Charles III announced in the King's Speech that the United Kingdom will adopt digital identifications. The proposal envisions a voluntary app that would let citizens verify their identity for government procedures, renting housing, or buying alcohol. The government has been laying the groundwork; this announcement gives it symbolic momentum.
The word voluntary always shows up at the start.
I know that pattern. It's introduced as a convenient option. The infrastructure gets built around it. Over time, the path without that option grows more complicated. It's not a conspiracy. It's simply how complex structures tend to evolve.
It's worth looking at what's happening in other countries, because the models aren't the same, and the differences matter.
France has had France Identité for years now. The model links the physical document to the app via NFC and keeps data on the user's device, according to official statements. CNIL has shown real capacity to halt initiatives it deemed invasive.
Estonia offers a mature case. They've maintained mandatory digital identity for years and let every citizen check exactly who accessed their data and when. That active transparency changes the trust equation entirely.
Mexico is moving forward with the SAT's e.firma. The tool provides an electronic signature with a solid cryptographic base for tax procedures and some government services. The challenge isn't so much technical as it is institutional trust. Past incidents involving exposed electoral data leave questions that aren't easy to answer.
The UK carries a clear precedent. A previous project for mandatory physical ID cards faced widespread rejection and was dismantled. Now they're back with a digital, voluntary version. That institutional memory should shape the design itself, not just the messaging.
What separates an acceptable model from a risky one comes down to three concrete questions: who accesses the data and under what conditions; whether there's an auditable log the citizen can check directly; and whether there's an independent authority with real power to sanction abuses.
France offers partial answers. Estonia stands out for its solidity. Mexico shows technical progress but fragmented execution. The UK is still at the stage of promises.
The technical approach is decisive. A centralized design concentrates all information on government servers. Decentralized verifiable credentials let the user decide what data to share, without needing a connection to a central database for validation. This second path is standardized, and several countries are exploring it. The choice between state control and citizen control defines the outcome. History offers varied examples, though not always encouraging ones.
The British announcement coincides with practical needs that emerged after Brexit around identity verification for employment and services. A digital ID could ease real administrative friction. The risk remains that the solution to one concrete problem ends up creating bigger privacy problems.
From Mexico, these discussions arrive with a layer of skepticism that seems healthy. We've seen how state digital infrastructures drifted from their original purposes. That doesn't make it impossible to design these models well. It just demands that the standard of evidence be high.
I still don't have a clear read on the final balance. If a well-designed digital identity can genuinely include those currently excluded by outdated documents or geographic distance, then does rejecting these models on principle end up protecting the most vulnerable — or simply leaving them out of services they deserve?
Sources
1. UK Government — Digital Identity and Attributes Trust Framework, GOV.UK (2023-2024)
2. CNIL — France Identité: analyse de la conformité, Commission Nationale de l'Informatique et Libertés
3. e-Estonia — X-Road and the Digital Identity Infrastructure, e-estonia.com
4. SAT México — Documentación técnica de la e.firma, sat.gob.mx
5. W3C — Verifiable Credentials Data Model 2.0, w3.org/TR/vc-data-model