What identity verification does
Today's identity verification is a set of procedures for turning paper into data. The person opening a bank account, applying for a lease, or subscribing to an age-restricted service is asked to photograph the identity documents they hold — a passport, a driving licence, a utility bill — and to submit those photographs to the organisation running the check. They are asked to take a selfie, sometimes moving their head or blinking, so the system can confirm that the passport is a passport of a living person, not a photograph of one. They are asked, in some flows, to grant camera access, microphone access, and permission to run the check against sanctions and politically-exposed-persons registers under the money-laundering regulations that apply.
The material submitted is then processed by the organisation running the check. The output is a set of yes/no answers about the person: is this person real, is this person the person they say they are, is this person eligible to open the account. The output is stored alongside the material that produced it. The organisation ends the process holding copies of everything the person submitted.
Paper documents as digital credentials
The material used to verify identity in this way was not designed for digital use. Passports, driving licences, and utility bills are physical objects, made to be looked at by a person in a room with the person carrying them. Their security relies on the material of the document, on the difficulty of forgery, and on the fact that presenting a forged one to a border guard or a bank teller means being there when it is checked.
Photographed and submitted to a digital verification service, those documents inherit the properties of any other credential. They can be copied. They can be forwarded. They can be produced by anyone who obtains a suitable image, whether legitimately or otherwise. Where the physical document is protected by the physical relationship between it and the person carrying it, the digital image is not. The digital verification apparatus is a physical-world proof retrofitted onto a digital transaction. The verifier does not see the person; it sees a rendering of the person's document.
Even the government-issued electronic IDs that exist to formalise this transaction — eIDAS-recognised eIDs across the EU, GOV.UK Verify (until its retirement), the Aadhaar-based digital identities that transact at scale in India — are certificate-mediated proxies for the same underlying paper documents. The certificate says: a trust service provider, at some moment in the past, checked a person's paper documents and found them satisfactory, and issued a key which is now being used. The certificate does not say who is using the key at the moment of the transaction.
The material organisations end up holding
The retrofit has a consequence. Organisations conducting identity verification, at the end of the process, hold copies of the material submitted. Photographs of passports. Photographs of driving licences. Biometric templates. Address histories. Credit report extracts. The results of PEP checks and sanctions screening. Every organisation that runs verification builds its own database of this material.
The datasets are attractive to attackers because each record contains what a criminal needs to impersonate the person to a third party. In 2022, the Australian telecommunications company Optus disclosed a breach in which the driving licence numbers, passport numbers, and Medicare numbers of 9.8 million customers were exfiltrated. Latitude Financial disclosed a similar breach the following year, affecting 14 million records, some of which had been collected in 2005 and retained under money-laundering rules ever since.
The datasets are also attractive to regulators, for the same reason. The regulations that oblige an organisation to collect the data — money-laundering regulations, know-your-customer requirements, age-verification rules — carry alongside them the regulations that oblige the organisation to protect it. The organisation is required to hold data that, once held, is a liability. It is compelled to collect it, then compelled to defend it, then subject to enforcement action when the defence fails.
The pattern is not a story about individual organisations doing verification badly. It is a story about the structural consequence of asking every organisation that needs to know something about a person to collect and store the underlying material.
Verification designed for the digital paradigm
The alternative the research examines does not begin with the assumption that identity verification requires material to be submitted. It begins with the assumption that identity in a digital context does not have to look like identity in a physical one.
An identifier designed for the digital environment is not a photograph of a paper document. It is cryptographic material generated by the person, held only by the person, and presented in forms that appear different to each organisation the person interacts with, so that data collected in one context cannot be joined up with data collected in another.
Verification, in an architecture built on that kind of identifier, does not require the organisation to hold the material used to verify. The organisation asks a question — is this person over eighteen; is this person a UK resident; is this person the individual on this signed lease — and receives an answer from the person's own device, bound to the person present at the moment the answer is given. What the organisation stores is a record of the question and the answer, not a copy of the person.
The research question is how identifiers designed for the digital paradigm, and verification performed on the person's own device, could remove the need for organisations to hold personal data at all.



