Myanmar: Human Rights Analysis of Biometric Digital ID Systems
from excessive unsolicited and uninvited intrusions from other people.19 The right to privacy is
broad and covers, among other things, communications and any information that “may give an
insight into an individual’s behaviour, social relationship, private preference and identity that go
beyond even that conveyed by accessing the content of a communication.”20
Article 17 requires any interference with the right to privacy to be both lawful and not arbitrary.
This means that restrictions on this right, including rules about the collection of data, should be
clearly authorised by law. Furthermore, to ensure that restrictions are not arbitrary, international
standards suggest that any interference should be in accordance with the objectives of the ICCPR
and be “reasonable in the particular circumstances”. The former implies that any interference
should be proportionate in the sense that the harm to privacy is outweighed by the benefits that
flow from the interference and that if a less intrusive option for securing the benefits is available,
that option should be used.21
The right to privacy requires States to regulate by law the gathering and holding of personal
information (data protection). This includes rules to ensure that personal information is not
accessed by individuals who do not have a legal right to access it and is not used in a manner which
is incompatible with human rights. Individuals should have the ability to confirm which bodies,
whether public or private, hold their personal information, to correct inaccurate information and
to have information that was gathered unlawfully deleted.22
Biometric data is extremely sensitive because it is inseparably linked to a particular person and
cannot be changed. The UN High Commissioner for Human Rights has noted that biometric data
has the potential to be gravely abused and that there is a particular risk where large amounts are
stored in a single, centralised database.23 Identity theft involving biometric data, for example, is
extremely difficult to remedy. In addition, biometric data may be used for different purposes from
those for which it was collected, including the unlawful tracking and monitoring of individuals.24
Given these risks, the European Union’s General Data Protection Regulation identifies biometric
data (along with other data, such as data about racial or ethnic origin or religious beliefs), as
“special category” data which should not normally be processed, subject only to narrowly defined
exceptions.25 The Human Rights Committee has also indicated that a requirement to provide
fingerprints or retinal scans to obtain social assistance is a breach of the right to privacy.26
19
Report of the UN High Commissioner for Human Rights on the right to privacy in the digital age, 3 August 2018,
para. 11. Available at: https://ap.ohchr.org/documents/dpage_e.aspx?si=A/HRC/39/29.
20
Ibid., para. 6.
21
Human Rights Committee, General Comment No. 16, 8 April 1988, paras. 3-4. Available at:
https://www.refworld.org/docid/453883f922.html.
22
Ibid., para. 10.
23
Report of the UN High Commissioner for Human Rights, note 19, para. 14.
24
Ibid.
25
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, Article 9. Available
at: https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679.
26
Human Rights Committee, Concluding Observations of the Human Rights Committee, 7 April 1999, U.N. Doc.
CCPR/C/79/Add.105, para. 16. Available at: https://undocs.org/CCPR/C/79/Add.105.
-5-