64410304 advancements in facial recognition technology for secure identification

Scotland’s Digital ID: ScotAccount Uses Experian, Cifas and Biometric Checks

The Scottish Government opposes a mandatory UK digital identity scheme. At the same time, Scotland already operates its own reusable digital identity service. For people asked to verify who they are, a passport can be only one part of a wider chain involving Experian credit-record checks, Cifas fraud screening, biometric facial comparison, cloud infrastructure and a unique identifier designed to work across public services.

Scotland does not need to wait for a future UK digital identity programme to discover what a government digital ID looks like. One is now operating.

ScotAccount’s own terms describe it as the name for the “individual digital identity services provided by the Scottish Government”. The Scottish Government says the system allows people to sign in to multiple public services, verify their identity and, if they choose, save verified information such as their name, date of birth and address so that it can be reused when another participating service needs it.

Modern Scot previously examined the system in ScotAccount Brings Digital Identity Into Scotland’s Property Ownership System, when the same identity layer began appearing inside another part of Scotland’s public infrastructure. The Government’s newer documents, privacy notices, contracts and freedom-of-information responses now allow a clearer examination of what sits behind that account.

The question is not whether ScotAccount is a digital ID. The Scottish Government’s own documentation answers that question. The issue is what happens when a citizen uses that identity to enter a public service, who participates in establishing that identity, what information is checked beyond an official document, how long parts of the resulting data trail remain, and how the system is intended to expand across government.

A passport is not necessarily the end of the identity check

ScotAccount allows identity verification using an official document such as a passport, but the document is not necessarily the only source against which the person is checked.

The current ScotAccount privacy notice says that all users who are required to verify their identity are also subject to separate activity-history and fraud checks.

For an official-document route, ScotAccount uses Experian and Experian’s subcontractor Mitek. The process can involve a photograph of the identity document and a photograph of the user. Mitek is used for document checks and for biometric “likeness” and “liveness” checks intended to establish that the document is genuine, that a real person is present and that the person matches the photograph on the document.

ScotAccount may also send a person’s name, date of birth and passport number to HM Passport Office so that the passport can be checked against government records. HM Passport Office returns the result of that check.

Those are recognisable identity-verification steps. A passport is being checked against the authority that issued it and the person presenting it is being compared with the photograph it carries.

But ScotAccount then performs an additional check through Experian.

The privacy notice calls this an “activity history check”. Experian conducts a soft search of the person’s credit record to determine whether the identity has existed over time. ScotAccount says Experian uses information from sources including the electoral register and financial institutions and checks whether the information supplied by the person matches those sources.

The Scottish Government says it does not receive the underlying credit information. Experian returns a pass or fail result. The search does not affect the person’s credit score.

That boundary is important. ScotAccount is not receiving a citizen’s bank transactions, and using ScotAccount does not mean a bank account is being connected to the Scottish Government.

It does mean that, for a person required to verify their identity, the verification process can extend beyond a state-issued passport and into records held by a commercial credit-reference agency, including records derived from financial institutions.

When identity is proved through questions, financial history moves closer to the centre

ScotAccount also offers a route for people who do not have suitable photographic identification or cannot use the photographic process.

That route uses knowledge-based verification. A person can be asked questions drawn from information about their bank accounts, mortgages, loans, credit cards or other personal history. ScotAccount sends the person’s name, date of birth and address to Experian, which generates the questions from information it already holds. The answers are returned to Experian for checking.

Again, the Scottish Government says it does not see the person’s underlying financial records, transactions, questions or answers. It receives a pass or fail outcome.

Experian occupies a different legal position during this part of the process. For document verification it can act as a processor operating under Scottish Government instructions. For the knowledge-based verification and activity-history checks, the current privacy notice describes Experian as an independent data controller. It can retain some information for fraud and error prevention and to meet its own legal and regulatory requirements.

The public-facing transaction may look like one government identity check while, behind it, different organisations are processing different parts of the evidence under different legal roles.

Cifas adds a separate fraud database

Experian is not the only external organisation involved.

ScotAccount also checks identifying information against Cifas, the UK fraud-prevention service. According to the Scottish Government’s privacy notice, the purpose is to determine whether an identity is at higher-than-usual risk of fraud, has been stolen or misused, or appears to be synthetic.

Cifas sends ScotAccount a result stating whether fraud is known or suspected in connection with the identity and can provide details of associated fraudulent activity.

This is separate from checking whether a passport is genuine. It is a second question: not simply whether the document is valid, but whether the identity appears in information used for fraud prevention.

ScotAccount’s legal basis for managing accounts, verifying identity and conducting fraud monitoring is not consent. The Scottish Government says the processing is necessary for a task carried out in the public interest under Article 6(1)(e) of UK GDPR. It relies on substantial-public-interest provisions for biometric processing connected with identity checking and fraud prevention.

Consent enters at a different stage. Users can choose whether to save their successfully verified information in ScotAccount so that it can be reused later. The Government says refusing to save those verified attributes does not prevent the person using ScotAccount or the online service they are accessing.

It can be easy to miss. A user can choose whether to retain a reusable bundle of verified information. The underlying account, identity and fraud processing needed to run the verification service itself is performed under the Government’s public-task basis.

One identity, increasingly many services

ScotAccount is designed to be reusable.

When an account is created, the user is assigned a randomised unique account identifier. The identifier is shared with services when the person signs in. Where a participating service requires verified identity, ScotAccount can also provide the verification result and verified information including the person’s name, date of birth and address after the user confirms the information to be shared.

The Government’s service documentation describes the purpose plainly: public bodies should not need to build their own separate identity-checking systems, and citizens should not have to prove the same identity repeatedly. By June 2026, the Scottish Government said ScotAccount had more than 768,000 registered accounts.

The system has already been used for services including Disclosure Scotland applications, the Crown Office and Procurator Fiscal Service Witness Gateway, insolvency and debt services, tobacco and vaping registration, funeral-sector registration and the Register of Assignations and Statutory Pledges.

The Government is deliberately widening that reach.

Its 2026–31 Programme for Government commits to digital services built around a “tell us once” approach, shared data definitions and datasets, a ScotGov App intended to give citizens access to multiple services without separate websites and logins, and accelerated development of Data Exchange so that data held by one organisation can be made available to another while, the Government says, protecting privacy and security.

ScotAccount sits among the common components being assembled for that model alongside Digital Mailbox, ScotPayments and ePass.

This does not mean Scotland currently has a single database in which every piece of information held by every public body has been merged. The published evidence does not establish that.

It does establish something more specific: Scotland has built a persistent, reusable digital identity layer intended to operate across an expanding number of public services, while the Government is simultaneously developing the infrastructure for greater sharing and reuse of public-sector data.

What can be shared when fraud is suspected

The ordinary sharing described by ScotAccount is relatively narrow. A service can receive the account identifier and, where requested and confirmed by the user, contact information and verified identity attributes.

The privacy notice contains a broader provision for crime and fraud.

For those purposes, ScotAccount says information can sometimes be shared with the agencies and departments running services accessed through ScotAccount, other UK public-sector organisations including the Home Office, law-enforcement bodies including Police Scotland and the National Crime Agency, Experian and relevant monitoring providers.

The categories listed include IP addresses and geolocation, the ScotAccount number, device information, identity-document details, names and dates of birth, addresses, phone numbers and email addresses.

That does not mean all of those data are routinely sent to all of those bodies whenever someone signs in. The privacy notice describes sharing for identifying crime and protecting against fraud.

But it demonstrates that the identity layer is not limited to a one-time comparison between a person and a passport. It produces account, device, verification and security information which sits within a wider counter-fraud framework.

A seven-year audit trail

Different parts of ScotAccount are retained for different periods.

The Scottish Government says biometric data used during identity verification are kept until verification is complete, normally only for minutes but potentially for up to one week. It says the questions and answers used for knowledge-based verification are not retained by ScotAccount.

Ordinary system logs recording actions taken in ScotAccount are kept for 12 months. Security-monitoring data are kept for six months.

Separately, ScotAccount maintains a secure audit trail of its audit logs for seven years for fraud-monitoring purposes.

A user can delete information they have chosen to save and can delete the ScotAccount itself. The privacy notice also makes clear that data held by other organisations involved in the verification process can be governed by those organisations’ own legal responsibilities and retention requirements.

The system therefore cannot be understood simply by looking at the contents visible inside a citizen’s ScotAccount. Part of the processing exists in records maintained by separate organisations involved in establishing and protecting the identity.

The Experian contract is worth £2.68 million

The commercial identity-checking role is not incidental.

In March 2025 the Scottish Government published a contract award for the renewal of Experian digital-identity services with a value of £2,680,647 excluding VAT. The contract notice describes the procurement as part of the Digital Identity Scotland programme.

Experian Limited, the contracted UK entity, is based in Nottingham. The wider Experian group is incorporated in Jersey and headquartered in Dublin, with a substantial international business.

The relevant reporting point is therefore not that ScotAccount hands a citizen’s banking account to an American company. The documents do not support that statement.

The stronger documented fact is that Scotland’s government digital identity system depends in part on a commercial credit-reference organisation to test the history and credibility of an identity, including by carrying out a soft search of records assembled from sources that include financial institutions.

Its cloud host is subject to United States jurisdiction

A separate international-jurisdiction issue exists in the infrastructure underneath ScotAccount.

In a freedom-of-information response published in July, the Scottish Government confirmed that ScotAccount is hosted on Amazon Web Services in UK regions and that ScotAccount data are processed and stored within the UK.

The Government also expressly confirmed that AWS is subject to United States jurisdiction.

The same FOI request asked whether ScotAccount’s Data Protection Impact Assessment specifically examined the risk of extraterritorial data access under the US CLOUD Act or the UK-US Data Access Agreement. The Scottish Government said it did not.

Scotland opposes a mandatory UK digital ID, while pushing Scots into its own

The contrast becomes sharper when ScotAccount is placed beside the UK Government’s developing digital-identity policy.

In an FOI response published in August, the Scottish Government said it had been clear in its opposition to a mandatory UK digital identity scheme, citing concerns about inclusion, proportionality, privacy and non-discrimination.

That position is not inconsistent with operating any form of digital identity. A government can oppose a mandatory national scheme while supporting a voluntary or service-specific digital identity system.

The technical similarities already visible.

GOV.UK One Login is also designed to let people prove their identity once and reuse that verified identity across government services. It too uses Experian. Its identity process can include financial-history questions about bank accounts, mortgages, loans and credit arrangements, as well as fraud checking, document verification and facial comparison.

The systems are not identical. Their governance, scope, legal arrangements and degree of compulsion differ. Scotland continues to say that offline routes should remain available to people who cannot or do not wish to use digital services.

ScotAccount is a digital identity service by the Scottish Government’s own definition.

ScotAccount and GOV.UK One Login are already being discussed together

The two systems are not presently connected through the proposed UK national digital-ID infrastructure. The Scottish Government says there are currently no plans to make that connection.

However, it has also confirmed continuing work with the UK Government on possible “interoperability and federation of credentials” between ScotAccount and the existing GOV.UK One Login system.

In a further FOI response, the Scottish Government explained that interoperability could mean one digital identity system recognising or accepting credentials issued by another, while federation could allow a person to authenticate across systems without creating separate accounts.

Six meetings specifically concerning ScotAccount and GOV.UK One Login interoperability or credential federation took place between August 2023 and June 2025. The Government says they remained exploratory and produced no formal agreement, detailed design or agreed data flows.

As of the April 2026 FOI request, no Data Protection Impact Assessment, data-sharing agreement, privacy notice or formal interoperability document had been produced for connecting the two systems, because the work had not progressed that far.

That is an important boundary. There is no evidence that ScotAccount data are currently being merged into GOV.UK One Login.

There is evidence that the two governments have been exploring whether credentials issued in one system could eventually be recognised by the other.

The question is no longer whether Scotland has digital identity

The debate over digital identity can easily become trapped between two inaccurate descriptions.

One presents ScotAccount as little more than a convenient username and password. The Scottish Government’s own documentation does not support that description.

The other assumes that every database has already been secretly merged, that government receives citizens’ bank transactions or that foreign authorities have already accessed Scottish identity records. The available evidence does not support those claims either.

The documented system is substantial enough without either exaggeration.

A citizen can create a persistent Scottish Government account. Where identity verification is required, a passport or other document can be checked, the person’s face can be biometrically compared with the document, Experian can search the person’s credit record for evidence that the identity has existed over time, Cifas can be consulted for fraud indicators, and a unique identifier can then follow the verified account into participating public services. Parts of the resulting audit record are retained for years. The service is hosted on infrastructure operated by a company subject to US jurisdiction. The Government is simultaneously expanding “tell us once”, shared-data and common-service infrastructure.

None of those elements is hidden. They are spread across privacy notices, technical guidance, procurement records, policy papers and freedom-of-information responses.

Taken together, they describe something much larger than a login page.

They describe Scotland’s digital identity infrastructure.

The unanswered public-service question

The Scottish Government’s case for the system is that reusable identity reduces duplication, prevents fraud, allows public bodies to avoid building multiple verification systems and makes services quicker for citizens. Its published principles emphasise data minimisation, user control and continued offline access.

The countervailing governance question arises from the same architecture.

When a citizen already possesses a government-issued passport, why is it necessary in some online verification journeys to supplement that official identity with an activity-history search through a commercial credit-reference agency and a separate check against a fraud-prevention database?

The answer may be that a genuine passport establishes the validity of a document but does not, by itself, eliminate impersonation, stolen identities, synthetic identities or other forms of fraud. That is the rationale built into the Government’s current system.

But as ScotAccount moves from individual services towards a common route into public administration, the proportionality of each additional check becomes more important, not less. So does the distinction between data required to establish identity, data used to assess fraud risk, data saved for convenience and data made reusable across government.

The Programme for Government now proposes a ScotGov App, “tell us once” services and a Data Exchange intended to make information held by one organisation available to others. ScotAccount already provides the persistent identity capable of connecting a person to those services.

That makes digital identity a present question for Scotland, not a future one.

The system already exists. The next question is how far it will be allowed to reach.

Sources

Privacy notice — ScotAccount — mygov.scot / Scottish Government, last updated 24 June 2026.

ScotAccount Terms of Use — Scottish Government, accessed 30 September 2026.

Verifying your identity with ScotAccount — mygov.scot / Scottish Government, accessed 30 September 2026.

ScotAccount: equality impact assessment — Scottish Government, 5 March 2026.

ScotAccount hosting infrastructure and jurisdictional risk assessment: FOI release — Scottish Government, 21 July 2026.

Digital identity scheme consultation queries: FOI release — Scottish Government, 19 August 2026.

Queries concerning interoperability between ScotAccount and GOV.UK One Login: FOI release — Scottish Government, 25 August 2026.

Programme for Government 2026 to 2031 — Delivering a stronger NHS and Public Services — Scottish Government, 1 September 2026.

Building joined-up digital public services in Scotland — Scottish Government Digital Directorate, 18 June 2026.

DIG — Digital Identity Experian Renewal, Contract Award Notice — Public Contracts Scotland / Scottish Government, 10 March 2025.

GOV.UK One Login: privacy notice — Government Digital Service, updated 28 January 2026.

Proving your identity with GOV.UK One Login by answering security questions — Government Digital Service, updated 22 September 2026.

John Campbell

John Campbell

Covers Scotland’s economy, industry and business environment, with particular attention to investment, trade and energy.

Latest from Policy and Government