Biometric Technology at the Borders of Citizenship
319
collection, storage, transfer, and processing of biometric data. The impact of standards on our daily life – and, in this case, on identity documenting – is such that their
development should be entrusted with public regulators, while reality is that it has
tacitly been outsourced to private standard-setting agencies that account to no one.
As these agencies include some of the finest experts in the field and generally produce high-quality outputs, this situation is not necessarily to be regretted, though it
does raise a few concerns on both a practical and a conceptual plane.
I will not dig too deep into this debate; suffice it to observe that developing
countries – their engineers and, as a reflection, their concerns – often lament a sense
of exclusion and neglect. Empirical studies which may prove or disprove these
assertions are warranted, but it seems preliminarily fair to admit that technical
standards still reflect both deeply rooted asymmetries in global knowledge production4 and what the European Commission phrases as a global struggle for technological hegemony (European External Action Service 2021). Building on an
appearance of decentralisation (in that they are not directly issued or enforced by
States), technical standards can be actually painted right at the core of complex webs
of interlegality that shape what practices are internationally permitted and what are
to be discarded (Cohen 2019, 202–237); considerations to this end are expressed in a
lexicon of technical “necessity” or even “inevitability” but not infrequently shaped
by cultural backgrounds and geoeconomic pursuits (especially between the US and
China – Wu 2020, 107), with state-backed corporate commercial interests as value
vectors and strategic drivers within data chain meta-regulatory efforts (Bloomfield
2012; Krisch 2005, 405; Levy 2008, 950; Nedergaard 2007). As I write, private entities
keep playing an exceedingly problematic standard-setting role for identity applications and beyond, by actively engaging with policymakers and technical bodies
towards the negotiation, socialisation, and legal “hardening” of standards they will
be massively profiting from. I labeled their role as “problematic” not merely because
private entities are by definition uninterested in catering for the public good as their
primary objective, but more specifically because in these contexts, standard-setting
work is relied upon by FIs that either ignore “borderline citizenship” situations or
target individuals experiencing them with financial sanctions, on behalf of GN
jurisdictions (most often the US).
As for biometrics, privacy-wise, the World Bank Group’s Identification for
Development (ID4D) advises to implement standards ISO/IEC 27001 and ISO/IEC 29100.5
Most of the standard-drafting, however, is allocated to ISO/IEC Joint Technical Committee (JTC) 1 and its various subcommittees (World Bank Group 2017, 7–8). This JTC is
4 On this concept, refer e.g. to (Castro Torres and Alburez-Gutierrez 2021).
5 See https://id4d.worldbank.org/id-biometrics-primer under the tag “How and where should biometric data be stored?”