Egypt Egypt anti-cybercrime law social media

Egypt's SIM-Fraud Crackdown Enforces a Data Law Carriers Had Ignored Since 2020

NTRA's prosecution referral of all four Egyptian carriers enforces existing consent law, but its biometric fix may not stop the resale problem that caused the crisis.

Egypt's SIM Registration Crackdown People of Internet Research · Egypt 4 of 4 National operators referred NTRA referred every licensed Egypt… 25 years Prison sentence in trigger case Sharqia student sentenced in absen… Since 2020 Data protection law in force Law 151/2020 already required expl… peopleofinternet.com
Egypt's SIM Registration Crackdown People of Internet Research · Egypt 4 of 4 National operators referr… 25 years Prison sentence in trigger case Since 2020 Data protection law in force peopleofinternet.com

Key Takeaways

The Referral

On August 10, 2026, Egypt's National Telecommunications Regulatory Authority (NTRA) referred all four of the country's mobile network operators — Vodafone Egypt, Orange Egypt, e& (formerly Etisalat), and WE — to the Public Prosecution over the registration of mobile lines under citizens' personal data without their knowledge or consent. Alongside the referral, NTRA ordered an immediate suspension of bulk and corporate line sales and activations for both private and government entities, launched a mandatory SMS campaign requiring existing line holders to visit branches and re-register under their real identities or face permanent cancellation, and announced an accelerated rollout of biometric identity verification through operator apps (NTRA press release).

A Line That Became a Life Sentence

The trigger was concrete, not abstract. A university student in Sharqia, identified in Egyptian press as Amr Emara, was sentenced in absentia to 25 years in prison on drug-trafficking charges after a mobile line registered under his national ID surfaced in a narcotics investigation. He had reportedly let a friend's sister use his identity to activate the line for unrelated services; it was later passed to someone else without his knowledge, and that someone used it in a crime he had no part in (Biometric Update). The case spread on Egyptian social media, and complaints about unfamiliar SIM lines registered to real people's names followed. That is the actual stake here: not a theoretical privacy harm, but a functioning legal system building a criminal case on top of a stranger's misappropriated identity credential.

The Case for the Crackdown

Steelmanned, NTRA's response is not regulatory overreach — it is the state finally enforcing law that has been on the books for years. Egypt's Personal Data Protection Law No. 151 of 2020 requires a data controller to obtain a subject's explicit consent before collecting or processing their personal data, and provides for penalties ranging from fines to imprisonment for violations (Law 151/2020 overview). Telecom operators are also subject to identity-verification and data-retention obligations under the 2018 Cybercrime Law. A line registered to someone's national ID without their consent is, on its face, exactly the conduct Law 151/2020 was written to prevent — and operators had five years to build compliant onboarding before a 25-year sentence made the failure visible.

NTRA's administrative response has also been more measured than the "suspend everything" framing suggests. Spokesperson Mohamed Ibrahim clarified that citizens can obtain a full list of lines registered under their national ID by presenting it at any operator branch, sign a non-possession form to immediately suspend an unrecognized line, and — critically — that discovering an unauthorized line does not automatically expose the citizen to criminal liability; NTRA has drawn a line between operators' administrative violations and Public Prosecution's criminal jurisdiction (Egypt Independent). That distinction matters: it aims the enforcement at the companies that failed KYC checks, not at citizens caught in their paperwork.

Where the Fix Overshoots the Problem

The weak point is the biometric rollout. NTRA is accelerating facial verification — a selfie matched against the national civil registry — through operator apps, expanding a pilot program NTRA chairman Mohamed Shamroukh had flagged only in 2025 (Biometric Update). But biometric matching verifies who registers a line, not who ultimately possesses it — and the Sharqia case shows the fraud happened after a legitimate registration, when the line was handed to someone else. Facial verification at signup does nothing to stop that transfer. Egypt risks building a permanent, civil-registry-linked facial recognition dataset covering tens of millions of subscribers, rolled out under emergency press-release timelines rather than the kind of statutory guardrails — retention limits, purpose limitation, independent oversight — that a biometric identity layer of this scale should carry under Law 151/2020's own consent and proportionality principles.

The open-ended freeze on bulk and corporate line sales carries a similar risk. It is a defensible emergency brake given documented abuse, but NTRA has announced no timeline or published criteria for lifting it, leaving legitimate businesses in indefinite limbo while operators fix onboarding systems the businesses had no part in breaking.

The Proportionate Version

Enforcing Law 151/2020 against operators who failed basic consent verification is not the part of this story that should worry pro-innovation observers — it is overdue. What deserves scrutiny is the second track: a biometric national-ID layer bolted onto telecom onboarding at speed, with no public commitment yet to retention limits or independent audit, addressing registration fraud while leaving the resale loophole that actually produced a 25-year sentence untouched. Egypt can hold operators accountable for the law they already had without normalizing an emergency-built biometric database as the permanent fix.

Sources & Citations

  1. NTRA official press release
  2. Law No. 151 of 2020 (Personal Data Protection Law)
  3. Daily News Egypt: NTRA refers four mobile operators to prosecution
  4. Biometric Update: Egypt expands biometric SIM registration after identity misuse case
  5. Egypt Independent: Four mobile operators referred to prosecution