Unique identifiers and digital identity

Personal identifiers are useful, if not unavoidable, for digital societies to function. A wide array of public services rests on the premise of identifying and authenticating citizens, and in many cases, the quality of that process determines the quality of the service itself.

There are 195 recognized countries in the world today, and according to the data we have collected, roughly half of them have implemented some kind of unique identifier for their citizens, residents, visitors, or (why not) e-residents.

The names for these identifiers vary. Depending on the country, this attribute may be called a Personal Identification Number, Citizen Number, Resident Registration Number, or simply a Taxation ID.

In this article, we take a brief look at the essence of personal identifiers and the history behind them.

A brief history of personal identifiers

The history of personal identifiers can be divided into three waves.

Denmark was an important player in the first wave, starting the practice as early as 1924. Records were initially kept on paper cards, but between 1968 and 1972 the Danish registry was computerised and became "complete," with every inhabitant included from that point on. Sweden began issuing unique identifiers to its population in 1947.

The second wave began around 1980. SFR Yugoslavia introduced its JMBG in 1977, and many Eastern Bloc countries followed suit throughout the 1980s. Estonia introduced its unique personal identifier in 1989.

We are now in the midst of a third wave, occurring largely outside of Europe. The central question of this third wave is whether personal identifiers should be private or not. Up until this point, they mostly were not, with birthdays and genders often encoded directly into the identifier. This falls short of today's privacy standards.

Some countries have since moved toward more private, randomised identifiers (Latvia, for instance, from 2017). Still, there's little sign that older, more revealing identifiers will be phased out quickly, since doing so would compromise the principle of uniqueness.

One hypothesis worth noting: in small countries like Estonia, privacy may have natural limits, since people can often be identified simply through their social connections and personal appearance.

How personal ID numbers are structured

Countries vary widely in how they format their identifiers. Most fall somewhere between 8 and 14 digits, though San Marino uses a five-digit SSN, while China, Iraq, and Mexico each use 18 symbols.

Mexico takes a distinctive approach, deriving part of the identifier from the first letters of a person's name, with a special catalogue in place to filter out any inadvertently inappropriate combinations. Ukraine is the only country known to allow citizens to opt out of identification on religious grounds. Some countries, including Switzerland and the United Arab Emirates, encode their ISO 3166-1 country code into the identifier to better support international use.

Privacy risks of national identification numbers

The most important question surrounding any personal identifier is what risks it carries.

In 1991, Hungary's Constitutional Court ruled that a "general, uniform personal identification code [...] is unconstitutional." The reasoning centered on the lack of protection for citizens against officials who might misuse their data.

That data asymmetry between state and citizen was very real in the 1990s, but technology has since matured. Estonia's Personal Data Usage Monitor, built on the X-Road, gives citizens a comprehensive view of how the government has used their personal data.

Perceived risk varies by culture, tradition, and national history. Countries such as Germany, the UK, the US, Portugal, Hungary, Australia, and Singapore all place legal limits on "general, uniform personal identification codes." Yet, modern life is difficult to imagine without some form of digital identifier, given how many services now depend on it.

Some privacy-conscious countries, Germany and Austria among them, have developed clever cryptographic schemes to further anonymise individuals. Most, however, have simply found a legal workaround: identifiers that are neither fully "generic" nor fully "public," such as a Taxation ID.

Should personal identification numbers be public or private?

This brings us to an important question:

Should a personal identifier be public, secret, or something in between?

People often instinctively fear public identifiers for the same reason they fear exposed passwords – the worry that they could be intercepted and used for identity theft.

In practice, this intuition is misleading. Once an identifier becomes public, it can no longer be used for authentication. Public identifiers are safe precisely because well-designed systems don't grant any advantage to someone who merely knows the identifier. Modern systems are expected to require actual authentication, ideally backed by 2FA. The perceived risk disappears once identifiers become public and stop being used to authenticate.

This decision, public or secret, has to be made long before a system is designed. Reversing it later can undermine the entire architecture of the data exchange system. As with any complex system, it comes down to building the right foundation from the start.

Written by Anto Veldre