When bodies become data-do biometrics pose a threat to human rights?

Harpreet Singh Grover · Journal of Indian Society of Periodontology · 2024

The shift from a traditional pen and paper to digitalization in even the most basic of tasks is a change long overdue. While it all seems aligned with the modern technology, the background picture has some hidden dark details. Dark enough to let data regulators be extremely cautious in the way these data banks are going to be used for the intended purpose solely. In an exponentially expanding digital world biometrics-which essentially are measurable biological and behavioural characteristics unique to an individual (fingerprints, facial recognition, palm prints, iris recognition, voice, ear geometry and so on) are fast replacing traditional passwords as standalone tools of authentication. Biometric data once obtained is mapped and saved before being stored for future access control. Majority of the time this storage is in an encrypted form within the device or in a remotely located server. Hardware such as biometric scanners are then used to capture the biometric for identity authentication by matching these scans against that in the saved database to approve or disapprove access. Bodies become Data or in other words it becomes the key to the locked access. Advanced biometrics like voice recognition and heartbeat patterns are being used in the banking sector to verify customer identities. E-passports, automobile, telecom and health industries are also finding a use for advanced biometrics. While these systems offer a lot of promise for the future of cyber security, they certainly are not infallible. Concerns of database breach have been in the limelight especially after segments of digital and personal privacy have become prominent after the enactment of the Digital Personal Data Protection Act, 2023 (“the Act”). Whether a user submits data to a website or over social media, platform encryption and protection are the safeguards. However, in certain cases these platforms act as a sieve for draining data leading to potential abuse and violations of human rights. There have been reported instances wherein biometric data was clandestinely obtained by fraudulent means for surveillance or monitoring the movements or fiscal health of an individual by hostile agencies or third parties or oppressive regimes using such personal data as tools for gross human rights infringements. With a background approach that the human rights which people enjoy offline are essentially similar in an online situation too, in the year 2017, UN Security Council Resolution 2396 introduced legally binding obligations on its member states to develop and share biometric data. However, because of weak guidelines it proved to be grossly insufficient to protect significant human rights impacts, with the result that many International Civil Society Organisations (CSO) had to step in to protect individual civic spaces such as freedom of assembly and freedom of association. To highlight such blatant misuse of biometric records, as recent as on June 24, 2021 European Center for Not-for-Profit Law in collaboration with Human Rights Watch, Article 19, Privacy International and the International Centre for Not-for-profit Law (ICNL)-all members of a Global Civil Society organisation delved into these issues. The speakers at length discussed the Human Rights risks entailing use of biometrics and the safeguards required therein. It was clearly observed that biometrics and the related artificial intelligence (AI) driven technology in some contexts provided a little or a very limited efficacy whereas the risks of grave Human Rights abuse in the same context were undoubtedly much grave. While there are multiple benefits related to biometrics, striking a balance between security measures and individual Human Rights is crucial in the ethical implementation of biometric technologies. The road ahead for responsible organisations making use of such data is to address the loopholes in the existing International and national laws on data protection such as the General Data Protection Regulation (GDPR) of the European Union or the Digital Personal Data Protection Act 2023 of India respectively. In addition, further protective steps such as UN Special Rapporteur on Human Rights are the need of the hour to integrate and strengthen the safeguards of using biometrics without any curtailment of the human rights. Otherwise, the legal consequences could be severe and unforgiving for the culprit organisations or groups responsible for guardianship of such data.

Read the paper · More papers on PaperTik