Author: Samuel Asiamah, CISSP — Founder & Principal Consultant, SKFT Solutions LLC
I was not planning to write about the Ghana Card that day.
I had gone to an MTN service center to purchase an internet service. After presenting my Ghana Card, I expected the process to be straightforward. Instead, I was asked to provide my fingerprint using a handheld mobile device.
What caught my attention was not just the fingerprint scan. It was the device itself. Employees carried the biometric devices around the service center much like they would carry their own smartphones. As a customer, I had no way of knowing how the device worked, where the data was being transmitted, or what security controls were in place. That, perhaps, is a discussion for another day.
As the employee completed the registration, one question kept running through my mind:
If my fingerprints are already securely associated with my Ghana Card, why are they being collected again?
I asked the representative, hoping to better understand the process. They could not really explain why another fingerprint capture was necessary. We completed the registration, but I left thinking about that simple question.
As someone who has spent more than two decades working in cybersecurity and enterprise infrastructure, I could not help wondering whether we are creating additional repositories of one of the most sensitive forms of personal data a citizen can possess.
Why This Matters to Me
I support strong identity verification. Banks, telecom providers, government agencies, and other institutions all have a responsibility to verify who they are dealing with. Identity verification helps reduce fraud, protect customers, and improve trust in digital services.
My concern is not about verification. My concern is about unnecessary collection.
Fingerprints are different from passwords. If my password is compromised, I can change it. If my fingerprints are compromised, I cannot replace them. That is why every organization collecting biometric data has an even greater responsibility to protect it.
Ghana has invested heavily in the Ghana Card as a national identity system. If the Ghana Card is now accepted for banking, SIM registration, taxation, healthcare, passports, pensions, and other services, then it is fair for citizens to ask how much biometric data private companies still need to collect and store on their own.
The Question Behind the Ghana Card
The Ghana Card was supposed to help Ghana move toward a trusted national identity system. To me, that means reducing identity confusion, reducing duplicate records, and giving institutions a reliable way to verify who someone is.
That is why the fingerprint question matters.
If the National Identification Authority already maintains the authoritative identity record, should every telecom operator also maintain its own biometric records? Or should the telecom provider verify the customer securely against the national identity system without keeping more sensitive data than necessary?
I do not claim to know every legal, technical, or regulatory requirement behind Ghana's SIM registration process. There may be operational reasons for the current approach. But I do believe the question deserves a serious public conversation.
Could Verification Be Enough?
This is the question I keep coming back to.
In a privacy-conscious identity system, the goal should be to verify identity without collecting more information than needed. If a telecom provider only needs to confirm that the person in front of them matches the Ghana Card presented, then perhaps the system should focus on secure verification rather than repeated biometric collection.
That approach could reduce unnecessary duplication of sensitive data. It could lower cybersecurity risk. It could also strengthen public confidence in the Ghana Card as the country's trusted identity foundation.
The more organizations store biometric data, the more places that data can be exposed, mishandled, or misused. That does not mean organizations are acting carelessly. It simply means that every additional database creates another security responsibility.
Biometric Data Is Not Ordinary Data
When people talk about privacy, it can sometimes sound abstract. But biometric data is personal in a very real way.
A name can be changed. A phone number can be changed. A password can be changed. A fingerprint cannot.
That is why biometric collection must be treated differently from ordinary customer information. It should be collected only when necessary, stored only for as long as required, protected with strong security controls, and governed with clear accountability.
Citizens should be able to understand why their biometric data is being collected, where it is stored, who can access it, how long it will be retained, and what happens if there is a breach.
Those are reasonable questions in any digital society.
My Cybersecurity Concern
From a cybersecurity perspective, the issue is not only whether a company has good intentions. The issue is risk.
Every system that stores sensitive data becomes a target. Every database needs access controls, encryption, logging, monitoring, backups, incident response, audit trails, and governance. The more sensitive the data, the higher the standard should be.
If biometric records are stored across multiple organizations, then Ghana's identity ecosystem becomes harder to secure. A weakness in one organization could create consequences that affect citizens far beyond that organization.
That is why I believe Ghana's digital identity progress must be matched by strong privacy and cybersecurity practices across every institution that touches identity data.
What I Hope Ghana Gets Right
I believe the Ghana Card is one of Ghana's most important digital transformation projects. It has created a stronger foundation for identity verification, digital banking, telecom registration, public service delivery, and national planning.
But the more important the Ghana Card becomes, the more carefully the identity ecosystem around it must be governed.
Ghana should not only ask whether people have registered. It should also ask whether institutions are using identity data responsibly.
Are organizations collecting only what they need? Are they protecting biometric records properly? Are citizens being told clearly how their data is used? Are private companies creating unnecessary duplicate databases? Are regulators providing enough transparency and oversight?
My Perspective
I wrote this article not to criticize Ghana's digital identity program, but because I believe it is too important not to question carefully.
The Ghana Card has the potential to become one of the strongest foundations of Ghana's digital future. But digital trust is not built by technology alone. It is built by governance, security, transparency, and respect for citizens' personal information.
My concern is simple: if Ghana has already built a national identity system, then we should be careful not to weaken public trust by allowing unnecessary collection and duplication of biometric data.
Strong identity verification is necessary. But verification should not automatically mean every institution must collect and store fingerprints.
The future of Ghana's digital economy depends not only on identifying citizens, but on protecting them.
About the Author
Samuel Asiamah, CISSP
Founder & Principal Consultant, SKFT Solutions. With more than 20 years of experience in enterprise infrastructure and cybersecurity, Samuel provides strategic advisory services to governments, regulated industries, and organizations building resilient digital ecosystems across Africa and beyond.