A Guide to Litigating Identity Systems
agencies, particularly where affected persons are not afforded the right
to be heard.91
e) The Supreme Court of the Philippines has noted the risk that a biometric
identity system could be used for nefarious state surveillance activities,
such as tracking an individual’s movements, or evading constitutional
search and seizure protections by accessing an individual’s information
via the identity system database.92
Storage
36. The centralised storage of biometric data for authentication in an identity
system (the process whereby an individual’s identity is verified by matching
their biometric data at the point of authentication with the data stored in
the identity system’s database) constitutes a disproportionate interference
with the right to privacy because it heightens the risk of cybersecurity
breaches.
a) The Mauritian Supreme Court rejects the centralised, indefinite storage of
fingerprint data largely by focusing on the risk of security breaches that
were not adequately defended against.93 Specific security breach risks
identified by the court included: cloning government credentials and
using them to access the database; an indirect proxy attack on the
database via the government’s portal; accessing data on the local
machines used to upload data to the database server; and reading data
from identity cards at a distance with special devices.94
91
Opinion of Justice Batts, Julian J. Robinson v. The Attorney General of Jamaica, Claim No. 2018HCV01788, ¶ 349,
366 (2019).
92
Blas F. Ople v. Ruben Torres and others, Supreme Court of the Republic of the Philippines, G.R. No. 127685, Part III at
5 (1998).
93
Madhewoo, 2015 SCJ 177 at 30–32.
94
Madhewoo, 2015 SCJ 177 at 30.
26