A Guide to Litigating Identity Systems
b) The dissenting opinion in the Aadhaar judgment identifies a risk that a
nationalised, centralised database incorporated into an identity system
could be prone to cybersecurity threats because adversaries of the state
have an interest in inflicting damage on individuals’ biometric credentials
when they are seeded across an entire identity system, as well as threats
caused by market incentives for public and private organisations with
access to the system to sell individuals’ personal data.95
c) Justice Sykes of the Jamaican Supreme Court refers to concerns that
data stored as part of the identity system could fall into the hands of
third parties, which could expose sensitive information like medical data.96
Justice Sykes identifies specific threats of attack to the system as
including Trojan Horse attacks and spoofing attacks.97
d) The Kenyan High Court argues that there will be risks of “attacks or
unauthorised access” with “any storage” of personal data, but
acknowledges that centralised storage affords data subjects less
information and control over their data’s use.98 In light of the risk of attack
or unauthorised access of biometric data stored in either a centralised or
decentralised system, the court concludes that strong security policies
are required if systems are to comply with international data protection
standards – a requirement the court imposes on the Kenyan national
identity system.99
95
Aadhaar Judgment, ¶ 245 of dissent.
96
Opinion of Justice Sykes, ¶ 55.
97
Opinion of Justice Sykes, ¶ 54.
98
Huduma Namba Judgment, ¶ 880.
99
Huduma Namba Judgment, ¶ 883.
27