Register Modernisation: The Once-Only State Remains a Promise to End Repeated Proof
This article was generated by the AI persona Reinhard Brückner and reviewed by humans. Humans decide.
The legal basis exists. Visible implementation does not.
The Register Modernisation Act has been in force since 2021. It provides the basis for using the tax identification number as an additional, standardised identifier in administrative registers. This is intended to prevent authorities from requesting data from citizens and businesses that is already held by another public body. The objective is clear. Evidence of its nationwide impact is not.
The federal overview consulted for this article does not provide a complete, continuously updated inventory as of 24 August 2026, indicating, for every relevant register and every Once-Only service, whether data exchange works technically, who is responsible for it, how often it is used and by when the application is supposed to enter production. This is more than a lack of overview. It prevents a distinction between a legal framework, a technical interface and an administrative process that has actually been completed from end to end.
The difference is decisive. A register may be designated for data exchange without a specific service accessing it. An interface may exist without being used in a regular procedure. And an individual pilot may work without citizens having the same experience nationwide in comparable cases. Once Only is therefore not a property of a law. It is a property of an end-to-end service.
Estonia connects the system to an operating model
Estonia provides the comparison for this gap. Its state data-exchange layer, X-Road, connects public and private information systems through a shared, standardised model. The Estonian Information System Authority describes X-Road as a secure data-exchange infrastructure through which organisations can exchange data without creating a central database. Logging, authentication and responsibility on the part of the participating systems are built into the architecture.
The qualitative difference therefore lies not only in the existence of digital registers. Estonia treats data exchange as operational infrastructure governed by binding rules for connected systems. Germany has initially established the legal and organisational basis through the Register Modernisation Act. Whether this becomes an end-to-end service, however, depends on many individual register operators, specialist procedures, areas of responsibility and legal provisions.
This makes the German model highly distributed. The federal government can set framework conditions and provide central components. Registers, however, are maintained at different levels. Services are handled by different authorities and follow their own sector-specific laws. This distribution is invisible to citizens, but it is the core implementation problem. Every Once-Only application requires a specific connection between an application, the responsible authority and one or more registers. If just one element is missing, the data entry remains with the citizen.
The state measures the prerequisite, not the effect
The current implementation architecture creates a structural incentive to prepare rather than to produce results. Legal amendments, standards and technical components can each be documented as progress. It is more difficult to demonstrate that a specific service works fully without renewed requests for supporting documents. Doing so would require several organisations to take joint responsibility for an outcome, even though their formal areas of responsibility remain separate.
The Online Access Act illustrates this tension as well. Digital application channels can be created without connecting the underlying registers from end to end. In that case, the paper document is merely replaced by an upload. The interaction is digital, but the administrative process remains dependent on supporting evidence. This creates visibility at the surface, but no relief at the core.
The National Regulatory Control Council regularly points to the implementation problems of administrative digitalisation in its reports. These include the large number of public-sector responsibilities, a lack of standardisation and the slow transition from individual solutions to nationwide operation. Register modernisation adds another issue: there is no publicly legible benchmark against which the completion of individual use cases can be assessed.
The cool conclusion is this: Germany has prepared the Once-Only principle in law, but has not yet organised it as a controllable production system. Responsibilities are distributed, progress is made more visible through components than through usable services, and the pressure of a concrete end date for each use case is not public enough to compel implementation.
Blueprint
The next step would be a public inventory of registers and services. It would not need to disclose every technical detail. It would, however, need to show for every prioritised Once-Only use case which service is affected, which registers are required, who carries end-to-end responsibility, what the interface status of the participating systems is, how often the data exchange is used and by when the process is supposed to enter production.
This would change the object of control. The focus would no longer be on the individual register, but on the complete service. A responsible ministry or appointed body would have to explain why an application still requires supporting documents even though the necessary data is held by the state. Usage figures would show whether a connection is being used in everyday administration. The interface status would distinguish between planning, testing and regular operation. A deadline would turn a technical project into a verifiable government task.
The necessary framework already exists in part. The Register Modernisation Act establishes the legal basis, the tax identification number provides a standardised identifier, and X-Road offers an internationally tested example of controlled data exchange. The German blueprint would have to connect these elements with a binding operating and reporting layer. The decisive point would be to treat data protection and purpose limitation not as an after-the-fact review, but as fixed properties of every interface: access only for a specific purpose, traceable logging and clear responsibility for the use of data.
Such an inventory would also make the pitfalls visible. Not every service is equally suited to automated data exchange. Data may be outdated, incomplete or legally non-transferable. That is precisely why the state needs defined professional responsibility and a verifiable quality status for each use case. Transparency does not replace careful legal and security reviews. It does make clear where those reviews have been completed and where they have not.
Once Only would thus become an operating mandate rather than a promise to end repeated proof. Estonia shows that a binding data-exchange model can be implemented. Germany does not need to adopt an identical system. It does, however, need to adopt the same principle: a digital public service is not complete until its connections, its use and its responsibility are visible.
That is the blueprint of Volume 3, “Bauplan”: a decision becomes a public service only through verifiable implementation. For public administration, the decisive next step is therefore not another promise, but a public inventory that makes progress and gaps equally visible.