Why Do Governments Keep Forgetting Who You Are? The Cross-Border Digital Identity Problem
- Aug 26
- 7 min read
Updated: Aug 28
Lose your documents in your home country and there is usually a clear path to replacing them. Abroad, even a routine procedure can become significantly more complicated. A bank in another country may require additional proof of identity, while some administrative procedures can mean obtaining documents from several countries where you previously lived. What was straightforward at home can become a bureaucratic project once a border is involved.
The problem is not that a person somehow loses their identity abroad. It is that the systems designed to confirm identity — and verify the documents, qualifications and records connected to it — were largely built within national borders. Once a person crosses a border, verifying that information can become slower and more dependent on manual processes.
This is the real challenge of cross-border digital identity. Identity documents do not simply become invalid abroad, but recognizing and verifying them — and accessing the information behind them — becomes significantly harder. Solving that requires looking beyond a single wallet app to the legal, institutional and technical infrastructure of trust that has to sit behind it.
This is the challenge explored in Code the State by Yulia Kravchenko, a digital governance and interoperability researcher at TalTech in Estonia, and Oleksandr Iefremov, CEO of Ukrainian GovTech company Kitsoft: why digital identity still does not work seamlessly across borders and what it takes to build the infrastructure of trust between countries.
What Is Digital Identity and How Does It Work?
Most conversations about digital identity focus on the credential itself: the physical passport, the ID card, or its digital equivalent stored on a phone. That is only half the picture.
Digital identity is made up of two layers. The first is the credential itself — the document or chip that proves who someone is. The second, less visible layer is the set of attributes attached to that identity, such as a person's name, age or education, along with the trust infrastructure that allows any of that information to be verified by someone else.
Kravchenko argues that people tend to overestimate the importance of the credential itself and underestimate everything sitting behind it.
A digital identity wallet, in other words, is not just a container for a document. It is the visible layer of a much larger system of registries, issuers and verifiers that have to agree, technically and legally, on what counts as valid proof. Without that infrastructure behind it, a wallet is just a folder of files that nobody outside the issuing country has any obligation to trust.
Why Is Digital Identity Difficult to Verify Across Borders?
The everyday consequences of this gap are concrete rather than abstract. The guests describe cases of couples travelling to another country simply to get married because proving they were legally free to marry was more complicated in the country where they lived than completing the process somewhere else.
Getting a certificate confirming that no legal proceedings are pending against you can mean collecting the same document from every country where you have lived for more than six months — a process Kravchenko describes from personal experience as "a constant fight with bureaucracy."
Another example concerns Ukrainian citizens who relocated to Germany after 2022 and are becoming eligible to apply for German citizenship. Under Germany's current naturalization rules, the standard residency requirement is five years. Iefremov expects a large volume of applications to put additional pressure on German administrative capacity. He argues that processing a large number of such applications could become difficult without better interoperability between Ukrainian registries and those of EU Member States.
Iefremov also points to an example from his own experience. When Kitsoft registered a company in Belgium to launch BelDoc, an online business-registration service, the process benefited from changes to know-your-customer procedures for notaries that allowed standard bank-led verification instead of extensive in-person document processing.
He contrasts this with an earlier company-registration process in Germany, which required physical presence, bilingual document readings and the attendance of all shareholders.
What Cross-Border Digital Identity Requires Beyond Technology
A better app is not enough. Building cross-border digital identity that actually works requires legal alignment between countries, institutional trust between the agencies that issue and verify credentials, common technical standards and certification.
Kravchenko describes the EU's approach through the updated eIDAS regulation and the European Digital Identity Wallet. She explains that Member States are required to have a wallet, but the infrastructure behind it is just as important as the application itself.
Building this infrastructure involves trusted issuers and verifiers, common standards, certification and ensuring interoperability between Member States. Kravchenko emphasizes that countries need to operate according to the same standards so that a credential issued in one country can be accepted in another.
At the level of government-to-government data exchange, Iefremov points to the Once-Only Technical System, or OOTS, as an initiative intended to enable interoperability between countries. He says Ukraine has also joined the initiative.
Kravchenko also points to Ukraine's inclusion in the EU trust service list as an important step toward interoperability.
What Types of Credentials Does Digital Identity Include?
Interoperability does not mean treating every credential in the same way.
Iefremov describes a rough hierarchy. Government-issued identity documents sit at the foundation, since other credentials ultimately rely on a verified identity. Above that are controlled credentials such as driver's licenses or diplomas, which may be issued by government bodies or accredited institutions such as universities and can carry legal weight or unlock specific rights.
At the lighter end are short-lived credentials such as event tickets, which can use similar underlying technology but require far less assurance.
Professional and educational credentials raise their own cross-border questions. A digital diploma may be issued and independently verified through the institution that provided it. The harder cases are qualifications that have not been digitized or that a receiving institution in another country has no established way to verify.
Medical records present a different challenge because access may sometimes be needed when the person cannot actively participate. An unconscious patient after an accident cannot unlock a phone-based wallet to share information about allergies or medical history, and emergency responders cannot wait for consent that cannot physically be given.
In situations like this, a wallet-only model is not sufficient. Access to underlying medical systems may also be needed when emergency services have to retrieve data outside the standard consent flow.
How Digital Identity Wallets and Government Registries Share Data
One of the central design questions in digital identity is who decides when information about a person can be shared, and under what conditions.
Digital identity wallets are designed around active user control. A person chooses what information to disclose and to whom — whether that means proving their age or verifying their identity when accessing a service.
Other scenarios work differently. In situations such as medical emergencies or access to criminal records, data may need to be retrieved without the person's active consent.
Iefremov's broader argument is that different technologies fit different use cases. Wallet-based sharing can work when individuals actively control disclosure. Systems such as OOTS can serve other interoperability scenarios.
There is no single established rule for which technology should be used in every scenario — a point Iefremov explicitly makes in the conversation.
Digital Identity Security: Biometrics, Centralization and Vendor Lock-In
Behind the technical debate sits an institutional question: why do governments often hold onto data rather than share it?
Drawing on Estonia's experience, Kravchenko describes how institutions came to recognize that keeping their own copies of data also meant taking responsibility for maintaining and protecting those copies. Once existing data could instead be reused through an interoperability layer, institutions had less reason to maintain duplicate datasets.
Centralization introduces a different security concern. Iefremov argues that digital credentials can offer security advantages over physical documents, while warning about the risks of centralized infrastructure. He sees decentralization as a more stable approach, while also emphasizing the need to consider what happens if one node is compromised.
Vendor dependency adds another risk. Iefremov warns against governments relying on a single external provider for identity infrastructure without developing technical capacity of their own. His recommendation is for governments to remain in the lead and work with multiple vendors rather than relying on one.
Citizen-facing identity verification, he argues, should remain free, while businesses can pay for verification services. Kravchenko explicitly agrees that citizens should not have to pay to use their digital identity.
Biometrics create another category of risk. Iefremov argues that AI can be used to create fake credentials and bypass biometric checks. He also points to the difficulty governments face when verification depends on external devices they do not control.
Kravchenko highlights a fundamental asymmetry: you can replace a document or change your name, but you cannot replace your face or fingerprints. She says this is something everyone needs to keep in mind when thinking about biometrics.
Surveillance is another concern discussed in the conversation. Kravchenko says democratic governments need to take precautions and implement cybersecurity measures. She also stresses the importance of educating citizens about how digital identity works and how they can protect themselves, noting that the human factor remains important even when security measures are in place.
What Governments Need to Build Cross-Border Digital Identity
Systems such as the EU Digital Identity Wallet take years to build because the task is much larger than developing and releasing an app.
The infrastructure behind the wallet includes issuers, verifiers, common technical standards and certification. These elements need to work together across Member States to make credentials interoperable.
Kravchenko argues that this step-by-step process is necessary because fixing the infrastructure after it has already been deployed can be significantly harder.
Cross-border digital identity therefore depends on more than the technology citizens see on their phones. It requires countries to make their systems interoperable and establish the standards and trust needed to recognize credentials issued elsewhere.
There is still a long way to go before digital credentials can be recognized seamlessly across borders. But the goal is to make it possible for people's identities, documents and qualifications to be verified across countries with fewer administrative barriers.
Watch the full Code the State episode
Yulia Kravchenko and Oleksandr Iefremov explore digital identity, interoperability and trust between governments in the Code the State episode "Why Do Governments Keep Forgetting Who You Are?". Watch or listen to the full conversation on Spotify, YouTube or Apple Podcasts.


