Thank you Warwick. It's great to be here back in Berlin after being here last year to talk about the work that the UK was doing to build trust in digital verification services, the systems we use to prove ourselves and things about us. As Warwick said, I'm the Chief Executive for the Office for Digital Identities and Attributes, which is a part of our Science, Innovation and Technology Department in the UK. We're responsible for making sure that people can take advantage of digital identities in their everyday lives across the economy.
And whether they're being built by government or by the private sector, the services that we use to prove things about us need to be trusted or they're not useful. Last year I was at this conference talking about how we'd been building an ecosystem of services in the UK that people could use anywhere across the economy and that gave people a choice about which identity services that they used. And I'm going to continue that story today.
I'm going to talk about the things that we've done to build trust in that ecosystem and I'll talk about what that looks like in practice and what's going to be possible in just a few months' time across at least England and Wales. And I'll talk a little bit about what's coming next after that as well. Trust continues to be central to what we are trying to achieve in the UK, not least now as we are in the middle of a consultation process for the introduction of a new form of digital ID that will be issued by central government.
The aim that the government has announced is to introduce that before the end of this parliament, so that will be by 2029. It won't be mandatory to have one, but it will be free of charge to get one, so if everybody wants one they can have one. And we also hope that that will mean that the UK's ecosystem will become more inclusive by design. But there's a consultation happening and I'm a civil servant and therefore I can't talk about it.
So I'm not going to talk that much about it in detail today, but the proposal is intended to build on work that we have already done, not least the introduction of Gov.UK OneLogin, which is a service that we use to access central government services via Gov.UK. And of course over the last year or so we've been working to build a government wallet as well. Last year we issued digital veterans cards, which are issued to former members of the armed forces, into the Gov.UK wallet.
And we've recently completed a trial issuing digital driving licenses to friends and family in the UK for the first time. But the Gov.UK wallet and Gov.UK OneLogin systems are part of a much wider hybrid ecosystem of services that are predominantly built in the private sector. And we've chosen that hybrid approach with deliberate intention to encourage innovation, to drive adoption, to build resilience, to support inclusion, and also to grow an entire new part of the UK's tech sector. But because of that choice, we need to trust a whole ecosystem of services.
And to build trust in that ecosystem and to trust digital identity and realize its benefits at scale, we think that you need common standards, independent assurance processes, and to underpin all of those processes with legislation. Getting that right will mean that we have an interoperable ecosystem which is secure, privacy preserving, inclusive, and importantly gives people choice about how and whether they use these services. So we've created common standards. That's the UK Digital Verification Services Trust Framework. Bit of a mouthful, apologies.
But that is a technology agnostic set of rules that enable people to know what good looks like. And it promotes privacy, security, transparency, inclusivity, and interoperability across that entire ecosystem. These rules leave space for the ecosystem to innovate inside a common framework without specifying specifically how every single part of the system has to work. But it also sets a consistent floor for the quality of digital identity in the UK. So we've got rules. How do we know that people are actually following them?
Well, we have independent assurance processes for that. Service providers can use that independent process to prove that they follow the rules in the trust framework. And they're independently assessed by third-party conformity assessment bodies using a certification scheme that's written by my team in Ofdia. And this process is already operational today. Two conformity assessment bodies are offering this certification, BSI and the Kantara Initiative.
And the UK's statutory national accreditation body, the UK Accreditation Service, ensures that the rules that we've written align to international standards. But it also makes sure that those conformity assessment bodies are implementing them consistently. Importantly, our conformity assessment process is not based on a specific technology standard. There are many technical standards that we are allowing to operate inside the UK's ecosystem.
And, in fact, we're encouraging it. Predominantly, that's because we don't think technical conformance is enough to build trust inside an ecosystem. Trust in digital identity is not purely a technology problem. And just because you can trust that the technology functions doesn't mean that you can trust it. We need to have confidence in the whole process that wraps around all of this, not just the technology. And so we've intentionally chosen a product services and processes standard, ISO 17065, as the basis for the UK's conformity assessment system.
Digital identities are only as strong as the processes that sit around them, the services that are running those processes, and the organizations that underpin them. And without confidence in the service and the service provider, we can't have confidence in anything that that service produces. To help people know whether a service can be trusted, we've created a centralized government registry. And many of you will be familiar with using registers and digital signatures across lots of ecosystems, but obviously things like verifiable credentials rely on that.
We're extending that same concept to services that create, store, or verify digital identities. We're in the process of enabling public key infrastructure as part of that register that will enable anyone to check in real time whether or not a service meets the rules set by government. Over the summer, services will also start to be granted this new trust mark, UK Certified E. This will be a visible indication to users and to relying parties across the UK that a service meets the rules that my team in government has set. And this entire regime has now been given a basis in UK law.
The trust framework, the certification process, the trust mark, and the register are all underpinned by the UK's Data Use and Access Act that was passed through Parliament last year. And that now means that all of it can act as a trust anchor for the UK's ecosystem. We're now starting the detailed, difficult work of pointing the UK's wider legal infrastructure towards things like our register as the basis for trust in digital identity across the UK. And that makes it possible to do some new and, for us, quite exciting things that we couldn't do before.
As one example, later this year, fingers crossed, because we've now got our trust architecture in place, you'll be able to use a digital identity to prove your age to buy alcohol in pubs, restaurants, and shops in the UK. This has never been possible before. And that means that you'll be legally able to use a service like this one from British company Yoti. You'll be able to prove that you are who you say you are using an on-device biometric system. And you'll be able to present a privacy-preserving proof of age. The retailer will be able to programmatically verify that that is real.
And importantly, the retailer will only receive the information that it needs to complete the transaction. That I am over 18, and that it is me. And that's it. Here's another example from a company called Lucidity in the UK as well. Prevents a very similar interaction pattern with biometrics, with a digital proof, and of course with verifiers to do the same thing. To quickly and securely prove that you are old enough to buy a drink in a privacy-preserving way.
As I say, none of this has been possible before the work that we did last year with the Data Act and with other legislation that's coming forward this year. And of course it would be really, really annoying if you needed a different service every time you walked into a different shop. But because we have our trust anchors in place, these services can also now start to interoperate. And they are starting to do so.
So whether they're private sector providers or the government-provided wallet, the UK wallet, all of these services will have the same trust anchors, and they will also therefore have equivalent validity across the UK economy. That will enable relying parties to have confidence that they are doing the right things when they check those identities. And this works specifically because both ends of these transactions, the wallet on the user's device and the verifier used by the retailers, are rooted in that trust architecture. And I'm going to break that down a little bit more now.
Let's go back to that YOTI service as it's quite instructive. There are two services here. I've changed the labels here from what we call them in the UK, just to make it slightly more easy to follow for those of you that are not in the UK or trading there. We've got a verifier and a wallet, what we call something different. And there is also an identity creation service underneath that as well. All three of those services have been separately certified and appear on the government statutory DVS register, as we call it.
And in fact, by the time we've changed the regulations for alcohol purchasing this year, they must be on that register in order to be used for alcohol sales. No other form of digital identity will be accepted. To get onto that register, providers have to go through the independent certification process to prove that they are meeting the trust framework. And in this particular instance, they need to be able to demonstrate that they can prove my age to what we refer to as a medium level of confidence. The conformity assessment process can prove that that is happening.
And we put the outcomes of that process on the register, which then means that we're able to point UK regulations at the register and say, if you use one that's on that list, it's therefore acceptable. And because that register has that legal status, it can act authoritatively as the UK's central trust anchor for these systems. All of that means that by the time any of you visit the UK, hopefully by Christmas, you will be able to use a DVS service like these to buy alcohol in pubs, restaurants, and shops across the UK.
And because these services have been evaluated through conformity assessment, and because they appear on that public register, we can trust the outputs they provide. You'll notice that those private sector services that I've just showed you, they weren't using government issued verifiable credentials. There's no technical reason why they couldn't do that, but they don't have to under this model.
We're starting to move away from a process that requires a specific document to do a specific thing in the UK, and instead we're able to place our trust in the services and the quality of the data that those services can demonstrably provide. Our trust architecture will now mean an end to having to hand over a physical document in a pub to prove who you are and that you are over 18. And a whole ecosystem of services is making this possible. We don't have to do it all ourselves.
We're hugely excited and grateful that all of these companies on the screen behind me have decided to build companies in the UK, to invest in the UK economy, and to create jobs and help us to grow our economy more widely. So that's one example of how a digital verification service in the UK could be used and supported by our DVS architecture. Alcohol purchases, though, are just the start.
Today, there are 62 digital verification services from 45 separate companies that appear on our statutory register. That's live information from today. They're providing a whole range of services. They're not all consumer-facing. Some of them provide small pieces of componentry that get plugged into wider systems. Some of them are business-to-business services, and of course, lots of them provide wallet services and the kinds of things that you might see on a checkout in a shop by the time that you get there. By the time you go into Tesco's or Sainsbury's.
And it's already a £2 billion industry in the UK by revenue. We think it might double by 2030, so £4 billion based on the latest data that we've got. It's generated £800 million worth of GVA to the UK economy, and it's underpinning 10,000 jobs so far from the hybrid model that we've pursued. And we want to make sure that that sector continues to grow, because it's critical to the success of everything else that we are trying to do at the moment. But growing the sector means we need to continue to open up new use cases, so we are doing just that.
Possibly most significantly, in February, our Treasury Department, our Finance Department, for those of you that are not in our antiquated English language, has published new guidance on how to meet the requirements of the money laundering regulations for knowing your customer. And this guidance makes use of the services on that government register and says that they are now the preferred method of doing digital verification checks on customers in the UK. And that is massive for us.
It unlocks 16 new sectors of the economy that could mean for people to be able to use digital verification services in. Not least financial services, which is the obvious one, but also things like gambling and possibly one that wasn't on your bingo card for today, art sales, is also on that list. We're also enabling age verification use cases.
Now, alcohol is one that I've obviously just discussed, but we're also investigating a whole range of other age verification use cases, because we think that alcohol was the totemic first use case, but the pattern probably is the same in lots of other places. So we're working on age verification more widely. And the fact that all of our trust architecture elements are now in place means we can start to unlock these use cases much quicker. The legislative barriers are starting to fall away and the technologies are starting to work.
This year we're also commencing a new legal framework for data sharing between government organizations, public authorities as we refer to them, and private sector organizations as well. This new legal power is explicitly permission based, so it won't happen unless the person is asking for it. So I have to ask for my data via this ecosystem. But that is going to help our markets grow in a more inclusive way. There's some data that only government has about you, and it would be useful if that could be unlocked into the wider economy. So that's what this legal framework is for.
And it will also mean that more people therefore will be able to access digital identities when they otherwise might not have done. So that's basically what I wanted to talk about today. I've spoken about the UK's trust architecture and how we're using standards, assurance, and governance to build an ecosystem of trusted services across both the public and private sectors. I've spoken about what that looks like in practice, focused on the alcohol use case in particular, and I've also spoken about some of the things that are coming next.
It's genuinely exciting to be working in this field in the UK at the moment, whether that's as a government official or whether that's somebody running a digital verification services business. With our trust framework, we think we have the basis to make things simpler and faster for citizens and businesses across the economy, but also importantly to stimulate a whole new sector of our tech economy as well. So that's it. Thank you. My email address is there if you want to speak to me about any of that.
And of course, we've got our website and our blog if you want to follow along with the latest information and updates. Thanks. Thanks very much, John.
Obviously, there had to be a controversial question about saying that 63% are against mandatory use of digital identity in the UK. So also the UK system is not sovereign because they're using US software. So how do you regain that trust? So obviously, there's a reason why we go through consultation processes to listen to what people think about what the government wants to do. And the government will make decisions based on that.
Obviously, as an official, I can't really comment on the kind of strategic intention and design there. But I think everything we're doing is to build trust. And we have pretty good evidence, actually, that there are some people for whom trust in government won't be the thing that gets them to use these systems. And in the reverse, some people don't trust technology companies or other companies to do some of this too. So I don't think it's a universal kind of broad brush picture that we can paint across the entirety of any population in any country.
Different people have very strong views on this in general. But I think our hybrid architecture enables us to kind of meet everybody's needs and kind of do that in a trusted and secure way. So that's kind of what we're focused on is making sure that there's something for everyone and that regardless of what they choose to use, that it can be trusted. Great. Thank you very much. Great to have had you. Thanks. John Kierke.