Public transport as a digital service: the ticket is just the beginning

SpaceX's decision to exclude Poland from the joint European Starlink Roam region prompted a response from the government and raised questions about the transparency of the rules, costs to users, and dependence on global digital infrastructure providers.

6 Min Read
transport publiczny

The most interesting change in the digitalisation of public transport is taking place beyond the smartphone screen. It is no longer a question of whether a ticket is in the form of a paper ticket, a QR code or a token in an app. The very logic of the service is changing. Passengers identify themselves using a card, a phone or an account; the system records the journey and only then calculates the fare.

The ticket is no longer a product but the result of a calculation

The Netherlands illustrates the scale of this change. From June 2023, public transport across the country can be used via OVpay by tapping a standard payment card, mobile phone or other payment-enabled device on entry and exit. By 2025, the proportion of journeys paid for by debit card, credit card or mobile phone had risen from 15 per cent to 20 per cent. In total, the OV-chipkaart and OVpay systems processed 2.42 billion passenger transactions. At the same time, the number of OV-chipkaart cards in circulation fell from 13.4 to 12.7 million. The existing card is due to be phased out by the end of 2027 at the latest.

This is not merely a cosmetic change to the sales channel. The transport sector is beginning to utilise the payment infrastructure that passengers already possess. There is no longer any need to buy a local card, install an app or familiarise oneself with the fare structure in advance. The operator, however, is taking on a much more challenging task: it must correctly link identification, journeys, fares and settlements for millions of transactions.

The same trend can be seen in the Upper Silesian-Zagłębie Metropolis. Since August 2025, card payment terminals have been operational in almost 1,900 Transport GZM vehicles. No account or app is required to use them. The Start/Stop system allows passengers to start and end their journey using a card or the app, with the fare calculated based on the journeys recorded. A daily spending limit also applies: currently, passengers using this fare will not pay more than 13 zł in a single day.

In practice, this creates an architecture familiar from other digital platforms. The interface may change, but the core value lies in the back-end: the user account, the fare engine, payments, identification, journey data and billing mechanisms. GZM Transport stores electronic tickets in the customer’s account, supports EMV cards and the pay-as-you-go model, under which payment is only debited after the journey has been completed.

Data is becoming the second key asset

For years,Transport for London has been providing information via its API on routes, stops, disruptions, vehicle arrivals, fares and occupancy levels. As early as 2018, TfL’s data was powering nearly 700 apps used by 42 per cent of Londoners. Today, the Unified API continues to serve as a common layer for accessing data from multiple transport modes, rather than forcing every app developer to integrate separate systems.

This is the fundamental difference between a transport app and a digital transport platform. The former serves its own users. The latter allows services to be developed outside the operator’s organisation as well: in journey planners, maps, city apps, corporate systems or mobility services.

However, this growing integration comes at a price. The cyberattack on TfL in September 2024 did not stop at the internal IT infrastructure. The restrictions introduced following the incident affected, amongst other things, access to journey history, refund processing and passenger card systems. As recently as May 2025, TfL reported that some data relating to refunds for contactless payments remained unavailable due to the security measures implemented following the attack.

In digital transport, therefore, a back-end failure is not simply a ‘website’ problem. It can simultaneously affect payments, customer service, billing and access to data.

From 2026, this aspect will also have a specific regulatory dimension in Poland. The amendment to the Act on the National Cybersecurity System, implementing NIS2, came into force on 3 April. Transport is among the key sectors. Entities meeting the criteria of the Act have, amongst other things, obligations relating to registration, risk management and the implementation of an information security management system; for entities covered by the regulation at the time the Act came into force, the deadline for implementing the main obligations is 3 April 2027.

The digitalisation of transport is therefore reaching a stage where the app and the ticket are the most visible, but not the most important, elements of the system. Its value is determined by the invisible layers: interoperability, APIs, the fare engine, data, payments and infrastructure resilience.

The simpler the journey becomes for the passenger, the more complex the technology that ensures this simplicity becomes.

Share This Article