Digital identity is, in itself, neither a global panopticon nor a mere convenience: it is an infrastructure whose use depends on its architecture and its legal framing. The same technology can include 850 million undocumented people or, poorly designed, become a single point of control. The honest question is therefore not "for or against," but "under what safeguards, and with what reversibility?"
Definition: a digital identity is a set of verifiable attributes (name, age, rights) allowing one to prove who one is online or offline. It can be centralised in a single database, or distributed and minimised, revealing only one attestation at a time. This architectural choice determines its potential for surveillance as much as for simplification.
Three distinct dynamics converge towards the same object: a unique, verifiable digital identifier. The European Union legislates with eIDAS 2; India has built the world's largest biometric database with Aadhaar; the World Bank promotes legal identity as a development goal. No single hand coordinates them: it is a structural demand that brings them together. As artificial intelligence makes the fake indistinguishable from the real, "proving you are a real and unique human" becomes a coveted resource.
This simultaneity is not proof of a conspiracy, but it deserves attention: money, identity, and the biometric gaze are all going digital at the same moment, each for its own stated good reasons. It is their eventual interoperability, more than each pillar in isolation, that raises questions.
The European Union adopted the eIDAS 2.0 regulation — Regulation (EU) 2024/1183, which entered into force on 20 May 2024. It establishes a European Digital Identity Wallet. Each member state will have to offer one to its citizens, intended to hold identity documents, attestations, and supporting credentials, and designed to be interoperable across the Union.
The text promises protective properties: the ability to disclose only a necessary attestation (proving one's adulthood without revealing one's date of birth), and optional use. The danger of such a wallet comes neither from its existence nor from its convenience, but from its capacity for aggregation: the more attestations it concentrates, the more its cut-off amounts to exclusion. Protection does not consist in refusing the tool — an illusory refusal — but in demanding three verifiable properties:
eIDAS 2 promises these properties. The whole citizen stake is that they be upheld, controllable, and sanctionable — engraved in law, not merely displayed in communications.
In India, the Aadhaar system, managed by the UIDAI, has recorded the biometric data — fingerprints, iris, photograph — of some 1.4 billion people. It is the largest biometric identification system ever built. It has enabled massive inclusion: opening accounts, direct disbursement of subsidies, access to services for populations previously invisible to the administration.
But this same system is a single point of control whose uses the courts had to bound. As early as 2017, the K. S. Puttaswamy judgment of the Indian Supreme Court enshrined privacy as a fundamental right. In 2018, the Court found Aadhaar constitutional while restricting its mandatory character for private actors (reading down section 57, ending the compulsory linking of Aadhaar to bank accounts and SIM cards). Aadhaar thus illustrates a central truth: inclusion and control are not two opposing systems, but two uses of the same infrastructure. If access to food, health, or money depends on a single identifier, any failure — technical or political — of that identifier becomes an exclusion.
The World project (formerly Worldcoin) offers a proof of "humanity" based on a biometric scan of the iris, via a device called the "Orb," delivering a World ID identifier. The argument: distinguishing real humans from bots and AIs in an internet saturated with fakes.
Several data protection authorities reacted. The Spanish agency AEPD ordered, on 6 March 2024, under the GDPR's emergency powers, the suspension of biometric data collection on its territory. The Hong Kong authority (PCPD) acted in May 2024. These decisions show that private biometric collection, even justified by a legitimate aim, does not escape the law: a global actor can be stopped by national regulators. The World case illustrates the boundary between an innovation and a mass collection of sensitive data that authorities deem disproportionate.
The World Bank, through its ID4D (Identification for Development) initiative, estimates that around 850 million people remain without legal identity (2021 estimate, down from the one billion estimated in 2017). Giving these people an identity is presented as a development goal, tied to financial inclusion and access to services. This argument is sincere and partially verified: the absence of identity really does exclude hundreds of millions of people — more than half of them children whose birth was never registered.
But the architectural choice is never neutral. Some platforms, such as MOSIP (Modular Open Source Identity Platform) from India, serve as a foundation for several countries. Conversely, Estonia rests on X-Road, an architecture where data remains distributed across administrations rather than centralised in a single database. Centralising like Aadhaar or distributing like X-Road does not produce the same power: the second path better preserves reversibility and limits the single point of failure.
Digital identity ceases to be a convenience as soon as it commands access. In Nigeria, the policy of mandatory linkage between the national identity number (NIN) and SIM cards led to the suspension of tens of millions of non-compliant phone lines: according to the regulator NCC, tens of millions of lines were barred in 2024, with a marked drop in teledensity. By contrast, Singapore illustrates a massive and largely consented adoption: its SingPass service is used by the vast majority of adults.
But adherence is never guaranteed — and this is important news against fatalism. In the United Kingdom, the GOV.UK Verify digital identity programme was a documented failure: the National Audit Office (2019) noted that it had reached only around 3.6 million users out of the 25 million targeted, with a verification success rate of around 48%, leading to the programme's abandonment. When people are not compelled, citizens may simply not sign up.
Unification passes through discreet but decisive technical standards. The ISO/IEC 18013-5:2021 standard defines the mobile driving licence (mDL), allowing one to present one's licence from a phone and to verify its authenticity cryptographically. It is one of the first "physical-world" credentials to migrate to the digital wallet.
This movement prefigures the moment when all attestations — diplomas, rights, authorisations, transport tickets — will reside in a single wallet. It is precisely this concentration that calls for vigilance: a single, convenient tool becomes, by its centrality, a lever. The technical capacity to centralise and to track exists; what remains to be seen is whether design and the law bound it.
Honesty requires separating two often-conflated questions. The first: can a centralised digital identity infrastructure technically enable traceability and control? Yes, the capacity exists. The second: is that the design choice adopted? Not necessarily — privacy-respecting models exist and are deployed (Estonia's X-Road, eIDAS 2's selective disclosure, minimisation standards).
To claim that digital identity is, in essence, a panopticon is to deny these models. In Michel Foucault's analysis (Discipline and Punish, 1975), the panopticon is not first an architecture but a mechanism of power: it works through the internalisation of the gaze, when the observed never knows whether they are being watched. But to deny that the capacity for surveillance exists is blindness. The truth lies in the gap between "can" and "does" — a gap that depends less on technology than on governance, checks and balances, and circumstances. The boundary is not technical: it is legal and political.
Contrary to a widespread narrative, the European Union has not legalised a control grid: it has forbidden several of its building blocks. The General Data Protection Regulation — GDPR (EU 2016/679) — strictly governs the processing of personal data and confers enforceable, free-of-charge rights: access, rectification, erasure, objection, portability. Biometric data are "sensitive" data there, benefiting from reinforced protection.
On biometrics, NIST (the U.S. standards institute) documented, in its reference study on the demographic effects of facial recognition (NISTIR 8280, 2019), that false-positive rates could be on the order of 10 to 100 times higher for certain groups depending on the algorithm. NIST does not say that facial recognition is "racist in essence": it shows that some systems are gravely biased and others much less so. This is why mandatory auditing is an essential safeguard: without oversight, the worst system can be deployed without anyone knowing.
Digital identity is neither a dystopian fatality nor a mere administrative modernisation. It is a powerful, double-edged infrastructure whose trajectory depends on human and revocable decisions. The real risk is not an orchestrated conspiracy, but a convergence of incentives — states, banks, companies, citizens each pushing their own piece — that draws a grid with no conductor. Such a convergence is corrected only by deliberate and maintained rules.
The citizen's sovereignty plays out exactly there: demanding the architecture, not just the promise. Requiring that minimisation, non-correlation, and reversibility be written into law, controllable and sanctionable. Exercising one's GDPR rights. Supporting regulators, NGOs, and journalists who turn indignation into a legal limit. Organisations such as the EFF remind us that a digital identity should never be a condition of access to civic life, and the European Data Protection Supervisor (EDPS) has publicly stated that the success of the European framework will be measured by its ability to embody fundamental rights, not merely by its technical performance. What you see clearly, you can refuse — or govern.
Is the European digital identity mandatory? No. eIDAS 2 (Regulation EU 2024/1183) requires states to offer a wallet to their citizens, but the text provides for it as optional for the user. The stake is that this optional character remains effective and that the absence of a wallet does not entail exclusion from essential services.
Is World ID banned? Not globally, but its biometric collection has been suspended by several authorities: the Spanish AEPD in March 2024 and Hong Kong's PCPD in May 2024. These decisions illustrate that large-scale iris collection runs up against data protection law.
Does Aadhaar prove that digital identity leads to total control? No. Aadhaar shows both faces: massive inclusion and a single point of control. Above all, the Indian Supreme Court restricted its mandatory uses (Puttaswamy, 2017-2018), proof that checks and balances can bound even the world's largest biometric system.
Does digital identity allow me to be surveilled? The technical capacity to track exists on centralised models, but it is not a fatality: distributed architectures (X-Road) and selective disclosure (eIDAS 2) limit this traceability. The GDPR moreover strictly governs any processing of your data.
What is the main guarantee to demand? Reversibility and minimisation written into law. A respectful digital identity reveals only one attestation at a time, does not allow your uses to be correlated, and can be revoked without excluding you from society. As long as these guarantees are legally binding, the tool remains a service, not a leash.
This investigation is only a gateway. To understand how digital identity articulates with programmable money and the biometric gaze — and how these three pillars become an architecture — the full investigation "The Architecture of Control" documents each source, regulation, and court decision. Always distinguish capacity from intention, convergence from conspiracy, the announced project from the successful one.
No. eIDAS 2 (Regulation EU 2024/1183) requires states to offer a wallet to their citizens, but the text provides for it as optional for the user. The stake is that this optional character remains effective and that the absence of a wallet does not entail exclusion from essential services.
Not globally, but its biometric collection has been suspended by several authorities: the Spanish AEPD in March 2024 and Hong Kong's PCPD in May 2024. These decisions illustrate that large-scale iris collection runs up against data protection law.
No. Aadhaar shows both faces: massive inclusion and a single point of control. Above all, the Indian Supreme Court restricted its mandatory uses (Puttaswamy, 2017-2018), proof that checks and balances can bound even the world's largest biometric system.
The technical capacity to track exists on centralised models, but it is not a fatality: distributed architectures (X-Road) and selective disclosure (eIDAS 2) limit this traceability. The GDPR moreover strictly governs any processing of your data.
Reversibility and minimisation written into law. A respectful digital identity reveals only one attestation at a time, does not allow your uses to be correlated, and can be revoked without excluding you from society. As long as these guarantees are legally binding, the tool remains a service, not a leash.
Dossier : Monnaie & identité numérique : l'architecture du contrôle
TOME 2: L'Architecture du Contrôle
Accueil · Collection · Journal · Dossiers · Sources