Feeds

Government ID Card claims deflated

Biometric data open to abuse, says EU data supervisor

  • alert
  • submit to reddit

Protecting against web application threats using SSL

Biometric data employed for identification purposes could be misused and lead to "function creep", the European Data Protection Supervisor has warned.

In a comment this week, the EDPS, who monitors the use of public data, said the ease with which biometric information, such as fingerprints, could be shared with other databases across the EU would leave it open to abuse.

The statement is in stark conflict with the UK government’s claims that biometric data used for its controversial ID card scheme will not be used for any other purposes.

The EDPS Peter Hustinx said the accuracy of biometric data in uniquely identifying a person is "overestimated", and could in fact "facilitate the unwarranted interconnection of databases".

Commenting on a European Commission paper last year on the interoperability of different databases across the EU, Hustinx said biometric data could not be guaranteed to provide the unambiguous 'primary key' required by most databases for identification. In many cases a primary key is a number unique to one individual.

As a result it could breach EU principles of data quality, Hustinx said.

A further concern is that because biometric data is not unique, it could lead easily be shared between different databases throughout the EU.

Ultimately, Hustinx warned, this could lead to function creep when the interlinking of two databases designed for two distinct purposes provides a third one for which they have not been built.

This is in turn would lessen the possibility of member state governments being able to supervise the protection of personal data.

Overall, the EDPS also said the EC’s paper had not given a clear definition of interoperability and called for further analysis in order to ensure protection of data.

He said: "The commission argues that interoperability is a technical rather than a legal or political concept. This is confusing and only serves to avoid fundamental issues. Interoperable systems increase the risks for citizens, if such systems allow for new access to their personal data. It is essential to examine this more carefully and not hide it as a technicality."

Copyright © eGov monitor Weekly

eGov monitor Weekly is a free e-newsletter covering developments in UK eGovernment and public sector IT over the last seven days. To register go here.

Reducing the cost and complexity of web vulnerability management

More from The Register

next story
Infosec geniuses hack a Canon PRINTER and install DOOM
Internet of Stuff securo-cockups strike yet again
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
Greater dev access to iOS 8 will put us AT RISK from HACKERS
Knocking holes in Apple's walled garden could backfire, says securo-chap
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.