ID ENABLING ENVIRONMENT ASSESSMENT (IDEEA) Guidance Note
Total Page:16
File Type:pdf, Size:1020Kb
ID ENABLING ENVIRONMENT ASSESSMENT (IDEEA) Guidance Note Please provide comments to [email protected]. © 2018 International Bank for Reconstitution and Development/The World Bank 1818 H Street, NW, Washington, D.C., 20433 Telephone: 202-473-1000; Internet: www.worldbank.org Some Rights Reserved This work is a product of the staff of The World Bank with external contributions. The findings, interpretations, and conclusions expressed in this work do not necessarily reflect the views of The World Bank, its Board of Executive Directors, or the governments they represent. The World Bank does not guarantee the accuracy of the data included in this work. Nothing herein shall constitute or be considered to be a limitation upon or waiver of the privileges and immunities of The World Bank, or of any participating organization to which such privileges and immunities may apply, all of which are specifically reserved. Rights and Permissions This work is available under the Creative Commons Attribution 3.0 IGO license (CC BY 3.0 IGO) http://creativecommons.org/licenses/by/3.0/igo. Under the Creative Commons Attribution license, you are free to copy, distribute, transmit, and adapt this work, including for commercial purposes, under the following conditions: Attribution—Please cite the work as follows: World Bank. 2017. ID Enabling Environment Assessment, Washington, DC: World Bank License: Creative Commons Attribution 3.0 IGO (CC BY 3.0 IGO) Translations—If you create a translation of this work, please add the following disclaimer along with the attribution: This translation was not created by The World Bank and should not be considered an official World Bank translation. The World Bank shall be liable for any content or error in this translation. Adaptations—If you create an adaptation of this work, please add the following disclaimer along with the attribution: This is an adaptation of an original work by The World Bank. Views and opinions expressed in the adaptation are the sole responsibility of the author or authors of the adaptation and are not endorsed by The World Bank. All queries on rights and licenses should be addressed to the World Bank Publications, The World Bank, 1818 H Street, NW, Washington, DC, 20433; USA; email: [email protected]. 2 Consultation Draft - October 2018 Disclaimer This Guidance Note is an explanatory commentary on the diagnostic tool ID Enabling Environment Assessment (IDEEA). These are designed together to support the review and analysis of a given country’s legal and regulatory enabling environment for digital identification (ID) systems. Both the IDEAA and this Guidance Note are based on evolving international good practice. As diagnostic tools, they are not intended as a basis for legislation, but rather as a basis for broad, multi-stakeholder consultation on what a country may consider including in its legal and regulatory framework. Both the IDEEA and this Guidance Note are “living” documents, which are intended to be updated from time to time. They reflect experience in a range of countries from different regions, with different legal systems and at different stages of economic development. They also take account existing literature (for example, on national ID, civil registration and vital statistics and citizenship, data protection and privacy, cyber-security, etc.), international conventions, norms and principles (including the Principles on Identification, available at: http://pubdocs.worldbank.org/en/200361509656712342/web-English-ID4D-IdentificationPrinciples.pdf). There is no guarantee that addressing all the issues raised in the IDEEA or this Guidance Note will result in a perfect or even workable legal and regulatory enabling framework for ID in a country – that will depend on many exogenous factors to be factored into a legislative strategy, which may be different from country to country. 3 Consultation Draft - October 2018 Contents Some Rights Reserved ............................................................................................................................ 2 Rights and Permissions ........................................................................................................................... 2 Disclaimer ............................................................................................................................................... 3 INTRODUCTION ...................................................................................................................................... 6 This Guidance Note ................................................................................................................................. 6 The purposes of World Bank support ...................................................................................................... 6 Key principles for digital ID ................................................................................................................... 7 IDEEA QUESTIONNAIRE AND COMMENTARY .................................................................................... 9 PART I. THE ID SYSTEM LANDSCAPE ................................................................................................... 9 PART II. QUESTIONS ABOUT GENERALLY APPLICABLE LAWS AND REGULATIONS ......................... 12 The Legal System and Sources of Law .............................................................................................. 12 Inclusion ............................................................................................................................................... 12 Design ................................................................................................................................................... 14 Data protection and privacy ................................................................................................................. 14 A. Data protection and privacy principles ..................................................................................... 17 B. Data sharing .............................................................................................................................. 19 C. Data security ............................................................................................................................. 23 Cyber threats ......................................................................................................................................... 25 International and extraterritorial issues ............................................................................................... 26 Other ID related laws, regulations and policies ................................................................................... 29 Governance .......................................................................................................................................... 32 Individual rights and protections .......................................................................................................... 32 Institutions ............................................................................................................................................ 36 PART III. QUESTIONS ABOUT EACH ID SYSTEM AND ITS LEGAL FRAMEWORK ............................... 42 The ID System, its Purposes and Capabilities .................................................................................. 42 Legal, regulatory and policy purposes ................................................................................................. 43 Capabilities ........................................................................................................................................... 43 Functional purposes .............................................................................................................................. 47 Inclusion ............................................................................................................................................... 49 Coverage and eligibility ........................................................................................................................ 49 Accessibility and barriers to inclusion.................................................................................................. 57 Births, deaths and other events ............................................................................................................. 61 Mandatory nature ................................................................................................................................. 63 Design ................................................................................................................................................... 65 Vendors, technology and procurement ................................................................................................. 65 Registration ........................................................................................................................................... 66 A. Collection of personal data ....................................................................................................... 66 B. Validation and de-duplication ................................................................................................... 73 C. Identifiers and credentials ......................................................................................................... 76 4 Consultation Draft - October 2018 Use, storage and protection of personal