Gov.UK Verify, the new Electronic Identity (eID) Management system of the UK Government, has been promoted as a state-of-the-art privacy-preserving system, designed around demands for better privacy and control, and is the first elD system in which the government delegates the provision of identity to competing private third parties. Under the EU eIDAS, Member States can allow their citizens to transact with foreign services by notifying their national elD systems. Once a system is notified, all other Member States are obligated to incorporate it into their electronic identification procedures. The paper offers a discussion of Gov.UK Verify's compliance with eIDAS as well as Gov.UK Verify's potential legal equivalence to EU systems under eIDAS as a third-country legal framework after Brexit. To this end it examines the requirements set forth by eIDAS for national eID systems, classifies these requirements in relation to their ratio legis and organises them into five sets. The paper proposes a more thorough framework than the current regime to decide on legal equivalence and attempts a first application in the case of Gov.UK Verify. It then assesses Gov.UK Verify's compliance against the aforementioned set of requirements and the impact of the system's design on privacy and data protection. The article contributes to relevant literature of privacy-preserving eID management by offering policy and technical recommendations for compliance with the new Regulation and an evaluation of interoperability under eIDAS between systems of different architecture. It is also, to our knowledge, the first exploration of the future of eID management in the UK after a potential exit from the European Union.
Article navigation
19 July 2017
Research Article|
December 07 2017
Identity Assurance in the UK: technical implementation and legal implications under eIDAS
Niko Tsakalakis
;
Niko Tsakalakis
Web and Internet Science, University of
Southampton
Search for other works by this author on:
Sophie Stalla-Bourdillon;
Sophie Stalla-Bourdillon
Institute for Law and the Web, University
of Southampton
Search for other works by this author on:
Kieron O’Hara
Kieron O’Hara
Web and Internet Science, University of
Southampton
Search for other works by this author on:
Online ISSN: 2332-4031
Print ISSN: 2332-4031
© 2017 N. Tsakalakis, S. Stalla-Bourdillon, and K.
O’Hara
2017
N. Tsakalakis, S. Stalla-Bourdillon, and K.
O’Hara
Licensed re-use rights only
The Journal of Web Science (2017) 3 (1): 32–46.
Citation
Tsakalakis N, Stalla-Bourdillon S, O’Hara K (2017), "Identity Assurance in the UK: technical implementation and legal implications under eIDAS". The Journal of Web Science, Vol. 3 No. 1 pp. 32–46, doi: https://doi.org/10.1561/106.00000010
Download citation file:
Suggested Reading
An empirical analysis of the purchaser‐provider relationship in the NHS internal market
J Manag Med (March,2000)
Speak more or less: how firms adjust environmental information disclosure to performance feedback
Chinese Management Studies (March,2025)
Challenges of introducing a professional eID card within health care
Transforming Government: People, Process and Policy (March,2016)
Constructing identities – professional use of eID in public organisations
Transforming Government: People, Process and Policy (May,2015)
RFID Tags and the European Union: Really free internal distribution?
Journal of International Trade Law and Policy (May,2005)
Related Chapters
Brexit as a Breeding Ground for Problem-Based Learning
Teaching the EU: Fostering Knowledge and Understanding in the Brexit Age
Crossing the Race Line: “No Polish, No Blacks, No Dogs” in Brexit Britain? or, the Great British Brexit Swindle
Europe's Malaise: The Long View
Identity and Citizenship: The Search for a Supranational Social Contract
Political Identification in Europe: Community in Crisis?
Recommended for you
These recommendations are informed by your reading behaviors and indicated interests.
