Myanmar: Human Rights Analysis of Biometric Digital ID Systems
•
A clear legal framework should be put in place before implementing any biometric digital
ID regime. Digital ID systems represent a restriction on the right to privacy which, to be
legitimate under international law, must be clearly based in law.115 In addition, inadequate
or non-existent legal frameworks create fertile ground for arbitrary application of the
system, potentially breaching the right to privacy and leading to discriminatory impacts.
The case studies highlight the challenges created by an inadequate legal framework,
including legal challenges and confusing and inconsistent implementation. As evidenced
by Aadhaar in India, a lack of clear rules can lead to poor protection against data breaches
and confusion over which benefits should be linked to the digital ID regime.
•
Myanmar should adopt a strong personal data protection law before putting in place a
biometric digital ID regime or engaging in large-scale collection of biometric data. In
addition to the legal framework for the biometric digital ID regime, strong privacy and data
protection legislation is needed to protect users against abuse of the highly sensitive data
involved.116 In all three case study countries, courts determined that stronger data
protection systems were needed to ensure appropriate implementation of digital ID
regimes.
Data protection regimes are complex. However, there are a number of good models for
this in existence, including The European Union’s General Data Protection Regulation. It
is significant that the Regulation identifies biometric data as a distinct category of special
personal data which requires heightened protection. European law also recognises that it is
not legitimate to require private actors to retain personal data on a mass basis simply so
that law enforcement officials can access that data later on should they wish to.
•
Registration in biometric digital ID regimes should be voluntary and should not represent
a pre-requisite for being able to access social services or benefits. Biometric data should
only be collected with a person’s consent. For this reason, digital ID schemes should never
be mandatory, whether directly or indirectly, through conditioning access to key services
on participating. As part of this, care should be taken to communicate clearly with users
that having a biometric digital ID is not required to access social services.
•
An independent oversight body should be established for any biometric digital ID regime,
which could be the same as the oversight body for the personal data protection regime.
This is crucial to ensure, in practice, that public authorities and private companies comply
with the rules, including those aimed at protecting privacy. The independent oversight body
should have a clear legal mandate and effective protection for its independence. Individuals
should have the right to petition the oversight body for relief where they believe their
privacy or other rights have been breached.
115
Report of the Special Rapporteur on the promotion and protection of the right to freedom of opinion and
expression, note 29, para. 3.
116
United Nations Development Group (UNDG), Data privacy, ethics and protection guidance note on big data for
achievement of the 2030 agenda. Available at:
https://unsdg.un.org/sites/default/files/UNDG_BigData_final_web.pdf.
- 19 -