Kammarkoll

Search everything said in the debates of the Swedish Riksdag

← To the search

Response to interpellation 2023/24:402 on BankID for everyone in Sweden

8 February 2024 · 7 speeches · KD, S

Translated from Swedish by AI; the translation may contain errors. The Swedish text is the original.

Summary AI, written in advance

The debate concerns the need for a state e-identification to increase accessibility and security 1 2. KD argues that a state solution at the highest trust level is necessary to complement the functioning private alternatives 1 2. KD believes it is reasonable for authorities to issue electronic identification to make services more secure, and that companies themselves decide what security is required. S argues that the state should provide e-identification because private actors' control creates inequality and excludes citizens 3. S believes that BankID's dominance constitutes a security risk and an imminent privacy risk 3.

Written by AI in advance and may contain errors. The numbers lead to the speech a statement builds on; check against the text below.

Statsrådet Erik Slottner (KD)

Madam Speaker! Denis Begic has asked how the government will ensure that the use of BankID and other e-identifications meets the highest security standards while simultaneously protecting users' privacy. He has also asked how the government and Sweden are preparing to meet the upcoming technological challenges and innovations in the field of electronic identification and digital services.

The investigation Secure and accessible digital identity (I 2022:04) shall investigate and submit proposals on how e-identifications can be designed and provided at the highest trust level, as well as propose changes resulting from the revised e-IDAS Regulation.

On 16 October, the investigation submitted the partial report A Secure and Accessible State e-ID (SOU 2023:61). In the partial report, a proposal is presented on how a state e-ID at the highest trust level can be designed and provided by a state agency. The purpose of the state e-ID is to contribute to the society's security and robustness, counter fraud, and facilitate digital inclusion. The partial report has been out for consultation with approximately 150 referral bodies with the final response date being 31 January 2023. Now the partial report is being further prepared within the Government Offices.

The revised e-IDAS Regulation, which is expected to be adopted at the beginning of 2024, sets requirements for member states to provide a digital identity wallet. With the digital identity wallet, natural and legal persons shall be able to securely request, receive, store, select, combine, and use personal identification data and digital credentials such as driving licenses, educational certificates, and e-prescriptions. The digital identity wallet will be able to be used in all public actors' e-services and in certain private e-services. The digital identity wallet will also be usable in other EU countries and, just like the state e-identification, will be provided at the highest trust level.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Denis Begic (S)

Madam Speaker! I thank the Minister for the answer.

The reason I submitted the interpellation was that I recently submitted a motion regarding state control over BankID. I have received a number of reactions from people who have not been granted BankID and therefore cannot identify themselves. In today's Sweden, BankID is an incredibly important tool for being able to conduct banking transactions and much more. It is therefore serious that a private actor decides who gets and does not get BankID. It should be the state that provides this.

In an increasingly digitized world where we not only log in to social media but also pay our bills online, it is important to find a balance between security, efficiency, and privacy for the citizens. It is crucial for protecting them. The current situation, where access to e-identification is largely determined by private actors, creates inequality and excludes many, especially the elderly and persons with disabilities. Therefore, I strongly support what the Minister of Justice has set out here, namely the state e-identification.

Another aspect is the privacy risk. BankID, which is central to our digital world, is owned by the banks, who can decide who should receive BankID and who should not. The risk of data breaches and for misuse of the information that they access when you log in and out and do everything else is, of course, imminent.

The Swedish Financial Supervisory Authority has correctly pointed out that the dominant position that BankID has, as well as its central role in many of our societal functions, constitutes a security risk. This underscores the need for us to take greater responsibility for the security of our digital systems, especially in light of the threat profile that nevertheless exists against Sweden and Swedish citizens.

I have not looked at all 150 referral responses, but I have looked at a good number of them. Some say nothing, and then there are some that have opinions. I therefore think it is important that the government and the Council of State take this most seriously when they are now going to enter into this work.

I therefore asked these questions about how we protect ourselves against attacks and about what we do to ensure that BankID is not the only possibility to log in to the bank or to the Swedish Tax Agency, gambling sites, or whatever it may be. It is incredibly important that we have systems that are robust.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Statsrådet Erik Slottner (KD)

Madam Speaker! I believe that this interpellation debate might possibly become something more sensible, I was about to say, than the previous one. I still, after hearing Begic's contribution, make the assessment that we are in very much agreement. I completely agree that e-identifications are incredibly important, and that they are secure is naturally completely crucial. This creates very good conditions to be able to perform ever more transactions on the internet in a secure and reliable way.

It is also important that they maintain the highest level of trust. It makes online authentication safer. We know that many use hijacking of e-identifications as a way to defraud people, not least the elderly. It is, I think, incredibly heartbreaking to hear all the stories we receive.

For this reason, we appointed this investigation very early, almost immediately after I became Minister for Civil Affairs. I believe it was the first investigation I appointed. It was to produce proposals on how a state e-identification at the highest trust level could look and be designed. We have received a partial report with concrete proposals, but we are still awaiting the final report - I believe it is to be released on May 31.

Sweden is today one of four countries in the EU that lack an e-identification at the highest trust level. The e-identifications we have today, BankID, which is the dominant one, and Freja, where you do not need to have a bank account to access the service, do not meet the requirements for the highest trust level.

The Government also makes the assessment that it is reasonable for it to be a state authority that issues a state e-identification, just as it is a state authority that issues passports and other national identity documents, for example, driver's licenses. The private actors that exist on the market have furthermore not shown interest in offering an e-identification at the highest trust level. I think it is important to say that Bank-id and Freja support the proposal for a state e-identification. It should therefore not be seen as a competitor to the private alternatives that currently function very well, but as a complement and a way to make the private alternatives even more secure.

I also think it is worth mentioning, as I did initially, that this e-identification at the highest trust level shall also enable an introduction of the digital identity wallet within the EU, which shall allow us to identify ourselves digitally in a easier and smoother way throughout the union. This will facilitate traveling, living, seeking healthcare and whatever it may be throughout the union.

I will also add that the government is not resting on its hands. We allocated 40 million SEK to Digg, the Agency for Digital Government, which will begin to design and develop such an e-identification. We are therefore not even waiting for the final report before allocating funds, but we are allocating funds already in 2024 to prepare the development of a state e-identification.

The government is, therefore, working hard on this issue. It is a priority issue for the government, and I completely share the assessment that Sweden needs a state e-identification at the highest trust level.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Denis Begic (S)

Madam Speaker! I do not know how the previous debate went, but I have no reason to be either angry or puzzled about what is happening. For me, what is happening now in Sweden is important; therefore, I posed this question.

I receive emails from citizens stating: It is incredibly difficult for me, because I committed a crime nine years ago and cannot get a BankID or perform the public services that a good citizen should be able to perform. Therefore, it is important for me to ask the Minister where we stand in this discussion.

I asked two questions, and I believe I have received answers from the Minister - for that, I thank you. The second question concerns the technology and how we are to proceed. Technical innovations are moving incredibly fast. We saw yesterday how people are being defrauded in Sweden; the Minister may have followed Uppdrag granskning. It was frightening to see. Technological development sometimes outpaces us. Neither politics nor society can actually keep up. Therefore, we must be very innovative.

I therefore asked the question of what the government is doing so that the innovative sector in Sweden, which is so good, can continue to be the best in the world. There are, of course, things that are crucial. It is about the legislation, and it is about how the government helps with the new innovation centers that are to come. But it is also about how important it is that we quickly adapt to the security risks we are aware of. Who believed just a few years ago that it would look the way it does in the world today?

We are vulnerable; we see that daily. Sometimes when you are going to log in with BankID, you are told that you cannot do so at that moment because something has happened, and most often we do not know what.

I have also, Minister, read that neither Freja nor BankID have any objections. The problem is that for logging into any bank, only BankID and nothing else applies. We must consider whether it is reasonable or unreasonable that a certain type of service from a private owner is required to log into the bank.

I hope it is not this they are after. We know that it is logged. Even though they probably have good control, we know that it is possible to see where people have logged in from, which device has been used, whether one was in Sweden or abroad, what it looked like and so on. In that way, it is possible to track where people are.

What are these logs used for? I cannot answer that, because it is not something one discloses; they are probably trade secrets. It probably concerns things in order to be able to provide us with additional services that we might need. I would therefore be incredibly grateful if I had a government bank-id that I can log in with at any bank I want, where one only has the right to see my identity document and not where I am, what I look like, and so on. I hope that the Minister understands what I mean.

Sweden's future in the digital era depends on our ability to adapt, learn, and also cooperate with other countries. The technical challenges we will face should be a high priority for Sweden - and I am pleased that the government responds accordingly. We have nothing else to say than that we must protect our citizens, not only against external threats but also against id-threats, one could say.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Statsrådet Erik Slottner (KD)

Madam Speaker! I can almost go home and celebrate with champagne tonight! I believe it is the first time an interpellator has said that he or she is satisfied with the answer I have given to the interpellation. I thank you very much for that acknowledgment.

One of several reasons why we are now introducing a state e-identification is precisely accessibility: that all citizens should be able to gain access to an e-identification even if one, for example, lacks a bank account number. One should not be dependent on perhaps one or two private alternatives in order to be able to obtain an e-identification; instead, this shall be something the state can offer. The accessibility argument is therefore one of many reasons to introduce this.

BankID has nevertheless functioned very well. It was procured during the early 2000s because it was seen that the banking sector was very well suited to issue e-identifications. This has contributed to Sweden's deep and very advanced digitalization and has resulted in 94 percent of the Swedish people - one of the highest proportions in the world - using the internet every week and performing many of their services digitally. BankID has thus been incredibly important for digital innovation and digital participation in Sweden. We must nevertheless give them credit that this has served Sweden well.

One can always think that it is a problem that there is a dominant actor, but as said, there is also Freja. Then, one cannot force private actors to start e-identifications, and I believe that the dominant position that Bank-id has is due to it being a well-functioning service that has been demanded by the Swedish people. Furthermore, it is all the major banks that operate and stand behind Bank-id. Now, as said, comes the state complement, which I hope will become widespread.

Denis Begic broadens the debate on cybersecurity in general and how we should protect ourselves. I just want to say that the cybersecurity issues are on the desk of Civil Defence Minister Carl-Oskar Bohlins and that the banks' e-identification is on the desk of Financial Markets Minister Niklas Wykman. I just want to get this said. I can still comment on some parts.

A lot of work is underway to strengthen Sweden's cybersecurity, but we will need to do much more. One thing I can mention is the formation of a cyber campus at KTH, Kungliga Tekniska högskolan, which will be an important contribution to this.

Two weeks ago, the government decided to give PTS, the Swedish Post and Telecom Authority, expanded mandates to strengthen our defense against so-called hybrid attacks against electronic communications, with a particular focus on submarine cables.

We have within the EU negotiated the cyber resilience act, which shall certify all products that can be connected, which today are significantly more than what we think of in our everyday lives. This is a way to strengthen cyber resilience.

I am convinced that with the development we see today within AI, artificial intelligence, we will be able to use AI technology as a way to detect cyber threats. This is something that I really hope will be able to happen, and I also believe that it will happen. The government is working in a broad field of areas to strengthen AI development. Not least the AI Commission is an important contribution in this work, but as was said, more will be needed.

Begic mentioned the heinous frauds that occur, not least against many of the country's elderly. There, we have given an additional assignment to the Consumer Agency to return with proposals on how we can strengthen the protection even further. Here, the Ministry of Justice's many measures also play a major role.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Denis Begic (S)

Madam Speaker! I am glad that the Minister can celebrate with champagne tonight. I do not intend to do that, because there will surely be some other interpellation debate where we will get angry at each other. Until then, I say that we are absolutely in agreement on this issue. It feels incredibly good to hear this.

I know that it is approximately 8.5 million Swedes who use BankID, but the problem is that BankID has always been dominant. It was the first to be established, and one must definitely give them praise for the digitalization that Sweden has received thanks to their service. I use it myself when I am going to order such a PAP machine that I have for my sleep apnea. It is ordered with the help of BankID, and then it arrives at home.

It is, therefore, a fantastically good service that we have received, but it was many years ago. Now a leap towards something more secure is needed. We need to be at the forefront when it comes to how we secure our citizens, precisely because we currently have a threat situation, both against Sweden as a country, from other actors, and against our citizens. In that case, it is important that we as a country consider how we are to proceed.

Therefore, I have a final question for the Minister, which he may not be able to or want to answer in this situation: Will we need to legislate so that state BankID is also used on the private market? Will it be necessary to open up so that it is possible to log in even with a state electronic ID?

The speech at riksdagen.se, in Swedish (opens in a new tab)

Statsrådet Erik Slottner (KD)

Madam Speaker! Regarding the last question, it will not be a requirement. It depends entirely on what the needs look like. It becomes a bit technical, but BankID speaks of starting by identifying oneself with the state electronic ID. Then, when one is to navigate towards more services, it may suffice to identify oneself with, for example, BankID or other digital identities that may come. I stumbled a bit over the words there, but I have not consumed the champagne yet, if anyone was wondering.

There will be no general requirement, but the state e-identification is a way to meet the requirement of having an e-identification at the highest trust level. We think it is reasonable that state authorities, just as they issue analog physical identities, also have a responsibility to issue an electronic identification. This will make our digital services and identities more secure. It will become more difficult to hack digital identities that are issued by an authority.

Last but not least, it is the various companies themselves that decide which security level is to be required. Not all digital services probably need the highest level of trust, while other digital services need to raise the level of trust. It depends entirely on what types of services are to be performed.

The interpellations debate was hereby concluded.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Source: The Swedish Parliament. The speeches come from the open data of the Riksdag, translated into English by AI, which may contain errors.