This panel will explore how public-private collaboration, evolving technical standards, and modern authentication methods are converging to create a more secure, user-centric, and privacy-preserving identity ecosystem.
This panel will explore how public-private collaboration, evolving technical standards, and modern authentication methods are converging to create a more secure, user-centric, and privacy-preserving identity ecosystem.
In a panel discussion focusing on digital identity and trust, experts Jerome Thorstenson and Adam Cooper explore the transformative potential of decentralized identities and verification processes, predicting significant industry changes by 2030. Thorstenson, representing the Salling Group, and Cooper, drawing on his experience with multinational organizations like the World Bank, emphasize the interplay between technology, legal frameworks, and societal factors. The discussion highlights existing challenges and potential solutions in digital identity, emphasizing inclusivity and privacy. They examine the growing trend of convergence between governmental and commercial digital wallets, illustrating the convenience of carrying credentials on smartphones and discussing future integration with government-based digital identities. Concerns about privacy in the digital sphere are emphasized, notably regarding the role of biometric verification and centralized data storage. The diverse strategies of global regions, such as ASEAN's focus on digital trade and Africa’s initiatives, underscore varying priorities and challenges. Despite the potential security threats of social data aggregation, there is an acknowledgment of its role in fostering societal structures. The dialogue suggests that while a fully ideal digital trust infrastructure may not be immediate, considerable progress can be achieved with shared responsibility between governmental and private entities.
So, again, I'm Jerome Thorstenson from Salling Group. I am an architect, and to answer your question, I'll actually say there is two. I think that we are looking at decentralized identities as a game-changer, and I am also thinking that verifying, or the way we do verification of identities is gonna be a game-changer.
Yeah, and Adam? Yeah, good morning, everyone. Late addition to the panel, but hopefully I'll be... Thanks. My name's Adam Cooper. I'm an enterprise architect back in the day, but latterly, I've spent most of my time working with governments over the years, helping them to understand how to implement digital technology, largely in the identity space.
I'm now an independent consultant, but I work predominantly with organizations like World Bank, where a lot of these international interoperability problems come to the fore, and many of the things that we heard earlier from Elizabeth was talking about. What do I think's gonna shape things in the next five years to 2030?
Well, I think it's gonna be a convergence of many things. Jerome just mentioned wallets. I think technology is part of that. I also think that legal and regulatory forces will be a major part as well, and that the whole reason why we have the EUDI wallet, for example, is regulation, and a continuance of work that started, well, back with the first version of EIDIS in 2014. So we're on that journey, that trajectory anyway, with the legal element of that. But I think the social forces as well.
More and more of what we do is geared around the user-centric world, and as a consequence, there's a big overlap between what we do as people, whether it's with our governments or in our daily lives. And it's no surprise that most of our time is spent actually not working with governments. So the example I give about wallets always is that on my phone, to get here, I have my plane ticket. I have parking capabilities. I have my credit cards. I'm already doing that with commercial wallets. It'd be great to do it with my government wallet too.
Maybe there's something where we can bring the two together. And I think that convergence of all of those trust frameworks that we heard earlier that Elizabeth was talking about, being able to do things internationally as I pass through an airport from one country to another, it works with my credit card and my mobile phone, why shouldn't it work with my identity?
You know, that's great, because yesterday I was in conversation, or in the panel downstairs, listening to the panel downstairs on wallets and what end users expect. And there was general consensus on that is, don't, I mean, even Christina Yasuda said, like, don't wait for the government, you know. Don't wait for the governments because otherwise, so I think there's definitely seems to be a feeling that private has got a real role to play. And as you say, a kind of convention of the two. So you mentioned standards. So let's start with strategic vision and standards.
What core principles should define tomorrow's digital trust infrastructure? From my perspective, in a lot of my work, I'm involved in, not in places like Berlin, but in the developing world, usually, it's inclusivity. It's everybody in this room will have, I can guarantee you will have a smartphone. We've all got passports. We've probably got ID cards. If you go to many parts of the world, that's not the norm.
So we can do great things with technology, with biometric verification, doing that through your handsets, carrying your credentials around with you, and being able to share them digitally. But can I do that in sub-Saharan Africa? Can I do that everywhere in the world? Probably not. So we need alternatives. We need to be inclusive. We need to appreciate that, yes, we can biometrically verify everyone. We're not always gonna use a mobile phone, perhaps, to do the verification elements and the authentication. It may well be that I need to provide government infrastructure to do that.
Yeah, Gerard? Yeah, so one of the things that I am kind of looking for in this space is the whole privacy aspect of it. So how do we actually manage to achieve this, but manage it in a way where we say it is based on the least amount of information?
So today, if you go the biometric way, you can do one of two things. You can say, okay, my biometrics are stored on my smart device, phone, whatever, computer, or you can store it centrally. And there's an inherent risk of storing it either on the device itself or on the central location, right? So that's kind of my view on it. So Elizabeth mentioned EIDAS.
I mean, obviously, that's kind of a huge influence, but what other, I mean, in addition to EIDAS, what other sort of global standards and governance frameworks do you think are proving the most influential in aligning efforts? Should I take that? So EIDAS is just one example. Regionally, lots of other things are happening. So if you look to ASEAN, for example, the Association of Southeast Asian Nations, they're looking at this from a slightly different angle.
It's not so much that they want to provide a digital identity for all of the citizens, but all the residents, I should say, from an inclusivity point of view, but they're actually looking at use cases more strongly, things like international trade. It's driving a lot of the work there in the trust framework element. Very similar story in Africa as well with the African Union looking right now at building a digital identity wallet, strangely, but specifically for digital trade. So they're driving out those use cases, which I think is very powerful.
And you'll also notice that those use cases are not governmental ones. It's about trade. It's actually building economies. And that's another important aspect that we shouldn't forget.
Yeah, I mean, considering what's happening in the world today with tariffs and so on, it seems that, you know, that kind of certainly is a very important driver for these sorts of things. But in general, I mean, do you think we're seeing a convergence or is kind of fragmentation still happening?
I mean, how do you guys feel about that? I mean, Jerome? So I'm leaning towards the convergence because what we are actually chasing at the moment is a way to say, okay, we have a parent company where everybody is kind of hired into, right? And it doesn't really matter what part of the world that you're hired into. If we have a digital wallet or equivalent of a wallet where we can say, okay, so we are offering you this position, you accept it, we can do everything electronically. We don't have to do all the nitty gritty paperwork at the location.
That would just smooth onboarding times and it will make our lives easier, both as employers and employees. So we can actually trust that once somebody signs up or signs a contract saying, yes, I would like to come work for you guys, then we can actually say, okay, these are your, potentially your credentials to use as the next generation of single sign-on, right? Kind of bring your own identity to work.
Yeah, so the next set of questions that I want to ask were around sort of privacy and trust by design. I think Jerome, you mentioned decentralization.
You know, again, what role do you think decentralized or federated identity models play kind of in this whole world? That's a tough one. So I don't believe that we can do anything really central and I don't think that we are in a position where we necessarily can wait for a government to invent the wheel on this. I think that the only way we can do this is kind of doing it on, I would say, some level of trust. And it's kind of a funny science because how do you trust somebody you don't know? And how do you, across borders, decide who is the trusted wallet holder that you can use?
So it's a mess right now. Well, maybe. I often think, and I think it was last year, I spoke about this, about decentralization and centralization and do they really exist as concepts in my mind?
Because, yes, I can give you a wallet with your national ID in it, but where does that national ID come from? It comes from a centralized institution, a government. So there has to be an appreciation that both have to coexist. It's that convergence again. What we're doing with the wallets is we're giving you the ability to share that information with more control and enhance your privacy, perhaps. But there's still a reliance there to have a government to say who we are. We do it now, crossing the border to come here from the UK. I have to have a passport. Why do I have to have a passport?
Because that's the thing that everybody trusts internationally. It's based on standards, which everyone understands, standards not just for the creation of the document and the electronic passport, but also for the process that went into proving who I am. That still exists for the wallet. So I think the wallet really is that convergence point in many ways.
I think from the inclusivity point of view as well, the appreciation before where I said, well, not everybody's going to have a digital device necessarily for whatever reason, partly because we need to provide people with choice, but partly for inclusivity. There needs to be the data somewhere in government and the ability to get access to that data. And this is where one of the concepts that Elizabeth mentioned earlier, DPI, digital public infrastructure, is going to be useful, I think, in certainly the next five years if we think about that question again.
Because that's providing the digital roads, rail tracks, infrastructure, as we think of it as the physical world, in the digital world. And provide that. But what I think needs to happen is we need to drop the P. I think it just needs to be digital infrastructure that's available more to the private sector, as much to the private sector as it is the public. Because that's what's going to power us to do more with wallets. That's where we're going to get more trust from, because we can dig into those really good data sets that sit in government.
Birth registration, ID cards, passports, driving license. I mean, Lofi talking about MDL yesterday was really good. The rollout of that is de facto ID in many countries. Because we use it now from a physical wallet, and we're soon going to use it from a digital wallet. It's a very powerful thing.
And again, that's the social aspect of, as people, we're going to drive this forward too. Yeah, I thought the presentation by Lofi Yardang yesterday was really interesting, and that's why we're really keen to have him over here. Because I think, for many people in their mind, MDL is kind of an American, US thing, and there's very little interoperability.
I mean, I was surprised and interested to learn just how useful it could potentially be. We'd like to make this as interactive as possible, so if you have any burning questions, please just pop them into Slido, and hopefully, if we've got time, I can pick them up and read them.
So yeah, please jump in if you'd like to ask our panelists any questions. The next question I have is, is it really possible to build a truly privacy-respecting biometrics and still meet regulatory demands like NIST 2, GDPR, and PSD 2?
See, I have my doubts, to be honest. So the way we do things is kind of, funnily enough, backwards, seen from my point of view. So what we tend to do is we push out some regulations saying we have to do this. And that's great, but there is no clear instructions on how to break it down. And I'm afraid that we might end up in a situation where we say, okay, so every bank is gonna decide to make their own wallet. What kind of information is stored in that wallet? How is that shared among other financial institutes? And let's take an everyday example. Let's take credit scoring.
If you have, let's say, 20 banks all feeding into the same central credit score bureau, how's that managed? Can you truly do that with respect to privacy? I don't think so, because you're handing over a personal identifiable information each and every time. Unless you go something like, blockchain, right, where you say you have a wallet ID, nobody knows who kind of has this wallet ID, except the wallet holder.
And then we're kind of back to the same thing, because today we are in a position where you can take a wallet ID and you can kind of reverse engineer it and figure out who is actually the owner, right? Yeah. I think you made some, so yeah, sorry, you were gonna say? Just to build on that, I think, I completely agree with everything you just said, but I think one of the things we need to also focus on is that there's a huge focus on, from the top end of thinking about, well, how do we regulate identity and how it's used and data and protect that?
But we also need to think about what happens once we've shared data? And this is where it all generally falls apart, in my opinion. It's with the service providers. When I go to my bank and I give them my data, how can I have any trust in what they do with it? And we're relying then largely on laws and regulations that frankly are usually well behind the curve with technology, don't appreciate the type of data sharing that might go on behind the scenes. And we're also our own worst enemies. If I want something desperately, I'm gonna say yes. Yeah. And we all do it.
It's either the fatigue with ticking boxes or it's, I just want to get this thing done. I've got like 10 minutes to do this, I'm catching a flight, okay, I'm gonna press yes. And then I forget about it. And there's no traceability then, there's no, it's very hard.
I mean, the wallets might help in a little way in that they might tell me when I've shared data and what it was, but they don't tell me what happens to it. Now, in some countries, you can actually see, certainly within a government, what happens to your data. So you've probably all heard of X-Road in Estonia. Ukraine have a similar system called Chambita, kind of fought for X-Road. And there are others as well, that give you sort of an audit trail of what government's doing with your data. But we have zero audit trail of what the commercial world is doing with our data. Exactly.
Until it's breached. Yeah. And that's the problem. And that's something we need to solve. One of the things you mentioned earlier was kind of the whole idea of business cases behind wallets. And I'm very glad that you did. And what I'd like to call out is later this morning, Martin is going to be leading a discussion around what are the real business cases for wallets. So please look out for that in the track sessions. I'm pleased to see that we've got a couple of questions from our audience. So just have a look.
In quotes, our time is full of paradoxes. We want to reestablish trust, but the way to do it conflicts with privacy. What are your thoughts on that? Shall I start? Sure.
Yes, I think there is a conflict there between trust and privacy. I think partly because, how do we form trust in the first place? I kind of trust my government because it does things for me. It provides me with, you know, I get a pension, I get helped out with healthcare when I'm ill.
You know, I might be able to get my passport and driving license from it. It does things for me, so I kind of trust it. But it's only kind of trust. I wouldn't necessarily give my government my banking data or things like that. And I might be skeptical about what it does with my healthcare data and all these kind of things because it does research to try and help me, but ultimately share my personal data. Do I trust my bank? Maybe. That's where I keep my money. I trust it quite a bit. It hasn't lost my money, so I'm gonna give my bank lots of information because, you know, they're good to me.
But do I trust a new organization that comes to me? How do I form that trust?
I mean, that's difficult because we try and do it on a human level. Do I trust you?
I mean, you know, we've met a few times over the years. I kind of trust you. We get on well. But would I give you my data? Probably not. Yeah. Yeah. But just to touch on that, so if you look at a broader perspective and say, okay, so you have all these social medias out there, right? The thing that they collect about you is all your data, all your habits. That's because we're lovely social beings. Exactly. We like to talk. Yeah.
And the issue is, so in Denmark right now, they have a legislation coming up saying they wanna give the police intelligence division the ability to mass pull this information and build profiles on you. And we're talking about this in a little country, right? We're what, six million people? Yeah. And they wanna do social profiling. How did we ever get to a point where that is an okay norm? Because what the government is telling you is, oh, but if you are a law-abiding citizen, well, you have nothing to worry about.
But see, the thing is, if you start storing that information, you start processing that information, what happens the second that there's a new legislation saying this is now illegal? Do we go back in time, run through all the archives and say, oh, here you go? Or what happens, right?
I think, if we got a moment. I think ultimately, once your data's out there, it's out there. And whether it's a government or a bank or anything, they can profile me. We've created through our own social love of sharing media and photographs.
And hey, I'm here, I'm having a great time. And hey, look at my son. And I go to work here. I've given it all away, kind of, in social media.
Well, maybe not me, but you guys. But it's there. And we've then created these enormous corporations behind our desire to share data. And then we wonder what they're gonna do with it. It's the naivety, almost, of us as human beings. Where I think there needs to be more emphasis is in governments need to really front up to this. And where we see, in many countries I operate in, where we insist on having a legal ecosystem that is protecting the citizen, that needs to happen more in countries like this, where there is real danger that states can do some pretty interesting stuff with your data.
That's how the ID card system got cancelled in the UK. Yeah, well, that always amuses me, how kind of national ID-phobic the Brits are, when, as you say, they'll gladly share all this stuff on social media, but, oh, we, you know, and it's kind of like, rather naive, as you say, to imagine that the government doesn't know all they need to know about you anyway. I've got one question here from the audience and that I'd like to combine with a question of mine. So my question is, we've looked at some of the negative things, but maybe try and look at the positive side.
What lessons can be drawn from real-world implementations in sectors like finance, you mentioned, but then healthcare and supply chains? And I'd like to combine that with a question from the audience. I'd love to hear your reflections on the interoperability between public and private sector when it comes to inclusiveness, notably within national healthcare. Okay. You want to start? So in healthcare, a couple of things.
One, if we look at how people work today, quite often they've moved from one job to another, have multiple jobs, and this is particularly the case in healthcare in many countries. So in the United Kingdom, for example, we have 1.7 million people working in the National Health Service. At any one time, 250,000, so a quarter of a million of those people are moving daily from one part of the organization to another. Each of these parts of the organization are employers in their own separate way. They have their own identity and access management systems. They have their own employment, HR systems.
So being able to move those staff around, the only really way you can do that efficiently is digitally. Currently, for most of them at the moment, they have to carry around lots of pieces of paper to prove that I have the right to work in the UK. I don't have any convictions that would preclude me from working with children, for example. I'm a qualified theater nurse, so I can actually go into the operating theater this morning and help somebody to live. And if you're doing that on paper, it slows the whole system down. It costs huge amounts of money.
So we created something called a Digital Staff Passport, which is a digital wallet that shares all of those lovely credentials, and it's great, and it works. So that's one example of actually doing things for workforces and allowing them to be mobile. The other thing in healthcare is data, which is a very double-edged sword. Everybody who ever goes to a hospital creates medical records. Whoever is treated creates a medical record.
That creates a huge amount of data, which can be used very intelligently to profile and understand simple things like what are the trends in different diseases and where we should build hospitals, and could we actually find clues to solving some of the more dangerous things in healthcare and in society that are endangering us all? But that means using our detailed data, which, as well as we can try to anonymize it, ultimately can be reverse engineered. Exactly.
So we have to accept a little bit, I think, that sometimes the power of doing a thing might influence the unarmed privacy, but that might help us live longer. It's a choice. Thanks so much to all of you for your contributions. I know there are a couple of questions left that we're not gonna get to, because unfortunately the clock has caught up with us. I just wanted you guys, just a closing statement on where you see the future of this whole digital trust thing. Are we ever gonna get there, or is it just gonna be one of those works in progress forever and ever?
Honestly, I think we're gonna not fully get there, but we're gonna come very, very close to being in a good position. Yeah, I think, yes, it's progressively getting better. I think it's a continual journey, as ever. The only other thing I would say about identity is it's starting to become critical national infrastructure, and that needs to be appreciated as well. I think that our two panellists have made some excellent points this morning, and we can just see how identity really is at the centre of everything. Please give it up for Alan Cooper and Jerome Torstensen. Thank you. Thank you.
Thank you. Thank you. Thank you. Thank you. Thank you.
See All Locations
See All Locations