Who Pays Your Fines When You Say No to Digital ID?

Who Pays Your Fines When You Say No to Digital ID?

Company directors across Britain are being told by campaign groups like the TOGETHER Declaration to refuse OneLogin and reject Digital ID. Videos get projected onto Parliament. Petitions rack up signatures. Emails flood MPs’ inboxes.

Great. And then what? When 18 November arrives and Companies House demands your identity verification or slaps you with criminal penalties, where exactly are these campaigners?

Spoiler: not paying your fines.

They Tell You to “Just Say No” to Digital ID. But Who Pays Your Fines When You Do?

You can’t file your confirmation statement without OneLogin access since 13 October 2025. From 18 November, you won’t be able to file one at all unless you’ve verified your identity and provided a personal code. Refuse, and you face unlimited fines, potential director disqualification, and your company gets struck off. That’s not optional. That’s coercion wrapped in bureaucratic language, and the people shouting “just say no” aren’t offering a single practical alternative beyond sending more bloody emails.

To be honest, I have thought many times about closing my company and scrappy my VAT registration but what does that achieve? Sole traders will be in the next cohort to get forced into the One Login anyway.

The WebFiling trap has already sprung

Since 13 October 2025, Companies House WebFiling requires GOV.UK OneLogin access for every user. Your old Government Gateway credentials stopped working. If you needed to file a confirmation statement, accounts, or any statutory return after that date, you had no choice but to connect to OneLogin. The system doesn’t ask permission, it just locks you out until you comply.

HMRC services still use Government Gateway for now. Corporation Tax returns and VAT submissions haven’t migrated to OneLogin yet, though that’s coming eventually. But for anything Companies House related? You’re already in the system whether you wanted to be or not.

This creates a split situation where directors face immediate OneLogin requirements for Companies House filings whilst still using older systems for tax obligations.

You see, despite what was announced in September about all this happening by the end of this government (2029), the system is already built.

It’s deliberately confusing, perhaps intentionally so. When everything eventually consolidates under OneLogin, refusal means total exclusion from every government service you need to run a business legally.

November 18th is when identity verification becomes mandatory

The date everyone’s panicking about marks the start of mandatory identity verification under the Economic Crime and Corporate Transparency Act 2023. It’s not a single cliff-edge deadline, it’s a trigger date with rolling deadlines depending on your circumstances.

New directors appointed on or after 18 November must verify their identity before they can act. No verification, no appointment. Existing directors must verify when they file their next confirmation statement due on or after that date. If yours is due in March 2026, that’s your deadline. If it’s due in December 2025, you’ve got less time. This creates a 12-month transition period ending mid-November 2026, affecting an estimated 6-7 million individuals.

People with Significant Control face separate deadlines based on their birth month, with verification required within the first 14 days of each month starting November 2025. Someone born in January has until 14 January 2026. Someone born in July gets until 14 July 2026.

Confused yet? Me too!

Failure to verify is a criminal offence. Not a civil penalty, not an administrative fine. Criminal prosecution with unlimited fines. That’s the stick they’re using to force compliance whilst maintaining the fiction that digital ID is “voluntary.”

But weren’t we repeatedly told we didn’t have to do it? Well, we do.

What TOGETHER actually does versus what directors need

TOGETHER Declaration runs email campaigns, publishes videos, drafts a Digital Bill of Rights with zero legal force, and projects slogans onto buildings. Their campaign page even compares OneLogin to the Post Office Horizon scandal, which is a brilliant analogy except for one tiny problem:

  • where’s their equivalent of the Justice for Subpostmasters Alliance that fought the actual legal battle?
  • Where’s the legal defence fund?
  • The coordinated test case?
  • The alternative verification system negotiated with government?

Nowhere.

Because TOGETHER is a pressure group that generates content, not a legal defence operation. They’ve got “hundreds of thousands of supporters” according to their own website, but those supporters are left holding the bag when criminal penalties arrive.

Their 4th Anniversary Event is scheduled for 16 November 2025. Two days before the mandatory verification deadline. Perfect timing to talk about the problem whilst doing sod all to solve it for directors who’ll face prosecution 48 hours later.

What directors facing criminal penalties actually need is

  • legal representation,
  • financial support for fines,
  • negotiated alternative verification routes, and
  • coordinated mass non-compliance with proper legal backing.

What they’re getting is another petition to sign and more videos to watch about how terrible it all is.

The security shambles nobody wants to discuss

A whistleblower from inside the civil service provided evidence to journalist Andrew Orlowski that OneLogin failed Red Team security testing in March 2025. Cyberis, the cybersecurity consultancy that ran the test, discovered hackers could gain privileged access without triggering security monitoring tools.

This wasn’t theoretical.

The vulnerabilities were real enough that the Department for Science, Innovation and Technology asked Computer Weekly not to publish full technical details whilst they scrambled to fix the problems.

Over 300 contractors worked on OneLogin development without necessary security clearance. Worse, much of the development was offshored to Romania through Deloitte, a fact that GDS chief executive Tom Read apparently discovered after the work had already been done and without National Cyber Security Centre approval.

The internal CISO report from November 2023 confirmed 39% of production administrators lacked appropriate Security Check clearance despite handling millions of citizens’ sensitive personal data.

Romania’s town of Râmnicu Vâlcea earned the international nickname “Hackerville” for its concentration of cyber-crime networks. The FBI has trained Romanian law enforcement specifically to combat operations from that region. And this is where substantial chunks of Britain’s centralised digital identity infrastructure got built,

  • by contractors without proper clearance,
  • working on laptops they used for personal tasks like watching TikTok alongside their sensitive government work.

The government’s own revised business proposal to the Cabinet Office warned that security vulnerabilities could be exploited by fraudsters or hostile actors seeking to disrupt national infrastructure, with “severe consequences for a large number of people, and result in persistent reputational and political damage.”

They knew.

They warned themselves.

And they rolled it out anyway.

The “voluntary” digital ID that comes with criminal penalties

Technology minister Liz Kendall stood in Parliament and stated “there will be no sanction or penalty for people if they do not have a digital ID.”

That’s bollocks.

When refusing means you cannot legally work, cannot act as a company director, cannot file statutory returns, and face criminal prosecution for non-compliance with verification requirements, the penalty is structural.

Prime Minister Starmer was more honest: “You will not be able to work in the United Kingdom if you do not have a digital ID. It’s as simple as that.” Yet the official government line maintains nobody is being “forced” because you can technically pay an Authorised Corporate Service Provider to verify on your behalf instead. Translation: it’s optional as long as you’re wealthy enough to pay someone else who has submitted to the system to act as your proxy every single time you need to file something.

That’s not optional.

That’s a two-tier compliance tax where small business directors either surrender their biometric data and identity documents to a system with proven security flaws, or pay recurring fees to accountants and solicitors for basic administrative tasks they used to handle themselves. Tasks I have managed to do perfectly fine for over 30 years!

Either way, you’re in the system. The only choice is whether you hand over your data directly or fund someone else to do it for you.

The data doesn’t stay on your phone

Government marketing claims documents are “stored in the GOV.UK One Login app on your phone and not in the cloud.” Technically true. Functionally meaningless.

The government’s own privacy notice states that when you sign in or prove your identity, they send “the result of your identity check, reasons for failure if applicable, information that enables the other government service to match you against their records, which typically includes your name, date of birth and address” to whatever service you’re accessing.

The app allows you to “securely share identity information issued by government departments with other government departments and public and private organisations.” Every department and organisation you verify with processes your data as an independent data controller under their own privacy policies. Your driving licence number, issue date, expiry date, passport number, and ICAO issuer code all get transmitted to HMRC when you verify through Government Gateway.

So yes, the encrypted data technically sits on your phone until you use it. Then it broadcasts across government networks, gets stored in multiple departmental databases, and sits on servers run by organisations you’ve never heard of who operate under “independent data controller” status.

The “stored locally” claim is like saying your bank card is secure because the plastic sits in your wallet, whilst ignoring that every transaction sends your details across global payment networks.

Last June, HMRC admitted that criminals used phishing techniques to compromise around 100,000 taxpayer accounts and extract £47 million in fraudulent tax repayments.

That’s just tax records.

Imagine what happens when OneLogin consolidates access to 180+ government services including benefits, pensions, passports, and medical records in a single breachable system built by Romanian contractors without security clearance.

File early if your statement is due soon

If your confirmation statement is due before 18 November, file it now. You can submit early and reset your 12-month clock, potentially buying yourself additional time before facing the identity verification requirement. The government guidance states verification applies to confirmation statements filed on or after 18 November, not just those due after that date.

This means filing a statement due in March 2026 today (31 October 2025) should let you complete it without providing a personal code, and reset your next due date to October 2026. Whether Companies House honours this or finds a way to require verification regardless isn’t clear from official guidance, but worst case you’ve completed this year’s filing early.

Notice I sad SHOULD let you use the old login method.

It’s a delaying tactic, nothing more. Unless something fundamental changes through legal challenge or political intervention, you’re facing the same choice in 12 months:

  • verify through OneLogin,
  • pay an ACSP, or
  • face criminal prosecution.

But if buying 7-8 extra months gives you breathing room to see how this plays out, it’s worth doing whilst the option exists.

No real opposition, just noise

The Liberal Democrats ran a petition claiming “We fought against Labour’s plans for ID cards, and we won. We will fight tooth and nail to oppose these plans too.” Except they’re not in power, don’t have the votes to block anything, and their “fighting tooth and nail” consists of collecting email addresses whilst directors face criminal penalties.

They fought Tony Blair’s physical ID cards successfully when they were in coalition government and could actually scrap the scheme. Now they’re shouting from opposition benches with zero legislative power to stop anything. Meanwhile nearly three million people have signed various petitions against digital ID, and it made absolutely no difference to implementation timelines or legal requirements.

This is what happens when opposition groups prioritise brand-building and content creation over legal strategy and practical support. TOGETHER has videos, petitions, anniversary events, and a draft Digital Bill of Rights. What they don’t have is legal defence funds, negotiated alternatives, coordinated court challenges, or financial backing for directors who refuse to comply.

Campaign groups are excellent at telling you what to oppose. They’re bloody useless at protecting you from the consequences of actually doing it.

What Directors Need to Know Right Now

Can I Still File My Confirmation Statement Without OneLogin Today?

You need OneLogin to access the WebFiling system since 13 October 2025, but if your confirmation statement is due before 18 November, you don’t need to complete the full identity verification process with a personal code yet. That requirement only kicks in for statements filed on or after 18 November 2025.

What Happens If I Refuse to Verify My Identity After 18 November?

Refusal to verify is a criminal offence under the Economic Crime and Corporate Transparency Act 2023, carrying unlimited fines. You also won’t be able to file confirmation statements, which means your company faces being struck off and you risk director disqualification. There’s no legal exemption for objecting on principle.

Can I Pay Someone Else to Verify Instead of Doing It Myself?

Yes, you can use an Authorised Corporate Service Provider like an accountant or solicitor to verify your identity on your behalf. This shifts the OneLogin requirement onto them rather than removing it, and you’ll pay professional fees every time you need to file something. It’s expensive compliance, not genuine choice.

Does HMRC Require OneLogin for Tax Returns Yet?

No, HMRC still uses the Government Gateway system for Corporation Tax and VAT returns as of October 2025. They’ve announced plans to migrate to OneLogin eventually, but business users haven’t been switched over yet. When that happens, you’ll need OneLogin for everything.

If I File My Confirmation Statement Early, Can I Delay the Verification Requirement?

Potentially yes, if your statement is due after 18 November but you file it before that date. Filing early resets your 12-month deadline, so submitting in October 2025 pushes your next due date to October 2026. However, there’s no official guidance confirming Companies House will definitely honour this approach.

Is My Data Really Stored Only on My Phone Like the Government Claims?

Technically your encrypted documents sit on your phone until you use them, but the government’s own privacy notice confirms they transmit your name, date of birth, address, passport number, driving licence details and other personal data to every department and organisation you verify with. Each one processes it as an independent data controller under their own policies, meaning it gets stored across multiple government databases.

What Practical Support Do Campaign Groups Offer If I Refuse to Comply?

None. Groups like TOGETHER Declaration run email campaigns and publish videos but provide no legal defence funds, no financial support for fines, no negotiated alternatives with government, and no coordinated legal challenges. They’re excellent at generating outrage but useless at protecting directors from the actual consequences of non-compliance.


Sources

Access to Companies House WebFiling accounts to move to GOV.UK One Login
gov.uk

Companies House ID Verification: New Rules for Directors & PSCs
cooperparry.com

Don’t force Company Directors into Digital ID
togetherdeclaration.org

Security tests reveal serious vulnerability in government’s One Login digital ID system
computerweekly.com

New digital ID scheme to be rolled out across UK
gov.uk

GOV.UK One Login: privacy notice
gov.uk

HMRC loses £47m in fraudulent tax repayments
icaew.com

My writing:

I don’t write for the algorithms here. I write for you, the reader. So I am so grateful for your time. Thank you for reading.

Comments:

To keep this site free from spam, comments have been turned off. You are very welcome to contact me via my Facebook profile using the link in the footer.

About me…