16
6
Protect privacy and agency through system design.
•
Privacy by design approach. Identification systems must be designed to
prioritize and protect data and privacy as the default setting without requiring any additional special action on the part of an individual. Personal
data, including any data that are linked or linkable to an individual, must
be protected from improper use proactively and by default through a robust legal and regulatory framework, system design, and the adoption of
technical standards and operational controls.18
•
Data protection principles in practice. The design, policies, and technology used by identification systems should comply with global norms for
data protection, including data minimization and proportionality, purpose
specification, lawful processing, strict limits on data retention, data accuracy, security, accountability, and transparency, among others.19 For example, identification systems should limit the collection and exposure of
data—particularly sensitive personal information20 —including in credentials and the structure of identification numbers. Authentication protocols
must disclose only the minimum data necessary to ensure appropriate
levels of assurance and retain data only for as long as required for the purposes for which the data may lawfully be used, or for which consent has
been given. These levels and the method of authentication should reflect
an assessment of the level of risk in the transactions and should preferably
be based on recognized international standards.21 Data rules and policies
should be transparent and made available to people in a user-friendly format to facilitate knowledge of their rights and the processes available to
exercise control or oversight of their data.
18 On the “privacy-by-design” approach, see, for example, Cavoukian, A. 2011. “Privacy by Design: The 7 Foundational Principles. Implementation and Mapping of Fair Information Practices.” https://iab.org/wp-content/
IAB-uploads/2011/03/fred_carter.pdf.
19 Commonly referenced examples of standards include the Fair Information Practices (FIPs), the OECD’s Privacy
Guidelines, the EU’s General Data Protection Regulation, the UN Principles on Data Privacy and Protection,
and Convention 108+, among others.
20 “Sensitive personal information” can vary by context but commonly includes data that could be used to create
fraudulent identities and/or to profile or target individuals. This includes biometric data and identifying numbers, such as permanent or unique identity numbers (UINs), as well as attributes such as religion, ethnicity,
caste, political affiliation, and so forth. The disclosure of identifying information may involve particularly serious risks to certain people, for example, asylum seekers and refugees. Therefore, specific considerations apply
to ID systems used primarily or exclusively for humanitarian purposes, particularly in settings affected by
conflict, violence, and fragility. See, for example, the International Committee of the Red Cross “Policy on the
Processing of Biometric Data by the ICRC.” 2019. Available at: https://www.icrc.org/en/download/file/106620/
icrc_biometrics_policy_adopted_29_august_2019_.pdf, and the ICRC/Brussels Privacy Hub Handbook on
Data Protection in Humanitarian Action, 2nd Edition, 2020.
21 Such risk impact assessments should be carried out by the responsible entity that creates, collects, shares, or
uses data for authentication and identification purposes linked to the specific use case. Examples of existing
standards for levels of assurance for identity proofing include ISO/IEC 29115 and those issued by eIDAS, the
UK Cabinet Office, the U.S. National Institute of Standards and Technology (NIST), and others.