This article explores how digital identity systems fail when personal data changes, highlighting legal rulings, infrastructural inertia, biometric limitations, and the resulting social exclusion and systemic risks.
Download the slides: https://www.slideshare.net/slideshow/when-digital-identity-mismatches-cause-systemic-harm-infrastructure-challenges-and-legal-gaps/288980240
A government database is not a neutral record of who you are. It’s an infrastructure, and like all infrastructures, it embeds assumptions about what stays fixed and what is allowed to change. When those assumptions are wrong, the people who fall outside them don’t experience a glitch. They experience what I’ve come to think of, following the structural violence literature, as a slow, distributed harm, one that rarely announces itself as a single event, but accumulates instead across a thousand small refusals.
This is the story of what happened after India’s Supreme Court tried to change one of those assumptions, and what that reveals about identity infrastructure more broadly.
NALSA and the Limits of Legal Recognition
In National Legal Services Authority vs Union of India (2014), the Court recognised transgender people as a third legal gender category and affirmed a right to self-identification without surgery, without a medical certification, and without judicial sign-off. When read against the global landscape of gender recognition law at the time, this was a remarkable decision. It remains one of the most expansive judicial statements on gender self-determination anywhere.
However, the judgement itself is not an infrastructure, and infrastructures do not update themselves. The participant in my study were doctors, welfare officers, transgender people, and NGO workers. They told me how their lives and work had been shaped in the ten years after this change, how the digital identity infrastructure developed gradually, and how it played a major part in shaping what the law says a person is entitled to. At the database level, in the structure of an application form, or the discretion exercised by a registration clerk, we can see how the slow changes to an infrastructure can lead to people being excluded. Leigh Star made this point about infrastructure decades ago, showing how it only becomes visible when it breaks. For most people, an identity system is invisible precisely because it works. For a transgender person in post-NALSA India, the system becomes visible constantly, at every counter, every renewal, every moment where a self-identified gender meets a field that was never built to hold it.
The Category Was Never Built For This
Bowker and Star spent years documenting how classification systems render people unintelligible within a system. They looked at the ways that a category built for one purpose gets weight added to it by every system downstream. Aadhaar’s gender field is a small, blunt example of this. It’s one binary value, entered once, and it quietly holds up the banking and financial services system, the welfare system, the health system, the education enrollment system, and many other bureaucratic systems in the public and private sector. No one sat down and decided to exclude transgender people from Aadhaar and the health and welfare systems. They just never asked whether a value such as gender would needed to be changed the way that a name might need to be changed after registration.
NALSA exposed how brittle that design assumption already was. The ruling changed overnight, but it took the infrastructure a decade to catch up. Adding a third value to a database field is trivial engineering. But it’s not trivial to propagate changes to a value correctly through every downstream system that depends on the original record. An Aadhaar number touches bank details, voter registation records, school records, the PAN financial services number, and welfare enrollment. Each of these systems was built independently, on its own timeline, often by different vendors, and each carries the same unexamined assumption of stability.
The result, the for person at the centre of it, is not one singular failure but a cascading of failures and breakdowns. A gender marker updated with one authority remains unchanged with three others. Each disagreement becones its own small confrontation. An account might be flagged for review, a benefit claim delayed or cancelled, a hospital record that doesn’t reconcile and shapes continuation of care for the patient. These systems were never designed to expect a person to change.
Where Law Meets The Registration Desk
This is where I think an information systems lens adds something to the legal literature. NALSA’s language on self-identification was unambiguous. However, the registration desk, the bank branch, the welfare officer, these are a separate empirical question, and one that I’ve spent considerable fieldwork time on. Local officials, working with outdated departmental circulars or simply being unfamiliar with the judgement, have continued to demand medical proof that the ruling explicitly waived.
I’d argue that this is where the actual work of exclusion happens. It’s not in the statute. It’s at the registration desk, months or years after the statute was decided. The law is not self-executing. It has to be carried, imperfectly, through layers of bureaucratic infrastructure and human discretion, and at every layer there is room for the original intent to be diluted, misunderstood, or simply ignored. Studying identity systems only at the level of policy systematically misses this because it only asks whether the right law exists. To see where recognition actually breaks down, you have to look at the infrastructure itself, and the people operating it.
Biometric Infrastructure and the Assumption of a Fixed Body
Biometric identity systems using fingerprints and facial matching carry their own version of this problem. They’re built on an implicit model of the body as stable and fixed over time. Someone whose facial presentation changes during transition, or whose biometric enrollment predates that transition, can trigger automated non-matches that have nothing to do with fraud and everything to do with a system encountering a case its designers never modelled. Nobody programmed the system to distrust transgender bodies. But a false non-match doesn’t feel like an accident to the person standing at the counter. It’s the direct, traceable consequence of a design choice that assumed away the very possibility of bodily change.
Toward a Different Frame
I want to end where the next piece in this series will pick up. The dominant frame in digital identity work treats exclusion as a problem of absence, asking who lacks an ID, and how do we enrol them. That framing has done very tangible good. However, it also obscures a second, distinct failure mode, one that doesn’t show up in enrolment statistics at all. That’s the mode of failure that this series is interested in. Not the missing ID, but the ID that stops matching the person holding it.
That’s not a legal problem anymore. NALSA settled the legal question a decade ago. It’s an infrastructural question. It’s a question that involves updating workflows, propagating the data changes across sytems that were never meant to talk to each other in this way. It’s also a question of building institutional trust that has to be rebuilt one registration at a time. In the next video in this series, I’ll look at what the costs are for the people caught in the gaps of an infrastructure.
If your organisation manages identity, registration, or eligibility systems, the gap between what policy promises and what your infrastructure can actually deliver is where the risk and the harm accumulates. I work with public and private institutions to audit their systems for exactly this kind of drift between legal entitlement and operational reality. Get in touch to talk about whether your systems might be carrying assumption and biases that they were never designed to hold.