Digital Identity Systems In Public Administration Control .
Digital Identity Systems in Public Administration Control
1. Introduction
Digital identity systems are technological infrastructures through which governments identify, authenticate, verify, and classify individuals when providing public services or exercising administrative powers. They may include national identity databases, biometric identification, digital authentication credentials, population registers, digital signatures, facial recognition, e-KYC systems, interoperable government databases, and digital public-service portals.
From a public-administration and competition-law perspective, digital identity creates a distinctive form of institutional power. The State may become the unavoidable provider of an identity credential that citizens, businesses, banks, healthcare providers, employers, and digital platforms must use. Consequently, control over the identity layer can affect market access, interoperability, data access, privacy, administrative discretion, and competitive neutrality.
The central legal question is therefore not simply whether a government may establish digital identity. It is:
How far may public authorities control access to economic and social activity through a digital identity infrastructure without creating disproportionate exclusion, discriminatory access, surveillance, or competition distortions?
2. Meaning of Digital Identity in Public Administration
A digital identity system generally performs five functions:
- Identification – establishing who a person is.
- Authentication – confirming that a person claiming an identity is actually that person.
- Authorisation – determining what services or activities the authenticated person may access.
- Attribution – connecting transactions or actions to a particular individual.
- Data linkage – connecting information held across different governmental databases.
Examples include:
- national digital identity numbers;
- biometric authentication;
- electronic identity cards;
- digital passports;
- government authentication apps;
- tax-identification systems;
- digital health identifiers;
- social-security authentication;
- digital signatures;
- public-sector single sign-on systems.
The legal significance increases when one identity infrastructure becomes mandatory or practically indispensable.
3. Digital Identity as an Instrument of Administrative Control
Digital identity can transform traditional administrative control.
Traditional model
Government → citizen → individual administrative decision.
Digital identity model
Government identity infrastructure → authentication → database matching → automated eligibility determination → service access.
The identity layer therefore becomes a gateway to administrative rights and economic participation.
For example, if access to a public subsidy requires digital authentication, inability to authenticate may effectively prevent access to the subsidy even though the individual legally qualifies.
This produces an important distinction:
Legal entitlement ≠ technological accessibility.
A person may possess a statutory right but be unable to exercise it because the digital identity infrastructure cannot authenticate them.
4. Major Forms of Public-Administration Control
A. Identity Registration Control
The State determines:
- who receives an identity;
- what information is recorded;
- how identity is verified;
- when identity can be suspended;
- when identity information can be corrected.
This creates substantial administrative power.
B. Authentication Control
Authentication can determine access to:
- welfare benefits;
- taxation;
- healthcare;
- education;
- voting-related services;
- licences;
- business registration;
- banking;
- government procurement.
If authentication becomes mandatory, the authentication provider becomes an important gatekeeper.
C. Database-Linkage Control
Digital identity allows public authorities to connect datasets concerning:
- taxation;
- social security;
- immigration;
- healthcare;
- education;
- criminal justice;
- employment;
- property;
- business activity.
Such interoperability can greatly improve administrative efficiency but simultaneously increases the risk of function creep.
D. Eligibility Control
Identity infrastructure may become the technical basis for determining whether an individual qualifies for a particular benefit.
Automated eligibility systems may therefore transform identity data into administrative decision-making power.
5. Digital Identity and the Rule of Law
A fundamental constitutional concern is that administrative power must remain subject to:
- legality;
- proportionality;
- procedural fairness;
- non-discrimination;
- transparency;
- judicial review;
- accountability.
Digital identity systems can challenge these principles because decisions may be generated through technical systems that are difficult for individuals to understand.
For example:
Identity mismatch → automated rejection → no benefit → no effective explanation.
This creates a potential automation-based administrative barrier.
6. Digital Identity and Fundamental Rights
Digital identity systems implicate several rights.
Privacy
Centralised identity databases may permit extensive profiling.
Informational self-determination
Individuals may lose meaningful control over how personal information is collected and linked.
Equality
Biometric systems may produce unequal authentication outcomes for particular groups.
Due process
Automated identity failures may deny access without adequate human review.
Freedom of movement
Identity verification can become particularly significant where physical or digital movement depends on authentication.
Human dignity
A system that treats an individual as merely a data profile can create constitutional concerns when technological classification determines access to essential services.
7. Digital Identity as a Public-Utility-Like Infrastructure
When a government identity system becomes indispensable to participation in public and private life, it begins to resemble essential infrastructure.
The concern is especially strong where:
identity → authentication → public services → private-sector transactions.
A single identity layer can therefore affect:
- banks;
- telecommunications;
- insurance;
- healthcare;
- e-commerce;
- employment;
- government contractors.
This creates a vertical dependency structure.
The State controls the identity layer while downstream providers depend upon it.
8. Competition-Law Dimension
Digital identity is not traditionally an antitrust market. Nevertheless, competition concerns may arise when a State-controlled identity infrastructure interacts with commercial markets.
Potential problems include:
1. Exclusive access
Only selected private entities may receive access to identity verification services.
2. Discriminatory authentication
Some providers may receive superior technical access or lower authentication costs.
3. Self-preferencing
A government-controlled infrastructure could theoretically favour government-owned or preferred downstream services.
4. Interoperability restrictions
Competing identity providers may be denied interoperability.
5. Data advantages
The identity operator may possess uniquely valuable datasets unavailable to competitors.
6. Bundling
Identity authentication may be tied to unrelated governmental or commercial services.
9. Six Important Case Laws
The following cases provide important principles for analysing governmental digital identity systems, even where the underlying disputes involved privacy, biometric identification, databases, surveillance, or administrative technology rather than a modern digital-ID platform itself.
Case 1: Justice K.S. Puttaswamy (Retd.) v. Union of India (2017)
Court: Supreme Court of India
This is the foundational Indian privacy judgment.
The Supreme Court recognised privacy as a fundamental right under Article 21 and other constitutional guarantees.
The judgment is particularly important for digital identity because large-scale identity systems involve:
- collection of personal information;
- biometric information;
- profiling;
- data aggregation;
- informational autonomy.
The Court emphasised that State interference with privacy must satisfy constitutional requirements including legality, legitimate purpose, and proportionality.
Relevance
Digital identity cannot be treated merely as an administrative database.
It implicates constitutional privacy and individual autonomy.
Principle: Digital identity infrastructure must operate within constitutional limitations on State power.
10. Case 2: K.S. Puttaswamy (Aadhaar) v. Union of India (2018)
Court: Supreme Court of India
This case directly concerned India's Aadhaar system.
The Supreme Court upheld the Aadhaar framework in substantial part but imposed important constitutional limitations.
The judgment examined:
- biometric authentication;
- identity databases;
- government welfare;
- proportionality;
- privacy;
- data protection;
- mandatory authentication;
- private-sector use.
The Court invalidated or restricted several aspects of the statutory framework, including the use of Aadhaar authentication for certain private purposes.
Importance for public administration
The judgment illustrates that:
Administrative convenience does not automatically justify universal identity authentication.
Where identity becomes the gateway to services, constitutional proportionality becomes critical.
Competition relevance
The restriction on private-sector use also demonstrates how control over identity infrastructure can determine the boundaries of downstream commercial dependence.
11. Case 3: Schrems v. Data Protection Commissioner (Schrems I) (2015)
Court: Court of Justice of the European Union
The CJEU examined international transfer of personal data and the adequacy of data protection safeguards.
Although the case did not concern a national digital identity system specifically, it established an important principle:
Personal-data infrastructures are subject to fundamental-rights constraints.
Relevance to digital identity
A public identity system may generate enormous quantities of personal information. If identity data are transferred or interoperated across jurisdictions, adequate safeguards become essential.
The case therefore supports scrutiny of:
- cross-border identity verification;
- government-cloud infrastructure;
- international data transfers;
- third-party authentication providers.
12. Case 4: Schrems II (Data Protection Commissioner v. Facebook Ireland and Schrems) (2020)
Court: Court of Justice of the European Union
The CJEU invalidated the EU-US Privacy Shield and scrutinised governmental access to personal data.
The decision is significant because it recognised that data-processing systems cannot be assessed purely by contractual or administrative convenience.
Digital identity implication
A digital identity infrastructure must consider:
- government access;
- surveillance risks;
- security safeguards;
- effective legal remedies;
- proportionality.
Where identity information is stored by private cloud or technology providers, public authorities cannot simply transfer responsibility to those providers.
13. Case 5: S. and Marper v. United Kingdom (2008)
Court: European Court of Human Rights
The case concerned retention of fingerprints and DNA profiles by public authorities.
The European Court of Human Rights found that indiscriminate retention of biometric information could violate Article 8 of the European Convention on Human Rights.
Relevance
Digital identity systems increasingly rely on:
- fingerprints;
- facial recognition;
- iris scans;
- voice recognition;
- other biometric identifiers.
The case establishes an important principle:
Biometric information is not simply ordinary administrative information.
Its retention, use, and linkage require strong justification.
14. Case 6: Big Brother Watch and Others v. United Kingdom (2021)
Court: European Court of Human Rights
The Grand Chamber considered the compatibility of large-scale surveillance regimes with Article 8 and Article 10 ECHR.
The Court emphasised the need for adequate safeguards against abuse in systems involving large-scale acquisition and processing of information.
Digital identity relevance
A digital identity infrastructure can potentially become a surveillance architecture when identity information is combined with:
- location information;
- transaction histories;
- communications;
- government records;
- biometric information.
Therefore:
Identification infrastructure should not automatically become behavioural-surveillance infrastructure.
15. Case 7: Digital Rights Ireland Ltd v. Ireland (2014)
Court: Court of Justice of the European Union
The CJEU invalidated the EU Data Retention Directive because indiscriminate retention of communications data interfered disproportionately with fundamental rights.
Digital identity significance
The case demonstrates that even where data processing serves legitimate public objectives, generalised and indiscriminate data collection may be disproportionate.
This principle is relevant to identity systems that seek to retain extensive transactional or behavioural information merely because it may become administratively useful.
16. Case 8: Bridges v. Chief Constable of South Wales Police (2020)
Court: Court of Appeal of England and Wales
The case concerned the use of automated facial recognition technology by police.
The Court examined:
- Article 8 ECHR;
- data protection;
- equality considerations;
- legal framework;
- discretion surrounding deployment.
Relevance
Facial recognition can function as a form of digital identity authentication.
The case therefore illustrates the importance of:
- clear legal authority;
- safeguards;
- proportionality;
- equality;
- operational controls.
It is particularly significant for public authorities using AI-enabled identity verification.
17. Comparative Case-Law Principles
| Case | Core principle | Digital identity relevance |
|---|---|---|
| Puttaswamy I | Privacy is fundamental | Constitutional limits on identity databases |
| Puttaswamy II / Aadhaar | Identity systems subject to proportionality | Limits on mandatory authentication and private use |
| Schrems I | Personal data require adequate protection | Cross-border identity infrastructure |
| Schrems II | Government access must respect fundamental rights | Cloud-hosted identity systems |
| S. and Marper | Biometric retention requires safeguards | Biometric identity databases |
| Big Brother Watch | Surveillance requires safeguards | Identity-to-surveillance risks |
| Digital Rights Ireland | Indiscriminate data retention can be disproportionate | Data-minimisation principle |
| Bridges | Automated biometric identification requires legal safeguards | Facial-recognition identity systems |
18. Digital Identity and Administrative Discretion
Digital identity can either reduce or increase administrative discretion.
Reduction
Automated verification can reduce:
- arbitrary decision-making;
- corruption;
- duplicate beneficiaries;
- fraudulent registrations;
- inconsistent administrative treatment.
Increase
At the same time, administrators and system operators may gain unprecedented power to:
- suspend identity;
- correct records;
- deny authentication;
- link databases;
- classify individuals;
- monitor transactions.
Thus digitalisation does not eliminate administrative discretion.
It may merely move discretion from individual officials to system designers, database administrators and algorithmic rules.
19. The Problem of Identity Failure
One of the most important issues is authentication failure.
A system may reject a legitimate person because of:
- biometric mismatch;
- outdated information;
- database errors;
- connectivity problems;
- technical malfunction;
- duplicate records;
- incorrect demographic information.
The legal problem becomes acute where authentication is a prerequisite for essential services.
Proper safeguard
A constitutionally robust system should provide:
- alternative authentication;
- offline procedures where appropriate;
- human review;
- correction mechanisms;
- emergency access;
- written reasons;
- appeal rights;
- compensation where serious administrative error causes loss.
20. Digital Identity and Exclusion
Digital identity may create digital exclusion.
Vulnerable individuals may face difficulties because of:
- lack of digital literacy;
- disability;
- lack of devices;
- poor connectivity;
- biometric difficulties;
- age;
- migration status;
- documentation problems.
A system designed for administrative efficiency may therefore produce unequal practical access.
This is particularly problematic where identity authentication is compulsory.
21. Centralisation vs Federated Identity
Two broad architectural models exist.
Centralised identity
One authority controls the primary identity database.
Advantages:
- uniformity;
- administrative efficiency;
- easier verification.
Risks:
- single point of failure;
- surveillance;
- concentration of power;
- large-scale data breach;
- exclusion if the central system fails.
Federated identity
Multiple identity providers interact through interoperable standards.
Advantages:
- competition;
- redundancy;
- innovation;
- reduced centralisation.
Risks:
- interoperability failures;
- inconsistent standards;
- multiple privacy risks;
- complex governance.
From a competition perspective, interoperability and non-discriminatory access become particularly important in federated systems.
22. Digital Identity as a Gatekeeper
A particularly important concept is identity gatekeeping.
Consider:
Citizen → Digital ID → Authentication → Government service → Economic opportunity.
If the digital identity system is unavailable, every downstream activity can be blocked.
This makes identity infrastructure comparable to a bottleneck facility.
The stronger the dependency, the greater the need for:
- interoperability;
- non-discrimination;
- transparency;
- technical neutrality;
- accessible dispute resolution.
23. State Monopoly and Digital Identity
A State monopoly over identity is not automatically unlawful.
Indeed, there can be legitimate reasons for government control of foundational identity:
- national security;
- prevention of identity fraud;
- reliable public records;
- universal service delivery;
- legal certainty.
The competition-law question is different:
Does the State's control of foundational identity unnecessarily extend into competitive downstream markets?
A government should therefore distinguish between:
identity authority and commercial service provision.
If the identity authority also operates commercial services using privileged identity data, concerns about competitive neutrality become stronger.
24. Data Advantage and Competitive Neutrality
The operator of a public identity system may have access to information unavailable to private competitors.
Suppose a government identity infrastructure knows:
- verified age;
- address;
- citizenship;
- business ownership;
- tax status;
- licensing status.
If a government-affiliated commercial entity receives preferential access to this information, competitors could face a structural disadvantage.
This creates a potential data-access asymmetry.
25. Remedies and Safeguards
A comprehensive legal framework should include:
A. Purpose limitation
Identity data should be collected for clearly defined purposes.
B. Data minimisation
Only necessary information should be processed.
C. Functional separation
Identity verification should be separated from unrelated commercial functions.
D. Non-discriminatory access
Eligible service providers should receive equivalent access conditions.
E. Interoperability
Competing identity systems should be capable of secure interaction where appropriate.
F. Human override
Essential public services should not depend exclusively on automated authentication.
G. Auditability
Identity decisions should generate auditable records.
H. Judicial review
Citizens should have effective remedies against erroneous identity decisions.
I. Security
Centralised identity infrastructure requires exceptional cybersecurity protection.
26. Administrative Law Test
A court reviewing a digital identity measure could ask:
1. Legal authority:
Does legislation authorise the system?
2. Legitimate objective:
What public interest does it serve?
3. Necessity:
Is digital identity genuinely necessary?
4. Proportionality:
Is the interference with rights proportionate?
5. Equality:
Does the system disadvantage particular groups?
6. Procedural fairness:
Can individuals challenge adverse identity decisions?
7. Data protection:
Is collection and retention appropriately limited?
8. Accountability:
Who is responsible when the system fails?
27. Competition-Law Test
Where public identity infrastructure affects markets, an additional framework can be applied:
Relevant identity service → market power → dependency → discriminatory access → foreclosure → competitive harm → proportional remedy.
The most significant competition concerns arise where the identity infrastructure is:
- mandatory;
- technically indispensable;
- difficult to replicate;
- controlled by one entity;
- connected to multiple downstream markets.
28. Key Legal Risks
The principal risks can be summarised as follows:
- Identity exclusion
- Biometric discrimination
- Database centralisation
- Government surveillance
- Function creep
- Automated administrative error
- Lack of procedural remedies
- Cybersecurity concentration
- Data-access asymmetry
- Discriminatory commercial access
- State-platform dependency
- Interoperability restrictions
29. Overall Legal Position
Digital identity systems can substantially improve public administration by reducing fraud, simplifying service delivery, improving authentication, and enabling interoperable government services.
However, identity infrastructure is fundamentally different from an ordinary government IT system because it can become a foundational control layer through which individuals gain or lose access to public and economic activity.
The principles emerging from Puttaswamy, Aadhaar, S. and Marper, Schrems I, Schrems II, Digital Rights Ireland, Big Brother Watch, and Bridges collectively support a framework based on:
legality + necessity + proportionality + privacy + equality + transparency + interoperability + effective remedies.
The most important legal distinction is between legitimate identity administration and excessive identity-based control.
A government may legitimately establish a foundational identity system, but the system should not become an unchecked mechanism through which the State can automatically determine a person's access to essential services, nor should control over identity be unnecessarily leveraged to distort downstream competitive markets.
Conclusion
Digital identity systems in public administration represent a new form of infrastructural administrative power. Their importance extends beyond identification: they can determine authentication, eligibility, service access, data linkage and, indirectly, participation in markets.
The strongest legal model therefore treats digital identity as critical public infrastructure subject to constitutional, administrative, privacy and competition safeguards.

comments