the Cairo Institute for Human Rights Studies, called for an end to requiring telecom users to provide biometric data. They said NTRA had not disclosed how many unauthorized registrations it had confirmed, or where in the process the failures occurred. Without that finding, they argued, there is no basis for concluding that biometric matching would fix the problem.

That critique is hard to dismiss. As Biometric Update notes, a face match at enrolment does not stop a legitimate holder from later handing over an activated SIM. The coalition also flagged that the operators whose systems failed would be the ones collecting the biometrics. A control aimed at one failure point should be justified by evidence of where the failure occurred.

Meanwhile the CBE approved rules on August 23 for a Digital Financial Identity platform for eKYC. Daily News Egypt quotes Governor Hassan Abdalla saying they cover governance, roles, technical requirements and data-protection and cybersecurity controls. Each piece is defensible alone. Together they create shared identity rails across banking, telecoms and capital markets, and the risk is function creep: a database built to fight SIM fraud is later used for something else.

Where data-protection law comes in

The safeguard is Egypt's Personal Data Protection Law, Law No. 151 of 2020. It defines biometric and financial data as sensitive personal data. It requires explicit consent or a legal basis for collection, and it says data may not be retained longer than the purpose needs. Its Article 6 gives addressees one year from the issuance of the Executive Regulations to comply, and the grace period ends on October 31, 2026.

The law also has large carve-outs. Article 3 excludes data held by national security authorities, and data held by the CBE and the entities it supervises (with exceptions for money transfer and currency exchange companies) as long as CBE rules on personal data are followed. So the banking identity layer answers mainly to the central bank, and the security-agency layer answers to no data-protection regulator at all. The gap between the PDPL's principles and where the biggest identity databases sit is the real policy problem.

What proportionate policy looks like

The pro-innovation position is not to oppose digital identity. It is to insist that each deployment meet the standard the FRA sandbox already sets:

VLens says it has validated 4.3 million Egyptian identities and lodged more than 550,000 e-signed contracts in the FRA's central repository. Those are the scale numbers that make the data-governance question urgent. The NFC passport pilot shows Egypt can build identity tools with limits, and October 31 will show whether the rest of the stack accepts the same ones.

Sources & Citations

  1. FRA: first-year sandbox achievements
  2. Egypt Law No. 151 of 2020 (Personal Data Protection Law), English text
  3. ID Tech: Egypt sandbox approval for NFC passport checks
  4. Daily News Egypt: FRA begins live testing
  5. Daily News Egypt: CBE eKYC regulations
  6. CIHRS joint statement on telecom biometrics
  7. Biometric Update: Egypt expands biometric SIM registration