Digital Infrastructure Fragility Indices
Digital Immunity Passports and Access Control Systems
Introduction
Digital immunity passports are digital systems that record, verify, and communicate information about a person's health or immunity status for the purpose of determining access to places, services, employment, travel, education, public events, or other activities. They may use QR codes, digital identity credentials, vaccination records, testing certificates, biometric identifiers, or interoperable health databases.
The legal significance of these systems is broader than public-health regulation. When possession of a particular digital credential becomes a condition for participating in ordinary economic or social life, the system can function as an access-control infrastructure. This creates questions concerning privacy, data protection, equality, discrimination, freedom of movement, employment, proportionality, administrative law, competition, consumer protection, and due process.
A useful distinction is:
- Health-record system – stores medical information.
- Digital certificate – confirms a specified vaccination/test/immunity status.
- Verification system – allows a third party to check the certificate.
- Access-control system – makes possession of the certificate a condition of entry.
- Universal digital identity infrastructure – links health status to a broader identity credential.
The fifth model presents the greatest structural risks because health information can become incorporated into a general-purpose system of social and economic access.
1. Nature of Digital Immunity Passports
A digital immunity passport generally performs three functions:
A. Identification
The system associates an individual with a digital credential, identity number, QR code, mobile application, biometric identifier, or other authentication mechanism.
B. Health-status assertion
The credential may state or cryptographically establish that the person:
- has received a particular vaccination;
- has tested negative;
- has recovered from a disease;
- satisfies specified health requirements; or
- possesses some other officially recognised status.
C. Access determination
A separate organisation can use the credential to decide whether the individual may:
- enter a workplace;
- board transportation;
- attend an event;
- enter a school or university;
- cross a border;
- access public premises;
- use particular services; or
- perform particular employment.
This last stage transforms a medical credential into an access-control mechanism.
2. From Health Certificate to Digital Gatekeeper
The principal legal concern arises when the credential becomes practically indispensable.
Suppose a government creates a digital immunity credential for international travel. That may be relatively narrow.
But imagine the credential subsequently becomes necessary for:
transportation → employment → banking → education → retail → government services.
At that point, the system is no longer merely a health certificate. It becomes a digital gatekeeping infrastructure.
The legal analysis therefore has to examine not only the original health objective but also the secondary uses and cumulative effects of the infrastructure.
3. Privacy and Data-Protection Issues
Health information is generally treated as particularly sensitive personal information.
A digital immunity passport may reveal:
- vaccination status;
- testing history;
- medical history;
- recovery status;
- dates of medical procedures;
- identity information;
- travel history;
- location;
- access history; and
- potentially employment or behavioural information.
The danger increases when multiple datasets are connected.
Example
A QR verification system may initially reveal only:
“Valid”
But if verification events are logged, the operator might construct a database showing:
Person A → airport → restaurant → workplace → stadium → hotel.
Thus a system ostensibly designed for health verification can become a population-movement and behavioural-monitoring infrastructure.
4. Data Minimisation
A central principle is that the verifier should obtain only the information necessary for the particular access decision.
For example, if the only relevant question is:
“Does this person satisfy the applicable entry requirement?”
the verifier may not need to receive:
- the person's complete medical history;
- vaccine manufacturer;
- date of every vaccination;
- previous medical conditions; or
- unrelated test results.
A privacy-preserving architecture would ideally provide a binary or narrowly scoped answer:
Eligible / Not eligible
rather than exposing the underlying health record.
5. Function Creep
One of the greatest risks is function creep.
A credential introduced for:
disease-control purposes
may later be used for:
employment verification,
then:
insurance risk assessment,
then:
financial services,
and eventually:
general identity and social-access management.
The legal problem is that the original justification for processing the information may not automatically justify these later uses.
Function creep is particularly problematic when the individual has no realistic ability to refuse the additional uses.
6. Access Control and Fundamental Rights
An immunity passport can affect several rights simultaneously.
Freedom of movement
Travel restrictions based on health credentials may interfere with domestic or international movement.
Privacy
Mandatory disclosure of health status can interfere with informational privacy.
Equality
People unable to obtain a particular credential may experience indirect exclusion.
Employment
Mandatory workplace certification can affect the right to work and economic participation.
Education
Credential requirements may affect access to schools and universities.
Association and assembly
Requirements for public-event access may affect participation in collective activities.
The relevant legal question is therefore generally one of proportionality:
- Is the measure pursuing a legitimate objective?
- Is it rationally connected to that objective?
- Is it necessary?
- Is there a less restrictive alternative?
- Is the overall burden proportionate to the benefit?
7. Discrimination and Equality
Digital immunity systems can create both direct and indirect discrimination.
For example, a formally neutral requirement may disproportionately affect people who:
- cannot medically receive a vaccine;
- have limited access to testing;
- lack smartphones;
- lack internet connectivity;
- have disabilities;
- possess foreign vaccination records that cannot be recognised;
- cannot afford repeated testing; or
- have documentation from jurisdictions lacking interoperability.
Consequently, a system should generally provide reasonable alternative means of proving eligibility.
A paper certificate, offline credential, assisted verification mechanism, or manual administrative process may be necessary to avoid digital exclusion.
8. Digital Divide
A passport that exists exclusively through a smartphone application can create a distinction between:
digitally enabled persons
and
digitally excluded persons.
This is particularly significant where the credential becomes necessary for essential activities.
The legal issue changes dramatically depending upon the service.
A digital certificate required to enter a voluntary entertainment venue raises fewer concerns than one required to:
- obtain emergency medical care;
- access public administration;
- maintain employment;
- receive education; or
- exercise fundamental rights.
9. Administrative-Law Concerns
Where a public authority determines access through an automated system, administrative-law principles become important.
An individual should ordinarily have some means of discovering:
- why access was refused;
- what information caused the refusal;
- whether the information is accurate;
- who made the decision;
- how the decision can be challenged; and
- how an incorrect status can be corrected.
A system that simply produces:
ACCESS DENIED
without meaningful explanation or appeal can create a serious due-process problem.
10. Automated Decision-Making
Digital immunity systems may automatically determine eligibility.
For example:
Digital identity ↓ Health database ↓ Vaccination/test status ↓ Automated verification ↓ Eligibility calculation ↓ Access permitted/denied
If the system makes errors, the consequences may be immediate.
Possible errors include:
- duplicate identity records;
- expired certificates;
- incorrect vaccination entries;
- database synchronization failures;
- identity mismatches;
- foreign-record recognition failures; and
- algorithmic classification errors.
Accordingly, robust human review and correction mechanisms are important where automated decisions materially affect individuals.
11. Competition-Law Dimension
Digital immunity passports can also raise competition concerns.
Suppose one company controls:
- the identity infrastructure;
- the health credential;
- the verification API;
- the access-control terminals; and
- the authentication network.
That company may become an essential intermediary between individuals and service providers.
Potential exclusionary conduct could include:
- discriminatory API access;
- excessive verification fees;
- refusal to interoperate;
- tying health credentials to unrelated services;
- preferential treatment for affiliated businesses;
- technical restrictions on competing wallets;
- exclusive verification arrangements; and
- leveraging health infrastructure into adjacent digital markets.
Thus a public-health credential can potentially become a digital bottleneck.
12. Interoperability
Interoperability is particularly important.
An immunity passport issued in one jurisdiction should ideally be capable of being verified elsewhere without forcing the individual to adopt a proprietary identity system.
Otherwise, the system may produce:
credential monopoly → verification monopoly → access monopoly.
Open technical standards can reduce this risk.
13. State-Backed Monopoly Risk
A particularly important scenario arises where the state designates one system as the mandatory verification infrastructure.
Even if the infrastructure operator is technically private, government designation can create substantial market power.
The relevant competition questions include:
- Who controls the standard?
- Can competing credentials be recognised?
- Can competing verification providers operate?
- Are APIs available on fair terms?
- Can users export their credentials?
- Can service providers choose alternative verification mechanisms?
- Is the infrastructure governed transparently?
The more indispensable the credential becomes, the stronger the argument that the infrastructure should be subject to neutrality, interoperability, and non-discrimination requirements.
14. Case Laws
The following cases are particularly useful for analysing the legal principles surrounding digital immunity passports and access-control systems.
1. Solvay Pharmaceuticals GmbH v. Council of the European Union — EU
This line of EU jurisprudence illustrates the importance of proportionality and judicial review where regulatory measures affect economic and individual interests.
Relevance
An immunity-passport regime cannot simply rely on the existence of a public-health objective. The particular mechanism used to achieve that objective must be rational and proportionate.
The case is useful when discussing the distinction between:
legitimate public-health objective
and
excessive regulatory burden.
2. S. and Marper v. United Kingdom — European Court of Human Rights
The European Court of Human Rights examined the retention of biometric information and emphasised the importance of privacy safeguards surrounding personal data.
Principle
The mere fact that information is useful to authorities does not mean that unlimited retention is justified.
Relevance
This principle is highly applicable to immunity-passport databases.
If vaccination or health credentials are retained indefinitely, linked to identity databases, or used for unrelated purposes, the system may become disproportionate.
The case supports arguments concerning:
- data retention;
- purpose limitation;
- privacy;
- state databases; and
- safeguards against misuse.
3. Big Brother Watch and Others v. United Kingdom — European Court of Human Rights
This case concerned state surveillance and the safeguards required for large-scale collection and use of information.
Principle
Large-scale information systems require effective safeguards against arbitrary or disproportionate interference with privacy.
Relevance
A digital immunity system capable of recording every verification transaction could potentially generate extensive movement and behavioural information.
The case therefore provides an important framework for analysing:
health credential + identity + access logs + surveillance capability.
4. Digital Rights Ireland Ltd v. Minister for Communications — Court of Justice of the European Union
The CJEU examined the compatibility of large-scale retention of communications data with fundamental rights.
Principle
Large-scale data retention can constitute a serious interference with privacy and data protection and must satisfy strict proportionality requirements.
Relevance
The case is useful by analogy where an immunity-passport architecture creates a comprehensive database of health-related or access-related information.
The greater the scope of data collection and retention, the stronger the justification and safeguards required.
5. Tele2 Sverige AB v. Post- och telestyrelsen; Secretary of State for the Home Department v. Watson — CJEU
The Court examined general and indiscriminate retention of electronic communications data.
Principle
Government information systems cannot automatically escape fundamental-rights scrutiny merely because the information may assist legitimate governmental objectives.
Relevance
The case supports scrutiny of:
- indiscriminate health-data retention;
- universal identity linkage;
- access logs;
- location information;
- automated surveillance; and
- secondary uses of collected information.
It is particularly relevant to the distinction between verification and continuous monitoring.
6. R (Bridges) v. Chief Constable of South Wales Police — UK Court of Appeal
This is one of the most important UK authorities concerning automated biometric surveillance.
The case concerned the use of automated facial-recognition technology in public spaces.
Principle
The deployment of sophisticated technology by public authorities must comply with applicable legal frameworks governing privacy, data protection, and discretion.
Relevance
Digital immunity verification similarly involves technological identification and automated decision-making.
The case is useful for analysing:
- algorithmic access control;
- automated identity verification;
- public-authority discretion;
- privacy safeguards;
- proportionality; and
- technological surveillance.
It demonstrates that technological novelty does not remove ordinary legal constraints.
7. R (Lumsdon) v. Legal Services Board — UK Supreme Court
This case is significant for the proportionality analysis of regulatory restrictions.
Principle
A regulatory measure must be examined in light of whether less restrictive alternatives could achieve the legitimate objective.
Relevance
Applied to immunity passports, authorities should consider alternatives such as:
- testing;
- temporary certificates;
- medical exemptions;
- manual verification;
- proof of recovery;
- alternative identity credentials; or
- risk-based measures.
The availability of less restrictive alternatives can be critical to the proportionality analysis.
8. Carson v. United Kingdom — European Court of Human Rights
The case addresses discrimination and the application of Article 14 ECHR.
Principle
Differential treatment requires adequate justification where comparable individuals are treated differently on a protected or otherwise relevant basis.
Relevance
Immunity-passport systems can create differentiated access between:
- vaccinated and unvaccinated individuals;
- digitally connected and digitally excluded individuals;
- domestic and foreign certificate holders;
- medically exempt and non-exempt persons.
The case therefore assists in analysing whether differential treatment is objectively and reasonably justified.
15. Comparative Legal Principles From the Cases
| Legal issue | Relevant authority | Principle |
|---|---|---|
| Privacy and biometric information | S. and Marper | Strong safeguards for sensitive personal information |
| Large-scale surveillance | Big Brother Watch | Mass information systems require safeguards |
| Data retention | Digital Rights Ireland | Serious interference requires strict justification |
| Communications/data monitoring | Tele2 Sverige/Watson | Indiscriminate retention is subject to fundamental-rights limits |
| Automated identification | R (Bridges) | Technological surveillance requires lawful and proportionate controls |
| Regulatory proportionality | Lumsdon | Less restrictive alternatives matter |
| Differential treatment | Carson | Discrimination requires objective justification |
16. Architectural Safeguards
A legally robust immunity-passport system should preferably incorporate privacy by design.
Decentralised credentials
Rather than maintaining a permanent central database of every verification event, credentials can be stored with the individual and cryptographically verified.
Selective disclosure
The system should disclose only what is necessary.
For example:
“Meets current entry requirement”
rather than:
“Received vaccine X on date Y at hospital Z.”
Expiry
Credentials should automatically expire where the underlying public-health justification is temporary.
Purpose limitation
Data collected for public-health verification should not automatically become available for:
- advertising;
- insurance profiling;
- employment screening;
- credit scoring;
- unrelated law enforcement; or
- commercial behavioural analysis.
Auditability
Authorities should maintain transparent records concerning:
- who operates the system;
- what data is collected;
- how long it is retained;
- who can access it;
- how automated decisions are made; and
- how errors are corrected.
17. Emergency Powers and Sunset Clauses
Emergency health measures create a special danger of permanence through institutionalisation.
A credential introduced during a pandemic may continue after the original emergency has ended.
Therefore, legislation should ideally include:
- a defined duration;
- periodic review;
- statutory renewal requirements;
- independent oversight;
- sunset provisions; and
- termination procedures.
The government should have to justify continued operation, rather than allowing an emergency infrastructure to become permanent by default.
18. Public-Private Partnerships
Many digital identity and health systems involve private technology providers.
This creates an important governance question:
Can the state outsource the operation of a fundamental access-control function without outsourcing constitutional responsibility?
Private operators may control:
- cloud infrastructure;
- authentication;
- identity matching;
- software;
- verification APIs;
- analytics; and
- cybersecurity.
But public authorities may remain responsible for ensuring that the system complies with fundamental rights and administrative-law requirements.
19. Essential-Facility Analogy
From a competition perspective, a universally required digital immunity verification system can resemble an essential digital infrastructure.
If access to important markets requires use of a particular verification network, exclusion from that network can effectively exclude:
- individuals;
- businesses;
- competing credential providers;
- competing technology providers.
This raises potential issues concerning:
- refusal to deal;
- discriminatory access;
- interoperability;
- tying;
- leveraging;
- excessive pricing;
- exclusive dealing; and
- self-preferencing.
The competition analysis becomes particularly strong when the system is both state-supported and unavoidable.
20. Cybersecurity and Identity Theft
A centralised immunity database creates significant security risks.
Compromise could expose:
- identity information;
- health information;
- vaccination history;
- travel records;
- access records.
A stolen credential could also be used to impersonate another person.
Therefore, systems require:
- cryptographic authentication;
- revocation mechanisms;
- secure key management;
- breach notification;
- identity recovery;
- fraud detection;
- independent security testing; and
- strict access controls.
Cybersecurity is not merely a technical issue. Where the credential determines access to essential services, cybersecurity becomes a rule-of-law and rights-protection issue.
21. The Risk of Universal Access Control
The most serious long-term concern is the transformation of a health credential into a universal access token.
The progression could look like:
Health verification
↓
Digital identity
↓
Access credential
↓
Economic participation
↓
Behavioural monitoring
↓
Universal gatekeeping
At the final stage, the institution controlling the credential could potentially determine who can participate in significant areas of social and economic life.
That creates a structural constitutional and competition concern even if the system began with a legitimate public-health objective.
22. Legal Test for an Immunity-Passport System
A useful analytical framework is:
Step 1 — Legitimate objective
Is there a genuine and sufficiently important public-health objective?
Step 2 — Legal authority
Does legislation or another valid legal instrument authorise the system?
Step 3 — Necessity
Is digital certification actually necessary?
Step 4 — Proportionality
Are the restrictions proportionate to the objective?
Step 5 — Data minimisation
Is only necessary information processed?
Step 6 — Alternative access
Can people use non-digital or alternative forms of verification?
Step 7 — Equality
Does the system disproportionately disadvantage particular groups?
Step 8 — Due process
Can an incorrect denial be challenged rapidly?
Step 9 — Interoperability
Can competing credential and verification systems function?
Step 10 — Sunset
Does the system automatically terminate or undergo mandatory review when the emergency ends?
23. Competition-Law Test
Where a digital immunity passport becomes infrastructure for economic participation, competition authorities should additionally ask:
Market definition
What market exists for:
- digital health credentials;
- identity verification;
- verification APIs;
- access-control services?
Market power
Does one provider control an indispensable identity or verification infrastructure?
Exclusion
Can competitors connect to the system?
Interoperability
Are technical standards open and non-discriminatory?
Tying
Is the health credential being tied to unrelated digital services?
Leveraging
Is market power in identity infrastructure being used to dominate adjacent markets?
Self-preferencing
Does the infrastructure operator favour its own downstream services?
24. Best-Practice Governance Model
A rights-compatible model would ideally have the following characteristics:
PUBLIC HEALTH OBJECTIVE │ ↓ Limited Health Data │ ↓ Privacy-Preserving Digital Credential │ ┌─────────┴─────────┐ ↓ ↓ Digital Verification Offline Alternative │ │ └─────────┬─────────┘ ↓ Access Decision │ ┌────────┴────────┐ ↓ ↓ Granted Refused │ ↓ Human Review / Appeal Process
The critical feature is that access control should not become a permanent identity-surveillance system.
Conclusion
Digital immunity passports occupy a difficult legal space because they combine health information, digital identity, authentication, automated decision-making, and access control.
The core legal principle is that a legitimate public-health objective does not automatically legitimise every technological mechanism used to pursue it.
The strongest safeguards are:
- purpose limitation;
- data minimisation;
- privacy-preserving verification;
- non-discrimination;
- offline alternatives;
- human review and appeal;
- interoperability;
- independent oversight;
- strict cybersecurity; and
- sunset clauses.
From a competition perspective, the greatest danger arises when a digital immunity passport becomes a state-backed universal gatekeeper. Once one infrastructure controls identity, verification and access, exclusion from that infrastructure can effectively mean exclusion from markets and essential social functions.

comments