About Nesta

Nesta is a research and innovation foundation. We apply our deep expertise in applied methods to design, test and scale solutions to some of the biggest challenges of our time, working across the innovation lifecycle.

The UK public sector spends £6 billion a year renting the infrastructure on which its digital services depend, largely from three American companies. The recently signed Microsoft memorandum of understanding commits a further £9 billion over five years and 95% of central and local public sector organisations now spend budget on ‘hyperscale’ cloud providers. The consequence is a state that pays to access information it theoretically owns, stores its data in formats it did not set and relies on systems it cannot exit.

This is not a pothole problem that can be filled with quick patches. Nor is it a race won by playing catch-up. Both are reactive mindsets: one fixes yesterday's failures, the other chases yesterday's winners. Britain needs to think like the builder of a road network, creating the shared infrastructure that allows millions of journeys to happen, rather than trying to build a road for every journey. A state that has systematically transferred its technical capability and data assets to foreign vendors cannot be fixed through means as simple as a skills programme or a revised framework agreement. It needs an infrastructure overhaul that rebuilds the shared foundations on which digital capability can emerge, connect and scale.

At the heart of this infrastructure overhaul is a coordination layer. In part, this is like a rulebook; for a road network, the rulebook dictates how to drive on it, how it must be built, how it must connect with other roads, and who sets the terms for everyone who uses it. But like a functional road network, the coordination layer needs more than just a rulebook. Roads need to be funded and maintained. They need skilled engineers to build and operate them properly. And the people who use or are affected by them need a say in how they are designed in order to deliver maximum public value.

Diagram of digital public infrastructure components, where critical enablers combine to form a foundation, supporting existing opportunities like connected retirement, and paving the way for future possibilities

The digital public infrastructure framework

Read the text-based description of this image

A network model of sovereignty

Digital sovereignty has become a race to own things: sovereign clouds, sovereign AI, sovereign chips. If Britain depends on foreign technology, the instinct is to catch up and build more British alternatives. 

Yet the existing models that appear to have solved the problem have created another one: America has concentrated digital capability inside a handful of technology giants that limits public stewardship. China has concentrated it inside the state and limited pluralism. Europe has concentrated on regulating digital markets, prompting growing concern that compliance burdens fall heaviest on smaller firms and slow the innovation. Britain has little to gain from copying any of them, and certainly does not need a smaller version of any of these.

The temptation is to ask what Britain should build next. Britain has no shortage of digital systems, but it has a shortage of shared ones. NHS England alone runs around 50 separate customer relationship management platforms, while DEFRA alone runs four digital services for agricultural food trade with near-identical functions. Each of the NHS's 209 secondary care organisations negotiates and buys its own core infrastructure, while over 320 local councils largely do the same. Fragmentation has become the default architecture of the British state. Therefore, a better question is what foundation would connect the capabilities Britain already has and leave the door open for those yet to come.

This echoes the weaponized interdependence of Farrell and Newman, who argue that influence in the modern economy comes less from owning every critical technology than from shaping and controlling the network hubs on which others depend. Money, information and data increasingly flow through a surprisingly small number of shared systems, and whoever sits at those chokepoints can monitor or exclude everyone else. So Britain's comparative advantage may lie in building and governing the shared infrastructure on which individual technologies depend.

Some governments seem to have understood this sooner than others. Estonia is famous for its digital government. Less well known is that it did not build one giant government database. Instead it built X-Road, allowing separate organisations to exchange information through common standards. India's success with digital payments followed much the same logic. Government did not produce the country's winning payments app. It built Unified Payments Interface (UPI) instead. Hundreds of banks and payment providers now compete on the same infrastructure.

That is the role of the coordination layer: shared standards, APIs, interoperability frameworks and governance arrangements that lower the cost of participation for everyone. This allows universities, start-ups, and open-source communities to build on common foundations instead of recreating infrastructure from scratch. Public institutions gain genuine choice because technologies become easier to replace. Smaller firms compete because barriers to entry fall. Open-source innovation becomes part of public infrastructure rather than sitting at its margins. Capability is no longer concentrated within a handful of firms or the state, and instead can be cultivated across an ecosystem.

Seen in this light, sovereignty looks rather different. It is less about technological self-sufficiency than about preserving resilience and agency in an interconnected world. Canada's Digital Sovereignty Framework reflects this evolution, defining sovereignty as the capacity to exercise autonomy regardless of where technologies are developed or hosted. Its emphasis on:

The coordination layer, like a road network, creates the conditions under which everyone else can travel further. The five enablers that follow describe what that road network needs in practice: technical capability, sustained investment, shared rules, interoperable connections and a foundation of trust.

Five critical enablers for British DPI

These are five structural preconditions for building UK DPI capable of moving beyond the constraints of the current tenant-state model. The first two, establishing a national digital corps and sovereign tech fund, lay the groundwork for the other  three: an open commons mandate, a mandatory interoperability regime, and a national digital credentials infrastructure. Without a talented workforce and sufficient funding, the other enablers are significantly more challenging. 

Graphic of critical enablers for digital public infrastructure, where five distinct building blocks represent the specific foundational mandates, credentials, corps, and funds required

Five critical enablers for digital public infrastructure

Read the text-based description of this image

Enabler 1: Civil digital corps by channelling technical talent into public service

The problem

The state cannot build sovereign digital public infrastructure without technical capability. Britain has an abundance of technical talent, but lacks a public service model that can access it at scale. Only 4% of civil servants identify as digital or data specialists, against 8-12% in the private sector. Contractor over-reliance erodes institutional capability

Existing initiatives, from No.10 Innovation Fellowship to the Police Digital Service Bench, have demonstrated interest from the UK's technical community. Yet each has relied on ad hoc governance, fragmented communities and temporary funding, rather than a permanent institution to steward, deploy and retain expertise. Without a permanent institutional home, these initiatives fail to convert expertise into lasting organisational capacity. The result is a state that rents skills for isolated projects but is unable to strategically govern its own digital architecture.

Singapore confronted the same failure a decade ago until their GovTech was placed under the Prime Minister's Office to give it the cross-government authority. In-house engineers were recruited and deployed directly into 60 of Singapore's 95 agencies, and compensated at levels competitive with top private sector roles. Singapore also created the Smart Nation Fellowship Programme to bring technology specialists from industry into government for fixed-term public service roles. This has helped transform Singapore into a global leader in digital government, enabling the state to rapidly deploy shared infrastructure such as a national API marketplace and a unified cloud tech stack.

The solution

A civil digital corps, modelled on the Army Reserve, as a technical capability service for government. Departments access a single cross-government service responsible for sourcing, accrediting and deploying specialist technical expertise.

Instead of outsourcing technical capability, the state becomes the steward of its own technical expertise. The Police Digital Service Technical Bench demonstrates the value of maintaining a standing pool of pre-vetted specialists. However, these models rely on commercial intermediaries to own the community and broker expertise. A civil digital corps would internalise these functions within the state, creating a permanent institution that accumulates capability rather than repeatedly purchasing it.

The corps would attract and retain talent through a public service compact rather than salary competition. Members would receive benefits the market cannot easily replicate, including portable security clearance, recognised technical accreditation, attribution for open-source contributions made during service, and participation in nationally significant digital public infrastructure programmes.

The civil digital corps would operate as the government's shared technical capability service. Departments might submit technical challenges through a single operating platform, which maintains a permanent capability registry, common security vetting, standard data-sharing agreements and reusable deployment frameworks. Instead of each department separately recruiting experts, negotiating legal agreements, managing security clearance and procuring specialist support, these functions would be delivered once as a shared government service.

The corps would also act as the steward of the UK's public-interest technical community. It would continuously maintain relationships with industry, academia, open-source communities and specialist practitioners, matching expertise to government missions while preserving institutional knowledge across programmes. This would replace today's fragmented landscape with a permanent operating model for sovereign technical capability.

The Cabinet Office should designate a convening body to establish the civil digital corps as a cross-government technical capability service. Within the first year, the corps should launch a minimum viable service comprising a national capability registry, common security vetting, standard data-sharing agreements and a single front door through which departments can submit technical challenges and access accredited specialists. Three to five digital public infrastructure programmes would be selected as early adopters to test the service model, refine governance arrangements and demonstrate faster access to trusted technical expertise without repeated procurement.

Enabler 2: A sovereign tech fund for open-source infrastructure, funded at infrastructure scale, not IT budget scale

The problem

Open-source software underpins the UK’s digital estate, from encryption protocols securing state data to shared libraries public services run on, and contributed 27% of UK digital gross value added in 2022. Building sovereign DPI is impossible without a secure, resilient open-source ecosystem. Yet it is chronically underfunded because it constitutes a market failure: the software is freely available to all, so no individual actor has sufficient incentive to maintain it.

Germany's Sovereign Tech Agency has invested over €23 million in 60+ open-source projects since 2022. France, Germany, the Netherlands and Italy have pooled investment via the European Digital Infrastructure Consortium. The UK has no comparable vehicle. Instead of investing in the open commons, the state’s procurement doctrine puts billions into proprietary vendor rental, transforming a shared economic multiplier into a systemic vulnerability.

The solution

A UK sovereign tech fund capitalised at £1.6 billion over three years, less than 10% of the government's £26 billion annual digital technology spend. Mandated to invest in the open-source components, data exchange layers and interoperability infrastructure underpinning government services, it should be designed to give the state the commercial leverage and technical independence of a major technology company.

The fund's first function should be technical due diligence. Government has historically bought and built technology without a clear picture of where open-source components sit in its systems, how critical they are or who depends on them. The fund therefore begins by mapping that estate before committing capital.

The fund should not only invest as a public steward targeting the underfunded infrastructure layer, it should also operate with a global mandate. Open infrastructure is a borderless shared resource and British public investment strengthens the commons on which all actors depend. Securing global software is the most efficient way to protect our own digital infrastructure.

The fund's specific instruments should include the following.

  • Long-term maintenance contracts for critical open-source components, each specifying accountable ownership for vulnerability response, binding patching service levels, and clear liability terms so the government no longer depends on code nobody is accountable for. Long-term maintenance contracts, as opposed to innovation grants, ensure funding is directed towards the unglamorous, critical work of security patching, bug fixing and operational stability, rather than shiny new products that could create further unmaintained code in the future. 
  • Co-investment with devolved administrations and local authorities so that shared infrastructure is built once rather than duplicated across every council, NHS trust and police force.
  • Exit-funding for vendor migration that treats switching costs as a one-off infrastructure investment, rather than forcing departments to fund costly migrations out of operational budgets - a constraint that currently makes staying locked-in the only affordable choice.

By funding the maintenance of critical open-source projects, the fund acts as an economic multiplier. It drives growth by lowering the cost of innovation for the UK’s technology sector, allowing British start-ups to build on robust, state-backed open architecture rather than being forced into expensive, proprietary vendor systems.

Governed as a mission-led public institution accountable to parliament, the fund should have a board combining political mandate, technical independence and public representation, with a statutory sunset review and a mandate to publish all investment decisions. The fund's contracts should also be where the state finally assigns accountability and security responsibility for the open-source infrastructure it depends on. This provides the missing structural fix. By packaging maintenance funding and security accountability together, the government ensures that critical code always has a clearly assigned owner.

Announce the UK sovereign tech fund in the autumn budget with an initial £350 million capitalisation, drawn from existing Department for Science, Innovation and Technology and Central Digital and Data Office budgets, reclassified as infrastructure. Within six months, publish a critical open-source dependency audit, identifying open-source components that central government digital services depend on, who maintains them, and what the failure risk is. Commission the first tranche of maintenance contracts for the 20 most critical, underfunded software components, specifically targeting the pieces of code that pose the greatest security or failure risk to government services. Announce the co-investment framework for devolved administrations.

Enabler 3: Replace the current procurement doctrine with an open commons mandate

The problem

The UK’s ‘buy the best available commercial product’ doctrine treats digital infrastructure as an isolated commodity rather than a collective foundation. In practice, this means procurement teams define a ‘good commercial deal’ by short-term fiscal cost savings, like beating list prices for vendor products. 

As the Competition and Markets Authority (CMA) and recent UCL Institute for Innovation and Public Purpose (IIPP) research highlight, this narrow focus ignores the real engine of vendor lock-in - the long-term cost of exiting. Because dominant cloud and data monopolies use proprietary architectures, switching systems later can be very costly. The current doctrine masks these future exit costs and the substantial algorithmic rents that follow. This makes lock-in a perpetually rational choice for risk-averse legal and financial teams.

The solution

The alternative is the open commons mandate, drawn from the Commons Network's call for conscious procurement strategies as a means of achieving digital sovereignty. It establishes three non-negotiable conditions for any public sector technology contract.

  • Unconditional data portability: the state can retrieve all its data, configurations, and integrations in vendor-neutral, open formats within 90 days, at no cost, at any point, without penalty clauses.
  • No proprietary dependency: core service functions cannot rely on vendor-specific formats, APIs, or identity systems for which no open-standard alternative exists.
  • Public money, public code: any software developed with public funds, including bespoke development within a vendor contract, is licensed as open-source compatible with reuse by other public bodies.

This is a redefinition of what the market is competing on. When leaving a vendor is costless, suppliers must win and retain business based on the quality and reliability of their service, while the open code requirement allows more companies to enter the market and innovate.

The mechanism to implement this already exists. Under the Procurement Act 2023, which came into force in February 2025, all public bodies must follow the National Procurement Policy Statement. The government is already rewriting that statement, so embedding these three conditions requires no new legislation, just political will to use existing architecture to shift public procurement from passive purchasing to a market shaping tool.

To operationalise this, the Digital Commercial Centres of Excellence (CCS and CDDO) must reform their core KPIs, moving away from short-term volume discounts with hyperscalers and toward measuring the long-term public value of dynamic exiting ability. 

Alongside this, a “public technology contracts register”, built on the contract publication system the Procurement Act already mandates, would require every contract above £5 million to carry an open commons compliance certification before it can proceed. Non-compliant legacy contracts are placed on a renegotiation timetable attached to spending review settlements, with milestones published and tracked.

The UK government commissions an emergency portability audit of the 50 largest central government technology contracts, assessing each against the three open commons conditions and publishing the results by department. This creates an immediate baseline and surfaces the scale of the problem publicly. Simultaneously, the revised NPPS is drafted for consultation, embedding the open commons conditions as mandatory procurement criteria, using the Procurement Act 2023's existing architecture rather than waiting for new primary legislation. The public technology contracts register is launched as a module on the existing central digital platform, which is already live. Any contract renewal or extension signed in year one without a compliance assessment is flagged to the relevant parliamentary scrutiny committee, establishing the accountability norm before the formal blocking power is in place.

Enabler 4: A mandatory interoperability regime with system architecture as law

The problem

Britain digitised its public services in the 2000s without mandating interoperability. The result is an estate of over 1,100 public sector bodies operating largely incompatible digital systems that cannot exchange data without bespoke, expensive and fragile point-to-point integrations negotiated bilaterally. The CMA's 2025 cloud market investigation confirmed that the "lack of open APIs and standard data formats" is a primary mechanism of lock-in, meaning customers cannot shift workloads or use multiple providers without significant engineering overhead, resulting in "heightened reliance on a single vendor's proprietary stack."

The problem operates at two distinct levels. At the technical level, systems use incompatible data formats, proprietary APIs, and vendor-specific protocols that prevent straightforward exchange. At the organisational level, every public body becomes a unique technical environment requiring bespoke integration, legal agreements and procurement. Large incumbents can absorb these costs, while small-to-medium enterprises (SMEs), open-source suppliers and universities often cannot. These limit competition, slowing innovation and reducing sovereign control over the digital stack.

The solution

A mandatory interoperability regime, established in statute, with two binding layers.

  • Technical interoperability: mandatory open data exchange standards for all public sector systems. These are statutory minimum requirements that existing systems must achieve on a published timetable and future systems must meet before deployment. The standards are published by a statutory “Office of Digital Interoperability”, updated through an open governance process, and are vendor-neutral. 
  • Organisational interoperability: a single, publicly auditable organisational interoperability framework covers standardised consent, data-sharing agreement templates, accountability allocation and privacy standards. This replaces the current patchwork of bilateral departmental negotiations. Every organisation in the public estate operates within this framework by default. Custom bilateral agreements may exist within it but cannot substitute for it.

A new statutory Office of Digital Interoperability should be launched to govern the UK's interoperability architecture through an open standards process involving government, industry, academia, standards bodies and the open-source community. This office will publish mandatory interoperability profiles, common information models and conformance requirements while maintaining open-source reference implementations, software development kits and conformance testing tools that reduce implementation costs, particularly for SMEs.

Open interfaces and shared architectures allow SMEs, universities and open-source communities to build reusable components once and deploy them across government. Rather than integrating separately with hundreds of organisations, suppliers integrate once with the national interoperability framework and compete on capability, creating a larger domestic market for innovative digital services. 

Cross-stack interoperability creates the technical foundation for cross-sector innovation. Portable architectures and common information models allow data and services from different sectors to be securely composed. They achieve this by replacing high-risk, bespoke system integrations with a single shared data vocabulary and standardised APIs, reducing deployment costs and enabling new digital services across the economy.

This mirrors successful open platform ecosystems such as Kubernetes and OpenStack, where common interfaces enable competition and innovation across multiple providers rather than locking users into a single technology stack. Sovereignty therefore derives from maintaining choice, portability and competition across the stack.

The first mandatory technical standard is published - NHS data exchange as the highest-stakes, most tractable initial domain (the prescribing record use case provides a concrete, patient-safety-justified starting point). Within 12 months, the organisational interoperability framework is published and becomes the statutory default for all new cross-departmental data-sharing agreements. The live public compliance dashboard goes live on the same day as the first technical standard, establishing the accountability infrastructure before the compliance requirement it will monitor.

Enabler 5: Establish a national digital credentials infrastructure

The problem

The conventional sequencing for building digital public infrastructure runs: identity, payments, data sharing. Similarly, Britain's digital trust infrastructure has been framed primarily as an identity problem. In practice, the government more often needs to verify what someone is entitled, qualified or authorised to do than who they are. Professional licences, Disclosure and Barring Service (DBS), right to work and even personal identity are all credentials, yet each sector maintains separate verification processes with little interoperability.

The NHS Digital Staff Passport demonstrated both the opportunity and the missing infrastructure. Developed during COVID-19 to accelerate workforce mobility across NHS organisations, it showed that portable digital credentials could reduce repeated employment checks and administrative burden. However, national rollout stalled because every credential remained tied to its own issuer, verification process and assurance policy. There was no common infrastructure through which an NHS trust could submit a single verification request, such as "is this clinician currently cleared to work here?", and receive a trusted auditable response composed from multiple independent credential issuers. Instead, each organisation continued to reconnect to individual registries and apply its own assurance processes.

The same fragmentation exists across public and private sectors. Every organisation builds bespoke integrations to verify licences, qualifications, entitlements and permissions, despite relying on many of the same credential issuers. What is missing is a shared digital credential infrastructure that enables authorised organisations to request trusted verification across multiple credential types through a single interoperable layer.

The same limitation will constrain the next generation of digital public infrastructure. As AI agents begin acting on behalf of people and organisations, systems will need to verify not only identity but delegated authority, permissions and scope of access. Existing identity frameworks alone cannot provide this authorisation layer.

The solution

Establish a national digital credential infrastructure, a shared digital public infrastructure that enables trusted verification of credentials across government and the wider economy.

Rather than issuing credentials or creating a national identity database, this infrastructure should provide a credential verification network. Credential issuers, such as professional regulators, licensing bodies, government departments and accredited organisations, should continue issuing credentials under their existing statutory responsibilities. When an authorised organisation needs to verify whether an individual, business or AI agent is authorised to perform a particular action, it submits a single request to the network. The network securely verifies the relevant credentials and returns an auditable response, including the verification outcome, issuing authority and assurance metadata, without exposing or centralising the underlying credential data.

Built on the UK's digital verification services trust framework and open standards such as W3C verifiable credentials, it creates common verification rails while allowing existing issuers, wallets and sector-specific systems to continue operating independently.

The national digital credential infrastructure applies the same principle as the open-source Beckn Protocol, which underpins India's Open Network for Digital Commerce (ONDC): verify once, reuse everywhere. Conventional platforms such as Uber verify their own drivers and keep that trust relationship inside their own platform. Any new entrant must repeat the same onboarding, verification and trust-building process before it can compete. ONDC separates verification from the platform. Each platform remains responsible for verifying its own drivers, but once that platform is admitted to the ONDC network, every compatible consumer application can trust and transact with it through a shared registry. This allowed Namma Yatri, a ride hailing app,to emerge as a community-led, zero-commission alternative without first recreating a proprietary ecosystem.

The government should establish the foundations of the network. DSIT should publish the first National Trust Registry and open verification protocol, building on the UK's digital verification services trust framework and W3C verifiable credentials standards. A founding coalition of authoritative issuers, such as DBS, Home Office, Companies House and selected local authorities should be onboarded to publish verification keys and revocation services through the registry.

Assessing DPI maturity across five key UK sectors

Implementation of the five critical enablers should reflect the capabilities that already exist across different sectors. Many of the foundations for DPI are already in place, built through successive programmes of public investment, regulatory reform and sector-led innovation. Their maturity is uneven, and so are the sovereignty risks that accompany them.

Before prioritising investment or reform, the UK needs a consistent way of measuring digital infrastructure maturity. The framework proposed here, drawing on GovStack’s Digital Maturity Assessment and UCL's framework for the conceptualisation and measurement of digital public infrastructure, assesses sectors across six pillars.

  • Technology and interoperability: audits whether technical assets (APIs, architectures, and data standards) connect seamlessly without proprietary friction against a strict sovereignty requirement for open-source, vendor-neutral, and publicly-auditable codebases.
  • Policy and regulations: maps the statutory and regulatory frameworks governing the sector to evaluate whether legislation secures data residency and grants public authorities the proactive legal right to technically audit vendor code and algorithms.
  • Skills and capacity building: measures the sector's critical human capital layer, tracking skills against a core sovereign baseline: whether the UK public sector possesses the in-house engineering talent to independently maintain, modify, or fork critical systems rather than acting merely as trained vendor software users.
  • Institutional framework and cross-sector collaboration: evaluates whether coordination across foundational DPI layers (identity, payments, and data exchange) is transparent and free from vendor capture, anchoring collaboration in open, multi-stakeholder governance structures and ring-fenced DPI budgets.
  • Sovereign procurement and contract terms: directly audits the commercial framework to prevent hidden vendor lock-in costs, checking delivery against explicit legal protections including open-source preferences, total data portability, and legally binding exit provisions.
  • Access, adoption and public value: quantifies the equitable generation of public value across the wider ecosystem, blending user centricity with a sovereign mandate to eliminate rent-extracting commercial gatekeepers, lower entry barriers for new innovations, and dissolve platform monopolies.

Five-tier DPI maturity scoring rubric

Each of the five key sectors is scored one to five against the above pillars.

⭐ - Fragmented and proprietary: siloed systems, total reliance on closed vendor platforms, non-existent cross-sector interoperability, and public sector capacity limited to trained end-users. 

⭐⭐ - Emerging silos: initial open standards or shared assets exist in isolated pockets but lack statutory mandates, legal rights to audit, or sovereign control.

⭐⭐⭐ - Compromised frameworks: national frameworks or open APIs are established but compromised by legacy lock-in, limited internal public sector engineering capacity, or foreign-owned foundational rails.

⭐⭐⭐⭐ - Advanced interoperability: mature, state-backed digital rails with widespread adoption and coordinated domestic skills, lacking only full sovereign procurement protections, statutory audit powers, or domestic asset ownership.

⭐⭐⭐⭐⭐ - Sovereign DPI: public stewardship backed by domestic engineering capability, borderless open-source architecture, full interoperability, and statutory audit rights that maximise domestic public value.

Key assets and constraints across sectors

Our assessment using the maturity framework above shows UK DPI does not start from a blank sheet. The following table unpacks the specific assets and constraints driving the maturity scores above.

Key assets and constraints across sectors
Sector Key assets Key constraints
Finance • Mandated Open Banking APIs provide the UK's most mature interoperable DPI.

• Strong regulatory governance through the Financial Conduct Authority (FCA) and statutory oversight.

• Proven ecosystem that has enabled widespread fintech innovation and adoption.
• Core payment infrastructure (VocaLink/Faster Payments) is foreign-owned.

• Open Finance remains incomplete across pensions, insurance and mortgages.

• Proprietary infrastructure and limited procurement levers constrain sovereign control.
Commerce • Strong legislative momentum through Smart Data, digital trade and competition reforms.

• Open Banking and Companies House provide shared digital foundations for business services.

• Growing use of digital identity and verifiable credentials.
• Supply chain and trade data remain fragmented across proprietary platforms.

• Commerce infrastructure is dominated by foreign-owned platforms and payment providers.

• Open standards and portability remain largely voluntary rather than embedded in market rules.
Health • Nationally scaled health datasets and the NHS app provide significant public digital assets.

• Fast healthcare interoperability resources (FHIR) establishes a common interoperability standard across the NHS.

• Strong research capability supported by long-standing public investment.
• Proprietary electronic patient record systems create deep vendor lock-in.

• Data governance and access remain fragmented across organisations and UK nations.

• Limited portability and exit provisions constrain sovereign stewardship of core systems.
Public utilities • Energy has national-scale smart metering and common switching standards, with smart metering equipment technical specifications allowing meters to retain smart functionality when customers change supplier.

• Water has a sector-wide open data platform through Stream and designed to make water company data accessible for shared use.

• Rail has operational data feeds and a Rail Data Marketplace, giving developers and industry users a central access point to rail data.
• Energy data access remains controlled through the DCC licensing model, limiting third-party access and leaving the smart meter communications layer dependent on a proprietary monopoly.

• Rail data remains fragmented between open, restricted and commercialised datasets, while digital signalling is still being deployed route by route rather than as a complete national system.

• Data sharing and interoperability beyond sector boundaries remain limited, constraining innovation and cross-utility services.
Education • Jisc and the Janet network provide UK-operated national digital connectivity.

• National digital standards establish a baseline for schools.• Strong culture of publishing education data and digital guidance.
• No shared learner identity, credential or interoperable records infrastructure.

• Heavy reliance on proprietary education platforms with limited portability.

• Weak institutional governance and procurement arrangements for sector-wide DPI.

Where to start: six opportunities for DPI

The five critical enablers are the foundations - the legal, institutional and technical preconditions for a systemic shift toward DPI. These foundations are geared towards creating the conditions for long-term resilience and growth. The six opportunities below are where to start before they are in place.

For each opportunity, the data already exists, the barrier is governance rather than technology, and the benefit is visible within a parliamentary term. Like Open Banking, these are further proof of concepts that can demonstrate what DPI delivers in practice, build public and political confidence, and create momentum for the broader programme of foundational work.

The problem

The Pensions Dashboard Programme is a step forward for pensions planning, helping citizens to find pensions and view them in one place. But pension assets remain highly fragmented, with 3.3 million lost pension pots containing £31.1 billion. Retirement planning often focuses on pensions in isolation, rather than on people's day-to-day expenses and overall retirement income, including the state support they are entitled to. Only 62% of those entitled to Pension Credit claim it, leaving up to 910,000 households missing around £2.5 billion annually.

The fix

Build a retirement action layer on top of existing infrastructure, enabling people to consolidate pension pots, identify unclaimed entitlements and make informed retirement decisions based on a complete view of their finances. Expand the Pensions Dashboard from a service that helps people view all their pensions in one place into one that also enables pension consolidation through participating providers. Use consented Open Banking data to build a fuller picture of an individual's income, spending and savings, enabling more personalised assessments of whether they are on track for an adequate retirement; and proactively screen and signpost eligible citizens for Pension Credit using existing government data.

What makes it DPI

Creates a transaction layer for retirement. The state connects existing public infrastructures (Pensions Dashboard, Open Banking and government retirement services) through common consent, identity and interoperability rules, allowing any authorised provider to build retirement planning, consolidation and decumulation services on the same rails rather than through proprietary integrations.

How this will lead to growth

Unlock capital by helping households make better use of their retirement assets and savings, while stimulating innovation and growth in retirement planning, guidance and income services. Consolidated pension assets reduce administrative friction, while connected pension and financial data enables personalised retirement planning, new retirement services and better matching of household savings to productive investment.

The problem

British homes and businesses could provide around 84GW of demand flexibility by 2040 through energy-smart appliances such as EV chargers and heat pumps. That is more than Britain's current peak electricity demand. Yet NESO's Demand Flexibility Service delivered less than 1% of that potential in 2024/25. Poor market coordination prevents this flexibility from being deployed efficiently. An asset has to qualify separately with NESO and with its regional network operator, because there is no common registration standard between them. Clearing one market's bar doesn't clear the other's. Dispatching an asset requires its smart meter data, and that access has to be separately authorised for every third party who wants it, rather than granted once.

The fix

Mandate interoperability across three layers.

  • Markets: Require NESO and regional network operators to adopt Elexon's Flexibility Market Asset Register (FMAR) once it is operational, so core asset information is submitted once and reused across national and local markets.
  • Devices: Extend interoperability to market onboarding by requiring compliant energy smart appliance systems to support standardised registration through FMAR and a common consent framework at installation. The draft Energy Smart Appliances Regulations mandate common smart functionality, interoperability and security requirements, but stop short of market registration and consent.
  • Data: Establish a statutory framework for portable, machine-readable consent, similar to Australia's Consumer Data Right. Consumers would have a legal right to grant, view and withdraw permissions over their energy and asset data, and all accredited data users would be bound to honour them. This would build on Ofgem's proposed Consumer Consent Solution, putting it on a statutory footing and extending it to cover existing consents and all data users so that consumers can see and control all access to their data in one place.

What makes it DPI

The government establishes shared rules for market registration, device onboarding and consumer consent, allowing participants to access existing markets through a single interoperable process rather than multiple bespoke ones.

How this will lead to growth

Reduces the cost of participating in flexibility markets, enabling more households, businesses and service providers to compete. Lower barriers to entry increase the supply of flexible demand, support new energy management services and improve the efficiency of electricity markets.

The problem

England is rolling out 10 million smart water meters by 2030, but water companies are adopting different data standards, privacy interpretations and customer propositions. Also, because water meters are swappable devices, anchoring digital accounts to the physical meter or customer accounts will cause data architecture to break every time a meter is replaced or a person moves house. This risks creating 17 incompatible data ecosystems just as water scarcity becomes a strategic national challenge.

The fix

Establish a national smart water data framework built on a property-linked identity rail. First, launch a consent-based household consumption data rail anchored to "supply point IDs", allowing households to securely share their water usage data. Second, introduce secure access protocols to safely integrate more complex, commercially sensitive operational network data.

What makes it DPI

Creates a national resource coordination layer for water. Government establishes common customer data rights, operational data standards and a national smart meter data exchange, allowing household consumption, network operations and water resource data to flow securely across water companies, regulators and authorised third parties.

How this will lead to growth

Raises the resilience of Britain's water system. It reduces dramatic bill spikes by alerting households to hidden consumer-side leaks, unlocks efficiency insights and creates incentive opportunities like gamifying water-saving. Smart meter data also becomes operational infrastructure for water management, enabling dynamic drought response, earlier leak detection, and more efficient investment in reservoirs, treatment and distribution networks.

The problem

A hospital doctor, GP and pharmacist can each hold a different view of the same patient's medicines. Prescribing, dispensing and monitoring data are fragmented across NHS systems, with no common information architecture to keep them synchronised. The result is around 1.8 million medication errors every year during hospital care transitions. Relying on voluntary technical standards fails because tech vendors have no commercial incentive to open their systems, and individual NHS Trusts lack the market power to force native software rewrites.

The fix

Deliver a single longitudinal medicines record by shifting from voluntary standards to statutory data rights. First, legislate a statutory right for the NHS to directly access and extract raw backend data from all clinical systems, with fixed egress fees based on cloud costs. The NHS should then prioritise building a central data standardisation engine that extracts raw vendor tables, standardises terminology using the NHS dictionary of medicines, and provides a single prescribing view to clinicians. As NHS Trusts go through re-procurement cycles, use this new legal baseline to mandate open-standard interoperability as a condition for future contracts.

What makes it DPI

A public data ingestion and standardisation layer for medicines. By using legal mandates to decouple patient data from proprietary clinical system backends, the state stops renting access to medical records. This shifts coordination away from private vendors into a secure, state-managed data environment tied to the patient’s unique NHS number.

How this will lead to growth

Makes routine NHS care a strategic asset for life sciences. Longitudinal medicines data supports real-world evidence for clinical trials and AI. The Scottish Combined Medicines Dataset (SCoMeD) has demonstrated the value of interoperable medicines records for world-class health research. Scaling this capability across England would strengthen the UK's competitiveness as a global life sciences and clinical research hub.

The problem

Starting a food business requires separate registration with HMRC, the local authority and often the Food Standards Agency. The same information is submitted multiple times to bodies that share nothing. The same pattern repeats across childcare, construction and dozens of other sectors.

The fix

A Business Commencement API: a new business registration at Companies House automatically triggers all relevant downstream registrations, using the company number as the universal identifier. Deliverable through secondary legislation under existing Digital Economy Act powers.

What makes it DPI

The company number becomes the coordination layer connecting tax identity, regulatory compliance and local authority records, without merging any bodies or building new databases. The same architecture later supports licence renewal and risk-based inspection.

How this will lead to growth

Friction tax elimination for every new business in the country. Reduces the cost of market entry, frees regulatory capacity for enforcement over data entry, and gives the government a real-time picture of business formation it has never had before.

The problem

Early years information is collected but not connected. Only 24% of local authorities and 16% of integrated care boards link local authority and health data on children; 14.5% of eligible children have an ASQ-3 assessment recorded nationally despite 78.6% completion locally, while 34% of eligible families miss Healthy Start support.

The fix

Mandate the Digital Red Book as the national standard for recording and sharing key early years events across health, local authority and family services. Building on previous Digital Red Book initiatives, this proposal moves beyond digitising the Personal Child Health Record to standardising how mandated Healthy Child Programme assessments, including the ASQ-3, are recorded. Information would be captured once and reused across care, parental access and national reporting.

What makes it DPI

A national child development information architecture. The Digital Red Book becomes the common information standard for recording developmental assessments, referrals and outcomes, linked through the NHS number and exchanged through interoperable APIs across health, local authority and family services.

How this will lead to growth

Makes early intervention scalable. Standardised child development information allows support to be delivered consistently across the country, increasing the effectiveness of existing programmes and reducing the costs of fragmented overlapping delivery.

Conclusion

The transition from a ‘tenant state’ to a sovereign digital nation is not a single digital transformation or IT project. It is a fundamental shift in the UK’s governing doctrine. For three decades, the British state has acted as a passive consumer of proprietary technology, effectively outsourcing its architectural agency to a handful of global vendors. The result is a fragmented estate that acts as a drag on growth rather than an engine for it.

Building DPI is the process of reclaiming that agency. By focusing on the coordination layer - the standards, protocols, and data commons that allow a modern economy to function - the state can move from being a mere renter of services to the architect of a new digital realm.

The five enablers outlined in this paper represent the minimum structural reform required: building sovereign technical capability, funding the digital commons, rewriting procurement law, mandating interoperability and establishing trusted digital verification. None are technically difficult, but all require political will to override the existing arrangements. 

The six use cases demonstrate the rewards for this effort are immediate and material. Whether it is unlocking £31 billion in dormant pensions, eliminating the £1.7 billion friction tax on our energy grid, or reducing millions of prescribing errors through interoperable health records. These are near-term achievable returns for governance decisions that could be made this year. The data, standards and infrastructure already exist; the question is whether we choose to use them.