Deactivating and Recycling Inactive Mobile Numbers: A Critical Review of the Communications Authority of Kenya's 2026 Procedural and Technical Safeguards

Number recycling & consumer protection · Kenya Guideline CA.G.520:2026

Number recycling & consumer protection

Analysing Kenya’s Guideline CA.G.520:2026 — deactivation, whitelisting, and the fight against SIM-swap fraud

Telephone numbers are no longer just routing identifiers. They are keys to financial inclusion, digital identity, and civic life. In September 2026, the Communications Authority of Kenya (CA) issued Guideline CA.G.520:2026 a detailed framework for deactivating and recycling inactive mobile numbers. This post unpacks the guideline’s lifecycle, its whitelisting provisions, and the technical safeguards that aim to balance resource scarcity with consumer protection.

1. Introduction

Mobile numbers, governed internationally by ITU-T Recommendation E.164, are finite resources assigned temporarily to subscribers. Kenya’s numbering space is under pressure: a growing share of numbers lies dormant abandoned by emigrants, closed businesses, or users who simply stop using a line. Left unmanaged, these dormant numbers create efficiency losses and security risks: recycled numbers can become vectors for identity theft, account takeover, SIM-swap fraud, and financial one-time password interception.

The guideline responds to this governance challenge. It sets out a procedural and technical lifecycle for deactivation and recycling, while introducing whitelisting for incarcerated and indisposed subscribers, and a default-off marketing regime. This analysis walks through each component, drawing on Kenya’s documented experience with mobile-money fraud.

2. Numbering as critical infrastructure

In Kenya, mobile numbers are tightly coupled with mobile-money wallets (e.g., M-Pesa), banking one-time passwords, and digital identity. Control over a number increasingly equals control over a person’s financial and digital life. The guideline frames the stakes along three axes:

  • Financial integrity - numbers used for money laundering or SIM-swap-enabled theft.
  • Social stability - identity theft and misinformation circulation.
  • National security - covert coordination of criminal activity.

This framing is echoed in regional reports: Kenyan authorities have recorded a sharp year-on-year increase in fraudulent SIM issuance and substantial losses linked to SIM-swap schemes (Kariuki, 2026; Rio Times, 2026).

3. Number recycling rationale

The ITU’s numbering principles require administrations to use the minimum practicable number of digits and treat assignment as a temporary grant of use. Kenya’s guideline identifies six circumstances that make a number eligible for recycling:

  • Abandonment after loss or device replacement
  • Permanent emigration
  • Business closure
  • Deliberate abandonment to evade financial obligations
  • Regulatory reclamation (e.g., SIM-boxing misuse)
  • Death or permanent unavailability of the registered owner

This taxonomy distinguishes involuntary, voluntary, and punitive scenarios — a distinction that shapes the whitelisting protections.

4. The deactivation and recycling process

The guideline’s core is a structured, time-bound lifecycle:

1 3 months inactivity 2 Direct notification (SMS) 3 3 more months notification 4 Public notice & *106# status check 5 30-day cure period 6 Data de-link & archiving 7 Centralised reporting 8 Release to new subscriber

Inactivity is defined narrowly: no call, SMS, data, top-up, or value-added service for 3 months (cl. 4.1). Upon detection, the provider must notify the subscriber via KYC contact details (SMS and other channels). Notification continues for another 3 months so a full 6 months of inactivity must elapse before any public step.

๐Ÿ“ข Public transparency: 30 days before the 6‑month mark, providers publish a quarterly list of numbers susceptible to deactivation (on website, print, and other media). A USSD short-code, *106#, allows any member of the public to check a number’s status (active, suspended, under recycling, or deactivated). This is a practical due-diligence tool for creditors, family, or business contacts.

After the notice period, the provider must de-link and securely archive the previous owner’s personal data, cached data, and associated services, while retaining records required by law (Data Protection Act, 2019). The provider reports deactivated and recycled numbers quarterly to a centralized system (intended for third parties like lenders or utilities). Only after this reporting may the number be provisioned to a new subscriber.

Structural protection: the entire sequence gives a minimum nine‑month runway from first inactivity to final recycling three months of silent monitoring, three months of direct notification, and a 30‑day public cure period within the second phase.

5. Whitelisting: balancing continuity and fraud prevention

Section 5 introduces whitelisting for subscribers whose inactivity is involuntary not abandonment or a security risk. Two categories:

  • Incarcerated persons - the Commissioner General of Prisons submits the convict’s number and national ID for whitelisting within 3 months of a conviction exceeding 6 months (after appeals). Remand suspects likely held >6 months also qualify.
  • Indisposed persons - a caregiver can request whitelisting in person, with original ID documents for both requester and subscriber, if expected absence from using the number exceeds 6 months.

Whitelisting suspends the deactivation clock: prisoner whitelisting runs for the sentence length; caregiver-initiated runs in renewable 1‑year increments.

The guideline is alert to fraud: caregiver-initiated whitelisting is restricted to numbers already confirmed inactive during KYC verification - preventing a third party from fraudulently locking an active line. However, the guideline does not specify dispute or audit mechanisms if whitelisting is granted or denied incorrectly.

6. Technical safeguards: data and marketing misuse

Recycled numbers can carry forward B2C messaging relationships that were never consented to by the new holder. The guideline responds with a default‑off model:

  • By default, newly issued and recycled numbers are barred from receiving any marketing messages from the assigning provider or third parties.
  • Consent must be affirmatively established through a business‑specific USSD dial - dialing one business’s consent code does not imply consent to others.
  • Providers must retain records of these consent dials for as long as the number remains active, and delink all B2C relationships before deactivation/recycling.
  • Every B2C message must carry an easy opt-out mechanism.

This extends consumer‑protection logic from email/SMS marketing into the recycling context, preventing a new subscriber from inheriting someone else’s marketing subscriptions.

7. Discussion: strengths, gaps, and implementation risk

Strengths: The guideline converts administrative reclamation into a consumer‑protection instrument. The 9‑month notice runway, *106# status‑check, centralised reporting, and default‑off marketing show awareness that mismanaged recycling creates identity confusion, debt‑collection errors, and unsolicited marketing.

Implementation risks:

  • Centralised database delay: The guideline’s transition clause acknowledges the database will only become effective once established - no firm date. Until then, the quarterly reporting requirement has no operational counterpart, leaving third parties without a reliable way to update records.
  • KYC data quality: The framework relies on accurate KYC contact info. Given agent‑assisted registrations and shared IDs (which prompted mass SIM deactivation exercises), notification may not reach the true subscriber.
  • Diaspora subscribers: Emigrants are named as a source of inactive numbers, but notification mechanisms are domestically oriented (SMS, national newspapers).
  • Whitelisting verification & disputes: No audit or dispute‑resolution mechanism is specified if whitelisting is granted, denied, or revoked incorrectly.
  • International alignment: The guideline tracks ITU principles (E.164, E.190) but future revisions could reference comparable regional practice (e.g., biometric SIM‑replacement verification, statutory criminalisation of unauthorised SIM swaps in other African jurisdictions).
⚠️ Critical takeaway: The guideline’s effectiveness will depend heavily on implementation capacity — the timeline for the centralised database, the accuracy of KYC data, and the mechanisms available to audit or contest whitelisting and deactivation decisions.

8. Conclusion

Guideline CA.G.520:2026 is a procedurally detailed attempt to reconcile the scarcity of numbering resources with consumer protection. Its notice‑and‑cure architecture, public verification code, and default‑off marketing regime go beyond the ITU’s minimum efficiency‑oriented principles. For students and practitioners of telecommunications regulation, it offers a compelling case study of how a technical resource the telephone number has become entangled with financial inclusion, identity security, and consumer‑protection law.

The ultimate test, however, lies in operational details that remain unresolved: the centralised database, KYC data quality, and transparent dispute mechanisms. As Kenya’s mobile‑money ecosystem continues to evolve, this guideline will be a key reference point for regulators across the region.


References

  • Communications Authority of Kenya. (2026). Procedures and technical safeguards for deactivation and recycling of inactive telecommunication numbering resources (Guideline No. CA.G.520:2026, Version 1.0).
  • International Telecommunication Union. (1997). The international public telecommunication numbering plan (ITU-T Rec. E.164).
  • International Telecommunication Union. (2008). Criteria and procedures for reservation, assignment and reclamation of E.164 country codes (ITU-T Rec. E.164.1).
  • Kariuki, J. (2026, August 10). SIM card now a banking credential. Regulate it like one. The Star.
  • Rest of World. (2023, April 10). M-Pesa has become a tool for SIM swap fraud.
  • Rio Times. (2026, August). New financial scams sweep Kenya as authorities watch.
  • Republic of Kenya. (2019). Data Protection Act, 2019.
๐Ÿ“„ Analysis based on Guideline CA.G.520:2026 · for educational and policy discussion

Comments

Popular posts from this blog

Part 1: Exploitation of Network-Centric Warfare Domains in Kenyan Politics 2008: The Emergence of Digital Influence Operations

Russia's African Strategy

Information Warfare and Deception: Alleged Mossad Tactics in Facilitating U.S. Military Action Against Libya (1986)