
Executive Summary
In August 2026, the National Telecom Regulatory Authority (NTRA) acknowledged receiving complaints from individuals who discovered that mobile lines had been registered using their personal data without their knowledge. Following examination and inspection, NTRA referred all four mobile network operators to the Public Prosecution. These incidents occurred despite the existing registration rules, which require applicants to appear in person at an authorized point of sale, present the original of a valid national ID card, and sign a contract.
The crisis reveals the ability of entities within the sales, activation, and data management chain to circumvent existing controls. Moreover, published information does not provide evidence to support the claim that the lack of facial or fingerprint verification is the source of the problem.
NTRA has linked efforts to address the crisis to accelerating biometric verification through operators’ applications. This approach would add facial images, digital templates, or fingerprints to a process that already involves identity data, contracts, and transaction records. While live verification may prevent a person from using a stolen ID card image in a specific case, it does not prevent a complicit employee or agent, nor does it restrict accounts with broad authorities, nor does it correct a record that has been wrongly linked to its owner. It also makes access to telecommunications services, or the correction of an institutional error, conditional on providing sensitive data that individuals cannot easily change if it is leaked.
The paper recommends withdrawing any directive that requires users to provide a facial image or fingerprint to register a mobile line, to check or correct lines registered in their name, or to recover access to them. NTRA, mobile operators, and service providers should be prohibited from retaining such data for these purposes. The option to unlock an app using a fingerprint stored locally on the phone may be retained, provided that the data does not leave the device and a passcode or equivalent authentication method is available.
The proposed alternative relies on controlling point‑of‑sale procedures, including the responsible employee’s account and the device used for line registration and activation, recording an indelible record of each transaction, immediately notifying the ID holder, separating group activation authorities, analyzing anomalous patterns, and making the “My Numbers” service available through both in-person and remote channels with dedicated support. This is further complemented by ensuring a notice period and the right to object before line suspension, holding the operator accountable for its agents, compensating those affected, and publishing quarterly reports on erroneous registrations, corrections, and appeals.
First: Unexplained Registration Crisis
On 6 August 2026, NTRA temporarily reactivated the “My Numbers” (Arqami) service via the My NTRA application after its suspension for updates, while concealing parts of the line numbers. It announced that the final version of the service would rely on biometric verification of users’ identities. The service allows individuals to ascertain the mobile lines registered under their national ID number, enabling them to access their data and request rectification of any incorrect registrations.
Requiring biometric verification to access the service means that users will be forced to provide sensitive personal data even when they are simply trying to correct an error made by the mobile operators or one of its agents. The “My Numbers” statement indicates that the authority intends to pursue this approach, but it does not specify the type of biometric data used, the verification mechanism, the reference against which the data will be compared, or how this data will be stored.
The following day, NTRA issued a clarification regarding complaints about lines registered in the names of individuals who did not know of them. The statement of 7 August affirmed that the mere registration of a line in a person’s name does not establish their legal liability “where it is established that the line does not belong to them, or was not in their possession or under their actual control. Legal liability is personal, and acts cannot be attributed to anyone other than their perpetrator. Responsibility is determined in light of the facts, evidence, and the findings of investigations, without prejudice to the competence of investigative and judicial authorities to assess the evidence and determine liability in accordance with the law.”
On 10 August, NTRA announced that it had referred all four mobile network operators to the Public Prosecution following examination and inspection. NTRA also directed mobile operators to accelerate the introduction of biometric verification mechanisms for mobile line holders through the mobile operators’ electronic applications in the coming period. According to NTRA, these mechanisms would enable more secure verification of users’ identities and allow citizens to take the necessary measures regarding any line registered in their name that is not in their possession.
As of the time of writing, the authority had not published the number of cases in which lines were registered without the owners’ knowledge, nor had it broken down these cases by operator or line type, nor had it identified the stage at which the error occurred. It is therefore not possible to determine whether the erroneous registration occurred at the point of sale, through the device or employee account used to register and activate the line, during transactions involving third parties, or as a result of a database error. Without this diagnosis, it is difficult to determine the appropriate intervention. Applying a new blanket measure to millions of subscriptions risks addressing a cause that has not yet been established as the root of the problem.
Second: Flaws in the Registration Process
Biometrics addresses only one part of the registration process, which is verifying that the person present is the ID card holder. However, registration doesn’t end there; it passes through the point of sale, the activation device, and employees’ accounts, and then its data is transferred across several systems and databases. A failure at any of these stages can result in an incorrect registration, even if biometric verification is successfully completed.
The regulations governing the sale of mobile phone SIM cards to individuals require Egyptian customers to visit an authorized retailer, present the original valid national ID card and a color copy of it, sign a contract, and receive a copy of the contract. The regulations also set a maximum of 10 voice lines and 5 data lines per operator. Nevertheless, unauthorized registrations have occurred, indicating that the malfunction may arise despite fulfilling these requirements, whether through the use of another person’s data, the misuse of customer data, or the abuse of employee authorization after the customer has left. This demonstrates the limits of adding biometric verification: it may confirm that the person present is the ID card holder, but it does not prove that they consented to every line registered in their name, or that the verification result was not used in a subsequent transaction.
NTRA rules allow entities and companies to open an account comprising multiple mobile lines, administered by an authorized representative, but require the registration of the actual user for each SIM card and the updating of their data upon any change. These rules show that accurate registration of corporate lines depends not only on verifying the identity of the authorized representative, but also on maintaining an accurate link between each line and its actual user. Accordingly, failing to register the actual user or update their data can result in lines being associated with data that does not reflect the person who actually possesses or uses them.
Third: What Biometric Data Can and Cannot Prevent
Biometric verification systems can operate in different ways. The system may compare a user’s facial image or fingerprint with specific reference data for that individual, such as an image linked to a national ID number. Alternatively, it may search for the closest match within a database containing a large number of individuals.
The second approach is broader in scope and carries greater risks of false matches and of the system being used to identify individuals for other purposes. To date, NTRA has not clarified whether the proposed system will use facial recognition or fingerprints, how the verification process will work, what reference data it will rely on, or where biometric data will be stored.
Biometric verification typically does not rely on the image or fingerprint alone. Instead, the system converts it into digital data representing certain features of the face or finger, known as a “biometric template”. It may also use “liveness detection” to verify that the person in front of the device is physically present, rather than a photograph or recording. This can complicate certain forms of identity impersonation, but it remains dependent on the accuracy of the reference data, the integrity of the device and software, and on safeguards against manipulation or reuse of the verification result.
The ability to prevent certain forms of identity impersonation does not necessarily mean that biometric verification addresses the underlying cause of the crisis in Egypt. If the problem stems from an employee’s abuse of authority, the activation of an additional line after a transaction has been completed, or the alteration of a record within the company’s systems, facial verification will not prevent it. Likewise, relying on inaccurate reference data could result in the rightful holder being rejected or an existing incorrect association being confirmed. Biometrics verifies an individual’s identity at a specific moment. Still, it doesn’t prove their consent to the transaction, nor does it monitor what happens to the data and records thereafter.
NIST guidelines stipulate that biometric data should not be the sole means of verifying a user’s identity, and that a non-biometric alternative should be available, with a preference for performing the verification on the device itself whenever possible. In mobile applications, for example, users can unlock an app using a fingerprint stored on their device without sending the fingerprint data to the telecommunications operator, while retaining a PIN as an alternative. This differs from sending a facial image to the operator’s servers or one of its third-party service providers, which requires biometric data to be collected and processed outside the user’s device.
A facial recognition system does not provide a definitive result by comparing two images alone; rather, it calculates a similarity score between them. The system then sets a threshold for determining whether the two images match. If this threshold is set high, the system becomes more stringent, reducing the chance of incorrectly accepting someone else but increasing the likelihood of rejecting the identity holder. Lowering the threshold reduces rejections of the correct user but increases the chance of accepting a non-matching person. Facial recognition tests show that image quality, lighting, and certain demographic characteristics affect error rates to varying degrees across different systems.
Not all users are equally affected by system errors. Older people or some with disabilities may have difficulty meeting the image-capture requirements, while other users may lack a suitable phone or a stable internet connection, or their facial features may differ from those in an older photo used for comparison.
Pakistan’s experience demonstrates that fingerprint verification does not prevent manipulation; in fact, it may even extend it to the devices and data surrounding the system. After implementing fingerprinting and multi-finger verification for SIM card registration, the Pakistani telecommunications authority announced in March 2026 the seizure of a phone containing 224,201 digital fingerprints, along with tools for spoofing location and manipulating verification devices, as part of a Pakistani crackdown. This does not mean that the same will occur in Egypt, but it shows that fingerprint verification alone is insufficient, and that securing verification devices, monitoring personnel, and protecting fingerprint data remain essential.
This risk is all the more significant because biometric data, unlike passwords, is difficult to replace if compromised or misused. An individual can change a compromised password or deactivate a card, but they cannot change their face or fingerprints. Even when the system retains a digital template instead of the original image or fingerprint, this data remains linked to their identity and can be misused or associated with other records if security is weak. Therefore, collecting biometric data requires a clear necessity and robust safeguards, rather than a general assumption that it will make the system more secure.
Third: Rights, Law, and the Necessity Test
Egypt’s Personal Data Protection Law classifies biometric measurements as sensitive personal data. The Law links processing to a specific and lawful purpose, requiring data accuracy, security, and non-retention after the purpose is fulfilled. It subjects the processing of sensitive personal data to conditions and licensing or authorization depending on the case. The Executive Regulations further provide that processing this category of data must be essential and necessary for the stated purpose and must not result in harm to the data subject.
User consent is insufficient to justify the collection of biometric data if the necessity of such collection is not established from the outset. Less intrusive alternatives, such as tightening registration procedures, immediate notification, and record correction, can address line registration issues without collecting facial images or fingerprints. Consent also loses its meaning if refusing to provide such data would result in being denied the ability to purchase a mobile line, find out which lines are registered in the individual’s name, or correct an error. Even where consent has been obtained, the data should not subsequently be used for purposes other than those for which it was collected.
The implications of mandatory biometric verification extend beyond the collection of sensitive personal data to users’ right to access telecommunications services. Article 57 of the Egyptian Constitution protects the privacy of correspondence and communications. It also requires the State to protect citizens’ right to use public means of communication and prohibits the arbitrary disruption, suspension, or denial of such means.
The User Charter also recognizes users’ rights to privacy, quality of service, and access to complaint mechanisms. Therefore, refusing to provide a facial image or fingerprint, or failing biometric verification, should not result in a person being denied the ability to purchase a mobile line, find out what is registered in their name, or correct an error in their data. A system should not be considered successful simply because the number of recorded violations decreases if some users are unable to access the service or challenge registration errors.
However, it is not possible to assess whether the proposed system complies with these safeguards given the limited information publicly available about it. The Egyptian authorities have not provided detailed information on its legal basis, the conditions governing data processing, the retention period, the entities that will have access to the data, or the procedures for deletion and responding to data breaches. Nor has NTRA published findings or data showing that unauthorized registrations are primarily caused by people using identity documents that do not belong to them, the type of situation that biometric verification may help address.
Conversely, the nature of the registration process points to other vulnerabilities that could be addressed by controlling access authority, devices, logs, and mechanisms for appeals and corrections. Consequently, this policy paper finds no sufficient grounds to justify the collection of facial or fingerprint data.
The United Nations report on privacy in the digital age reinforces this conclusion. It links the use of biometric data to requirements of necessity and proportionality, rather than to an assumption of enhanced security. In the Egyptian context, no data has been published to prove that the lack of biometric verification is the root cause of erroneous SIM card registrations. Meanwhile, less privacy-intrusive measures exist, specifically targeting the registration process, access authority, and system logs. Therefore, official data provides no justification for introducing facial or fingerprint collection into a process whose flaws can be remedied without gathering such sensitive data.
Mexico offers a relevant example of the importance of less intrusive alternatives. It established a mandatory mobile phone user registry that included biometric data, which the Supreme Court subsequently invalidated in 2022. According to the Mexican ruling, the reasons for the decision included the possibility of achieving the security objective through less privacy‑intrusive means and the disproportionality between the registry’s burdens and its benefits.
While the ruling does not legally apply to Egypt, it reinforces the argument advocated by this paper. There is no justification for collecting biometric data when the problem can be addressed through less intrusive measures that directly target the root cause of the flaw.
Fourth: Feasible Non-Biometric Measures
Addressing erroneous registration depends on tightening controls at the stages of registration, activation, and record management, rather than adding a biometric layer that may not target the source of the malfunction. The paper proposes distributing protection measures across these stages while holding mobile operators primarily accountable for the integrity of transactions, as they manage agents and devices and maintain the logs necessary to verify registration validity and correct errors.
On this basis, the paper compares three approaches to addressing erroneous registration. Retaining the current rules does not address the shortcomings revealed by the mobile operators. Mandating biometric verification may complicate some cases of identity impersonation, but it does not prevent manipulation originating from within the company or its databases. It also introduces new risks associated with the collection of facial images or fingerprints and with verification errors.
The proposed package, by contrast, targets the registration stages themselves, from tightening control on point‑of‑sale procedures and access powers to notifying the user and enabling objection and rectification channels, without collecting biometric data.
1. Withdrawing the Biometric Requirement and Publishing the Investigation Findings
The paper recommends that NTRA issue a decision to withdraw any directive that makes facial images or fingerprints a requirement for line registration, contract renewal, use of the “My Numbers” service, denial of line ownership, or account recovery.
The decision should also prohibit mobile operators and their third-party service providers from collecting or retaining such data for these purposes. An exception to this is the use of a fingerprint stored locally on the user’s device to unlock the application, provided that the biometric data does not leave the device and that a non-biometric alternative, such as a PIN, is available.
The paper further recommends that NTRA publish the findings of its investigation into unauthorized registrations in an aggregated format that protects individuals’ data, specifying the number of confirmed cases, the type of line, the channel through which the breach occurred, and the stage at which it occurred.
The report should distinguish between individual and corporate lines, and between identity impersonation, abuse of powers, and records’ errors. Each operator should be required to submit data enabling the tracing of the transaction trail, including authorizations, agents, and amendments related to the disputed cases.
2. Strengthening Oversight of Point-of-Sale Outlets and Access Authorizations
The paper recommends requiring mobile operators to assign a unique identifier to each point of sale, employee, and activation device, so that every transaction can be traced to the person who performed it and to when and where it took place. This information must be recorded in a log that employees cannot modify or erase. Any device suspected of being compromised must be deactivated, and employee access authorizations revoked immediately upon completion of their work. Device location may be used as one of the verification indicators, but should not be relied on as the sole means of verification.
Furthermore, transactions most susceptible to manipulation, such as activating a large number of lines or repeatedly replacing SIM cards, should be subject to additional approval, with a clear separation between the employee initiating the transaction and the one approving it.
Operating companies should periodically review powers and authorizations of accounts and set limits on the number of transactions that can be carried out within a short period. Sales incentives should also not be based solely on the number of lines activated, as this could encourage employees to bypass registration procedures.
The paper recommends using indicators to detect unusual transactions at an early stage, such as repeated use of the same identity data across different points of sale or a sudden increase in activations associated with a particular employee or device. These indicators should not trigger automatic suspension of a line, but rather a human review of the transaction log, contract, and employee data before any action is taken.
3. Immediate User Notification and a Documented Objection Mechanism
The paper recommends requiring mobile operators to notify the data subject immediately upon issuing, replacing, or transferring ownership of a line in their name, through a previously verified channel such as another line or an existing account with the company.
The notification must include basic details about the transaction and a free and expedited method for objection. If no verified channel is available, the user must be provided with a receipt confirming the transaction, with the option to delay the activation of higher-risk operations for a short period to allow for review.
If the data subject objects, any new changes to the record must be suspended and a request with a reference number must be opened, without automatically disconnecting the line from its current user.
The operator is responsible for verifying the validity of the registration through the contract, the employee record, and the consent associated with the transaction. If this cannot be proven, the relevant records must be corrected, and the parties that received the incorrect data must be notified. This procedure ensures that unauthorized registrations are detected early, rather than waiting for them to be discovered by chance through the “My Numbers” service or when another problem arises.
4. Inquiry and Rectification through Equivalent Channels
The paper recommends making the “My Numbers” service and line ownership rectification procedures available through multiple non‑biometric channels. This includes in‑person verification using the original ID card at branches and service centers, as well as a remote channel for users whose identity has already been verified, relying on login to their account with the mobile operator and confirmation of the request through a one‑time code sent to a phone number or communication channel previously authenticated and independent of the line in question.
Where no reliable means of remote verification is available, the user should be directed to an in-person or assisted channel rather than being required to answer personal questions or undergo less secure verification procedures. Assistance channels should also be available to older persons, persons with disabilities, and people living in remote areas, at no cost and without undue delay.
An alternative mechanism could be established to verify the validity of identity data without granting mobile operators direct access to government databases or providing them with copies of identity cards. During line registration, the company would send the minimum data necessary for verification, such as the ID number and name, to a dedicated government system. The system would not return the individual’s existing data; rather, it would send a limited response confirming that the data matches and the ID is valid, or that they do not match. The response could be linked to a transaction reference number and given a short validity period to prevent it from being reused to register other lines.
The use of this mechanism must be limited to verifying a specific transaction, with queries logged and open searches of citizens’ data prohibited. In this way, the mobile operator can verify the validity of the data without obtaining a copy of the ID card, a facial image, or accessing any other data recorded by the government entity.
It’s not enough to enable users to identify lines registered in their names; they must also be able to dispute any line that doesn’t belong to them easily. If a user finds an unfamiliar number through the “My Numbers” service, they should be able to file a complaint free of charge with the mobile operator and immediately receive a reference number to track it. The operator should flag the line as disputed pending the outcome of the investigation, without automatically disconnecting it from its current user.
The operator should then review the registration documents, transaction records, the employee involved, and the device used to carry out the transaction. It should then provide the complainant with a written result within a specified period. If the complainant is not satisfied with the decision, they should have the right to escalate the complaint to NTRA and request a review by a competent official. If it is proven that the line was unlawfully registered in their name, it must be detached from their data, all records to which this information was transferred must be corrected, and they must be compensated for any direct costs incurred as a result of the error.
5. Handling Corporate Lines without Mass Disconnection
The paper recommends establishing separate and clear rules for corporate and institutional lines that distinguish between the entity that holds the contract, the person authorized to manage the account, and the actual user of each line. The entity should record the name of the person who receives each SIM card and update this information whenever the line is assigned to a new user or returned.
Adding large numbers of lines or modifying their registration details should also require approval from two authorized representatives of the entity, with the user notified when a line is assigned to them. This would prevent large numbers of lines from being registered using an administrative representative’s personal data, while maintaining the line’s ownership by the entity and identifying the actual user.
When it is necessary to review data or renew contracts for existing lines, bulk or immediate suspension should be avoided. The paper recommends granting entities and users a period of at least 30 days to update their data, while sending individual notifications explaining the reason for the review, the required steps, the deadline, and the means of objection. The deadline should be extended for those who have already initiated corrective procedures. Where specific evidence of fraud or an imminent risk exists, faster action may be taken against the line concerned, provided that the decision is reasoned and subject to prompt review.
6. Operator Accountability and Transparency
The paper recommends holding mobile operators accountable for registrations carried out through their branches, agents, and employee accounts. Responsibility should not be limited to the individual employee or point of sale where the failure is linked to the operator’s procedures, access controls, or oversight systems.
Where a line is established to have been registered without the owner’s knowledge, the operator should bear the costs of rectification and compensate the user for proven direct damages, in accordance with uniform rules established by NTRA, without prejudice to the user’s right to seek judicial redress.
The paper also recommends that NTRA publish a periodic report detailing, for each operator, the number of confirmed unauthorized registrations following investigation; the time taken to detect and correct them; the actions taken against non-compliant outlets or activation devices; and the outcomes of appeals, compensation claims, and data breaches associated with these operations.
NTRA already publishes information on user complaints and refunded amounts, as reflected in its complaints report. Unauthorized registration should be added as a distinct category with a standardized definition, so that figures can be compared across operators and over time.
Review procedures can be directed at lines with actual indicators of a problem, rather than subjecting all users to additional verification measures. In India, for example, authorities use citizen complaints and communications data analysis to identify numbers suspected of misuse, and then require operators to re‑verify those specific lines. This experience demonstrates that oversight can focus on suspected cases rather than impose a new procedure on millions of subscribers.
Conclusion
The crisis of lines being registered without their owners’ knowledge reveals a malfunction that extends beyond the moment of verifying the applicant’s identity. The problem extends to how the transaction is initiated, the authorizations granted to employees and agents, the company’s ability to prove user consent, the accuracy of records, and the speed at which errors are detected and corrected. Therefore, adding facial images or fingerprints to the registration process does not necessarily address these points and may shift a greater share of the cost of the malfunction onto the user, rather than holding the entity that manages the registration process accountable for its control.
Collecting biometric data is not a limited-impact security measure that can simply be added as a precaution. Faces and fingerprints are highly sensitive data that are difficult to replace if leaked or misused, while verification errors may disrupt people’s access to their lines or to means of correcting their data.
In the absence of a published diagnosis establishing that impersonation at the point when an identity card is presented is the principal cause of unauthorized registrations, creating this new risk is disproportionate to the problem the policy seeks to address.
The protection of mobile line ownership can be enhanced without this expansion in data collection. This requires that each transaction be made traceable, that the user be notified immediately when a line is registered in their name, that a simple means of objection and rectification is available to them, and that mobile operators bear responsibility for the agents, activation devices, and accounts through which they operate. Directing review procedures to transactions and cases in which actual indicators of malfunction appear also allows risks to be addressed without subjecting all users to additional measures.
This approach would give NTRA clearer tools for measuring the policy’s success. Instead of evaluating the system by the number of people who complete a new verification process, it could measure the number of unauthorized registrations, the time needed to detect and correct them, objection outcomes, the recurrence of violations at outlets and devices, and the compensation received by affected individuals. These indicators link accountability to the entities responsible for preventing and remedying errors, thereby subjecting oversight to public scrutiny.
Protecting mobile line ownership does not require the user’s facial image or fingerprint to be a permanent condition for obtaining service or correcting an error. The most secure policy is the one that minimizes the data required, verifies the user’s consent to the specific transaction, and enables the company to interpret every record generated within its systems and hold the responsible party accountable. In this way, identity protection is achieved through the integrity of the registration process itself, not by collecting more data about the users.