img
24 Aug 2026
Joint Statement: Rights Organizations Call for an End to Requiring Telecom Users in Egypt to Provide Biometric Data
24 أغسطس 2026

The undersigned organizations reject any policy that makes providing a facial image, fingerprint, or other biometric identifier data a condition for registering, managing, or recovering a mobile phone line; using the “My Numbers” service; or challenging the registration of mobile lines in an individual’s name without their knowledge. They call on the National Telecommunications Regulatory Authority (NTRA) to withdraw any directives that would impose this form of verification on telecommunications service users.

NTRA announced this measure after receiving complaints from individuals who had discovered mobile phone lines, and, in some cases, associated mobile wallets, registered in their names without their knowledge. On 10 August 2026, NTRA announced that, following inspections and verification procedures related to these complaints, it had referred Egypt’s four mobile operators to the Public Prosecution. NTRA also directed the operators to accelerate the rollout of biometric mechanisms to verify the identities of line holders via their applications.

To date, NTRA has not disclosed how many unauthorized registrations its investigations confirmed. It has not identified where in the registration process the failures occurred or how individuals’ personal data were used to register lines without their knowledge. Nor has it clarified whether the incidents resulted primarily from impersonation at the point of sale using another person’s national identity card, misuse of access privileges by employees or agents, or manipulation of activation devices, user accounts, or mobile operators’ internal records.

Without identifying where in the registration process the failures occurred and what caused them, there is no basis for concluding that biometric verification would effectively address the problem. Biometric matching may help establish that the person carrying out a transaction matches the identity associated with a specified reference record. On its own, however, it cannot prevent employees or agents from misusing their access privileges, lines from being added or records altered unlawfully within operators’ systems, or from the reuse of previous verification results.

Requiring the processing of highly sensitive data from millions of users before the source of the problem is identified would shift the response away from addressing weaknesses in the registration system and toward expanding the volume and sensitivity of personal data collected from individuals.

This policy raises further concerns because biometric data would be collected or processed by the same companies whose sales, registration, and activation systems were used for the unauthorized registrations. These are also the companies that NTRA referred to the Public Prosecution in connection with those incidents.

To date, NTRA has published no assessment of whether these companies, or any service or technology providers acting on their behalf, are capable of protecting biometric data. It has also not clarified how legal responsibilities would be allocated among the entities involved, or what procedures would apply if the data were leaked, accessed without authorization, or used for purposes other than those for which it was collected.

Biometric data differ fundamentally from many other means of verification. Passwords can be changed, and identity documents can be revoked or replaced. Individuals, however, cannot change their faces or fingerprints if data derived from those characteristics are compromised or misused. The risks are not limited to the retention of original facial images or fingerprints. Such data may also be converted into digital biometric templates that remain linked to an individual’s identity and can be combined or cross-referenced with other data.

Combining persistent biometric identifiers with telecommunications subscription data could create an infrastructure capable of linking multiple datasets relating to the same individual. Once established, this infrastructure could enable surveillance or profiling and facilitate the reuse of data for purposes beyond those for which they were originally collected. These risks require clear and enforceable legal, technical, and regulatory safeguards governing access, linkage, retention, and sharing.

Linking biometric data to telecommunications services raises direct human rights concerns. An individual whose personal data were used without their knowledge to register a mobile line could be required to provide even more sensitive data merely to identify the lines registered in their name or challenge an unauthorized registration. This would impose an additional burden on the affected individual due to a failure in a system operated by the relevant mobile operator and overseen by NTRA. The operator should instead be required to demonstrate the validity of the registration and promptly correct the individual’s data.

The effects of mandatory biometric verification may extend beyond the rights to privacy and personal data protection. Mobile phone numbers and access to mobile networks have become essential for using government and banking services, seeking employment, and accessing education and healthcare. Making access to mobile services conditional on a verification process that may produce errors or be inaccessible to some users could deepen existing forms of digital exclusion, particularly for older persons, persons with disabilities, and those without suitable smartphones or reliable internet access.

Egypt’s Personal Data Protection Law No. 151 of 2020 classifies biometric data as sensitive personal data, subjecting its processing and protection to heightened requirements. Article 57 of the Egyptian Constitution also protects the inviolability and confidentiality of communications. Under international human rights standards, any interference with the right to privacy must have a clear legal basis, pursue a specific and legitimate purpose, and be demonstrably necessary and proportionate. The personal data processed must also be limited to what is necessary to achieve that purpose.

The information disclosed by the authorities to date is insufficient to demonstrate that these requirements have been met. The authorities have not published findings establishing that identity fraud at the point of registration was the primary cause of the confirmed incidents. Nor have they presented an assessment comparing biometric verification with less intrusive measures that could address weaknesses in the registration system itself.

The undersigned organizations call for unauthorized registrations to be addressed through measures that remedy failures within mobile operators’ systems without exposing all users to additional risks to their privacy and personal data. They therefore call on the Egyptian authorities and NTRA to take the following measures:

l  Withdraw any directive that makes providing a facial image, fingerprint, or other biometric identifier, or undergoing biometric matching, a condition for registering a mobile phone line, renewing or re-entering into a service contract, recovering access to a line, using the “My Numbers” service, or challenging the registration of a line in an individual’s name without their knowledge.

  • Do not permit NTRA, mobile operators, or service or technology providers acting on their behalf to collect, process, or retain biometric data for any of these purposes unless a specific legal basis authorizes such processing and the authorities publicly demonstrate in a manner open to independent assessment that it is necessary and proportionate and that no less intrusive means can achieve the same purpose.
  • Guarantee effective, accessible, and equivalent non-biometric procedures for all users, including in-person verification using an original identity document. Appropriate assistance and reasonable accommodation should be available to older persons, persons with disabilities, and individuals facing barriers to digital access.
  • Publish aggregated findings from investigations into unauthorized registrations while protecting the personal data of affected individuals. The findings should specify the number of substantiated cases; the stages at which the failures occurred; the points of sale involved; the employee or agent accounts and activation devices used; and the corrective and oversight measures adopted to prevent similar incidents.
  • Require mobile operators to maintain secure audit logs, protected against unauthorized alteration or deletion, for every line registration, transfer of ownership, and SIM replacement. The logs should allow each transaction to be traced to the relevant point of sale, employee or agent account, activation device, time of execution, and any subsequent modification.
  • Require mobile operators to review access privileges within their systems and restrict them to what employees need to perform their duties. All access to and modification of subscriber data or line records should be logged in a manner that allows responsibility for unlawful activity to be determined.
  • Require mobile operators to establish mechanisms for detecting unusual registration patterns. Transactions that may indicate misuse of employee or agent accounts or activation devices should be identified and investigated before they result in unauthorized registrations.
  • Notify individuals immediately whenever their personal data are used to register a new line, transfer its ownership, or replace its SIM card. Individuals should also have a direct and prompt means to stop or challenge any transaction they did not initiate or authorize.
  • Provide a free, prompt, and documented mechanism through which individuals can challenge lines registered in their names without their knowledge. Mobile operators should be held accountable for transactions conducted through their branches and authorized agents, required to correct inaccurate records, and obliged to provide effective remedies to affected individuals, including compensation where harm is established.

l  Publish the complete legal and technical architecture of any proposed biometric verification system before it becomes operational. This information should include the types of data to be processed; the source of the reference data used for matching; where processing and storage will take place; the entities that will have access to the data; applicable retention periods and deletion procedures; safeguards governing access, sharing, and linkage; and mechanisms for human review, complaints, and appeals in cases of failed or disputed matches.

Protecting individuals from having mobile lines registered in their names without their knowledge requires reforming the registration system and holding the entities responsible for operating it accountable. It should not entail compelling users to provide a new category of persistent and highly sensitive data to address failures whose causes have yet to be identified.

Mobile operators and regulatory authorities must bear responsibility for the integrity of their systems and demonstrate the validity of transactions conducted through them. The burden arising from institutional failures should not be transferred to affected individuals.

Signatory Organizations:

1.   Access Now

2.   Arab NGO Network for Development

3.   Cairo Institute for Human Rights Studies

4.   Digital Action

5.   Egyptian Commission for Rights and Freedoms

6.   Egyptian Human Rights Forum

7.   Egyptian Initiative for Personal Rights (EIPR)

8.   EgyptWide for Human Rights

9.   El Nadeem Center for the Rehabilitation for Victims of Violence and Torture

10.        Global Voices

11.        INSM for Digital Rights 

12.        Law and Democracy Support Foundation

13.        Masaar Foundation

14.        Project on Organizing, Development, Education, and Research (PODER)

15.        Refugees Platform in Egypt 

16.         Sinai Foundation for Human Rights 

17.        SMEX

18.        The Egyptian Front for Human Rights

19.        The Regional Center for Rights and Liberties



Tags