ailiteracynepal 🇳🇵
Text size

Chapter 03 · Section I · 17 min read

What is being collected — ID, KYC, biometrics, location

The 2026 reality is not that any single Nepali database is dangerous; it is that the country has quietly stood up the raw material for a national profile of every citizen, and almost no one is keeping a map of the pieces.

If you walked through Singha Durbar today and asked a senior bureaucrat what data the Nepali state holds on its citizens, you would get a confident answer. It would also be wrong — not because the bureaucrat is lying, but because nobody, in any single office, has the full map. Pieces of you live at the National ID Management Centre. Other pieces live at Nepal Rastra Bank through your bank’s KYC file. Others sit on a server in Mumbai because your wallet provider runs on AWS. Others are with Nepal Telecom because you carry a phone. Each office knows its own piece. Almost none of them knows what the other offices know. The story of privacy in Nepal in 2026 is the story of those pieces, what they would say if they were stitched together, and the fact that nobody has yet decided who is allowed to do the stitching.

The National ID, and what makes it different

The National ID programme, run out of the Department of National ID and Civil Registration, is the closest thing the country has to a single citizen index. Roughly two-thirds of eligible adults are now enrolled. The enrolment record is not light: a ten-finger fingerprint scan, an iris scan of both eyes, a high-resolution face photograph, a signature, the standard demographic block (name, date of birth, parents, spouse, address), and a household linkage that ties each individual to a household number and, through it, to siblings, parents, and children.

Take a moment with that linkage. Most foreign ID systems index people. The Nepali system indexes people inside families. That is reasonable for a country where land, inheritance, citizenship, and social-security entitlements all flow through household relations. It is also, for a model that wants to predict things about you, an enormous structural gift. If the bank only knows your salary but the National ID knows your household, the bank — given access — knows your salary in the context of your father’s land, your sister’s loan, your brother-in-law’s default. The unit of analysis becomes the family, not the person, and the family did not separately consent.

What banks and wallets actually keep

Open an account with any commercial bank, or onboard onto eSewa, Khalti, IME Pay, or Fonepay, and you will be asked for: a selfie (often a “liveness” video of you turning your head), a photograph of your citizenship or National ID, a photograph of a utility bill or rent agreement, and — quietly, in the background — your device fingerprint, your IP at the moment of onboarding, and your GPS location if you granted it. NRB’s customer-due-diligence rules require the bank to keep these for at least five years after the relationship ends. In practice, they are kept indefinitely.

Layer the transaction log on top. Every wallet top-up, every QR payment to a tea shop, every salary transfer creates a row in a database with a timestamp, a counterparty, an amount, and — increasingly — a merchant category. After two years of regular use, an eSewa or Khalti file describes a person with disconcerting precision: where they buy lunch, which clinic they pay, which temple they donate to, which relative they remit to, when their salary lands, when it runs out.

Telecom, health, and education — the next three layers

Nepal Telecom and Ncell hold call detail records, SMS metadata, and the cell-tower trace of every active SIM. A cell-tower trace is not GPS, but in urban Kathmandu, the towers are dense enough that the trace pins you to a few hundred metres. Across a week, the pattern of towers your phone touched is a near-perfect map of where you live, where you work, where you pray, and who you visit. Mobile-money behaviour on the same SIM (telco-billed top-ups, NTC’s own wallet) adds a transactional layer to the location layer.

Health is digitising faster than people realise. The Health Management Information System (HMIS) is moving district hospital records, vaccination registries, and increasingly outpatient visits into electronic form. Patan Hospital, Bir Hospital, and the Kathmandu Medical College network already run electronic medical record systems. The clinical data — diagnoses, prescriptions, lab results — is some of the most sensitive a person ever generates, and it is now sitting in databases administered by people most patients have never heard of.

Education is the quietest layer and arguably the fastest-moving. Private schools across Kathmandu, Pokhara, Biratnagar, and Butwal have rolled out digital classrooms — attendance apps, homework platforms, AI-tutor wrappers, parent-communication apps. Each one collects a behavioural trail on a minor: when they log in, what they answer, what they fail, how long they pause before answering. Most of these platforms are foreign-built; most of the data sits abroad; almost none of the parents have read the terms.

The aggregation problem, stated plainly

Look at any one of these datasets in isolation and you can write a defensible justification for it. The National ID is for service delivery. KYC is for anti-money-laundering. Cell-tower records are for billing and network operations. HMIS is for public health planning. School platforms are for learning. Each is “fine.”

The aggregation problem is what privacy law in mature jurisdictions exists to manage. Nepal has, at the time of writing, no equivalent of the EU’s GDPR, no equivalent of India’s DPDP Act in full force, and no dedicated data-protection authority with staff and a budget. The Individual Privacy Act, 2018 exists on paper but lacks the enforcement machinery — and, more importantly, the dataset-level imagination — that the current moment requires. The state is building the raw material faster than it is building the guardrails.

Why biometrics are categorically different

There is one more point that gets lost in general privacy conversations and deserves to be said clearly. Biometrics are not passwords. A password, when leaked, can be changed. A credit-card number can be reissued. An address can change. A fingerprint cannot. An iris pattern cannot. A face, in the era of high-resolution face recognition, is your password for the rest of your life — and you broadcast it every time you stand in front of a CCTV camera.

This means that the biometric components of the National ID, the liveness videos sitting on wallet servers, and the face frames captured by every “smart” CCTV system being procured by municipalities are a different class of asset from the rest of the data. When ordinary data leaks, the harm is bounded by time and by the speed of remediation. When biometric data leaks, the harm is bounded by the lifespan of the human. There is no “rotate your iris” step. The country has not yet had the conversation that this fact requires.

Check your understanding

Quick check

Four datasets are described below. Which combination would, if joined, create the most sensitive composite profile of a Nepali citizen?

Quick check

What is the strongest reason biometric data (fingerprints, iris scans, face frames) deserves a higher protection standard than passwords or card numbers?

What comes next

If the raw material is being collected at this scale, the next question is where it physically lives — and under whose laws. Most of the datasets above sit on foreign cloud infrastructure: AWS Mumbai, Singapore, GCP, Azure. The next section is about what cross-border hosting actually means for sovereignty, lawful access, and the realistic middle path between “host everything in Nepal” and “ignore the question.”