South Africa's mobile operators began doing something on July 1, 2026 that RICA has required in theory since 2002 but never delivered in practice: checking a new SIM registration against the government's actual population register, in real time, before activating the line. The change is procedural rather than legislative — no new statute took effect that day — but it marks the first time the gap between what RICA demands and what carriers actually verify has meaningfully narrowed.
What changed on July 1
The enforcement push follows a March 26, 2026 meeting convened by Justice and Constitutional Development Minister Mmamoloko Kubayi, who told operators that improperly registered SIMs had become the connective tissue for "banking fraud, cash-in-transit heists, extortion, contract killings, and kidnappings" (Department of Justice statement). Non-compliance under RICA already carries penalties of up to R5 million or ten years' imprisonment — the problem was never the law's teeth, but that millions of SIMs were registered against fabricated or stolen identities with no real-time cross-check against Home Affairs to catch it.
The Association of Comms & Technology (ACT), representing Vodacom, MTN, Telkom, Cell C, Rain and Liquid Intelligent Technologies, negotiated an interim industry framework with government that layers real-time Home Affairs verification, tighter distribution-channel oversight, and closer law-enforcement cooperation onto existing RICA processes (TechCentral). The Competition Commission cleared the six-operator agreement as unlikely to raise coordination concerns, and it takes effect as a voluntary industry safeguard while Parliament weighs formal amendments to RICA section 40.
The case operators are making
The fraud numbers are the strongest argument for tightening the system, and they deserve to be stated plainly before any pushback. Telecoms-enabled fraud costs South Africa more than R5.3 billion a year, and close to 60% of mobile banking fraud is tied directly to SIM-swap attacks, according to the Communications Risk Information Centre's 2025 sector report (ITWeb). SIM swaps hijack the one-time-password channel that banks use for two-factor authentication, turning a stolen phone number into a stolen bank account. Roughly 80% of the SIMs issued annually reportedly move through informal channels vulnerable to bulk fraudulent registration. A regulator that can catch a fake ID at the point of activation, rather than after a kidnapping ring has already used the number, is doing exactly the kind of proportionate, evidence-driven intervention this publication has generally favored — real-time database matching is a narrower, more targeted tool than blanket data retention mandates or communications surveillance.
Where the line should hold: biometrics
The part still pending is more consequential. ICASA has asked the Department of Justice for either direct control of the RICA database or, failing that, a mandatory biometric layer — a live selfie matched against the Home Affairs photo on file — added to every new activation and swap (BiometricUpdate). That proposal is not law, and it shouldn't become law without more scrutiny than it has so far received.
Biometric information is not ordinary personal data under South African law. POPIA's Section 26 classifies it as "special personal information" alongside health, religious, and political data, subject to a general prohibition on processing unless a specific statutory exception applies (POPIA Section 26). That classification exists for a reason: unlike a password or even an ID number, a face template cannot be reissued if it leaks, and once telecom operators are routinely capturing and matching live facial images against a state population register, the infrastructure for that matching does not stay confined to fraud prevention. It becomes an off-the-shelf capability for whatever the next emergency happens to be.
The operators' own framework, notably, stops short of mandating biometrics — it discusses "wider use of biometric authentication" as one option among several, alongside secure SIM packaging and channel audits. That restraint from industry, which has the clearest commercial incentive to solve fraud fast, is worth noting. It suggests even the parties who'd benefit most from a biometric mandate see real-time database matching as sufficient for now, and biometrics as a bigger step that deserves its own legislative debate rather than a rider on emergency enforcement.
What should happen next
Parliament's draft RICA amendment, due for stakeholder engagement following the June 2026 deadline set by Minister Kubayi's office, is the right venue for the biometric question — not an ICASA administrative request or an industry framework agreement. If lawmakers do proceed, the bill should specify data retention limits, a right to non-biometric alternatives for people without matchable Home Affairs photos, and an independent audit mandate, given POPIA's Information Regulator has not yet weighed in publicly on a proposal that would make telecom operators custodians of biometric identity data at national scale. Real-time population-register checks close a genuine fraud loophole with a tool proportionate to the problem. A live-selfie mandate is a different order of intervention, and it should get a different order of debate.