A Guide to Litigating Identity Systems Permanence 52. The use of biometric data in identity systems is similarly problematic because it is stored indefinitely for the duration of a person’s life and potentially beyond. This highlights the importance of storage limitation, which serves as a safeguard by limiting the duration for which data is processed and stored. a) While related partly to the digital nature of data storages and breaches, Jamaican Supreme Court Justice Sykes suggests that once a biometric system breach has occurred, it cannot be reversed.198 As a result, an individual’s biometric data will be exposed forever. b) The Kenyan High Court argues that the misuse of biometric data is dangerous because biometrics are “uniquely linked with individuals,” “cannot be changed and are universal,” and because “the effects of any abuse of [sic] misuse of the data are irreversible.”199 The irreversibility of misuse of biometric data is amplified when the data is centrally stored because data subjects will most often lack information or control over the use of data stored in that manner.200 c) The majority opinion in the Aadhaar judgment does not make the connection between biometrics and permanence expressly. However, the court restricts the time for which data can be stored partly on the grounds that the right to be forgotten would be infringed by lengthy storage of data.201 The court limits the time for which authentication transaction data can be stored from five years to six months.202 198 Opinion of Justice Sykes, ¶ 50. 199 Huduma Namba Judgment, ¶ 880. 200 Huduma Namba Judgment, ¶ 880. 201 Aadhaar Judgment, ¶ 205 at 282. 202 Aadhaar Judgment, ¶ 205 at 282. 47

Select target paragraph3