The debate around digital ID privacy usually gets stuck on the wrong question. People argue about whether digital IDs should exist at all, when the more practical question is already unfolding beneath that argument: who sits in the middle, holding your information, every time you prove who you are? The answer changes everything about what that system actually does to you.
Three Basic Models: Government, Big Tech, and You
There are three broad ways a digital ID scheme can be built, and they behave very differently.
The government-held model puts your verified details in a national database. When a service needs to check something about you, it pings that database and gets a confirmation back. Convenient, but it creates one large target for a data breach and one place from which all your authentication activity can, in theory, be watched.
The platform-held model is already the most common one most people use without calling it an ID scheme at all. Every time you tap “Sign in with Google” or “Continue with Apple,” a private corporation logs the fact that you authenticated with that service, at that time. That corporation now has a record of your activity across every site where you used that button.
The self-sovereign or wallet model stores your credentials on your own device. You share only what a transaction requires — your age, not your name; your address, not your date of birth. Technically this is the most privacy-protective option, but it depends entirely on your phone working, staying charged, and not getting lost or stolen.
What Governments Are Actually Building Right Now
These are not hypothetical designs. The EU Digital Identity Wallet, under the eIDAS 2 regulation passed in 2024, is being rolled out across EU member states and will give citizens a standardised wallet app for authenticating with public and private services. The UK ran a digital driving licence pilot in 2023 through the DVLA. In the United States, more than a dozen states including Arizona, Maryland, and Colorado have issued mobile driver’s licences accepted at some TSA checkpoints.
Most of these schemes are hybrids. The government issues the credential, but delivery runs through private infrastructure — Apple Wallet, Google Wallet, or a third-party app. That means digital ID privacy depends not just on the government’s rules but on the terms of service of whatever company is carrying the wallet.
Laws governing these schemes vary sharply. The EU framework includes audit rights and limits on which parties can request verification. The US state-level schemes have no consistent federal standard governing who can demand to see a mobile ID and for what purpose.
How Online Communities and Virtual Worlds Fit In
People who spend time in online communities and virtual worlds are facing a version of this problem right now, not in the abstract future.
In the UK, the Online Safety Act 2023 requires platforms to take steps to prevent children from accessing certain content, which in practice is pushing many services toward age verification. When a platform verifies your age, it either collects your documents directly or hands that job to a third-party age-check company. Either way, a new organisation now holds a record linking your real identity to your account username.
Community shutdowns make this worse in a way that rarely gets discussed. When a platform closes, the identity records it gathered do not automatically disappear. They sit on servers, get transferred in asset sales, or simply go undeleted. There is no standard process that mirrors what happens to a paper form you hand in person.
Moderation decisions are also affected. If your real identity is tied to your account, a wrongful ban is no longer just an inconvenience — it is an event linked to your verified name, potentially visible to future services you try to join using the same credential.
The Logging Problem Nobody Talks About
Every digital ID check can generate a log. The system that verified you can record when the check happened, what was confirmed, and which service asked. A physical driving licence handed to a bouncer leaves no automatic record. A digital check almost always does.
Across a year of normal online activity — age-verifying a streaming site, authenticating with a community forum, signing into a government portal — those logs build into a detailed map of your interests, habits, and movements. That map exists even if you never did anything wrong.
Most current schemes do not require these logs to be deleted after a fixed period. The EU’s eIDAS 2 framework sets some limits, but enforcement across member states is uneven. In the UK and US, retention rules for third-party verification providers are not standardised.
Questions Worth Asking Before Any Scheme Goes Live
- Can you use the service without a digital ID, or is it the only option?
- Who is legally allowed to request your ID, and can that list be expanded later without public notice?
- How long are verification logs kept, and who can access them — including law enforcement without a warrant?
- What happens to your data if the company holding it is sold, hacked, or shut down?
- Is there an independent body with real enforcement power to audit the scheme and publish findings?
What You Can Do Before the Rules Are Settled
Check whether your country has a data protection authority. In the EU, each member state has one under GDPR. In the UK it is the ICO. In Australia it is the OAIC. Each of these bodies accepts complaints when a service collects more information than it needs for the stated purpose.
Use a separate email address for any service that requires identity verification. This limits how easily your verified identity can be linked to your activity on other platforms.
Respond to public consultations on digital ID legislation. The UK government ran a consultation on digital identity trust frameworks in 2023 and published a summary of responses. Plain-language submissions from ordinary people do appear in those summaries and do influence how schemes are scoped.
Check the terms of service for the online communities and virtual worlds you use regularly. Some platforms are quietly updating their terms to require real-identity verification as a condition of continued access. Knowing that in advance gives you time to decide whether that trade-off is acceptable before the change takes effect.
Frequently asked questions
If a digital ID stays on my phone, is my data really private?
Partly. A wallet-based credential stored on your device means the issuing government or company does not automatically see every time you use it. But the service you present it to still receives a confirmation, and that service can log it. The device itself — and whoever made the operating system — also has visibility into when the wallet app runs. “Stored on your phone” reduces central surveillance but does not eliminate the logging problem at the point of use.
Can a website or online community legally demand my real identity?
It depends on the country and the type of content. In the UK, the Online Safety Act 2023 requires certain platforms to verify user ages but does not require platforms to collect full real names. In the EU, the Digital Services Act requires very large platforms to take measures against illegal content but does not mandate real-name registration for ordinary users. Any platform asking for more than the law requires should be asked why, and their answer should be in writing.
What happens to my identity records if a platform shuts down?
There is no universal answer, and that is the problem. Under GDPR in the EU and UK, a company closing is required to handle personal data in accordance with its privacy policy and data protection law — but enforcement after a shutdown is difficult and often does not happen. In the US there is no equivalent federal rule. In practice, identity records collected by a platform that closes may be transferred to a buyer, retained by the original company’s directors, or simply left on servers with no active oversight.
Scams, fraud, bots and manufactured noise keep spreading because the internet was built with no reliable way to know who anyone actually is. Everyone deserves authenticity and accountability online, and that is the mission we are working on. Subscribe to CDM Worlds to follow how digital identity decisions are reshaping the communities you are part of.
