Civic Engagement Platform

An official website of the OECD.
Created by the Public Governance Directorate This website was created by the OECD Observatory of Public Sector Innovation (OPSI) and Observatory of Civic Space, both within the Public Governance Directorate (GOV).
How to validate authenticity Validation that this is an official OECD website can be found on the Civic Space page of the corporate OECD website.
Go back

Draft Recommendation on the Governance of Digital Identity

More information and context

Commments for version

updated at 21 Mar 2023
  How I can comment this document?
Comments about
II. 4. Encourage the development of digital identity solutions that empower users to easily and securely control what attributes and credentials they share, when, and with whom.

Comments (4)


You must sign in or sign up to leave a comment.
  • Risa Arai

    This is problematic when it comes to the digital legal identity issued by the government. We can say that 'For the digital version of national ID solutions, users can easily see how their personal data was accessed, changed, deleted' but users should not be able to control and change them without judicial processes.

    1 vote  |  I agree 1 I disagree 0
    No responses
    • Philip Sheldrake

      One can argue for this as necessary, but it is insufficient. As it stands, in smacks of the neoliberal fallacy of individual choice and control. Appropriate governance must include constant attention to the emergent (unintended) consequences of user behaviour, including those arising from expected behaviour.

      • Eduardo Chongkan

        "As it stands, in smacks of the neoliberal fallacy of individual choice and control." -- I think I understand what you mean here. I have some points of view that I believe are related.
        A) eSignature and Legal liabilities: If we allow to sign legally binding contracts with biometrics or without an attorney present, I am sure we will be seeing fraud beyond what we have now. Imagine someone getting a phishing link and signing something with a click.. The only solution I though of was to offer multi-sig transactions and require legally biding signatures to be done with multi-sign only.
        B) I had imagined a platform that acted as Data Agent, the user would onboard there and his/her data would be stored encrypted with something like https://www.skyflow.com/ (Data privacy and security, on cloud or premise) This resolves most of my Security and Infrastructure efforts and costs.

        No votes  |  I agree 0 I disagree 0
        No responses
        • Eduardo Chongkan

          C) Every-time a company or supervised entity needs to read the users KYC data, The request gets logged, the user gets a push on the phone to allow or deny access to X or Y data from Z Entity. (This flow is also considered in the W3C forum) OR..

          C.1) I wanted to have the user assign the platform as data agent in his behalf, and charge the requester a fee for access, then pay the user for using his data, so that users will be more willing to have the data up to date and present any challenged proof in order to continue to get paid passively for the usage of his data.

          No votes  |  I agree 0 I disagree 0
          No responses