1 00:00:01,000 --> 00:00:02,809 Almost 30 years ago, 2 00:00:02,833 --> 00:00:06,750 my country was facing the need to rebuild everything from scratch. 3 00:00:07,333 --> 00:00:09,518 After years of Soviet occupation, 4 00:00:09,542 --> 00:00:13,768 Estonia regained its independence, but we were left with nothing. 5 00:00:13,792 --> 00:00:18,226 No infrastructure, no administration, no legal code. 6 00:00:18,250 --> 00:00:20,125 Organizational chaos. 7 00:00:20,708 --> 00:00:21,976 Out of necessity, 8 00:00:22,000 --> 00:00:25,434 the state leaders back then had to make some daring choices. 9 00:00:25,458 --> 00:00:28,018 The ones that our country could afford. 10 00:00:28,042 --> 00:00:30,934 There was a lot of experimentation and uncertainty 11 00:00:30,958 --> 00:00:32,768 but also a bit of luck involved, 12 00:00:32,792 --> 00:00:35,434 particularly in the fact that we could count on a number 13 00:00:35,458 --> 00:00:37,018 of brilliant visionaries, 14 00:00:37,042 --> 00:00:40,184 cryptographers and engineers. 15 00:00:40,208 --> 00:00:42,476 I was just a kid back then. 16 00:00:42,500 --> 00:00:46,792 Today, we are called the most digital society on earth. 17 00:00:48,167 --> 00:00:49,434 I'm from Estonia, 18 00:00:49,458 --> 00:00:53,559 and we've been declaring taxes online since 2001. 19 00:00:53,583 --> 00:00:58,309 We have been using digital identity and signature since 2002. 20 00:00:58,333 --> 00:01:01,684 We've been voting online since 2005. 21 00:01:01,708 --> 00:01:04,976 And for today, pretty much the whole range of the public services 22 00:01:05,000 --> 00:01:06,518 that you can imagine: 23 00:01:06,542 --> 00:01:11,059 education, police, justice, starting a company, 24 00:01:11,083 --> 00:01:13,976 applying for benefits, looking at your health record 25 00:01:14,000 --> 00:01:16,059 or challenging a parking ticket, 26 00:01:16,083 --> 00:01:19,143 that's everything that is done online. 27 00:01:19,167 --> 00:01:21,934 In fact, it's much easier to tell you 28 00:01:21,958 --> 00:01:25,351 what are the three things we cannot yet do online. 29 00:01:25,375 --> 00:01:28,768 We have to show up to pick up our ID documents, 30 00:01:28,792 --> 00:01:30,851 get married or divorced, 31 00:01:30,875 --> 00:01:32,684 or sell real estate. 32 00:01:32,708 --> 00:01:34,292 That's pretty much it. 33 00:01:36,208 --> 00:01:39,809 So, that's why don't freak out 34 00:01:39,833 --> 00:01:41,934 when I tell you that every year 35 00:01:41,958 --> 00:01:45,851 I can't wait to start doing my tax declaration. 36 00:01:45,875 --> 00:01:46,893 (Laughter) 37 00:01:46,917 --> 00:01:48,934 Because all I have to do 38 00:01:48,958 --> 00:01:51,059 is sit on my couch with a mobile phone, 39 00:01:51,083 --> 00:01:55,101 swipe a few pages with prefilled data on income and deductions 40 00:01:55,125 --> 00:01:56,809 and hit submit. 41 00:01:56,833 --> 00:01:58,393 After three minutes, 42 00:01:58,417 --> 00:02:01,059 I'm looking at the tax return amount. 43 00:02:01,083 --> 00:02:05,393 It actually feels like a quite rewarding experience. 44 00:02:05,417 --> 00:02:07,434 No tax advisers, 45 00:02:07,458 --> 00:02:09,726 no collecting receipts, 46 00:02:09,750 --> 00:02:11,292 no doing the math. 47 00:02:12,625 --> 00:02:15,393 And have I mentioned that I have not visited a state office 48 00:02:15,417 --> 00:02:16,958 for almost seven years? 49 00:02:18,667 --> 00:02:21,976 Indeed, one of the features of the modern life 50 00:02:22,000 --> 00:02:24,184 that has no reason to exist anymore, 51 00:02:24,208 --> 00:02:27,018 considering technological possibilities of today, 52 00:02:27,042 --> 00:02:29,684 is the labyrinth of bureaucracy. 53 00:02:29,708 --> 00:02:32,351 We've almost got rid of it completely in Estonia, 54 00:02:32,375 --> 00:02:36,518 in an effort coordinated by the government that has also digitized itself. 55 00:02:36,542 --> 00:02:41,458 For instance, cabinet of ministers work in e-Cabinet is absolutely paperless. 56 00:02:43,375 --> 00:02:46,476 The central idea behind this development 57 00:02:46,500 --> 00:02:49,184 is transformation of the state role 58 00:02:49,208 --> 00:02:52,125 and digitalization of trust. 59 00:02:52,833 --> 00:02:54,101 Think about it. 60 00:02:54,125 --> 00:02:57,976 In most countries, people don't trust their governments. 61 00:02:58,000 --> 00:03:01,059 And the governments don't trust them back. 62 00:03:01,083 --> 00:03:04,351 And all the complicated paper-based formal procedures 63 00:03:04,375 --> 00:03:06,851 are supposed to solve that problem. 64 00:03:06,875 --> 00:03:09,143 Except that they don't. 65 00:03:09,167 --> 00:03:12,393 They just make life more complicated. 66 00:03:12,417 --> 00:03:17,101 I believe Estonian experience is showing that technology can be the remedy 67 00:03:17,125 --> 00:03:18,934 for getting the trust back, 68 00:03:18,958 --> 00:03:20,934 while creating an efficient, 69 00:03:20,958 --> 00:03:24,976 user-centric service delivery system 70 00:03:25,000 --> 00:03:28,458 that actively responds to citizens' needs. 71 00:03:29,833 --> 00:03:33,768 We did not do it by digitizing bureaucracy as it is. 72 00:03:33,792 --> 00:03:38,184 But by rather agreeing on a few strong, common principles, 73 00:03:38,208 --> 00:03:40,684 redesigning rules and procedures, 74 00:03:40,708 --> 00:03:43,309 getting rid of unnecessary data collection 75 00:03:43,333 --> 00:03:45,268 and task duplication, 76 00:03:45,292 --> 00:03:48,851 and becoming open and transparent. 77 00:03:48,875 --> 00:03:50,268 Let me give you a glimpse 78 00:03:50,292 --> 00:03:53,958 into some of the key e-Estonia design principles today. 79 00:03:56,042 --> 00:04:00,893 First, it is essential to guarantee privacy and confidentiality 80 00:04:00,917 --> 00:04:03,059 of data and information. 81 00:04:03,083 --> 00:04:06,643 This is achieved through a strong digital identity 82 00:04:06,667 --> 00:04:08,518 that is issued by the state 83 00:04:08,542 --> 00:04:10,559 and compatible with everything. 84 00:04:10,583 --> 00:04:13,125 In fact, every Estonian has one. 85 00:04:14,000 --> 00:04:18,559 The identity is doubled with a strong digital signature 86 00:04:18,583 --> 00:04:22,768 that is accepted, used and legally binding 87 00:04:22,792 --> 00:04:25,500 both in Estonia and European Union. 88 00:04:26,708 --> 00:04:32,101 When the system can properly and securely identify who is using it, 89 00:04:32,125 --> 00:04:37,018 after logging in, it will provide access to the personal data of the citizen, 90 00:04:37,042 --> 00:04:40,809 and all the public services within one tool 91 00:04:40,833 --> 00:04:44,625 and allow to authorize anything by signing digitally. 92 00:04:46,583 --> 00:04:50,226 A second principle, and one of the most transformative, 93 00:04:50,250 --> 00:04:53,268 is called "Once only." 94 00:04:53,292 --> 00:04:57,184 It means that the state cannot ask for the same data 95 00:04:57,208 --> 00:04:59,059 more than once. 96 00:04:59,083 --> 00:05:02,893 Nor can store it in more than one place. 97 00:05:02,917 --> 00:05:04,184 For instance, 98 00:05:04,208 --> 00:05:07,143 if you've already provided your birth or marital certificate 99 00:05:07,167 --> 00:05:09,101 to the population registry, 100 00:05:09,125 --> 00:05:12,059 this is the only place where this data is going to be held. 101 00:05:12,083 --> 00:05:16,625 And no other institution will be ever asking for it again. 102 00:05:17,583 --> 00:05:20,684 Once only is a very powerful rule, 103 00:05:20,708 --> 00:05:24,768 as it defines the whole structure of the data collection in a country. 104 00:05:24,792 --> 00:05:26,476 What information is collected 105 00:05:26,500 --> 00:05:29,268 and who is responsible for maintaining it, 106 00:05:29,292 --> 00:05:32,393 making sure we avoid centralization of data, 107 00:05:32,417 --> 00:05:34,184 duplication of data, 108 00:05:34,208 --> 00:05:37,208 and guarantee that it's actually up to date. 109 00:05:38,792 --> 00:05:42,268 This distributed approach also avoids the problem 110 00:05:42,292 --> 00:05:45,059 of the single point of failure. 111 00:05:45,083 --> 00:05:48,226 But since the data cannot be replicated, 112 00:05:48,250 --> 00:05:50,351 or collected more than once, 113 00:05:50,375 --> 00:05:53,309 it means that the design has to keep in mind 114 00:05:53,333 --> 00:05:56,851 secure and robust access to that information at all times, 115 00:05:56,875 --> 00:06:00,083 so the public institution can offer a service. 116 00:06:01,208 --> 00:06:05,559 This is exactly the role of the data exchange platform 117 00:06:05,583 --> 00:06:07,768 called the X-Road 118 00:06:07,792 --> 00:06:10,708 that has been in use since 2001. 119 00:06:11,708 --> 00:06:13,351 Just like a highway, 120 00:06:13,375 --> 00:06:17,018 it connects public sector databases and registries, 121 00:06:17,042 --> 00:06:19,851 local municipalities and businesses, 122 00:06:19,875 --> 00:06:25,309 organizing a real-time, secure and regulated data exchange, 123 00:06:25,333 --> 00:06:29,542 saving an auditable trace after each move. 124 00:06:31,500 --> 00:06:34,143 Here's a screenshot of a live feed 125 00:06:34,167 --> 00:06:37,059 showing all the requests performed on the X-Road 126 00:06:37,083 --> 00:06:40,458 and all the services that it actually facilitates. 127 00:06:41,542 --> 00:06:44,351 And this is the real picture 128 00:06:44,375 --> 00:06:48,976 of all the connections between public and private sector databases. 129 00:06:49,000 --> 00:06:50,268 As you can see, 130 00:06:50,292 --> 00:06:52,917 there is no central database whatsoever. 131 00:06:53,833 --> 00:06:57,559 Confidentiality and privacy are definitely very important. 132 00:06:57,583 --> 00:06:59,476 But in the digital world, 133 00:06:59,500 --> 00:07:02,476 reliability and integrity of information 134 00:07:02,500 --> 00:07:04,708 is just critical for operations. 135 00:07:05,458 --> 00:07:06,726 For instance, 136 00:07:06,750 --> 00:07:09,059 if someone changes your medical health record, 137 00:07:09,083 --> 00:07:11,101 let's say allergies, 138 00:07:11,125 --> 00:07:13,684 without you or your doctor knowing, 139 00:07:13,708 --> 00:07:15,750 treatment could be deadly. 140 00:07:16,625 --> 00:07:20,518 That's why in a digital society, a system like an Estonian one, 141 00:07:20,542 --> 00:07:23,309 when there's almost no paper originals, 142 00:07:23,333 --> 00:07:26,934 there's almost only digital originals, 143 00:07:26,958 --> 00:07:29,059 integrity of data, 144 00:07:29,083 --> 00:07:31,934 data exchange rules, software components 145 00:07:31,958 --> 00:07:34,292 and log files is paramount. 146 00:07:35,583 --> 00:07:40,768 We use a form of blockchain that we invented back in 2007, 147 00:07:40,792 --> 00:07:44,143 way before blockchain even became a thing, 148 00:07:44,167 --> 00:07:48,583 to check and guarantee the integrity of data in real time. 149 00:07:49,417 --> 00:07:51,768 Blockchain is our auditor 150 00:07:51,792 --> 00:07:55,101 and a promise that no access to the data 151 00:07:55,125 --> 00:07:58,292 or data manipulation remains unrecorded. 152 00:08:02,083 --> 00:08:06,708 Data ownership is another key principle in the design of the system. 153 00:08:07,625 --> 00:08:12,059 Aren't you worried by the fact that governments, tech companies 154 00:08:12,083 --> 00:08:14,018 and other businesses around the world 155 00:08:14,042 --> 00:08:17,434 claim data they've collected about you is theirs, 156 00:08:17,458 --> 00:08:21,601 generally refuse to give access to that information 157 00:08:21,625 --> 00:08:24,976 and often fail to prove how it was used 158 00:08:25,000 --> 00:08:27,167 or shared with third parties? 159 00:08:28,333 --> 00:08:31,958 I don't know, for me it seems like a quite disturbing situation. 160 00:08:34,083 --> 00:08:37,684 The Estonian system is based on the principle 161 00:08:37,708 --> 00:08:42,226 that an individual is the owner of the data collected about him, 162 00:08:42,250 --> 00:08:47,309 thus has an absolute right to know what information is collected 163 00:08:47,333 --> 00:08:50,184 and who has been accessing it. 164 00:08:50,208 --> 00:08:54,309 Every time a policeman, a doctor or any state officer 165 00:08:54,333 --> 00:08:57,893 is accessing personal information of the citizens online, 166 00:08:57,917 --> 00:09:02,309 first they only get to access it after logging in 167 00:09:02,333 --> 00:09:05,768 to the information they're authorized to see to do their job. 168 00:09:05,792 --> 00:09:09,809 And secondly, every time they're making requests, 169 00:09:09,833 --> 00:09:12,042 this is saved in a log file. 170 00:09:14,667 --> 00:09:19,018 This detailed log file is part of the state public services 171 00:09:19,042 --> 00:09:21,268 and allows real transparency, 172 00:09:21,292 --> 00:09:26,708 making sure no privacy violation will remain unnoticed to the citizen. 173 00:09:28,000 --> 00:09:31,684 Now, of course, this is only a simplified summary 174 00:09:31,708 --> 00:09:36,375 of all the design principles that e-Estonia is built on. 175 00:09:37,917 --> 00:09:40,333 And now, government is building up 176 00:09:41,458 --> 00:09:45,476 to get ready for use of artificial intelligence 177 00:09:45,500 --> 00:09:49,226 and building a whole new generation of public services -- 178 00:09:49,250 --> 00:09:50,851 proactive services 179 00:09:50,875 --> 00:09:52,684 that would activate seamlessly 180 00:09:52,708 --> 00:09:55,976 based on different life situations that people might be in, 181 00:09:56,000 --> 00:10:00,750 such as childbirth, unemployment or starting a business. 182 00:10:03,250 --> 00:10:04,518 Now, of course, 183 00:10:04,542 --> 00:10:07,851 running a digital society with no paper backup 184 00:10:07,875 --> 00:10:09,417 can be an issue, right? 185 00:10:10,417 --> 00:10:13,434 Even though we trust our systems to be solid, 186 00:10:13,458 --> 00:10:18,768 but one can never be too cautious as we experienced back in 2007, 187 00:10:18,792 --> 00:10:22,559 when the first cyberincident happened, 188 00:10:22,583 --> 00:10:25,309 and it literally blocked part of our networks, 189 00:10:25,333 --> 00:10:28,667 making access to the services impossible for hours. 190 00:10:29,583 --> 00:10:31,226 We survived. 191 00:10:31,250 --> 00:10:36,476 But this event put cybersecurity at the very top of agenda, 192 00:10:36,500 --> 00:10:40,917 both in terms of strengthening the platform and backing it up. 193 00:10:41,958 --> 00:10:46,518 So how do you back up a country-wide system in a small state 194 00:10:46,542 --> 00:10:48,667 where everything is super close? 195 00:10:49,500 --> 00:10:53,768 Well for instance, you can export a copy of the data 196 00:10:53,792 --> 00:10:55,893 outside the country territory 197 00:10:55,917 --> 00:10:59,542 to an extraterritorial space of an embassy. 198 00:11:00,542 --> 00:11:03,851 Today, we have those data embassies 199 00:11:03,875 --> 00:11:08,309 that are holding the most critical digital assets of Estonia, 200 00:11:08,333 --> 00:11:11,393 guaranteeing continuity of operations, 201 00:11:11,417 --> 00:11:12,934 protection of our data, 202 00:11:12,958 --> 00:11:16,226 and most importantly, our sovereignty. 203 00:11:16,250 --> 00:11:20,250 Even in case of a physical attack on our territory. 204 00:11:22,042 --> 00:11:24,018 Some of you might be thinking by now, 205 00:11:24,042 --> 00:11:25,958 where are the downsides? 206 00:11:27,083 --> 00:11:29,559 Well, going all digital 207 00:11:29,583 --> 00:11:34,851 is administratively, and let's be honest, financially more efficient. 208 00:11:34,875 --> 00:11:37,518 Interfacing primarily with computer systems 209 00:11:37,542 --> 00:11:40,351 might create an impression that the human factor, 210 00:11:40,375 --> 00:11:42,184 elected politicians, 211 00:11:42,208 --> 00:11:44,161 and participating in democratic processes 212 00:11:44,185 --> 00:11:47,018 is somehow less important. 213 00:11:47,042 --> 00:11:48,893 And there are also some people 214 00:11:48,917 --> 00:11:51,434 who feel threatened by pervasive technology 215 00:11:51,458 --> 00:11:53,917 that might make their skills obsolete. 216 00:11:55,708 --> 00:11:58,059 So all in all, unfortunately, 217 00:11:58,083 --> 00:12:00,018 running a country on a digital platform 218 00:12:00,042 --> 00:12:03,768 has not saved us from political power struggles 219 00:12:03,792 --> 00:12:06,393 and polarization in the society, 220 00:12:06,417 --> 00:12:08,976 as we have seen in the last elections. 221 00:12:09,000 --> 00:12:11,542 Well, until there are humans involved. 222 00:12:13,917 --> 00:12:16,643 One last question. 223 00:12:16,667 --> 00:12:19,059 If everything is location-independent 224 00:12:19,083 --> 00:12:22,726 and I can access all of the services from anywhere in the world, 225 00:12:22,750 --> 00:12:25,809 why cannot others tap into some of these services, 226 00:12:25,833 --> 00:12:28,542 even if they don't reside within Estonian borders? 227 00:12:30,000 --> 00:12:31,476 Five years ago, 228 00:12:31,500 --> 00:12:35,851 we launched a governmental start-up called e-Residency program 229 00:12:35,875 --> 00:12:40,393 that for today joins tens of thousands of people. 230 00:12:40,417 --> 00:12:45,726 These are businessmen and women from 136 different countries, 231 00:12:45,750 --> 00:12:48,851 who established their businesses digitally, 232 00:12:48,875 --> 00:12:51,476 who do their banking online, 233 00:12:51,500 --> 00:12:57,393 and who run their companies virtually over e-Estonia platform, 234 00:12:57,417 --> 00:13:01,101 within European Union legal framework, 235 00:13:01,125 --> 00:13:04,851 using an e-identity card similar to mine 236 00:13:04,875 --> 00:13:08,167 and all of that from anywhere in the world. 237 00:13:09,625 --> 00:13:13,143 The Estonian system is location-independent 238 00:13:13,167 --> 00:13:14,851 and user-centric. 239 00:13:14,875 --> 00:13:20,018 It prioritizes inclusiveness, openness and reliability. 240 00:13:20,042 --> 00:13:24,268 It puts security and transparency at its center. 241 00:13:24,292 --> 00:13:28,184 And the data into the hands of the rightful owner, 242 00:13:28,208 --> 00:13:30,684 the person they refer to. 243 00:13:30,708 --> 00:13:32,684 Don't take my word for it. 244 00:13:32,708 --> 00:13:34,309 Try it. 245 00:13:34,333 --> 00:13:35,684 Thank you. 246 00:13:35,708 --> 00:13:40,250 (Applause)