What It Means to Own Your Digital Identity
Ownership implies you can hold something, transfer it, or destroy it at will. Almost nothing about how digital identity actually works fits that model — which raises the question of whether "ownership" was ever the right word for it.
A strange thing happens if you try to actually locate your digital identity. Not describe it — locate it, the way you could point to a physical object and say "there, that's mine." You'll find fragments: a login here, a verified email there, a photo tagged by someone else on a platform you barely use, a credit history held by three companies you've never spoken to. Nowhere in that scattering is there a single thing you could point to and call, unambiguously, yours.
This matters because "ownership" is the word almost everyone reaches for when talking about digital identity, and it may be quietly the wrong word — not because ownership is too strong a claim, but because it imports assumptions from physical property that don't map cleanly onto what identity actually is or how it behaves online.
What ownership normally requires
Ownership, in the everyday sense, implies a cluster of powers: you can possess the thing, exclude others from it, transfer it to someone else, and destroy it if you choose. A book on your shelf satisfies all four. You have it, you can stop anyone else from taking it, you can give it away, and you can burn it if you're so inclined.
Apply this test to your digital identity and the picture falls apart quickly. You don't possess it in any singular sense — it exists as claims made about you, scattered across databases you don't control. You can't fully exclude others from it — a facial recognition system can identify you in a photograph you never consented to be in. You can rarely transfer it — try moving your reputation on one platform to another and see how much survives the trip. And you very often cannot destroy it — "right to be forgotten" requests exist precisely because deletion turned out to be far harder than creation, both technically and legally.
If digital identity fails all four tests for ownership, calling it "yours" in the ownership sense is closer to a hopeful metaphor than an accurate description.
A different frame: identity as testimony, not property
A more accurate frame might be this: digital identity isn't a possession, it's an ongoing set of claims made by various parties — sometimes you, more often institutions — about who you are and what you've done. Your bank makes a claim about your creditworthiness. A platform makes a claim about your engagement history. A government makes a claim about your citizenship. None of these claims live "in" you the way a possession would. They live in the systems of whoever is making the claim, about you, on your behalf, or sometimes despite you.
This reframing changes what "control" would even mean. If identity is testimony rather than property, the relevant question isn't "how do I own this" but "whose testimony is authoritative, and can I contest it when it's wrong." Anyone who has tried to correct an error on a credit report already knows the answer in miniature: the claim was never really yours to control in the first place, even though it was unmistakably about you.
Where self-sovereign identity tries to intervene
This is the gap that "self-sovereign identity" systems — a growing area of work using cryptographic credentials rather than centralised databases — are trying to close. The idea, at its simplest, is to let a person hold a verifiable credential directly (a proof of age, a proof of qualification, a proof of membership) and present it selectively, without a central authority needing to be consulted every time the claim is checked, and without that authority accumulating a log of every place the claim was used.
This doesn't fully solve the ownership problem — a credential still has to be issued by someone in the first place, and issuance is itself a form of authority. But it does shift meaningful power: from "the issuer must be asked every time and knows everywhere you've used this" to "the issuer is consulted once, and after that, you hold the proof and choose when to show it." That's a real difference in kind, even if it isn't full ownership in the classical sense. It's part of the specific problem a messaging system currently in development at Openmind is trying to work on — cryptographic, self-held identity rather than a centrally-issued one — though it's still early enough that there isn't much to show yet.
Why the metaphor still matters, even if it's imperfect
None of this means people should stop saying "own your identity" — language evolves useful shorthand for complicated things, and the phrase does real work in signalling that something has gone wrong with how much control individuals currently have. But it's worth knowing, underneath the shorthand, that the actual shape of the problem isn't "someone stole my property." It's closer to: "many parties are making claims about me, I have limited visibility into most of them, and correcting a false one is far harder than it should be."
That's a less tidy problem than theft, and it doesn't have a single tidy solution. But naming it accurately is the first step toward the more modest, achievable goal that's actually available: not full ownership, which may not even be coherent for something like identity, but better visibility into the claims being made, and a real mechanism to contest the ones that are wrong.
Frequently asked questions
Can you actually own your digital identity in a legal sense?
Not in the way you own physical property. Digital identity mostly exists as claims made by third parties — banks, platforms, governments — and ownership in the classical sense (possess, exclude, transfer, destroy) doesn't cleanly apply to claims made by someone else about you.
What is self-sovereign identity?
An approach where a person holds verifiable credentials directly and presents them selectively, rather than a central authority being consulted and logging every use. It shifts power without eliminating the need for an initial issuing authority.
Why is it so hard to correct wrong information about yourself online?
Because the claim usually lives in someone else's system, governed by their process, not yours. You're not editing your own record — you're petitioning whoever holds the authoritative version to change theirs.
Is deleting your digital identity actually possible?
Rarely completely. Data is often copied, cached, or referenced elsewhere before a deletion request is honoured, and "right to be forgotten" processes exist precisely because full deletion turned out to be much harder than simple creation.
Does blockchain solve the digital identity problem?
It can help with specific pieces — verifiable, tamper-resistant credentials you hold rather than a company holding on your behalf — but it doesn't solve the underlying issue that someone still has to issue the credential in the first place.