326
R. Vecellio Segate
occurred a few times already, how could asylum seekers trust this process, and
particularly that States will not attempt at forcedly gathering or misappropriating
information databases possessed by the UNHCR (not least under the guise of prosecutorial investigations arranged ad hoc)? In fact, even after asylum seekers’ claims
are approved and they are granted refugee status in their new country, States of
origin will hardly fail to put pressure on international organisations (IOs) to disclose
refugees’ data, for either persecutory or, more neutrally, statistical purposes: state
administrations retain a granular interest in knowing exactly who fled and why, and
they are going to petition the UNHCR and similar organisations to release such data.
Providing States of origin with refugees’ identity data would, however, defeat the
very purpose of international refugee law, as a global system of last-resort protection
for individuals who are persecuted (or perceive themselves to be at risk of persecution) in their original country of citizenship and/or habitual residence. The UNHCR
has been sharing asylum seekers’ data with the potential host State for decades,
without any consent from these individuals nor any mitigation framework in place;
for instance, the US Department of Homeland Security (DHS 2019, 14) notes that
DHS and UNHCR have been indirectly sharing biographic information during the refugee
resettlement process for many years. The MOU between DHS and UNHCR for Refugees on the
Sharing of Personal Data expands that information sharing to include biometrics.8
What this means is that their data has been shared without consent, but also without
a number of safeguards related to, for instance, cybersecurity. No technical standards applied mandatorily to these data transfers, nor were the transfers themselves
recorded anywhere public. As if this were not serious enough, in several instances
the UNHCR (and similar agencies) has been succumbing to political pressure to share
data with persecuting governments from the States of origin, too – not least during the
infamous Rohingya crisis (Holloway and Lough 2021; Human Rights Watch 2021;
Rahman 2021). This is a blatant violation of international law, and exposes the need to
design identity onboarding procedures that build on solid laws and equally solid
technical standards enabling their meaningful enforcement – especially when Stateparticipated IOs are involved. Distributed ledgers and open registries are warranted,
to ensure that not only IOs refrain from disclosing this data directly, but that host
States do not attempt at doing so themselves with authorities in sending countries, at
a later stage. This happens frequently owing to “diplomatic comity” but also in the
hope to stop migrations ab initio – which, again, defeats the very purpose of having
an international legal framework for asylum seekers. Sharing UNHCR aggregate
data, instead, raises in principle no legal issue, and it might support political science
researchers (e.g. Marbach 2018) – though again, the extent to which “aggregate” data
8 Emphasis removed.