Digital ID Privacy: Who Holds Your Data Changes Everything

The debate around digital ID privacy usually gets stuck on the wrong question. People argue about whether digital IDs should exist at all, when the more practical question is already unfolding beneath that argument: who sits in the middle, holding your information, every time you prove who you are? The answer changes everything about what that system actually does to you.

Three Basic Models: Government, Big Tech, and You

There are three broad ways a digital ID scheme can be built, and they behave very differently.

The government-held model puts your verified details in a national database. When a service needs to check something about you, it pings that database and gets a confirmation back. Convenient, but it creates one large target for a data breach and one place from which all your authentication activity can, in theory, be watched.

The platform-held model is already the most common one most people use without calling it an ID scheme at all. Every time you tap “Sign in with Google” or “Continue with Apple,” a private corporation logs the fact that you authenticated with that service, at that time. That corporation now has a record of your activity across every site where you used that button.

The self-sovereign or wallet model stores your credentials on your own device. You share only what a transaction requires — your age, not your name; your address, not your date of birth. Technically this is the most privacy-protective option, but it depends entirely on your phone working, staying charged, and not getting lost or stolen.

What Governments Are Actually Building Right Now

These are not hypothetical designs. The EU Digital Identity Wallet, under the eIDAS 2 regulation passed in 2024, is being rolled out across EU member states and will give citizens a standardised wallet app for authenticating with public and private services. The UK ran a digital driving licence pilot in 2023 through the DVLA. In the United States, more than a dozen states including Arizona, Maryland, and Colorado have issued mobile driver’s licences accepted at some TSA checkpoints.

Most of these schemes are hybrids. The government issues the credential, but delivery runs through private infrastructure — Apple Wallet, Google Wallet, or a third-party app. That means digital ID privacy depends not just on the government’s rules but on the terms of service of whatever company is carrying the wallet.

Laws governing these schemes vary sharply. The EU framework includes audit rights and limits on which parties can request verification. The US state-level schemes have no consistent federal standard governing who can demand to see a mobile ID and for what purpose.

How Online Communities and Virtual Worlds Fit In

People who spend time in online communities and virtual worlds are facing a version of this problem right now, not in the abstract future.

In the UK, the Online Safety Act 2023 requires platforms to take steps to prevent children from accessing certain content, which in practice is pushing many services toward age verification. When a platform verifies your age, it either collects your documents directly or hands that job to a third-party age-check company. Either way, a new organisation now holds a record linking your real identity to your account username.

Community shutdowns make this worse in a way that rarely gets discussed. When a platform closes, the identity records it gathered do not automatically disappear. They sit on servers, get transferred in asset sales, or simply go undeleted. There is no standard process that mirrors what happens to a paper form you hand in person.

Moderation decisions are also affected. If your real identity is tied to your account, a wrongful ban is no longer just an inconvenience — it is an event linked to your verified name, potentially visible to future services you try to join using the same credential.

The Logging Problem Nobody Talks About

Every digital ID check can generate a log. The system that verified you can record when the check happened, what was confirmed, and which service asked. A physical driving licence handed to a bouncer leaves no automatic record. A digital check almost always does.

Across a year of normal online activity — age-verifying a streaming site, authenticating with a community forum, signing into a government portal — those logs build into a detailed map of your interests, habits, and movements. That map exists even if you never did anything wrong.

Most current schemes do not require these logs to be deleted after a fixed period. The EU’s eIDAS 2 framework sets some limits, but enforcement across member states is uneven. In the UK and US, retention rules for third-party verification providers are not standardised.

Questions Worth Asking Before Any Scheme Goes Live

  • Can you use the service without a digital ID, or is it the only option?
  • Who is legally allowed to request your ID, and can that list be expanded later without public notice?
  • How long are verification logs kept, and who can access them — including law enforcement without a warrant?
  • What happens to your data if the company holding it is sold, hacked, or shut down?
  • Is there an independent body with real enforcement power to audit the scheme and publish findings?

What You Can Do Before the Rules Are Settled

Check whether your country has a data protection authority. In the EU, each member state has one under GDPR. In the UK it is the ICO. In Australia it is the OAIC. Each of these bodies accepts complaints when a service collects more information than it needs for the stated purpose.

Use a separate email address for any service that requires identity verification. This limits how easily your verified identity can be linked to your activity on other platforms.

Respond to public consultations on digital ID legislation. The UK government ran a consultation on digital identity trust frameworks in 2023 and published a summary of responses. Plain-language submissions from ordinary people do appear in those summaries and do influence how schemes are scoped.

Check the terms of service for the online communities and virtual worlds you use regularly. Some platforms are quietly updating their terms to require real-identity verification as a condition of continued access. Knowing that in advance gives you time to decide whether that trade-off is acceptable before the change takes effect.

Frequently asked questions

If a digital ID stays on my phone, is my data really private?

Partly. A wallet-based credential stored on your device means the issuing government or company does not automatically see every time you use it. But the service you present it to still receives a confirmation, and that service can log it. The device itself — and whoever made the operating system — also has visibility into when the wallet app runs. “Stored on your phone” reduces central surveillance but does not eliminate the logging problem at the point of use.

Can a website or online community legally demand my real identity?

It depends on the country and the type of content. In the UK, the Online Safety Act 2023 requires certain platforms to verify user ages but does not require platforms to collect full real names. In the EU, the Digital Services Act requires very large platforms to take measures against illegal content but does not mandate real-name registration for ordinary users. Any platform asking for more than the law requires should be asked why, and their answer should be in writing.

What happens to my identity records if a platform shuts down?

There is no universal answer, and that is the problem. Under GDPR in the EU and UK, a company closing is required to handle personal data in accordance with its privacy policy and data protection law — but enforcement after a shutdown is difficult and often does not happen. In the US there is no equivalent federal rule. In practice, identity records collected by a platform that closes may be transferred to a buyer, retained by the original company’s directors, or simply left on servers with no active oversight.

Scams, fraud, bots and manufactured noise keep spreading because the internet was built with no reliable way to know who anyone actually is. Everyone deserves authenticity and accountability online, and that is the mission we are working on. Subscribe to CDM Worlds to follow how digital identity decisions are reshaping the communities you are part of.

Grab Your Free Ebook

Subscribe to our mailing list and get your free copy of Escape the Plantation.

“No problem can withstand the assault of sustained thinking.”

                                                                                                                                                 — Voltaire

🔒 YOU own the information that identifies YOU.
The operation of this website is governed by the ordinances of the City of Osmio, including its Privacy Ordinance.
View Privacy Ordinance

No Tracking Pixels or Beacons

Today's internet has become infested with hidden trackers — tiny “pixel beacons,” scripts, and device tracking tools designed to follow you without your knowledge.

As a Member Enterprise of The Authenticity Alliance, the operator of this website uses no tracking pixels, no beacons, and no covert identity-reporting mechanisms of any kind.

If we want to know something about you, we’ll ask — we won’t spy.
Learn About Spyfree

What is Authenticity™?

The word “Authenticity™” identifies a digital or physical space of “accountable anonymity” in which people enjoy both privacy for themselves and accountability from others.

Authenticity™ is the condition that exists in a space where there are

  • Digital Signatures Everywhere backed by
  • Measurably Reliable Identity Certificates that are
  • Owned by their Users and which provide
  • Privacy via Accountable Anonymity.

 

Learn about digital signatures and identity certificates in this short video →

What is The Authenticity Alliance?

We are an Authenticity Growers Cooperative

Similar to familiar agricultural cooperatives in the physical world, The Authenticity Alliance is a network of enterprises and individuals whose purpose is to “grow” Authenticity and bring it to the digital world.

Each Authenticity Enterprise—that is, each Member Enterprise of the Alliance—solves a particular inauthenticity problem in its chosen target market or audience.

What Does The Authenticity Alliance Do?

The Alliance brings together independent enterprises that share a common mission: creating spaces of accountable anonymity where digital signatures, reliable identity certificates, and privacy protection work together to solve real-world inauthenticity problems.

Who is the Authenticity Alliance?

The Authenticity Alliance is comprised of two groups working together to promote trust and transparency across digital ecosystems.

  • Enterprises: Authenticity Enterprises that provide Authenticity solutions for the inauthenticity pains in a specific market or industry.
  • Individuals: People who understand the problems of inauthenticity that plague the world’s information systems and who want to help implement and promote Authenticity™ principles.

Authenticity Enterprises

Each is an Enterprise Member of The Authenticity Alliance

Individual Enterprise in The Authenticity Alliance

Customers and members of an Authenticity Enterprise are automatically eligible to become Individual Members of The Authenticity Alliance.You may also join directly as an individual Member here.

 

© 2026 The Authenticity Alliance. All rights reserved. REAL Security | REAL Privacy | REAL Accountability