In July 2026, the brand new Burnham government cancelled the UK’s national digital ID scheme. Nearly three million people had signed a petition against it and a very hostile Commons debate had been held. The £1.8 billion budget was redirected to a VAT cut on winter electricity bills, and it looked like, by any reasonable measure, that the government had caved to public pressure and the people had won.
The digital ID card, the government-issued credential that would have sat on every citizen’s phone was dead. Ministers said so and the media reported it as a victory for civil liberties. The petition organisers celebrated their win and the political pressure that had built over months quietly evaporated, and the country moved on to other things.
Two months later, the House of Commons Library published a briefing confirming that GOV.UK One Login, GOV.UK Wallet, and the Digital Verification Services Trust Framework are all continuing unaffected by the cancellation. One Login now has 23 million accounts across more than 120 government services. The GOV.UK Wallet is live and a digital driving licence is being piloted. The government’s own Blueprint for Modern Digital Government lists all of them as active programmes.
The government cancelled the card but it did not cancel the system.
To understand why the cancellation is not as clear cut as the government claims, you need to know what the infrastructure actually consists of. GOV.UK One Login is the single sign-on and identity verification system that the government wants every citizen to use when accessing public services. The GOV.UK Wallet is the app that holds digital credentials like the driving licence. And the Digital Verification Services Trust Framework is the rule book that certifies private companies to offer identity verification, allowing them to plug into the same infrastructure and sell identity services to employers, banks, and landlords.
Everything being built sits on a single platform, GOV.UK One Login. The Wallet and the digital driving licence both depend on it, every private identity provider certified under the trust framework connects to it. One Login is the foundational layer of the UK’s digital identity infrastructure.
Its security record is damning, and the government’s response to it is worse.
In November 2022, the Cabinet Office had flagged serious data protection failings, and in September 2023, the NCSC warned of significant shortcomings in information security, including risks of data breaches and identity theft. Contractors in Romania had been working on One Login’s development on unsecured workstations without appropriate security clearance, and without the knowledge or consent of GDS’s own CEO. The code they produced was not being reviewed by UK-based security-cleared personnel before going into production.
A cyber security professional working on One Login first raised concerns through proper channels in July 2022, shortly after launch. They reported that the system lacked basic governance and risk management processes, and identified over 500,000 system vulnerabilities, with thousands rated as critical or high severity. GDS’s own Chief Information Security Officer investigated and reportedly confirmed key parts of the claims. The government later argued that the vulnerability count was artificially large because findings were repeated across multiple production accounts. But by November 2023, the new CISO confirmed the system still carried “a high level of risk” and noted that 39% of staff with privileged access lacked mandatory security clearance.
The whistle blower then waited 18 months for the problems to be addressed, and when this didn’t happen, they escalated to their MP in January 2024. Three weeks later, GDS commenced disciplinary action against them, and when the MP wrote to the minister asking about the allegations, GDS framed the risks as manageable and never mentioned the NCSC’s earlier warnings.
The government’s response was not to slow down or tackle the issues. It was to reduce oversight. GDS disbanded its independent information assurance team in 2023, and in early 2025, the One Login Inclusion and Privacy Advisory Group went the same way and was quietly shut down.
In May 2025, One Login lost its certification under the Digital Identity and Attributes Trust Framework (DIATF), the scheme the government created to certify private companies as fit to handle citizens’ identities. A private company that lost that certification would be removed from the register and unable to operate. GDS knew the certification had lapsed, and then described the underlying security concerns as “outdated,” and just kept the system running. One Login continued handling millions of citizens’ data across dozens of government services for eight months without the accreditation the government was enforcing against the private sector. Users were not notified and the service was not paused. In December 2025, two months after One Login scraped its certification back, the Data Use and Access Act gave the framework statutory force. If the lapse had happened eight weeks later, it would have been a legal breach. The margin between a double standard and breaking the law was two months.
Multiple whistle blowers have since come forward. One told ITV News that the shortcomings could lead to “the worst data breach in UK government history.” Another said the vulnerabilities “are standard things you must not do, but they’ve been done,” and warned that it would not take any creative thinking for a state actor or organised crime group to exploit them. Lord Clement-Jones, the Liberal Democrat technology spokesman, said a whistle blower told him the system would not pass key security tests until March 2026, contradicting official assurances. That deadline passed without being met and as of May 2026, the government was still describing compliance as something One Login was “working towards.”
The security failures are one problem. The surveillance architecture is another.
Every time you use one of your credentials from the GOV.UK Wallet, the system checks whether it is still valid, creating a digital record of each use. A car rental company legitimately needs to know your licence hasn’t been suspended, whereas a nightclub checking your age does not. But the current design makes no distinction. Present your digital driving licence to prove your age at a bar and the system runs the same verification process as if you were hiring a car, and the issuer can potentially see both events. The technology to separate these use cases exists but the implementation does not use it.
Security experts have already warned about the digital trail that use of the GOV.UK Wallet will likely leave behind. Privacy International and Big Brother Watch have both flagged concerns about user profiling, surveillance, and function creep. The government claims there is no central repository tracking users’ interactions and that data remains on the user’s device. But the credential verification process inherently involves contacting the issuer or checking a status list. The privacy promise is a policy commitment. It is not a cryptographic guarantee, and policies can change with a government.
The cancellation of the card changed something else that received very little attention. The original scheme would have created a single, government-issued digital identity with public accountability, but what replaced it is a market.
The UK’s Digital Verification Services sector generated £2 billion in revenue in 2024/25. Under the trust framework, private providers are certified to verify identities on behalf of government and business. The Office for Digital Identities and Attributes describes these providers as “critical intermediaries” who will allow people to share information from the GOV.UK Wallet and create reusable digital credentials. In February 2026, HM Treasury confirmed that certified digital identity services can satisfy the identity verification requirements in the Money Laundering Regulations. The infrastructure is becoming load-bearing across the economy.
The tech industry lobbied explicitly against the government card, arguing that the private sector was already providing digital ID services and that a government scheme would crowd out commercial alternatives. That argument won when the card was cancelled, however, the infrastructure was not.
Under the original scheme, there would have been one government identity with one set of accountability mechanisms and one data controller. Under the replacement, there is a fragmented market of private providers with different terms of service, different data handling practices, and little transparency, all sitting on top of the same government platform that has repeatedly failed its own security assessments. The citizen’s personal data now flows through both the government system and whichever private provider they choose, doubling the attack surface.
Right now, the GOV.UK Wallet is optional, the digital driving licence is a pilot and physical documents still work. But the direction of travel is clear. Once enough government services are routed through One Login, once banks and employers accept wallet credentials under the trust framework, and private providers build their businesses on the infrastructure, the old alternatives will degrade. Not because anyone bans them, but because nobody maintains them. We have seen this pattern with every comparable digital infrastructure project.
When the wallet becomes the default, something changes that goes beyond convenience. The government already knows a lot about you, but that knowledge is fragmented across departments. HMRC sees your income and tax, DVLA sees your licence, DWP sees your benefits. These systems don’t routinely talk to each other, and that fragmentation, inefficient as it is, acts as a privacy and security safeguard. No single system sees the whole picture, and a breach of one doesn’t automatically mean a breach of everything.
The wallet changes that. One Login becomes a single identity layer connecting interactions across government and the private sector. And it doesn’t just centralise data the government already holds separately. It adds an entirely new category: day-to-day activity that currently no department sees. Where you proved your age, which hotels you checked into, what age-restricted content you accessed online under the Online Safety Act. A system designed to replace a paper driving licence becomes the single thread connecting your tax records, your employment, your driving history, your age-verified browsing, and your physical movements, all in one place, all logged. The government would need to actively prevent that centralisation and the current design does not.
Nobody in government appears to have connected the card debate to the infrastructure underneath it. The petition did not mention One Login, the Commons debate did not interrogate the security record, and the cancellation announcement did not address the Wallet or the trust framework. Three million people fought the thing they could see and they won. The thing they couldn’t see is still growing, and nobody seems to be watching it.
I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.
Sources
House of Commons Library, “Digital ID in the UK,” CBP-10369, published 4 September 2026
UK Government, Blueprint for Modern Digital Government, 2026
Computer Weekly, “Government faces claims of serious security and data protection problems in One Login digital ID,” April 2025
Computer Weekly, “Gov.uk One Login loses certification for digital identity trust framework,” 13 May 2025
Computer Weekly, “MPs question security of digital ID system,” November 2025
ID Tech Wire, “Critical Security Flaw Found in UK’s Gov.uk One Login Identity System,” 16 May 2025
ID Tech Wire, “UK One Login Digital ID System Faces Major Security Breach Allegations,” April 2025
ITV News, “Whistleblowers raise ‘extreme’ concern about security of government’s Digital ID,” 18 December 2025
Biometric Update, “One trust question for GOV.UK One Login answered, another raised,” October 2025
Biometric Update, “UK gov’t proceeding with GOV.UK and private sector digital ID plans as DSIT closes,” August 2026
Think Digital Partners, “One Login and GOV.UK Wallet push continues after digital ID cancellation,” 8 September 2026
Public Technology, “GDS ramps up ‘capability delivery’ for One Login with £44m deal,” August 2024
Public Technology, “Deloitte signed to £50m deal to support delivery of GOV.UK App,” August 2024
Infosecurity Magazine, “UK’s New Digital IDs Raise Security and Privacy Fears,” January 2026
Written evidence to Parliament, “The public distrust government-issued digital ID,” November 2025
Written evidence to Parliament, “Response to Question 4: Risks of Digital Identification,” August 2025
HM Treasury / DSIT, Digital identity guidance for Money Laundering Regulations, 26 February 2026
GOV.UK Wallet example credential issuer, technical documentation (ISO mDL / OID4VCI architecture)


