I posted breaking news on X, but on September 26 the UK government announced a plan to introduce digital ID through the “GOV.UK digital wallet.” It has triggered a major debate about digital society, sharply pitting demands for efficiency against concerns about privacy violations.

Most notably, the policy would make use of this digital ID for “Right to Work checksmandatory. Why has a proposal presented as a free digital ID scheme provoked such a strong backlash?

What Is the UK Digital ID Wallet?

The UK government’s GOV.UK Wallet is a mechanism for securely storing and presenting government-issued credentials, such as driving licences, on an individual’s smartphone.

1. Objectives of Introduction (the Government’s Case)

The government mainly emphasizes the following benefits.

  • Reducing illegal employment: Digital authentication prevents unlawful employment using forged documents1
  • Simplifying identity verification: Complex paper documents and in-person checks are accelerated digitally.
  • Improving citizen services: It makes access easier not only to public services but also to private services.

2. Background to the Backlash: Public Concerns Reflected in a Petition with More Than 1.6 million Signatures

It may all sound beneficial, but this is the UK—a country where it has long been said that governments seeking to introduce compulsory ID systems will fall. Immediately after the announcement, a parliamentary petition opposing mandatory digital ID collected more than 1.6 million signatures. Citizens’ greatest fears can be summarized in the following 2 points.

  • Risk of becoming a surveillance society: Concern that the state will compel citizens to register IDs, making their behavior and attributes easier to track.
  • Security risk: Cybersecurity expert Professor Alan Woodward warns that centrally managed ID data would become a “huge hacking target”, potentially exposing every citizen’s sensitive information at once. Such incidents may seem rare, but happen surprisingly often. The examples look like this.

Countries with a Record of Nationwide ID Database Leaks

CountryMajor leak and estimated scaleNotes
Ecuador2019: more than 20 million records (all citizens, including deceased people)Entire registries, including national IDs and taxpayer numbers
Turkey2016: at least 50 million records (equivalent to the entire population)Names, ID numbers, addresses, electoral data, etc.
South Korea2014, 2019, etc.: more than 100 million resident registration numbers leakedResident registration numbers, financial data, and other social-infrastructure IDs
EgyptReported in 2025: 77.7 million records (nationwide scale)National identification numbers, addresses, etc.
South AfricaReported in 2025: 44.5 million records (almost the entire population)Entire registries including ID numbers
Saudi ArabiaReported in 2025: 26.8 million records (almost all citizens)
China2022: more than 1 billion records (nationwide scale)Leaked from a police database
Note: Several people pointed out that India’s Aadhaar leak is absent, but it affected less than 6 tenths of the population and therefore does not belong in a record of nationwide ID database leaks.
Trends and Additional Notes
  • The Ecuador incident arose from human error in leaving an entire public registry exposed in the cloud, and included all residents plus deceased people.
  • Turkey, Egypt, South Africa, and others suffered simultaneous multinational, extremely large-scale leaks in September 2025 caused by misconfigured ID servers. Data for almost entire national populations leaked in formats matching official data structures.
  • Multiple leaks involving nationwide common numbers used for administrative purposes have been confirmed in South Korea and China.

Worldwide, countries where national ID systems are embedded in social infrastructure have repeatedly experienced leaks of entire registries.

The Complex Relationship with DIATF That Experts Are Watching

Experts were surprised by this news not only because of concerns about surveillance and leaks. More surprising was its fundamental reversal of prior policy.

To understand this digital ID policy technically and legally, one must grasp its relationship with the existing regulatory framework called the “DIATF (Digital Identity and Attributes Trust Framework)2.”

What Is DIATF (the Trust Framework)?

DIATF specifies how private companies (IDSPs/DVSs: digital verification service providers) verify users’ identity and attributes, such as age and employment eligibility, and provide them to private-sector relying parties, establishing the necessary trust rules and technical standards.

[Traditional Structure] GOV.UK Wallet → DIATF-certified private provider → private business (verifier)

[Structure Suggested by This Policy Shift] GOV.UK Wallet → private business (mandatory for RTW checks)

Under the traditional structure, multiple certified private providers, currently 52, stood in the middle. This offered privacy benefits: the government could not directly trace where an individual presented a credential, and semi-anonymous attribute verification was easy. Private businesses could also use existing technologies such as OpenID Connect. (Indeed, implementation is easier this way.)

Stakeholders worry that the shift to direct presentation from a government wallet to private businesses may let an issuer learn a user’s residence depending on how ZKP is used with a digital credential; make government tracking easier; and force DIATF-certified private providers to compete with government, potentially collapsing the industry. The government asserts freedom of choice, but debate has arisen over whether making it mandatory for employment, which directly affects people’s lives, will effectively bias choice toward GOV.UK Wallet.

Above all, uncertainty about the technical and operational framework—”So how will this work?”—is also fostering suspicion.

Relationship with DIATF: 3 Scenarios

What will the relationship between DIATF and GOV.UK Wallet become? Here are 3 possible scenarios.

Scenario A: Complementary Model

DescriptionGOV.UK Wallet permits presentation to private businesses while retaining a flow through DIATF-certified DVSsBenefitsMaintains the role of existing DIATF-certified providers and permits mutual complementarityRisksImplementation complexity, higher costs, and transitional confusion

Scenario B: Government-led Model

DescriptionGOV.UK Wallet prioritizes presentation to private businesses, reducing DIATF providers to a supporting roleBenefitsStrengthens government control and gives the state the lead in presentation processesRisksPrivate-provider opposition, reduced appetite for investment, and competition-policy problems

Scenario C: Coexistence and Choice Model

DescriptionUsers and businesses may choose GOV.UK Wallet or a DIATF-certified walletBenefitsMaintains competition and guarantees freedom of choiceRisksComplex interoperability and the burden of developing standards

The government’s official position repeatedly uses the word “choice,” suggesting that Scenario C, the coexistence model, is the main path.

Important Practical Issues

? Security Risks

The security standards to be used are unknown, so this remains uncertain.

⚖️ Development of the Legal Framework

Making digital ID mandatory requires supporting legislation:

  • Clarifying rules for wallet presentation
  • Redesigning certification criteria
  • Obligations and penalties

? Interoperability

Technical specifications enabling mutual presentation and verification between GOV.UK Wallet and DIATF-certified wallets are essential:

  • OpenID4VP (OpenID for Verifiable Presentations)
  • SD-JWT-VC (Selective Disclosure JWT for Verifiable Credentials)
  • API standardization

? Inclusion

  • Support for people without smartphones
  • Consideration for older and disabled people
  • Alternative means, such as physical cards

How Does It Differ from Digital IDs Elsewhere?

Comparing the UK proposal with digitally advanced countries and EU initiatives reveals its distinctive features and challenges.

DimensionUK (GOV.UK Wallet)EU (EUDI Wallet)Estonia
Adoption driverPromoting adoption through mandatory Right to Work checksCross-border interoperability between member states and general-purpose use casesAlready a foundation of citizens’ lives, with high adoption and diverse uses
Technical foundationTransitioning to two coexisting routes: wallet presentation and DIATFDeveloping interoperability standards based on ARF/HLRMature public-private coordination through PKI and X-Road
GovernanceDIATF, with operating rules in use-case-specific supplementary codesDeveloping an EU-wide certification scheme through ENISADecentralized, highly transparent data coordination enabled by X-Road
Degree of compulsionStrong direction toward mandatory use for a specific purpose, RTWEmphasizes user sovereignty, with use voluntary in principleAlready established as de facto social infrastructure

This comparison shows that while the EU emphasizes “user sovereignty” and “generality” and builds interoperability over time, the UK proposal seeks rapid nationwide adoption through mandatory use for Right to Work checks, applying strong regulatory pressure and reflecting a more “top-down” design philosophy.

Technical Implementation Issue: Interoperability

The practical focus going forward is how the technology adopted by GOV.UK Wallet will work with global standards.

Whether the UK wallet fully supports the international standards becoming mainstream in the EU, including OIDC4VP, SD-JWT-VC, and mdoc, and permits mutual recognition with private wallets will be key to competition and convenience. Specifications favoring only the government wallet risk chilling the private ecosystem.

Conclusion: The Future of Digital ID Depends on Design

The UK digital ID wallet offers the major benefit of efficiency, but contains risks because too much remains unknown to judge whether privacy and freedom will be secured.

Digital ID succeeds or fails not according to whether it is introduced, but according to the design philosophy of “who manages the data and who controls presentation”. Can the UK overcome the risk of creating a huge hacking target and concerns about surveillance, and earn citizens’ trust? The answer will depend on the transparency of the concrete implementation and legal framework to be disclosed. Future developments deserve attention.

[Key Terms]

  • GOV.UK Wallet: the UK government’s digital ID wallet.
  • Right to Work (RTW): verification of the right to work. Use for this check is now moving toward being mandatory.
  • DIATF: the UK trust framework, or regulatory framework, for private digital ID service providers.
  • VC / SD-JWT: international technical standards for digital credentials.

Footnotes

  1. I suspect one factor is that Nigel Farage’s populist party Reform UK has now become the relatively 1st-largest party.
  2. Digital Identity Attribute Trust Framework

Related posts

GOV.UK Wallet and One Login

What Is GOV.UK Wallet? GOV.UK Wallet is a digital document management app under development by the UK government. It was revealed in the context of digital…

OpenID · 2025-03-13