What’s in my ID to you?
In transgender circles, and especially in their genderqueer segment, the question of the “sex/gender” field in identity documents comes up from time to time: which options in it would be appropriate, and whether it should exist at all. Such discussions often suffer from a problem tied to a stereotypical view of documents as a Soviet-style passport: a paper booklet with a certain number of fixed fields that has to be presented at various institutions. But that view belongs to the last century, and reasoning about the “sex” field within such a context can, in my view, be compared to trying to replace a single component in an outdated computer when what ought to be done is a complete upgrade.
In this article I will try to make the case for why it makes more sense to raise the question not of one particular field or another, but of a complete change in the approach to identity documents, and to outline a possible implementation of such an approach.
Electronic advantages
First of all, the future — and, in fact, the present as well — undoubtedly belongs to electronic documents. Let’s begin by looking at the advantages they have over traditional paper ones from a technical point of view.
-
Capacity. An electronic chip can hold a far greater volume of data than fits on a piece of paper.
-
Changeability. If a paper document has to be replaced, that can be a rather lengthy procedure. On an electronic one, with the appropriate equipment, the data can easily be rewritten (I’ll note that in general this applies both to the specific contents of the data fields and to the very set of those fields).
-
Variability. The algorithms for reading and writing electronic documents can be diverse and can allow for work with heterogeneous data that isn’t necessarily formed according to a rigid template.
-
Universality. One and the same document-processing protocol can support a wide range of devices — from electronic locks to vending machines.
-
Automation. Since data processing is possible without human involvement, in many situations this makes it possible to eliminate the human factor, which in the post-Soviet space often shows up in the form of “gatekeeper syndrome.”
-
Remote access. An electronic card can play the role of a key that opens access to data which, given a network connection between the terminal and the computer holding the database, can physically be located anywhere on the globe.
The list doesn’t claim to be exhaustive, but it seems quite sufficient for appreciating the advantages of electronic documents in the age of information technology.
One could go through these points in more detail and describe, on the strength of all of them, what an implementation of electronic identity documents might look like. However, that approach seems mistaken to me. The thing is, it starts from what can be done, but doesn’t raise the question of what is actually needed. Certainly, the properties listed may already be enough to simplify many procedures technically and thereby make life easier for people, but the fact that a piece of paper is replaced by an electronic card, and the gatekeeper by a card reader, does not change the conceptual model of relations between citizens and state institutions. And some people will meet such changes with outright skepticism, seeing in the possibilities of computerized record-keeping a “hello” from totalitarianism.
What, in my view, does need to be changed conceptually is what we’ll talk about next.
Identification of identity
“Identity” and “identification” are words that share a root. What is the difference between them? Identity is something internal, inherent to the person themselves, something they feel and define as characterizing them. Identification, on the other hand, is a process initiated from the outside, when someone, proceeding from their own notions, determines who and what a particular person is.
It seems entirely natural to want the identification of us to coincide as closely as possible with our identity. In fact, quite a few psychological and social problems arise precisely because other people, society and the state see, or want to see, in us someone completely other than who we are from our own point of view.
And the highest priority in identification belongs to the state. It is the state that defines the parameters by which we are to be identified (first name, last name and patronymic, date of birth, sex, registered address and so on — the things usually listed in a passport or a document equivalent to it), the format and possible values of these parameters, as well as the rules according to which they are to be assigned. It drives people into rigid frameworks and forces them to go through complicated bureaucratic procedures if the initially assigned parameters don’t suit them for some reason. In totalitarian systems, changing identification parameters can be entirely impossible, and the freer the state, the simpler such procedures within it tend to be. But one way or another, the state’s very monopoly on identification is usually not questioned by anyone.
But can anyone really identify us better and more accurately than we ourselves can? And isn’t it our right to be perceived in accordance with our identity?
One could object here that the state identifies us not simply because it feels like it, but in order to solve a multitude of tasks of record-keeping and oversight — it needs to know whom to pay salaries and pensions to, who pays taxes, who serves in the army, who commits offenses and so on. But if you look at it this way, all these tasks exist in particular contexts in which only certain specific parameters are needed to solve them, and there is no real need for the entire set of a person’s passport data to be nailed to every subject. In the general case, a unique identifier may be enough — one that makes it possible to tell the history of subject 12345’s interactions with state institutions from the analogous history of subject 54321, whoever may be standing behind those numbers.
Let’s now turn to the experience of social networks. On a social network, every user has a profile that can contain a great many fields. But almost all of these fields are optional: users are able to fill in only the ones they themselves see fit — in effect, the ones that reflect their identities. After all, our identities largely determine the spheres of social interaction we want, and through the values of the fields in our profile we mark out these spheres, explicitly or implicitly. So for one person it may be important to state, for example, their ethnicity, religion and political views. For another these things aren’t important at all; instead it’s important to indicate gender identity and sexual orientation. And a third person is interested only in professional interaction, so they may skip everything listed above but describe their work experience and achievements as fully as possible. And so on.
I have already mentioned in this text the information age we live in. Its defining feature is an informational, “virtual” space that exists in parallel with the material one. At times they complement each other, and at times they flow into one another so that sometimes the boundary cannot be drawn at all. And if until now it has rather been the network pulling elements of the material world into itself (in this context, for example, tying registration on certain resources to passport data), then what’s stopping us from turning this process the other way around where that seems appropriate?
Below I will try to model how this might be implemented.
The personal profile
So let’s suppose that a “user profile” — or, as it would be more correct to call it, a personal profile — can be created for every inhabitant of Earth. Initially, when a child is born, such a profile can be created by their parents, and in childhood changes can be made to it with the parents’ consent; upon reaching adulthood, the person receives the right to manage it entirely. Accordingly, they themselves decide what information about themselves to enter into this profile and what not to (and can change that decision at any moment). Broadly speaking, all this information can be divided into two categories: self-declared and verified.
Self-declared information is identity parameters in their pure form, which a person can define for themselves at will, without being obliged to look over their shoulder at anyone or anything. This includes, for example, such data as name, gender, adherence to one religion or ideology or another, interests, hobbies, favorite authors and bands, and so on.
Verified information is data that either is determined by factors independent of the person themselves (blood group, chromosome set, fingerprints), or consists of facts from the past (date of birth, information about finishing school and university, work record, criminal record), or arises out of the person’s interaction with society and cannot be changed without the agreement of the other participants in these interactions (marital status, place of work, bank account). What unites these groups of data is that they can be checked and confirmed through certain formal procedures. A person will not be able to change such information in their profile simply because they want to, but they will be able to decide whether it should be contained there at all.
Generally speaking, the binary framing of the question — “to store or not to store this or that information in the profile” — isn’t quite correct within the proposed model. The question can be posed more flexibly: whom do we want to show this or that information to, and whom not. A similar practice, once again, exists on social networks, where we can open some data to the whole world, some only to friends, and some is accessible only to ourselves. In the same way, in our identity profile a confidentiality parameter can be attached to every field. And it would be good to be able to configure this parameter as flexibly as possible. To allow some things to be seen only by a certain category of organizations or by a specific organization, some only within one’s own country, some only by a certain group of people or by specifically designated people. Or the other way around — by everyone except such-and-such people and organizations. In general, there can be many variations here. It goes without saying that the option “don’t write any data into the profile at all” also remains, as before.
At the same time, if we tie a bank account to the profile, for example, it would be absurd to forbid access to this information to the bank where we opened it. Or to information about professional status — to the organization where we work. For data of this kind, the confidentiality settings could be assigned by default, with the possibility of adjusting them later. That said, I see no reason to forbid a user from imposing even such nonsensical restrictions — everyone is free to make their own mistakes and to draw their own lessons from them.
This whole system will be at its most effective if it is global, so that we can be identified in accordance with our profiles in any corner of the globe. Technically, this question comes down, first, to developing a universal “identification protocol” that provides access to profiles, and second, to its support by various institutions and organizations. This question can be resolved in different ways: at an initially global level, up to and including the UN, or in a less centralized way — for example, through the implementation of this protocol via a treaty among several countries that others could then join. That said, even implementation within a single state would be a great achievement and a good example that others would probably follow before long.
How it works
Storage
Until now the personal profile has been discussed as something abstract, apart from the question of its physical embodiment. Now is exactly the time to move on to that question as well, namely: where should the data be stored? Technically it can, of course, be kept on the card that the user carries with them (see the point about “capacity”), but that brings us back to the notorious “without a piece of paper you’re a bug.” After all, if the card is lost or damaged, restoring such a heterogeneous set of data may turn out to be lengthy and complicated, or even entirely impossible for some part of it. That’s why it is smarter to store the data in the network and to use the card only as a key for accessing it (“remote access”). That said, nothing prevents some most-needed part of the profile (at the user’s own discretion) from being duplicated on the card as well, which would make it possible to handle a number of particular tasks without a network connection — all the more so since a connection can sometimes be undesirable from a security point of view (and the equipment would cost less, too).
Storage in the network, moreover, by no means presupposes a single central server. A decentralized structure is actually preferable: it can be of the cloud type, or it can be such that different fragments of one profile are stored on different servers depending on where and when they were entered — the main thing is that, when needed, they can easily be assembled together by a unique key-identifier. In general, these are already fairly low-level technical details that I won’t go into here.
And what might be placed on the surface of the card itself? It would be logical to put a photograph there — for those cases when identification may be carried out the old way, without electronics (besides, that would make it possible to launch the system without waiting for the moment when support for its protocol is provided everywhere, from the capital to the most remote villages). The same unique identifier to which everything else is tied could also be placed on it. Then in a number of situations — in the case, for example, of mechanical damage that keeps the card from being read by a computer — this identifier could be entered manually and all the necessary information obtained (within the part of the profile available to that institution given the confidentiality levels that have been set). All the other fields (including even one’s name) are entirely optional — but if the owner of the card wants to display something else on it, there should be no obstacles to that. If in our model the profile itself can be shaped as the person wishes, then, naturally, the same extends to the card as well — within the limits allowed by the technical protocol. The card can also be reissued at any moment if personal data has changed, or, again, simply because the person wants it — let’s not forget that first and foremost it is only a key and nothing more.
Creation and modification
Let’s now talk about how, and by whom, data can be written into a profile.
When a new profile is created, there is a need to make sure that one did not exist for this person before. Since we’re saying that the profile is a universal document which shouldn’t depend on any other papers, certificates and so on, the most logical thing to use for this purpose is biometrics. Let’s note here that this makes biometrics a mandatory parameter of the profile — one of those parameters that cannot be changed at will. Since a human being is, after all, not pure consciousness with its identities but also a biological organism in the material world, there is probably no getting away from that.
To have the right to create profiles, their “providers” must support the identification protocol and have the appropriate certified equipment. Let me emphasize that these by no means have to be state institutions — they could perfectly well be private ones, as long as they are able to meet the technical requirements. In general, creating a profile could simply be an additional service provided by one institution or another — a university, a bank, a mobile operator, an immigration service and so on.
As for entering new data and making changes to the profile — the user could do that themselves at the same kind of institution, connecting to the profile through a special computer using the card, or by entering their identifier and passing a biometric test. Let me emphasize that since the procedure is fully automated, the institution’s employees generally get no access at all to the profile’s data (unless the user, of their own accord, asks them for help in working with the data).
A question may arise here: if the person enters the information themselves anyway, then why go to some institution to do it at all — why not allow them to do it on any computer, granting access to the profile by entering their identifier and a password? That, in general, is debatable. In my view, such an approach, unlike the use of biometrics, doesn’t provide a sufficient level of security — even if the password is generated automatically (which rules out the use of primitive passwords like “11111”), it can still be spied out, stolen and so on. That said, if at some point in the future biometric devices become relatively affordable to install on home computers, the need to visit special institutions may indeed become superfluous.
Verification
All data entered by the owner of a profile is unverified by default. If it is self-declared by nature, then nothing more needs to be done with it. But if verification is required, there are two possible approaches to it: to request it right away, or to put it off until it is actually needed.
Let’s suppose that a certain person enters data about their education into their profile: university, year of graduation, major and so on. If they request verification, this data is sent by the “provider” to the university in question. The university either confirms it as is, and then the verification flags are set automatically; or doesn’t confirm it, having found nothing similar in its records, and then this data is deleted from the profile; or finds errors in the data and makes its own corrections. In the last case, the corrections are forwarded to the person who made the request, and they can agree with them, at which point the verification procedure is complete, or disagree and go on sorting the situation out directly with the university. As we can see, apart from that last case, this entire process requires no active involvement from the owner of the profile (compare that with today’s typical practice, where in similar situations you have to run around to various offices yourself in order to obtain one certificate or another and complete the necessary paperwork).
If verification isn’t requested, that means that when the person comes, let’s say, to apply for a job and they are asked about their education, it will rightly be pointed out that the data about it is unconfirmed. To which they may say “to heck with it” (it’s clear that this will substantially reduce the chances of being hired), or may request verification, or delegate it to the employer. In that case the procedure will not differ significantly from the one described above.
Naturally, there is also a third way of resolving the question, in which at the end of a course of study the university itself offers graduates to enter verified data about their education into their profiles. This option, in my view, is the one to be treated as the main one — but for those who initially declined such a service, or who studied when this system did not yet exist, the options described above remain.
Data that has already been verified cannot be changed by the user at their own discretion. However, as was said earlier, they can set any confidentiality levels for it and even delete it from the profile entirely. In the latter case, if after some time they change their mind and want to enter it back, nothing, of course, prevents them from doing so, but the verification will have to be carried out again.
Access
Now, having finished with the questions of creating and updating a profile, let’s consider a situation in which some organization requests certain data about a person. It turns to the profile and gets access to the part of it that is open to it. If it doesn’t find what it’s looking for in that part, it sends this person a request to disclose particular data, with a mandatory explanation of what it is needed for. The person, for their part, may grant this request by changing the confidentiality settings or by providing the necessary information directly, but they may also refuse — and note that, unlike the organization making the request, they are not obliged to justify the reason. If the organization isn’t satisfied with such a turn of events, it can go to court, which will consider how serious its argument is. If, for example, it is the police, who suspect the person of a crime and are looking for evidence of it, their claim may be granted and the confidentiality restrictions lifted by force. In turn, the person can also go to court afterward if they believe the restriction was lifted unlawfully.
Thus, as we can see, although the state retains certain levers of influence over the processes of identification, the situation is very different from today’s. Of course, under this system nothing prevents state institutions, as before, from keeping databases of their own with their own sets of parameters, but all official interactions with citizens they are obliged to carry out in accordance with citizens’ profiles. And the maximum of control over these interactions lies precisely in the hands of the citizens, not the institutions.
It is we ourselves who determine how we are to be identified and how we are to be perceived.
The multi-passport
Everything described above already looks so revolutionary that one could probably stop right there. But in closing I want to consider an even more radical idea, one I would call “multi-profiling”.
Until now it has gone without saying that one personal profile is created for each person. But let’s now suppose that this restriction doesn’t exist. The link to biometrics still remains, but any number of virtual personas — or, if you like, “avatars” — can be tied to it. Each avatar can have its own name and its own set of parameters identifying it. This makes possible a situation in which one physical person appears in different contexts as, in essence, different people.
If we talk about the demand for such an option, the first to come to mind are transgender people. If someone, after transition, prefers to leave the past behind and start life with a clean slate — clearly, they can simply change some fields in the profile or delete them from it. Or they can just “drop” the old profile and create a new one. But it gets even more interesting for bigender people, who could maintain two profiles at once — for their female and their male embodiment.
That said, it isn’t only transgender people who could make use of this. Different profiles could be set up by performers — for their stage persona and for everyday life. By celebrities — when they want to limit the attention paid to them and stay incognito. By people inclined toward one kind of role play and fantasy or another. By those for whom this would be a way to “start a new life.” By those who prefer to keep their different social circles separate and unmixed. That said, I’m not aiming to compile an exhaustive list — one way or another, there will be people who find a use for this option.
Yes, most such wishes can also be met by adjusting the confidentiality levels of the information in a profile. But the technical implementation of multi-profiling doesn’t look much more complicated, and since biometrics make it possible, where needed, to establish that avatars belong to one person, there shouldn’t be any fundamental counterarguments on the organizational side either. So an identification system could include both the one and the other approach, leaving the choice of the more acceptable one to users themselves.
* * *
Before putting a period at the end, I want to say a few more words.
Computer technology is already developed to such a degree that, from a technical point of view, everything described in this article is not some kind of science fiction but entirely feasible. Unfortunately, that doesn’t mean it can easily be brought about any time soon. And the main obstacles to it lie not in the technological plane but in the social one. There are the bureaucratic structures — cumbersome and clinging tightly to the means of control and power over people at their disposal. And there is society itself — inert, driven into the frameworks of predetermined identifications and keeping itself within them, so that it doesn’t even occur to most people that things could be otherwise.
But if, while reading this article, you found yourself thinking that things can and should be otherwise, then spread these ideas further — and the more often they are voiced, the sooner they will move out of the category of the utopian and into a concrete project slated for implementation.
Inna Iryskina