A mandate becomes a menu
When South Korea's revised mobile phone activation rules took effect on July 6, 2026, the headline change was subtle but consequential: facial recognition, originally positioned as the backbone of a new anti-fraud system, became one option among three. Customers registering a new SIM can now verify their identity by live facial scan matched against a government ID, through the Ministry of the Interior and Safety's mobile ID app, or with a same-day certified copy of their resident registration (Korea Times). Anyone who declines the face scan, or fails it — capped at three attempts — is routed to a non-biometric fallback rather than being turned away (Korea Times).
That this is being reported as a concession tells you how the original plan was framed. The Ministry of Science and ICT had piloted facial matching through carriers and MVNOs beginning in late 2025 as a way to stop "daepo phones" — SIMs registered on stolen or fabricated IDs and resold to voice-phishing operators. The government's own figures put 2026 voice-phishing losses at roughly ₩1 trillion, and it argued a live face-to-ID match was the only verification strong enough to close the loophole (Korea.kr).
The case regulators actually made
That case deserves to be stated fairly. Voice phishing in South Korea is not a marginal nuisance; it is a sustained, organized financial-crime problem that disproportionately hits the elderly, and burner SIMs are a genuine enabler of it. A biometric check that only compares a live image against an ID photo, discards the image immediately, and stores nothing but a yes/no match result — as the Ministry describes its system — is a materially narrower design than a persistent facial-recognition database. Reasonable regulators can support fraud-prevention biometrics of that shape.
But two of Korea's most relevant institutions concluded the design still fell short. The Personal Information Protection Commission, at its 10th full commission meeting on May 27, 2026, found that the Telecommunications Business Act and related statutes "do not clearly permit using facial information as a means of identity verification for mobile phone activation," and that without a guaranteed non-biometric alternative, customers had no real ability to refuse (fnnews). The PIPC gave the Ministry two options: build a genuine non-biometric alternative, or first pass legislation authorizing the biometric use. The National Human Rights Commission of Korea separately urged the government to reconsider making facial verification mandatory across the board (NHRCK).
Optional now, legal later
The Ministry's response was to keep the July 6 date and make the fallback real, rather than delay for legislation. That is the right sequencing failure to flag. The government is not disputing that it currently lacks clear statutory authority to process facial biometrics for this purpose — it has committed to closing that gap by amending the Enforcement Decree of the Telecommunications Business Act by October 2026 (Korea JoongAng Daily). In the interval, a nationwide biometric verification system for a state-mandated service is running on the strength of a ministry decision, not a statute Parliament passed.
Making the scan optional is a genuine improvement, and it is the outcome a functioning oversight system should produce: an independent privacy regulator flags a legal-basis gap, a human rights body raises fundamental-rights concerns, and the implementing ministry adjusts the rollout rather than steamrolling ahead. That is worth crediting. Voice-phishing fraud is real, KISA's security testing reportedly found no major vulnerabilities in the matching pipeline, and immediate-deletion-of-the-raw-image is a defensible privacy-by-design choice for a fraud check (Korea Times).
What should not be normalized is the sequencing: legalize first, deploy second. "Optional" only constrains the state's own conduct for as long as the ministry chooses to keep the fallback open — a discretionary policy, not a statutory right, and one that a subsequent enforcement-decree amendment could narrow just as easily as it could formalize. If the October amendment ships with the same fallback options as July's implementation and Parliament, not the ministry, provides the eventual legal basis, this becomes a reasonable case study in regulatory correction. If the codification instead ratifies facial recognition as the default and quietly narrows the alternatives regulators fought for, the "optional" period will have been a pilot phase for a mandate, run on borrowed legal authority. Korea's own privacy watchdog said as much in May. The right test for October is whether the eventual statute enshrines the fallback rights the PIPC demanded — or merely legalizes what the Ministry had already built.