Regional Overview
Regional Overview
often targeting migrants, refugees, stateless
communities, LGBTI persons, and human rights
defenders.
All Central Asian countries have personal data
protection or privacy laws that regulate the
collection, processing, and protection of personal
data, including biometrics used in digital ID
systems.35 These frameworks generally require
lawful and purpose-limited processing, consent,
and security measures. In Kazakhstan, Kyrgyzstan,
Uzbekistan, and Turkmenistan, biometric data
is explicitly treated as sensitive and subject to
heightened safeguards. Tajikistan’s 2018 Law
on Personal Data sets out general protections
but does not create a distinct higher-protection
regime for biometrics. None of the five countries,
however, restrict government access to personal
data collected through digital ID, allowing state
agencies broad access for national security, law
enforcement, and administrative purposes.
This contributes to ongoing concerns about privacy,
surveillance, and data security, particularly in relation
to large biometric databases and integrated identity
platforms. Tajikistan’s and Uzbekistan’s laws, for
example, require security measures but stop short
of mandating encryption of digital ID and biometric
data, despite documented risks.
Common concerns across the region include
government surveillance and access to personal
data, privacy risks from centralised biometric
databases, breaches, and exclusion from public
services for individuals without digital ID
credentials. Government agencies are generally
permitted to access data collected through
digital ID systems for national-security, lawenforcement or public-administration purposes;
none of the sub-regions has established clear legal
prohibitions on such access. The most extensively
documented case of digital ID related data misuse
concerns Rohingya refugees. Human Rights
Watch reported in June 2021 that, between 2018
and 2021, the Bangladeshi government submitted
approximately 830,000 names with biometric
data to Myanmar authorities, drawing on data
UNHCR had collected during refugee registration
without obtaining specific informed consent for
that onward transfer.36 Surveillance concerns
connected to digital ID and biometric systems
have also been documented in China, Thailand,
Singapore, Viet Nam, Maldives and Afghanistan.
See Table 4 - Domestic legal framework for
data protection and privacy across Asia-Pacific
( page 41 )
International Commitments
There is no international treaty specifically
regulating digital identity systems. Most countries
are, however, parties to international human
rights treaties that create obligations relevant
to legal identity, non-discrimination and access
to essential services — including the ICCPR,
ICESCR, CRC, CEDAW, CERD and CRPD. Article
7 of the CRC and Article 24(2) of the ICCPR are
particularly relevant for birth registration; Article
24 ICCPR and Article 8 CRC for the right to
identity.37
Ratification of the Statelessness Conventions
across the region remains low and uneven. Regional
and international digital governance frameworks
provide further, albeit non-binding, structuring
influences on digital ID policy. Japan, South
Korea, Australia, New Zealand, the Philippines
and Singapore participate in the APEC CrossBorder Privacy Rules system, which operates as
a voluntary certification mechanism for crossborder data transfers. It also indirectly shapes
standards for handling digital ID related personal
data.38 Japan, South Korea and New Zealand are
adherents to the OECD Recommendation on the
Governance of Digital Identity, adopted in June
2023, which sets out principles for trusted, usercentred, and interoperable digital ID ecosystems.39
In Southeast Asia, states engage with ASEAN’s
Framework on Personal Data Protection and the
ASEAN Digital Economy Framework Agreement;
while both instruments are non-binding, they
signal a regional commitment to converging
approaches on data protection and digital
economy enablers, including digital identity.40
At the multilateral level, commitments on civil
registration and vital statistics form a key part
of the normative environment for digital ID.
States across the five sub-regions that endorsed
the Ministerial Declaration adopted at the Third
Ministerial Conference on Civil Registration
and Vital Statistics in Asia and the Pacific have
committed to a Decade of Action for Inclusive and
Resilient CRVS.
This includes registering every birth and death
by 2030 and addressing the exclusion of digitally
marginalised populations.41 This regional agenda links
foundational CRVS reforms with the development
of digital public infrastructure, reinforcing the
expectation that digital-ID systems should support
universal, non-discriminatory access to registration
and services.
The CRC General Comment No. 25 (2021)
is identified as the most directly applicable
international interpretive instrument requiring
that digital systems be designed so that all
children can safely access essential public and
educational services without discrimination.42
When read alongside core treaty provisions on
birth registration and identity, this guidance
positions digital ID and associated datagovernance frameworks as central to states’
obligations to prevent exclusion, protect
privacy. It also emphasises the need to ensure
that stateless, undocumented or otherwise
marginalized children are not left outside
legal-identity and service-delivery systems.
See Table 5 - Ratification of Statelessness
Conventions across Asia-Pacific ( page 46 )
Designed to Include? The
Impact of Digital ID and
Legal Identity on Citizenship
and Nationality Rights
Across the five sub-regions, digital ID systems have
not significantly reduced statelessness. Access to
digital identity remains conditional on possession
of foundational legal identity documents —
birth certificates, national ID cards or residence
permits. Stateless persons are disproportionately
likely to lack these documents and are therefore
typically excluded from digital ID systems and the
services tied to them. Where digital ID becomes de
facto mandatory for accessing services, exclusion
from legal identity is reproduced and entrenched
at the digital level.
Services commonly inaccessible to stateless
persons without digital ID include government
e-services, healthcare systems, social protection,
school enrollment, banking and financial services,
employment registration, SIM-card registration,
tax and licensing, and property registration.
Exclusion is most acute in South Asia (Bangladesh,
India, Pakistan, Sri Lanka), parts of Southeast Asia
(Indonesia, Philippines, Viet Nam, Myanmar),
Central Asia (Kazakhstan, Kyrgyzstan), and
increasingly East Asia (Japan). In the Pacific,
where most countries are still developing digital
ID systems, the risk of entrenching exclusion is yet
to be determined.
Good Practices
Notwithstanding this broad pattern, several
country-level practices offer partial models for
more inclusive digital identity:
Bhutan’s NDI was launched on 13 October 2023
as the first national-scale Self-Sovereign Identity
system, with a statutory basis in the National
Digital Identity Act 2023.43 Unlike conventional
20
21
STATELESSNESS ENCYCLOPEDIA ASIA PACIFIC THIRD EDITION - REGIONAL OVERVIEW
REPORT 2026
Select target paragraph3
Connect to a paragraph
Connect to an entity
Disable highlights
Add to table of contents