Myanmar: Human Rights Analysis of Biometric Digital ID Systems • A clear legal framework should be put in place before implementing any biometric digital ID regime. Digital ID systems represent a restriction on the right to privacy which, to be legitimate under international law, must be clearly based in law.115 In addition, inadequate or non-existent legal frameworks create fertile ground for arbitrary application of the system, potentially breaching the right to privacy and leading to discriminatory impacts. The case studies highlight the challenges created by an inadequate legal framework, including legal challenges and confusing and inconsistent implementation. As evidenced by Aadhaar in India, a lack of clear rules can lead to poor protection against data breaches and confusion over which benefits should be linked to the digital ID regime. • Myanmar should adopt a strong personal data protection law before putting in place a biometric digital ID regime or engaging in large-scale collection of biometric data. In addition to the legal framework for the biometric digital ID regime, strong privacy and data protection legislation is needed to protect users against abuse of the highly sensitive data involved.116 In all three case study countries, courts determined that stronger data protection systems were needed to ensure appropriate implementation of digital ID regimes. Data protection regimes are complex. However, there are a number of good models for this in existence, including The European Union’s General Data Protection Regulation. It is significant that the Regulation identifies biometric data as a distinct category of special personal data which requires heightened protection. European law also recognises that it is not legitimate to require private actors to retain personal data on a mass basis simply so that law enforcement officials can access that data later on should they wish to. • Registration in biometric digital ID regimes should be voluntary and should not represent a pre-requisite for being able to access social services or benefits. Biometric data should only be collected with a person’s consent. For this reason, digital ID schemes should never be mandatory, whether directly or indirectly, through conditioning access to key services on participating. As part of this, care should be taken to communicate clearly with users that having a biometric digital ID is not required to access social services. • An independent oversight body should be established for any biometric digital ID regime, which could be the same as the oversight body for the personal data protection regime. This is crucial to ensure, in practice, that public authorities and private companies comply with the rules, including those aimed at protecting privacy. The independent oversight body should have a clear legal mandate and effective protection for its independence. Individuals should have the right to petition the oversight body for relief where they believe their privacy or other rights have been breached. 115 Report of the Special Rapporteur on the promotion and protection of the right to freedom of opinion and expression, note 29, para. 3. 116 United Nations Development Group (UNDG), Data privacy, ethics and protection guidance note on big data for achievement of the 2030 agenda. Available at: https://unsdg.un.org/sites/default/files/UNDG_BigData_final_web.pdf. - 19 -

Select target paragraph3