New Zealand - Digital Identity Services (2023)
Digital Identity Services Trust Framework Act 2023
New Zealand
RAI-NZ-NA-DIST2XX-2023The Digital Identity Services Trust Framework Act 2023 establishes a legal framework to accredit and regulate digital identity services in New Zealand, create governance bodies (a TF board and a TF authority), and require accredited providers to meet TF rules, reporting and record-keeping obligations. The Act provides a register of accredited providers and services, enforcement powers, remedies, and specific offences and penalties for misuse or misrepresentation of accreditation.
Summary
The Digital Identity Services Trust Framework Act 2023 (the Act) creates a statutory trust framework for digital identity services used in transactions between individuals and organisations in New Zealand. Its core purposes are to establish a legal and governance structure for accreditation and oversight of digital identity service providers (TF providers), to promote secure, reliable digital identity services, and to incorporate te ao Māori approaches to identity. The Act sets out definitions of “digital identity service,” “TF provider,” and other key terms, and clarifies that while services may continue to be offered outside the framework, representations that a service or provider is accredited when it is not are criminalised.
The Act establishes two administering bodies: the TF board and the TF authority. The TF board has responsibilities primarily around recommending TF rules and governance, and the Act requires consultation and inclusion of a Māori Advisory Group to ensure te Tiriti o Waitangi/Treaty of Waitangi principles are recognised in governance. The TF authority is the accreditation and enforcement body: it processes accreditation applications, maintains a public register of accredited providers and accredited services, oversees third‑party assessors, conducts investigations, issues findings and remedies, and enforces TF rules and regulations. The TF authority is empowered to require information, issue compliance orders, and vary or cancel accreditation where necessary. The Act also provides limited immunities and protections for certain office holders and participants acting in good faith.
Part 3 sets out the accreditation regime: application requirements, specified “key information” and other documentation providers must supply, decision-making and reconsideration processes, duration and renewal of accreditation, provisional accreditation options, and obligations to notify changes. Accredited providers must meet record‑keeping and reporting obligations; third‑party assessors may be certified and are themselves subject to accountability and reporting requirements. The TF register is compulsory and is intended to provide transparency for relying parties and users of accredited services.
The Act contains a robust complaints, investigation and remedies framework. Members of the public, relying parties, or other participants may file complaints. The TF authority can investigate breaches, issue public warnings, require additional reporting, impose compliance orders, and suspend or cancel accreditation. Offences include knowingly or recklessly misrepresenting accreditation status, misuse of accreditation marks, giving false information in accreditation applications, failing to provide required information, failing to report changes to key information, and obstructing the TF authority. Penalties range from fines for individuals (commonly up to NZD 10,000 or NZD 50,000 depending on the offence) to higher maximum fines for bodies corporate (commonly up to NZD 20,000 or NZD 100,000).
The Act expressly interfaces with the Privacy Act 2020, and identifies relationships with earlier identity-related Acts to ensure consistent application of privacy and identity‑related obligations. It provides for TF rules and delegated regulations to specify technical, security, and operational requirements for accredited services and allows Orders in Council to stagger commencement; to the extent not commenced earlier, the Act came into force on 1 July 2024. The Department of Internal Affairs administers the Act and hosts the Trust Framework operational materials and register.
In effect, the Act seeks to balance innovation and market participation in identity services with consumer protections, accountability, and transparency — while embedding cultural responsiveness and oversight mechanisms to maintain public trust in digital identity systems.
Full article
Read full text ↗Overview
The Digital Identity Services Trust Framework Act 2023 establishes a statutory trust framework to regulate and accredit digital identity services in New Zealand. The Act creates two administering bodies (a TF board and a TF authority), an accreditation regime for TF providers and accredited services, TF rules and regulations, and an official register of accredited providers and services. The Department of Internal Affairs is the administering agency for the Act; for the official text see the New Zealand legislation site at Digital Identity Services Trust Framework Act 2023 (full text) and the Department of Internal Affairs Trust Framework overview at Trust Framework - Department of Internal Affairs. The Act recognises te Tiriti o Waitangi/Treaty of Waitangi obligations and requires governance arrangements to incorporate te ao Māori approaches to identity. It criminalises misrepresentation of accreditation and misuse of accreditation marks, sets record-keeping and reporting obligations, and provides investigatory and enforcement powers for the TF authority.
Definitions
The Act defines key terms: "digital identity service" (a service or product enabling users to share personal or organisational information in digital form), "TF provider" (an individual or organisation providing digital identity services), "accredited digital identity service" (a service accredited by the TF authority), "accreditation mark" (approved mark identifying accredited services), and "trust framework" (the legal framework established by the Act). The regulations are authorised to prescribe the types of digital identity services that may be accredited. The Act distinguishes between services inside the trust framework and those provided outside it, while making false claims of accreditation an offence.
Governance and Institutional Framework
The Act establishes two principal bodies: the TF board and the TF authority. The TF board advises on TF rules, consults on rule development, and reports to the Minister. The TF board is supported by a Māori Advisory Group and advisory committees to ensure inclusion of te ao Māori perspectives. The TF authority is an operational regulator responsible for administering accreditation processes (applications, renewals, provisional accreditation), maintaining the TF register, certifying third-party assessors, investigating breaches, and enforcing TF rules. The Department of Internal Affairs is the responsible department for both bodies and provides administrative support. Governance functions include mandatory consultation before recommending TF rules and reporting obligations to the Minister. Relevant official material and guidance for governance and providers is available at the Department of Internal Affairs' Trust Framework pages at Trust Framework - Department of Internal Affairs, and the Act text sets out appointments, functions, and powers for board and authority members in Parts 4 and 5 of the Act.
Key Focus Areas
The Act focuses on accreditation and conformity assessment, transparency and disclosure via a public register, data protection and privacy alignment (explicitly applying the Privacy Act 2020 in specified ways), cybersecurity and operational security requirements (to be set in TF rules and regulations), and consumer protection through complaints, dispute resolution, and enforcement remedies. It emphasises record-keeping and reporting by accredited providers and by third-party assessors, mandates certification of assessors, and establishes penalties for false representations and misuse of accreditation marks. The Act also addresses market surveillance and oversight by empowering the TF authority to require information, conduct investigations, and issue compliance orders. It sets out that TF rules will contain technical and procedural requirements for identity proofing, credential management, authentication strength, interoperability, data minimisation and retention, and secure information sharing. The Act makes clear the rights and responsibilities of trust framework participants—users, TF providers, and relying parties—and requires providers to take reasonable steps to protect personal and organisational information when operating accredited services.
Implementation Framework
Implementation relies on the TF authority operationalising the accreditation processes, TF rules being recommended by the TF board and made under the Act, and the establishment of the TF register. The Act authorises Orders in Council to bring provisions into force on staggered dates; to the extent not earlier commenced, it came into force on 1 July 2024. Implementation steps include publication of TF rules and guidance, certification programmes for third-party assessors, applications and assessment procedures for providers, development of accreditation marks and terms of use, technical guidance for secure identity-sharing, and public education for relying parties and users. The Department of Internal Affairs hosts templates, guidance and application materials to support providers through accreditation at Trust Framework - Department of Internal Affairs. Ongoing rulemaking and delegated regulations will define the detailed technical specifications and service categories eligible for accreditation.
Monitoring and Evaluation
The Act mandates record-keeping and reporting by accredited providers and third-party assessors, and requires the TF authority to maintain a register of accredited providers and services for transparency and market surveillance. The TF authority has powers to investigate breaches, require documents and information, and to regulate its own procedures for investigations. The Act also provides for periodic reviews: a review of the TF board’s operation and a review of the complaints process and dispute resolution scheme. Monitoring mechanisms include public warnings, additional reporting obligations, compliance orders, and suspension or cancellation of accreditation where breaches are found. The TF authority’s enforcement outcomes and register entries provide a public record that supports external oversight and performance evaluation.
Penalties, Liability, and Appeals
The Act specifies criminal offences and monetary penalties: knowingly or recklessly misrepresenting accreditation or provider status carries maximum fines of NZD 50,000 for individuals and NZD 100,000 for bodies corporate; misuse of accreditation marks and giving false information in accreditation applications carry similar maxima; lesser fines (for example NZD 10,000/NZD 20,000) apply for failure to provide required information or failure to notify changes. The Act also provides remedies and non-criminal enforcement tools for the TF authority — compliance orders, public warnings, additional reporting requirements, suspension or cancellation of accreditation, and rights for providers to elect to forfeit accreditation. The Act contains immunity provisions for certain office holders and for TF providers in relation to user actions, and provides appeals/reconsideration pathways for accreditation decisions. Specific offences and fines are listed in Part 6 and Part 7 of the Act (see the legislation at full text).
Relationship to Other Instruments
The Act expressly identifies relationships with the Privacy Act 2020 and earlier identity-related Acts (Electronic Identity Verification Act 2012 and Identity Information Confirmation Act 2012). It requires the TF authority and board to take into account relevant law, and the TF rules will be developed in consultation with affected stakeholders. The Act allows regulations and Orders in Council to align technical and procedural TF requirements with existing sectoral obligations (privacy, information security, consumer protection) and to ensure interoperability with government systems and identity initiatives. The Department of Internal Affairs provides guidance on how the TF framework operates alongside other statutes at Trust Framework - Department of Internal Affairs.
International Alignment
Although primarily domestic, the Act anticipates international interoperability and alignment by permitting TF rules to include technical standards and cross-border considerations for identity exchange. The TF authority’s accreditation and certification processes are designed to support internationally interoperable assurance levels where appropriate. The Act’s emphasis on accredited marks, certified assessors, and technical specifications facilitates equivalence assessments with overseas digital identity frameworks, supporting international commerce and cross-border services while protecting New Zealand residents’ privacy. Where international standards or mutual recognition arrangements are relevant, the TF board and authority may reference them in TF rules and guidance.
Implementation Timeline
| Event | Date |
|---|---|
| Introduction of Bill | 2021-09-29 |
| First reading | 2021-10-19 |
| Committee report | 2022-04-19 |
| Second reading | 2022-07-26 |
| Third reading / Committee of the Whole | 2023-03-28 |
| Royal assent | 2023-04-05 |
| Default commencement (to extent not earlier commenced) | 2024-07-01 |
Sources and References
| Source | Type |
|---|---|
| Digital Identity Services Trust Framework Act 2023 (New Zealand Legislation, full text) | Primary Source |
| Trust Framework - Department of Internal Affairs | Primary Source |
Requirements for a company
What an organisation has to do under New Zealand - Digital Identity Services (2023), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
10- Do not knowingly or recklessly misrepresent your accreditation or provider status.Any individual or organisation providing digital identity services.
- Submit application with key and specified information to become an accredited service.Providers seeking to operate an accredited digital identity service.
- Implement technical, security and privacy measures required by Trust Framework rules and regulations.Accredited providers of digital identity services.
- Take reasonable steps to protect personal and organisational information when operating accredited services.TF providers operating accredited services.
- Only use approved accreditation marks consistent with the TF authority's terms of use.Accredited providers of digital identity services.
- Obtain certification from the TF authority to operate as a third-party assessor.Third-party assessors of digital identity services.
- +4 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under New Zealand - Digital Identity Services (2023), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Any individual or organisation providing digital identity services. | Do not knowingly or recklessly misrepresent your accreditation or provider status. “knowingly or recklessly misrepresenting accreditation or provider status carries maximum fines of NZD 50,000 for individuals” | — | Part 6 | Critical |
| 2 | Providers seeking to operate an accredited digital identity service. | Submit application with key and specified information to become an accredited service. “Accreditation application: Submit application with key and specified information per sections 23–25” | Before operating an accredited service | sections 23–25 | Critical |
| 3 | Accredited providers of digital identity services. | Implement technical, security and privacy measures required by Trust Framework rules and regulations. “Comply with TF rules: Implement technical, security and privacy measures required by TF rules and regulations” | Ongoing | — | Critical |
| 4 | TF providers operating accredited services. | Take reasonable steps to protect personal and organisational information when operating accredited services. “requires providers to take reasonable steps to protect personal or organisational information when operating accredited services.” | Ongoing | — | Critical |
| 5 | Accredited providers of digital identity services. | Only use approved accreditation marks consistent with the TF authority's terms of use. “Use of accreditation mark: Only use approved mark consistent with TF authority terms of use” | — | Part 6 | Critical |
| 6 | Third-party assessors of digital identity services. | Obtain certification from the TF authority to operate as a third-party assessor. “mandates certification of assessors” | Before conducting assessments | — | Critical |
| 7 | Accredited providers of digital identity services. | Maintain records and file reports as required by Trust Framework rules and the Act. “Record-keeping and reporting: Maintain records and file reports as required by TF rules and section 42” | Ongoing | section 42 | Important |
| 8 | Accredited providers of digital identity services. | Notify the TF authority of changes to key or specified information. “Notification of changes: Notify TF authority of changes to key or specified information under section 33” | Upon change | section 33 | Important |
| 9 | TF providers and other relevant parties. | Provide documents and information as required by the TF authority during investigations. “The TF authority has powers to investigate breaches, require documents and information” | Upon request | — | Important |
| 10 | TF board and TF authority. | Ensure governance arrangements incorporate te ao Māori approaches to identity. “requires governance arrangements to incorporate te ao Māori approaches to identity.” | Ongoing | — | Important |
Related Regulations
© Regulations.AI · updated on 13-Jun-2026