Identity is often discussed as a single topic, but it's worth pulling it apart from the data exchange component, where the two have recently become muddled together.
In terms of identity itself, self-sovereign identity (SSI) and traditional public key infrastructure (PKI) based offerings are, for the most part, on the same page. Both put control in the hands of the user, differing mostly in how trust is established, its levels, and where it comes from. This post focuses on data exchange, where both SSI and PKI place much of the responsibility for privacy.
How is data stored in SSI model?
The data side of SSI mainly comes down to these three questions:
- Who stores it?
- How is it stored and shared?
- Who shares it?
With SSI, the underlying assumption is that end-users store their own data, either on their phone or in a cloud service. But issuers must also retain the data they created, so we immediately end up with data stored in two places, effectively doubling the attack surface.
If end-users are responsible for storing their own data, the only realistic approach is to consolidate it in a single location, which is exactly what makes it a goldmine for identity thieves. We're now forcing individual data to centralize on a single device, whereas it was previously fragmented across many issuer databases and far less useful to an attacker. Once we start sharing portions of that data with third parties, it exists in a third location, but the weakest link remains the end-user's device, where everything about them has been consolidated in one place.
The average end-user simply isn't equipped to defend their data against malicious actors who steal identities professionally. Privacy and control are worthwhile goals, but we can't pursue them at the expense of security, not when the data in question is what people rely on to function in society.
Data exchange in SSI
If we're to consider SSI in a society, we need to look at how data sharing works. The core idea is that end-users can share their data without relying on the issuer beyond the initial issuance.
Take the example below, where an individual wants to share their clean bill of health status with an insurance provider. This need only be a "yes" or "no" response, but it must come from a trusted source, most likely a health registry or the specific doctor or hospital that carried out the assessment. Once the end-user receives the data from the issuer, they can share it whenever and with whomever they like, with no further interaction required from the issuer.
For the receiver to trust this data attribute, the issuer must "sign" it in a way that lets the receiver verify who issued it and confirm it hasn't been altered. This signature is then sent to a register of some kind, which the receiver can easily check.

This is relatively straightforward, though it doesn't address how each party knows who the other is in a trusted manner. The verification register is also a new piece of infrastructure that must be implemented, integrated, and managed by a trusted entity. If that entity chooses to use a blockchain, it would need a costly, managed one. Still, the core challenge remains data storage.
The verification register is effectively functioning as an OCSP (Online Certificate Status Protocol), letting parties confirm whether a digital signature was valid at the time of signing. Today, sharing verified documents is already done by digitally signing a container with the document inside. Any modification in transit is easily detected, since it would alter the hash of the signed data. All of this can be achieved with traditional PKI-based digital identity, which has been running for decades using trust service providers (TSPs) and a secure data exchange layer, such as those in Estonia, Ukraine, Namibia, Greenland, and Benin.
Data Exchange with PKI
From a high level, trusted and secure data exchange can look like the flow chart below. Rather than the end-user storing all their data, they give consent to third parties to access that data from the source. Immediately, we remove a major weak point, while keeping the most sensitive data types split between issuers by using the once only rule among government agencies, where they cannot request data available via any other government agency.

The data issuers can be public or private organisations integrated with the data exchange platform. The key is that they are the sources of the data they hold, meaning what they share is both up-to-date and inherently verified simply by virtue of coming from the source. A breach at any single data source would only expose the specific type of data that source holds, which isn't enough to steal an entire identity, and offers little benefit to an attacker if PKI-based digital identity is in use.
Receivers establish peer-to-peer agreements with the data sources they need to interact with, and with permission, can access relevant data on their citizens or customers in real time, efficiently and securely. This way, no data travels over the open internet, and all data access is tracked and made visible to the individual it concerns, creating transparency and trust.
Privacy vs security
It can't be denied that this model involves some trade-off in privacy and control, since we rely on the issuer each time we want to grant access to our data, and the issuer, in turn, knows who is accessing it.
But the model doesn't force this approach. When an end-user would prefer the issuer not know who the data is being shared with, they can simply retrieve the data themselves, receive a digitally signed attribute, and share it with whomever they please, privacy intact. In fact, this is where we align with SSI operating as intended, accepting some trade-off in convenience and security, both in requiring the end-user to store that data and in sharing it over the open web.
What is worth noting about this model is that it is not new. It is how the X-Road in Estonia functions, and how it has been effectively functioning for about twenty years. It's also how the X-Road and Cybernetica’s Unified Exchange Platform (the product version of the X-Road) are functioning in many countries around the world today. It's trusted because issuers and receivers know who each other are and hold direct agreements with one another, because data access tracking provides transparency, and because consent management gives end-users control.
This model doesn't merely avoid harming equity and inclusion. It actively embodies it, while also offering proven interoperability, both locally and internationally. This is demonstrated by Estonia and Finland enabling cross-border data exchange and identity recognition.
We achieve decentralisation through peer-to-peer data exchange, with data attribute types split across issuers, so there's no need to centralise an individual's entire set of identity attributes in a single, insecure place like their smartphone. Instead, the model delivers control, usability, accessibility, genuine and realistic security, verifiability, authenticity, transparency, and convenience, all built on tried and tested technologies like secure data exchange and PKI-based digital identity.
Different problems need different identity solutions
Much of the point I'm looking to make here is that SSI isn't presenting us with something new, but rather something not particularly well-suited to government-run societies. It's pushing for new technologies and processes that are relatively untried and untested, aimed at replacing social media-based login services tied to unverified and untrusted internet identities.
Estonia draws a lot of attention here, having run digital government services for 20 years without standing still in terms of innovation. The lessons Estonia has learned are there for the taking, with local companies offering to share the technologies and ways of working that make Estonia what it is, and to customise them to fit other governments
It's well understood that no two governments operate the same way, so what Estonia has built isn't shared as a fixed set of principles that may or may not align with a given country's culture and legal landscape. Instead, it's offered in a customisable form, backed by analysis, consultation, and advice on how best to integrate such services into a particular government's existing ways of working.
At its core, SSI pushes positive ideas and principles, like end-user control, interoperability, and data privacy. That's a good thing, but as a package, it simply isn't appropriate for governments.
What it does seem well-suited for is interacting online with businesses and services that don't need to know who we are. It's valuable for reducing the risk of correlation, the risk of being tracked across the web so our data can be monetized and sold. It's valuable for the times we'd prefer to act privately. But when it comes to banking, an industry bound by AML and KYC regulations, or to limiting fraud in areas like welfare, insurance, tax, or healthcare, our true identity is something that must be beyond doubt.
I'm not saying PKI is perfect, and I'm not saying what Estonia has built is flawless. But when it comes to fraud, identity theft, and ease of government interaction, I know of nothing better. We have an excellent foundation for governments, one that's well-regulated, tried, and tested. Let's build on it.
Written by Maximiliaan van de Poll