Skip to main content
Rules Mate

Digital ID Act 2024: what accreditation means for a business that wants to use or provide digital ID

Rules Mate Editorial7 min read

How the Digital ID Act 2024 accreditation scheme works, the difference between accreditation and AGDIS participation, and what an accredited entity has to prove and keep proving.

What the Digital ID Act 2024 does

The Digital ID Act 2024 (Cth), Act No. 25 of 2024, puts two things on a statutory footing: a voluntary accreditation scheme for providers of digital identity services across the economy, and the Australian Government Digital ID System (AGDIS). It received assent on 30 May 2024 and commenced on 30 November 2024, together with the supporting rules and data standards made that month (checked August 2026 against the Act's commencement table — commentary widely reports 1 December, which does not match the instrument).

Regulatory responsibility is split. The Australian Competition and Consumer Commission is the Digital ID Regulator, responsible for accrediting entities, approving AGDIS participation, and compliance and enforcement. The Office of the Australian Information Commissioner is the regulator for the privacy aspects of the accreditation scheme and the AGDIS, with an expanded role beyond its ordinary Privacy Act functions. The ACCC sets out that division on its digital ID regulation page.

Chapter 2 of the Act covers accreditation — applications, conditions, variation and revocation. Chapter 5 establishes the Digital ID Regulator, whose functions include overseeing and maintaining the AGDIS, issuing directions, conducting compliance assessments, requiring information from entities, and suspending or revoking accreditation.

Accreditation and AGDIS participation are different things

This is the distinction that costs businesses the most time. Accreditation is a credential granted under the Act certifying that a provider meets prescribed privacy, security, fraud, usability and accessibility requirements. Approval to participate in the AGDIS is a separate decision permitting an entity to operate inside the government's own digital ID system, either as a provider of services within it or as a relying party consuming identities from it.

An entity can be accredited without participating in AGDIS. An accredited provider serving private-sector customers under commercial contracts sits entirely outside the AGDIS. Conversely, participation in the AGDIS is conditional on accreditation for the relevant service type, so accreditation is the gate rather than the destination.

The ACCC maintains two public registers — an accredited entities register and an Australian Government Digital ID System register. Both list the type of services an entity may provide, the day the accreditation or approval came into force, and any conditions imposed. The accredited entities register also carries entities accredited within the previous 12 months, which is the practical way to check whether a supplier's accreditation has lapsed or been revoked.

Participation in the AGDIS is being phased, and it opens to the private sector from December 2026 (checked August 2026, from the ACCC's digital ID regulation page). Until then, private-sector relying parties cannot consume identities from the AGDIS and must contract directly with accredited providers or operate outside the scheme altogether.

The three accredited service types

The Digital ID (Accreditation) Rules 2024 set out the kinds of service for which an entity may be accredited:

Service typeWhat it does
Accredited identity service provider (ISP)Verifies a person's identity and generates and manages their digital ID
Accredited attribute service provider (ASP)Verifies and asserts specific attributes about a person — a qualification, a licence, an entitlement — without necessarily establishing full identity
Accredited identity exchange provider (IXP)Brokers the flow of identity and attribute assertions between providers and relying parties, and is designed so that it cannot see both sides of a transaction

The exchange model matters to the privacy design. An identity exchange sits between the provider and the relying party specifically so that neither can build a complete picture of where a person uses their digital ID. If you are assessing a supplier's architecture, the presence or absence of that separation tells you a great deal.

What an applicant has to prove

Accreditation is not a self-declaration. The Rules prescribe assurance assessments and systems testing that an applicant must complete before accreditation is granted, including security assessments, fraud assessments, penetration testing and usability testing.

A privacy impact assessment is required as part of that package. Rule 2.4 of the Digital ID (Accreditation) Rules 2024 governs the assessment's scope and content, the independence and competency of the assessor, and the applicant's response to the risks and recommendations it identifies; rule 2.3(3)(c) makes it part of the pre-accreditation assessments. The explanatory statement describes the rule 2.4 assessment as a point-in-time compliance assessment. If you are scoping that work, the process in privacy impact assessments is the baseline the OAIC expects.

In deciding an application the Digital ID Regulator must have regard to the applicant's tolerance of fraud risks and of cyber security risks — and whether that tolerance is likely to create an unacceptable risk in respect of the accredited services — and to whether the applicant's privacy impact assessment and its response to that assessment identify any matters of concern.

Two of the underlying controls will already be familiar to Australian businesses that sell to government. The security posture expected of an accredited entity aligns closely with the Essential Eight maturity levels, and entities running a certified information security management system will find much of the evidence already produced — the ISO 27001 gap assessment is a reasonable way to test how much of the work is already done.

Staying accredited

Accreditation carries continuing obligations, and Chapter 6 of the Rules provides for an annual review of an entity's accreditation, including whether the entity continues to comply with the applicable law. The Rules also set requirements for maintaining accreditation across protective security, fraud and privacy controls.

One point is widely misstated and worth stating plainly: an accredited entity is not required to conduct a fresh privacy impact assessment every year. The annual review provisions require the entity to provide a copy of any PIA and its response to it. That is a production obligation. The obligation to conduct a new assessment attaches to accreditation and to material change, not to the calendar.

Accredited entities also sit under heightened privacy safeguards in the Act itself, enforceable by the Information Commissioner. Section 51 requires an entity that collects biometric information solely to verify an individual's identity to destroy it immediately after the verification is complete. Section 53 prohibits using or disclosing information about a person's verification attempts, methods or timing for profiling — even where the individual has consented — and sections 54 and 55 prohibit specified enforcement and marketing uses. Sections 45 and 46 require express consent before disclosing name, address, date of birth, phone number, email address or restricted attributes to a relying party. Biometric information is also sensitive information under the Privacy Act, which brings APP 3 consent requirements and the analysis in the biometric information guide into scope.

Breach notification is layered rather than separate. Where an accredited entity is required under section 26WK of the Privacy Act to give the Information Commissioner an eligible data breach statement, section 39 of the Digital ID Act requires it to give a copy to the Digital ID Regulator at the same time. An accredited entity that is not otherwise an APP entity is treated as one for the purposes of Part IIIC. The Accreditation Rules also require a documented data breach response plan identifying roles, a communication plan, and escalation and notification to affected individuals — the same artefact described in writing a data breach response plan.

Using digital ID as a relying party

A business that wants to accept digital ID rather than provide it is a relying party, and its position is simpler but not obligation-free.

Digital ID is voluntary for the individual, and section 74 of the Act says so directly: a participating relying party must not, as a condition of providing a service or access to a service, require an individual to create or use a digital ID. The section goes further than a bare prohibition — a contravention is deemed where the alternative offered is not reasonably accessible, or where it results in the service being provided on substantially less favourable terms. A business that keeps a nominal non-digital pathway but degrades it has not complied.

Relying parties should also be clear about what they receive. A well-designed digital ID transaction returns an assertion — this person is over 18, this person is who they say they are — rather than a copy of the underlying identity documents. Collecting and storing document images when an assertion would do is the failure mode that turns an identity control into a data breach liability under APP 11. The point of the scheme is to stop businesses holding identity documents they do not need.

Before contracting, check the supplier on the ACCC's accredited entities register rather than relying on a claim in a proposal, confirm the service types the accreditation actually covers, and read any conditions attached to it. The register records all three.

Deciding whether accreditation is worth it

Accreditation is voluntary, so the decision is commercial. It is worth pursuing where digital ID services are the product rather than a supporting function, where customers or procurement processes require an accredited counterparty, or where AGDIS participation is the objective — and from December 2026 that becomes available to private-sector relying parties for the first time.

It is usually not worth pursuing where the business simply wants to verify its own customers. Contracting an accredited provider transfers the assurance burden without the accreditation overhead, and the compliance question then becomes supplier due diligence rather than scheme membership.

For businesses in the middle — building identity verification into a product but not selling identity as a service — the useful exercise is to run the accreditation requirements as a gap assessment even if you never apply. The Rules describe a defensible baseline for handling identity data, and the Privacy Act 2026 readiness check will surface the reform obligations that apply whether or not you seek accreditation.

Frequently asked

Is accreditation under the Digital ID Act 2024 mandatory?

No. The Act establishes a voluntary accreditation scheme for providers of digital identity services. A business can provide identity verification services in Australia without accreditation, subject to the Privacy Act and any sector-specific rules. Accreditation becomes effectively necessary where a customer or procurement process requires an accredited counterparty, or where the entity wants to participate in the Australian Government Digital ID System, because AGDIS participation is conditional on accreditation for the relevant service type.

What is the difference between accreditation and AGDIS approval?

Accreditation is a credential certifying that a provider meets the prescribed privacy, security, fraud, usability and accessibility requirements. Approval to participate in the Australian Government Digital ID System is a separate decision permitting the entity to operate inside the government's own system. An accredited provider serving private-sector customers under commercial contracts operates entirely outside AGDIS. The ACCC maintains a separate public register for each.

What kinds of digital ID service can be accredited?

Three service types under the Digital ID (Accreditation) Rules 2024: an accredited identity service provider, which verifies identity and generates and manages a person's digital ID; an accredited attribute service provider, which verifies and asserts specific attributes such as a qualification or entitlement; and an accredited identity exchange provider, which brokers assertions between providers and relying parties and is designed so it cannot see both sides of a transaction.

Do accredited entities have to run a privacy impact assessment every year?

No, and this is a common misstatement. A privacy impact assessment is required as part of accreditation under rule 2.4 of the Digital ID (Accreditation) Rules 2024, with rule 2.3(3)(c) making it part of the pre-accreditation assessments; the explanatory statement describes it as a point-in-time compliance assessment. The Chapter 6 annual review requires the entity to provide a copy of any PIA and its response to it — a production obligation, not a duty to conduct a fresh assessment each year.

When can private-sector businesses use the Australian Government Digital ID System?

Participation in AGDIS is being phased, and the ACCC states it opens to the private sector from December 2026 (checked August 2026). Until that phase commences, private-sector relying parties cannot consume identities from AGDIS and must contract directly with accredited providers or operate outside the scheme. Businesses planning to rely on AGDIS should treat the December 2026 date as a planning assumption and confirm the position closer to the time.

Can a business require customers to use a digital ID?

The Digital ID Act is built on express consent and on digital ID being voluntary for the individual, with relying parties expected to offer an alternative channel. Removing every non-digital pathway makes a voluntary system mandatory in practice. Relying parties should also design to receive an assertion — that a person is verified, or is over a given age — rather than collecting and storing copies of identity documents, because storing documents the business does not need converts an identity control into a data breach liability.

Related

Related reading