Navigated to Humanity Centered Data | Quality of Life Data for All People
    All AI articles
    Ethics

    Data Privacy for Displaced People: What AI Systems Are Collecting in 2026

    By the Humanity Centered Data Editorial Team
    June 4, 20269 min read

    What AI Systems Are Collecting About Displaced People in 2026

    The question of data privacy for displaced people in 2026 starts with an inventory of what AI systems actually collect. Humanitarian agencies and their partners hold biometric identifiers, family composition, displacement history, protection flags, medical records, language and literacy data, mobile phone metadata where data sharing agreements exist, location at the day or hour resolution, and increasingly the transcripts and voice recordings of beneficiary interactions with chatbots and call centers. When that data feeds into AI systems, the privacy risks compound. The model itself becomes a potential leak point, the training pipeline becomes a potential leak point, and the outputs can re identify individuals even when the inputs were de identified.

    Displaced people are among the most surveilled populations in the world relative to their political power. They consent to data collection under conditions that rarely meet a strict standard of informed consent, because refusing to provide data often means losing access to assistance. The asymmetry shapes everything else.

    The Five Categories of Data at Risk

    The first category is biometric data. Iris scans, fingerprints, and facial recognition templates are now standard at major refugee registration sites. UNHCR's proGres v4 and the WFP SCOPE system both rely on biometric identifiers. The technical security of these systems is strong. The political risk is that biometric data shared with host governments or repatriation partners can be used in ways the data subject never anticipated.

    The second category is location and movement data. Mobile phone metadata, satellite based settlement detection, and increasingly the geolocation of social media posts all produce detailed records of where displaced people are and how they move. AI systems trained on this data can predict future movements with useful accuracy, which is operationally valuable and protection sensitive.

    The third category is family and household composition. Registration data captures relationships, dependencies, and household structures in detail. Combined with location data, it produces a complete picture of family networks that could be exploited by hostile actors.

    The fourth category is protection flags and case notes. Gender based violence cases, child protection cases, and survivor of torture cases are recorded in protection databases that increasingly feed into AI assisted case management tools. The narrative content of these records is among the most sensitive personal data the sector handles.

    The fifth category is the rapidly growing record of AI mediated interactions. Chatbots, call center transcripts, and language model assisted intake produce searchable records of conversations that may contain disclosures the displaced person did not realize were being stored.

    For context on how counting methods themselves shape the data layer, see AI vs Traditional Methods.

    Who Can See the Data

    The intended audience for humanitarian data is narrow: agency staff with a need to know, partner organizations under data sharing agreements, and the data subjects themselves. The actual audience is wider. Cloud infrastructure providers process the data on behalf of agencies. AI model providers can retain prompts and outputs unless contractually prohibited. Host governments often have legal authority to request data on populations within their territory. Donors sometimes condition funding on data access. Researchers request data under various sharing arrangements. Each expansion of the audience expands the surface area for misuse.

    The 2026 picture is that most agencies have improved their formal data sharing controls compared to five years ago, but the informal pathways have grown faster than the controls. Staff using consumer AI tools to summarize protection case notes, draft donor reports, or translate beneficiary communications routinely transmit sensitive personal information to third party model providers whose data handling has not been audited.

    What Responsible Data Practice Looks Like

    The leading practice in 2026 has converged on a small set of principles. Apply data minimization: collect only what is required for the specific purpose. Restrict protection sensitive data to systems that have been technically and legally assessed for the purpose. Use internal model hosting or enterprise contracts with zero retention guarantees for any AI processing of personal data. Maintain a clear and accessible record of what data is held, by whom, and for how long. Build accessible grievance mechanisms that allow data subjects to request access, correction, and deletion.

    The agencies that have moved fastest publish their data protection policies, undergo independent audits, and engage affected populations in the design of data systems. The agencies that have moved slowest treat data protection as a compliance exercise rather than a protection function. The difference shows up in the frequency of preventable incidents.

    For broader context on the accountability landscape, see Who Is Responsible When AI Gets It Wrong in a Refugee Crisis.

    Why the Stakes Are Different for Displaced People

    A privacy breach for a person with documentation, citizenship, and political voice is a serious harm. A privacy breach for a displaced person can be catastrophic. The same data that supports protection can be used to deny it. Identification data shared with the wrong actor can expose families left behind. Movement data can be used to target return policies. Protection case notes shared inappropriately can re traumatize survivors and place them in renewed danger. The privacy stakes are inseparable from the protection stakes, which is why the 2026 conversation about humanitarian AI has converged on data protection as the central governance challenge of the sector.

    Sources and Further Reading

    • UNHCR data protection policy: https://www.unhcr.org/data-protection
    • ICRC handbook on data protection in humanitarian action: https://www.icrc.org/en/data-protection-humanitarian-action-handbook
    • IASC operational guidance on data responsibility: https://interagencystandingcommittee.org/
    • OCHA Centre for Humanitarian Data: https://centre.humdata.org/
    • CALP Network on data and digital cash: https://www.calpnetwork.org/
    • Signal Code: A Human Rights Approach to Information During Crisis: https://hhi.harvard.edu/publications/signal-code-human-rights-approach-information-during-crisis
    • WFP SCOPE digital beneficiary management: https://www.wfp.org/scope

    All practices and risks described above reflect publicly documented agency policies and peer reviewed research published through mid 2026.

    🌍
    AI and Humanitarian Response

    Data Privacy for Displaced People: What AI Systems Are Collecting in 2026

    Biometrics, location, family ties, medical records, and protection flags all flow through AI systems used by humanitarian agencies. A clear look at what is being collected, who can see it, and what the risks are for displaced people in 2026.

    9 min read
    Ethics

    How AI Is Used to Detect Hate Speech and Misinformation in Conflict Zones (2026)

    A 2026 guide to how AI is being used to detect hate speech, incitement to violence, and misinformation in conflict zones, including UN, academic, and platform initiatives, with limits and risks.

    9 min read
    Ethics

    The Risks of AI in Humanitarian Work: Bias, Privacy, and Accountability (2026)

    AI tools are now woven through humanitarian operations. The benefits are real and so are the risks. A frank look at the bias, privacy, and accountability gaps shaping the sector in 2026.

    10 min read
    Impact

    How AI Is Being Used to Predict Refugee Crises Before They Happen (2026)

    Machine learning models are now feeding into UNHCR, IOM, and World Bank early warning systems. A clear look at what AI can and cannot predict about forced displacement in 2026.

    9 min read
    Impact

    AI vs Traditional Methods: How Humanitarian Organizations Are Counting Displaced People in 2026

    Registration desks, household surveys, and satellite based machine learning estimates are now being combined to count displaced populations. A practical comparison of what each method gets right and wrong in 2026.

    8 min read
    Impact

    What Is the Humanitarian AI Paradox? (2026)

    In 2026, 93 percent of humanitarian workers report using AI tools, but only 8 percent work in organizations with a fully integrated AI strategy. The gap between individual adoption and institutional readiness is the defining tension of the sector.

    6 min read
    Advertisement
    Advertisement