Written evidence submitted by Andrea Fallon (HAR0561)
Dear Chair and Committee Members,
I write in response to the Committee’s inquiry, Harnessing the Potential of New Forms of Digital ID, to address Question 4: What potential risks does the adoption of new forms of digital identification have for individuals, including risks to privacy and security of personal data?
The proper function of government in a constitutional democracy is to serve the people within clear legal limits. A mandatory digital identification regime does not reflect those limits; it presumes authority over the individual that has no lawful foundation in our constitutional tradition.
The common law does not create rights; it recognises and protects them. Among these is the individual's right to live free from arbitrary surveillance, compulsion, or data harvesting by the state. That right is not subject to revocation by administrative convenience or technological expedience.
In Entick v Carrington (1765) 19 St Tr 1029, the court held that no public authority may interfere with property or privacy without lawful justification rooted in statute or common law. This principle remains binding and was recently reaffirmed by the UK Supreme Court in R (Catt) v Association of Chief Police Officers [2015] UKSC 9, which made clear that the state may not retain data on individuals absent clear legal necessity and proportionality.
Furthermore, in R (Daly) v Secretary of State for the Home Department [2001] UKHL 26, the House of Lords held that any interference with fundamental rights must meet strict tests of necessity and proportionality, even where public policy goals are engaged. That principle was echoed in R (Gillan) v Commissioner of Police of the Metropolis [2006] UKHL 12, where broad discretionary powers to demand personal information were struck down for lacking adequate safeguards.
Any digital ID system that conditions participation in civic life upon constant identity verification fails this test. It reverses the presumption of liberty, subjects the individual to continuous oversight, and reconfigures the state-citizen relationship into one of default suspicion.
The risks are not abstract. Centralised digital ID systems enable population-level surveillance, the automation of access control, and the profiling of behaviours. These systems are vulnerable to misuse — not only by future governments, but by bad actors, insiders, or foreign adversaries.
When such a system becomes a requirement for employment, housing, travel, or access to services, it creates a permanent infrastructure of compliance and exclusion. It fosters dependency on state systems and eliminates the possibility of anonymity in ordinary life — a principle vital to a free society.
Attempts to introduce compulsory identification have consistently failed in Britain — not due to technical limitations, but because they contradict the underlying values of our constitutional order. The repeal of the Identity Cards Act 2006 was not merely political; it was a reaffirmation of the principle that liberty is not licensed by the state.
Digital ID schemes are not neutral tools — they are governance architectures. If made mandatory, they institutionalise suspicion and restructure the balance of power between individual and state. This is not compatible with a lawful society where the state is accountable to the people, not the reverse.
I urge the Committee to recommend that any proposal for a mandatory digital identification system be unequivocally abandoned. The risks are structural, not technical. No amount of oversight can redeem a system that begins with the wrong premise.
Yours faithfully,
July 2025