top of page


Estonia’s Data Governance Lesson for Digital States
Estonia’s data governance failures show why digital identity, registries, portals and data exchange must be governed as lawful public authority.
Ott Sarv
May 29


Why Canonical Records Are the State’s Memory, Not Just a Database
Canonical records are the state’s lawful memory: the records that determine which facts public services may recognise, rely on, correct and defend.
Ott Sarv
May 22


The Module Is Not the Rail: Rethinking DPI in Africa
Digital identity, payments and data exchange are shared capabilities. Regional DPI works only when they are composed around lawful Digital Public Functions with accountable institutions, authoritative records, validation and remedy.
Ott Sarv
May 6


The DPI Debate Is Not About Platforms. It Is About Authority
Shared DPI platforms are useful, but they do not decide who has authority, which records are canonical, which rules apply, or how people can challenge and correct outcomes.
Ott Sarv
May 2


Digital Identity Safeguards Before Trust Frameworks
Safeguards are the entry point, not the destination. Digital identity becomes trustworthy only when risks are converted into legal authority, institutional roles, validation, supervision, lifecycle funding and remedy.
Ott Sarv
Apr 30


Global DPI Governance: Europe’s Contribution Beyond Regulatory Templates
Europe should not export DPI as a regulatory template or technical stack. Its stronger contribution is a governance-rich model for lawful, attributable, reviewable and remediable digital public action.
Ott Sarv
Mar 31


SADC Regulatory Sandboxes Need a Clearer Legal Home
Regional sandbox cooperation is useful, but it is not a legal home. SADC should operate as a coordination layer beneath AU frameworks and alongside AfCFTA where digital trade is engaged.
Ott Sarv
Mar 25


GovStack Modularity and Trust Frameworks: Executive Summary
GovStack building blocks can support reuse, but trust-layer modularity must be more than software assembly. Trust services need legality gates, service contracts, evidence artefacts and inspection hooks before scale.
Ott Sarv
Mar 1


Autonomous Legal Acts: When the Protocol Becomes the Proclamation
When protocol execution creates legal consequence, the state must prove that authority, mandate, canonical facts, executable rules, attribution, evidence and remedy remain intact.
Ott Sarv
Feb 24


Law as an API: Architecting Autonomous Legal Acts in the 2026 Data Economy
In an agent-centric data economy, law must become executable without losing authority, discretion, attribution or remedy. This article defines Legal APIs, Autonomous Legal Acts and sovereign endpoints.
Ott Sarv
Feb 18


Blockchain in Government: Governance Before Technology
Consensus is not a mandate. Before adopting blockchain, define legal effect, accountable institutions, correction at source, and enforceable remedy.
Ott Sarv
Jan 2


DPI is not DPG, DPF, or DPS: why confusing these terms is costing governments billions
Reuse scales safely only when Digital Public Infrastructure, Digital Public Goods, Digital Public Functions and Digital Public Services are governed with distinct ownership, evidence duties and remedy paths.
Ott Sarv
Nov 29, 2025


DPI safeguards: why guidance without enforcement fails
DPI safeguards are not principles or checklists. They become real only when competent authorities can suspend effect, compel evidence, correct records, propagate correction and reverse outcomes.
Ott Sarv
Nov 1, 2025


The DPI Trap: Governance Drift Turns Rails into Platforms
DPI programmes drift when shared rails absorb policy logic, mandate and remedy. This article distinguishes DPI, DPS, DPF and DPG, then shows how safeguards become enforceable sequencing gates.
Ott Sarv
Sep 29, 2025


Donor Wallet, No Cross-Match: Why Policy-Agnostic GovStack Wallets Fail in Government
A GovStack-style wallet can scan perfectly and still fail under public scrutiny. This article defines the Seven Layer cross-match gates for wallet reliance, evidence, recovery and remedy.
Ott Sarv
Sep 10, 2025


Digital Public Infrastructure: Law Before Code
Law before code means a digital permit, benefit or licence becomes legitimate only when authority, mandate, canonical records, service logic, attribution, interface and remedy precede automation.
Ott Sarv
Aug 27, 2025


Data Exchange Platform Governance: Plumbing Does Not Grant Access
Data exchange rails provide trust plumbing, not ownership or access rights. Each disclosure must remain tied to legal authority, institutional mandate, necessity, correction at source and remedy.
Ott Sarv
Aug 14, 2025


Digital Sovereignty Through DPI Sequencing
A digital system can move money, route data or issue credentials without lawful public authority. DPI becomes sovereign only when authority, mandate, records, execution, evidence and remedy are sequenced before scale.
Ott Sarv
Jul 31, 2025
Download The Seven Layer Model for Digital Public Infrastructure
bottom of page