South Africa's Regulation of Interception of Communications Act (RICA) has required identity registration for every SIM card since 2011. What changed on July 1, 2026 is enforcement with teeth: mobile network operators must now check every new SIM registration in real time against the Department of Home Affairs population register, rather than accepting a photocopied ID document that no one verifies against a live database.
The problem this actually solves
The trigger wasn't abstract. At a March 26, 2026 meeting convened by Justice and Constitutional Development Minister Mmamoloko Kubayi, government and telecom operators confronted what Kubayi's own ministry described as systemic weaknesses in SIM registration that have facilitated fraud, extortion and kidnappings (Department of Justice statement). The core exploit was mundane: bulk registration of SIM cards for resale, frequently using false or mismatched identity information, leaving large numbers of active lines that cannot be reliably traced back to a real person (Biometric Update).
That matters for two distinct reasons. First, SIM-linked fraud — swap scams, banking-app takeovers, impersonation — has grown steadily since 2019 as digital banking scaled faster than the verification infrastructure underneath it, according to the Association of Comms and Technology (ACT), the industry body representing South Africa's major operators (TechCabal). Second, and more consequentially for public safety, unregistered or falsely registered SIMs break the evidentiary chain police need to trace suspects. As ICT commentator Adrian Schofield put it in comments to ITWeb: when police can't trace communications back to criminals, the legal provisions for court-ordered interception become pointless (ITWeb, June 29, 2026, Telecoms industry to tighten SIM card verification).
Steelmanning the case for real-time verification
The strongest argument for this reform is that South Africa already had the legal obligation — RICA has mandated ID collection for fifteen years — without the technical means to enforce it. A paper ID check with no database behind it is registration theater, not registration. Home Affairs Minister Leon Schreiber made the more compelling technical case at the March meeting: the department's identity-verification API is already used successfully by the banking sector for account opening and fraud checks, so extending the same real-time rail to telecoms closes an obvious and long-standing gap rather than building new surveillance infrastructure from scratch (Department of Justice statement). Given penalties of up to R5 million or ten years' imprisonment already exist on the books for non-compliant registration, matching that legal exposure with an actual verification mechanism is a defensible proportionality argument, not overreach.
Where the design still needs scrutiny
The risk is not the goal — traceable SIM ownership is a legitimate, internationally common policy objective — but the architecture. Real-time verification against a national population register means every SIM activation now generates a query against one of the country's most sensitive government databases, run through however many mobile operator retail points and third-party dealers exist nationwide. Under the Protection of Personal Information Act (POPIA), network operators are "responsible parties" obligated to collect only what's needed, secure it, and use it solely for the stated purpose — obligations enforced by South Africa's Information Regulator, an independent body with the power to investigate, audit, and issue administrative fines (popia.co.za, Chapter 3 processing conditions and Chapter 5 regulator powers). Centralizing that many verification calls through a growing number of retail and reseller touchpoints is precisely the kind of expansion the Regulator's minimality principle was written to constrain, yet the ACT framework and government's own statements to date describe none of the audit logging, retention limits, or breach-notification specifics that would let the public verify compliance.
The framework also has a jurisdictional hole. RICA's SIM-card definition covers "an independent, electronically activated device," language that predates eSIMs and arguably doesn't capture them, while Section 40(1)(b) exempts foreign roaming customers from local registration altogether — a loophole through which a South African could obtain a global eSIM from an unlicensed offshore provider outside ICASA's jurisdiction and avoid the verification regime entirely (De Rebus, legal status of eSIMs in South Africa). A verification mandate that hardens physical-SIM retail while leaving a growing eSIM channel unregulated will catch low-level resellers and miss the more sophisticated fraud rings it's aimed at.
What should happen next
The Department of Justice's own timeline calls for a draft legislative amendment to RICA itself, not just the interim ACT-government framework, with stakeholder engagement following the June 2026 drafting deadline (Department of Justice statement). That legislative process is the right venue to fix what enforcement alone cannot: writing eSIMs unambiguously into RICA's scope, closing the roaming exemption, and — critically — publishing data-minimization and audit standards for the Home Affairs verification pipeline before, not after, it scales nationwide. Proportionate regulation means matching the fix to the problem: real-time identity checks address a genuine traceability failure, but only if the register being queried is itself protected as rigorously as the fraud it's meant to stop.