A Guide to Litigating Identity Systems
Permanence
52. The use of biometric data in identity systems is similarly problematic because
it is stored indefinitely for the duration of a person’s life and potentially
beyond. This highlights the importance of storage limitation, which serves as
a safeguard by limiting the duration for which data is processed and stored.
a) While related partly to the digital nature of data storages and breaches,
Jamaican Supreme Court Justice Sykes suggests that once a biometric
system breach has occurred, it cannot be reversed.198 As a result, an
individual’s biometric data will be exposed forever.
b) The Kenyan High Court argues that the misuse of biometric data is
dangerous because biometrics are “uniquely linked with individuals,”
“cannot be changed and are universal,” and because “the effects of any
abuse of [sic] misuse of the data are irreversible.”199 The irreversibility of
misuse of biometric data is amplified when the data is centrally stored
because data subjects will most often lack information or control over the
use of data stored in that manner.200
c) The majority opinion in the Aadhaar judgment does not make the
connection between biometrics and permanence expressly. However, the
court restricts the time for which data can be stored partly on the
grounds that the right to be forgotten would be infringed by lengthy
storage of data.201 The court limits the time for which authentication
transaction data can be stored from five years to six months.202
198 Opinion of Justice Sykes, ¶ 50.
199 Huduma Namba Judgment, ¶ 880.
200 Huduma Namba Judgment, ¶ 880.
201 Aadhaar Judgment, ¶ 205 at 282.
202 Aadhaar Judgment, ¶ 205 at 282.
47