Features

ENBIC: Who owns West Africa’s biometric data, and what role does IOM play?

Published

on

Kindly share this article

A small plastic card may soon become one of the most consequential documents carried by millions of West Africans.

The ECOWAS National Biometric Identity Card, ENBIC, is designed to make movement across the region easier, replace the old travel certificate and provide a more secure means of establishing identity. But beneath the promise of seamless travel lies a question that deserves far more public attention:

When a citizen submits fingerprints, facial images, biographical information and other identity details for an ECOWAS biometric card, who ultimately controls that information?

And, perhaps more importantly, where does the International Organization for Migration (IOM) fit into a system that involves the collection, verification, sharing and potentially cross-border use of some of the most sensitive information a person possesses?

These are not merely technological questions. They are questions of sovereignty, privacy, accountability and citizens’ rights.

A regional identity project with national fingerprints

ENBIC is not simply another identity card.

ECOWAS says the card was established pursuant to Decision A/DEC/01/12/14 and is intended to facilitate free movement, serve as proof of identity and residence, and increasingly function as a travel document. The regional body says the card can also support services such as national identification, financial services and e-commerce.

In Nigeria, the ENBIC application platform is operated through the Nigeria Immigration Service. The official portal invites Nigerian citizens to apply, reissue cards, correct information, track applications and book appointments.

That immediately raises an important distinction.

ENBIC may be a regional instrument, but the biometric information collected from a Nigerian citizen does not automatically become the property of a regional organisation—or of an international organisation involved in supporting the programme.

Indeed, Nigeria’s own data-protection framework places obligations on organisations that determine the purposes and means of processing personal information.

The Nigeria Immigration Service’s privacy policy identifies NIS as the data controller for its digital services and expressly includes facial images and fingerprints among the personal information it may collect.

That is significant.

It means that the public conversation should move beyond the simplistic question of “Who owns ENBIC?”

The more useful questions are:

Who is the data controller? Who is the processor? Where is the database hosted? Who can access it? Under what law? For what purpose? For how long? Can it be transferred outside Nigeria? And who can order its disclosure?

Those questions become particularly important when identity systems cross national boundaries.

IOM is involved—but involvement is not ownership

IOM’s participation in ENBIC is not new.

ECOWAS documented IOM’s involvement in the initiative as far back as 2016, when the organisation supported member states by examining opportunities and challenges associated with rolling out a national biometric identity card for ECOWAS countries.

In 2019, ECOWAS also said IOM supported an advocacy and sensitisation campaign on ENBIC in Nigeria, Benin and Togo. The exercise involved border officials, transporters and communities and was presented as part of efforts to improve free movement, border management and the fight against trafficking.

More recently, in September 2026, ECOWAS and IOM again engaged the Nigerian media on the ENBIC initiative, explaining its anticipated contribution to mobility, identity verification and border management.

But there is an important distinction that should not be lost in the public debate:

Supporting, advising, sensitising or providing technical assistance does not, by itself, establish ownership of citizens’ biometric information.

Publicly available ECOWAS and Nigerian documents reviewed for this story do not establish that IOM owns the ENBIC database.

What they do establish is that IOM has had a role in supporting aspects of the broader biometric identity and migration-management agenda.

That distinction is crucial because allegations that an international organisation “owns” citizens’ biometric data require evidence of legal ownership or data-controller status—not simply evidence of participation in a programme.

But who controls the information once borders disappear?

This is where the ENBIC debate becomes more complicated.

A biometric identity card is valuable precisely because different authorities can trust the identity attached to it.

ECOWAS is pursuing interoperability between national foundational identification systems and ENBIC. In February 2026, the regional body said its roadmap work was intended to establish pathways from national foundational ID systems to ENBIC and clarify the functions of stakeholders involved in planning, designing, developing, deploying, operating and managing the card throughout its life cycle.

Interoperability brings obvious benefits.

A traveller should not have to prove identity repeatedly at every border.

But interoperability also creates a governance challenge:

The more systems communicate, the more important it becomes to know exactly what information is being exchanged.

A border official may need to know that a person is who they claim to be.

That does not necessarily mean the official needs unrestricted access to the person’s entire identity record.

The difference between identity verification and identity surveillance is therefore one that policymakers cannot afford to ignore.

Biometrics are not ordinary data

A lost password can be changed.

A compromised fingerprint cannot.

A person can obtain a new passport number.

They cannot obtain a new set of fingerprints.

They cannot simply replace the face they were born with.

That is why biometric databases require a higher level of scrutiny.

IOM’s own 2026 publication on biometrics and identity management acknowledges the potential benefits of biometric systems while identifying risks involving privacy, discrimination, accountability, security, interoperability, “function creep” and misuse. It recommends attention to legal frameworks, data-protection impact assessments, cybersecurity, oversight and redress mechanisms.

The warning about function creep is particularly relevant.

A system created to facilitate travel could potentially acquire additional functions over time.

Today, ENBIC may primarily answer:

“Who is this traveller?”

Tomorrow, policymakers could be tempted to ask:

“Where has this person travelled?”

Or:

“Which government services has this person accessed?”

Or:

“Which security databases should this identity be compared against?”

Some of those uses may be lawful or legitimate under particular circumstances.

But the central principle remains:

A new use of biometric data should not simply be assumed because the technology makes it possible.

What does ECOWAS law say?

West Africa is not without data-protection rules.

The ECOWAS Supplementary Act on Personal Data Protection establishes principles governing the processing and transfer of personal data.

Among other provisions, it requires information about the identity of the data controller and the purposes for which information is being processed, and places conditions around transfers of personal data to countries outside ECOWAS.

ECOWAS has also acknowledged that its existing regional data-protection framework requires updating. In November 2024, experts from member states and national data-protection authorities met to validate a revised Supplementary Act designed to respond to changes in the digital environment.

That development is revealing.

Technology has moved rapidly.

Regional governance is trying to catch up.

And ENBIC sits directly in that gap.

Nigeria has its own privacy obligations

Nigeria’s Data Protection Act 2023 provides another layer of protection.

The Nigeria Data Protection Commission says the law regulates the processing of personal data, protects data subjects’ rights and establishes an independent regulator responsible for supervising data controllers and processors.

The NDPC also lists rights including the right to be informed, access personal information, seek rectification, object to processing, restrict processing and report concerns to the supervisory authority.

This creates an important accountability chain for ENBIC in Nigeria.

If NIS is collecting the information, citizens should be able to understand:

what information is collected;

why each category is collected;

who determines the purposes of processing;

which organisations process the information on behalf of NIS;

whether information is transferred outside Nigeria;

how long the information is retained;

who can access it;

how breaches are reported;

and what remedies are available to citizens.

The NIS privacy policy states that personal information may be shared with government agencies, security services, service providers, international immigration or border authorities where legally required, and law-enforcement agencies responding to valid requests or legal processes. It also says transfers outside Nigeria may occur where necessary for service provision or international cooperation, subject to legal and security safeguards.

For an ordinary citizen, however, “where legally required” should not end the conversation.

The next question should be:

Which law, which authority and which procedure?

The unanswered IOM questions

IOM’s involvement therefore deserves scrutiny—not because participation proves ownership, but because international organisations operating around identity systems can occupy influential positions in programme design, technical assistance, migration management and border governance.

The public deserves clarity on several issues.

1. Does IOM have any access to ENBIC biometric records?

If yes, what categories of information can it access?

Is the access direct or through another institution?

Is the access temporary, permanent or project-specific?

2. Is IOM a data controller, joint controller, processor or simply a programme-support organisation?

These are not interchangeable descriptions.

Each can carry different legal responsibilities.

3. Where is the data stored?

Is Nigerian ENBIC data physically hosted in Nigeria?

Is any component hosted elsewhere?

Who operates the servers?

Who holds encryption keys?

4. Can data move between ECOWAS countries?

If yes, what information is exchanged during border verification?

Does the receiving authority obtain the complete biometric record, a verification response, or only limited identity information?

5. What happens when an international partner leaves a project?

Does it retain copies?

Are those copies destroyed?

Who independently verifies deletion?

6. What happens after a data breach?

Who must notify affected citizens?

Which regulator investigates?

Which institution pays for remediation?

And can a citizen obtain compensation?

These questions are not accusations.

They are basic governance questions for any regional biometric system.

The sovereignty question

There is also a deeper issue.

Biometric identity systems are increasingly becoming part of the infrastructure through which governments understand their populations.

Whoever controls the infrastructure does not necessarily “own” the people—but can acquire significant power over how people are identified, verified and permitted to move.

That is why data governance should be treated as part of national and regional sovereignty.

Nigeria’s immigration authorities are already emphasising cybersecurity, data privacy and protection of critical information infrastructure as part of their digital transformation agenda.

The same principle should apply to regional identity infrastructure.

If ENBIC is to become a trusted regional credential, citizens need more than assurances that the card is secure.

They need to know who is accountable when something goes wrong.

The danger of confusing integration with unrestricted data sharing

There is a seductive logic behind digital integration:

One region.

One identity standard.

One interoperable system.

But regional integration does not have to mean unlimited information sharing.

A well-designed system can allow a border officer to verify that a traveller is legitimate without exposing every piece of information contained in that person’s identity profile.

This is where data minimisation becomes important.

Collect only what is necessary.

Use it only for clearly defined purposes.

Give access only to those who need it.

Keep it only as long as necessary.

And create an auditable trail showing who accessed what information and why.

These safeguards become even more important because the ECOWAS vision for ENBIC is broader than merely producing a plastic card. The Commission says the card is increasingly being developed as an instrument capable of supporting identification and other services beyond border travel.

The broader the system becomes, the greater the need for clearly defined boundaries.

A card is not the real story

The real story is the database behind the card.

The traveller sees a photograph, name, card number and security features.

Behind that card could sit fingerprints, facial information, biographical records and links to other identity systems.

That invisible infrastructure is where the real power lies.

And that is why the central question surrounding ENBIC should not simply be:

“Will this card make travelling across West Africa easier?”

It probably can.

The more difficult question is:

“Can West Africa build a regional identity system that makes movement easier without making citizens’ most sensitive information vulnerable to unnecessary access, indefinite retention or uncontrolled secondary use?”

That is the test that matters.

What IOM’s role should mean—and what it should not mean

IOM’s long-standing involvement in ENBIC and related identity-management discussions makes the organisation an important stakeholder in understanding the project’s development. But the available evidence does not establish that IOM owns Nigerian citizens’ ENBIC biometric data. ECOWAS and Nigerian authorities remain central actors in the system’s institutional and operational architecture.

That distinction should be preserved.

At the same time, international involvement should never be treated as a substitute for public accountability.

If IOM provides technical assistance, the public should be able to know the boundaries of that assistance.

If it processes information, the legal basis should be clear.

If it has no access to biometric databases, that should be clearly stated.

If it does have access, citizens deserve to know under what safeguards.

And if it does not control the data, the institutions that do should be clearly identified.

The questions West Africa cannot afford to postpone

ENBIC promises to make borders less cumbersome.

But digital borders can become invisible in another sense: citizens may never see the databases through which they are being identified.

That is precisely why transparency must precede convenience.

The ECOWAS Commission has acknowledged that the implementation of ENBIC requires clear institutional arrangements, legal considerations, infrastructure, risk management and coordination among stakeholders.

Those arrangements should be visible to the people whose identities are being digitised.

West Africans should not have to discover after a breach, a misuse or a disputed border decision who had access to their information.

They should know before handing over their fingerprints.

The fundamental principle is simple:

The citizen may carry the card, but the real power lies with whoever controls the data behind it.

And as West Africa moves toward increasingly interconnected identity systems, the question of who controls that power—and who can hold them accountable—must become part of the ENBIC conversation.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version