Registers Instead of Certificates
Once-only taken to its conclusion: the state should not demand certificates it issues itself. What registers must deliver and where administrations can start.
Date
Author
Reading time
Tags

Anyone who hands a public authority a certificate of residence, a commercial register extract, or a criminal record certificate is proving something to the state that the state already knows. The EU's once-only principle requires that citizens and companies submit their data to the administration only once. This article takes the principle to its conclusion: the goal is not the digital certificate but doing away with the certificate altogether, because authorized bodies read directly from the register. We show what registers must deliver to make this possible and where administrations can start today.
The certificate is a detour via the citizen
The state establishes identity. It confirms who a person is, where they live, what they own, which company they represent, and whether they have a criminal record. This is precisely why nobody has to prove their own identity: passports, the land register, the commercial register, and the criminal register relieve people of that burden. That is how we describe it in our book Der selbstfahrende Staat (Springer Gabler 2024), and up to this point the principle is uncontroversial.
Things become odd only in the next step. As soon as an authority needs one of these facts for a procedure, it demands proof from the applicant: an extract, a confirmation, a certificate. The person goes to office A, collects a document, and carries it to office B so that office B will believe what office A already knows. The certificate is a detour via the citizen, a relic from a time when registers were made of paper and authorities could not exchange data with one another. Lengthy processes have grown out of this history, and they remain largely paper-based to this day, even though parts of them are being digitized step by step.
This partial digitization changes little. Anyone who needs a digital certificate of residence today must in many cases request it manually, download it, and upload it to another portal. For the administration and for the people concerned, virtually no improvement has been achieved; the detour is the same, only the medium has changed. In the two previous articles in this series we described the form (The Office Without Forms) and the application (Application-Free Government) as relics. The certificate is the third, and all three are connected: a form consists largely of fields a register could answer, and an application is often nothing more than a bundle of certificates.
A certificate the state demands from me is a piece of information it could give itself.
Once-only: what the principle requires and where Europe stands
The once-only principle is not a vision but applicable European law. Regulation (EU) 2018/1724 establishing the Single Digital Gateway obliges member states to exchange evidence for certain cross-border procedures through a common technical system; this Once-Only Technical System has been required to be operational since December 2023. With its Register Modernization Act of 2021, Germany laid the foundation for uniquely assigning individuals across administrative registers via a single identification number and provided for a data protection cockpit in which citizens can see which authority has retrieved which data. Austria has long had digital central registers such as the Central Register of Residents and the commercial register, works with sector-specific personal identifiers, and conducted its 2011 census entirely from registers. Estonia has shown since 2001, with its X-Road data exchange layer, how authorities query data from one another instead of demanding it from people.
The principle itself is formulated in our book as follows: all data is recorded, stored, and processed only once at the relevant location and can then be used by all authorized suborganizations. If a person registers a new address at the municipal office, the federal government can also access this registration data. And for registration via an app to work in every municipality, the federal government needs interfaces to all states and municipalities, because the registration system is organized federally despite the existence of a central register. For people, the benefit is tangible: they no longer have to re-enter the same data at every contact with the authorities or, as we describe it in the book, submit five or six documents.
One point is often overlooked in the debate. Once-only rests on a premise that underlies our entire book: we, the people, trust our democratic state and provide it with the data it needs for its tasks. This is not a new demand. Registers of residents, land registers, and court records have existed for a long time; the state has always had to hold data on its population in order to exercise its sovereign functions. What is new is that this data is being networked, and with networking, the traceability of every use becomes a condition.
What a register must deliver
Once-only stands or falls with the quality of the registers. A register is more than a database: in the book we describe digital registers as a special form of digital core component that stores and manages a state's master data pools, enables access, and at the same time implements the necessary access rights and logging rules. Five requirements follow from this:
- Unambiguous identity. Every person, every company, and every parcel of land needs an identifier through which data from different registers can be linked. The German feasibility study for an education register (Gawronski 2020), which we take up in the book, therefore starts by requiring a personal identifier; as long as it is missing, first name, surname, date of birth, and place of birth remain the minimum attributes for identifying a person unambiguously, and historical data cannot be linked cleanly. Germany solves this with the identification number, Austria with sector-specific identifiers.
- One authoritative source per item of master data. For every fact there is exactly one body that records it and is responsible for it. Everyone else reads. This applies regardless of whether the register is kept centrally at the federal level or distributed across municipalities.
- Standardized interfaces and complete data operations. Every record must be creatable, readable, editable, deletable, and searchable, and for each of these operations a precise rights structure must define who may perform it. Without standardized interfaces, data remains stuck where it originated, such as health data collected in another state that cannot be reused at home.
- Complete logging. Every access is stored, is visible to the person concerned, and can be audited. This is the real advance in data protection: a click-based search for a piece of sensitive information can be logged; leafing through stacks of files cannot.
- Federal equivalence. A digital state copes equally well with centralized and distributed data storage. Every municipality can keep its data in its own standardized register that is released to state and federal authorities through rights management; the state receives a virtual state register without the data having to move. Where a responsibility lies remains a political and legal question; technically it is easy to solve.
Whoever meets these five requirements can replace certificates with register queries step by step. The following overview shows which source underlies certificates commonly required in Germany and Austria today.
| Certificate today | Authoritative register | What is eliminated |
|---|---|---|
| Certificate of residence | Register of residents / Central Register of Residents | Requesting, printing, submitting |
| Birth certificate | Civil register / Central Civil Register | Certified copies for every procedure |
| Certificate of good conduct / criminal record certificate | Federal Central Criminal Register / Criminal Register | Application, fee, waiting time |
| Commercial register extract | Commercial register (Handelsregister / Firmenbuch) | An extract for every tender or funding application |
| Land register extract | Land register | Proof of ownership and encumbrances |
Taken to its conclusion: from certificate to digital twin
The evolutionary stages we describe in the book for all administrative services also apply to the certificate. In the analog state, parents appear in person at the office after a birth and present paper documents. In the digital state, they submit the same documents digitally, and the birth certificate is issued digitally. In the automated state, the birth certificate is generated automatically under the once-only principle from the data recorded by the hospital administration, and the follow-up processes start by themselves: notification of the responsible authorities, issuance of identity documents, application for benefits. Here the certificate has not been digitized; it has disappeared.
The final stage goes one step further. In the self-driving state, every person, every organization, and every company has a digital twin at the data level within the administration. For companies, this twin is created at incorporation and exists until closure; the existing registers store its master data, and by linking that data, procedures run without any action being required. Employment data then no longer has to be held and maintained redundantly by companies, municipalities, states, registers, social insurance institutions, ministries, statistical offices, and tax offices. For citizens, a Public Service Wallet brings together all identity documents, certificates, and confirmations in real time and without an application. The revision of the eIDAS Regulation adopted in spring 2024, Regulation (EU) 2024/1183, obliges member states to offer a European Digital Identity Wallet and points in exactly this direction.
What matters is what this wallet is not: it is not a folder of PDF certificates that people continue to upload. It is the person's view of their register data and of the accesses to it. The certificate no longer travels from office to office; the authorized office reads the register, and the person sees that it has done so. Only then has once-only been taken to its conclusion: the goal is not the digital certificate but the superfluous one.
Where it gets stuck in practice
In our projects with public administrations, we rarely find that the law prohibits a register query. As we note in the book, it is far less the legal questions of official secrecy or data protection that prevent mutual use than the historically grown distrust of data-processing bodies and the habit of thinking in data pools that are to be used only within one's own domain. Added to this is a craft problem: many procedural laws and regulations formulate the applicant's duty to furnish evidence, not the authority's duty to obtain it. As long as a law says "shall submit," the certificate remains, even if the register has long existed.
This suggests a pragmatic entry point that does not require a comprehensive reform:
- Draw up a certificate inventory. For every procedure in an organization, list which certificates are required, which register holds the underlying fact, and whether a query is already legally permissible. In our experience from public administration projects, most certificates originate from a handful of registers.
- Clarify responsibility for master data. For every fact, it must be established who maintains it and how mutual access, including logging, is regulated, especially where a central law is implemented differently across the states.
- Rephrase the duty to submit as a duty to obtain. With every amendment to a procedural rule, check whether "shall submit" can be replaced by "shall be obtained from the register." This is a question of legislative drafting, not of technology.
- Build interfaces and logging as a core component. Register queries do not belong in each specialized procedure individually but in a shared service that provides rights, logging, and disclosure for everyone.
- Make accesses visible. Citizens and companies should see which body read which data and when. This transparency is the quid pro quo for networking and the prerequisite for trust to hold.
One principle always applies: the digital state does not collect data indiscriminately; based on the legal situation, it records only the data it needs for its tasks and services. Once-only does not mean more data, it means fewer copies.
The next step
How registers, core components, and digital twins work together in the overall picture of the self-driving state is described in our book Der selbstfahrende Staat. To learn how we support public administrations with certificate inventories, clarifying responsibilities, and building register services, see our page on public administration.

More articles
Get in touch
Arrange a no-obligation initial conversation with our contact person.
Christian Buchegger
Chief Sales Officer & Authorised Signatory




