Executive Summary
This briefing supports a UK policy document on a National Digital Service that would issue digital identities to both citizens and organisations. It collates evidence across three interlocking topics: (1) audit trail systems that make government data access visible to citizens, drawing on Estonia’s Data Tracker and comparator regimes; (2) organisational digital identity systems including Estonia’s e-Business Register, the EU’s eIDAS 2.0 framework, the Global Legal Entity Identifier (LEI) and verifiable LEI (vLEI), and the UK’s reformed Companies House regime under the Economic Crime and Corporate Transparency Act 2023 (ECCTA); and (3) the cryptographic rights and key management arrangements that determine whether citizens, in practice, control their own keys. Specific findings, with statistics where available, are set out below.
TOPIC 1 — Audit Trail Systems for Government Access to Citizen Data
1.1 Estonia’s Data Tracker (Andmejälgija)
The Data Tracker was launched by Estonia’s Information System Authority (RIA) in 2017 and sits inside the state portal eesti.ee. Its purpose, as RIA describes it, is to give “the citizen … a clear overview of the operations performed with their data” — both internal database operations and inter-agency data exchanges across the X-Road interoperability layer. RIA publishes a protocol that database owners must implement as an X-Road service so that their access logs feed into a single, citizen-facing view; the tool was funded in part by the European Regional Development Fund.
How it works in practice. A citizen authenticates to eesti.ee using their ID-card, Mobile-ID, Smart-ID or, since July 2025, the new state Eesti.ee mobile app, and can see logged events showing who queried data about them, when, and for what purpose. From 7 July 2025 the Eesti.ee app added in-person identity verification via QR code, and on 4 June 2025 the Riigikogu amended the Identity Documents Act to give app-based digital identification the same legal standing as a physical ID. By early July 2025 the app had been downloaded by more than 54,000 users following a pilot involving 2,300 volunteers; user satisfaction averaged 4 out of 5.
Coverage and statistics. Estonia’s e-Estonia briefing (which is the publicly available baseline) notes that “479 institutions and enterprises rely on the national data exchange layer X-Road – and over a million Estonian citizens and residents,” and that the Data Tracker initially covered four core databases. X-Road has been live since 2001; “as of the beginning of [the relevant] month, over 5 billion queries have been exchanged on the X-Road … Almost 986 million requests took place in 2018.” Among the heaviest service providers, the Estonian Health Insurance Fund alone handled 7,182,244 X-Road queries in the month referenced. There is, however, no comprehensive published dataset breaking down access events by purpose.
Enforcement effects. Unauthorised access by a public servant is a criminal offence in Estonia, and visibility through the Data Tracker has produced concrete sanctions — for example, an Estonian police officer who looked up his future wife’s record, and a paramedic who checked an ambulance call-out at a neighbour’s request, both admitted wrongdoing and paid fines after their access was logged. The Data Protection Inspectorate (DPI) reports receiving “over 3,000 inquiries per year,” with questions outnumbering complaints since GDPR came into force in 2018, according to Maarja Kirss, the DPI’s Head of Cooperation.
Important limits. The Data Tracker covers only government-held data flowing through X-Road; private-company access (e.g., Meta, Google) is not visible unless the company is participating in delivering a specific public service.
1.2 Comparator regimes
No other EU member state has yet replicated the Data Tracker as a single, universal, citizen-facing audit interface across all government databases. The eIDAS 2.0 European Digital Identity Wallet Architecture and Reference Framework (ARF v1.4, May 2024) requires wallets to log attribute attestations issued and shared so that users can see, and where appropriate withdraw, what has been transferred — but this is a wallet-level audit log of credential presentation, not a logging requirement for every government-held database query. Estonia is described by international observers (LOTI, Microsoft, the e-Governance Academy) as having the most mature operational model anywhere.
1.3 UK existing mechanisms
The UK does not provide an automatic, citizen-visible audit feed of government access to citizen data. It instead relies on:
- Subject Access Requests (SARs) under Articles 15 and 23 of the UK GDPR, which require a citizen to actively request a copy of their data and information about its disclosures.
- Investigatory Powers Commissioner’s Office (IPCO) oversight of investigatory powers under the Investigatory Powers Act 2016 (IPA). IPCO oversees the use of investigatory powers by over 600 public authorities, including the intelligence agencies and law enforcement. The 2023 Annual Report (HC 603) recorded just under 360,000 authorisations across all powers in 2023, with year-on-year growth of “between 9–10%,” and 386 inspections carried out by IPCO Inspectors. The 2024 Annual Report (HC 1277), laid before Parliament on 16 December 2025 by the Investigatory Powers Commissioner Sir Brian Leveson, notes the merger on 1 March 2024 of IPCO with the Office for Communications Data Authorisations (OCDA), and an approximate 4% reduction in IPCO funding for 2025/26.
- Notification regimes under RIPA / IPA: subjects of intercept warrants are not routinely notified; the Investigatory Powers Tribunal hears complaints, and the IPC can notify a “serious error” to an affected person under section 231 IPA where it is in the public interest. Annex C of the 2024 Annual Report (titled “Serious errors”) describes the framework but not large numbers of citizen notifications.
- Data breach notification under UK GDPR Article 34 (high risk to individuals’ rights) and the ICO’s threshold regime — reactive, not preventative.
1.4 Delayed notification in law-enforcement contexts
Comparators on the secrecy/notice tension are well established:
- United States – “sneak and peek” warrants under §213 USA PATRIOT Act 2001 (codified at 18 U.S.C. §3103a). Notice of execution can be delayed where the magistrate finds reasonable cause that immediate notice would have an “adverse result” (endangerment, flight, destruction of evidence, witness intimidation, or jeopardising the investigation). The 2005 Reauthorization Act set a guideline of notice within 30 days of execution, with extensions of up to 90 days for good cause. Volume is substantial: in FY2020 courts issued close to 20,000 thirty-day delayed-notice search warrants and approved extended delayed notice in more than 10,000 cases. Drug cases accounted for more than 70% of issuances; fewer than 250 were terrorism investigations — illustrating the well-documented “mission creep” of delayed-notice powers.
- United Kingdom – RIPA Part III §49 notices: a person served with a notice can be barred from telling anyone except their lawyer that they have received it, with criminal penalties for “tipping off” (see Topic 3 below).
- The general policy tension — between investigative secrecy and a citizen’s right to know — is addressed in academic and Congressional Research Service literature (e.g., CRS LSB10652) but has not been resolved with a uniform “tell-after-X-days” mechanism in the UK.
1.5 Academic/think-tank work on automatic audit trails
Privacy International’s analysis of e-Estonia describes the Data Tracker as a leading example of “privacy by design” combined with detective controls, while flagging that key generation flaws (the 2017 ROCA vulnerability affecting around 750,000 ID cards, and the 2011 distribution of around 120,000 faulty cards) underline the importance of where private keys are generated. The e-Governance Academy’s December 2025 podcast and blog with the Estonian DPI argue that visibility-by-default deters misuse and that “transparency becomes a working system of accountability.” The OECD Working Party of Senior Digital Government Officials (chaired by Siim Sikkut, Estonia’s former Government CIO) has highlighted the Estonian model in its peer reviews as a benchmark for trust architecture.
TOPIC 2 — Organisational Digital Identity Systems
2.1 Estonia’s e-Business Register
Estonia’s e-Business Register, operated by the Centre of Registers and Information Systems (RIK) under the Tartu County Court Registration Department, is the foundational organisational identity layer. Since 2011 most companies have been incorporated online via the e-Business Register; registration has fallen “from 5 days to a couple of hours.” Authentication and digital signature for filings require an Estonian ID-card, Mobile-ID, Smart-ID, or e-Residency digital ID. The portal lets users register companies, sole traders, non-profits and state agencies; submit annual reports; manage members lists; check beneficial owners and tax-arrears information; and (crucially) see all the legal persons connected to them. Each legal entity has an 8-digit Registry Code (Registrikood).
A core architectural feature is that, under Estonian law, “only real persons can give signatures.” Organisational e-seals (digital seals) exist for institutional authentication of documents but legally function as additional authenticity tools accompanied by the digital signature of a natural person acting for the organisation — i.e., the sponsoring natural person model is built into Estonian PKI from the outset.
2.2 EU eIDAS 2.0 — organisational dimension
Regulation (EU) 2024/1183, which amends the 2014 eIDAS Regulation, was published in the Official Journal on 30 April 2024 and entered into force on 20 May 2024. It establishes the European Digital Identity (EUDI) Wallet framework. Five Implementing Regulations adopted on 28 November 2024 (published 4 December 2024) specify wallet integrity, Person Identification Data (PID) and Electronic Attestations of Attributes (EAAs), interoperability protocols, certification, and notifications. By late December 2026 every Member State must make at least one EUDI Wallet available; from late December 2027 a wide range of public bodies and regulated private-sector relying parties (financial services, telecoms, transport, very large online platforms) must accept it.
The organisational dimension comprises three building blocks:
- Legal Person Identification Data (LPID). The wallet framework allows issuance of credentials representing a business’s identity (name, registration number, VAT number, authorised representative status). LPIDs would typically be issued by a national business registry or chamber of commerce.
- Qualified Electronic Attestations of Attributes (QEAA) and Public EAAs (PubEAA). Qualified Trust Service Providers (QTSPs) issue QEAAs that carry legal trust across the EU; PubEAAs are issued by public authorities.
- Qualified Electronic Signatures and Seals (QES / QESeal). The wallet must, by default and free of charge to natural persons, support QES creation. For organisations, qualified electronic seals provide entity-level signatures.
Article 5a of the regulation requires the Commission to set reference standards and procedures by 21 November 2024; under the EU’s “Digital Decade” target, 80% of citizens are intended to use a digital ID by 2030.
2.3 The Global Legal Entity Identifier (LEI) and vLEI
The LEI is a 20-character alphanumeric ISO 17442 code identifying a legal entity uniquely worldwide. It is governed by the Financial Stability Board (FSB)–created Global Legal Entity Identifier Foundation (GLEIF), a supra-national not-for-profit established in 2014 and headquartered in Basel. GLEIF reports the Global LEI System as having 2.93 million active LEIs at end-2025, after issuance of more than 355,000 new LEIs during 2025 — an annual growth rate of 13.5%, up from 11.5% in 2024. About 89,000 LEIs were issued in Q4 2025 alone (3.1% quarterly growth). India retained the second-largest active LEI population, growing 49.2% in 2025; growth was driven elsewhere by EU rules including the Digital Operational Resilience Act (DORA), which from January 2025 mandated the LEI as the sole identifier for non-EU ICT service providers used by EU financial institutions. GLEIF also reports over 6,600 government entities and 81 international organisations with LEIs at end-2025, and a 2025 LEI renewal rate of 57.1%. GLEIF coordinates a network of 23 Validation Agents across Africa, Australasia, China, Europe, India, the Middle East and North America.
The verifiable LEI (vLEI) is GLEIF’s W3C/Trust over IP verifiable-credential implementation, standardised in ISO 17442-3 (2024). The vLEI Ecosystem Governance Framework defines four credential types: a Legal Entity vLEI Credential (issued by Qualified vLEI Issuers — QVIs — to a legal entity); a QVI Authorisation vLEI Credential; a Legal Entity Official Organisational Role (OOR) vLEI Credential (using ISO 5009 role codes — for example, “director” or “CFO”); and a Legal Entity Engagement Context Role (ECR) vLEI Credential. GLEIF’s Root Autonomic Identifier (AID) provides the cryptographic root of trust; credentials use the Authentic Chained Data Container (ACDC) specification on top of Key Event Receipt Infrastructure (KERI). Crucially, the vLEI explicitly combines three concepts — the organisation’s identity (LEI), a person’s legal name, and the role that person plays for the legal entity — and so directly embodies the sponsoring natural person principle. vLEIs are designed to be issued into organisational wallets and to interoperate with the EUDI Wallet ecosystem.
2.4 UK Companies House digital identity (ECCTA 2023)
The Economic Crime and Corporate Transparency Act 2023 (ECCTA) is reshaping UK organisational identity. Mandatory identity verification for individuals associated with UK companies came into force on 18 November 2025, after a voluntary phase from 8 April 2025. By the start of the mandatory period, more than 300,000 individuals had verified during the voluntary window.
The scheme covers all directors, persons with significant control (PSCs), members of LLPs, and individuals who file at Companies House. Verification can be performed:
- Directly via the GOV.UK One Login ID Check app (using a UK biometric passport, photocard driving licence, biometric residence permit, or frontier worker permit) — average completion time 2.4 minutes (18 March – 30 June 2025); or
- Indirectly via an Authorised Corporate Service Provider (ACSP) — a UK-AML-supervised firm (typically a solicitor, accountant or company-secretarial provider) authorised by Companies House. ACSP registration opened on 18 March 2025.
Once verified, an individual receives a Companies House personal code that they re-use across all their roles and across companies, demonstrating “verify once, use many.” Existing directors must verify by reference to their next confirmation statement during the 12-month transition period ending in November 2026; existing PSCs must verify within 14 days of the first day of their birth month following commencement. Filings submitted by unverified individuals will be rejected unless routed through an ACSP. Directors of overseas companies with a UK establishment, and individual LLP members and PSCs, are also brought in from 18 November 2025; rules for corporate directors, corporate LLP members, officers of corporate PSCs and limited partnerships are due in 2026–2027. From 1 April 2027 Companies House plans software-only iXBRL-tagged accounts filing and the abolition of abridged accounts. Around 7 million individuals are in scope. The YouGov Business Omnibus survey of 1,007 senior decision-makers (16–25 June 2025) found 81% support for the new identity verification process and 73% agreement that directors and PSCs would find it easy to verify.
The failure-to-prevent-fraud offence under ECCTA came into force on 1 September 2025, materially increasing organisational accountability.
2.5 UK Register of Overseas Entities (ROE)
The ROE was created by the Economic Crime (Transparency and Enforcement) Act 2022 and opened on 1 August 2022. Any overseas entity holding a “qualifying estate” — a freehold or a leasehold of more than seven years in UK land — must register with Companies House and disclose registrable beneficial owners (RBOs) or, if none, managing officers. Critically, all information must be independently verified by a UK-regulated agent holding a Companies House agent assurance code (typically an AML-supervised solicitor, accountant or trust/corporate service provider); self-certification is not permitted. Each entity receives an Overseas Entity ID that must be presented to HM Land Registry or the Registers of Scotland before any property transaction. Penalties for non-compliance include daily fines of up to £2,500 and up to five years’ imprisonment. ECCTA 2023 strengthened the regime with title-number disclosure, the requirement to provide a “principal office” address in addition to a registered office, designated contact persons for under-16 managing officers, and trust-related disclosure obligations. The Register of Overseas Entities (Protection and Trusts) (Amendment) Regulations 2025 enable certain trust-related information to be accessed by the public on application from 31 August 2025, where a legitimate interest is demonstrated. OpenOwnership has noted that the UK-regulated agent structure creates domestic liability for verification but does not yet require agents to disclose what specific documents they used to verify — a noted weakness compared with full disclosure-based verification systems.
2.6 Tap-to-ID and organisational presentation
The combination of the LEI (for stable, globally unique identification of the entity), the vLEI (for cryptographic, role-bound presentation), and an EUDI-compatible organisational wallet provides the building blocks for a “Greggs-terminal-identifies-itself-as-Greggs-plc” tap-to-ID flow. In this model, a point-of-service device would hold an organisational vLEI credential cryptographically chained back to GLEIF’s root of trust and ISO 17442-3, plus an OOR credential for the human officer or ECR credential for the engagement context (e.g., the cashier acting on behalf of Greggs plc to verify a service claim). The relying party’s wallet would receive a verifiable presentation that includes the organisation’s verified identity, the role of the presenting principal, and (optionally) selectively disclosed attributes such as the entity’s UK Companies House registered number. For UK use, integration with Companies House’s verification regime (personal codes for officers; ACSP-vouched filings) and with the ROE (Overseas Entity ID) would supply the underlying registry truth.
TOPIC 3 — Citizen Cryptographic Rights and Key Management
3.1 Estonia’s PKI infrastructure
Since 2002, Estonian eID documents have provided two asymmetric key pairs with corresponding X.509 certificates on every ID-card chip:
- Authentication key — used for TLS client authentication into e-services; can also be used for decrypting documents encrypted to the cardholder. Operations are authorised by the 4-digit PIN1 code.
- Digital signature key — used to give legally binding digital signatures that under eIDAS qualify as Qualified Electronic Signatures (QES), authorised by PIN2.
Citizens can use the DigiDoc4 client to encrypt and decrypt documents, sign documents (in BDOC/ASiC-E containers using the ETSI XAdES standard), and authenticate. Estonia’s PKI is overseen by RIA, with certificates issued by SK ID Solutions; the Digital Signature Act 2000 gives digital signatures equivalence to handwritten signatures. The same key infrastructure underpins Mobile-ID, Smart-ID, the e-Resident’s digital ID, and digital seals issued for institutions. Under the Identity Documents Act, only real persons can give signatures; institutional “signatures” are e-seals.
Modern Estonian ID-card chips use 384-bit elliptic curve cryptography (ECC) following the 2017 ROCA vulnerability that affected RSA-keyed cards. Key generation now occurs inside the chip, ensuring the private key never leaves the secure element — a fix to the architectural concern earlier flagged by Privacy International.
Estonia’s e-Estonia and RIA materials describe an emerging “next-generation” model based on split-key technology for mobile wallet implementations, particularly where European certification (CC EAL, FIPS 140) is required and a physical secure element is unavailable.
3.2 EU eIDAS 2.0 and citizen cryptography
eIDAS 2.0 elevates the citizen’s cryptographic rights to a default. Article 5a of Regulation (EU) 2024/1183 mandates Qualified Electronic Signatures by default and free of charge for natural persons using the EUDI Wallet. The wallet must rely on Qualified Signature/Seal Creation Devices (QSCDs), and citizens must be able to apply QES and QESeals using keys stored in or accessible via the wallet. Implementing Regulation (EU) 2025/1944 (29 September 2025) addresses qualified electronic registered delivery services, while the seven implementing regulations published on 30 July 2025 cover the broader trust services package. The Wallet’s Architecture and Reference Framework (ARF) requires logging of attribute attestation events, providing the user with a withdrawal mechanism aligned to GDPR’s right to erasure. In short: the EUDI Wallet is, by design, a citizen-controlled signing and decryption instrument as well as an identity instrument.
3.3 UK Investigatory Powers Act 2016 / RIPA Part III §49
Section 49 of the Regulation of Investigatory Powers Act 2000, the operative power to compel disclosure of “protected information,” came into force on 1 October 2007 and remains UK law, sitting alongside the Investigatory Powers Act 2016 framework. Key features:
- A section 49 notice can require a person to either hand over a key (defined broadly as “any key, code, password, algorithm or other data”) or produce the protected information in intelligible form.
- Disclosure may be compelled where it is necessary in the interests of national security, for the prevention or detection of crime, or for the economic well-being of the UK, and is proportionate, with no other reasonably practicable means of obtaining the information (s.49(2)–(3)).
- Failure to comply is an offence under section 53 punishable by up to two years’ imprisonment, or up to five years in cases involving national security or child indecency (Coroners and Justice Act 2009 amendment).
- A “tipping-off” prohibition can be imposed: a recipient of a notice can be barred from telling anyone except their lawyer that they have received it (s.54).
- Section 49(9) excludes keys used solely for generating electronic signatures — preserving authentication-only keys from compulsion (a narrow but important right).
- Notices must be authorised by a circuit judge or, in a magistrates’ court, a district judge, and oversight is provided by the Investigatory Powers Commissioner under the Revised Code of Practice (2018).
The Investigatory Powers Act 2016 did not modify s.49 but extended the broader landscape: under section 253 IPA 2016, the Secretary of State can issue Technical Capability Notices (TCNs) to “relevant operators” requiring them, on an ongoing basis, to maintain the capability to remove encryption applied by the operator. UK CSPs are required to maintain such capability; foreign companies are not formally required to remove encryption. Reports in February 2025 indicated that Apple Inc. had received a TCN ordering it to break the encryption on iCloud backups worldwide — a development that has triggered a transparency and proportionality controversy and a US Congressional response. The Investigatory Powers (Amendment) Act 2024 received Royal Assent on 25 April 2024 following Lord Anderson of Ipswich’s review; it makes targeted reforms but does not amend s.49 itself.
Hansard records that “up to the end of 2007 there have been no persons reported to the Ministry of Justice as being cautioned, prosecuted or convicted under section 53”; an April 2008 Hansard answer recorded eight section 49 notices served and two persons charged with non-compliance. There are no comprehensive published statistics on the contemporary use of s.49, although the Investigatory Powers Commissioner’s Annual Reports (2022, 2023 and 2024) provide aggregate oversight figures.
The widely cited Trinity College Law Review article (“The Right to Encryption?”) and Open Rights Group’s analysis frame s.49 as a substantial intrusion on cryptographic self-determination, particularly in light of forgotten-password risks and the privilege against self-incrimination (note Article 8 ECHR proportionality requirements and the European Court of Human Rights’ jurisprudence in John Murray v United Kingdom (1996)).
3.4 GOV.UK Wallet’s cryptographic architecture
The GOV.UK Wallet, being built by the Government Digital Service (GDS), uses a deliberately simple and standards-based cryptographic stack:
- The wallet generates a key pair on the user’s device (with the private key bound to the device’s secure element where available).
- Identification of the wallet’s public key uses the
did:keymethod, conveyed in the JWT headerkidparameter. - Proofs of possession at the credential endpoint follow OpenID for Verifiable Credential Issuance (OID4VCI), with the JWS algorithm fixed as ES256 (ECDSA over P-256 with SHA-256).
- Issued credentials use the W3C Verifiable Credentials Data Model v2.0, signed by the issuer’s private key in JWT form (
typ: vc+jwt), with the wallet’sdid:keyas the subject identifier. - Authentication and account state come from GOV.UK One Login, with credential issuers verifying access tokens (
typ: at+jwt) against One Login’s published JWKS and theissvaluehttps://token.account.gov.uk. - The programme adheres to NCSC advice and operates a “three lines of defence” assurance model.
Government policy commits to require services to “issue a digital verified credential alongside any paper or card-based credential or proof of entitlement eligibility by the end of 2027.” There will be no central record of where the documents in the GOV.UK Wallet have been used (per the GOV.UK guidance on the digital identity sector, last updated 17 October 2025). On 1 January 2026 the government confirmed that the new digital ID for Right-to-Work checks (announced September 2025) will be optional, not mandatory.
Crucially for the policy question, current GOV.UK Wallet documentation indicates that the wallet’s cryptographic capabilities are oriented to proof of possession and credential signing on behalf of the user rather than to general-purpose user-controlled encryption (e.g., the wallet does not, today, give a citizen a personal encryption key with which to seal arbitrary correspondence to themselves). This is a substantive gap relative to the Estonian model.
3.5 Policy proposals and the “right to seal a letter”
The “right to seal a letter” analogy — that a citizen should be entitled, by virtue of citizenship, to a state-recognised cryptographic identity that lets them digitally seal and sign communications — is most fully realised in the Estonian eID and emerging EUDI Wallet models, where citizen-controlled QES keys and authentication/decryption keys are part of the core entitlement. The European Digital Rights (EDRi) network and the Open Rights Group have argued that any UK National Digital Service must, at minimum, give citizens the ability to digitally sign with QES-equivalent assurance and to encrypt documents to themselves, mirroring the postal-letter-sealing analogy.
Specific policy proposals that surface across the literature surveyed (Privacy International on e-Estonia; the Trinity College Law Review article on cryptography law; e-Governance Academy podcast with the Estonian DPI; Ascertia’s UK digital ID briefing) cluster around four ideas:
- Constitutional or statutory recognition of a citizen’s right to use strong cryptography, with the s.49 power preserved only for narrowly drawn, judicially supervised circumstances and statutory time limits on tipping-off prohibitions.
- An automatic audit trail (Estonia-style) in which every government query against a citizen-record is logged into a citizen-visible feed inside the wallet, with non-repudiable hashes and a residual delayed-notification regime modelled on US §3103a but with statutory caps on extension.
- A right to sponsor natural persons, building Companies House personal codes and ACSP verification together with vLEI OOR/ECR credentials, so that each organisational presentation cryptographically names the human acting on behalf of the entity — preserving accountability even as institutions act digitally.
- Citizen-controlled keys for encryption, not only signing, so that the GOV.UK Wallet provides at least the encryption/decryption pair that the Estonian ID-card has provided since 2002.
Synthesis for the Policy Document
For a UK National Digital Service issuing identities to both citizens and organisations, the evidence base supports a design grounded in three commitments:
- Visibility-by-default for state access, modelled on Estonia’s Data Tracker — a single citizen-facing audit feed of every query against citizen records, with statutorily defined and judicially supervised delayed-notification windows (drawing on US §3103a guideline of 30 days extendable to 90 days for good cause) rather than indefinite secrecy, and with criminal sanctions for unauthorised access, as Estonia has demonstrated to operate in practice.
- A two-layer organisational identity stack, combining (a) the Companies House personal code regime under ECCTA (mandatory from 18 November 2025, ~7 million people in scope) and ROE-style independently verified registration for foreign entities, with (b) LEI/vLEI plus EUDI-compatible organisational wallets, so that any UK organisation can present itself in tap-to-ID contexts with cryptographic, role-bound credentials traceable to a registry source of truth and a sponsoring natural person.
- Citizen cryptographic rights as a foundational entitlement, including state-recognised QES, encryption to self, key generation inside a secure element on the user’s device (avoiding the architectural concerns that plagued the early Estonian ID), and a statutory rebalancing of RIPA Part III §49 to ensure judicial supervision, proportionality, time-limited tipping-off prohibitions, and clear protection for keys used solely for authentication or signing.
Key Quantitative Reference Points
- Estonia X-Road monthly Health Insurance Fund queries: 7,182,244.
- Estonia X-Road cumulative queries: >5 billion; 2018 annual queries: ~986 million (i.e., about 0.99 billion).
- IPCO oversight scope: >600 UK public authorities; ~360,000 investigatory-power authorisations in 2023; 386 inspections in 2023.
- US §213 PATRIOT Act delayed-notice warrants in FY2020: ~20,000 (30-day) plus >10,000 extensions; >70% drug cases; <250 terrorism cases.
- GLEIF active LEIs at end-2025: ~2.93 million, with ~355,000 new LEIs in 2025 (annual growth 13.5%); Q4 2025 issuance ~89,000; 23 Validation Agents globally; >6,600 government entities and 81 international organisations identified.
- UK Companies House mandatory IDV from 18 November 2025, individuals in scope: ~7 million; voluntary verifiers by 18 November 2025: >300,000; ID Check app average completion time: 2.4 minutes; ECCTA support among UK senior decision-makers (n=1,007): 81%.
- EUDI Wallet availability deadline: late December 2026; mandatory acceptance by relying parties: late December 2027; EU “Digital Decade” target: 80% of citizens to use a digital ID by 2030.
- RIPA §49 penalties: up to 2 years’ imprisonment for non-compliance, up to 5 years for national-security or child-indecency cases.
- Estonian ID-card cryptography: 384-bit ECC (post-2018 cards), with two key pairs per card (authentication/decryption + signing).
These figures, and the architectural choices behind them, provide a defensible evidence base for proposing that a UK National Digital Service deliver, by design, citizen-visible audit trails, verified organisational identities tied to sponsoring natural persons, and a citizen-cryptographic entitlement at parity with leading European peers.