A Guide to Litigating Identity Systems agencies, particularly where affected persons are not afforded the right to be heard.91 e) The Supreme Court of the Philippines has noted the risk that a biometric identity system could be used for nefarious state surveillance activities, such as tracking an individual’s movements, or evading constitutional search and seizure protections by accessing an individual’s information via the identity system database.92 Storage 36. The centralised storage of biometric data for authentication in an identity system (the process whereby an individual’s identity is verified by matching their biometric data at the point of authentication with the data stored in the identity system’s database) constitutes a disproportionate interference with the right to privacy because it heightens the risk of cybersecurity breaches. a) The Mauritian Supreme Court rejects the centralised, indefinite storage of fingerprint data largely by focusing on the risk of security breaches that were not adequately defended against.93 Specific security breach risks identified by the court included: cloning government credentials and using them to access the database; an indirect proxy attack on the database via the government’s portal; accessing data on the local machines used to upload data to the database server; and reading data from identity cards at a distance with special devices.94 91 Opinion of Justice Batts, Julian J. Robinson v. The Attorney General of Jamaica, Claim No. 2018HCV01788, ¶ 349, 366 (2019). 92 Blas F. Ople v. Ruben Torres and others, Supreme Court of the Republic of the Philippines, G.R. No. 127685, Part III at 5 (1998). 93 Madhewoo, 2015 SCJ 177 at 30–32. 94 Madhewoo, 2015 SCJ 177 at 30. 26

Select target paragraph3