Why Do Governments Keep Forgetting Who You Are? The Cross-Border Digital Identity Problem
- 1 hour ago
- 8 min read
Lose your documents in your home country and there is usually a clear path to replacing them. Abroad, even a routine procedure can become significantly more complicated. A bank in another country may require additional proof of identity, while some administrative procedures can mean obtaining documents from several countries where you previously lived. What was straightforward at home can become a bureaucratic project once a border is involved.
The problem is not that a person somehow loses their identity abroad. It is that the systems designed to confirm identity - and verify the documents, qualifications and records connected to it - were largely built within national borders. Once a person crosses a border, verifying that information can become slower and more dependent on manual processes.
This is the real challenge of cross-border digital identity. Identity documents do not simply become invalid abroad, but recognizing and verifying them - and accessing the information behind them - becomes significantly harder. Solving that requires looking beyond a single wallet app to the legal, institutional and technical infrastructure of trust that has to sit behind it.
What Is Digital Identity and How Does It Work?
Most conversations about digital identity focus on the credential itself: the physical passport, the ID card, or its digital equivalent stored on a phone. That is only half the picture.
Digital identity is made up of two layers. The first is the credential itself - the document or chip that proves who someone is. The second, less visible layer is the set of attributes attached to that identity, such as a person's name, age or education, along with the trust infrastructure that allows any of that information to be verified by someone else.
Yulia Kravchenko, a digital governance and interoperability researcher at TalTech in Estonia, argues that people tend to overestimate the importance of the credential itself and underestimate everything sitting behind it.
A digital identity wallet, in other words, is not just a container for a document. It is the visible layer of a much larger system of registries, issuers and verifiers that have to agree, technically and legally, on what counts as valid proof. Without that infrastructure behind it, a wallet is just a folder of files that nobody outside the issuing country has any obligation to trust.
Why Is Digital Identity Difficult to Verify Across Borders?
The everyday consequences of this gap are concrete rather than abstract. The guests describe cases of couples travelling to another country simply to get married because proving they were legally free to marry was more complicated in the country where they lived than completing the process somewhere else.
Getting a certificate confirming that no legal proceedings are pending against you can mean collecting the same document from every country where you have lived for more than six months - a process Kravchenko describes from personal experience as "a constant fight with bureaucracy."
A more structural example comes from Ukrainian citizens who relocated to Germany after 2022 and are becoming eligible to apply for German citizenship. Under Germany's current naturalization rules, the standard residency requirement is five years. Iefremov expects a large volume of applications to put additional pressure on German administrative capacity. He argues that processing a large number of such applications could become difficult without better interoperability between Ukrainian registries and those of EU Member States.
This is Iefremov's professional assessment of a potential administrative challenge rather than a confirmed statistic. But it illustrates a broader pattern: practical, high-volume needs are often what push governments to invest in interoperability.
Iefremov also points to a more encouraging case from his own experience. When Kitsoft registered a company in Belgium to launch BelDoc, an online business-registration service, the process benefited from changes to know-your-customer procedures for notaries that allowed standard bank-led verification instead of extensive in-person document processing.
He contrasts this with an earlier, more traditional company-registration process in Germany, which required physical presence, bilingual document readings and the attendance of all shareholders. The comparison illustrates how much cross-border friction can depend on institutional choices rather than technology alone.
What Cross-Border Digital Identity Requires Beyond Technology
A better app is not enough. Building cross-border digital identity that actually works requires several elements to move together: legal alignment between countries, institutional trust between the agencies that issue and verify credentials, common technical standards, independent certification and secure infrastructure for exchanging data.
The European Union's approach illustrates why. Under the European Digital Identity Framework, EU Member States are required to provide EU Digital Identity Wallets. The framework goes far beyond the app itself: common standards, technical specifications and certification requirements are intended to make wallets interoperable and accepted across the EU.
At the level of government-to-government data exchange, the EU has built a separate but related piece of infrastructure: the Once-Only Technical System, or OOTS, established under the Single Digital Gateway Regulation. OOTS enables official evidence needed for cross-border administrative procedures to be exchanged between authorities, with the citizen's permission, rather than requiring people to repeatedly collect and upload the same documents themselves.
Iefremov cites Ukraine's engagement with European digital infrastructure as an example of the level of institutional alignment interoperability requires. Ukraine is working toward deeper integration with EU digital systems, but its relationship with individual frameworks such as OOTS needs to be understood precisely rather than treated as full participation by default.
Ukraine has also made progress in the related field of electronic trust services. The broader lesson is that trust between national digital systems is built layer by layer - through legal alignment, technical compatibility, standards and recognition - rather than granted all at once.
What Types of Credentials Does Digital Identity Include?
Interoperability does not mean treating every credential in the same way.
Iefremov describes a rough hierarchy. Government-issued identity documents sit at the foundation, since other credentials ultimately rely on a verified identity. Above that are controlled credentials such as driver's licenses or diplomas, which may be issued by government bodies or accredited institutions such as universities and can carry legal weight or unlock specific rights.
At the lighter end are short-lived credentials such as event tickets, which can use similar underlying technology but require far less assurance.
Professional and educational credentials raise their own cross-border questions. A digital diploma may be issued and independently verified through the institution that provided it. The harder cases are qualifications that have not been digitized or that a receiving institution in another country has no established way to verify.
Medical records present a different challenge because access may sometimes be needed when the person cannot actively participate. An unconscious patient after an accident cannot unlock a phone-based wallet to share information about allergies or medical history, and emergency responders cannot wait for consent that cannot physically be given.
In situations like this, a wallet-only model is not sufficient. Access to underlying medical systems may also be needed, with clearly defined conditions governing when emergency services can retrieve data outside the standard consent flow.
How Digital Identity Wallets and Government Registries Share Data
One of the central design questions in digital identity is who decides when information about a person can be shared, and under what conditions.
Digital identity wallets are designed around active user control. A person chooses what information to disclose and to whom - whether that means proving their age or verifying their identity when accessing a service.
OOTS works differently but also involves the citizen. It exchanges official evidence between public authorities for cross-border administrative procedures with the user's permission.
A third category sits apart from both. In narrowly defined situations, such as medical emergencies or specific law-enforcement contexts, government registries may need to be accessed outside the standard active-consent flow because waiting for a person's action may be impossible or inappropriate.
Iefremov's broader argument is that different technologies fit different use cases. Wallet-based sharing can work well when individuals actively control disclosure. Evidence-exchange systems such as OOTS serve citizen-initiated administrative procedures. Other exceptional situations require their own access frameworks.
There is no single architecture that solves every identity scenario.
Digital Identity Security: Biometrics, Centralization and Vendor Lock-In
Behind the technical debate sits an institutional question: why do governments often hold onto data rather than share it, even when reuse could make life easier for citizens?
Estonia offers an instructive example. Its long-standing once-only approach allows public authorities to reuse data already available elsewhere in government rather than repeatedly asking citizens to provide the same information.
Drawing on Estonia's experience, Kravchenko suggests that part of the institutional shift came from recognizing that holding duplicate copies of personal data also means taking on the cost and responsibility of protecting them. In her view, once data reuse becomes simpler and less risky than duplication, institutions have a stronger incentive to change.
Centralization introduces a different security concern. Iefremov argues that digital credentials can offer security advantages over physical documents, while warning that highly centralized systems can increase the potential impact of a single breach. Decentralized architectures can limit how much information one compromised node exposes, but governments still need contingency plans for failures elsewhere in the network.
Vendor dependency adds another risk. Iefremov warns against governments relying on a single external provider for identity infrastructure without developing technical capacity of their own. In his view, this kind of lock-in can weaken government control over costs and architecture.
His recommendation is for governments to remain in the lead and deliberately work with multiple vendors rather than defaulting to one. Citizen-facing identity verification, he argues, should remain free, while associated costs can sit with businesses that rely on that verification. Kravchenko explicitly agrees that citizens should not have to pay simply to use their digital identity.
Biometrics create another category of risk. Iefremov's professional assessment is that increasingly sophisticated AI-generated content makes biometric spoofing and credential forgery an evolving concern. Governments also do not fully control the security of the personal devices - phones, cameras and sensors - on which biometric verification often depends.
Kravchenko highlights a fundamental asymmetry: a compromised document or name can be replaced or changed, but a face or fingerprint cannot simply be reissued. In her view, that alone calls for particular caution in how biometric systems are designed and secured.
Surveillance concerns also affect public trust in digital identity. Some citizens associate expanded digital identity infrastructure with greater government monitoring. Kravchenko sees the broader challenge as requiring both technical safeguards and better public understanding of how these systems work, including education on how citizens can protect themselves.
What Governments Need to Build Cross-Border Digital Identity
Systems such as the EU Digital Identity Wallet take years to build because the task is much larger than developing and releasing an app.The surrounding trust infrastructure has to come first: issuers, verifiers, common technical standards and a certification regime robust enough for institutions across multiple countries to rely on it.
Kravchenko argues that moving too quickly can create a harder problem later: fixing foundational identity infrastructure after it is already live. Cross-border digital identity is therefore not a single technology decision. It is a long process of aligning law, institutional trust, technical standards, interoperability and security practices.
There is still a long way to go before digital credentials can be recognized seamlessly across borders. But the direction is clear: making it possible for people's identities, documents and qualifications to be verified across more countries with fewer administrative barriers.
Watch the full Code the State episode
Yulia Kravchenko and Oleksandr Iefremov explore digital identity, interoperability and trust between governments in the Code the State episode "Why Do Governments Keep Forgetting Who You Are?". Watch or listen to the full conversation on Spotify, YouTube or Apple Podcasts.