{"id":1548,"date":"2019-02-08T16:38:25","date_gmt":"2019-02-09T00:38:25","guid":{"rendered":"https:\/\/blog.mozilla.org\/netpolicy\/?p=1548"},"modified":"2020-01-28T10:17:11","modified_gmt":"2020-01-28T18:17:11","slug":"kenya-government-mandates-dna-linked-national-id-without-data-protection-law","status":"publish","type":"post","link":"https:\/\/blog.mozilla.org\/netpolicy\/2019\/02\/08\/kenya-government-mandates-dna-linked-national-id-without-data-protection-law\/","title":{"rendered":"Kenya Government mandates DNA-linked national ID, without  data protection law"},"content":{"rendered":"<p>Last month, the Kenya Parliament passed a seriously concerning <a href=\"http:\/\/kenyalaw.org\/kl\/fileadmin\/pdfdownloads\/AmendmentActs\/2018\/StatuteLawMischellaneousNo18of2018.pdf\">amendment<\/a> to the country\u2019s national ID law, making Kenya home to the most privacy-invasive national ID system in the world. The rebranded, National Integrated Identity Management System (NIIMS) now requires all Kenyans, immigrants, and refugees to turn over their DNA, GPS coordinates of their residential address, retina scans, iris pattern, voice waves, and earlobe geometry before being issued critical identification documents. NIIMS will consolidate information contained in other government agency databases and generate a unique identification number known as Huduma Namba.<\/p>\n<p>It is hard to see how this system comports with the right to privacy articulated in Article 31 of the Kenyan Constitution. It is deeply troubling that these amendments passed without public debate, and were approved even as a data protection bill which would designate DNA and biometrics as sensitive data is pending.<\/p>\n<p>Before these amendments, in order to issue the National ID Card (ID), the government only required name, date and place of birth, place of residence, and postal address. The ID card is a critical document that<a href=\"https:\/\/www.khrc.or.ke\/2015-03-04-10-37-01\/blog\/675-a-call-to-action-to-end-statelessness-in-kenya.html\"> impacts everyday life,<\/a> without it, an individual cannot vote, purchase property, access higher education, obtain employment, access credit, or public health, among other fundamental rights.<\/p>\n<p>Mozilla strongly believes that that no digital ID system should be implemented without strong privacy and data protection legislation. The proposed Data Protection Bill of 2018 which Parliament is likely to consider next month, is a strong and thorough framework that contains provisions relating to data minimization as well as collection and purpose limitation. If NIIMS \u00a0is implemented, it will be in conflict with these provisions, and more importantly in conflict with Article 31 of the Constitution, which specifically protects the right to privacy.<\/p>\n<p><a href=\"https:\/\/www.businessdailyafrica.com\/analysis\/ideas\/Kenya-needs-unified-identity-registration\/4259414-4846478-119h6iqz\/index.html\">Proponents<\/a> of NIIMS claim that the system provides a number of benefits, such as accurate delivery of government services. These arguments also seem to conflate legal and digital identity. Legal ID used to certify one\u2019s identity through basic data about one\u2019s personhood (such as your name and the date and place of your birth) is a commendable goal. It is one of the United Nations Sustainable Development<a href=\"https:\/\/unstats.un.org\/sdgs\/metadata\/?Text=&amp;Goal=16&amp;Target=16.9\"> Goals 16.9<\/a> that aims <i>\u201cto provide legal identity for all, including birth registration by 2030\u201d<\/i>. \u00a0However, it is important to remember this objective can be met in several ways. \u201cDigital ID\u201d systems, and especially those that involve sensitive biometrics or DNA, are not a necessary means of verifying identity, and in practice raise significant privacy and security concerns. The choice of whether to opt for a digital ID let alone a biometric ID therefore should be closely scrutinized by governments in light of these risks, rather than uncritically accepted as beneficial.<\/p>\n<ul>\n<li><b>Security Concerns: The centralized nature of NIIMS creates massive security vulnerabilities. It could become a honeypot for malicious actors and identity thieves who can exploit other identifying information linked to stolen biometric data. The amendment is unclear on how the government will establish and institute strong security measures required for the protection of such a sensitive database. If there\u2019s a breach, it\u2019s not as if your DNA or retina can be reset like a password or token.<\/b><\/li>\n<li><b>Surveillance Concerns: \u00a0By centralizing a tremendous amount of sensitive data in a government database, NIIMS creates an opportunity for mass surveillance by the State. Not only is the collection of biometrics incredibly invasive, but gathering this data combined with transaction logs of where ID is used could substantially reduce anonymity. This is all the more worrying considering Kenya\u2019s history of<\/b><a href=\"https:\/\/privacyinternational.org\/sites\/default\/files\/2017-10\/track_capture_final.pdf\"> <b>extralegal \u00a0surveillance and intelligence sharing<\/b><\/a><b>.<\/b><\/li>\n<li><b>Ethnic Discrimination \u00a0Concerns: The collection of DNA is particularly concerning as this information can be used to identify an individual\u2019s ethnic identity. Given Kenya\u2019s history of \u00a0<\/b><a href=\"https:\/\/www.khrc.or.ke\/publications\/183-ethnicity-and-politicization-in-kenya\/file.html\"><b>politicization of ethnic identity<\/b><\/a><b>, collecting this data in a centralized database like NIIMS could reproduce and exacerbate patterns of discrimination.<\/b><\/li>\n<\/ul>\n<p><b>The process was not constitutional<\/b><\/p>\n<p>Kenya\u2019s constitution requires public input before any new law can be adopted. No public discussions were conducted for this amendment. It was offered for parliamentary debate under \u201c<i>Miscellaneous<\/i>\u201d amendments, which exempted it from procedures and scrutiny that would have required introduction as a substantive bill and corresponding public debate. The Kenyan government must not implement this system without sufficient public debate and meaningful engagement to determine how such a system should be implemented if at all.<\/p>\n<p>The proposed law does not provide people with the opportunity to opt in or out of giving their sensitive and precise data. The Constitution requires that all Kenyans be granted identification. However, if an individual were to refuse to turn over their DNA or other sensitive information to the State, as they should have the right to do, they could risk not being issued their identity or citizenship documents. Such a denial would contravene Articles 12, 13, and 14 of the Constitution.<\/p>\n<p>Opting out of this system should not be used to discriminate or exclude any individual from accessing essential public services and exercising their fundamental rights.<\/p>\n<p>Individuals must be in full control of their digital identities with the right to object to processing and use and withdraw consent. These aspects of control and choice are essential to empowering individuals in the deployment of their digital identities. Therefore policy and technical decisions must take into account systems that allow individuals to identify themselves rather than the system identifying them.<\/p>\n<p>Mozilla urges the government of Kenya to suspend the implementation of NIIMS and we hope Kenyan members of parliament will act swiftly to pass the Data Protection Bill of 2018.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Last month, the Kenya Parliament passed a seriously concerning amendment to the country\u2019s national ID law, making Kenya home to the most privacy-invasive national ID system in the world. The &hellip; <a class=\"go\" href=\"https:\/\/blog.mozilla.org\/netpolicy\/2019\/02\/08\/kenya-government-mandates-dna-linked-national-id-without-data-protection-law\/\">Read more<\/a><\/p>\n","protected":false},"author":1616,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[652,327266,327267,574,847],"tags":[],"coauthors":[318939],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Kenya Government mandates DNA-linked national ID, without data protection law - Open Policy &amp; Advocacy<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.mozilla.org\/netpolicy\/2019\/02\/08\/kenya-government-mandates-dna-linked-national-id-without-data-protection-law\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alice Munyua\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/2019\/02\/08\/kenya-government-mandates-dna-linked-national-id-without-data-protection-law\/\",\"url\":\"https:\/\/blog.mozilla.org\/netpolicy\/2019\/02\/08\/kenya-government-mandates-dna-linked-national-id-without-data-protection-law\/\",\"name\":\"Kenya Government mandates DNA-linked national ID, without data protection law - Open Policy &amp; Advocacy\",\"isPartOf\":{\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#website\"},\"datePublished\":\"2019-02-09T00:38:25+00:00\",\"dateModified\":\"2020-01-28T18:17:11+00:00\",\"author\":{\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/07979f9f8391f03ec641bf63270eec56\"},\"breadcrumb\":{\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/2019\/02\/08\/kenya-government-mandates-dna-linked-national-id-without-data-protection-law\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.mozilla.org\/netpolicy\/2019\/02\/08\/kenya-government-mandates-dna-linked-national-id-without-data-protection-law\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/2019\/02\/08\/kenya-government-mandates-dna-linked-national-id-without-data-protection-law\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.mozilla.org\/netpolicy\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Kenya Government mandates DNA-linked national ID, without data protection law\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#website\",\"url\":\"https:\/\/blog.mozilla.org\/netpolicy\/\",\"name\":\"Open Policy &amp; Advocacy\",\"description\":\"Mozilla&#039;s official blog on open Internet policy initiatives and developments\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.mozilla.org\/netpolicy\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/07979f9f8391f03ec641bf63270eec56\",\"name\":\"Alice Munyua\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/image\/3ec97ff79d8cfcc627ff9a37ae4970d0\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/dacd1a604507751688071aebc3c61bde?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/dacd1a604507751688071aebc3c61bde?s=96&d=mm&r=g\",\"caption\":\"Alice Munyua\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Kenya Government mandates DNA-linked national ID, without data protection law - Open Policy &amp; Advocacy","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.mozilla.org\/netpolicy\/2019\/02\/08\/kenya-government-mandates-dna-linked-national-id-without-data-protection-law\/","twitter_misc":{"Written by":"Alice Munyua","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/blog.mozilla.org\/netpolicy\/2019\/02\/08\/kenya-government-mandates-dna-linked-national-id-without-data-protection-law\/","url":"https:\/\/blog.mozilla.org\/netpolicy\/2019\/02\/08\/kenya-government-mandates-dna-linked-national-id-without-data-protection-law\/","name":"Kenya Government mandates DNA-linked national ID, without data protection law - Open Policy &amp; Advocacy","isPartOf":{"@id":"https:\/\/blog.mozilla.org\/netpolicy\/#website"},"datePublished":"2019-02-09T00:38:25+00:00","dateModified":"2020-01-28T18:17:11+00:00","author":{"@id":"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/07979f9f8391f03ec641bf63270eec56"},"breadcrumb":{"@id":"https:\/\/blog.mozilla.org\/netpolicy\/2019\/02\/08\/kenya-government-mandates-dna-linked-national-id-without-data-protection-law\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.mozilla.org\/netpolicy\/2019\/02\/08\/kenya-government-mandates-dna-linked-national-id-without-data-protection-law\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/blog.mozilla.org\/netpolicy\/2019\/02\/08\/kenya-government-mandates-dna-linked-national-id-without-data-protection-law\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.mozilla.org\/netpolicy\/"},{"@type":"ListItem","position":2,"name":"Kenya Government mandates DNA-linked national ID, without data protection law"}]},{"@type":"WebSite","@id":"https:\/\/blog.mozilla.org\/netpolicy\/#website","url":"https:\/\/blog.mozilla.org\/netpolicy\/","name":"Open Policy &amp; Advocacy","description":"Mozilla&#039;s official blog on open Internet policy initiatives and developments","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.mozilla.org\/netpolicy\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/07979f9f8391f03ec641bf63270eec56","name":"Alice Munyua","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/image\/3ec97ff79d8cfcc627ff9a37ae4970d0","url":"https:\/\/secure.gravatar.com\/avatar\/dacd1a604507751688071aebc3c61bde?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/dacd1a604507751688071aebc3c61bde?s=96&d=mm&r=g","caption":"Alice Munyua"}}]}},"_links":{"self":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/posts\/1548"}],"collection":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/users\/1616"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/comments?post=1548"}],"version-history":[{"count":0,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/posts\/1548\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/media?parent=1548"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/categories?post=1548"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/tags?post=1548"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/coauthors?post=1548"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}