King’s Speech 2026: digital ID and EU alignment

In short: The King’s Speech 2026, delivered on 13 May 2026, announced two Bills that reach regulated firms: the Digital Access to Services Bill, which puts the government’s digital ID scheme on a statutory footing alongside Part 2 of the Data (Use and Access) Act 2025, and the European Partnership Bill, which legislates for closer trading ties with the European Union. Neither has yet been introduced in Parliament.
Employers will have to check a government digital ID before someone starts work, and they will have to do it before this Parliament ends. That is the sharp end of the Digital Access to Services Bill, one of two Bills in the King’s Speech 2026 that reach telecoms operators, payment firms and data controllers. The other, the European Partnership Bill, legislates for closer trading ties with the European Union. Neither Bill has been introduced yet, so what follows separates what the government has committed to from what it has not.
What the Digital Access to Services Bill does
The Bill puts the government’s digital ID scheme on a statutory footing. The King’s Speech commits Ministers to “proceed with the introduction of Digital ID that will modernise how citizens interact with public services”. The scheme itself is already described in some detail: it is free to the individual, the credential sits on the user’s own device, and the government expects to reach all UK citizens and legal residents by the end of this Parliament (Department for Science, Innovation and Technology, Digital ID scheme: explainer, updated 18 March 2026).
It is not a voluntary credential in every setting. That explainer states that the digital ID “will also be required for right to work checks”, and that “it will be a legal requirement for employers to check your digital ID as proof of your right to work”. The credential will carry name, date of birth, information on nationality or residency status, and a photograph as the basis for biometric security. The consultation is considering whether to add address. Police will not be able to demand to see it.
The Data (Use and Access) Act 2025 machinery the Bill builds on
Most of the regulatory architecture is already enacted. Part 2 of the Data (Use and Access) Act 2025 secures the reliability of digital verification services through five instruments: a trust framework (section 28), supplementary codes (section 29), a register (section 32), an information gateway (section 45) and a trust mark (section 50). Section 27, which introduces them, came into force on 1 December 2025 under the Data (Use and Access) Act 2025 (Commencement No. 4) Regulations 2025, SI 2025/1213, regulation 2.
The practical consequence is that a provider wanting to serve the digital ID scheme has to reach the section 32 register first, and the trust framework rather than a new authorisation regime does the gatekeeping. The Bill sits on top of that architecture; it does not replace it.
What regulated firms have to do
Three groups carry work. Identity providers have to reach the register in Part 2 of the Data (Use and Access) Act 2025 and hold themselves to the trust framework. Relying parties, meaning telecoms operators taking a digital ID as a customer identity input, payment firms using it in customer due diligence, and platforms using it for age assurance, have to settle their own controller position and their contractual terms with the provider. Employers have to build the right to work check into onboarding.
For all three, identity verification at population scale using a biometric photograph is systematic processing on a large scale, so a data protection impact assessment under Article 35 UK GDPR is the sensible starting assumption rather than an open question, and our DPIA page sets out the scoping. One point deserves care at the design stage. The government’s stated position is that it “will only provide third parties with access to your personal data when you instigate this sharing or it is otherwise permitted under UK data protection laws”. Consent is therefore not the only gate, and a product designed on the assumption that it is will misstate the lawful basis to users. The gating workstream for anyone launching an identity-dependent product is data protection compliance.
What the European Partnership Bill covers, and what it does not
The King’s Speech describes the European Partnership Bill in seven words. It sits in the paragraph on trading relations, as “a Bill to strengthen ties with the European Union”. No text, no scope note and no explanatory material has been published, and the Bill is not before Parliament. What can honestly be said about it comes from the policy package it would implement, the UK-EU Common Understanding agreed at the summit of 19 May 2025.
Three tracks in that document commit the UK to align dynamically with EU rules, and those are the tracks that need primary legislation: possible participation in the European Union’s internal electricity market, a Common Sanitary and Phytosanitary Area covering agri-food, and a link between the UK and EU emissions trading schemes. Each carries the same constitutional design, namely dynamic alignment with EU rules, an independent arbitration panel for disputes, and the Court of Justice of the European Union as the ultimate authority on questions of EU law.
Data protection, telecoms and financial services are not in that group, and nothing in the Common Understanding proposes putting them there. UK adequacy in particular does not turn on this Bill. It rests on the European Commission’s decisions of 28 June 2021 under the GDPR and the Law Enforcement Directive, which the Commission amended by renewal decisions on 19 December 2025. The Common Understanding does carry one item close to this firm’s work, at paragraph 54: the UK and the Commission agreed to examine the difficulty that law enforcement and judicial authorities in one jurisdiction have in obtaining data from electronic communications and other service providers operating in the other. Nothing has been published on how that would be legislated, or on whether the European Partnership Bill is the vehicle.
Two further Bills in the same speech touch this firm’s pillars and are not covered here. The speech announced a Cyber Security and Resilience Bill, as legislation “to improve the country’s defences against cyber-security threats”, and a Regulating for Growth Bill, as legislation “to reduce the burden of unnecessary regulation through innovation”. Neither has been introduced. Both warrant their own treatment.
Viewpoint
Taken together the two Bills show a government legislating on top of machinery it already holds rather than building new regulators. On digital ID it is using the digital verification services regime in Part 2 of the Data (Use and Access) Act 2025, where the register and the trust framework do the work an authorisation regime would otherwise do. In our experience advising firms that depend on third-party identity checks, the binding constraint is rarely the technical standard. It is who bears the loss when a verified identity turns out to be wrong, and neither the Act nor anything published about the Bill answers that.
On Europe, the informative point is where the government has accepted dynamic alignment and where it has not. Electricity, agri-food and carbon are in. Data protection, telecoms and payments are out. I read that as a considered position rather than an omission, and I would not treat the European Partnership Bill as the opening of a wider convergence. What to watch is the introduction of both Bills, because until there is a text the scope of either is inference from published policy rather than law. That is the position this article now takes.
For advice on digital identity, data protection or the UK and EU regulatory position, contact Rob Bratby at Bratby Law.
Correction, 7 August 2026: this article previously described four Bills. Two of them do not exist. An “Enhancing Financial Services Bill”, said here to absorb the Payment Systems Regulator into the FCA, and a “Competition Reform Bill”, said here to replace the CMA Panel with sub-committees of the CMA Board, were not announced in the King’s Speech 2026, are not before Parliament, and are not recorded on gov.uk or legislation.gov.uk. The discrepancy was identified on 6 August 2026 and confirmed against the primary sources on 7 August 2026. Those two sections have been removed and the article rewritten around the two Bills the speech does announce. Every remaining assertion has been re-verified against the full text of the King’s Speech 2026 on gov.uk, the Department for Science, Innovation and Technology digital ID explainer, the Data (Use and Access) Act 2025 on legislation.gov.uk, and the UK-EU Common Understanding. Three further statements were wrong and have been corrected: the digital ID is not voluntary, because employers will be required by law to check it for right to work purposes; the government’s published commitment is to the end of this Parliament, not to 2029; and the European Commission’s UK adequacy decisions of 28 June 2021 were amended by the renewal decisions of 19 December 2025, not superseded by them. A claim that the renewed decisions run until 27 December 2031 has been removed because it could not be verified against the decisions themselves.
Correction, 12 July 2026: this article previously dated the FCA’s Competition Act investigation into Mastercard, Visa and PayPal to 6 May 2026. The investigation opened in March 2026 and was publicly confirmed on 6 May 2026. The passage carrying that reference sat in a section removed by the rewrite of 7 August 2026.
