Regional Overview Regional Overview individuals in digital transactions, with examples including China’s “internet number” and Japan’s My Number system. In contrast, countries without specific laws regulate digital ID through broader digital governance frameworks that recognize electronic signatures and set standards for identity verification. Across all six countries, digital ID is not legally linked to citizenship, as systems are designed to be accessible to both citizens and foreign residents based on proof of legal residency rather than nationality. In the Pacific sub-region, only three countries (Australia, New Zealand, and Vanuatu) have established legal and policy frameworks governing digital identity, while the remaining countries are at early stages of development.27 Australia and New Zealand provide detailed statutory definitions, framing digital identity as an electronic means of authentication for accessing services and securely sharing personal data, whereas Vanuatu regulates its national ID system through multiple laws without explicitly defining digital identity. All three countries clearly separate digital identity from citizenship status. Samoa and Papua New Guinea have introduced legal or policy frameworks to support future digital ID systems, explicitly defining their structure and clarifying that digital ID does not confer citizenship. The rest of the region, including countries like Kiribati, the Marshall Islands, and Nauru, lacks dedicated legal definitions or frameworks, though some have general electronic transactions laws or national strategies that lay the groundwork for future digital ID implementation. In Central Asia, digital identity is generally regulated through a mix of laws on identity documents, electronic government, electronic signatures, digital development, and data protection rather than through standalone digital ID legislation.28 Kazakhstan and Kyrgyzstan are exceptions, having adopted comprehensive Digital Codes that explicitly govern digital identity, biometric authentication, and digital public services, while Tajikistan, Uzbekistan, and Turkmenistan rely on broader legal frameworks such as electronic document and e-government laws, with Turkmenistan still lacking an operational digital ID system. Most countries provide general grievance mechanisms through administrative or data protection channels, but only Kazakhstan has a dedicated system for digital ID complaints, with its Digital Code mandating oversight of biometric data use and enforcement through inspections and penalties. Across all sub-regions, domestic legal frameworks do not establish a direct statutory linkage between digital ID and citizenship. Both citizens and, in some countries, foreign residents can in principle access digital ID provided they have documentation proving legal residency. In practice, however, the requirement to possess foundational legal identity documents as a prerequisite for digital ID enrollment creates an indirect link to citizenship, since stateless persons and undocumented migrants typically lack such documents. Dedicated complaint mechanisms remain rare. The Kazakhstan Digital Code mandates ministry-level review of complaints concerning biometric authentication and data processing,29 and Pakistan’s NADRA operates a centralized complaint-management system;30 most other countries rely on general administrative complaint pathways, dataprotection authorities or agency help desks. See Table 3 - Domestic legal framework for digital ID across Asia-Pacific ( page 34 ) Data Protection Data-protection frameworks vary widely. All East Asian countries except North Korea have established data protection and privacy laws, generally providing safeguards for the collection, processing, and use of personal data within digital ID systems, including consent requirements, purpose limitation, and security obligations.31 China, Taiwan, Mongolia, and South Korea maintain relatively comprehensive frameworks, with China’s Personal Information Protection Law and South Korea’s Personal Information Protection Act offering strong protections for sensitive data such as biometrics, alongside enhanced rights and oversight mechanisms. However, most countries lack explicit restrictions on government access to personal data collected through digital ID systems, as seen in Hong Kong’s framework. Despite robust legal regimes in some cases, concerns persist across the sub-region regarding surveillance risks, data breaches, and the growing use of AI, particularly in China’s state-controlled digital identity infrastructure, while North Korea remains an outlier with no data protection laws and pervasive state surveillance. Across the Pacific, most countries lack both digital ID systems and corresponding data protection frameworks, with only seven (Australia, Kiribati, New Zealand, Palau, Papua New Guinea, Samoa, and Vanuatu) having some form of legal or policy safeguards.32 Among these, Australia and New Zealand provide relatively comprehensive privacy regimes, though gaps remain, such as the absence of mandatory encryption and limited data erasure rights. Samoa and Vanuatu have more recent laws addressing data retention, security, and general safeguards, but weaknesses persist, particularly around biometric data regulation and government access. Papua New Guinea and Kiribati maintain broader data governance frameworks that only partially address digital ID concerns. Palau is notable for aligning its Digital Residency Program with ISO 27001 standards. Overall, uneven regulatory coverage and limited safeguards raise growing concerns about privacy risks, data misuse, and potential surveillance across the region. In South Asia, the picture is uneven.33 Bhutan, India, Nepal, and Sri Lanka have data protection laws or policies, but only Bhutan’s National Digital Identity framework includes explicit, built-in safeguards for digital ID systems, such as user consent, encryption, and controlled access to biometric data. In contrast, India, Nepal, and Sri Lanka lack specific protections like mandatory encryption or robust safeguards governing the storage, use, and access to digital ID data. Across the region, significant concerns persist around privacy, surveillance, and exclusion, compounded by major data breaches in countries like India, Bangladesh, and Pakistan. Risks of state surveillance are particularly acute in contexts such as the Maldives, where digital ID metadata may be used to monitor individuals, and Afghanistan, where biometric data from e-Tazkira systems may be misused. Civil society in Sri Lanka and elsewhere has also warned that expansive digital ID systems could enable mass surveillance in the absence of strong legal protections. Seven of eleven Southeast Asian countries (Malaysia, Singapore, Indonesia, Thailand, the Philippines, Viet Nam, and Brunei) have data protection or privacy laws that regulate personal data used in digital ID systems, generally requiring consent, imposing security measures, and offering complaint and enforcement mechanisms.34 However, Cambodia, Laos, Myanmar, and TimorLeste lack comprehensive frameworks for digital ID, heightening risks of privacy violations, surveillance, and data misuse; with Myanmar’s UID Smart Card and biometric SIM registration schemes drawing particular concern. Across the sub-region, recurring problems include largescale data breaches, expanded state surveillance powers, centralized population databases, and exclusion of those without digital credentials, illustrated by major leaks in Malaysia and the Philippines, cybersecurity and spyware abuses in Viet Nam and Singapore, and extensive surveillance using biometric and digital ID infrastructures in Myanmar, Thailand, and Brunei, 18 19 STATELESSNESS ENCYCLOPEDIA ASIA PACIFIC THIRD EDITION - REGIONAL OVERVIEW REPORT 2026

Select target paragraph3

Connect to a paragraph
Connect to an entity
Disable highlights
Add to table of contents