There is a consultation happening right now that most people have never heard of, yet it has the potential to reshape how we live, work, and interact with the state.
It is about the proposed national digital ID system.
TAKE PART IN THE CONSULTATION HERE
On the surface, it is being presented by the Labour government as something helpful, modern, convenient. A way to make services smoother, to reduce paperwork, to “put you in control.” That is how it is being sold.
But if you look more closely, this is not a minor upgrade to public services. It is a fundamental shift in how identity works in society.
And once systems like this are in place, they are almost impossible to reverse.
This Is Not Just About Convenience
We are told this is about making life easier. Fewer forms, fewer calls, quicker access. But convenience is not neutral.
Every system that promises convenience also changes behaviour, creates expectations, and gradually becomes the default. What begins as optional often becomes expected, then necessary.
You may not be forced to use a digital ID on day one.
But what happens when it becomes the fastest way?
The easiest way?
Eventually, the only practical way?
That is how change happens, quietly, gradually, without a single moment where people are asked clearly, do you actually want this?
A System That Touches Everything
This is not just about logging into government services.
The proposals include:
- Using digital ID across public services
- Linking identity across departments
- Enabling businesses and third parties to use it
- Making it central to employment checks
- Expanding it into everyday life
That means your identity could become something that is:
- Checked more often
- Shared more widely
- Relied on more heavily
- Controlled more centrally
This is not just a tool. It is infrastructure. And infrastructure shapes society.
The Risks Are Not Theoretical
Supporters will say there are safeguards, security, oversight, transparency.
But even the best-designed system cannot remove the fundamental risks:
Centralisation of identity
When identity is concentrated, the impact of errors, breaches, or misuse becomes far greater.
Function creep
Systems do not stay limited. They expand, slowly, step by step, each change justified in isolation.
Loss of real choice
If everything works better with digital ID, then choosing not to use it becomes a disadvantage.
Erosion of everyday privacy
The more identity is required, the less space remains for ordinary life without being identified.
Power imbalance
The more data and control sit in one system, the more power shifts away from individuals.
None of this requires bad intentions. It is simply how large systems evolve.
This Is Also About Your Right to Say No
One of the most important issues, and one that is barely discussed, is this:
What if you do not want a digital ID?
Not because you cannot use it.
Not because you do not understand it.
But because you do not agree with it.
A free society must allow that choice.
But if services become easier, faster, or only accessible through this system, then that choice becomes meaningless in practice.
That is not inclusion. That is quiet coercion.
Why This Consultation Matters
This is not a done deal. The government is actively asking for views, right now, before 5 May.
Consultations like this shape policy. They influence decisions, they create records of public concern, they matter far more than people think.
If only supportive voices respond, the outcome is predictable. If large numbers of people raise serious, reasoned concerns, it becomes much harder to ignore.
This is one of the few moments where ordinary people can directly influence the direction of something this significant.
What You Can Do
You do not need to be an expert. You just need to be clear.
Tell them:
- Whether you think this system is necessary
- Whether the risks have been properly considered
- Whether you are comfortable with how far it could go
- Whether you want identity to become more central in daily life
Even a short response matters. Silence, on the other hand, is often interpreted as acceptance.
This Is Bigger Than Technology
This is about the kind of society we are building. One where identity becomes:
- More central
- More required
- More visible
- More controlled
Or one where:
- Privacy is preserved
- Choice is real
- Systems remain proportionate
- Power remains balanced
These decisions are rarely dramatic. They happen through consultations like this, through small steps that add up over time.
Final Thought
The most important question is not how well this system could work.
It is:
Do we actually need it?
And if the answer is not clear, then the risks deserve far more weight than the promises.
Take part before 5 May. Make your voice heard at: https://digitalidconsultation.cabinetoffice.gov.uk/t/haveyoursayondigitalid
Because once systems like this are built, they do not quietly disappear.
TAKE PART IN THE CONSULTATION BEFORE 5 MAY 2026 HERE
You don’t need to choose and fill in all sections. Just choose the sections that you feel strongly about. Even if it’s just one section, it all helps! Say no to National Digital ID. Help us protect our freedom.
The Great British PAC shared some of their answers to the consultation if it helps.
Are there technical issuance standards… we should be building the national digital ID to?
Answer: No
Explanation:
The primary concern is not the choice of technical standards, but the necessity and proportionality of the system itself.
Focusing on technical implementation risks obscuring the more fundamental issue, whether a national digital identity system of this kind should be created at all. Questions of architecture, standards, and interoperability are secondary to concerns about privacy, civil liberties, and the long-term societal impact.
Even the most robust technical standards cannot eliminate the core risks associated with:
- Centralisation of identity infrastructure
- Expansion of data linkage across services
- Function creep over time
- Increased capacity for monitoring and profiling
Technical design can mitigate certain risks, but it cannot resolve the underlying issue that such a system fundamentally reshapes how identity is managed in society.
In addition, reliance on device-based credentials raises further concerns around:
- Loss, theft, or compromise of devices
- Dependence on specific technologies or platforms
- Exclusion of those without access to compatible devices
For these reasons, it is not appropriate to focus on refining technical standards without first establishing a clear and compelling case for the system itself, which has not been demonstrated.
Do you have any concerns about the impact… specific to your part of the UK?
Answer: England (adjust if needed)
Explanation:
While many of the concerns apply across the UK, there are important contextual considerations:
Consistency of rights and protections
Any system must ensure that individuals across all parts of the UK benefit from equal protections in relation to privacy, data use, and access to services. Divergence in implementation could lead to unequal treatment or confusion.
Risk of uneven access and digital exclusion
There are significant regional differences in digital access, infrastructure, and confidence. A system that assumes widespread digital readiness risks disproportionately disadvantaging certain communities, particularly those with limited connectivity or lower digital literacy.
Public trust and legitimacy
Trust in centralised digital systems is not uniform. Imposing or expanding such a system without broad and sustained public consent risks undermining confidence not only in the system itself, but in public services more broadly.
Pressure toward standardisation across devolved systems
Efforts to ensure interoperability across the UK may lead to pressure for uniform adoption, potentially overriding regional preferences or policy differences. This raises constitutional and governance concerns, particularly where devolved administrations may take different approaches to identity, data, or service delivery.
The key issue is not how to build this system, but whether it should be built at all. Technical refinement cannot address the fundamental concerns around necessity, proportionality, and long-term impact on rights and freedoms.
Are there technical issuance standards… we should be building the national digital ID to?
Answer: No
Explanation:
The primary concern is not the choice of technical standards, but the necessity and proportionality of the system itself.
Focusing on technical implementation risks obscuring the more fundamental issue, whether a national digital identity system of this kind should be created at all. Questions of architecture, standards, and interoperability are secondary to concerns about privacy, civil liberties, and the long-term societal impact.
Even the most robust technical standards cannot eliminate the core risks associated with:
- Centralisation of identity infrastructure
- Expansion of data linkage across services
- Function creep over time
- Increased capacity for monitoring and profiling
Technical design can mitigate certain risks, but it cannot resolve the underlying issue that such a system fundamentally reshapes how identity is managed in society.
In addition, reliance on device-based credentials raises further concerns around:
- Loss, theft, or compromise of devices
- Dependence on specific technologies or platforms
- Exclusion of those without access to compatible devices
For these reasons, it is not appropriate to focus on refining technical standards without first establishing a clear and compelling case for the system itself, which has not been demonstrated.
Do you have any concerns about the impact… specific to your part of the UK?
England
Answer: England
Explanation:
While many concerns apply UK-wide, there are specific issues in England:
Centralisation of power and accountability
England’s governance is more centralised compared to devolved nations. Introducing a national digital ID risks further concentrating control over identity, data, and access to services within central government structures, with limited local accountability.
Digital inequality across regions
There are significant regional disparities in digital access, connectivity, and confidence. A system that assumes universal digital readiness risks deepening existing inequalities, particularly in rural and economically disadvantaged areas.
Erosion of non-digital access
There is a risk that digital ID becomes the default route for accessing services, with non-digital alternatives gradually reduced in quality or availability. This creates indirect pressure to adopt the system, undermining genuine choice.
Public trust and consent
Trust in centralised data systems is uneven. Expanding identity infrastructure without clear necessity and broad public consent risks undermining confidence in public institutions more widely.
Any national identity system must take full account of regional differences in governance, infrastructure, and public trust. A one-size-fits-all approach risks undermining both effectiveness and legitimacy.
Scotland
Answer: Scotland
Explanation:
In Scotland, concerns are particularly linked to devolution and governance:
Devolved powers and policy divergence
Scotland has distinct approaches to public service delivery and data governance. A UK-wide digital ID system risks creating pressure for alignment, potentially limiting Scotland’s ability to pursue different, locally accountable approaches.
Democratic accountability
Decisions about identity systems with significant civil liberties implications should be subject to strong scrutiny within Scotland’s own democratic institutions. A centralised framework risks weakening this oversight.
Public trust and legitimacy
Trust in public systems is closely tied to transparency and local accountability. A centrally driven digital ID system may not command the same level of confidence, particularly if perceived as imposed rather than developed with meaningful Scottish input.
Digital exclusion and rural impact
Rural and remote communities face connectivity challenges. A system that relies heavily on digital infrastructure risks disproportionately affecting these populations.
Wales
Answer: Wales
Explanation:
In Wales, the following concerns are particularly relevant:
Respect for devolved governance
Wales has its own policy priorities and approaches to public service delivery. A national digital ID system risks constraining these by imposing a uniform framework that may not reflect local needs or values.
Language and accessibility
Any system must fully accommodate Welsh language requirements and ensure equal accessibility. There is a risk that centralised digital systems do not adequately reflect these obligations in practice.
Digital inequality and infrastructure gaps
Parts of Wales experience limited digital connectivity and lower levels of digital access. A system that assumes consistent access risks excluding or disadvantaging these communities.
Risk of indirect coercion
If digital ID becomes the fastest or most effective way to access services, individuals may feel compelled to adopt it, even where concerns exist. This undermines the principle of informed and voluntary participation.
Northern Ireland
Answer: Northern Ireland
Explanation:
In Northern Ireland, the proposal raises additional sensitivities:
Historical and societal context
Issues of identity, data, and state systems carry particular sensitivity. Any system that centralises identity or increases data linkage must be approached with extreme caution, given the importance of trust and consent in this context.
Trust in institutions
Levels of trust in centralised systems may differ significantly across communities. A digital ID system risks exacerbating concerns if it is perceived as intrusive or insufficiently accountable.
Cross-border considerations
Northern Ireland’s unique position raises questions about how a UK digital ID would interact with systems in the Republic of Ireland, particularly in everyday cross-border activity. This adds complexity and potential friction.
Risk of exclusion and inequality
As elsewhere, digital access is uneven. Any move toward digital-first identity risks disadvantaging those without access, skills, or trust in such systems.
Potential for disproportionate impact
Given the region’s history, there is a heightened need to ensure that any identity system cannot be used, now or in the future, in ways that could enable discrimination, monitoring, or unequal treatment.
Are there any ethical factors… deleting their digital ID?
Answer: Yes
Explanation:
The ability to delete a digital ID must be meaningful, not merely technical.
Key ethical considerations include:
Right to withdraw and genuine autonomy
Individuals must be able to delete their digital ID without suffering any disadvantage. If deletion results in reduced access to services, slower processing, or indirect penalties, then the right is not genuine.
Risk of indirect coercion
If digital ID becomes the most convenient or default way to access services, individuals may feel pressured to retain it even if they have concerns. Ethical design requires that deletion does not place individuals at a practical disadvantage.
Persistence of underlying data
Deleting a digital ID from a device does not necessarily mean the associated data is deleted from government systems. There must be clarity and strict limits on what data continues to exist, how long it is retained, and how it may be used.
Right to live without persistent digital identification
A person should be able to choose not to participate in a digital identity system at all, without being excluded or marginalised. This is a fundamental aspect of autonomy and freedom.
Are there any ethical factors… revoking (cancelling) a digital ID?
Answer: Yes
Explanation:
Revocation raises serious ethical and rights-based concerns:
Access to essential services
If a digital ID becomes linked to accessing public or private services, revocation could effectively deny individuals the ability to function in everyday life. This creates a risk of disproportionate harm.
Due process and safeguards
Any revocation must be subject to clear legal standards, transparency, and the right to challenge decisions. Without strong safeguards, there is a risk of error, misuse, or arbitrary action.
Presumption of innocence
Revocation mechanisms must not undermine the principle that individuals should not be penalised without proper evidence and process. Automated or precautionary revocation could have severe consequences.
Risk of overreach
A system that allows the state to disable or restrict a person’s ability to prove their identity digitally represents a significant concentration of power. This must be tightly limited, as it could be expanded beyond initial intentions.
Impact on civil participation
If identity becomes central to accessing services, employment, or participation, revocation risks excluding individuals from normal societal activity, which raises serious ethical concerns.
Should people be able to store their digital ID in third-party ‘digital wallets’?
Answer: No
Explanation:
Allowing third-party storage introduces additional layers of risk without addressing the core concerns of the system.
Expansion of data exposure
Involving third-party providers increases the number of entities handling sensitive identity data, raising the risk of breaches, misuse, or commercial exploitation.
Blurring of public and private roles
Identity is a fundamental aspect of the relationship between citizen and state. Extending this into private sector infrastructure risks weakening accountability and oversight.
Commercial incentives vs public interest
Third-party providers may have incentives that do not align with privacy or data minimisation, even if regulated. This creates long-term risks that are difficult to fully control.
Increased complexity and reduced transparency
Introducing multiple storage options makes it harder for individuals to understand where their data is held, who can access it, and how it is used.
System-wide risk expansion
Each additional integration point increases the overall attack surface and complexity of the system, undermining claims of security.
Government checker service
Answer: Strongly Disagree
Explanation:
The proposed checker service raises significant civil liberties concerns:
Normalisation of identity checking
Making identity verification widely available to private and third-sector organisations risks embedding routine identity checks into everyday interactions. This represents a fundamental shift toward a “show your papers” culture.
Expansion beyond necessity
Identity checks should be proportionate and limited to situations where they are genuinely required. A widely available checker service risks encouraging overuse and mission creep.
Creation of tracking infrastructure
Each “check” has the potential to generate data about where, when, and how individuals interact with services. Even if not initially used in this way, the infrastructure creates the possibility of tracking and profiling.
Private sector access to state-backed identity verification
Providing low-cost or free access to such a service risks significantly expanding its use beyond essential functions, embedding identity verification into commercial and everyday contexts.
Erosion of anonymity in daily life
The more widely identity must be verified, the less space remains for individuals to engage in lawful activity without being identified. This has long-term implications for freedom and autonomy.
The issues raised here are not simply technical or operational, they go to the heart of autonomy, due process, and the limits of state and institutional power. Systems that enable identity to be created, monitored, and revoked at scale require the highest level of scrutiny, and the risks identified have not been adequately addressed.
Are there any specific limitations you think we should set for the government checker?
Answer (free text):
Yes, but more fundamentally, the scope and necessity of a government checker service should be strictly limited from the outset.
If such a service is introduced, the following limitations are essential:
Strict purpose limitation
The checker should only be used where identity verification is legally required and proportionate. It must not be available for general or routine use in everyday transactions, as this would normalise excessive identity checking.
Prohibition on tracking and data retention
No record should be created of when, where, or by whom a check is performed, beyond what is strictly necessary for immediate verification. The system must not enable the building of activity logs or behavioural profiles.
No expansion into a general identity infrastructure
The checker must not evolve into a universal verification tool across sectors. Its use should be tightly defined in law, with clear limits preventing gradual expansion into wider commercial or social contexts.
Restricted access and licensing
Access should be limited to organisations with a clear legal basis and demonstrable need. It should not be made broadly available to private sector organisations for convenience or commercial use.
Explicit protection of anonymity
There should be a legal presumption against requiring identity verification unless strictly necessary. Individuals must retain the ability to engage in lawful activities without being routinely identified.
No linkage across services
The checker must not allow or facilitate linking identity checks across different services or organisations. Each interaction should remain isolated to prevent aggregation of personal data.
Transparency and independent oversight
There must be full transparency about how the checker operates, with independent oversight and regular public reporting to ensure it is not being used beyond its intended scope.
Right to refuse and equal alternatives
Individuals must have the right to refuse digital ID checks without suffering disadvantage. Equivalent non-digital options must remain fully available and effective.
Without strict and enforceable limitations, a checker service risks becoming a general-purpose identity verification infrastructure, fundamentally altering the balance between individual freedom and institutional control.
What further information, if any, should the digital ID also include?
Answer: None
Explanation:
No additional information should be included beyond what is strictly necessary, and there is a strong argument that even the proposed minimum dataset is excessive for many use cases.
From a rights-based perspective, data minimisation must be the guiding principle. Expanding the range of personal data contained within a digital ID increases risks of misuse, breach, and function creep.
Including core identifiers such as full name, date of birth, nationality, and especially a biometric facial image already creates a highly sensitive and comprehensive identity record. Adding further attributes would:
- Increase the potential harm from any breach or misuse
- Enable wider profiling and tracking across services
- Expand the number of contexts in which identity may be required
The proposal to allow selective disclosure (for example, confirming “over 18”) is positive in principle, but does not eliminate the underlying risks associated with storing and managing a broad set of personal attributes.
The appropriate approach is strict limitation, not gradual expansion. Any move to include additional data fields should require clear, evidence-based necessity and explicit public consent.
If your organisation were to rely on address information, what would help you trust an address on the digital ID?
Answer (free text):
The inclusion of address information raises significant concerns and should be approached with caution.
Address data is inherently dynamic and difficult to keep accurate in real time. Attempting to treat it as a reliable, centralised attribute risks creating false confidence while introducing additional privacy risks.
From a civil liberties perspective:
- Address information increases the sensitivity of the dataset and the potential harm if accessed or misused
- It enables more precise identification and tracking of individuals
- It may lead to expanded use cases beyond the original intent, particularly in commercial or enforcement contexts
Rather than seeking to “trust” address data within a digital ID, the more appropriate approach is to avoid centralising this information altogether.
Where address verification is genuinely required, it should be handled in a context-specific, decentralised way, rather than embedded into a persistent identity system.
Legal requirement to inform the government of changes or errors
Answer: Strongly Disagree
Explanation:
Imposing a legal obligation on individuals to maintain the accuracy of a digital identity system raises serious concerns about proportionality, fairness, and the shifting of responsibility from the state to the individual.
Disproportionate burden on individuals
Requiring people to report changes within a set timeframe creates an ongoing legal obligation that may be difficult for many to meet, particularly those with complex circumstances, limited capacity, or lower engagement with digital systems.
Risk of penalties and enforcement overreach
Such a requirement introduces the possibility of penalties for non-compliance, even where errors are minor, unintentional, or unavoidable. This risks criminalising administrative oversight.
Expansion of state control over identity data
A legal duty to maintain a state-managed digital identity represents a significant shift in the relationship between citizen and state, placing individuals under continuous obligation in relation to their personal data.
Questionable necessity
There is limited evidence that such a requirement is necessary. Existing systems already accommodate updates to personal information without imposing broad legal duties on individuals.
Potential for indirect coercion
Legal obligations reinforce the expectation that individuals must participate in and maintain the system, further undermining the principle that adoption should be voluntary.
A more proportionate approach would rely on voluntary updates, clear guidance, and system design that minimises the need for constant maintenance, rather than imposing legal duties.
The scope of information contained within a digital identity system, and the obligations placed on individuals to maintain it, must be tightly constrained. Expanding either risks creating a system that is intrusive, burdensome, and difficult to justify in a free society.
Barriers or inefficiencies… that digital ID could help with?
Answer: No
Explanation (optional if box allows):
The main barriers to accessing public services are not primarily caused by lack of digital identity. They are more often due to:
- Complex and fragmented processes
- Under-resourced services
- Poor communication and signposting
- Administrative delays
Introducing a digital ID risks misdiagnosing the problem. It addresses identity verification rather than the underlying structural issues. There is also a risk that adding a new system creates additional complexity, especially during transition.
Have you faced issues knowing which services are available?
Answer: Yes(this strengthens your argument)
Explanation (optional):
Difficulties in understanding available services are primarily due to poor communication, fragmented systems, and lack of clear guidance, not identity verification.
A digital ID would not meaningfully address this issue. Improving signposting, simplifying language, and better coordination between services would be more effective and less intrusive solutions.
Difficulty proving identity?
Answer: No(this reinforces your position)
Explanation (optional):
For most people, proving identity using existing documents and processes is already possible. While there may be isolated cases of difficulty, these do not justify introducing a comprehensive digital identity system with broad societal implications.
The issue is not widespread enough to require such a structural change.
Adoption of matching people across services
Answer: Very negative
Explanation:
The proposal to match individuals across public services represents a significant shift in how the state manages identity and data, with serious implications for privacy and civil liberties.
Creation of a linked identity system
Matching individuals across services enables the linking of data from multiple areas of life, increasing the risk of profiling and monitoring, even if unintended initially.
Function creep and expansion of scope
Once systems are linked, there is a strong likelihood that additional uses will be introduced over time. What begins as administrative efficiency can evolve into broader data sharing and surveillance.
Erosion of data minimisation principles
Linking services undermines the principle that data should be collected and used only for specific, limited purposes. It creates pressure toward greater data sharing by default.
Reduced autonomy and control
Individuals may lose meaningful control over how their information is used, as data flows between services without active involvement or clear visibility.
Risk of errors being amplified
Incorrect or outdated information could be propagated across multiple services simultaneously, making errors harder to identify and correct.
Shift in the citizen–state relationship
This approach moves toward a model where the state maintains a continuous, integrated view of individuals, which raises fundamental questions about proportionality and necessity in a free society.
Ethical issues in matching people across services
Answer:
There are significant ethical concerns:
Privacy and proportionality
Linking data across services increases the amount of personal information accessible within a single framework. This raises questions about whether such data use is proportionate to the intended benefits.
Informed consent
It is unclear whether individuals can meaningfully consent to their data being matched across multiple services, particularly if this becomes embedded as a default or expected system.
Chilling effects
If individuals know their interactions across services are linked, they may be less willing to seek support in sensitive areas, affecting wellbeing and access to help.
Power imbalance
The system increases the informational power of the state relative to the individual, without necessarily increasing transparency or control for the individual.
Risk of misuse or future expansion
Even if initially limited, the existence of linked data systems creates the potential for broader use in the future, including for purposes not originally intended.
Technical issues in matching people across services
Answer:
There are also substantial technical challenges:
Data accuracy and consistency
Different services may hold conflicting or outdated information. Matching systems risk spreading errors across multiple services simultaneously.
False matches and misidentification
Incorrect matching could result in individuals being linked to the wrong records, with serious consequences for access to services or entitlements.
Security risks
Linking systems increases the value of the data and creates a more attractive target for cyber attacks. A breach could expose interconnected datasets rather than isolated records.
System complexity and fragility
Highly integrated systems are more complex and harder to maintain. Failures in one part of the system can have cascading effects across services.
Interoperability challenges
Different departments and systems operate with varying standards and legacy infrastructure. Achieving consistent, secure integration is difficult and resource-intensive.
Audit and accountability difficulties
As systems become more interconnected, it becomes harder to track how data is used, who accessed it, and where errors originated.
The proposal shifts from improving services to restructuring how identity and personal data are managed across the state. This raises fundamental ethical and technical concerns that go well beyond efficiency and have not been adequately justified.
To what extent do you agree or disagree that the private sector and third parties should be able to use the digital ID alongside other options?
Answer: Strongly Disagree
Explanation:
Allowing the private sector and third parties to use a national digital ID represents a significant and concerning expansion of identity infrastructure beyond its original purpose.
Normalisation of identity checks in everyday life
Extending digital ID into the wider economy risks embedding identity verification into routine, low-risk interactions where it is not currently required. This would fundamentally change the nature of everyday transactions, moving toward a culture of constant identification.
Function creep and expansion of use
Once made available to private organisations, there is a strong likelihood that the use of digital ID will expand rapidly beyond initial intentions. Commercial incentives will drive wider adoption, leading to increased demands for identity verification in more contexts.
Erosion of anonymity and personal freedom
A key feature of a free society is the ability to engage in lawful activities without needing to identify oneself. Widespread use of digital ID in the private sector risks eroding this principle, particularly if it becomes the most convenient or expected option.
Indirect coercion despite “choice”
Although the proposal states that digital ID would be used “alongside other options,” in practice, the fastest and easiest method often becomes the default. This creates pressure on individuals to adopt the system, even if they have concerns.
Expansion of data exposure and misuse risk
Involving private and third-party organisations significantly increases the number of entities handling sensitive identity data. This raises the risk of data breaches, misuse, profiling, and commercial exploitation.
Blurring the boundary between state and commercial identity systems
A government-backed identity being used in private transactions risks creating a unified identity layer across society. This concentrates power and reduces the separation between public authority and commercial activity.
Long-term societal impact
The cumulative effect of widespread digital ID use across sectors is not simply convenience, it is a structural shift toward a more monitored, less private society. This has implications that extend far beyond individual transactions.
Extending a state-backed digital identity into the wider economy risks transforming it from a limited administrative tool into a pervasive identity requirement. The long-term consequences for privacy, autonomy, and everyday freedom are significant and have not been adequately justified.
Are there any additional challenges… for fully digital right to work checks?
Answer: Yes
Explanation:
There are significant additional challenges that go beyond those outlined:
Risk of exclusion from employment
Making digital checks the only route risks excluding individuals who do not have access to the required technology, who are less digitally confident, or who choose not to participate in digital ID systems. This creates barriers to employment.
Single point of failure
A fully digital system introduces dependency on technology. System outages, errors, or delays could prevent individuals from proving their right to work, directly affecting their ability to secure employment.
Error amplification and difficulty correcting mistakes
If incorrect data is recorded or a digital status is inaccurate, individuals may find it difficult to challenge or correct errors quickly, with immediate consequences for job opportunities.
Reduced flexibility and discretion
Current systems allow for a range of documents and approaches. Moving to a strictly digital model reduces flexibility and may disadvantage those with more complex or transitional circumstances.
Increased compliance burden on smaller businesses
Smaller employers may struggle with new systems, technical requirements, and ongoing updates, particularly if systems are complex or change over time.
Risk of over-reliance on automated decisions
Digital checks may encourage a more automated, less human approach to verification, increasing the risk of unfair or incorrect outcomes without proper scrutiny.
Would any additional support be required?
Answer: Yes
Explanation:
While support for businesses is important, the need for extensive support highlights the complexity and potential impracticality of a fully digital system.
Additional support would likely need to include:
- Ongoing technical support and system reliability guarantees
- Clear and rapid escalation routes for resolving errors
- Training that goes beyond initial implementation, recognising that systems evolve
- Support for handling cases where individuals cannot or do not use digital ID
However, even with support, these measures do not address the underlying risks of exclusion, dependency, and loss of flexibility inherent in a fully digital-only approach.
What information would your organisation require… confidence in a digital check?
You can select the listed options if required, but for the free text:
Any other information not listed above:
The focus should not be on expanding the amount of information shared, but on ensuring that any system is proportionate, accurate, and fair.
Key considerations include:
Right to challenge and correct errors
There must be clear, accessible mechanisms for individuals to challenge incorrect outcomes, with rapid resolution to avoid loss of employment opportunities.
Transparency of decision-making
Employers and individuals should understand how the check works, what data is used, and what limitations exist.
System reliability and accountability
Confidence depends on consistent system availability and clear accountability where errors occur.
Protection against over-collection of data
Only the minimum necessary information should be shared. Expanding data fields increases risk without necessarily improving trust.
Moving to a fully digital-only system for right to work checks represents a significant shift with real-world consequences for access to employment. The risks of exclusion, error, and over-reliance on technology must be carefully considered, as they directly affect individuals’ ability to participate in working life.
Are there any other groups that should be included?
Answer: No
Explanation:
The priority should not be expanding eligibility, but questioning the necessity and proportionality of the system itself.
Expanding access to additional groups would:
- Increase the scale and sensitivity of the system
- Extend exposure to privacy and security risks
- Accelerate normalisation of digital identity across society
Before considering wider inclusion, there must be clear evidence that the system is necessary, proportionate, and safe. That threshold has not been met.
A cautious approach is essential, particularly given the long-term implications of creating a national identity infrastructure.
Which age is most suitable to access the digital ID system from?
Answer: Other
Explanation:
The system should not be extended to children at all, and serious concerns exist even at age 16.
Risks of normalising identity from an early age
Introducing digital identity in childhood risks embedding the expectation of constant identification from a young age. This has long-term implications for autonomy, privacy, and how individuals understand their relationship with the state.
Safeguarding and consent concerns
Children and young people are not in a position to give fully informed consent to participation in a system with complex and long-lasting consequences. Parental oversight does not resolve this issue, as it introduces additional questions around control and data ownership.
Creation of lifelong identity tracking
Making digital ID available from birth or early adolescence raises the possibility of continuous identity records across a person’s entire life. This represents a profound shift in how personal data is managed and retained.
Disproportionate and unnecessary
There is no clear justification for requiring or encouraging children to adopt a digital identity system. Existing methods of age verification and identification are already available where needed.
Potential for expanded monitoring
Extending digital ID to younger age groups increases the risk that identity systems become integrated into areas such as education, online activity, or access to services, with unclear long-term consequences.A system with this level of sensitivity should not be introduced to children, and proposals to extend it to age 13 or from birth are disproportionate and raise serious concerns about privacy, autonomy, and lifelong data use.
Are you aware of any other barriers not captured in the consultation?
Answer: Yes
Explanation:
The consultation identifies practical barriers, but does not fully address more fundamental issues:
Choice not to participate
A significant group at risk of exclusion are those who actively choose not to engage with digital identity systems due to privacy, security, or civil liberties concerns. This is not a skills issue, but a legitimate exercise of personal autonomy.
Trust and legitimacy
Lack of trust in how data will be used, shared, or expanded over time is a major barrier. Without strong public confidence, uptake will be limited or reluctant.
Fear of misuse or future expansion
Concerns about function creep, data sharing, or future policy changes may deter individuals from participating, regardless of technical accessibility.
Dependency on technology and infrastructure
Barriers are not only about skills, but about ongoing access to devices, connectivity, and stable systems. These cannot be guaranteed equally across all circumstances.
Complex life circumstances
People with non-standard documentation, transitional situations, or administrative complexities may struggle to engage with rigid digital systems.
Is there any particular support not captured… that would help people use the digital ID?
Answer: Yes
Explanation:
While support measures may improve access, they do not address the underlying issue that participation itself may be inappropriate or undesirable for some individuals.
If the system proceeds, essential safeguards would include:
Genuine non-digital alternatives
Support should not focus solely on enabling digital participation. Equal, fully functional non-digital routes must remain available without disadvantage.
Right to opt out without penalty
Individuals must be able to refuse or withdraw from the system without experiencing reduced access to services or opportunities.
Clear limits on use and expansion
Support should include transparency about how the system will be used, and strict legal limits to prevent expansion beyond its original purpose.
Independent oversight and accountability
Trust cannot be built through support programmes alone. It requires visible, enforceable safeguards and independent scrutiny.
However, it is important to recognise that no amount of support can fully resolve concerns related to privacy, autonomy, and long-term societal impact.
Are there any groups not included… at risk of exclusion?
Answer: Yes
Explanation:
In addition to those already identified, the following groups are at risk:
Individuals who object on principle
People who have legitimate concerns about privacy, surveillance, or state overreach may choose not to participate. They risk being indirectly excluded if digital ID becomes the preferred or expected option.
Digitally capable but unwilling users
Not all exclusion is due to lack of skills. Some individuals are fully capable but unwilling to adopt systems they do not trust.
People in unstable or changing circumstances
Those with frequently changing personal details, housing situations, or documentation may struggle with systems that rely on up-to-date, consistent data.
Those concerned about data security
Individuals who have experienced fraud, data breaches, or misuse may be particularly reluctant to engage with a centralised identity system.
People seeking privacy in sensitive situations
Individuals accessing sensitive services may avoid systems that increase data linkage or traceability.
The concept of “inclusion” should not be used to justify or normalise a system that some individuals may reasonably choose to avoid. A truly inclusive approach must respect not only the ability to participate, but also the right not to.
Are there any other ways you think the government should consider supporting those who are digitally excluded?
Answer: Yes
Explanation:
Support for digitally excluded individuals is important, but it does not address the fundamental concern that the system itself may create new forms of exclusion and pressure to participate.
Any approach to support must include the following:
Equal, non-digital access as a permanent option
Support should not be limited to helping people use digital ID. Fully functional, non-digital alternatives must remain available on an equal basis, without delays, reduced service quality, or indirect penalties.
Respect for choice, not just capability
Not all exclusion is due to lack of skills or access. Some individuals may choose not to engage with digital identity systems due to privacy or trust concerns. Support strategies must recognise and respect this choice.
Avoiding dependency on intermediaries
Delivering support through third parties or “trusted organisations” may introduce new risks around privacy, data handling, and consistency. Individuals should not be required to rely on intermediaries to manage their identity.
Clear limits and transparency
Support must be accompanied by clear information about how the system works, what data is used, and what safeguards exist. Without this, support risks encouraging participation without informed understanding.
Long-term sustainability
In-person and local support may be resource-intensive and difficult to maintain at scale. There is a risk that such support is reduced over time, leaving individuals dependent on a system they cannot easily use independently.
Avoiding indirect coercion
Support programmes must not become a mechanism for encouraging or normalising adoption. The role of support should be to assist where appropriate, not to drive uptake.
Inclusion should not be defined solely as enabling participation in a digital system. It must also include the ability to access services without being required, directly or indirectly, to adopt that system.
Can you suggest any specific organisations or types of organisations which the government should engage with?
Answer (free text):
Engagement with accessibility organisations is important, but accessibility must be understood in a broader sense than technical usability alone.
The government should engage with:
Disability and accessibility organisations
Including groups representing people with visual, hearing, cognitive, and motor impairments, to ensure that any digital interface is usable in practice.
Organisations representing digitally excluded communities
Including those working with older people, low-income groups, and those with limited access to technology or connectivity.
Civil liberties and privacy organisations
Accessibility is not only about usability, but also about whether individuals can participate without compromising their rights. Organisations focused on privacy, data protection, and digital rights should be central to the design process.
Advocacy groups for vulnerable or marginalised individuals
Including those supporting people in complex or sensitive situations, where increased data sharing or identity linkage may create risks.
Community-based and local support organisations
These groups have practical insight into how systems operate in real-world conditions and the barriers people face beyond technical design.
However, it is important to recognise that:
Accessibility cannot be solved solely through design
Even a well-designed digital system may not be appropriate for all users. True accessibility requires that individuals are not required to use the system in order to access essential services.
Choice is a core part of accessibility
A system cannot be considered fully accessible if individuals are effectively compelled to use it. Equal, non-digital alternatives must remain available and fully functional.
Accessibility should not be limited to making a digital system usable, it must also include the ability to access services without being required to use that system at all.
The main barrier is not simply how people access the digital ID, but whether they are required to rely on it at all.
Providing alternative formats, such as physical cards or assisted access, does not resolve the underlying concerns if individuals remain dependent on a centralised identity system.
Key barriers include:
Dependence on a single system
Alternative access routes still require individuals to participate in the same identity framework. This creates a systemic dependency that may not be appropriate or acceptable for all users.
Loss of genuine choice
If all routes, digital or physical, are simply different ways of accessing the same system, individuals do not have a meaningful alternative. True choice requires the continued availability of independent, non-digital identification methods that are equally valid.
Risk of indirect coercion
If the digital ID system becomes the most efficient or widely accepted option, individuals may feel compelled to adopt it, regardless of whether they use a device or an alternative format.
Privacy and data concerns remain unchanged
Changing the format of access does not reduce concerns about data collection, linkage, and potential misuse. A physical or assisted route still connects back to the same underlying system.
Complexity and usability
Introducing multiple access routes can increase complexity, making the system harder to understand and navigate, particularly for those already facing barriers.
Stigma and unequal experience
Alternative routes may become seen as secondary or less efficient, leading to a two-tier system where some individuals receive slower or more limited access.
Security vs accessibility trade-offs
Efforts to maintain high security standards may make alternative routes more difficult to use, particularly for those with limited capacity, while simplifying them may introduce new risks.
Alternative access routes should not be treated as a substitute for genuine choice. Inclusion requires the ability to access services without being dependent on a centralised digital identity system at all.
Transparency is essential, but it must go beyond general commitments and be enforceable, detailed, and meaningful in practice.
Key measures should include:
Full visibility for individuals
Individuals should be able to see exactly when, where, and by whom their digital ID has been used or checked, in real time and in an accessible format.
Clear purpose limitation at each use
Every instance of data use should clearly state the specific purpose, the legal basis, and what data is being accessed or shared. This should not be presented in broad or vague terms.
No hidden or secondary data use
There must be strict prohibition of data being reused, shared, or analysed beyond the original purpose without explicit, informed consent. Any secondary use should require a clear legal basis and be transparently disclosed.
Independent oversight and auditing
Transparency cannot rely solely on government reporting. Independent bodies should have the power to audit the system, publish findings, and investigate misuse.
Public reporting and accountability
Regular, detailed public reports should be published on how the system is used, including the number of checks, types of organisations accessing it, and any incidents of misuse or breach.
Clear and accessible explanations
Information about how the system works must be understandable to the general public, not limited to technical or legal language.
However, it is important to recognise that:
Transparency alone does not address the core risks
Even a fully transparent system may still enable extensive data collection, linkage, and monitoring. The issue is not only whether people can see what is happening, but whether the level of data use is necessary and proportionate in the first place.
Power imbalance remains
Individuals may be able to view how their data is used, but may still have limited ability to challenge or prevent that use in practice.
Transparency is necessary but not sufficient. A system can be transparent and still be overly intrusive, and the primary safeguard must remain strict limits on what data is collected and how it can be used.
While technical security measures are important, the most effective safeguards are structural and legal, not just technological. A system of this scale cannot rely solely on cyber security controls, as risk increases with centralisation and expanded use.
Key additional safeguards should include:
Strict limitation of system scope
The most effective way to reduce risk is to minimise what the system does and where it is used. Expanding functionality increases the attack surface and potential consequences of failure.
Decentralisation where possible
Avoiding unnecessary centralisation of identity data reduces the impact of breaches and limits the potential for large-scale compromise.
Legal limits on access by authorities
Clear, narrowly defined legal boundaries must govern access by law enforcement, national security bodies, and other authorities. These powers should be subject to independent judicial oversight and not expanded through secondary use.
Prohibition of mass data access or monitoring
The system must not enable bulk access, pattern analysis, or monitoring of individuals’ interactions across services.
Strong protections against function creep
There should be explicit legal safeguards preventing the system from being extended into new uses without full legislative scrutiny and public consultation.
Independent oversight and enforcement
Security should not rely solely on internal processes. Independent regulators must have the authority to audit, investigate, and enforce compliance, including imposing meaningful penalties for misuse.
Clear redress mechanisms for individuals
Users must have accessible and effective routes to challenge misuse, breaches, or errors, with timely resolution and accountability.
Resilience and fallback systems
Given the potential consequences of failure, there must be robust non-digital fallback options that remain fully functional if the system is unavailable or compromised.
Even with strong safeguards, no system of this nature can be considered completely secure. The concentration of identity functions increases both the likelihood and the impact of failure.
Security cannot be treated solely as a technical challenge. The most important safeguard is limiting the scope, use, and power of the system itself, as the risks increase in proportion to its scale and reach.
What are the most important factors… to ensure alternative access routes are secure?
Answer (free text):
The most important factor is recognising that alternative access routes do not remove risk, they extend the system and introduce additional vulnerabilities.
Key considerations include:
Avoiding over-centralisation of identity
A centralised system, regardless of how it is accessed, creates a high-value target. The more widely it is used, the greater the incentive for sophisticated attacks.
Balancing security with accessibility
Measures that increase security often make systems harder to use, particularly for those already facing barriers. Overly complex processes may push users toward unsafe workarounds or reliance on intermediaries.
Minimising reliance on intermediaries
Alternative routes that depend on third parties, in-person verification, or assisted access increase the number of points where fraud or misuse could occur.
Clear and simple user processes
Complex systems are easier to exploit. Security depends not only on technical controls, but on processes that are understandable and resistant to manipulation.
System resilience and fallback options
If access routes fail or are compromised, individuals must still be able to access services without disruption. Over-reliance on a single system increases risk.
What are the most important factors… to prevent misuse by fraudulent actors?
Answer (free text):
The most important factor is recognising that systems of this scale and value will inevitably become primary targets for fraud, and risk cannot be eliminated.
Key considerations include:
Limiting the scope and use of the system
The broader the system’s use across sectors, the more valuable it becomes to attackers. Restricting its use reduces incentives for fraud.
Avoiding creation of a single point of failure
If a digital identity is compromised, the consequences could extend across multiple services simultaneously. This creates systemic risk that is difficult to contain.
Protecting against social engineering and coercion
Fraud is not purely technical. Systems that rely on individuals sharing or presenting credentials may be vulnerable to scams, pressure, or deception.
Rapid error detection and recovery
Individuals must be able to quickly identify and resolve issues if their identity is misused, with minimal disruption to their ability to access services or employment.
Clear accountability and liability
There must be clarity on who is responsible when fraud occurs, and mechanisms to ensure individuals are not unfairly penalised for system failures or criminal activity.
Avoiding over-reliance on technology alone
Fraud prevention must include human oversight and judgement. Fully automated systems risk making incorrect decisions that are difficult to challenge.
Fraud risk is not only about securing access routes, but about the scale, centralisation, and value of the system itself, which may make it an increasingly attractive target over time.
The most effective way to reduce fraud risk is not simply to strengthen access routes, but to limit the scope, centralisation, and dependency on a system that, by design, concentrates identity and therefore risk.
What additional oversight mechanisms… should be put in place?
Answer (free text):
Existing oversight mechanisms are unlikely to be sufficient for a system of this scale and sensitivity. Additional, robust, and independent safeguards are essential.
Key oversight measures should include:
Independent statutory regulator with strong powers
Oversight should not rely primarily on internal processes. A dedicated, independent body should have the authority to audit the system, investigate misuse, compel disclosure of information, and enforce compliance through meaningful sanctions.
Judicial oversight for sensitive access
Any access by law enforcement or national security bodies should require clear legal thresholds and independent judicial authorisation, not solely administrative approval.
Strict legal limits on scope and expansion
There should be clear statutory boundaries defining what the system can and cannot be used for. Any expansion of scope should require primary legislation, not incremental changes through secondary measures.
Regular public reporting and transparency
Detailed reports should be published on system use, including the number of identity checks, participating organisations, data access requests, and any breaches or misuse.
Independent security and ethics reviews
The system should be subject to ongoing external review, including ethical scrutiny, not just technical audits.
Sunset clauses and periodic reassessment
Given the long-term implications, the system should not be treated as permanent by default. Periodic review points should be built into legislation to reassess necessity and proportionality.
What measures… to make sure people can resolve issues?
Answer (free text):
Effective resolution mechanisms are critical, particularly given the potential consequences of errors or misuse.
Key measures should include:
Rapid, accessible resolution processes
Individuals must be able to report and resolve issues quickly, through multiple channels, including non-digital routes. Delays could have serious consequences, particularly where access to services or employment is affected.
Right to human review
Decisions affecting individuals must not rely solely on automated processes. There must be a clear right to have decisions reviewed by a human decision-maker.
Clear accountability and responsibility
It must be clear who is responsible when something goes wrong, whether it is a government department or another organisation using the system. Individuals should not be left navigating complex structures to resolve issues.
Right to compensation where harm occurs
Where individuals suffer loss or disadvantage due to system errors, misuse, or failure, there should be clear routes to compensation.
Accessible appeals process
There must be a transparent and independent appeals mechanism, separate from the system operators, to ensure fairness.
Support for vulnerable users
Those who may struggle to navigate complaints processes must have access to support that does not compromise their privacy or autonomy.
Oversight must not only detect problems after they occur, it must actively limit the potential for misuse and expansion in the first place.
Given the scale and sensitivity of the system, oversight must be independent, enforceable, and capable of constraining power, not simply reviewing it. Without this, safeguards risk being procedural rather than effective.
Other benefits for businesses not considered?
Answer: No
Explanation (optional):
The consultation already focuses heavily on efficiency and fraud reduction. There is limited evidence of additional meaningful benefits beyond those already identified, particularly when weighed against the broader risks and costs.
Other costs to businesses not considered?
Answer: Yes
Explanation:
Additional costs and risks include:
Ongoing compliance and system dependency
Businesses may become reliant on a central system, requiring continuous updates, training, and adaptation to policy or technical changes.
Liability and risk exposure
If errors occur in the system, businesses may face uncertainty about responsibility, particularly where incorrect identity verification affects hiring or service provision.
Operational disruption from system failures
Outages or delays could directly impact business operations, especially where identity checks become mandatory.
Increased administrative complexity
Rather than simplifying processes, introducing a new system may add layers of compliance, particularly during transition periods.
Other benefits for households not considered?
Answer: No
Explanation (optional):
The consultation emphasises convenience, but this is already considered. There is limited evidence of additional benefits that would outweigh the potential risks to privacy, autonomy, and access.
Other costs to households not considered?
Answer: Yes
Explanation:
Additional costs to households include:
Loss of privacy and increased data exposure
A centralised identity system increases the amount of personal data collected and potentially shared.
Risk of exclusion or disadvantage
Those who do not use the system may experience slower or reduced access to services, even if it is officially “optional.”
Burden of managing identity data
Individuals may face ongoing responsibility to maintain and update their information, with potential consequences if they fail to do so.
Impact of errors or system failures
Incorrect data or system outages could affect access to services, employment, or entitlements.
Reduced autonomy
There may be increasing expectation to use the system, limiting genuine freedom to choose alternative methods.
Other wider impacts not considered?
Answer: Yes
Explanation:
There are several broader impacts that require greater consideration:
Long-term societal change
The introduction of a national digital ID risks normalising identity verification across many aspects of daily life, fundamentally changing how individuals interact with services and organisations.
Shift in the balance of power
The system concentrates identity data and verification capability, increasing the informational power of institutions relative to individuals.
Function creep over time
Even if initially limited, the system is likely to expand in scope and use, creating long-term consequences that are difficult to reverse.
Trust in public institutions
If concerns around privacy and control are not adequately addressed, the system may reduce, rather than increase, public trust.
Final question: Anything else you wish to share
Answer (free text):
This proposal represents a significant structural change in how identity is managed across society. While it is presented in terms of convenience and efficiency, the long-term implications for privacy, autonomy, and the relationship between citizen and state are substantial.
The case for necessity has not been clearly established. Many of the problems identified, such as inefficiencies in public services, are organisational rather than identity-related, and could be addressed through less intrusive means.
There is a consistent risk throughout the proposal of:
- Gradual expansion of scope
- Increasing reliance on a single system
- Indirect pressure on individuals to adopt it
- Erosion of anonymity and proportionality in identity use
These risks are not fully mitigated by technical safeguards, support programmes, or oversight mechanisms.
A system of this scale should only proceed where there is clear evidence of necessity, proportionality, and broad public consent. Based on the information provided, those conditions have not been met.
Optional final line to make it very clear:
The question is not simply how to build this system, but whether it should be built at all.






EU faces car crash after Trump raises tariffs to 25% on cars. Telegraph