Regional Overview Regional Overview often targeting migrants, refugees, stateless communities, LGBTI persons, and human rights defenders. All Central Asian countries have personal data protection or privacy laws that regulate the collection, processing, and protection of personal data, including biometrics used in digital ID systems.35 These frameworks generally require lawful and purpose-limited processing, consent, and security measures. In Kazakhstan, Kyrgyzstan, Uzbekistan, and Turkmenistan, biometric data is explicitly treated as sensitive and subject to heightened safeguards. Tajikistan’s 2018 Law on Personal Data sets out general protections but does not create a distinct higher-protection regime for biometrics. None of the five countries, however, restrict government access to personal data collected through digital ID, allowing state agencies broad access for national security, law enforcement, and administrative purposes. This contributes to ongoing concerns about privacy, surveillance, and data security, particularly in relation to large biometric databases and integrated identity platforms. Tajikistan’s and Uzbekistan’s laws, for example, require security measures but stop short of mandating encryption of digital ID and biometric data, despite documented risks. Common concerns across the region include government surveillance and access to personal data, privacy risks from centralised biometric databases, breaches, and exclusion from public services for individuals without digital ID credentials. Government agencies are generally permitted to access data collected through digital ID systems for national-security, lawenforcement or public-administration purposes; none of the sub-regions has established clear legal prohibitions on such access. The most extensively documented case of digital ID related data misuse concerns Rohingya refugees. Human Rights Watch reported in June 2021 that, between 2018 and 2021, the Bangladeshi government submitted approximately 830,000 names with biometric data to Myanmar authorities, drawing on data UNHCR had collected during refugee registration without obtaining specific informed consent for that onward transfer.36 Surveillance concerns connected to digital ID and biometric systems have also been documented in China, Thailand, Singapore, Viet Nam, Maldives and Afghanistan. See Table 4 - Domestic legal framework for data protection and privacy across Asia-Pacific ( page 41 ) International Commitments There is no international treaty specifically regulating digital identity systems. Most countries are, however, parties to international human rights treaties that create obligations relevant to legal identity, non-discrimination and access to essential services — including the ICCPR, ICESCR, CRC, CEDAW, CERD and CRPD. Article 7 of the CRC and Article 24(2) of the ICCPR are particularly relevant for birth registration; Article 24 ICCPR and Article 8 CRC for the right to identity.37 Ratification of the Statelessness Conventions across the region remains low and uneven. Regional and international digital governance frameworks provide further, albeit non-binding, structuring influences on digital ID policy. Japan, South Korea, Australia, New Zealand, the Philippines and Singapore participate in the APEC CrossBorder Privacy Rules system, which operates as a voluntary certification mechanism for crossborder data transfers. It also indirectly shapes standards for handling digital ID related personal data.38 Japan, South Korea and New Zealand are adherents to the OECD Recommendation on the Governance of Digital Identity, adopted in June 2023, which sets out principles for trusted, usercentred, and interoperable digital ID ecosystems.39 In Southeast Asia, states engage with ASEAN’s Framework on Personal Data Protection and the ASEAN Digital Economy Framework Agreement; while both instruments are non-binding, they signal a regional commitment to converging approaches on data protection and digital economy enablers, including digital identity.40 At the multilateral level, commitments on civil registration and vital statistics form a key part of the normative environment for digital ID. States across the five sub-regions that endorsed the Ministerial Declaration adopted at the Third Ministerial Conference on Civil Registration and Vital Statistics in Asia and the Pacific have committed to a Decade of Action for Inclusive and Resilient CRVS. This includes registering every birth and death by 2030 and addressing the exclusion of digitally marginalised populations.41 This regional agenda links foundational CRVS reforms with the development of digital public infrastructure, reinforcing the expectation that digital-ID systems should support universal, non-discriminatory access to registration and services. The CRC General Comment No. 25 (2021) is identified as the most directly applicable international interpretive instrument requiring that digital systems be designed so that all children can safely access essential public and educational services without discrimination.42 When read alongside core treaty provisions on birth registration and identity, this guidance positions digital ID and associated datagovernance frameworks as central to states’ obligations to prevent exclusion, protect privacy. It also emphasises the need to ensure that stateless, undocumented or otherwise marginalized children are not left outside legal-identity and service-delivery systems. See Table 5 - Ratification of Statelessness Conventions across Asia-Pacific ( page 46 ) Designed to Include? The Impact of Digital ID and Legal Identity on Citizenship and Nationality Rights Across the five sub-regions, digital ID systems have not significantly reduced statelessness. Access to digital identity remains conditional on possession of foundational legal identity documents — birth certificates, national ID cards or residence permits. Stateless persons are disproportionately likely to lack these documents and are therefore typically excluded from digital ID systems and the services tied to them. Where digital ID becomes de facto mandatory for accessing services, exclusion from legal identity is reproduced and entrenched at the digital level. Services commonly inaccessible to stateless persons without digital ID include government e-services, healthcare systems, social protection, school enrollment, banking and financial services, employment registration, SIM-card registration, tax and licensing, and property registration. Exclusion is most acute in South Asia (Bangladesh, India, Pakistan, Sri Lanka), parts of Southeast Asia (Indonesia, Philippines, Viet Nam, Myanmar), Central Asia (Kazakhstan, Kyrgyzstan), and increasingly East Asia (Japan). In the Pacific, where most countries are still developing digital ID systems, the risk of entrenching exclusion is yet to be determined. Good Practices Notwithstanding this broad pattern, several country-level practices offer partial models for more inclusive digital identity: Bhutan’s NDI was launched on 13 October 2023 as the first national-scale Self-Sovereign Identity system, with a statutory basis in the National Digital Identity Act 2023.43 Unlike conventional 20 21 STATELESSNESS ENCYCLOPEDIA ASIA PACIFIC THIRD EDITION - REGIONAL OVERVIEW REPORT 2026

Select target paragraph3

Connect to a paragraph
Connect to an entity
Disable highlights
Add to table of contents