The Digital Identity: the Global Prospective
The digital identity is nowadays the main issue in Electronic Commerce as long as the challenge the parties to every electronic transaction are facing is to answer two simple questions reliably: Who are you? and How can you prove it?, referring to each other.
In Digital identity management, the ultimate and most efficient tool is the so-called federated identity management. As we have just learned and as it has been clearly depicted [1] “In a federated system, transacting parties can avoid the cost and expense of setting up their own identity management process, relying instead on identification and authentication services provided by trustworthy third parties. And users can avoid the need to obtain separate identity credentials (such as usernames and passwords) for every business they deal with. It is like replacing the need to carry a separate credit card from every business where an individual shops, with two or three credit cards (e.g., a Visa and a MasterCard) that all businesses will accept”.
Once, the main issue was to answer the question: Who is the author of an electronic document? Who is bound by it or responsible for it? and the answers were the electronic signatures and their management.
But as the opportunities to interact and establish economic relationships via Internet grow – and as a vast number of economic transactions are entered into without a proper electronic document – the main point has become the assessment of each party’s identity and therefore the identity management.
A variety of approaches may be taken to implement such management of the identity of individuals.
The USA approach, as we have heard, relies on the contract and on “soft law”, encouraging the private sector to set its own rules on the topic [2].
On the contrary, the European Union has preferred “hard law” and since the end of the last century has provided a complete set of rules to furnish parties that had never met before with the mutual assurance of each one’s digital identity. The legal framework moved forward from EU Directive 1999/93/CE on electronic signatures to the recent regulation (EU) no. 910/2014 of the European Parliament and of the Council of 23 July 2014 “on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC” that is due to apply, for the most part of it, from 1 July 2016.
These different approaches do not surprise.
In a simply way we can depict that as the different traditional attitudes of the two legal systems toward lawmaking. Montesquieu’s theory of the separation of political power among the legislature, executive and judiciary – which was the political background of the French Revolution – led to the idea of a civil code as the whole and entire summary of rules in private law arising from the people’s representatives. This feature of a civil law system involves a particular attitude and approach for the civil lawyer toward contract: on one hand, the parties to a contract may agree on the basic elements of the deal – e.g. price and item purchased – while the civil code will provide the entire set of rules to solve any dispute which may arise and any aspect of the deal not covered by an express agreement; on the other hand, civil lawyers are less likely than common lawyers to rely on contract to solve general problems, trusting better the intervention of lawmakers.
On the contrary, common law lawyers, on one hand, not having the possibility to fill the gaps in contract with rules “subject to agreement otherwise” because of the lack of a code, are used to drafting contracts intended to be self-sufficient, not to leave room for judge-made rules [3] and, on the other hand, have developed a stronger attitude to recourse to the contract to set erga omnes or at least multi party rules that meet the market’s need.
As a consequence, it is more natural for a common law lawyer to suggest using a contract – and, in this case, a multi-party contract or a contract open to other parties to adhere to [4] – to regulate also the management of digital identity. And in some way this can be regarded as an evolution of the electronic data interchange EDI [5] that constituted the basic framework of B2B electronic commerce in the Eighties.
The “hard law” approach has been chosen also by the People’s Republic of China. Art. 2 of the 2004 Electronic Signature Law (ESL) of the People’s Republic of China [6] provides a definition of electronic signature, with the same approach and broad content of EU Directive 1999/93/CE: “For the purposes of this Law, electronic signature means the data in electronic form contained in and attached to a data message to be used for identifying the identity of the signatory and for showing that the signatory recognizes what is in the message. The data message as mentioned in this Law means the information generated, dispatched, received or stored by electronic, optical, magnetic or similar means“.
And the reliability of an electronic signature is considered in art. 13 of China ESL [7] in the same manner as UE Directive 1999/93 CE.
The material convergence on digital identity management therefore appears to be stronger than the formal different approaches.
