Quasa
Use QUASA App
Join the pioneer of Web3 crypto freelancing today!
Open
Technology

China’s Digital ID Reaches 40 Million People but Remains Voluntary

|Updated: |Author: QUASA Editorial Team|6 min read| 3337
China’s Digital ID Reaches 40 Million People but Remains Voluntary

China’s national online identity system has moved well beyond its initial rollout. A July 2026 government anniversary account lists 40 million digital-identity holders, 90 million app downloads, 280 million authentication requests and connections to more than 530 apps, websites and mini-programs; these are government figures rather than an independent measurement.

The central qualification has not changed: the credential is not compulsory under the published framework. The national identity-authentication rules, effective July 15, 2025, make applications voluntary, encourage rather than universally require platforms to connect, and require equivalent service for people verified through another lawful method. China has therefore established a widely used state authentication layer, not a legally exclusive key to the internet.

What the national credential does

The system is formally called the National Online Identity Authentication Public Service. It issues a web number, an alphanumeric identifier containing no identity information in plain text, and a web certificate that carries the number and identity information in a non-plain-text form.

A connected website or app can use the national platform to establish that a person has passed real-name verification. If the service needs only an authentication result, the platform is meant to return that result rather than the person’s legal identity document. The arrangement places a government-run intermediary between the user and participating services that would otherwise perform their own checks.

Once a user successfully authenticates with the national credential, a connected platform generally cannot demand the same person’s plain-text identity information as well. That restriction has exceptions where another law requires the information or the user consents to providing it. The public platform can also supply an age marker when a service needs one to meet obligations involving minors or older users.

Voluntary enrollment can still produce broad reach

The legal design preserves choice at several levels. Individuals decide whether to apply, online platforms decide whether to connect, and government bodies and designated industries must retain an existing or other lawful verification route. A person who does not use the national credential is still entitled to equivalent service after completing another permitted identity check.

This distinction corrects two common descriptions of the original rollout. China did not require every internet user to obtain the credential, and the measures did not order every platform to adopt it. What entered force was a nationwide regulatory and technical framework capable of serving many unrelated platforms.

Its practical reach is nevertheless consequential. The service now appears in social, retail, transport, financial, medical and public-service settings, making it more useful to people and institutions even without a universal mandate. Convenience and widespread institutional adoption can turn an optional authentication method into an important part of everyday digital infrastructure.

That possibility is different from legal compulsion. The meaningful questions are whether alternative routes remain genuinely accessible, whether non-users receive equivalent treatment and whether connected platforms stop collecting identity details they no longer need. Adoption totals alone cannot answer those questions.

The privacy benefit is specific, not absolute

The strongest privacy case for the system is data minimization at participating businesses. A company may be able to establish that a user has been verified without storing a readable copy of the person’s identity card, legal name or document number. That could reduce the number of commercial databases exposing directly identifiable information when records are leaked, stolen or improperly used.

The framework also limits what the central platform is supposed to collect and do. Collection is restricted to information necessary for authentication, sensitive information requires the relevant consent, and users must be told the purpose, method and retention period for processing. Personal information must be deleted when required by law or requested by the user, while important data and personal information handled by the platform are generally stored inside China.

These safeguards do not make users anonymous. The platform establishes a relationship between a credential and a verified legal identity, and the credential provides another way to satisfy real-name requirements that already apply in regulated online settings. The change concerns who performs the verification and what information a connected service receives, not whether the underlying person can be identified.

Why centralization remains the main concern

The same architecture that can reduce identity-data collection by private companies concentrates authentication within state-controlled infrastructure. A common credential used across unrelated services creates a powerful point of trust and administration. Its published purpose limits matter, but exceptions tied to other laws and administrative requirements leave uncertainty about access, logging and enforcement in practice.

ARTICLE 19’s assessment argues that centralized authentication could expand surveillance and censorship in an internet environment already governed by real-name requirements. Its concern is especially acute for journalists, lawyers and rights defenders, for whom separating activities or identities can reduce exposure to retaliation.

That structural risk should not be converted into claims the available evidence does not establish. The measures do not describe a universal registry that records every click, purchase, taxi ride or hotel stay through the new credential. The adoption figures likewise do not demonstrate that every authentication is used for behavioral scoring or that one authority routinely combines activity from all connected services.

The narrower conclusion is still significant: a reusable state credential could make identity relationships easier to connect or act upon if logs, future mandates or access practices allow it. Public rules set formal limits, but they do not by themselves reveal the platform’s complete technical logging architecture or demonstrate how consistently safeguards are enforced.

Scale, rather than a new mandate, is the substantive update

During its first year under the binding framework, the system developed from a nationwide service into authentication infrastructure used across hundreds of digital properties. The app and platform also gained a lighter mini-program route, lowering the practical barrier for people who do not want to open the full application for every interaction.

The central trade-off is therefore sharper than it was at launch. China’s credential can keep readable identity details out of more corporate databases while concentrating verification in a government platform with a growing institutional footprint. Voluntary status answers whether the law formally forces enrollment; it does not resolve whether the system improves privacy overall or increases the state’s capacity to connect online identities.

The evidence supports an expanding national authentication service with a real data-minimization function and a consequential centralization risk. It does not support the stronger claim that the credential is already mandatory for every citizen, that every platform must accept it, or that it records every part of a person’s digital life.

Also read:

Share:

Subscribe to our newsletter

Get the latest Web3, AI, and crypto news delivered straight to your inbox.

0