No log, no decision: what Digg's report on the digital social contract means for private firms

Share

Digg's new report on the social contract in a digital transition moves the definition of trust from something institutions are granted to something they have to be able to prove, and that standard will not stop at the edge of the public sector. If you run a law firm, an advisory practice, or a family office in Sweden, the question is no longer whether your client files look orderly, but whether you can produce the evidence chain behind each one.

This piece sets out what Digg actually argues, what changes when Digg and PTS become a single agency on 1 January 2027, and what a firm should be able to evidence before that date.

Key Takeaways: Digg's Digital Social Contract and Private Firms

  • Digg reframes trust as provable practice rather than assumption, and invokes the administrative-law principle "no log, no decision": a decision that is not properly documented is not treated as valid or as having occurred.
  • The report places suppliers inside the contract, not outside it, with a duty to provide auditable and interoperable solutions — a higher bar than being compliant.
  • From 1 January 2027, Digitaliseringsmyndigheten puts eIDAS supervision and the state's identity building blocks inside one agency, so the reference standard for identity assurance gets set once and applied in both directions.
  • The EUDI wallet becomes a channel, not a substitute for the firm's own evidence: whoever holds the client relationship still has to show who was verified, how, when, and against which document.
  • Trust Circle produces the record Digg's test asks for — regulated identity, per-user access logs, EU-hosted storage, and qualified signatures as part of the file rather than the whole of it.

What is Digg actually saying about trust?

Digg's argument is that legitimacy in a digital era can no longer rest on institutional trust alone. The report describes a shift from trust as an assumption to trust as provable practice, supported by logging, traceability, explainability, benefit auditing, and clear chains of accountability. The social contract, in Digg's reading, is not broken and has not been replaced. It is being renegotiated, gradually, through the practical conditions of how rights, obligations, legitimacy, and responsibility are actually organised.

The sharpest formulation sits in a footnote. Digg invokes an established principle of Swedish administrative law and IT security, no log, no decision: a decision that has not been properly documented is not treated as valid or as having occurred. The report's point is to scale that principle up to automated decision-making, so that decision logs, reasoning, and version history are available both to the individual and to internal and external review before automated systems can be introduced legitimately.

Read that principle from the private side and it stops being abstract. When a supervisor, a court, or a counterparty asks how a client was identified, an assurance that the firm has always been careful is not an answer. The record is the answer, or there is no answer.

Why does a report about the state concern a private firm?

Because Digg assigns the private sector a role inside the contract rather than a position outside it. The report splits responsibility across the state, sector agencies, regions and municipalities, business and suppliers, civil society, and residents. The supplier role is defined as developing and providing auditable and interoperable solutions that operate within open and competition-neutral frameworks. Auditable is a higher bar than compliant. Compliant is a claim about a system's design. Auditable is a claim about what the system can hand over when someone asks.

Digg is also explicit that residents need better ways to identify themselves, use verified attributes, and sign digitally in both public and private contexts. The state is not building identity infrastructure only for its own counters. It is setting the reference standard that private relationships will be measured against.

There is a gap here worth naming. Across the Trust Circle pilot, run with six organisations spanning legal, advisory, and investment work, not one participant was actively sharing documents with clients through a controlled channel. Portals existed, and were used occasionally for large matters. Day to day, client documents still moved by email. That is the distance between what firms are assumed to do and what they can currently evidence.

What changes when Digg and PTS become one agency on 1 January 2027?

Supervision and standard-setting move into the same organisation. The government confirmed on 18 May 2026 that the merged authority will be called Digitaliseringsmyndigheten from 1 January 2027, with Digg wound up and integrated into PTS, and operations continuing at existing locations.

The part that matters commercially is rarely mentioned in coverage of the merger. PTS is Sweden's supervisory authority for trust service providers under eIDAS and publishes the Swedish trusted list of qualified providers. From 2027, the authority that audits qualified trust services will sit inside the same agency that owns the state's common building blocks for identity, authorisation, and logging. As a qualified trust service provider supervised by PTS and listed on the EU Trusted List, ZealiD operates under Article 13 of the eIDAS Regulation, which places liability for damage on the provider rather than the relying firm. That relationship does not change on 1 January. What changes is that the definition of adequate identity assurance will increasingly be set once and applied in both directions, to public building blocks and to the suppliers audited against them.

Digg frames the merger as an institutional response to the line between digital administration and digital infrastructure becoming less distinct, and is candid about the risks: culture clashes, shifting focus, unclear division of responsibility, and one logic temporarily crowding out the other. For firms procuring identity infrastructure in 2027, that argues for choosing suppliers whose standing is already documented, rather than suppliers whose status depends on an agency transition landing smoothly.

Does the EUDI wallet solve identity for professional firms?

Not on its own, and Digg says so directly. The report states that the wallet is not itself an eID, though it can be used for electronic identification, electronic signatures, and the sharing of verified attributes, and that the benefit to residents depends heavily on which digital interactions it can be used in and which attributes it actually carries.

The timeline supports the caution. Under Article 5a of Regulation (EU) 2024/1183, each Member State must provide at least one European Digital Identity Wallet by 24 December 2026, with acceptance obligations for regulated relying parties following roughly a year later. A notification deadline is not a functioning ecosystem, a point we set out in more detail in our reality check on EUDI wallets for private providers.

For a professional firm the practical conclusion is narrow and useful. The wallet will become a channel, not a substitute for the firm's own evidence. Whoever holds the client relationship still has to show who was verified, how, when, and against which document.

What does an "agent-driven public encounter" mean for signing?

Digg devotes a chapter to what happens when AI agents begin initiating matters, submitting information, and following processes on a person's behalf. The report's conclusion is that the decisive question stops being which portal or app the individual entered through, and becomes whether the infrastructure behind the encounter is standardised, secure, and traceable enough for public and private agents to act legitimately. Identity binding, delegation, logging, and attribution become the load-bearing elements, because otherwise technology reshapes the relationship while the accountability chain stays behind.

That is the same problem a firm already has, in miniature. A client instructing an assistant, a colleague, or increasingly a software agent to approve a document produces an action in a system. A click proves a session was open. It does not prove who was behind it.

This is where a common assumption in Swedish firms breaks down. A BankID login returns a name and a personnummer. It does not return the identity document behind that name, its expiry date, a photograph, or evidence of liveness at the moment of verification. Firms treat it as identification. It is authentication against a register, which is a different thing, and the difference is exactly the evidentiary gap that surfaces when a file is challenged. The same reasoning applies to signatures, which we covered in what happens when you cannot prove who signed a document.

What does the shift look like inside a client file?

Element Trust as assumption Trust as provable practice
Client identification BankID login, or a scanned passport received by email Verified identity with document, expiry, photograph, and liveness evidence retained as a verification report
Document exchange Email attachments, portal used occasionally for large matters Controlled workspace with per-user access rights and a retrievable access log
Signature Click-to-accept, or an image of a signature applied to a PDF Qualified electronic signature with a qualified certificate naming the signatory
Delegation Inferred from context and correspondence Recorded: who acted, on whose behalf, under what authority
Storage Distributed across mailboxes, drives, and a shared folder Known location, known operator, documented retention
Evidence at audit Reconstructed from memory and email threads Produced from the record

The left column is not negligence. It is how most well-run firms operate today. The point of Digg's framing is that the left column stops being defensible once the right column becomes the reference standard.

What happens if you cannot show the chain?

2027 is the year both timelines arrive. Digitaliseringsmyndigheten stands up on 1 January. The Anti-Money Laundering Regulation (EU) 2024/1624 applies from 10 July, harmonising customer due diligence obligations directly rather than through national transposition.

The consequences are specific. A file that cannot show how identity was established is not a defensible file, and the exposure sits with the firm rather than with whichever tool it used. Passport copies sitting in an email inbox are a personal data incident waiting to be reported, not merely untidy practice. And visual inspection of an identity document has quietly stopped carrying weight, because a convincing forged document is now cheap to produce and a scan strips away every physical security feature the document had.

The honest counterpoint, which we hear often, is that clients are not all digitally mature and that one-off matters make structured onboarding feel disproportionate. That objection is real. It also points at the widest part of the gap, because the one-off client is precisely the one who will not be available to help reconstruct the file two years later when someone asks how they were identified.

What to do next

Four questions, answerable this week without a procurement process:

  1. For any client opened this year, can you produce the identity evidence itself, rather than the fact that identification took place?
  2. Does your document exchange leave a retrievable access log per user, or does it leave an email thread?
  3. Is your signature level the one that holds where the document will actually land, whether that is Bolagsverket, a court, or Finansinspektionen?
  4. Do you know where client documents are physically stored and who operates that infrastructure?

Where the answers come back thin, the gap is usually structural rather than procedural. Trust Circle exists for that case: a client portal built on regulated identity, per-user access control, document storage on ZealiD's own infrastructure in Sweden, and qualified electronic signatures as one component of the record rather than the whole of it. The output is a file that answers Digg's test on its own terms, which is that the record exists and can be produced.

References

  • Myndigheten för digital förvaltning (Digg). "Samhällskontrakt i digital samhällsomställning: Perspektiv på sammanslagningen mellan Digg och PTS." Perspektiv på digitalisering, utgåva 3, 10 September 2026. Dnr 2026-06355. digg.se
  • Regulation (EU) No 910/2014 (eIDAS), Article 13. European Union, 2014. eur-lex.europa.eu
  • Regulation (EU) 2024/1183 (European Digital Identity Framework), Article 5a. European Union, 2024. eur-lex.europa.eu
  • Anti-Money Laundering Regulation (AMLR), Regulation (EU) 2024/1624. European Union, 2024. eur-lex.europa.eu
  • Regeringskansliet. "Digg och PTS blir Digitaliseringsmyndigheten." 18 May 2026. regeringen.se