The Costa Rican Data Protection Agency confirmed that the Migration Agency lacks registered data protection protocols for passport consent forms. This admission validates concerns about the legal compliance of handling citizens’ sensitive personal information, highlighting a significant gap in regulatory adherence by the institution responsible for issuing biometric passports. Public scrutiny has intensified following allegations of improper data management, including complaints lodged against associated entities such as the national bank and the postal service. Despite the agency’s insistence that its procedures are legally sound and that data access is strictly restricted and encrypted, the absence of an officially recorded protocol undermines claims of full transparency and security. This discrepancy suggests potential vulnerabilities in how confidential data is processed and shared, challenging the institution’s defense against accusations of irregularities. This case is highly relevant to open data because it illustrates the critical necessity for transparent, legally binding frameworks governing the handling of public information. Without registered protocols, citizens cannot trust that their data is protected or used solely for its intended purpose. It underscores that open data principles require not just accessibility, but strict accountability and verifiable security measures to prevent misuse and maintain public trust in government digital services.

Source:
Published on 2023-07-05