In the UK, an advisory committee tasked with overseeing the future national digital identity system is operating without public minutes, a declared budget, or known selection criteria. The paradox is striking: the body supposed to guarantee the transparency of a mass surveillance system is itself being built far from any democratic oversight.
One Advisory Group, Three Questions, One Single Answer
It all begins with an ordinary parliamentary exercise. Andrew Snowden, Conservative MP for Fylde and assistant whip, submits three written questions to the British Cabinet Office. He wants to know: will the minutes, recommendations, and advice of the digital identity advisory group ever be published? What budget has been allocated to it? By what criteria were its members selected?
Cabinet Office Minister James Frith responds - three times, with the exact same wording:
« The operation of the digital identity advisory group will be supported by the Cabinet Office’s existing digital taskforce. The group is not a decision-making body and its minutes will not be published. »
This response, reported by The Register, leaves Snowden with no illusions. “The answer was disappointing, to say the least,” he told the same outlet, adding: “If the government persists in developing a digital identity system, parliamentary scrutiny of this policy is vital. Dodging essential questions will not increase public support for digital identity."
"Not a Decision-Making Body”: A Distinction That Doesn’t Hold Up
The ministerial argument warrants examination. The group is supposedly merely “advisory,” meaning its deliberations do not need to be made public. But according to Reclaim The Net, this group’s precise role will be to weigh in on fundamental questions:
- what data will be collected on each citizen;
- how long it will be retained;
- which actors - government administrations or private entities - will be allowed to access it.
Calling this “advisory” does not change the nature of the influence exerted. It only changes the ability of citizens to be informed about it.
The group is convened by Darren Jones, Chief Secretary to the Treasury, and will meet quarterly for the duration of the program. Among the members whose identities have leaked: security expert David Rogers, Mumsnet founder Justine Roberts, and Victor Dominello, former Minister for Digital Government in New South Wales - which, as Reclaim The Net notes, is about ten thousand miles from the UK. How were these names selected? The minister refused to specify.
That same month, the government had already barred journalists from attending a digital identity advisory panel event.
What the System Plans to Collect
To grasp the stakes of this opacity, one must understand what the system actually entails. According to the UK government itself, as cited by Proton, a digital identity would contain:
- the holder’s full name;
- their date of birth;
- their nationality or residency status information;
- a photo used as the basis for biometric security.
A public consultation has also been announced to examine whether additional data - notably addresses - should be integrated. The identity would be stored in a mobile application, with no physical backup.
The UK government claims the system will use “state-of-the-art encryption” technology to guarantee data security.
This promise, reported by France 24, says nothing about the conditions of access to this data once decrypted - nor about the safeguards enforceable against government administrations or private partners.
The Trajectory: From a Controversial Project to a Legal Obligation
The history of digital identity in the UK is paved with abandonments. A first attempt dates back to the early 2000s: Tony Blair’s Labour government passed a law in 2006, which was repealed as early as 2011 by his Conservative successor. The debate resurfaces regularly, each time accompanied by substantial resistance.
Today, Keir Starmer’s government - also Labour - is relaunching the project with heightened ambition. According to Proton, a digital identity is to be issued to every British citizen and legal resident by 2028. According to France 24, the system is expected to become mandatory to prove the right to work in the country by the end of the current parliament, scheduled for 2029.
The official justification rests on two pillars:
- The fight against illegal work - Starmer declared that ‘you won’t be able to work in the UK unless you have a digital ID’ during the Global Progress Action Summit in London.
- Administrative efficiency - the government argues that relying on physical documents is inefficient and prone to fraud.
France 24 notes that 8.8% of the adult population in the UK participates in the informal economy, according to official 2023 figures - data the government is leveraging to legitimize the mandatory identification requirement.
Post-Brexit: Convergence or Escalation?
Leaving the European Union was presented, among other things, as reclaiming sovereignty over data and migration flows. The paradox is that the UK is preparing to deploy a mandatory digital identity system whose architecture - biometrics, centralized storage, administrative and potentially private access - closely mirrors the model the EU is developing on its side with the European Digital Identity Wallet (eIDAS 2.0), scheduled for rollout starting in 2026.
The difference perhaps lies in the pace and the oversight: while European institutions have produced public debates, impact assessments, and European Parliament votes, the British system is being built around an advisory group whose deliberations are shielded from parliamentary scrutiny. Brexit has not produced less of a digital state - it has produced a digital state with fewer safeguards.
The Absence of Debate: A Structural Problem
What is striking in this case, beyond the British context, is the method. Snowden’s written questions - one of the few tools available to an MP to extract information from a reluctant government - hit a wall of identical boilerplate. No budget revealed. No selection criteria. No minutes published.
Yet the decisions this group will guide touch upon the very architecture of the relationship between the state and every individual in the country: who can prove their legal existence, under what conditions, with what data exposed, and to whom. These are not technical questions. They are first-order political questions - and they are being handled in a room closed to journalists, MPs, and the public.
This precedent warrants attention far beyond the British Isles. Several European Union member states are engaged in parallel rollouts of national digital identities, often framed as technical projects. The question of who oversees these projects, with what powers and what level of transparency, will arise everywhere with the same urgency. British opacity is not an anomaly: it is a temptation that nothing, structurally, prevents from being replicated.