Why Canonical Records Are the State’s Memory, Not Just a Database
- Ott Sarv
- May 22
- 15 min read
Updated: May 25

Canonical records are the state’s lawful memory: the records that determine which facts public services may recognise, rely on, correct and defend. They are not merely databases. They carry authority, custodianship, correction duties and evidence rules, so digital decisions remain attributable, reviewable and correctable.
A canonical record is an authoritative public record that controls which fact the state may rely on for a defined public purpose. It has a lawful source, a named custodian, reliance rules, correction duties and evidence that can be reconstructed when the record is challenged.
A child is born abroad. The birth is notified to one authority, transliterated by another, entered into the civil register with one spelling, and later used by a passport office, a school, a health service and a border system. One record carries the parents’ names with diacritics. Another drops them. A third treats the child’s citizenship status as pending. The interface still looks clean. The service still returns an answer. The family only discovers the gap when a passport appointment fails or a school enrolment cannot be completed.
The problem is not merely inconsistent data. It is the state remembering the same person in different ways.
A civil register is not important because it is a database. It is important because it tells public institutions which birth, name, parentage, civil status and identity particulars the state is prepared to recognise. When that record is wrong, incomplete or not properly propagated, the error does not stay inside the registry. It travels into passports, schools, benefits, health services, border checks, wallets, credentials and every later decision that treats the civil record as settled.
That is why canonical records are not a database layer. They are the state’s memory. They decide which facts public institutions may rely on, which institution is answerable for those facts, and how a wrong fact can be corrected before it keeps producing lawful-looking but wrong outcomes.
The Seven Layer Model for Digital Public Infrastructure treats canonical records as Layer Three because records sit between public authority and digital execution. In Seven Layers terms, the sequence is Legal Authority, Institutional Mandate, Canonical Records, Service Logic, Evidence Layer, User Interface, and Remedy. Legal Authority may create the public function. Institutional Mandate may assign responsibility. But the civil register, company register, land register, tax register or biometric record class often supplies the fact on which the public act depends.
When a civil-status fact changes, the test is not whether one registry was updated. The test is whether every public service relying on that fact can discover the corrected state.
Why is a record not authoritative just because a system can query it?
A record is not authoritative merely because it is available to a system. Authority depends on whether the record is legally recognised as the source that controls a specific public fact, and whether a named custodian is responsible for correction, evidence and lawful reuse.
A civil register shows why availability is not authority. A system may query a record, copy it into another service, or convert it into an attribute for a wallet, but none of that proves that the record is the recognised source for the public act being performed.
The distinction is simple. A database stores data. A canonical record carries recognised evidentiary authority for a defined public purpose. It is not merely accurate, current or machine-readable. It is maintained by a named custodian, under a lawful mandate, with correction duties and reliance rules that other institutions can understand.
Availability is not authority.
This matters most when records travel. The Interoperable Europe Act recognises that cross-border digital public services require more than technical connectivity. It frames interoperability as a legal, organisational, semantic and technical discipline, not only as system-to-system exchange.
Legal interoperability begins with a question that technical exchange cannot answer on its own: which fact is recognised as the fact that controls the public act?
The state cannot rely on memory it cannot correct
A canonical record must be correctable because digital reuse turns one wrong fact into repeated public harm. The record must support challenge, amendment, audit history and propagation, so that correction reaches the services and decisions that depended on the old state.
Without correction, the record becomes a machine-readable injury. It can be exchanged, cached, presented, validated and reused, but the person affected remains trapped inside the original error.
Correction is not a helpdesk function. It is a public power. Someone must be able to receive the challenge, inspect the source, amend the record, mark the reason for the amendment, preserve the previous state for audit, and propagate the corrected state to the places where the wrong record was relied upon.
The Seven Layers article on data exchange platform governance states the operational test directly: a lawful data exchange must show which institution can correct the canonical record, which institution must reverse downstream effects, and how that correction propagates. It also draws the boundary clearly: a data exchange platform connects agencies, but it does not transfer ownership of sector data or create entitlement to receive it.
That rule is the heart of canonical-records governance. The platform may move the fact. It does not own the fact. The relying institution may use the fact. It does not become the custodian of the source. The person affected may challenge the consequence. The remedy must reach the institution that can correct the record at source.
Why does once-only reuse fail without record authority?
Once-only reuse fails without record authority because availability alone does not prove that a record is current, lawful, necessary or correctable. Reusing the wrong fact across many services does not reduce burden. It distributes the same error more efficiently.
The once-only principle is often presented as administrative kindness. People should not have to provide the same information repeatedly when the state already holds it. That is right, but incomplete.
Once-only only works when the reused record is recognised, current, necessary and correctable. Otherwise, the state simply reuses the same mistake with greater efficiency.
Once-only reuse should never mean once wrong, wrong everywhere. Reuse must depend on record authority, correction and propagation.
The Interoperable Europe Act places the once-only principle inside a wider interoperability setting. It covers cross-border services that depend on exchange of data, including professional qualifications, social security and health data, taxation, customs, public tender accreditation, driving licences, commercial registers and once-only services.
A wrong education record, company record, social-security record, civil-status record or tax record is not a harmless data error. It can change rights, duties, eligibility, market access, professional recognition or family life.
The practical rule is stricter than reuse. Do not reuse a record merely because it is available. Reuse it only when the record’s authority, custodian, purpose, correction route and evidentiary status are clear.
Can a wallet replace the source record?
A wallet cannot replace the source record. It may present an attribute, but the authentic source grounds it, the issuer attests it, the relying party uses it and the custodian remains responsible for correction.
This distinction matters because the European wallet architecture is not a global theory of foundational identity. It is an electronic identification, attribute-presentation and trust-services architecture. It should not be read as replacing civil registration, population registers, national ID systems or other canonical records that control authoritative public facts.
The amended European electronic identification and trust-services framework separates wallet functionality from the authority of authentic sources. It defines an authentic source as a “repository or system” recognised as a primary or authentic source under Union or national law.
The wallet presents. The authentic source grounds. The issuer attests. The relying party decides. The custodian corrects.
That structure is not a mere technical feature. It is a governance clue. When those roles collapse, wallets become attractive containers for uncertain authority.
In many Global South contexts, identity is often discussed as foundational identity, civil registration, population registration, national ID infrastructure or eligibility infrastructure. A European wallet should not be understood as replacing those record systems. It depends on them. Those systems remain part of the Canonical Records layer because they control the authoritative facts that a wallet may later present.
A business wallet makes the same problem visible for legal persons. A company may present representation rights, registration status, tax status, licences or beneficial ownership attributes. Each attribute depends on a record with its own custodian, legal basis, update cycle and correction path. A wallet can make presentation easier. It cannot decide which company register controls the fact, which authority may amend it, or what happens when the record is wrong.
When does biometric material become a canonical-records issue?
Biometric material becomes a canonical-records issue when it is captured, structured, stored, compared or reused as digital record material for identification, authentication, enrolment, deduplication, border control, benefit access or credential binding.
Biometric material creates one of the hardest cases for canonical-records governance because it is not confidential in the ordinary sense.
People walk through streets, airports, schools, hospitals and public offices with their faces, voices, gait, fingerprints and other bodily characteristics exposed. The governance problem does not begin because those characteristics are hidden. It begins when they are captured, structured, stored, compared or reused as digital record material.
Once biometric material is processed for identification, authentication, deduplication, enrolment, border control, benefit access or credential binding, it becomes more than an observable feature of the body. It becomes a computable record. It can be matched across contexts, linked to other records, reused by other systems, and relied upon in public decisions.
Public visibility is not lawful reusability.
That is why biometric material belongs inside the Canonical Records layer. The question is not whether it is confidential. The question is how it is classified, who may use it, which public function justifies it, which institution holds custody, what evidence is retained, how errors are challenged, and how misuse is restricted.
A facial image used for a passport, a fingerprint template used for deduplication, a liveness event used for enrolment, or a match result used for access to a public service may all be records. Their visibility in daily life does not remove their governance status.
The control is therefore not secrecy. The control is lawful classification.
The GDPR defines biometric data by reference to “specific technical processing” relating to physical, physiological or behavioural characteristics that allow or confirm unique identification. The point is not secrecy. The point is that technical processing turns observable bodily characteristics into governed record material.
The state does not need to pretend biometric material is confidential to govern it. It needs to recognise that public exposure does not authorise public reuse.
A source sample, derived template, match event and correction record are not the same governance object. Each needs its own authority, purpose, custody, retention, access, audit and remedy rule.
How should biometric record classes be governed?
Biometric record classes should be governed separately because a source sample, derived template, enrolment record, match event and correction record do not perform the same public function. Each class needs its own authority, purpose, custody, retention, access, audit and remedy rule.
A source sample is captured material such as a facial image, fingerprint, iris image, voice recording or similar material. It should be classified by lawful purpose, capture authority, custody, retention and permitted reuse.
A derived template is a technical representation used for comparison or verification. It should be governed as derived record material with strict purpose limitation and access control.
An enrolment record confirms that a person was enrolled into an identity, border, benefit, credential or service-access system. It becomes canonical where enrolment has legal or operational effect.
A deduplication result records a match, non-match or identity resolution event. It must preserve review evidence because false matches and false non-matches may affect rights or access.
An authentication event records that biometric verification was attempted, succeeded, failed or was restricted. It should keep sufficient audit evidence without turning authentication logs into general surveillance records.
A credential-binding record links a person, wallet, credential, device or authentication factor. It should be governed as a reliance record where binding determines whether a service may trust the credential.
A correction or restriction record limits use, corrects an association, rebinds identity or marks dispute. It is a remedy record that must propagate to affected services and relying parties.
Layer Three is where biometric material becomes governable: not because the body is confidential, but because digital reliance must be lawful, attributable, reviewable and correctable.
The single source of truth is a dangerous shortcut
The single source of truth is a dangerous shortcut because the state usually relies on many authoritative records, not one universal database. Each record controls a specific fact, purpose and legal effect, so the real governance task is record authority mapping.
Digital government often reaches for the phrase single source of truth. It sounds clean. It is also misleading.
The state rarely has one source for everything. It has many recognised records, each authoritative for a specific fact, purpose and legal effect. A population register may control identity particulars. A company register may control legal existence. A land register may control property rights. A tax register may control fiscal status. A professional register may control qualification. A civil register may control birth, name, parentage, marriage, divorce, adoption or death. A court record may control insolvency, restriction or legal incapacity.
The discipline is not to collapse those records into one technical source. The discipline is to know which record controls which public question.
That is why canonical-records governance should not begin with database consolidation. It should begin with a record authority map. Each relied-upon fact should have a named source, lawful basis, custodian, permitted reliance context, correction route, propagation duty and evidence requirement.
A clean platform without that map becomes a confidence machine. It returns answers faster than the state can explain them.
How do you test whether a record is authoritative?
A record is authoritative only when the controlled fact, legal basis, custodian, permitted reliance, correction route, propagation duty and review evidence are clear. If any of these are missing, the record may be useful data, but it should not govern public rights.
A record should not become part of Digital Public Infrastructure until it can pass a simple test.
The test begins with the fact the record controls. The specific public fact, attribute, status, entitlement, restriction, biometric material or relationship must be defined.
The next question is which law or lawful instrument recognises it. The record’s authority must have a legal source, not merely an administrative habit.
The custodian must then be named. A recognised body must own stewardship, update duties, correction and evidentiary accountability.
Permitted reliance must also be clear. Public institutions should know who may rely on the record, for which purposes and under which mandate.
The correction route must be operable. The affected person or institution must know how to challenge, restrict, correct or rebind the record.
Correction propagation must be part of the design. Downstream services, wallets, attestations, data exchanges and decisions must receive or discover the corrected state.
Review evidence must survive. The system must preserve source, version, timestamp, basis, actor, disclosure and reliance evidence.
If biometric material is involved, the system must classify the sample, template, enrolment event, match result, binding record and correction record before public reliance occurs.
This test is not bureaucracy. It is the minimum condition for digital reliance. A public service may be fast only after the state knows what it is relying on.
Data exchange needs record discipline before routing discipline
Data exchange needs record discipline before routing discipline because a platform can move a fact but cannot decide whether that fact is authoritative. Before reuse, the system must know which source controls the fact, who may rely on it and how correction works.
Data exchange platforms often present themselves as neutral infrastructure. In one sense, they are. They route requests, secure transmissions, identify participants, log events and help agencies avoid point-to-point integration. That is useful.
Neutral routing, however, does not remove the need for record authority. A request must still show why the data is needed, which institution has mandate, which source controls the requested fact, and which remedy is available if reliance on that fact causes harm.
The Seven Layers article on data exchange platform governance makes this point through mandate gating. It states that ecosystem membership gives capability, not entitlement, and that permission to receive a specific data point must be traceable to institutional purpose and mandate-bound procedure.
Canonical records make mandate gating real. Without them, access control becomes an exercise in permissions management rather than lawful reliance. The system can decide who may ask. It cannot prove whether the answer should govern.
Data exchange can route a fact. It cannot decide whether the fact is authoritative for the public act being performed.
What evidence must travel with record reliance?
Evidence must show what was relied upon, when, from which source, under which authority and with what consequence. The relying service may not need the full record, but review must be able to reconstruct the record chain.
A canonical record does not need to expose every detail every time it is used. Data minimisation remains essential. Yet minimisation must not destroy evidentiary sufficiency.
A relying institution may not need the full record. It may only need confirmation of a status, attribute or eligibility condition. But if that confirmation later becomes contested, the system must be able to reconstruct enough evidence to show what was relied upon, at what time, from which source, under which authority and with which result.
The amended European electronic identification and trust-services framework reflects a related discipline for public-sector attribute attestations. Where an electronic attestation of attributes is issued by or on behalf of a public sector body responsible for an authentic source, the framework requires the public authority behind the attribute to remain visible through the attestation structure.
That is exactly the kind of discipline canonical-records governance needs. The fact may be presented as an attribute. The public authority behind the attribute must remain visible.
The relying service may not need the full record, but review must still reconstruct source, time, authority, disclosure and consequence.
What fails when canonical records are treated as ordinary data?
When canonical records are treated as ordinary data, the state may lose the ability to identify the controlling source, correcting custodian, relied-upon version and downstream effects of correction. The service may work, but the decision becomes difficult to defend
When canonical records are treated as ordinary data assets, the failure usually appears late.
The service works. The form is pre-filled. The attribute verifies. The biometric comparison succeeds. The decision is issued. The dashboard shows reduced processing time. Only when the person contests the outcome does the gap become visible.
Nobody can say which record controlled the decision. Nobody can identify the custodian who must correct it. Nobody can reconstruct the version that was relied upon. Nobody can show whether a later correction reached the service, the wallet, the relying party or the case file. Nobody can explain whether the biometric match was authoritative, evidentiary, operational or merely a signal inside a wider decision process.
At that point, the dispute is no longer only about the person’s eligibility. It is about whether the state can explain its own memory.
A record that cannot be corrected is not canonical. A record that cannot be attributed is not canonical. A record that cannot be reconstructed under review is not canonical. It may still be useful data. It should not control public rights.
The operating model for canonical records
Canonical records become governable through designation, custodianship, reliance rules, classification, versioning, correction procedures, restriction procedures, propagation, disclosure evidence and review access. These controls make records usable for lawful digital reliance.
Canonical records need an operating model, not a slogan
Record designation identifies which register, source, biometric class or record source controls a defined public fact.
Custodianship names the institution responsible for stewardship, correction and evidence.
Reliance rules define who may rely on the record, for which purposes and under which mandate.
Classification distinguishes administrative records, authentic sources, attestations, biometric samples, templates, match events, logs and remedy records.
Versioning preserves the state of the record at the time of reliance.
Correction procedure allows affected persons and institutions to challenge and amend wrong records.
Restriction procedure allows disputed, compromised, unlawfully reused or unreliable records to be restricted before continued reliance causes further harm.
Propagation ensures corrected or restricted records affect downstream services, attestations, wallets and decisions.
Disclosure evidence records what was disclosed, to whom, when, why and under which authority.
Review access allows supervisors, courts or appeal bodies to reconstruct the record chain without exposing more record material than review requires.
This operating model should be visible in procurement, legislation, service design, wallet architecture, data exchange governance and supervision. Otherwise canonical records remain a diagram label rather than a public control
A system requirement should not only ask for integration with registers. It should require record authority mapping, correction propagation and review evidence.
How should digital government measure record authority?
Digital government should measure whether the state can identify the controlling record, compel correction, reconstruct evidence, propagate updates and change outcomes when a relied-upon fact is wrong. Transaction volume alone does not prove lawful digital government.
Digital government programmes often count services online, integrations completed, transactions processed and documents eliminated. These measures are not useless. They are incomplete.
A stronger measure asks whether the state can govern the facts on which its digital decisions depend.
Can a person identify the record that controlled the outcome?
Can the custodian be compelled to correct it?
Can the relying institution explain why it used that record?
Can the evidence be reconstructed?
Can a correction propagate to the services that relied on the old state?
Can oversight change the outcome?
If biometric material was used, can the system show what class of biometric record was processed, why it was necessary, who authorised it, and how a false match or false rejection can be challenged?
Those questions are harder than a transaction count. They are also closer to public trust.
Interoperability without canonical records moves uncertainty faster. Wallets without canonical records present uncertainty more elegantly. Automation without canonical records executes uncertainty at scale. Biometric processing without canonical-records classification turns observable bodily characteristics into reusable public records without first making them governable.
Without record authority, digital government risks governance drift: the point where systems begin producing outcomes that look operationally valid but are difficult to attribute, correct or reverse. Trusted digital services require more than availability and uptime. They require lawful records, accountable custodianship, correction propagation and reviewable evidence.
The state’s memory must be lawful before it becomes machine-readable.
The core rule for canonical records
Canonical records are not a data-management preference. They are the evidentiary layer that allows Digital Public Infrastructure to remember, rely, classify, correct and answer for the facts and record material it uses.
A platform can retrieve a record. A wallet can present a record. A biometric system can compare a record. A service can act on a record.
Only a lawful architecture can make the record governable.
















































