At some point recently, you probably hit a wall. A government portal asked you to upload your passport. A gig-work app wanted a selfie. A streaming site said it needed to confirm your age before you could watch anything. The question that follows — can I refuse a digital ID request — is not paranoid. It is the right question to ask, and it deserves a straight answer rather than reassurance.
What a Digital ID Actually Is — in Plain Terms
The phrase “digital ID” covers several different things, and the differences matter.
- A government-issued app, such as the UK’s GOV.UK One Login or Australia’s myID (formerly myGovID), that ties your identity to a government account
- A biometric check run by a private company — a facial scan or liveness test — often used by banks or employers
- An age-verification gate on a website, now legally required in the UK under the Online Safety Act 2023 for services that carry pornography
- A workplace login tied to your real name, such as a delivery or scheduling app that requires a photo ID before you can clock in
Each has different legal backing and different consequences if you refuse. Verifying your age to watch a film on a UK adult platform is a different legal instrument from the Australian government asking for a facial scan to access myGov services. Treating them as the same thing leads to confusion about what power you actually have.
Can I Refuse a Digital ID When a Government Service Asks?
In most democracies, no single law currently forces every adult to hold or use a digital ID for daily life. That is the official position. The practical reality is messier.
In the UK, GOV.UK One Login remains voluntary in principle, but it is becoming the default route into HMRC self-assessment, Universal Credit, and several other services. Paper alternatives exist but are slower and sometimes require a visit to a physical office. “Voluntary” starts to feel like a formality when the alternative costs you half a day and a bus fare.
In the EU, the European Digital Identity Wallet framework — agreed in 2024 — requires member states to offer a wallet to every citizen by the end of 2026, but acceptance by private services is being phased in rather than imposed overnight. Refusal currently means using existing national ID documents instead, which is still possible in most member states.
In Australia, myID (formerly myGovID) is already the primary login for the Australian Tax Office and Services Australia. There is a phone-based alternative, but wait times have been reported in the hours.
The practical trap is real: refusal is technically allowed, but the alternative route is often designed to be difficult enough that most people abandon it. Laws also change. What is optional today can become effectively compulsory within twelve months if alternative routes are quietly removed without any new legislation being passed.
When a Private Company Demands Verification
Private platforms operate under their terms of service, not a constitutional right to access. If you refuse verification on a gig-work app or a social platform, the service is simply withheld. There is no legal remedy in most countries because you have no right to use a private platform in the first place.
Age-verification laws complicate this. The UK’s Online Safety Act places the legal obligation on platforms, not users — but the practical result is that users get asked to prove their age. Some services use a “privacy-preserving” method: a third party confirms you are over 18 without passing your actual ID document to the platform. In principle, this limits exposure. In practice, it creates a new third party who now holds a copy of your passport, and that company may have weaker security than the platform you were trying to use.
What Refusal Actually Costs You Day to Day
The cost depends entirely on what you are refusing. Losing access to a social media account is an inconvenience. Losing access to your only route to Universal Credit payments in the UK, or to your Medicare records in Australia, is a different category of problem entirely.
Realistic scenarios people are already facing include: a bank account frozen pending re-verification, a delivery shift withheld because a scheduling app requires a new selfie, and a benefits portal that only accepts GOV.UK One Login as of a specific cutover date.
The cost of refusal also falls unevenly. Older people, people without smartphones, and people in rural areas with poor connectivity face higher practical barriers. Concerns about verification companies are not hypothetical — the identity verification firm ID.me drew congressional scrutiny in the US after millions of Americans were required to use it to access government services. That concern is legitimate and worth naming honestly rather than brushing past.
Rights You Do Have Right Now
Under UK and EU GDPR, you can:
- Ask any organisation what personal data they hold on you
- Ask why they hold it and what legal basis they are relying on
- Request deletion in certain circumstances, particularly where the data is no longer needed
In the US, federal protection is patchy. California’s Consumer Privacy Act gives residents some similar controls, but someone in Texas or Florida has significantly fewer options.
In the UK you can complain to the ICO (Information Commissioner’s Office) at ico.org.uk. Across the EU, each member state has its own Data Protection Authority. Filing a complaint is free and requires no legal expertise — you describe what happened, who asked for your data, and what your concern is.
These rights exist on paper. Enforcing them takes effort, and regulators are slow. The ICO has taken over two years to conclude some of its major investigations. Set realistic expectations.
Practical Steps If You Want to Push Back
- Ask in writing what the legal basis is for collecting your ID. Under GDPR, organisations are required to tell you. Keep the reply.
- Check whether a non-digital alternative exists before assuming there is none. It is sometimes just not advertised on the main page.
- Keep records of every verification request you comply with: who asked, when, what you provided, and what they said they would do with it.
- If a public body has designed a digital-only service that excludes people unfairly, a formal complaint to the relevant ombudsman is a realistic option — the Parliamentary and Health Service Ombudsman in the UK, or the Commonwealth Ombudsman in Australia.
- Start at your country’s data protection authority website. No sign-up or specialist knowledge is required to file a complaint.
Frequently asked questions
Is it illegal to refuse to provide a digital ID?
No. In the UK, EU, and Australia, there is currently no law that makes holding or using a digital ID a legal requirement for ordinary daily life. What exists is a growing set of services where refusing means losing access to that specific service — which is a practical consequence, not a criminal one.
Can a website legally force me to scan my face or upload my passport?
A private website cannot force you to do anything, but it can refuse you access if you decline. In the UK, the Online Safety Act 2023 requires certain platforms to verify users’ ages, so those platforms will require some form of check. What they cannot legally do under GDPR is collect more data than is strictly necessary for that purpose, or keep it longer than needed.
What happens to my ID documents after a verification check?
It depends on the company and the method. Some services delete the document image immediately after extracting the relevant data point. Others retain it for a period set out in their privacy policy. You are entitled to ask, in writing, exactly what is retained, for how long, and who it is shared with. If the answer is unclear or not given within one month, that is grounds for a complaint to your data regulator.
Related reading
Digital ID keeps returning because online systems cannot tell who anyone is. The real question is who holds that identity — you, a government, or a company that sells it. Get Wes Kussmaul’s Escape the Plantation free and follow where this goes.
