Skip to main content

Itsme? We say “it’s not me”, and here’s why.

By: ElioVP
November 27, 2025
AWS
Why We Do Not Use itsme: Privacy and Data Sovereignty

1. Introduction: the strategic case for refusal

In today's digital landscape, choosing an identity provider (IdP) is often reduced to a discussion about user experience (UX) and conversion rates. That narrow approach conceals the profound strategic, legal and operational risks of handing the “keys to the kingdom”, the authentication layer, to external parties. This report sets out the internal justification for our company policy of rejecting the itsme (Belgian Mobile ID) ecosystem for our employees and internal operations.

The prevailing narrative in the Belgian market presents itsme as a quasi-public utility, an innocuous digital equivalent of the physical identity card. Our forensic analysis reveals a different picture. This is not a sovereign public service, but a private commercial consortium dominated by banking and telecommunications giants, entities that already monetize intimate details of consumer behavior. Giving them the authentication layer would supply the final piece of the surveillance puzzle: the ability to track digital interactions across finance, healthcare and government services.

Our refusal rests on three non-negotiable pillars of our risk appetite:

  1. Data sovereignty and infrastructure integrity: We reject storing sensitive identity metadata on US-controlled cloud infrastructure (AWS), which remains subject to extraterritorial surveillance laws regardless of its physical location in Belgium.
  2. Privacy against commercial aggregators: We refuse to feed the data ecosystems of banks and telecommunications companies that already have excessive insight into our employees' private lives, metaphorically “the color of their underwear”.
  3. Metadata minimization: We consider centralized retention of transaction logs for 10 years, recording where, when and how often a user logs in, a disproportionate surveillance capability that conflicts with privacy-by-design principles.

This report examines these risks in detail, drawing on technical documentation, corporate filings and legislation to support our position that convenience must not come at the expense of digital autonomy.

2. The myth of the “Belgian” utility: corporate structure and foreign capital

Understanding itsme's risk profile first requires dispelling the misconception that it is a state-owned company. Although it holds government accreditation, Belgian Mobile ID NV is a privately held limited liability company. Its ownership structure is a who's who of the data economy, sectors that have historically treated personal information as a resource to extract rather than an asset to protect.

2.1. The shareholders: a consortium of data aggregators

Belgian Mobile ID was founded in 2017 as a joint venture between Belgium's “Big Four” banks and its three major mobile network operators (MNOs).

Table 1: shareholder composition and strategic conflicts

Shareholder sectorEntitiesPrimary business modelData already availableConflict of interest around identity
BankingBelfius, BNP Paribas Fortis, ING Belgium, KBC BankFinancial services, credit, insuranceTransaction histories, spending patterns, debt levels, asset values.Aggregation risk: Adding authentication data lets banks see intent, such as logging in with a competitor, before a transaction takes place.
TelecommunicationsProximus, Orange Belgium, TelenetConnectivity, media, advertisingReal-time cell-tower location, communication metadata, browsing behavior.Surveillance risk: Telecommunications companies control the physical layer. Linking the SIM (identity) to the app (authentication) creates a seamless tracking loop.
Government investmentFPIM (Federal Holding and Investment Company)State investmentPublic policyMinority interest: With only a 20% stake acquired in 2021 ^1, the state lacks operational control against the commercial majority.

The involvement of the Federal Holding and Investment Company (FPIM) is often cited to allay fears about privatization.3 A 20% stake, however, does not provide decisive control. Strategic direction, technology procurement and data-revenue policies are driven by the commercial majority of banks and telecommunications companies.4

This structure matters because these entities operate as data aggregators. Banks work under Know Your Customer (KYC) rules that give them deep insight into a citizen's financial life. By controlling the identity provider used to access non-banking services, such as healthcare, tax or legal services, these commercial entities gain visibility into the totality of a user's digital existence. They know not only that you paid a pharmacy, from banking data, but also that you logged in to a specialist oncology portal, from itsme metadata. Combining these datasets creates a “super-profile” of unprecedented granularity.

2.2. Foreign influence: Telenet and Liberty Global

A closer analysis of the consortium's “Belgian” character reveals substantial foreign-capital influence, introducing geopolitical risks incompatible with true data sovereignty.

Telenet, a founding shareholder and major mobile network operator in the scheme, is 100% owned by Liberty Global, a multinational telecommunications conglomerate headquartered in the UK, US and Bermuda.5 Telenet is not an independent Belgian actor; it is a subsidiary subject to its parent company's strategic and legal imperatives.

2.2.1. The transparency report: a pipeline to government surveillance

Our examination of Liberty Global's corporate governance reveals a substantial mechanism for disclosing data to government authorities. Liberty Global's own transparency reporting for 2024 states that it received 46,325 government inquiries concerning Telenet customers in Belgium.

Crucially, 90% of these requests resulted in the disclosure of customer data.8 Although these disclosures are framed within Belgian national rules, their sheer volume, averaging more than 126 requests per day, indicates that Telenet operates as an extremely efficient data pipeline to state security services.

For us, as a company rejecting itsme, the risk lies in the corporate veil. Liberty Global has deep ties to the US and UK markets.5 If the parent company receives a data request from a foreign jurisdiction, such as the United States, concerning a subsidiary's assets, internal corporate boundaries may prove porous. The US legal system, particularly through mechanisms such as the CLOUD Act discussed in Section 3, often disregards the separate legal personality of foreign subsidiaries where operational control can be established.

Liberty Global also acknowledges that for its other operations outside Belgium, national regulatory frameworks prohibit it from disclosing the number of government requests.8 This opacity is unacceptable. We cannot entrust our corporate identity infrastructure to a consortium partner whose parent company operates in a “black box” regarding government surveillance in other jurisdictions.

2.3. The international ties of other partners

The “Belgian” label is further weakened by the other partners:

  • BNP Paribas Fortis: A wholly owned subsidiary of French banking giant BNP Paribas. France has its own aggressive intelligence legislation, the Loi Renseignement.
  • ING Belgium: A subsidiary of the Dutch ING Group.
  • Orange Belgium: Controlled by France's Orange S.A., with more than 76% of the voting rights.

The itsme ecosystem is therefore effectively a joint venture of US/UK (Liberty Global), French (Orange and BNP) and Dutch (ING) capital. In a geopolitical crisis or a trade dispute over digital services, such as US versus EU technology regulation, these parent companies' loyalties will lie with their home jurisdictions and shareholders, not necessarily with the privacy of Belgian citizens or our employees.

3. Infrastructure vulnerability: AWS dependence and the end of sovereignty

The most direct reason for disqualification within our organization is Belgian Mobile ID's decision to migrate its infrastructure from on-premises data centers to the public cloud, specifically Amazon Web Services (AWS).9 Although this move is often justified by “scalability” and “modernization”,11 it fundamentally compromises the concept of data residency.

The Clarifying Lawful Overseas Use of Data (CLOUD) Act of 2018 is a US federal law that erodes protections based on data location. It explicitly empowers US law enforcement agencies to compel US-based technology providers, such as Amazon, to disclose data on their servers regardless of whether that data is stored in the United States or abroad.

This is not a theoretical risk. It is legislation.

  • Jurisdiction over the provider, not the data: The CLOUD Act asserts jurisdiction over the company, Amazon.com Inc. and its subsidiaries. If Amazon has “possession, custody or control” of the data, it must hand it over even if the server is physically in Brussels, Paris or Dublin.
  • Conflict with the GDPR: This creates a direct conflict with the GDPR, specifically Article 48, which restricts transfers based on foreign court orders unless a mutual legal assistance treaty (MLAT) applies. The CLOUD Act, however, often bypasses the MLAT process.12
  • The encryption defense is flawed: AWS often argues that it cannot produce data it cannot read, meaning encrypted data. However, if encryption keys are managed through AWS Key Management Service (KMS), or if keys are ever present in compute-instance memory to process an authentication request, AWS technically has the ability to decrypt it. Under a subpoena, it could be compelled to use that capability.13

For our company, this is a red line. We cannot claim to protect our employees' data if it sits on a server that a foreign judge in Virginia can seize without the knowledge or consent of Belgian authorities.

3.2. The “Local Zone” misdirection: Brussels is an outpost, not a fortress

Belgian Mobile ID and AWS have heavily promoted the launch of the AWS Local Zone in Brussels (eu-west-3-bru-1a) as a data-residency solution.9 They suggest that data “stays in Belgium”. Our technical analysis finds this a dangerous oversimplification.

3.2.1. Technical dependence on the parent region

An AWS Local Zone is not an independent cloud region. It extends a parent region. For the Brussels Local Zone, that parent region is Europe (Paris) (eu-west-3).

  • Control plane: The brains of the operation, including Identity and Access Management (IAM) systems, the API endpoints controlling infrastructure and configuration databases, reside in the parent region in Paris. An outage or compromise in Paris affects Brussels.
  • Data durability and replication: Critical services such as Amazon S3 (Simple Storage Service) are designed for extreme durability, typically achieved by replicating data across multiple Availability Zones (AZs). Because the Brussels Local Zone is often a single logical location, achieving high durability often requires replication back to the parent region in Paris.14
  • Snapshot storage: AWS documentation explicitly states that snapshots or backups created in a Local Zone for services such as Amazon EBS (Elastic Block Store) are stored in the parent region.

Therefore, even if compute takes place in Brussels, data, including backups, snapshots and potentially storage objects, flows to France. This places the data under French jurisdiction in addition to US jurisdiction through the CLOUD Act. The claim that “Belgian data stays in Belgium” is technically porous and legally inadequate.

3.3. The vendor lock-in risk

By migrating a national identity scheme to a proprietary US cloud, Belgian Mobile ID has created a single point of failure (SPOF). If AWS experiences a global outage, or Amazon decides to remove the service for commercial or geopolitical reasons, Belgium's digital identity infrastructure collapses. Our company advocates multicloud or hybrid-cloud resilience. Relying on one supplier for the identity of millions of citizens violates basic principles of operational continuity.11

4. The metadata panopticon: the “color of your underwear” problem

Our internal mandate asks why we should give banks and telecommunications companies more data when they already know “the color of our underwear”, a metaphor for the intimate financial and behavioral information they already hold. The itsme ecosystem intensifies this by creating a centralized metadata repository that tracks the context of every digital interaction.

4.1. Metadata is data

Belgian Mobile ID states that it does not see the content of documents you sign or the details of bank transactions, which is technically true with hash signing, discussed below. However, it explicitly logs the interaction's metadata.16

Table 2: the anatomy of the itsme audit trail

Data fieldDescriptionRetention periodPrivacy risk
TimestampExact date and time of the transaction.10 yearsReveals daily routines, sleeplessness through late logins, and working hours.
Service provider (SP)The entity requesting the identity, such as KBC Bank, UZ Leuven or the Federal Public Service Finance.10 yearsReveals the nature of the user's activity: banking, medical, government or legal.
Action typeLogging in, confirming a transaction, signing a document.10 yearsDistinguishes passive checking from active commitment.
Device telemetryIMEI, operating system, device model.10 yearsFingerprints the specific device and enables tracking of device changes.
Location indicator“Security Data” includes country location (MCC).10 years ^18Tracks international travel and location history.

4.2. Behavioral profiling through metadata aggregation

The danger lies not in a single log entry but in the aggregation of 10 years of this data. A 10-year retention period is grotesquely disproportionate for a simple authentication service.

Consider the story that can be constructed purely from the metadata itsme acknowledges storing:

  • Scenario A (medical): A user logs in to a general hospital portal, such as UZ Leuven, once a year. Suddenly, the frequency increases to weekly. They then log in to a specialist oncology service. Inference: serious illness.
  • Scenario B (financial): A user logs in to their main bank daily. Suddenly, within one week, they log in to three different consumer lenders and a debt-mediation service. Inference: financial distress.
  • Scenario C (legal/personal): A user logs in to a notary's or divorce lawyer's portal. Inference: a major life change or legal case.

This metadata forms a high-fidelity map of a person's life. It reveals what you do, whom you interact with and how often. For a consortium of banks and insurers that price risk, and telecommunications companies that sell advertising, this dataset is invaluable. Although they claim to maintain strict separation, the technical possibility of mining this data exists within the centralized servers.

4.3. “Security Data” and location tracking

The privacy policy explicitly mentions collecting “Security Data”, including the Mobile Country Code (MCC) and Mobile Network Code (MNC).18 This is derived from the SIM card.

Because the MNOs, Proximus, Orange and Telenet, are shareholders and “SIM Controllers”,17 there is a direct bridge between the physical network layer and the application layer.

  • The telecommunications view: Knows that the user is connected to cell-tower ID 12345 at 10:00.
  • The itsme view: Knows that the user logged in to Tax-on-web at 10:00.
  • The combined view: “User X was at location Y when they filed their tax return.”

This triangulation capability turns the identity app into a potential location tracker. For a company that values its employees' physical safety and privacy, allowing a third-party consortium to keep a 10-year log of location-correlated authentication events is an absolute no-go.

5. Security theater: the hash-signing flaw

One of itsme's main selling points is the qualified electronic signature (QES) and the principle of “What You See Is What You Sign” (WYSIWYS). The claim is that you always see what you sign. Technically, that claim is misleading and introduces a critical security gap known as the blind-signing vulnerability.

5.1. How hash signing works

In the current itsme implementation, the hash-signing variant,19 the process is:

  1. The user visits a website on their computer.
  2. The service provider displays the document's content to the user.
  3. The service provider calculates a cryptographic hash, a mathematical fingerprint of the document.
  4. The service provider sends only the hash to the itsme server.19
  5. The itsme app opens on the user's phone and displays a generic message: “Sign document for X”.
  6. The user enters their PIN and authorizes signing that hash.

5.2. The break in the chain

The fatal flaw is that the itsme app never sees the document.19 It sees only the hash. It therefore cannot verify for the user that the hash being signed actually corresponds to the document shown on their computer screen.

  • The threat model: If the service provider is malicious, or the user's browser is compromised by a man-in-the-browser attack, the screen can show an innocent “Contract A” while the background process sends the hash of a malicious “Contract B”, such as an asset transfer, to itsme.
  • The user experience: The user sees “Sign document for Bank” on their phone. They trust it and sign.
  • The result: The user has legally signed “Contract B” while believing they were signing “Contract A”.

This is not “What You See Is What You Sign”. Genuine WYSIWYS requires the signing device, the phone, to render the document's content independently or strictly verify the hash against a trusted display. By removing this context, itsme reduces signing to a blind act of faith in the service provider's integrity. We do not accept faith as a security control.

6. Institutional entanglement: the “Frank Robben” effect

The rapid rise of itsme cannot be separated from the distinctive institutional landscape of Belgian digital governance. Critics and privacy advocates have long pointed to the consolidation of power within a small circle of technocrats spanning the boundary between public mandates and private implementation.

Frank Robben, CEO of the Crossroads Bank for Social Security, founder of the eHealth platform and an administrator at Smals, symbolizes this entanglement. Although the state formally supervises the system, the structural reality remains: the Belgian state has aggressively promoted a private solution, itsme, as the default and often only viable mobile alternative to the physical eID card.

This creates vendor lock-in at national level. By deeply integrating itsme into the Federal Authentication Service (FAS) and promoting it for essential services, including tax, health and CovidSafeBE, the state has effectively privatized a core sovereign function: verifying its citizens.

  • Privatization risk: If Belgian Mobile ID NV decides to change its pricing for businesses, as it has done, or changes its terms to allow more aggressive data sharing, the Belgian ecosystem is held hostage. There is no easy switch to a public alternative because the state has underinvested in mobile eID in favor of relying on the consortium.

The government's recent launch of MyGov.be is seen as a belated attempt to regain this sovereignty, with State Secretary Mathieu Michel explicitly referring to the need for “control” and “sovereignty” missing from itsme.21

7. Conclusion: a policy of non-adoption

In short, rejecting itsme is a proactive measure to protect our corporate data perimeter and our employees' personal privacy. We are not technophobes; we are realists.

We do not use itsme because:

  1. We do not trust the shareholders: The consortium of banks and telecommunications companies has an inherent conflict of interest around data monetization.
  2. We do not trust the ownership: Liberty Global's 100% ownership of Telenet and its history of high data-disclosure rates create an unacceptable pipeline to foreign surveillance.
  3. We do not trust the infrastructure: Dependence on AWS and the US CLOUD Act makes data sovereignty an illusion.
  4. We reject the “color of your underwear” panopticon: Keeping granular transaction metadata for 10 years creates a surveillance database that we refuse to feed.
  5. We demand proof, not faith: The hash-signing protocol fails to give users cryptographic guarantees of content integrity.

As a company, we continue to use and support client-side certificate authentication, physical hardware tokens and self-sovereign identity (SSI) standards that keep keys and data firmly in users' hands, not those of a consortium.

Appendix: forensic data tables

Table 3: infrastructure sovereignty audit

ComponentProviderLocationJurisdictional risk
HostingAWS (Amazon)Brussels Local Zone / Paris parent regionCritical: Subject to the US CLOUD Act. The Local Zone's control plane resides in Paris, France.
NotificationsApple / GoogleWorldwideHigh: Metadata visible to US operating-system providers.
SIM controlProximus / Orange / TelenetBelgiumMedium: Telenet is 100% owned by US/UK holding company Liberty Global.
Root of trustBelgian government (National Register)BelgiumLow: But access to this root is guarded by the private consortium.

Table 4: the 10-year metadata risk assessment

Metadata fieldPotential inferenceCommercial value
Service provider ID“User logs in to a divorce lawyer's portal”High: marketing legal services.
Frequency“User logs in to a gambling site daily”High: insurance and lending risk assessment.
Time of day“User active between 02:00 and 04:00”Medium: health and lifestyle profiling.
Location (country)“User is in Thailand”Medium: fraud detection and travel-insurance sales.

The analysis above confirms that even when transaction content is encrypted, the metadata itsme acknowledges retaining for a decade provides a sufficiently detailed picture of user behavior to constitute a serious privacy violation.

References

  1. Federal Government renews Itsme accreditation for three years – The Brussels Times
  2. Proximus – Integrated annual report 2023
  3. itsme® raises €24.7 million to finance ambitious growth plans
  4. Namirial integrates itsme® with its Signature Platform to streamline compliant Digital Transactions in Belgium and beyond
  5. Liberty Global – Wikipedia
  6. LG-2024-10-K-ANNUAL-REPORT.pdf – Liberty Global
  7. VOLUNTARY AND CONDITIONAL TAKEOVER BID IN CASH possibly followed by a Simplified Squeeze-Out by LIBERTY GLOBAL BELGIUM HOLDING B – FSMA
  8. Data Privacy Protection – Liberty Global
  9. Scaling national identity schemes with itsme and Amazon Cognito | AWS Security Blog
  10. Billit subprocessors
  11. Belgian Mobile ID: It’s all about scalability. – Codit
  12. What is your opinion of Itsme? : r/belgium – Reddit
  13. Belgian Council of State Considers Encryption a Sufficient Measure for U.S. Data Transfers
  14. Government extends accreditation for itsme®
  15. Which ID data do I share? – itsme Customer Support
  16. Privacy Policy: itsme App & Services
  17. itsme® App Privacy Policy
  18. itsme® App Terms & Conditions
  19. 1-introduction – itsme® Sign documentation – GitHub Pages
  20. itsme® Signature Creation Service Policy
  21. Belgium launches MyGov.be, a state-run alternative to Itsme – The Brussels Times