A two-decade-old law gets teeth
Since 30 September 2005, South Africa's Regulation of Interception of Communications and Provision of Communication-Related Information Act (RICA) has required every SIM card to be registered to a real, verified person. For most of that time, enforcement was patchy. That changed on 1 July 2026, when penalties of up to R5 million or ten years' imprisonment for non-compliance took effect — a deadline set after Justice Minister Mmamoloko Kubayi convened an "urgent meeting on RICA and SIM Card Registration Challenges" on 26 March 2026 under the Justice, Crime Prevention and Security Cluster (Department of Justice statement).
The trigger was crime, not surveillance ambition. Investigators told local media that as many as 80% of the cellphone numbers they encounter in fraud and extortion cases are either unregistered or registered to the wrong person (IOL). Vodacom's own CEO has acknowledged that "people have learnt to game the system," and operators are now discussing a biometrically verified, reusable "digital RICA credential" that would replace paper-based registration entirely (TechCentral).
The steelman: this is a real crime-fighting law with real evidence behind it
Give the government its due. SIM-swap fraud, banking scams, and extortion calls routed through burner numbers are not hypothetical harms — they are the daily reality cited by South African police and by the private investigators quoted above. A verified registry that actually maps numbers to people is a legitimate policing tool used across dozens of jurisdictions, and South Africa's version predates this enforcement push by twenty years; nobody is inventing a new surveillance regime from scratch. Nor is the digital-ID convergence merely opportunistic: Home Affairs Minister Leon Schreiber is already building a national digital identity layer as Initiative 1 of the government's MyMzansi digital public infrastructure roadmap, aiming to give every citizen a single verifiable identity credential usable across banking, government services, and telecoms (MyMzansi roadmap). Linking SIM verification to that same trusted-identity spine, rather than running two disconnected KYC systems, is defensible architecture, not empire-building.
Where the design goes wrong
The problem is not that South Africa wants accurate SIM records. It is that the state has picked the heaviest available instrument — criminal liability up to a decade in prison — to police what is, for the overwhelming majority of the 80% non-compliance figure, an administrative failure: an outdated address on file, a SIM bought years ago under looser rules, a retailer who mis-keyed an ID number. RICA's Section 51 penalty was written for operators and intermediaries who deliberately evade record-keeping duties, not for individual subscribers caught in a legacy backlog. Applying decade-old maximum penalties as a blunt enforcement deadline, rather than phasing in verification with a genuine grace period and a low-friction re-registration path, criminalizes bureaucratic drift.
The deeper concern is what RICA is becoming, not what it was. TechCabal reports that the reform underway would tie SIM registration to "real-time checks against the Department of Home Affairs (DHA) database," explicitly building toward mobile numbers as trusted digital-identity credentials rather than mere communications endpoints (TechCabal). Once a phone number is cryptographically bound to a state identity database and required for banking, messaging, and — per the MyMzansi roadmap — government service access, losing SIM access effectively means losing access to civic and financial life. Researchers at CIPESA have documented this exact failure mode elsewhere on the continent: in Uganda, mandatory digital ID linkage has denied citizens access to social grants, health services, and even land title registration when registries contained errors or excluded people entirely (CIPESA). South Africa is not Uganda — it has stronger courts and a more mature data protection regulator under POPIA — but the architectural risk is identical: the more services get gated behind one verified identity token, the more catastrophic a wrongful mismatch, database breach, or administrative error becomes for the person on the receiving end.
The fix is proportionality, not abandonment
None of this argues against SIM verification as a crime tool. It argues against reaching for maximum criminal penalties as the primary enforcement lever for what operators themselves say is fixable through better technology — biometric re-verification, real-time DHA matching, and reusable credentials, all of which TechCentral notes could cut fraud and onboarding costs for operators directly, without threatening subscribers with prison time. Government should publish clear, low-friction remediation timelines before penalties bite, ring-fence RICA data from unrelated state uses beyond its stated law-enforcement purpose, and ensure the Information Regulator — not just Justice and Home Affairs — signs off before RICA fully merges into the MyMzansi identity layer. A verified SIM registry that actually reduces fraud is worth having. A criminal-penalty regime that punishes administrative backlog while quietly building the infrastructure for a single mandatory identity token is a different, riskier thing, and South Africa has not yet drawn that line clearly enough.