Written evidence submitted by Sir John Adye,
Chairman of Identity Assurance Systems (BIO0031)

Summary

  1. Background on Identity Assurance Systems (IdAS)

1.1.                Identity Assurance Systems Ltd (IdAS) is a small company registered in England and Wales. Its Chairman, Sir John Adye, was formerly the Director of GCHQ and an independent director of the National Biometric Security Project (NBSP), a US non-profit organisation hitherto funded by Congress. IdAS Ltd and its US sister company were founded in 2010 to take forward the work of NBSP when US Congressional funding ended.

1.2.                IdAS purchased the intellectual property (IP) of NBSP with funds provided by Board members, who like its other officers - former members of UK and US defence, security and intelligence agencies - all currently contribute their work without payment at this stage.

1.3.                The main aims of IdAS are:

  1. Declaration of interests

2.1.                John Adye and IdAS colleagues have a potential commercial interest in development of the conceptual framework and systems mentioned above. No Government or other external funding has as yet been sought or provided to IdAS, except for payment by the British Standards Institution (BSI) of some expenses for taking part in international standards meetings overseas.

  1. Future uses of biometric data and technologies

3.1.                In addition to the present uses summarised in the Select Committee's terms of reference for this Inquiry, IdAS expects to see a substantial and sustained increase in the use of biometric data and technologies in the global economy. The main examples are:

 

  1. Challenges

4.1.                There are four main challenges facing both Government and industry in developing, implementing and regulating new technologies that rely on biometric data:

 

 

  1. Effectiveness of current legislation

5.1.                The main area of current legislation relevant to this Inquiry is the Data Protection Act 1998 (which implements the relevant EC Directive 95/46/EC on data protection) together with related regulations which apply in the UK. Some other legislation such as the Protection of Freedom Act 2012 is also relevant.

5.2.                IdAS has taken legal advice in support of design work on our proposed framework (for which see Annex A) and on component applications and techniques. In most cases the relevant force of the current legislation is clear and helpful in designing appropriate means of protecting Personal Data. This is defined in the Act as data relating to a living individual from which the individual can be identified, either from the data alone or from the data in combination with other information in possession of the relevant Data Controller. Any processing of Personal Data must comply with the eight data protection principles of the DPA, for example its collection, use, storage, retention and disclosure. If the data is anonymised it will fall outside of the requirements of the DPA.

5.3.                The inter-relationship between legal definitions of Personal Data, and of biometric data at various stages of its acquisition and processing, is absolutely crucial to the future design and use biometric technology. Technical and related legal and regulatory issues are currently under discussion as part of the process of formulating the EU's draft Data Protection Regulation. Work done in this context by the Data Protection Working Party (an independent European advisory body set up under Article 29 of Directive 95/46/EC) may be relevant to this Inquiry, e.g.

5.4.                Such questions are important because the design of secure identity assurance systems, including biometrics and other technologies, must obviously enable compliance with applicable law, and because developing legislation and regulations in the EU and other countries will be highly relevant to the commercial viability and operational use of systems which are designed for application in the UK and are also marketed internationally.

5.5.                The following small extract from Section 2 of the Working Party's Opinion 03/2012 may help illustrate the points made above:

Biometric template: Key features can be extracted from the raw form of biometric data (e.g. facial measurements from an image) and stored for later processing rather than the raw data itself. This forms the biometric template of the data. The definition of the size (the quantity of information) of the template is a crucial issue. On the one hand, the size of the template should be wide enough to manage security (avoiding overlaps between different biometric data, or identity substitutions), on the other hand, the size of the template should not be too large so as to avoid the risks of biometric data reconstruction. The generation of the template should be a one-way process, in that it should not be possible to regenerate the raw biometric data from the template.

Under the current application of the EC Directive and the Data Protection Act 1998, this one-way process anonymises the biometric data (as mentioned in paragraph 5.2 above), so that it falls outside the data protection requirements of the DPA.

5.6.                IdAS suggests that the Select Committee consider how further formulative work on the EU's draft Data Protection Regulation can best be directed and handled, to ensure that it takes full account of UK national policies on the freedom of individuals and the protection of their personal data, and also on support to British industry in the fast developing field of identity assurance, using biometric and related technologies.

5.7.                If required, IdAS can provide further evidence on these questions and other parts of this written submission, including our Anonymous identity Assurance (AidA) design framework, which is briefly described in Annex A.

September 2014

 

 

 

 


Annex A   Conceptual design by Identity Assurance Systems of a framework using biometric and other technologies to link distributed identity verification systems:

IDENTITY ASSURANCE SYSTEMS - IdAS and AidA

What is AidA?

Anonymous identity Assurance - a framework or architecture for linking and managing distributed identity verification systems in the global economy:

 

What does AidA offer to people, to governments and commercial partners of IdAS?