ScotAccount now has more than 768,000 registered accounts and processes biometric images during some identity checks. The Scottish Government says the information remains in UK-based Amazon Web Services regions and that photographs are deleted after verification, but it has no ScotAccount-specific migration plan with defined times or costs. Its data-protection assessment did not specifically examine exposure under the US CLOUD Act or the UK–US Data Access Agreement.
Scotland is building a common digital identity service that increasingly sits between people and the public services they need.
ScotAccount allows one account to be used across Disclosure Scotland checks, NHS Scotland’s MyCare service, the Witness Gateway, Scotland’s Redress Scheme, debt arrangements, Registers of Scotland transactions, tobacco and vaping registrations, funeral-sector regulation and Legal Aid Online. More services are expected to join.
ScotAccount had just over 768,000 registered accounts at 1 June 2026. Some users need only an email address, telephone number and password. Others are asked to prove their identity using an official document and a live photograph of their face, or by answering questions derived from their personal and financial history.
The system can then retain verified details such as a person’s name, date of birth and address, allowing them to reuse that information when applying for another public service. Saving those details is optional, and the government says users can remove them or delete their account.
The Scottish Government presents this as a simpler and more secure alternative to repeatedly proving identity to different public bodies. It can reduce paperwork, duplicated verification systems and fraud risks while giving people one route into a growing collection of online services.
Its core cloud hosting is provided through infrastructure operated by Amazon Web Services.
The government’s answer
A Scottish Government freedom-of-information response published on 21 July confirms that ScotAccount is hosted on Amazon Web Services, using UK regions only. It says the data is processed and stored within the UK, while recognising that AWS is subject to United States jurisdiction. The response does not identify the particular data centres involved.
The same disclosure confirms that ScotAccount processes biometric data derived from identity documents and selfie images. That information is classed as special-category data under the UK General Data Protection Regulation.
The government says the images are used only to complete the identity check and are deleted when the check ends. ScotAccount’s privacy notice says the biometric information may be held for up to one week where verification is not completed immediately, although the process should ordinarily take only a few minutes.
The government has conducted a Data Protection Impact Assessment for ScotAccount. It told the FOI applicant, however, that the assessment did not specifically identify and assess the risk of extraterritorial access under the US CLOUD Act or the UK–US Data Access Agreement.
Its explanation was that a DPIA assesses compliance with UK data-protection law and is not intended to provide a comprehensive assessment of every international legal regime that could theoretically apply to a cloud supplier. The response does not identify a separate ScotAccount assessment addressing those laws.
The government also said it holds no separate ScotAccount document assessing the consequences of sanctions, a change in the hosting provider’s ownership or withdrawal of service. Officials said they had identified no continuity risks materially different from those already managed for other public services using commercial cloud infrastructure.
Most strikingly, the government confirmed that there is no ScotAccount-specific exit plan setting out how long migration would take or what it would cost. It said high-level exit and portability considerations form part of its general governance and supplier-management arrangements, but there is no plan containing defined timelines or cost estimates.
That distinction becomes harder to dismiss as the service grows. ScotAccount is no longer a small experiment serving one public body. It is becoming shared national infrastructure, with more than three-quarters of a million accounts and a stated role in future health and public-service delivery.
What happens when someone verifies their identity
People using photographic verification are asked to provide an image of an official identity document and a live image of their face. ScotAccount uses Experian and its subcontractor Mitek to check whether the document is genuine, whether the applicant is a real person and whether the face matches the document photograph. HM Passport Office may also verify passport information.
People who cannot use photographic identification may instead be asked questions about bank accounts, mortgages, loans, credit cards or other personal history. Experian generates and checks the answers. ScotAccount says it does not see the underlying financial information and receives only the result of the check. A soft search is recorded but does not affect the person’s credit score.
Cifas is used to check for known or suspected identity fraud. ScotAccount also records IP addresses, device information and other technical identifiers for security monitoring. Its current privacy notice says ordinary system logs are held for 12 months, security-monitoring data for six months and a secure audit trail for fraud monitoring for seven years.
The supplier chain therefore extends beyond Amazon. It includes Experian, Mitek, Cifas, HM Passport Office, support-service provider Atlassian and Netcompany, which the government says is building and supporting ScotAccount’s digital mailbox. ScotAccount’s privacy notice also says personal information collected through Atlassian products for user support may be transferred outside the European Economic Area for processing, meaning the UK-region assurance for the core AWS-hosted service should not be read as applying to every piece of information handled by every supplier.
Each company is performing a defined task under a different legal and contractual relationship. Some act as processors following government instructions; others, including Experian during certain checks, operate as independent data controllers.
This is not evidence that private companies are free to reuse ScotAccount information for advertising, commercial profiling or unrelated purposes. The government says suppliers receive only the minimum information required and are contractually restricted to providing their services. AWS says it does not use customer content for advertising or marketing and does not ordinarily move it outside the selected region, although exceptions may apply where this is necessary to provide a customer-initiated service or to comply with the law or a binding government order.
The issue is the number of dependencies now supporting one route into Scottish public services.
American jurisdiction does not mean automatic American access
The fact that AWS is an American company does not give United States authorities direct or routine access to ScotAccount.
A valid legal process would be required. AWS says it scrutinises government demands, challenges requests that are overbroad or legally defective and attempts to direct authorities to the customer before disclosing information itself. It also offers customers options to manage their own encryption keys.
The legal exposure is nevertheless real enough to require assessment.
The US CLOUD Act states that covered electronic communications and remote-computing providers must comply with lawful preservation and disclosure obligations for information within their possession, custody or control, regardless of whether it is stored inside or outside the United States.
The UK–US Data Access Agreement separately allows qualifying authorities in either country to seek electronic information directly from covered providers in the other country for investigations into serious crime. Existing domestic authorisations and oversight requirements continue to apply. It is a legal route, not a hidden back door.
The UK National Cyber Security Centre advises cloud customers to establish where information is stored, processed, managed and supported; which legal jurisdictions may apply; what access rights providers possess; and in what circumstances information could be obtained without the customer’s consent. It warns that jurisdiction can be more complicated than the physical location of a server.
The Scottish Government knows that AWS is subject to US jurisdiction. What remains unpublished is the specific analysis showing how that exposure has been addressed for a service processing identity and biometric information at national scale.
The cost of becoming difficult to replace
ScotAccount’s procurement history shows that supplier dependence is not a theoretical concern.
In 2021, the Scottish Government awarded Newcastle-based Scott Logic a contract worth £6.08 million to provide the Digital Identity Scotland beta service. Six tenders were received. None was recorded as coming from an SME. The contract award was not published on Public Contracts Scotland until December 2023.
In March 2025, the government awarded Scott Logic a further £982,702 contract without opening a new competition. Only one tender was recorded.
The official justification said the development and support work had continued longer than expected. Officials argued that replacing Scott Logic at that stage would cause delay, lose knowledge and experience, and create further costs.
That is a direct description of technological and institutional lock-in: the incumbent had acquired knowledge that government considered too costly and disruptive to replace.
The Scottish Government says it has since transferred software-engineering knowledge and skills into its own team, reducing its reliance on external delivery partners. That is an important safeguard and shows that at least part of the capability has been brought inside government.
The external chain has not disappeared. A separate £2.68 million identity-verification contract was awarded to Experian in February 2025 after one tender was recorded through the UK Government’s G-Cloud framework. It includes an option for a further 12-month extension.
Those three identified awards — the original Scott Logic contract, its extension and the Experian renewal — have a combined published value of almost £9.75 million excluding VAT. They do not represent the programme’s total cost.
A Scottish Government FOI release previously reported a whole-life funding estimate of £45 million for the Digital Identity Programme between 2018 and 2028. Officials said at the time that the figure would be revised once the future commercial model had been settled.
How this can affect people
For many users, ScotAccount may be a genuine improvement. A single sign-in can remove repeated forms, identity checks, paper documents and journeys to public offices. The government says it maintains non-digital routes and that the service remains voluntary.
Some individual online services may nevertheless require a ScotAccount before they will allow access through their digital route. If the account is inaccessible, suspended or cannot be verified, the person may have to use a different route or provide further information before receiving the service.
Concentrating access through one account also concentrates failure. An outage affecting ScotAccount or essential AWS services could interrupt sign-in or verification across several connected public bodies at once. It would not necessarily stop the underlying public services or remove offline alternatives, but it could prevent people from using their normal online route until the system returned.
There is also an equality question. The government’s own assessment acknowledges that people without photographic identification, reliable internet access or an established financial footprint may find verification more difficult. Young people, poorer households and residents of rural and island communities can face overlapping barriers involving document ownership, broadband, devices and travel to physical alternatives.
ScotAccount has responded by accepting additional documents, introducing security-question verification, allowing two-factor authentication through landlines and exploring forms of vouching by trusted people or organisations. The government’s assessment nevertheless recommends further non-biometric routes and continued protection of offline access.
The available evidence does not show that Amazon or the other suppliers are freely accessing or exploiting ScotAccount information, nor does it establish that the service is inherently unsafe. It does show that Scotland is turning ScotAccount into national public-service infrastructure without a published jurisdiction-specific risk assessment, a costed and timed exit plan, or enough public detail to judge how access would be maintained during a major supplier or system failure. As more services join, those safeguards should be demonstrated before the dependency becomes too extensive and expensive to unwind.
Sources
ScotAccount hosting infrastructure and jurisdictional risk assessment: FOI release
https://www.gov.scot/publications/foi-202600516387/
Privacy notice — ScotAccount
https://www.mygov.scot/privacy-notice-scotaccount
ScotAccount services and account information
https://www.mygov.scot/scotaccount
Verifying your identity with ScotAccount
https://www.mygov.scot/scotaccount/verify-identity
ScotAccount Equality Impact Assessment
https://www.gov.scot/publications/scotaccount-equality-impact-assessment/
ScotAccount: transforming public services in Scotland
https://blogs.gov.scot/digital/2025/07/16/scotaccount-transforming-public-services-in-scotland/
Scottish Government Digital Identity Scotland beta contract
https://www.publiccontractsscotland.gov.uk/search/show/search_view.aspx?ID=DEC495431
Digital Identity beta contract extension
https://www.publiccontractsscotland.gov.uk/search/show/search_view.aspx?ID=MAR526047
Digital Identity Experian renewal
https://www.publiccontractsscotland.gov.uk/search/show/search_view.aspx?ID=MAR525585
Digital identity accounts: FOI release
https://www.gov.scot/publications/digital-identity-accounts-foi-release/
National Cyber Security Centre: asset protection and resilience
https://www.ncsc.gov.uk/collection/cloud/the-cloud-security-principles/principle-2-asset-protection-and-resilience
UK–US Data Access Agreement factsheet
https://www.gov.uk/government/publications/uk-us-data-access-agreement-factsheet/policy-factsheet-on-the-uk-us-data-access-agreement
United States Code, Title 18, section 2713
https://uscode.house.gov/view.xhtml?req=%28title%3A18+section%3A2713+edition%3Aprelim%29
AWS data privacy information
https://aws.amazon.com/compliance/data-privacy-faq/
