Digital Identity and Payments as Control Points
Digital identity and electronic payments can improve security and convenience, but excessive concentration can turn them into exclusion points. This article examines voluntariness, interoperability, recovery, appeal, redundancy and real alternatives.
“Platforms and Algorithms of Attention” examined platforms that can shape what we see and where we direct attention. This article takes the next step: what happens when a digital system no longer influences only information but becomes a key to money, services and everyday participation? Digital identity and electronic payments can be highly useful, fast and secure. But precisely because they are becoming everyday infrastructure, they must also be assessed as potential control and exclusion points.
The problem is not that a system sometimes needs to know who we are or that a bank checks a transaction. Without identity proofing, authentication and anti-fraud rules, many services would be less secure. The problem arises when multiple life functions depend on one credential, one provider or one process, and an error or block simultaneously closes access to an account, public service, contract, communication channel or another essential function.
This article therefore does not set up a conflict between “digital” and “analogue”. It asks a more practical question: does a lawful user have real choice, recovery, appeal and fallback paths when an identity-payment system fails or rejects them? Digital sovereignty is not life without verification. It is life without unnecessary dependency on a single revocable point of access.
Digital identity is not the person but evidence in a particular context
We should first separate a person from their digital representation. Digital identity is a set of data, credentials and processes by which a system verifies a particular claim: who we are, how old we are, whether we hold a certain licence or whether we are entitled to a service. No single identifier contains the whole person.
This distinction matters because a poorly designed system quickly begins to demand full identification where a much narrower claim would be sufficient. For an age-restricted purchase, the relevant fact may simply be whether someone is above a threshold; the provider does not necessarily need a name, address and complete identity. A good system therefore asks not only whether something can be verified but how little data needs to be disclosed for that specific purpose.
Modern digital-identity standards therefore separate identity proofing, authentication and federation and emphasise assurance levels appropriate to the risk of the particular transaction. This reduces the temptation to use the strongest identity mechanism for every minor interaction.
In everyday language we often say that someone has “identified themselves” even though a system is performing several different functions. Identity proofing establishes who the person is claimed to be. Authentication verifies that a returning person is legitimately using that credential. Authorisation determines what they may actually do after successful authentication.
Keeping these functions separate is one of the most important safeguards against excessive concentration. The fact that a system has verified identity does not imply that the same system should decide every right, contract and transaction of that person. When all three functions are combined in one centre, a technical error or disputed decision can more easily become total exclusion.
It is therefore better to think in terms of a chain of permissions than one “digital identity” that opens everything. Each step should have its own purpose, proportionate assurance, audit trail and correction path.
When identity and payment converge, a powerful control point appears
A payment is more than moving a number between accounts. In modern life, payment capability is often a condition for rent, transport, communication, online services and many forms of work. If the same identity mechanism determines who we are, whether we may use an account and whether a transaction may proceed, its errors become far more consequential.
Such integration also has legitimate benefits: it can reduce fraud, support strong authentication and simplify processes. But convenience and concentration of risk can grow together. The more one credential becomes a universal key, the more important the rules for issuance, revocation, recovery and alternative access become.
The worst architecture is therefore not necessarily the one with the most technology, but the one in which one incorrect flag or one inaccessible account triggers cascading failure across all other functions. “How Do We Measure Whether Decentralisation Is Real?” would call this real centralisation regardless of how many apps appear on the surface.
Digital identity does not have to mean a central database
Criticising control points does not mean that every digital identity must be centralised or surveillance-oriented. Architectures can allow users to hold credentials in a wallet, disclose only a necessary claim to a service and let multiple providers verify issued credentials interoperably without one database containing every daily action.
The European Digital Identity framework is notable because its legal design requires user control, selective disclosure, interoperability and the possibility of pseudonyms where full legal identity is not required. It also provides that use of the European wallet is not compulsory and that appropriate alternatives must remain available for people who do not choose it.
That does not prove every implementation will be flawless. It does show why we should distinguish digital identity as a technology from centralised identity architecture as a design choice. Security, privacy and decentralisation are properties of design, not automatic properties of the word “digital”.
A digital identity may be voluntary on paper yet become nearly mandatory in practice if a person cannot access a bank, public service, hiring process or contract in reasonable time without it. A formal possibility of refusal is not the same as a real possibility of living without the system.
That is why the European wallet rules explicitly require alternative solutions and prohibit indirectly restricting access merely because a person has not chosen the wallet. This matters more than the word “voluntary” by itself: the alternative must be accessible, timely and practically usable.
The same principle applies more broadly. Whenever an essential service is digitised, we should ask what happens to a person without a suitable phone or connection, a person with a disability, someone who has lost a device or someone whose account has been incorrectly blocked. A system is inclusive only when its fallback works for people outside the ideal user scenario.
Disclose only what is necessary
Identity sovereignty is not measured only by who stores data. It is also measured by how much a user must disclose for each action. If proving one attribute always requires handing over a complete profile, the system creates unnecessary linkability across different areas of life.
Selective disclosure and pseudonyms are therefore important safeguards. European wallet rules provide for disclosure of only necessary attributes and the use of pseudonyms where legal identity is not required. This reduces the amount of information a service receives merely because it had to verify something.
The practical rule is simple: the proof should be as narrow as the purpose allows. A system that needs to know “over 18” does not automatically need a date of birth; a system that must verify eligibility for one service does not automatically need a history of unrelated services.
A payment account is infrastructure for participation
A payment account is so ordinary in modern economies that it is easy to treat it as just another commercial product. In reality it is often basic infrastructure for receiving wages, paying bills and rent, shopping online and using many public or private services. Losing access to the payment system can therefore cause much wider social exclusion.
The EU Payment Accounts Directive reflects this by giving consumers in the EU a right to a basic payment account regardless of residence or financial situation and by making it easier to switch banks. This does not create an absolute right to every account at every provider, but it expresses an important principle: basic access to payments is not an ordinary luxury service.
“Money, Credit, and Debt: Who Creates Purchasing Power and Under What Conditions?” showed how money and credit create important dependencies. This article adds the digital layer: it is not enough to ask who issues money or extends credit; we must also ask through which gates a person can actually reach their own money.
Risk management must not become automatic exclusion
Banks and other financial providers have legitimate obligations concerning fraud, money laundering, sanctions and other risks. This article therefore does not argue that every transaction must always be permitted or that providers should ignore legal obligations. The problem is blanket exclusion, in which entire categories of users are rejected without an individual and proportionate assessment.
The European Banking Authority has warned that unwarranted de-risking can deny legitimate customers access to financial services and particularly harm vulnerable groups. This illustrates the difference between managing risk and transferring administrative convenience onto the user in the form of complete exclusion.
A better safeguard is therefore not the absence of checks but an explainable decision, proportionality, an opportunity to supply missing information and an effective appeal process. If a system can exclude a person in seconds but requires months to correct an obvious mistake, the asymmetry of power is built into the process itself.
A single point of failure is not only a technical problem
When we think about payment resilience, we often imagine a server, network or electricity outage. Those risks matter, but a single point of failure can also be institutional: one authentication provider, one registry, one mobile operating system, one account-recovery process or one organisation without which the user cannot prove entitlement.
International standards for financial market infrastructures therefore require business-continuity planning, management of interdependencies and the ability to recover from major disruptions. The EU’s DORA similarly focuses on the operational resilience of the financial sector and the management of information and communications technology risk.
Technical redundancy alone is not enough. Two data centres run by the same provider do not create user independence if both lead to the same administrative switch that can block access. Real resilience combines technical redundancy and multiple paths for decision, recovery and access.
For essential functions it is healthy to preserve different channels. That can mean multiple providers, interoperable standards, portability of accounts or credentials, an offline mode for limited functions, a fallback identity-proofing procedure and at least one payment path that does not depend on the same network and device.
Cash is an important example of a functionally different path. The ECB emphasises that cash does not require internet access or electricity to make a payment, supports privacy and includes people with limited access to digital payments. That is why it can operate as a fallback during disruption rather than as a technological opponent of digital payments.
The objective is not for everyone to use every method all the time. It is that the failure of one method should not mean the failure of social participation. A system is more resilient when it has heterogeneous fallbacks rather than several copies of the same technology.
Interoperability, recovery and appeal determine real sovereignty
The best identity or payment service is not necessarily the one with the largest feature list but the one from which a person can safely exit and into which they can recover after an error. Interoperability reduces dependency on one provider; standardised exchange of credentials or payment data lowers switching costs; a clear recovery process prevents loss of a device from becoming loss of one’s digital life.
Technical recovery must be matched by institutional recovery. Who corrects an incorrect attribute? Who reviews an unjustified account closure? Who can restore access when an automated process makes a mistake? Which independent body can decide a dispute? Without answers, user “control” is mostly an aesthetic property of the interface.
The World Bank’s ID4D principles therefore pair interoperability with inclusion, privacy, clear institutional mandates, accountability and mechanisms for correction. Sovereignty becomes measurable by how much effective power the user has when something goes wrong.
Before treating an identity or payment system as neutral infrastructure, we can ask twelve questions: 1. Is use mandatory or is there a real alternative? 2. Is only the necessary attribute verified? 3. Are identification and authorisation separated? 4. Can the user employ a pseudonym when full identity is unnecessary? 5. Can they switch provider without losing essential functions? 6. Is there a fallback if the device is lost?
Then: 7. Does failure of one provider stop everything? 8. Is there an offline or otherwise functionally independent payment path? 9. Is a block explained? 10. Is there a rapid route to correct false data and unjustified exclusion? 11. Are identity and payment data used only for clearly defined purposes? 12. Who oversees the organisation that can revoke the credential or account?
If a system answers most of these questions well, digital identity can support greater usability and greater user control. But if one decision simultaneously determines identity, access to money and practical participation, it becomes an unusually strong point of authority. “Artificial Intelligence: Tool, Adviser or New Authority?” will continue at the next boundary: what happens when these systems are no longer operated only by people under explicit rules, but artificial intelligence begins to participate in assessment and decision-making — as a tool, adviser or new authority?
Sources and further reading
- European Union. Regulation (EU) 2024/1183 establishing the European Digital Identity Framework — wallet control, selective disclosure, interoperability, pseudonyms and alternative access.
- European Commission. Q&A — European Digital Identity: voluntary use, wallet acceptance and examples of public/private services.
- European Union. Commission Implementing Regulation (EU) 2024/2979 — wallet relying-party registration, pseudonyms and data-request limits.
- European Commission. Technical standards for cross-border European Digital Identity Wallets — common specifications and interoperability.
- NIST. SP 800-63-4 Digital Identity Guidelines — identity proofing, authentication, federation, risk and assurance.
- World Bank ID4D. Principles on Identification for Sustainable Development — inclusion, interoperability, privacy, user control and accountability.
- European Commission. Access to bank accounts — Payment Accounts Directive and the right to a basic payment account in the EU.
- European Banking Authority. Guidelines on policies and controls for effective ML/TF risk management when providing access to financial services — safeguards against unwarranted de-risking.
- European Central Bank. The role of cash — autonomy, privacy, inclusion and payment capability without internet or electricity.
- CPMI-IOSCO / Bank for International Settlements. Principles for Financial Market Infrastructures — operational risk, continuity and interdependency management.
- European Union. Digital Operational Resilience Act (DORA) — ICT and operational resilience requirements for the financial sector.
- European Union. Regulation (EU) 2024/886 on instant credit transfers — verification of payee and modern payment-service safeguards.