At the end of the day, whilst I am sure the reasons you've given are well intentioned, they strike me as the kind of non-excuses that the industry would come up to justify its current approach - rather than being true obstacles.
I think calling them "non-excuses" is cynical and unreasonable. These are massive practical challenges, costs, and risks for the railway to deal with, for the very low payoff of allowing Railcard holders, who already have multiple ways to store and display their Railcards, a different way of low to no additional convenience.
Initial download would only be required once upon setup. Updating would require much smaller amounts of data to be downloaded; if we go by my previous assumption of 10m Railcards in circulation and 100 kB per Railcard, it would be an average 2.7GB per night. Hardly taxing given the capabilities of modern internet connections.
2.7GB per device per night is an enormous amount of data, it is over 80GB a month. Adopting the lower bound of your assumption taking 10,000 devices in circulation and usage per day, that is pushing a million GB. Might not be "taxing" but it definitely won't be cheap.
I wasn't actually suggesting that the data would necessarily be stored on an SD card. It was just a demonstration that the required amount of storage isn't unreasonably expensive. Mobile phones are now routinely available with 1TB of storage or even more.
Not many, though, and (1) this heightened level of storage carries additional cost, and (2) you need to use some of that storage for other things too.
As above, it wouldn't necessarily be memory cards used. But these kinds of data security issues are far from insurmountable; you would expect such devices (and their storage) to be suitably encrypted in any event. Plenty of other bits of customer data will be floating about on devices issued to rail staff.
If it's encrypted then the decryption key needs to be somewhere. If it's known by rail staff, then it just takes one bent staff member to leak it. It can't be online because there isn't consistent coverage on trains. And if it's stored on the device it's as good as useless if the device is lost.
Clearly you wouldn't apply it retrospectively. It would be an option people could opt into if they wanted to be able to have an e-ticket-esque Railcard.
To rely on consent as the basis for processing data you'd need to allow people to withdraw consent freely and at any time, which has its own practical challenges. Presumably you'd want to revoke the Wallet pass belonging to the Railcard, which as mentioned upthread, you can't.
It's not at all clear why you are suggesting that a Data Protection Impact Assessment (DPIA) would lead to the conclusion that this is a "high risk activity". Do you have any examples of Article 36 ICO permission being denied?
With respect, if you are trying to tell me that storing 10 million photos of individuals on over 10,000 mobile devices strewn across the country is not a "high risk activity", I don't think we can have a constructive conversation.
We're not exactly talking about a huge number of devices, are we? Again, perhaps a few tens of thousands at the absolute most. Millions of smartphones with not dissimilar amounts of storage are sold each year in the UK
No, they aren't. The average smartphone sold has 128/256GB storage, an eighth/quarter of the amount you propose is needed.
I'm therefore unconvinced that there is a sufficiently serious shortage that this would be infeasible.
I'm not.
Ah, this old chestnut again! At most it would be one day's worth of cards that wouldn't be on the scanning device. That's a risk I think the railway can afford to take.
All well and good until someone buys a Railcard an hour before travel and gets written up for prosecution when it scans and the inspector gets an error.
So no, not "non-excuses" at all, serious and material barriers to taking an idea forward that has at best marginal benefits.