limited (Open CRVS, n.d.). In response to these initiatives, the Secure Identity Alliance, a
group of biotech companies, launched their own ‘open standards’ initiative to facilitate
interoperability of private sector software (Secure Identity Alliance, 2019). The World Bank
has supported MOSIP implementation in pilot countries, and also produced guidance on
procurement and other standards. But contracts for identity systems continue to be signed
between governments and technology suppliers, with minimal public understanding or
oversight of the terms and payments made, creating significant risks of corruption (which
would remain with an open source platform). There is often an insufficient national legal
framework to create accountability for the accuracy and fairness of the systems as they
function in practice. There is equally no agreed international legal framework governing
these powerful new technologies, leaving the providers of new identification systems largely
unsupervised.
Legal identity and data protection
In practice, African states are often rolling out biometric registration systems before data
protection and privacy laws are in effect, leaving control over that data almost entirely with
the biotech companies and the state (Privacy International, 2020b). Even where they are in
place, data protection authorities are poorly resourced and understanding of the issues very
low among national decision-makers (ID4Africa, 2019). Others have warned of ‘surveillance
humanitarianism’, whereby data collection systems deployed by aid organizations
inadvertently increase the vulnerability of people in urgent need (Latonero, 2019; see also
Hayes, 2017; Latonero, 2018), and deplored the fact that poor countries are the site for
experimentation with identification systems in the absence of any control by the users
(Currion, 2015; Schoemaker et al., 2018). Concepts of ‘informed consent’ central to the
ethical collection of data may be meaningless if registration in a scheme is compulsory to
obtain the benefits promised (Kak, 2020).
Rwanda enrolled more than nine million people into its national identity system (over one
weekend), linked multiple government departments and agencies into the database -- and
sold the data to the private sector – all without any data protection act in place (Atick,
2016). Zimbabwe was reported to have sold its citizens’ biometric data to China, to train
facial recognition on African faces, without any consent from those involved (Hawkins,
2018). Kenya rolled out its Huduma Namba project with no data protection law enacted, no
broader legal framework, and no parliamentary or public consultation on the issues. In
January 2020, the High Court in Nairobi ordered implementation of NIIMS to halt until the
time that a comprehensive regulatory framework was put in place (Privacy International,
2020a; Sinha, 2020); but later in the year civil society was again condemning the
government’s decision to proceed without addressing the discriminatory implementation of
the law (Nubian Rights Forum et al., 2020). A new biometric ID card was rolled out in
Tanzania without any data protection law in place, and SIM cards switched off if their
owners could not prove enrolment in the new national identity system, increasing already
substantial threats to free expression from a government (like Rwanda’s) with strong
authoritarian tendencies (Article 19, 2020; Lichtenstein, 2020).
More broadly, commentators have warned that the World Bank and other development
actors who have supported the roll-out of digital identity projects have failed to understand
‘the complex relationships between asymmetric information and power in contexts of a
weak rule of law’ (Khan & Roy, 2019). Despite the limited data collected, the Aadhaar
11