Regional Overview
Regional Overview
individuals in digital transactions, with examples
including China’s “internet number” and Japan’s
My Number system. In contrast, countries
without specific laws regulate digital ID through
broader digital governance frameworks that
recognize electronic signatures and set standards
for identity verification. Across all six countries,
digital ID is not legally linked to citizenship, as
systems are designed to be accessible to both
citizens and foreign residents based on proof of
legal residency rather than nationality.
In the Pacific sub-region, only three countries
(Australia, New Zealand, and Vanuatu) have
established legal and policy frameworks
governing digital identity, while the remaining
countries are at early stages of development.27
Australia and New Zealand provide detailed
statutory definitions, framing digital identity as an
electronic means of authentication for accessing
services and securely sharing personal data,
whereas Vanuatu regulates its national ID system
through multiple laws without explicitly defining
digital identity. All three countries clearly separate
digital identity from citizenship status. Samoa and
Papua New Guinea have introduced legal or policy
frameworks to support future digital ID systems,
explicitly defining their structure and clarifying
that digital ID does not confer citizenship. The
rest of the region, including countries like Kiribati,
the Marshall Islands, and Nauru, lacks dedicated
legal definitions or frameworks, though some
have general electronic transactions laws or
national strategies that lay the groundwork for
future digital ID implementation.
In Central Asia, digital identity is generally regulated
through a mix of laws on identity documents,
electronic government, electronic signatures, digital
development, and data protection rather than
through standalone digital ID legislation.28
Kazakhstan and Kyrgyzstan are exceptions,
having adopted comprehensive Digital Codes
that explicitly govern digital identity, biometric
authentication, and digital public services, while
Tajikistan, Uzbekistan, and Turkmenistan rely
on broader legal frameworks such as electronic
document and e-government laws, with
Turkmenistan still lacking an operational digital ID
system. Most countries provide general grievance
mechanisms through administrative or data
protection channels, but only Kazakhstan has a
dedicated system for digital ID complaints, with
its Digital Code mandating oversight of biometric
data use and enforcement through inspections
and penalties.
Across all sub-regions, domestic legal frameworks
do not establish a direct statutory linkage
between digital ID and citizenship. Both citizens
and, in some countries, foreign residents can
in principle access digital ID provided they
have documentation proving legal residency. In
practice, however, the requirement to possess
foundational legal identity documents as a
prerequisite for digital ID enrollment creates an
indirect link to citizenship, since stateless persons
and undocumented migrants typically lack such
documents.
Dedicated complaint mechanisms remain
rare. The Kazakhstan Digital Code mandates
ministry-level
review
of
complaints
concerning biometric authentication and
data processing,29 and Pakistan’s NADRA
operates a centralized complaint-management
system;30 most other countries rely on general
administrative complaint pathways, dataprotection authorities or agency help desks.
See Table 3 - Domestic legal framework for
digital ID across Asia-Pacific ( page 34 )
Data Protection
Data-protection frameworks vary widely. All
East Asian countries except North Korea have
established data protection and privacy laws,
generally providing safeguards for the collection,
processing, and use of personal data within digital
ID systems, including consent requirements,
purpose limitation, and security obligations.31
China, Taiwan, Mongolia, and South Korea
maintain relatively comprehensive frameworks,
with China’s Personal Information Protection
Law and South Korea’s Personal Information
Protection Act offering strong protections for
sensitive data such as biometrics, alongside
enhanced rights and oversight mechanisms.
However, most countries lack explicit restrictions
on government access to personal data collected
through digital ID systems, as seen in Hong Kong’s
framework. Despite robust legal regimes in some
cases, concerns persist across the sub-region
regarding surveillance risks, data breaches, and
the growing use of AI, particularly in China’s
state-controlled digital identity infrastructure,
while North Korea remains an outlier with no data
protection laws and pervasive state surveillance.
Across the Pacific, most countries lack both digital
ID systems and corresponding data protection
frameworks, with only seven (Australia, Kiribati,
New Zealand, Palau, Papua New Guinea, Samoa,
and Vanuatu) having some form of legal or policy
safeguards.32
Among these, Australia and New Zealand provide
relatively comprehensive privacy regimes, though
gaps remain, such as the absence of mandatory
encryption and limited data erasure rights. Samoa
and Vanuatu have more recent laws addressing
data retention, security, and general safeguards,
but weaknesses persist, particularly around
biometric data regulation and government access.
Papua New Guinea and Kiribati maintain broader
data governance frameworks that only partially
address digital ID concerns. Palau is notable for
aligning its Digital Residency Program with ISO
27001 standards. Overall, uneven regulatory
coverage and limited safeguards raise growing
concerns about privacy risks, data misuse, and
potential surveillance across the region.
In South Asia, the picture is uneven.33 Bhutan,
India, Nepal, and Sri Lanka have data protection
laws or policies, but only Bhutan’s National Digital
Identity framework includes explicit, built-in
safeguards for digital ID systems, such as user
consent, encryption, and controlled access to
biometric data. In contrast, India, Nepal, and Sri
Lanka lack specific protections like mandatory
encryption or robust safeguards governing
the storage, use, and access to digital ID data.
Across the region, significant concerns persist
around privacy, surveillance, and exclusion,
compounded by major data breaches in countries
like India, Bangladesh, and Pakistan. Risks of state
surveillance are particularly acute in contexts such
as the Maldives, where digital ID metadata may
be used to monitor individuals, and Afghanistan,
where biometric data from e-Tazkira systems
may be misused. Civil society in Sri Lanka and
elsewhere has also warned that expansive digital
ID systems could enable mass surveillance in the
absence of strong legal protections.
Seven of eleven Southeast Asian countries
(Malaysia, Singapore, Indonesia, Thailand, the
Philippines, Viet Nam, and Brunei) have data
protection or privacy laws that regulate personal
data used in digital ID systems, generally requiring
consent, imposing security measures, and offering
complaint and enforcement mechanisms.34
However, Cambodia, Laos, Myanmar, and TimorLeste lack comprehensive frameworks for
digital ID, heightening risks of privacy violations,
surveillance, and data misuse; with Myanmar’s
UID Smart Card and biometric SIM registration
schemes drawing particular concern. Across the
sub-region, recurring problems include largescale data breaches, expanded state surveillance
powers, centralized population databases, and
exclusion of those without digital credentials,
illustrated by major leaks in Malaysia and the
Philippines, cybersecurity and spyware abuses
in Viet Nam and Singapore, and extensive
surveillance using biometric and digital ID
infrastructures in Myanmar, Thailand, and Brunei,
18
19
STATELESSNESS ENCYCLOPEDIA ASIA PACIFIC THIRD EDITION - REGIONAL OVERVIEW
REPORT 2026
Select target paragraph3
Connect to a paragraph
Connect to an entity
Disable highlights
Add to table of contents