up:: For a general audience

Are refugee records safe?

This is the hardest case in the entire exposure landscape, and it is the one nobody has written about.

Every other category in this Guide involves data that is sensitive, long-lived, or hard to replace. Refugee biometric records are all three at once, held on people who fled a government, and that government is the party with the clearest reason to want them.

What is actually held, and where?

UNHCR, the UN Refugee Agency, runs BIMS, its Biometric Identity Management System. It is the primary biometric system in the agency’s registration ecosystem and is used in 93 countries.

For each person it captures a photograph, 10 fingerprints and 2 irises, stored in a centralized consolidated database to establish a globally unique identity, and paired with records including address, profession and education. BIMS sits inside a wider system called PRIMES, the Population Registration and Identity Management EcoSystem.

Reporting from 2019 records biometric verification in use for over 7 million refugees and asylees across 60 countries, and records including fingerprints, iris scans and facial biometrics being shared with United States Citizenship and Immigration Services for resettlement consideration.

Data protection is governed by UNHCR’s General Policy on Personal Data and Privacy, issued by the High Commissioner.

Sources: UNHCR, Keeping UNHCR’s Biometrics System up to date · UNHCR, Introducing PRIMES · Biometric Update, August 2019.

Why is this the hardest case?

Four things stack here that never stack together anywhere else.

Biometrics cannot be reissued. A leaked password gets changed and a compromised card gets replaced. A person has one set of fingerprints and two irises for life. There is no version 2 of a face.

The confidentiality horizon is a lifetime, and then longer. Refugee status can persist for decades, resettlement processes run for years, and family links recorded during registration outlive the individuals in them.

The population was registered precisely because it was in danger. These are records of people who fled a state, created at the moment of greatest vulnerability, often naming where they went and who they went with.

And the adversary with the clearest motive is identifiable. For most data, the question of who would want it is speculative. Here it is not. The party with the strongest reason to obtain a register of who fled, where they are now, and who they are related to is the government they fled. That is not an accusation against any particular state. It is the structure of the situation.

Put together: unreissuable identifiers, a lifetime horizon, a population selected for vulnerability, and a motivated adversary who may already be a state. Harvest Now Decrypt Later describes recording encrypted traffic today to decrypt it later. This is the case that model was built to describe, and almost nobody applies it here.

So is the data actually at risk?

Nobody outside the agency can say, and that is the finding.

What can be established from outside: like almost every large organization, UNHCR’s public-facing infrastructure is operated by commercial providers, and the posture of those public surfaces is set by the provider rather than by the agency. That pattern is covered in What an international organization needs to know.

What cannot be established from outside: how BIMS and PRIMES themselves protect data in transit between registration sites, regional systems and partner governments. Those are internal systems. They are not externally visible and no published assessment of their cryptographic posture appears to exist.

This page is careful about a distinction that matters

Measuring a public website or mail server says nothing about the systems holding biometric records, and treating one as evidence of the other would be wrong. The honest statement is that the question has not been asked in public, not that an answer is known.

The absence is the story. For a dataset with this risk profile, held across 93 countries, the fact that no public analysis exists is itself a finding.

What would a good answer look like?

The same three questions this Guide puts to any operator, adapted:

  1. Does registration data travel between sites, regional systems and partner governments under cryptography that would survive a future quantum computer?
  2. Where records are shared onward with national authorities, whose cryptography governs that transfer, and for how long is it retained?
  3. Can the systems holding this data have their cryptography changed without rebuilding them?

Question 3 is the one that decides how bad the answer to question 1 is. A system that can be updated has a problem. A system that cannot has a permanent one.

Is anyone responsible for asking?

No post-quantum mandate reaches a UN agency. OMB M-26-15 binds US federal executive departments. National timelines bind national systems. International organizations sit outside all of them, and the humanitarian agencies operate under their own data protection frameworks rather than under any state’s cryptographic requirements.

This is the same structural gap this Guide documents at city and county level, appearing again at the opposite end of the scale. See What is not legislated yet.

Questions people ask

Is UNHCR doing something wrong here? Nothing on this page says so. The agency publishes its systems, publishes a data protection policy, and is more transparent about biometric practice than most governments. The gap is that no external framework requires anyone to ask this specific question, so it has not been asked.

Isn’t the data encrypted? Systems of this kind use encryption in transit and processing. The question is which encryption, because the concern is not whether data is protected today but whether recorded traffic stays protected in 20 years.

Why would anyone bother recording this? Bulk collection is cheap, storage is cheap, and the value of a register of displaced people to a state that displaced them does not decay. Retrospective decryption of long-lived personal records is the exact case the threat model describes.

Could this be published without putting anyone at more risk? Yes, and it should be, because nothing here identifies a person, a location, or an exploitable weakness. It names a category of data and a question that has not been asked.

What about other humanitarian agencies? WFP, UNICEF, IOM and others operate registration and beneficiary systems with similar characteristics. This page names UNHCR because its biometric program is the largest and the best documented.

Where to go next

Go deeper into the technical detail

Harvest Now Decrypt Later explains the recording-now model in full.

These open the Post-Quantum Field Guide, a separate site written for security professionals.


Last verified 2026-08-10 · Maintained by Addie LaMarr, LaMarr Labs.