Home Reviews About
Twenty of Time

Why social security numbers should be replaced by privacy-first identifiers

A single permanent number is attractive because it appears to make identity simple. Employers, banks, government agencies and online services can use the same reference, reconcile records quickly and recover accounts with less friction. That convenience hides a structural weakness: when one identifier follows a person through work, health, tax, finance and daily life, a breach can expose a map of that person’s existence.

Australia does not issue a US-style Social Security Number, yet it has several close equivalents in practice. Tax File Numbers, Medicare numbers, driver licence details, passport numbers and customer references can become persistent handles for identity. The privacy commentary at Twenty of Time explores why systems built for convenience can gradually expand into systems of surveillance. The lesson is relevant in Sydney, Melbourne, Perth and regional communities alike: identity should be proved for a particular purpose without creating a universal trail.

A permanent number creates a permanent target

A fixed identifier does not become safer because it is familiar. It becomes more valuable each time another organisation stores it. A malicious actor who obtains a name and a universal number can connect information from separate databases, test that combination against other services and make convincing claims during fraud attempts. The damage persists because people cannot simply change their date of birth or historical identity.

This is the weakness of the Social Security Number model in the United States. It was designed as an administrative reference, yet it gradually became a key for employment, credit, insurance and financial accounts. The original purpose was narrower than its modern role. Once institutions began treating the number as proof of identity, possession of the number started to carry authority.

Australia’s fragmented set of identifiers offers some protection because a TFN is not the same thing as a Medicare number or a licence number. It is still possible, however, for data brokers, breached companies and careless institutions to assemble those pieces. A person who uses the same email address, phone number and identifying details across services can end up with a practical universal identifier even without one official number.

Identification is different from authentication

A privacy-first system begins by separating three jobs that are often bundled together. Identification asks who a person is. Authentication asks whether the person controlling an account is authorised. Authorisation asks what that person is allowed to do. A birth date, licence number or tax identifier may help identify someone, but it is a poor secret and a weak authenticator.

This distinction matters whenever a business asks for excessive information. A bottle shop may need to establish that a customer is over 18, but it generally does not need a permanent copy of a passport. A venue may need to check a ticket, not retain a person’s full identity profile. A bank needs strong customer verification, though that does not mean every later interaction should expose the same raw documents.

Privacy-preserving credentials can provide a better pattern. A trusted issuer could confirm that a person meets a condition, while the receiving service sees a short-lived cryptographic proof rather than the underlying identifier. The proof might establish Australian residency, age eligibility or a current licence status. It should reveal the minimum necessary fact, expire when appropriate and be difficult to reuse in another context.

Australia already has the pieces of the problem

Australian residents encounter identity infrastructure in ordinary routines. Someone in Melbourne might use myki, a bank app, Medicare, a workplace payroll system and a government account in the same week. A Sydney resident may present a driver licence to a property agent, upload identity documents to a cryptocurrency exchange and use a mobile number for account recovery. Each interaction can be legitimate while the combined data trail becomes excessive.

The Privacy Act 1988 and the Australian Privacy Principles set limits around collection, use, security and disclosure of personal information. They give organisations obligations, yet the framework has often struggled to make data minimisation a default experience. Reform debates have also focused on stronger protections, clearer individual rights and consequences for serious mishandling. A legal rule is useful, but it cannot make an over-collected identifier harmless after a breach.

The Digital ID Act 2024 creates a national framework for accredited digital identity providers and aims to support safer identity verification. Its value will depend on implementation choices. A digital identity that merely centralises more records under a polished interface would preserve the old risk. A system that uses selective disclosure, independent oversight, interoperability and strict limits on tracking could reduce it.

Everyday privacy also depends on household habits, not just legislation. A practical privacy-minded homemaking approach includes checking which services retain identity documents, removing old accounts, using a password manager and refusing unnecessary copies where a visual check is enough. These small decisions do not replace structural reform, but they reduce the number of places where a permanent identifier can leak.

Better identifiers should be purpose-bound

Replacing a universal number does not mean creating a new universal number with a different name. A privacy-first identifier should be scoped to a relationship or transaction. A tax agency may issue a tax-specific reference, an employer may receive a payroll identifier and a health service may use a separate patient token. Systems can link records when the law and the person’s circumstances require it, but routine access should not expose the linking key.

Pseudonymous identifiers can support this design. A service might receive a random, organisation-specific token that is meaningless elsewhere. If two retailers hold different tokens for the same customer, a breach at one retailer is less useful for profiling activity at the other. Tokens should be rotated when practical, and the process that maps them back to a real person should be tightly controlled rather than available to every database administrator.

The architecture must also account for recovery. A lost phone, changed address or compromised email account should not force a person to reveal a lifetime identifier to every provider. Recovery can use multiple verified channels, in-person options and independent review for high-risk cases. People with limited digital access, unstable housing, disability or poor connectivity need alternatives that do not turn privacy-preserving technology into a barrier to essential services.

Selective disclosure can make digital identity safer

A strong digital identity wallet should behave less like a database and more like a secure container for credentials. A person could store an official proof of age, a qualification or a licence status and disclose only the relevant claim. The receiving organisation would verify a cryptographic signature, confirm that the credential has not been revoked and avoid collecting the document number itself.

Australian use cases are easy to imagine. A pub in Brisbane could check an over-18 credential without recording a passport number. A telecommunications provider could confirm an identity during account opening without retaining a full scan indefinitely. A government service could verify eligibility while preventing unrelated departments or contractors from seeing the same underlying identifier. These examples require careful rules because “digital” does not automatically mean “private”.

The system should make consent meaningful. People need to see what information is requested, who will receive it, how long it will be kept and whether refusal will block access to an essential service. Consent screens filled with legal language do not provide real control. The default should be the narrowest disclosure, with a visible record of transactions and an easy way to challenge misuse.

There is a social dimension as well. Online services increasingly shape behaviour through personalisation, risk scoring and persistent account histories. A review of gambling and friendship shows why data-driven environments can affect relationships and decisions beyond the original transaction. When identifiers allow activity to be joined across contexts, an isolated choice can become a lasting profile that influences advertising, credit assessments or access to services.

Security needs limits, not just stronger locks

Encryption, multifactor authentication and access logging are essential, yet they do not solve the central problem if an organisation has collected too much data. A perfectly encrypted database can still be misused by an authorised insider, compelled under a broad legal demand or exposed through a flawed application. The most resilient record is often the one that was never created.

A replacement for social security numbers should therefore include data retention limits. Services should have a defined reason to keep a credential, a deletion schedule and an audit trail for exceptional access. Contractors should receive only the fields required for their task. Administrative systems should make bulk exports difficult, alert staff to unusual searches and separate identity verification from marketing and analytics.

Independent oversight matters because organisations have incentives to expand data collection. Regulators need the authority and resources to investigate, impose meaningful penalties and require deletion or redesign. Procurement rules can push government departments and large businesses towards privacy-enhancing technology. Civil society, security researchers and affected communities should be able to examine how identity systems operate without being dismissed as obstacles to efficiency.

The transition must avoid concentrating power in one provider. If every service relies on a single identity wallet, outage or exclusion can become widespread. Competition between accredited providers, open technical standards and offline verification options can improve resilience. A privacy-first identifier is successful when it limits correlation and abuse, not when it simply moves surveillance from many databases into one extremely attractive target.

The measure of success is less knowledge

The strongest test is whether an organisation can complete its legitimate task while learning less about a person. A tax office may need accurate records; a pub may need an age result; an employer may need work rights and payroll details. None of those purposes automatically justifies a reusable identity key that can be matched against unrelated behaviour.

Businesses can begin by mapping where identifiers are collected and which teams can access them. They can stop using licence numbers as general customer references, replace copied documents with verified attributes, separate marketing databases from compliance records and remove information after the legal retention period. These steps are particularly important for small retailers and service providers that rely on cloud platforms without fully understanding how identity data travels through them.

Public policy should reward restraint. Privacy impact assessments should examine the possibility of correlation, function creep and exclusion, rather than treating a checkbox as sufficient. Digital identity accreditation should test unlinkability, transparency and recovery. Individuals should have clear rights to access records, correct errors, challenge automated decisions and know when their identity has been used.

The broader principle extends beyond government forms. Persistent identifiers make people legible to institutions, advertisers and data brokers in ways that can narrow freedom of movement and thought. A person who expects every action to be connected may behave differently, avoid legitimate services or accept intrusive monitoring as unavoidable.

A safer identity system will not be defined by the number printed on a card or stored in an app. It will be defined by purpose-bound credentials, short-lived proofs, limited retention, independent accountability and practical control for the person being identified. The essential thing to remember is simple: identity should help prove what is necessary for one task, without becoming a permanent record of everything else.