The debate about digital ID usually gets stuck on whether governments should introduce it at all. That is the wrong place to start. The more useful question is simpler: who physically holds the record that connects your face, your name, or your device to your identity? Digital ID privacy turns almost entirely on that one answer. It determines who can see your data, who can profit from it, who can lose it in a breach, and who can cut off your access. No technical knowledge is needed to think it through — every scheme described here is just a practical arrangement between people.
The Three Basic Models: Government, Platform, or You
There are three ways a digital ID system can be structured, and they are genuinely different in their consequences.
A government-held model puts a central database under the control of a public body — think of it as a passport office that never closes and can be queried in real time. It is convenient for officials and for services that need to check your status quickly. It is also a single point of failure for an entire population.
A platform-held model hands the job to a private company — a bank, a phone network, or a tech giant. This already happens whenever a website invites you to log in with Google. When you do that, Google logs the fact that you visited that site, at that time, from that device.
A user-held model, sometimes called a wallet approach, stores a signed credential on your own phone or a small device you carry. You share it only when you choose. This is the least common of the three, but it is the one that keeps the most control in your hands.
What a Central Government Database Actually Means for You
Every verification event can generate a log: when it happened, which service requested it, and sometimes what you were trying to do. Over months, that log becomes a detailed record of your movements through digital life — which pharmacy you use, which government benefit you claimed, which age-restricted service you accessed.
The breach risk is also categorically different, and the arithmetic is the whole argument. A breach at a single bank exposes that bank’s customers. A breach of a national identity database exposes everyone, because the entire adult population is in one place by design. There is no version of a central register that is not also a single target, and the more services that depend on it, the more damaging it is when it fails — not only through theft, but through outage, since a population that cannot prove who it is cannot access anything.
Governments can also share that log. Courts can compel disclosure. Agencies can request access voluntarily. In some countries, bilateral agreements mean a foreign state can query your verification history. Digital ID privacy is not just about hackers — it is about who has legitimate access by design.
Why Letting a Private Company Hold It Is Not Obviously Safer
Private companies have commercial reasons to study your verification behaviour. Knowing you verified your age at a gambling site on a Tuesday evening, or at a pharmacy collecting a prescription, tells them something they can use to build a profile — even if they never sell your name directly.
Platform risk is also real. If the company holding your credential is acquired, changes its terms, or suspends your account by mistake, you can lose access to every service that depends on that credential. This has happened repeatedly with social login systems: users locked out of a Google or Facebook account have found themselves unable to access dozens of other sites simultaneously.
Regulation of private identity holders varies sharply by country. Australia’s Privacy Act covers some commercial identity services; in many other jurisdictions, the rules are thinner or untested. Most ordinary people cannot easily check which framework applies to the company holding their credential.
The Wallet Model: More Control, More Responsibility
A digital wallet stores a signed certificate on your device. When a website asks whether you are over 18, the wallet sends a simple yes — not your name, not your date of birth, not your address. This is called selective disclosure: you prove the fact without handing over the underlying document.
The analogy is a bouncer checking your age at the door. A good bouncer confirms you are old enough and lets you in. They do not photocopy your passport and file it.
The catch is recovery. If your phone is lost or stolen, getting your credentials back can be complicated, and the process varies by scheme. The wallet software itself also has to be trusted — if it reports your activity back to its developer, you have just recreated the platform-held model on your own device without realising it.
Digital ID Privacy in Practice: The Questions Worth Asking
Before accepting any ID scheme, ask these three things plainly:
- Does the verifier learn which services I use, or only that I passed a check? These are very different outcomes.
- Are logs kept, for how long, and who can request them? Many schemes bury this in terms of service. If the answer is not easy to find, treat that as a warning sign.
- What happens if the credential holder is hacked, sold, or shut down? A well-designed scheme has a clear answer. A poorly designed one does not mention the possibility at all.
What You Can Do Right Now, Before Any Law Is Finalised
Start with an audit. Several services already function as your de facto identity holder without being labelled as such. Your email provider, your mobile network, and your bank all hold enough about you to verify you to a third party. Most people have never thought of them that way.
Where you have a choice between logging in with a social account and creating a separate login, the separate login almost always shares less data with third parties. It takes two more minutes to set up and is worth it.
In the UK, Australia, and the EU, digital ID policy moves through public consultations at various stages. A short, plain-language submission from an ordinary person — three paragraphs explaining what you want to know before you trust a scheme — carries more weight than most people assume. Officials read them. Silence is taken as consent.
Frequently asked questions
Does it matter who holds my digital ID if I have nothing to hide?
Yes. The “nothing to hide” framing assumes the only risk is embarrassment. The real risks are breach, commercial exploitation, and loss of access. A database holding your identity can be hacked regardless of how innocent your behaviour is. A company can sell insights derived from your verification history without ever publishing your name. And if the holder cuts off your access — by mistake or by policy — you lose it whether or not you have done anything wrong.
Is a digital wallet on my phone actually more private than a government database?
In principle, yes — because selective disclosure means the verifier receives only the fact they need, not a copy of your document. In practice, it depends entirely on how the wallet software is built and whether it logs your activity. A wallet that phones home to its developer every time you use it offers no real privacy advantage. Check the specific product’s privacy policy before trusting it.
Can I opt out of a national digital ID scheme?
This varies by country and by the specific instrument involved. In Australia, the Digital ID Act passed in 2024 describes participation as voluntary for individuals. In the EU, the eIDAS 2.0 framework requires member states to offer a digital wallet but does not require citizens to use one. In the UK, no single national scheme is mandatory. These positions can change, and the rules around age verification and the rules around general identity are separate instruments — one can become compulsory while the other stays optional.
Related reading
- Banned by Mistake: How Platform Appeals Actually Work
- Digital Identity Explained: What It Is and What It Isn’t
Digital ID keeps returning because online systems cannot tell who anyone is. The real question is who holds that identity — you, a government, or a company that sells it. Get Wes Kussmaul’s Escape the Plantation free and follow where this goes.
