A digital wallet must not become digital surveillance

The state application must not develop into a centralized mechanism for profiling, monitoring and connecting citizens through state and private registers, warns Muhamed Gjokaj

6689 views 7 comment(s)
A digital wallet is a positive step, if data protection is at a high level (illustration), Photo: Shutterstock
A digital wallet is a positive step, if data protection is at a high level (illustration), Photo: Shutterstock
Disclaimer: The translations are mostly done through AI translator and might not be 100% accurate.

A digital wallet offered to citizens by the state and which would bring together a wide variety of personal documents, certificates, etc. in one place, in a mobile application, could be a useful, modern and European-compliant solution, only on condition that personal data protection standards are established and fully respected.

"Digitalization must not take precedence over the protection of citizens' fundamental rights, but must be built on these rights," he said. Muhammad Gjokaj, an expert in the field of personal data protection.

In an interview with "Vijesti", he commented on the Law on Electronic Identification and Services, in the context of standards, the Law on Personal Data Protection GDPR, and the LED Directive.

The Parliament adopted the Law at the end of June, and this regulation, among other things, also provides for the introduction of the Digital Wallet of Montenegro. Such a service, as planned, could be available from 2028, with the previously adopted law itself and the adoption of about 40 by-laws, which will be necessary for its implementation. The Ministry of Public Administration (MPA) announced that the digital wallet would be a mobile application that would unite personal documents in one place, such as a driver's license, health card, etc.

"The MPA initiative towards the digitalization of public services, the introduction of a digital wallet and the development of electronic identification of citizens are an important and positive step towards the modernization of public administration, more efficient exercise of rights and bringing Montenegro closer to European digital standards. Such solutions, if properly normatively, technically and institutionally set up, can significantly facilitate the everyday life of citizens, reduce administrative barriers and improve the quality of public services. However, support for innovative digital solutions does not mean that such a sensitive area can be entered without a previously clearly built normative platform that will guarantee lawful, transparent, limited and secure processing of personal data," Gjokaj told "Vijesti".

According to him, before the full implementation of the digital identity system, the state must provide a legal framework that will guarantee citizens that they know what their data is being processed, who accesses it, on what basis, for what purpose, how long it is kept, and what legal remedies are available to them in the event of misuse.

Voluntariness does not mean weak protection

Gjokaj referred to the part of the regulation that states that the use of the digital wallet, which will be free for citizens, is voluntary.

"The fact that the digital wallet is announced as a voluntary platform does not mean that citizens' personal data can be used unlimitedly, without clear procedures, without control, and without precisely defined responsibilities of data controllers, processors, and users," he said.

As he added, the voluntary use of the application does not relieve the state of the obligation to establish in advance the highest standards of data protection, information security, access control, processing records, and independent oversight.

"Therefore, digitalization should not be viewed only as a technological project, but as a legally, institutionally and security-sensitive system that must be based on full compliance with the Personal Data Protection Act, European standards, the principles of data minimization, purpose limitation, transparency, accountability and data protection from the very design of the system. Only in this way can a digital wallet be simultaneously modern, useful and secure for citizens," he says.

Gjokaj said that the most important issue regarding the introduction of a digital wallet in Montenegro is not exclusively technical in nature nor does it boil down to the functionality of the application itself, but that it primarily relates to the lawful, limited, secure and transparent processing of citizens' personal data.

"In principle, I support the introduction of innovative digital solutions and applications that can facilitate citizens' access to public services, reduce administrative procedures and enable faster exercise of rights. However, the mere fact that a certain technological solution is modern, useful or practical does not mean that the state can easily embark on the development of a normative framework without previously clearly established basic rules for the protection of personal data," he said, adding that, before introducing such a sensitive system, it is necessary to first provide a solid basic norm, or lex generalis in the field of personal data protection, fully aligned with the General Data Protection Regulation GDPR.

"Only after that, special laws, including regulations on electronic identification, digital wallets, electronic services, registries and data exchange, can be legally and systematically upgraded as lex specialis," said Gjokaj.

Positive step, but...: Gjokaj
Positive step, but...: Gjokajphoto: Savo Prelevic

According to him, a clear distinction should be made between the general data protection regime, which is based on GDPR standards, and the special data processing regime relating to competent authorities in the field of prevention, investigation, detection or prosecution of criminal offences and the execution of criminal sanctions, which is the subject of the so-called LED Directive (EU Directive 2016/680).

"In this sense, a digital wallet as an instrument of public and private electronic services must not be treated as a mechanism for security or police access to data, except in strictly prescribed cases, under clear legal conditions, with judicial, institutional and independent control," says Gjokaj.

Access to data must not be general.

The "Vijesti" interlocutor said that, in addition to a general law aligned with the GDPR, Montenegro must clearly regulate a special legislative framework according to LED standards, i.e. a law that is designated in the public domain as the law on the protection of personal data processed by competent authorities for the purpose of preventing, investigating, detecting or prosecuting criminal offenses or executing criminal sanctions.

"Only when it is precisely known when the general GDPR regime applies, and when the special LED regime, can we talk about a legally secure and European-harmonized digital identification system," said Gjokaj.

According to him, from the point of view of the Personal Data Protection Act and the principles of the GDPR, a digital wallet can be an acceptable solution only if the data controller, data processors and data users, the purpose of processing, the types of data that can be collected, the deadlines for their storage, as well as the conditions and authorizations for accessing data are clearly defined in advance.

"Access to data must not be general, unlimited or automatically available to all authorities. Such access may only be granted to entities that have a clear legal basis, a legitimate purpose and appropriate technical authorisations, and only to the extent necessary to provide a specific service. For example, if a citizen needs to confirm possession of a valid driving licence, it is not justified to request a complete set of personal data if it is sufficient to confirm only the existence and validity of the licence," said Gjokaj.

Of particular importance, he adds, is the application of the principle of data minimization.

"A digital wallet must not become a centralized mechanism that enables unnecessary profiling, tracking, or linking of citizens across various state and private registries. The system should be based on the principle of selective, or limited, disclosure of data, in a way that allows citizens to share only the information that is necessary to achieve a specific purpose," he said.

According to Gjokaj, personal data must be protected by the highest standards of technical and organizational security measures, including encryption, strong user authentication, access records, keeping transaction logs, separation of data according to the purpose of processing, limiting access to employees, regular security checks, risk assessments, and clearly defined procedures for dealing with a security incident or data breach.

“It is necessary to ensure full traceability of data access, including information about who accessed the data, when, on what legal basis and for what purpose,” he explains.

Compliance with GDPR, he said, also implies the application of the principles of "privacy by design" and "privacy by default":

"That is, technical or integrated protection, which means that data protection must be built into the system architecture from the very beginning, and not implemented subsequently. The default system settings should provide the highest level of protection of citizens' rights and privacy," he said.

Detailed assessments before implementation begins

Gjokaj adds that, before putting a digital wallet into operation, it is necessary to conduct a detailed assessment of the impact on the protection of personal data, because, he says, it involves the processing of a large volume of data, including identification data, potentially health data, data on education, qualifications, and other sensitive or significant categories of data.

"Without such an assessment, the system would pose a significant legal and security risk," he says.

When it comes to monitoring the legality of data processing, he said, it should be carried out by the Agency for Personal Data Protection and Free Access to Information, while at the same time, he added, it is necessary to ensure a strong system of monitoring in the field of cybersecurity, "whereby technical protection cannot be a substitute for monitoring the legality of personal data processing."

"A digital wallet can represent a significant step forward in the modernization of public administration only if the citizen remains at the center of the system, with a clear right to know who is requesting their data, for what reason, what data they are requesting, to refuse unnecessary sharing of information, to have insight into the history of their data usage, and to have effective legal remedies in case of misuse," says Gjokaj, adding that all of this can be achieved and a digital wallet can be a useful, modern, and European-compliant solution, "but only on condition that personal data protection standards are established and fully respected."

"Digitalization must not come before the protection of citizens' fundamental rights, but must be built on those rights. Otherwise, a digital wallet would not be an instrument for improving public services, but a potential mechanism for excessive surveillance and uncontrolled linking of citizens' data," says Gjokaj, adding that the legality and justification of a digital wallet "must not be assessed according to the degree of technological sophistication, but according to the level of compliance with the principles of legality, transparency, purpose limitation, data minimization, accuracy, limited retention period, integrity, confidentiality and responsibility of the data controller."

See more: