A single digital ID can simplify life, but who will protect the data?

Zarif Faiaz
Zarif Faiaz

There is something almost surreal about how cheap privacy, especially data privacy, has become in Bangladesh. On September 6, a reporter from Prothom Alo anonymously approached an online data seller and provided them with the mobile number of a government minister. Payment was made, and a few hours later, the seller delivered three months of the minister’s call detail records, including whom he had spoken to, when, for how long, and which mobile towers his phone had connected to. When approached for comments, the minister checked the records against that from his own phone. They matched.

Three months of someone’s digital movements and communications metadata—a minister’s, no less—cost Tk 1,050.

If that sounds too causal, it’s because it is. Such illegal practices have, unfortunately, become increasingly common. A Dismislab investigation conducted in June found a blooming online market where citizens’ personal data are being sold through Facebook advertisements, websites, Telegram, and WhatsApp. The array of data that are up for purchase includes people’s NIDs, call detail records, mobile phone location data, SMS lists, tax identification numbers (TINs), IMEI numbers, police clearance certificates, passport details, and mobile financial service statements. If even the personal data of a cabinet minister can be bought online with roughly the effort it takes to order dinner, we cannot help but ask: does “data security” mean anything today?

The urgency of that question has been heightened by the government’s reported plans for an extraordinarily ambitious digital identity project. Under the proposed Unified Digital Identity, or “One-ID,” citizens would receive a permanent identity from birth that could be used throughout their lifetime to access public services, including healthcare and education. The proposed system would gradually replace the separate functions of existing cards and documents, potentially reducing the need to maintain multiple forms of identification. Precisely what data the new card would contain, however, has not yet been finalised.

An average person spends much time navigating a maze of identity numbers, certificates, registrations, and databases. A well-designed digital identity system could, in theory, reduce duplication and spare people from repeatedly submitting the same information to different government offices. But we are carrying years of unresolved issues over how citizens’ data are collected, accessed, copied, protected, and, in many cases, sold. Most people have simply learned to live with this reality, often without knowing the extent of the risks. Many have had to suffer because of the weak safeguards. But no government has yet done enough to address these systemic vulnerabilities.

The Tech Global Institute (TGI) recently documented at least 68 reported or alleged data-breach incidents affecting both public and private institutions between January 2023 and May 2026. Thirty-six involved government organisations, and 32 private entities. The information thus exposed included NID numbers, biometric records, passport information, and other personally identifiable data.

Another study by TGI shows that our data-security problem is not necessarily one giant server waiting to be broken into—it is an ecosystem problem. Its examination of the country’s digital identity infrastructure identifies a complex web of government bodies, private organisations, verification systems, APIs, vendors, and other intermediaries with access to identity-linked information. It also identifies what it calls “shadow copies”: replicas of citizens’ data created for operational purposes, testing, maintenance, analytics or convenience, which may exist outside the systems and controls governing the original databases.

This reality should fundamentally change how we think about data security. A database can be technically secure while the ecosystem surrounding it remains porous. The front door may be locked, but that offers little assurance if dozens of side doors exist and no one can reliably say who has opened them. This is what makes the One-ID discussion more complicated. The issue is not simply whether Bangladesh possesses the technical capacity to produce 20 crore smart cards, build servers, collect biometrics, or connect databases. The country has already built enormous digital systems before. The more difficult questions concern governance.

Who will be allowed to access the information behind One-ID? Will a hospital verifying a patient’s identity see only what it needs, or could that access expose unrelated information? Will every query be logged? Who will audit those logs? What happens when an employee abuses legitimate access? What happens when a contractor quietly retains a copy of a database after its work ends? And when a breach occurs, who will be responsible for informing the citizen whose information has escaped? These are not hypothetical questions anymore. Bangladesh’s track record is sobering enough to make such concerns legitimate.

The government has repeatedly said it is working with the telecoms regulator and law-enforcement agencies to identify those responsible for data leaks. Mobile operators claim they maintain “strict controls” over access to customer information. But if those controls and safeguards are working as they should, where is the leaked data coming from?

That is the ghost hanging over One-ID. A unified identity system does not automatically mean that every piece of information about a citizen must sit inside one giant database. Good architecture can separate information, restrict access, and allow one institution to verify something without exposing everything another institution knows. But architecture is only half the story. The strongest encryption in the world cannot compensate for an official selling authorised access. A sophisticated access-control system accomplishes little if accounts are shared, logs are ignored, vendors keep unofficial copies, or breaches disappear into bureaucratic silence.

The promise of One-ID is convenience—one citizen, one identity, fewer forms, and fewer repeated submissions. The risk, however, is concentration. The more services that depend on one identity infrastructure, the more consequential any failure in that infrastructure can become. And the risks are not merely technical. They are compounded by weak institutional accountability and poor digital-security practices.

Of course, none of this means that the proposed system will automatically fail. It does, however, leave a substantial burden of unanswered questions. Before the debate becomes consumed by cards, chips, procurement, biometrics, and impressive diagrams of interconnected government services, citizens need to know what has actually changed in the institutions entrusted with their data.

Bangladesh’s data problem has never simply been a shortage of technology. It has been the shortage of accountability around the technology we already have. Before placing even more of our lives behind a single digital identity, the very real risks of personal data being lost or compromised deserve far more attention than they have received so far.


Zarif Faiaz is editor of the Tech & Startup section at The Daily Star and a research fellow at Tech Global Institute. He can be reached at faiaz@thedailystar.net.


Views expressed in this article are the author's own. 


Follow The Daily Star Opinion on Facebook for the latest opinions, commentaries, and analyses by experts and professionals. To contribute your article or letter to The Daily Star Opinion, see our guidelines for submission.