Myanmar: Human Rights Analysis of Biometric Digital ID Systems from excessive unsolicited and uninvited intrusions from other people.19 The right to privacy is broad and covers, among other things, communications and any information that “may give an insight into an individual’s behaviour, social relationship, private preference and identity that go beyond even that conveyed by accessing the content of a communication.”20 Article 17 requires any interference with the right to privacy to be both lawful and not arbitrary. This means that restrictions on this right, including rules about the collection of data, should be clearly authorised by law. Furthermore, to ensure that restrictions are not arbitrary, international standards suggest that any interference should be in accordance with the objectives of the ICCPR and be “reasonable in the particular circumstances”. The former implies that any interference should be proportionate in the sense that the harm to privacy is outweighed by the benefits that flow from the interference and that if a less intrusive option for securing the benefits is available, that option should be used.21 The right to privacy requires States to regulate by law the gathering and holding of personal information (data protection). This includes rules to ensure that personal information is not accessed by individuals who do not have a legal right to access it and is not used in a manner which is incompatible with human rights. Individuals should have the ability to confirm which bodies, whether public or private, hold their personal information, to correct inaccurate information and to have information that was gathered unlawfully deleted.22 Biometric data is extremely sensitive because it is inseparably linked to a particular person and cannot be changed. The UN High Commissioner for Human Rights has noted that biometric data has the potential to be gravely abused and that there is a particular risk where large amounts are stored in a single, centralised database.23 Identity theft involving biometric data, for example, is extremely difficult to remedy. In addition, biometric data may be used for different purposes from those for which it was collected, including the unlawful tracking and monitoring of individuals.24 Given these risks, the European Union’s General Data Protection Regulation identifies biometric data (along with other data, such as data about racial or ethnic origin or religious beliefs), as “special category” data which should not normally be processed, subject only to narrowly defined exceptions.25 The Human Rights Committee has also indicated that a requirement to provide fingerprints or retinal scans to obtain social assistance is a breach of the right to privacy.26 19 Report of the UN High Commissioner for Human Rights on the right to privacy in the digital age, 3 August 2018, para. 11. Available at: https://ap.ohchr.org/documents/dpage_e.aspx?si=A/HRC/39/29. 20 Ibid., para. 6. 21 Human Rights Committee, General Comment No. 16, 8 April 1988, paras. 3-4. Available at: https://www.refworld.org/docid/453883f922.html. 22 Ibid., para. 10. 23 Report of the UN High Commissioner for Human Rights, note 19, para. 14. 24 Ibid. 25 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, Article 9. Available at: https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679. 26 Human Rights Committee, Concluding Observations of the Human Rights Committee, 7 April 1999, U.N. Doc. CCPR/C/79/Add.105, para. 16. Available at: https://undocs.org/CCPR/C/79/Add.105. -5-

Select target paragraph3