The way we prove who we are has fundamentally changed in recent decades.
A birth certificate used to be the whole proof. Now it is the thing you show so a database can check its own record. Now a database decides. Healthcare, bank accounts, school enrollment, welfare payments: all of it runs through some system that has to recognize you first.
Roughly a billion people cannot prove who they are. No record, no card, no entry in anyone’s file. As more services move to digital verification, that gap stops being an inconvenience and starts being a wall.
Governments and companies are building biometric databases fast. Two questions follow. Who runs them. What happens to the people inside them.
Rights do not change when you go online. The tools do. The same system that gets someone a bank account can also track where they pray, who they meet and when they saw a doctor.
Every government at the UN agreed to it. Under Sustainable Development Goal 16.9, legal identity for all is due by 2030. Then comes the hard part. Build that digitally and you have built a register and a surveillance tool in one go.
The Infrastructure of Identity and Access Control
Every service you log into runs some form of authentication and authorization. The system checks you are who you claim, then decides what you are allowed to do.
Companies use identity management platforms to handle both without making the login unbearable. Customer Identity and Access Management, or CIAM, is the branch aimed at outside users rather than staff.
CIAM solutions cover sign-up, verification and permissions, and they have to satisfy privacy law at the same time. Multi-factor authentication, single sign-on and permission tiers are standard parts.
The architecture is not a technical detail. It decides where power sits.
Put every fingerprint and iris scan on one central server and you have built a single target. One breach exposes everyone. And a government that wants access has one door to knock on rather than a thousand.
There are other designs. Some keep the data on the person’s own device, or split it so no single party holds the whole record. The technology works. Adoption is patchy, and depends heavily on which country and which sector you are looking at.
Surveillance, Exclusion, and the Weaponization of Identity Systems
The expansion of biometric surveillance technologies has outpaced the development of protective legal frameworks in most regions.
These systems hold a lot in one place. Fingerprints. Facial geometry. Iris scans. DNA. The databases are often linked to each other, and other agencies can search them.
That changes what the state can see. Tracking people at this scale was not possible before, and the relationship shifts once it is.
Consider what a face match in a specific location reveals. It can show that someone went to a clinic, or a mosque, or a union meeting. None of that is the identity check itself. It comes free with it.
The Federal Trade Commission has flagged this. Its warning is that these systems now threaten privacy and civil rights, not that they might one day.
Law enforcement has moved fastest. 24 federal agencies are using facial recognition or planning to. Six of them cite domestic law enforcement as a use.
For people already on the margins, these systems tend to make things worse rather than better.
India shows how this plays out. Its ID system is tied to residency, which sounds neutral. For refugees and stateless people it is not. Their irregular status gets recorded and fixed in place, and the record then keeps them out of welfare, banking and everything else the system gates.
That is the pattern to watch. Once food, shelter or medical care requires enrollment, a system sold as inclusion works as control for anyone who cannot enroll or will not.
Legal Frameworks Struggling to Keep Pace
Regulation has arrived unevenly. Multinationals face a different rulebook in every market. Individuals get different protection depending on where they happen to live.
The GDPR and the California Consumer Privacy Act both try to hand control back to the person. Collect only what you need. Get consent. Delete it when asked. Those rules bear directly on biometric data, since a fingerprint template is personal data that cannot be reissued once it leaks.
Yet significant gaps remain.
Unlike many countries, there is no comprehensive data privacy law that includes biometric data and covers the entire United States, with data privacy regulation instead being sector specific and left to state and local governments. So your protection depends on two things you may not control. Which state you live in. What service you happened to use.
The UN Development Programme has looked at how these systems should be governed. Its conclusion is that they need a rights-based design and accountability that reaches beyond the agency running them. Very few systems in operation now clear that bar.
The enforcement landscape remains equally fragmented. Enforcement is split the same way. A company holding identity data answers to several regulators at once, each with its own requirements. The person whose data it is usually has nowhere useful to go when something goes wrong.
That gap gets exploited. A system can tick every box on the form and still do the thing the rules were written to prevent.
What a Better System Looks Like
The benefits are real. What tends to get skipped is the protective work. Privacy safeguards, and the effort to include minorities, stateless people and the displaced, are the parts that fall off the plan when budgets tighten.
Better technology will not fix this on its own, and neither will compliance. What matters is who owns the system and who it answers to.
A provider that wants to claim it protects rights has to do two things. Reduce the risk that the system discriminates. Hold a high standard on privacy and data protection.
In practice that means enrolling people who have no birth certificate. It means building so that biometric data cannot be turned into a surveillance tool later. And it means oversight that includes the people being registered, not just the agencies doing the registering.
None of this is waiting on a technical breakthrough. The designs exist. What blocks them is inertia, commercial pressure, and governments that want the surveillance capability the safeguards are meant to remove.
Digital identity is not paperwork. It decides who gets a bank account, who gets treatment, who counts. The systems being designed now will settle whether that works as inclusion or as control.
Editor’s Note: The opinions expressed here by the authors are their own, not those of impakter.com — In The Cover Photo: Digital identity systems increasingly determine access to services while raising questions about privacy, biometric data, surveillance and human rights. — Photo Credit: Lara Jameson




