Queries concerning interoperability between ScotAccount and GOV.UK One Login: FOI release

Information request and response under the Freedom of Information (Scotland) Act 2002.


Information requested

In your response to my previous FOI request (reference 202600512950, dated 22 April 2026), the Scottish Government confirmed that there are currently no plans to connect ScotAccount with the proposed UK national digital identity infrastructure, but stated:

"We continue to work with the UK Government on a commitment to interoperability and federation of credentials with their existing GOV.UK One Login programme, where this will benefit users of both Scottish and UK public services."

I would be grateful if you could provide the following information in relation to this work:

  • A description of what is meant by "interoperability and federation of credentials" between ScotAccount and GOV.UK One Login in this context — specifically, what data or credential attributes would be shared or recognised between the two systems, and in what direction.
  • The dates and nature of any meetings, agreements, or memoranda of understanding between the Scottish Government and the UK Government specifically concerning ScotAccount interoperability or credential federation with GOV.UK One Login, from 1 January 2023 to the date of this request.
  • Any data protection impact assessments, privacy notices, or data sharing agreements produced or in development in relation to ScotAccount interoperability with GOV.UK One Login.
  • Whether any Scottish citizen data held within ScotAccount or MyCare.scot would be accessible to, or shared with, UK Government systems as a result of this interoperability work, and if so what categories of data and under what legal basis.
  • Whether the GOV.UK One Login interoperability work has been or will be subject to scrutiny by the Scottish Parliament, and if so in what form.

Response

At the outset, it may be helpful to explain that engagement between the Scottish Government and the UK Government on interoperability between ScotAccount and GOV.UK One Login remains at an early, exploratory stage.

In line with our obligations under FOISA, we can only provide recorded information held at the time your request was received.

Where work has not progressed to the point of producing recorded information, the Scottish Government does not hold that information (section 17(1) of FOISA).

1. By way of general explanation, “interoperability” refers, at a high level, to the ability for different digital identity systems to recognise or accept identity credentials issued by another system. “Federation” refers to arrangements that can allow users to authenticate across systems without the need to create separate accounts for each service.

While these concepts provide a general description of the terminology used in the previous FOI response, there has not been sufficient work undertaken between the Scottish Government and the UK Government to agree a specific or detailed definition of “interoperability and federation of credentials” in relation to ScotAccount and GOV.UK One Login.

The discussions to date have been exploratory in nature and have not resulted in agreed definitions, technical designs, or decisions about implementation.

Accordingly, the Scottish Government does not hold recorded information on what specific data, credentials or attributes would be shared, or the direction of any such sharing (section 17(1) of FOISA).

2. In response to your question on meetings between the Scottish Government and the UK Government specifically concerning interoperability or credential federation between ScotAccount and GOV.UK One Login, there have been six meetings between 1 January 2023 and 23 April 2026 on the following dates:

  • 29 August 2023
  • 26 March 2024
  • 22 May 2024
  • 1 November 2024
  • 7 November 2024
  • 6 June 2025

These meetings consisted of general high-level, exploratory discussions on respective approaches, technologies, and user journeys. They did not result in formal decisions, agreed outputs, or detailed technical or policy development.

No formal agreements or memoranda of understanding are in place concerning interoperability or credential federation between ScotAccount and GOV.UK One Login.

3. No Data Protection Impact Assessments (DPIAs), data sharing agreements, privacy notices, or formal interoperability documentation have been developed in relation to interoperability between ScotAccount and GOV.UK One Login.

While high-level discussions have taken place (as noted above), these have not progressed to the stage at which such documentation would be required.

Accordingly, the Scottish Government does not hold this information (section 17(1) of FOISA).

4. No work has been undertaken to design or define data flows in the context of interoperability between ScotAccount and GOV.UK One Login.

Accordingly, the Scottish Government does not hold recorded information on whether any Scottish citizen data would be accessible to, or shared with, UK Government systems, nor on the categories of data or legal bases for such sharing (section 17(1) of FOISA).

5. As work on interoperability remains at an early exploratory stage, no specific arrangements for scrutiny by the Scottish Parliament have been established, and no recorded information is held on this matter (section 17(1) of FOISA).

More generally, matters relating to digital identity and public service delivery may be subject to scrutiny by the Scottish Parliament in the usual way.

About FOI

The Scottish Government is committed to publishing all information released in response to Freedom of Information requests. View all FOI responses at https://www.gov.scot/foi-responses.

Contact

Please quote the FOI reference
Central Correspondence Unit
Email: contactus@gov.scot
Phone: 0300 244 4000

The Scottish Government
St Andrew's House
Regent Road
Edinburgh
EH1 3DG

Back to top