A Wrongful Sentence Becomes a Regulatory Trigger
A university student in Sharqia governorate was sentenced to 25 years in prison in a drug-trafficking case built on a mobile line registered in his name — a line, his family says, he never activated or controlled. The case, reported by Biometric Update, went viral and prompted thousands of Egyptians to check their own records through the National Telecom Regulatory Authority's My NTRA app. Many found lines registered in their names that they had never requested.
NTRA's own account of the fallout is blunt. In an Aug. 7 statement, the regulator acknowledged "reports of mobile phone lines registered under citizens' names without their knowledge" and said it was "working to enhance user identity verification methods, including biometric verification systems, to improve data accuracy and reinforce the security of telecom services" (NTRA press releases). Three days later, the authority went further: it referred all four national operators — Vodafone, Orange, Etisalat by e&, and We — to the Public Prosecution over registration violations, froze bulk line sales, ordered SMS re-verification of existing subscribers, and directed operators to "expedite the provision of biometric verification mechanisms for line possessors via their electronic applications" (NTRA, Aug. 10; Daily News Egypt). The rollout, to be delivered through operator apps within a month, will require a live facial scan matched against national ID photos before any new SIM activates.
The Case for Moving Fast
The strongest argument for NTRA's speed is that the underlying harm is severe and ongoing. A wrongful multi-year prison sentence is not an abstract compliance failure — it is a person's liberty. NTRA says it fielded roughly 4,000 complaints from citizens who discovered lines registered in their names without consent (Egyptian Streets), which suggests the fraud was systemic rather than isolated, likely involving insiders or lax agent-level checks at retail points rather than a handful of bad actors. Regulators facing a documented, criminal-justice-grade failure mode have a legitimate interest in acting before the next wrongful conviction rather than after a lengthy rulemaking process. Referring all four operators to prosecution, rather than singling one out, also signals the problem is structural across the industry, not a single company's negligence — a fair reading given how uniformly the complaints landed.
Why the Fix Doesn't Match the Failure
But biometric verification targets the wrong link in the chain. The student's family's account — and the pattern across the roughly 4,000 complaints — points to registrations completed by someone other than the named ID holder, whether through insider fraud at operator kiosks, forged documents, or ID misuse by an acquaintance. Egypt's own National Human Rights Commission raised the obvious objection: face-matching only confirms that the person standing in front of the camera resembles the ID photo. It does nothing to stop a legitimate ID holder from being coerced or paid to register a line for someone else, and nothing to stop an operator employee from bypassing the check altogether, which is precisely the insider-abuse pattern the current prosecution referral implies. South Korea's National Human Rights Commission raised an identical concern about its own facial-verification SIM regime, for the same reason (Biometric Update).
A Real Legal Gap NTRA Isn't Closing
Egypt does have a data protection statute — Law No. 151 of 2020 — that requires explicit written consent and a license before biometric data can be collected. But the law exempts national security bodies from its scope entirely, and its enforcement body, the Personal Data Protection Center, has a board appointed by the minister that must include military and intelligence representatives (Access Now). NTRA has said biometric templates captured for SIM verification will not be stored by or accessible to operator staff, but it has not published a retention schedule, a named custodian, or an independent audit mechanism for a dataset that will eventually cover most of Egypt's mobile subscriber base. That is the actual privacy chaos advocates are flagging: not that verification exists, but that it is being deployed inside a legal framework with a security-agency carve-out and no independent regulator with teeth.
The Better Fix Was Already Available
The more proportionate response was sitting in NTRA's own toolkit before this case broke: enforce the existing rule that operators verify the actual presence and consent of the ID holder at the point of sale, audit agent-level registration logs for the accounts responsible for the roughly 4,000 flagged lines, and publish the results of the Public Prosecution referral once it concludes. NTRA's Aug. 7 statement already conceded the more important legal point — that a line registered in someone's name doesn't by itself establish criminal liability — which is a due-process fix a prosecutor and defense counsel can act on immediately, unlike a biometric rollout that takes a month to reach every retail point. Layering nationwide facial recognition onto an unreformed enforcement and data-protection regime doesn't close the fraud gap that produced a 25-year wrongful sentence; it just adds a new, harder-to-revoke category of data to a system that has not yet shown it can secure the data it already holds.
Egypt should finish the accountability process against the four operators, publish what the prosecution referral finds about how registrations were actually falsified, and only then decide whether biometric capture is the right tool — with a retention limit, an independent auditor, and a data protection authority that isn't co-chaired by the security services it is meant to check.