Structural Reform
The National Health Service was built on the principle that healthcare should be available to every citizen regardless of means. The National Digital Service (NDS) applies the same principle to the digital foundations of twenty-first century life: that every citizen should be able to prove who they are, access public services, communicate securely, and control their own data — and that the state has a duty to provide the infrastructure that makes this possible.
The NDS is not a programme. It is a permanent national institution comprising two operational arms — a universal digital identity system and a sovereign data infrastructure — governed by an independent commission accountable to Parliament. It is classified as a structural reform because it changes how the state operates rather than what it delivers to households. The services that the NDS enables — free bus travel, community food, school meals, energy and water USOs — are described in their respective service appendices. The Universal Digital Service, which guarantees every person aged 6 and over connectivity and a device, is a universal service that depends on the NDS for identity verification and entitlement management, but belongs under Universal Information Services rather than here.
This appendix describes the NDS's institutional design, governance, citizen rights regime, and physical infrastructure. The companion appendix — NDS: Digital Identity — describes the citizen-facing identity system, the five-year plan for near-universal coverage, and the tap-to-ID protocol through which citizens access universal services.
Duty
Digital security is as much a part of a state's basic responsibilities as policing the streets and defending the borders. This has been increasingly clear for many decades, but a lack of expertise and a reluctance to interfere in what appeared to be simply commercial technology has prevented states from assuming their responsibilities. The result is a world littered with digital harms — from cyber theft to cyber bullying to pervasive mental health conditions driven by unregulated platforms. Ensuring digital security involves the same trade-offs and reserved powers that societies have managed in the physical world, and covers the same level of risk to the safety of all citizens as kinetic military attack.
Prosperity 2030 assumes that this duty of care has not been fully acknowledged or actioned by 2030, and so includes policies toward assuming the responsibility and accountability that twenty-first century societies will need their governments to accept. The National Digital Service is the institutional expression of that commitment.
The urgency of sovereign digital infrastructure has been sharpened by geopolitical events. Approximately 95% of UK card transactions are processed through Visa and Mastercard — networks owned and controlled in the United States. The weaponisation of payment infrastructure is no longer hypothetical: SWIFT disconnections of Iranian and Russian banks, Visa and Mastercard's simultaneous suspension of Russian operations in 2022, and the broader pattern of US-led financial sanctions demonstrate that any nation dependent on foreign-owned payment rails faces an existential vulnerability. The Trump administration's second term — with its anti-CBDC executive orders, pro-dollar-stablecoin strategy, tariff threats, and territorial rhetoric toward allies — has converted this from a theoretical risk to a live policy emergency. Europe has responded with the European Payments Initiative (Wero, now reaching 50 million users), the digital euro (preparation phase complete, pilot scheduled 2027), and explicit statements from ECB officials that payment sovereignty is a strategic necessity. UK banks have begun developing a domestic alternative (internally codenamed DeliveryCo) targeted for launch around 2030. The NDS's tap-to-ID infrastructure provides the sovereign identity layer that any domestic payment alternative will require — ensuring that the UK has its own identity-verified transaction capability that does not depend on Visa, Mastercard, Apple Pay, or Google Pay.
The Bank of England's digital pound programme — currently in its design phase, with launch contingent on primary legislation — requires identity verification for all users. The BoE has been explicit that the digital pound would not be anonymous, though it would be private, with KYC obligations handled by regulated Payment Interface Providers. A functioning national digital identity system is therefore a precondition for a UK central bank digital currency. The NDS does not build or operate the digital pound, but it provides the identity infrastructure on which the digital pound depends. Designing the two systems in parallel — rather than discovering their interdependence after the fact — is a basic requirement of institutional competence.
Governance
A digital privacy and security commission will be established by the National Digital Service Act, tasked with maintaining the integrity, security, and day-to-day operations of both the digital identity system and the data infrastructure that supports it. This could use an existing data protection agency as a starting point and expand into a fully independent service reporting to Parliament. Its primary role will be to operate the National Digital Service under a charter to serve and protect UK citizens. Commissioners will need to pass security service vetting, be appointed by Parliament, and approve or dissent to annual reports on the integrity and service quality of the NDS.
The commission has three operational responsibilities. First, it operates the National Data Infrastructure — the sovereign facilities, networks, and systems described later in this appendix. Second, it safeguards the digital identity ecosystem — setting verification standards, managing the trust framework, overseeing tap-to-ID protocols, and ensuring that no citizen is excluded from digital public services. Third, it administers the citizen rights regime described below — the audit trail, the cryptographic entitlement, and the organisational identity register.
The commission will employ a dedicated data security force responsible for the physical and cyber protection of NDS facilities, the monitoring of access and threat patterns, and the investigation of security incidents. This is a civilian body with powers analogous to those of the NCSC but with direct operational responsibility for the NDS estate — a distinction comparable to the difference between a defence ministry (which sets policy) and a military service (which operates). At steady state, the commission's operational workforce is estimated at 3,000–5,000 personnel across facility operations, security, software engineering, and oversight functions.
The commission's charter must include explicit scope control. The NDS serves the programme's security-critical and cross-departmental workloads — identity verification, service transaction processing, inter-departmental data reconciliation, cryptographic key management, and secure communications. It does not absorb departmental IT operations. HMRC, DWP, NHS Digital, and other departments continue to operate their own processing systems on their own infrastructure. The NDS provides the sovereign-grade joins between departments, not a centralised replacement for them.
Citizen cryptographic rights
The NDS issues every registered citizen a cryptographic identity — a key pair bound to their device or NFC card's secure element — as the foundation of tap-to-ID verification. Following the Estonian model, which has provided every citizen with two key pairs (authentication/decryption and digital signature) since 2002, the NDS extends this cryptographic capability beyond service access to general-purpose use. Every NDS credential holder can encrypt personal data so that only they can read it, digitally sign documents with legal force equivalent to a handwritten signature, encrypt communications end-to-end with any other NDS credential holder, and grant and revoke time-limited, field-level access to their personal data — a doctor sees health records, an employer sees qualifications, neither sees the other.
This is not an optional feature. It is the digital equivalent of the right to seal a letter — the ability to communicate and store information in a form that cannot be read by anyone, including the state, without the citizen's explicit consent. The commission's charter prohibits the NDS from holding or escrowing citizens' private keys. Key generation occurs inside the secure element on the citizen's device or NFC card; the private key never leaves that element.
The National Digital Service Act will need to address the tension with existing law. Section 49 of the Regulation of Investigatory Powers Act 2000 gives the state power to compel disclosure of encryption keys, with penalties of up to two years' imprisonment for non-compliance (five years in national security cases). The programme's position is that NDS-issued keys should receive stronger statutory protection than general-purpose encryption — precisely because they are the foundation of the citizen's relationship with public services and the mechanism through which the state's own audit trail operates. Primary legislation should limit compulsion of NDS keys to cases authorised by judicial warrant, with the audit trail recording the warrant, the authorising court, and the investigating officer's identity, and with the citizen notified after a delay governed by the commission (see below). This represents a rebalancing, not an abolition, of the state's investigatory powers — one designed to ensure that the digital identity system commands the public trust on which its adoption depends.
Audit trail
Every query against a citizen's identity record through the NDS gateway is logged in an immutable, citizen-visible audit trail. The citizen can see, through their wallet or NDS portal, every instance in which their identity was accessed: who queried it (the individual officer's NDS identity), which organisation they represent (the organisation's NDS credential), and — where applicable — the authorising authority (the court, judge, or senior officer who approved the access). Estonia's Data Tracker, operational since 2017, demonstrates that this model works at national scale: Estonian citizens can see which of the 479 institutions connected to the X-Road data exchange layer have accessed their records, and unauthorised access by public servants has been detected and prosecuted through the audit log.
The audit trail applies at the NDS gateway level — that is, the citizen sees that a query was made against their NDS identity, by whom, and under what authority, but not necessarily which downstream departmental databases were subsequently consulted. Extending the audit trail into departmental systems is a longer-term ambition that requires compatible logging across all connected departments; the NDS gateway audit is the achievable first commitment.
For law enforcement and national security access, the audit trail still records every query, but disclosure to the citizen is delayed. The commission governs delay periods under the following indicative framework:
- Routine queries (e.g., identity verification for regulatory compliance): no delay; visible to the citizen immediately.
- Active criminal investigations: disclosure delayed by a default period — perhaps 90 days — after which the citizen is automatically notified unless the investigating authority applies to the commission for an extension.
- Serious and organised crime: longer default delay — perhaps 12 months — with extensions requiring application to the commission supported by a statement from a senior officer.
- National security: delay governed by the commission in consultation with the Investigatory Powers Commissioner, with a statutory maximum that prevents indefinite suppression. Even in national security cases, the audit record exists; the question is only when the citizen sees it.
Every application for delay or extension must itself carry the NDS identities of the applying officer, their organisation, and the authorising authority. There is no anonymous access to citizen records. The commission publishes aggregate annual statistics on the volume of delayed disclosures by category, the average delay period, and the number of extensions granted — providing parliamentary oversight without compromising individual investigations.
Organisational identity
The NDS issues digital identities to organisations as well as citizens. Every organisation that interacts with the NDS — whether as a service provider (bus operators, food venues, schools, energy suppliers), an employer conducting right-to-work checks, a public authority accessing citizen records, or a commercial entity verifying customer identity — must hold an NDS organisational credential.
Organisational credentials are anchored to sponsoring natural persons. An organisation cannot hold an NDS identity in the abstract; at least one named, NDS-verified individual must be registered as its responsible officer. This follows the principle embedded in Estonian law — "only real persons can give signatures" — and aligns with the UK's own direction of travel under the Economic Crime and Corporate Transparency Act 2023, which from November 2025 requires identity verification of all company directors and persons with significant control.
The organisational identity register builds on existing infrastructure. Companies House, already implementing mandatory identity verification for approximately 7 million individuals associated with UK companies, provides the registry backbone for corporate entities. The NDS extends this by issuing cryptographic organisational credentials — following the verifiable Legal Entity Identifier (vLEI) model developed by the Global Legal Entity Identifier Foundation — that bind the organisation's verified identity, its responsible officers, and their roles into a single, machine-readable, tamper-evident credential. For public-sector bodies, the NDS issues organisational credentials directly.
Private organisations must have at least one sponsoring citizen — an NDS-verified individual who accepts accountability for the organisation's use of NDS services. For companies, this is typically a director already verified through Companies House. For sole traders, charities, and unincorporated organisations, registration through the NDS organisational register links the entity to its responsible person. The register is designed to become self-sustaining through registration fees at scale, following the LEI model (currently approximately £60–80 per entity per year globally).
In practice, organisational identity means that when a participating food venue processes a tap-to-ID service claim, the terminal identifies itself — cryptographically, not just by network address — as belonging to a specific registered entity, operated by a named responsible person. When a police officer queries a citizen's NDS record, the query carries not just the officer's personal NDS identity but the organisational credential of their force and the credential of the authorising authority. This creates accountability at every level: individual, organisational, and institutional.
National Data Infrastructure
Purpose
The safety of the state, democracy, and every citizen depends on the implementation of protocols and systems that allow data to be stored and transmitted without interruption, corruption, or unauthorised exposure. The National Data Infrastructure (NDI) — the operational backbone of the NDS — ensures this. It comprises the data centres, networks, and systems that the commission operates under its charter, designed with security as the highest priority — comparable in design philosophy to the protection of critical national infrastructure in energy and defence.
Services the NDI supports
Almost every service in Prosperity 2030 depends on this infrastructure. The following programme services are listed in approximate order of data throughput and processing intensity at steady state:
- Digital identity verification and tap-to-ID transaction processing. The programme's universal services generate approximately 50–100 million tap events per day across transport, food, and other access points — volumes comparable to a major payments network. Identity resolution requires sub-second database queries across multiple government systems for every event.
- Audit trail and access logging. Every NDS gateway query generates an immutable audit record. At 50–100 million tap events per day plus law enforcement and administrative queries, the audit system processes and stores billions of records annually, each cryptographically signed and linked to the querying individual's and organisation's NDS credentials.
- National Contributions identity verification and cross-departmental reconciliation. HMRC's bulk payroll processing — approximately 30 million PAYE submissions — remains on HMRC's own infrastructure, which is already designed for that task. The NDI hosts the secure API gateways that connect HMRC's Real Time Information system, DWP benefit deduction feeds, and the identity resolution service for P800 year-end reconciliation across all income sources. It also holds the cryptographic key management for NC-related identity verification. The NDI provides the joins between departmental systems, not a replacement hosting platform for them.
- Energy USO smart metering and grid management. Smart meter data from 28 million households, transmitted at 30-minute intervals, generates approximately 1.3 billion data points per day. Grid balancing and standing charge absorption require real-time data flows between the NDI, GB Energy Network, and distribution network operators.
- Water catchment monitoring. Catchment Water System Operator (CWSO) telemetry from sensor networks across England and Wales, supporting real-time water quality monitoring, flood risk management, and infrastructure maintenance scheduling.
- NHS and care service records. Patient records, care quality monitoring, and the universal care service's scheduling and allocation systems. Health data carries the highest sensitivity classification and the strictest access control requirements.
- Food distribution and venue reimbursement. Community Food Centre supply chain management, school meal allocation, and participating venue transaction processing and reimbursement — approximately 4–5 million food service transactions per day at steady state.
- Transport usage monitoring. Boarding data from the universal bus service, supporting operator reimbursement, route optimisation, and capacity planning — approximately 15–20 million boarding events per day.
- Organisational identity register. The cryptographic credential infrastructure for all NDS-registered organisations, including certificate authority functions, credential lifecycle management, and the sponsoring-person verification system.
- Local democracy and public communications. Secure infrastructure for electoral administration, council communications, and the programme's citizen notification systems.
In aggregate, the programme's services will generate approximately 3–5 billion data transactions per year requiring sovereign-grade security, with secure storage requirements growing to an estimated 50–100 petabytes within five years and backbone capacity requirements of multiple terabits per second across the core network.
Existing baseline and the case for sovereign capacity
The UK government currently operates approximately 150 data centres through Crown Hosting and departmental facilities, alongside extensive use of commercial cloud services (primarily AWS, Microsoft Azure, and Google Cloud). Total government IT spending is approximately £4–5 billion per year across departments, of which roughly £1.50–2.00 billion is infrastructure. The National Cyber Security Centre (NCSC) operates on a budget of approximately £0.25 billion per year.
The NDI does not replace commercial cloud for general government computing, nor does it absorb departmental IT operations. Departments — including HMRC, DWP, and NHS Digital — continue to operate their own processing systems on their own infrastructure or commercial platforms. What the NDI provides is the sovereign-grade layer for workloads that span departments and cannot be entrusted to foreign-owned infrastructure: identity verification, cross-departmental data reconciliation (such as P800 matching across HMRC, DWP, and the identity system), service reimbursement transaction processing, health record interoperability, security-critical communications, and the cryptographic key management systems that underpin the entire digital identity ecosystem. These workloads require guaranteed UK jurisdiction, UK-vetted personnel, and physical security beyond what commercial cloud providers offer or contractually guarantee.
The NDI therefore represents an approximately 40% increase in dedicated government digital infrastructure spend, concentrated on the security-critical workloads that the programme's universal services create. It consolidates and security-hardens the existing Crown Hosting estate while adding the capacity required by the programme's new services — replacing aging facilities with purpose-built sovereign infrastructure rather than perpetually extending commercial cloud contracts for workloads that belong under direct government control.
Physical facilities
Multiple redundant physical facilities will house the core computing hardware. These will be security-hardened facilities — including underground installations where terrain and existing infrastructure permit — designed to maintain operations for up to a week without external power, with hibernation capabilities for extended periods of disconnection. Distributed across the country in a minimum of six geographic zones, each facility will be able to assume the functions of two peer facilities in the event of disconnection or compromise. Site selection will prioritise proximity to renewable energy sources, existing fibre trunk routes, and geological stability.
The UK has existing hardened facility capacity — former MOD installations, nuclear-rated bunker infrastructure, and Crown Hosting sites with partial resilience — that can serve as the starting estate, reducing early capital requirements and accelerating initial operational capability.
Core network
A secure core network will connect the primary data stores, physically separated from the public internet and employing quantum-resistant encryption on all inter-facility links. Gateways with layered intrusion detection and traffic inspection will connect the core network to the internet, over which most citizen-facing services will be delivered. The core network's design must assume that any single link or node can be compromised without exposing the system's integrity — the same redundancy philosophy that governs the physical facilities.
Systems and software
Systems designed to sovereign specifications will provide the highest levels of data security within NDI facilities. This means security-hardened deployments of open-source platforms — hardened Linux kernels, formally verified cryptographic libraries, and custom firmware for storage and networking hardware — rather than dependence on proprietary commercial operating systems whose source code cannot be fully audited. Focused design on core data storage and communications allows for the development of modular, low-energy systems deployed across the infrastructure, supporting standardisation and redundancy. Hardware supply chain integrity — verifying that computing equipment has not been compromised before installation — requires dedicated testing facilities and vetted procurement channels.
A sovereign software capability will be maintained as a permanent function of the commission: a security-cleared engineering workforce that can audit, harden, patch, and extend open-source platforms to sovereign specifications, with a long-term support commitment independent of any single commercial vendor. This is the software equivalent of the UK's defence procurement function — specifying, assuring, and maintaining critical systems rather than manufacturing every component.
Budget
The NDS budget totals £12.50 billion over five years: £0.50 billion in Year 1 (digital identity foundation only, before the NDI build begins) and £3.00 billion per year in Years 2–5. The citizen cryptographic rights, audit trail system, and organisational identity register are accommodated within the existing envelope, drawing on the service integration, software development, and contingency lines in both the digital identity and NDI budgets. The organisational identity register is designed to become self-sustaining through registration fees at full scale.
The Digital Identity and National Data Infrastructure (NDI) budgets fund a single system, and the boundary between them is functional. The Digital Identity budget carries everything the citizen touches: terminals, cards, enrolment, assisted verification, inclusion, the service desk, and the identity resolution and fraud prevention services directly behind them. The NDI budget carries everything the identity system stands on: facilities, the core network, cryptographic key management, the audit trail platform, the organisational identity register, and the secure gateways between departments. Each cost is booked once, in one budget only. Where a commitment spans the boundary, the audit trail being the clearest case (built and operated on NDI lines, fed by Digital Identity tap events), the build and operating cost sits in the NDI and the transaction volumes are carried in the NDI capacity plan. Steady-state costs divide on the same rule: £1.00 billion for the citizen-facing identity service, £2.00 billion for the platform it runs on.
Combined budget by year
| Year 1 | Year 2 | Year 3 | Year 4 | Year 5 | Total | |
|---|---|---|---|---|---|---|
| Digital Identity | 0.50 | 1.00 | 1.00 | 1.00 | 1.00 | 4.50 |
| National Data Infrastructure | — | 2.00 | 2.00 | 2.00 | 2.00 | 8.00 |
| NDS Total | 0.50 | 3.00 | 3.00 | 3.00 | 3.00 | 12.50 |
All figures in £ billions, 2025 prices.
NDI budget detail
| Component | Year 2 | Year 3 | Year 4 | Year 5 | Total |
|---|---|---|---|---|---|
| Facility construction and fit-out | 0.80 | 0.60 | 0.30 | 0.15 | 1.85 |
| Core network build | 0.30 | 0.25 | 0.10 | 0.05 | 0.70 |
| Systems and hardware procurement | 0.35 | 0.35 | 0.25 | 0.20 | 1.15 |
| Software development and hardening | 0.20 | 0.25 | 0.30 | 0.30 | 1.05 |
| Commission staffing and operations | 0.15 | 0.25 | 0.40 | 0.50 | 1.30 |
| Service integration and migration | 0.10 | 0.20 | 0.35 | 0.40 | 1.05 |
| Security, testing, and contingency | 0.10 | 0.10 | 0.30 | 0.40 | 0.90 |
| NDI total | 2.00 | 2.00 | 2.00 | 2.00 | 8.00 |
Capital and operational trajectory
The NDS's spending profile shifts substantially over the five-year period. In Year 2, approximately 60% of the NDI budget is capital expenditure (facility construction, network build, hardware procurement); by Year 5, approximately 80% is operational (staffing, software maintenance, service integration, security). The digital identity budget follows a different curve: Year 1 is predominantly capital (terminal deployment, infrastructure setup), while Years 4–5 are predominantly operational (card refresh, running costs, ongoing inclusion). The Digital Identity budget detail is provided in the companion appendix.
The new commitments — citizen cryptographic capability on NFC cards (approximately £1–2 additional per card, absorbed within the £1.00 billion card line), the audit trail system (approximately £0.10–0.20 billion build and £0.03–0.05 billion per year operating, absorbed within the NDI's service integration and software lines), and the organisational identity register (approximately £0.15–0.25 billion build, absorbed within service integration, with ongoing costs designed to be fee-funded) — consume roughly half of the programme's contingency reserve. The budget moves from comfortable to disciplined: it works if the commission manages scope tightly, but there is limited room for overruns.
At steady state beyond Year 5, the NDS requires approximately £3.00 billion per year — £1.00 billion for digital identity operations and £2.00 billion for NDI operations — funded from the programme's fiscal space. The £2.00 billion NDI steady-state cost covers facility operations, hardware refresh (replacing approximately 20% of the computing estate annually on a five-year cycle), the commission's permanent workforce, software maintenance, and continuous security improvement. This is sufficient and defensible provided the commission maintains scope discipline — serving the programme's defined security-critical workloads rather than absorbing every departmental IT project that would prefer sovereign hosting.
Benchmarks
The NDS's combined spend of £12.50 billion over five years is large by international standards but proportionate to the services it enables. India's Aadhaar system — covering 1.4 billion people, underpinning direct benefit transfer, financial inclusion, and tax administration — cost an estimated £4–7 billion all-in. Estonia's entire public digital infrastructure operates on approximately £0.15 billion per year for 1.3 million people. The UK's defence digital infrastructure (Defence Digital) operates on approximately £2.00 billion per year. The NHS digital transformation programme has consumed approximately £4.00 billion since 2019. The private sector invests approximately £4–5 billion per year in UK data centre capacity. The NDS budget sits within this landscape as a permanent institutional commitment comparable in scale to a major defence capability.
The critical efficiency metric is not the cost of the NDS itself but the administrative savings it generates. Manual eligibility verification, paper-based registration, and fraud investigation for a programme delivering £49 billion in annual services would cost substantially more than the digital system that automates these functions. A conservative estimate of 2–3% administrative cost saving on programme service delivery implies £1.00–1.50 billion per year in avoided costs — a payback period under ten years on the full NDS investment, and a permanent efficiency gain thereafter.
That estimate is deliberately not booked. The NAO's investigation into Verify found a benefits case revised down 75% that still could not be validated, with successive decisions to continue the programme justified against it. The programme's cashflow therefore carries the NDS at its full gross cost of £12.50 billion, funded from identified revenues; the £1.00–1.50 billion per year of avoided administrative cost, and the registration fee income designed to make the organisational register self-sustaining, appear nowhere as revenue. If realised, they accrue as headroom, not as funding assumptions.
The commission staffing and software lines (£1.30 billion and £1.05 billion across Years 2 to 5) are also a lesson from the record. Fishenden (2020) traces a quarter-century in which identity programmes outsourced the capability itself, relearning the same lessons as each contract cycle turned over. A permanent, security-cleared, in-house engineering workforce is what makes the NDS an institution rather than another programme, and it is priced accordingly.
References
Fishenden, J. (2020) Federated Identity for Access to UK Public Services: 1997–2020. An Overview. Available at: https://ntouk.wordpress.com/wp-content/uploads/2020/06/federated-identity-for-access-to-uk-public-services-1997-2020-jerry-fishenden-1.pdf (Accessed: 16 July 2026).
National Audit Office (2019) Investigation into Verify. HC 1926, Session 2017–2019. London: National Audit Office. Available at: https://www.nao.org.uk/reports/investigation-into-verify/ (Accessed: 16 July 2026).
All figures in 2025 prices. The NDS provides identity infrastructure for but does not itself build or operate the digital pound, DeliveryCo, or the skills credentialing system; these are parallel programmes that benefit from and depend on the NDS identity layer. Technical specifications, facility locations, and network architecture are subject to detailed design following the establishment of the commission. This appendix establishes the scale of institutional commitment and the rationale for sovereign digital infrastructure; it is not a technical specification.
Source: IGP Social Prosperity Network.