TL;DR: Reusable identity only improves governance when organisations can prove what is shared, when, and under which assurance level, according to Yoti. Yoti’s Digital ID combines selective disclosure, verified age and identity checks, peer-to-peer trust features, and device-based security controls such as biometrics and MFA.
NHIMG editorial — based on content published by Yoti: Digital ID features and privacy-preserving identity verification
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
Questions worth separating out
Q: How should organisations support Digital ID without increasing privacy risk?
A: Start by removing unnecessary data collection from the verification flow.
Q: Why does digital identity need privacy controls as well as stronger verification?
A: Stronger verification can still fail governance if it collects too much personal data or reuses it outside the original purpose.
Q: What do security teams get wrong about biometric verification in mobility?
A: They often treat biometric matching as the end of identity assurance when it is only one control point.
Practitioner guidance
- Define minimum-disclosure policies for each identity use case Map every age, identity, and student verification flow to the smallest attribute set required, then block requests for full documents when an attribute assertion is enough.
- Separate enrolment assurance from session assurance Document which checks establish identity at onboarding and which controls protect the live app session, including biometrics, MFA, device lock, and revocation paths.
- Set fraud controls around interaction type, not just identity presence For peer-to-peer use cases, define which transactions can proceed on verified profile attributes alone and which require stronger verification, payment controls, or manual review.
What's in the full article
Yoti's full article covers the product-level features this post intentionally leaves at the source:
- Step-by-step explanation of how the Digital ID app handles age checks, identity checks, and student verification in different scenarios
- Detailed guidance on using the app for peer-to-peer trust cases such as buying, selling, dating, and meeting someone new
- Practical descriptions of the security layers in the app, including biometric authentication and MFA
- Operational instructions for locking, suspending, and updating the Digital ID if a device or account is compromised
👉 Read Yoti's overview of privacy-preserving digital ID features →
Digital ID reuse and selective disclosure: what changes for IAM teams?
Explore further
Selective disclosure is the real governance test for reusable identity. The sector often talks about convenience, but the control question is whether the verifier receives only the attribute needed for the decision. That aligns with privacy-by-design expectations and with least-disclosure thinking in identity governance. For programmes that handle both human identity and digital credentials, the lesson is simple: minimising the claim is as important as validating the claimant.
A question worth separating out:
Q: Who is accountable when digital identity data is stored or shared incorrectly?
A: Accountability should sit with both the issuer and the provider that handles the data, because each controls a different part of the trust chain. Governance teams should assign ownership for proofing, storage, disclosure, and revocation separately so failures can be traced and corrected.
👉 Read our full editorial: Privacy-preserving digital ID raises the bar for reusable identity