18
GOVERNANCE
8
Protect personal data, maintain cyber security, and safeguard
people’s rights through a comprehensive legal and regulatory
framework.
•
Legal and regulatory frameworks. Identification systems must be underpinned by legitimate, comprehensive, and enforceable legal and regulatory frameworks and strong policies that promote trust in the system;
ensure data protection and privacy (including cybersecurity); mitigate
abuse such as unauthorized surveillance in violation of due process; are
free from discrimination and promote inclusion, particularly for vulnerable or marginalized groups; and ensure accountability. Legal frameworks
should be clear in delineating liability and recourse for individuals and
should be overseen by independent regulatory bodies with appropriate
powers and consistent funding. They should also protect people against
inappropriate access and use of their data for undue surveillance or unlawful profiling. Frameworks require a balance between regulatory and
self-regulatory models that does not stifle competition, innovation, or investment. Appropriate legal and regulatory frameworks are also required
for cross-border interoperability or mutual recognition.22
•
Rights of data subjects. Identification services should provide people with
genuine choice and control over the collection and use of their data, including the ability to selectively disclose only those attributes that are required for a particular transaction. People should be given a simple means
to have inaccurate data corrected free-of-charge and to obtain a copy of
their personal data. Personal data should not be used for secondary, unconnected purposes without a person’s informed consent, unless otherwise required or authorized under law (for example, as may be necessary
and proportionate).23 Identity providers and other stakeholders should be
transparent about identity management; develop appropriate resources
to raise people’s awareness of how their data will be used; and provide
accessible and user-friendly tools to manage their data, provide informed
consent, and address grievances. Identity providers should ensure that
the initial process to correct errors is administrative rather than judicial
in order to increase speed of resolution and reduce costs. Data sharing
arrangements should also be transparent and fully documented.
22 For example, asylum seekers and refugees must be given special consideration; see UNHCR Advisory Opinion
on the Rules of Confidentiality Regarding Asylum Information at https://www.refworld.org/docid/42b9190
e4.html
23 See, for example, Convention 108+, Articles 5, 10, and 11.