New Zealand - Digital Identity Services (2023)

Digital Identity Services Trust Framework Act 2023

New Zealand

RAI-NZ-NA-DIST2XX-2023
Effective: July 1, 2024
In Force(In Force)
ActGovernance and OversightConformity Assessment and Registration
Export PDF

The Digital Identity Services Trust Framework Act 2023 establishes a legal framework to accredit and regulate digital identity services in New Zealand, create governance bodies (a TF board and a TF authority), and require accredited providers to meet TF rules, reporting and record-keeping obligations. The Act provides a register of accredited providers and services, enforcement powers, remedies, and specific offences and penalties for misuse or misrepresentation of accreditation.

Summary

The Digital Identity Services Trust Framework Act 2023 (the Act) creates a statutory trust framework for digital identity services used in transactions between individuals and organisations in New Zealand. Its core purposes are to establish a legal and governance structure for accreditation and oversight of digital identity service providers (TF providers), to promote secure, reliable digital identity services, and to incorporate te ao Māori approaches to identity. The Act sets out definitions of “digital identity service,” “TF provider,” and other key terms, and clarifies that while services may continue to be offered outside the framework, representations that a service or provider is accredited when it is not are criminalised.

The Act establishes two administering bodies: the TF board and the TF authority. The TF board has responsibilities primarily around recommending TF rules and governance, and the Act requires consultation and inclusion of a Māori Advisory Group to ensure te Tiriti o Waitangi/Treaty of Waitangi principles are recognised in governance. The TF authority is the accreditation and enforcement body: it processes accreditation applications, maintains a public register of accredited providers and accredited services, oversees third‑party assessors, conducts investigations, issues findings and remedies, and enforces TF rules and regulations. The TF authority is empowered to require information, issue compliance orders, and vary or cancel accreditation where necessary. The Act also provides limited immunities and protections for certain office holders and participants acting in good faith.

Part 3 sets out the accreditation regime: application requirements, specified “key information” and other documentation providers must supply, decision-making and reconsideration processes, duration and renewal of accreditation, provisional accreditation options, and obligations to notify changes. Accredited providers must meet record‑keeping and reporting obligations; third‑party assessors may be certified and are themselves subject to accountability and reporting requirements. The TF register is compulsory and is intended to provide transparency for relying parties and users of accredited services.

The Act contains a robust complaints, investigation and remedies framework. Members of the public, relying parties, or other participants may file complaints. The TF authority can investigate breaches, issue public warnings, require additional reporting, impose compliance orders, and suspend or cancel accreditation. Offences include knowingly or recklessly misrepresenting accreditation status, misuse of accreditation marks, giving false information in accreditation applications, failing to provide required information, failing to report changes to key information, and obstructing the TF authority. Penalties range from fines for individuals (commonly up to NZD 10,000 or NZD 50,000 depending on the offence) to higher maximum fines for bodies corporate (commonly up to NZD 20,000 or NZD 100,000).

The Act expressly interfaces with the Privacy Act 2020, and identifies relationships with earlier identity-related Acts to ensure consistent application of privacy and identity‑related obligations. It provides for TF rules and delegated regulations to specify technical, security, and operational requirements for accredited services and allows Orders in Council to stagger commencement; to the extent not commenced earlier, the Act came into force on 1 July 2024. The Department of Internal Affairs administers the Act and hosts the Trust Framework operational materials and register.

In effect, the Act seeks to balance innovation and market participation in identity services with consumer protections, accountability, and transparency — while embedding cultural responsiveness and oversight mechanisms to maintain public trust in digital identity systems.

Full article

Read full text ↗

Overview

The Digital Identity Services Trust Framework Act 2023 establishes a statutory trust framework to regulate and accredit digital identity services in New Zealand. The Act creates two administering bodies (a TF board and a TF authority), an accreditation regime for TF providers and accredited services, TF rules and regulations, and an official register of accredited providers and services. The Department of Internal Affairs is the administering agency for the Act; for the official text see the New Zealand legislation site at Digital Identity Services Trust Framework Act 2023 (full text) and the Department of Internal Affairs Trust Framework overview at Trust Framework - Department of Internal Affairs. The Act recognises te Tiriti o Waitangi/Treaty of Waitangi obligations and requires governance arrangements to incorporate te ao Māori approaches to identity. It criminalises misrepresentation of accreditation and misuse of accreditation marks, sets record-keeping and reporting obligations, and provides investigatory and enforcement powers for the TF authority.

Definitions

The Act defines key terms: "digital identity service" (a service or product enabling users to share personal or organisational information in digital form), "TF provider" (an individual or organisation providing digital identity services), "accredited digital identity service" (a service accredited by the TF authority), "accreditation mark" (approved mark identifying accredited services), and "trust framework" (the legal framework established by the Act). The regulations are authorised to prescribe the types of digital identity services that may be accredited. The Act distinguishes between services inside the trust framework and those provided outside it, while making false claims of accreditation an offence.

Governance and Institutional Framework

The Act establishes two principal bodies: the TF board and the TF authority. The TF board advises on TF rules, consults on rule development, and reports to the Minister. The TF board is supported by a Māori Advisory Group and advisory committees to ensure inclusion of te ao Māori perspectives. The TF authority is an operational regulator responsible for administering accreditation processes (applications, renewals, provisional accreditation), maintaining the TF register, certifying third-party assessors, investigating breaches, and enforcing TF rules. The Department of Internal Affairs is the responsible department for both bodies and provides administrative support. Governance functions include mandatory consultation before recommending TF rules and reporting obligations to the Minister. Relevant official material and guidance for governance and providers is available at the Department of Internal Affairs' Trust Framework pages at Trust Framework - Department of Internal Affairs, and the Act text sets out appointments, functions, and powers for board and authority members in Parts 4 and 5 of the Act.

Key Focus Areas

The Act focuses on accreditation and conformity assessment, transparency and disclosure via a public register, data protection and privacy alignment (explicitly applying the Privacy Act 2020 in specified ways), cybersecurity and operational security requirements (to be set in TF rules and regulations), and consumer protection through complaints, dispute resolution, and enforcement remedies. It emphasises record-keeping and reporting by accredited providers and by third-party assessors, mandates certification of assessors, and establishes penalties for false representations and misuse of accreditation marks. The Act also addresses market surveillance and oversight by empowering the TF authority to require information, conduct investigations, and issue compliance orders. It sets out that TF rules will contain technical and procedural requirements for identity proofing, credential management, authentication strength, interoperability, data minimisation and retention, and secure information sharing. The Act makes clear the rights and responsibilities of trust framework participants—users, TF providers, and relying parties—and requires providers to take reasonable steps to protect personal and organisational information when operating accredited services.

Implementation Framework

Implementation relies on the TF authority operationalising the accreditation processes, TF rules being recommended by the TF board and made under the Act, and the establishment of the TF register. The Act authorises Orders in Council to bring provisions into force on staggered dates; to the extent not earlier commenced, it came into force on 1 July 2024. Implementation steps include publication of TF rules and guidance, certification programmes for third-party assessors, applications and assessment procedures for providers, development of accreditation marks and terms of use, technical guidance for secure identity-sharing, and public education for relying parties and users. The Department of Internal Affairs hosts templates, guidance and application materials to support providers through accreditation at Trust Framework - Department of Internal Affairs. Ongoing rulemaking and delegated regulations will define the detailed technical specifications and service categories eligible for accreditation.

Monitoring and Evaluation

The Act mandates record-keeping and reporting by accredited providers and third-party assessors, and requires the TF authority to maintain a register of accredited providers and services for transparency and market surveillance. The TF authority has powers to investigate breaches, require documents and information, and to regulate its own procedures for investigations. The Act also provides for periodic reviews: a review of the TF board’s operation and a review of the complaints process and dispute resolution scheme. Monitoring mechanisms include public warnings, additional reporting obligations, compliance orders, and suspension or cancellation of accreditation where breaches are found. The TF authority’s enforcement outcomes and register entries provide a public record that supports external oversight and performance evaluation.

Penalties, Liability, and Appeals

The Act specifies criminal offences and monetary penalties: knowingly or recklessly misrepresenting accreditation or provider status carries maximum fines of NZD 50,000 for individuals and NZD 100,000 for bodies corporate; misuse of accreditation marks and giving false information in accreditation applications carry similar maxima; lesser fines (for example NZD 10,000/NZD 20,000) apply for failure to provide required information or failure to notify changes. The Act also provides remedies and non-criminal enforcement tools for the TF authority — compliance orders, public warnings, additional reporting requirements, suspension or cancellation of accreditation, and rights for providers to elect to forfeit accreditation. The Act contains immunity provisions for certain office holders and for TF providers in relation to user actions, and provides appeals/reconsideration pathways for accreditation decisions. Specific offences and fines are listed in Part 6 and Part 7 of the Act (see the legislation at full text).

Relationship to Other Instruments

The Act expressly identifies relationships with the Privacy Act 2020 and earlier identity-related Acts (Electronic Identity Verification Act 2012 and Identity Information Confirmation Act 2012). It requires the TF authority and board to take into account relevant law, and the TF rules will be developed in consultation with affected stakeholders. The Act allows regulations and Orders in Council to align technical and procedural TF requirements with existing sectoral obligations (privacy, information security, consumer protection) and to ensure interoperability with government systems and identity initiatives. The Department of Internal Affairs provides guidance on how the TF framework operates alongside other statutes at Trust Framework - Department of Internal Affairs.

International Alignment

Although primarily domestic, the Act anticipates international interoperability and alignment by permitting TF rules to include technical standards and cross-border considerations for identity exchange. The TF authority’s accreditation and certification processes are designed to support internationally interoperable assurance levels where appropriate. The Act’s emphasis on accredited marks, certified assessors, and technical specifications facilitates equivalence assessments with overseas digital identity frameworks, supporting international commerce and cross-border services while protecting New Zealand residents’ privacy. Where international standards or mutual recognition arrangements are relevant, the TF board and authority may reference them in TF rules and guidance.

Implementation Timeline

EventDate
Introduction of Bill2021-09-29
First reading2021-10-19
Committee report2022-04-19
Second reading2022-07-26
Third reading / Committee of the Whole2023-03-28
Royal assent2023-04-05
Default commencement (to extent not earlier commenced)2024-07-01

Sources and References

SourceType
Digital Identity Services Trust Framework Act 2023 (New Zealand Legislation, full text)Primary Source
Trust Framework - Department of Internal AffairsPrimary Source

Requirements for a company

What an organisation has to do under New Zealand - Digital Identity Services (2023), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

10
  • Do not knowingly or recklessly misrepresent your accreditation or provider status.Any individual or organisation providing digital identity services.
  • Submit application with key and specified information to become an accredited service.Providers seeking to operate an accredited digital identity service.
  • Implement technical, security and privacy measures required by Trust Framework rules and regulations.Accredited providers of digital identity services.
  • Take reasonable steps to protect personal and organisational information when operating accredited services.TF providers operating accredited services.
  • Only use approved accreditation marks consistent with the TF authority's terms of use.Accredited providers of digital identity services.
  • Obtain certification from the TF authority to operate as a third-party assessor.Third-party assessors of digital identity services.
  • +4 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under New Zealand - Digital Identity Services (2023), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Any individual or organisation providing digital identity services.Do not knowingly or recklessly misrepresent your accreditation or provider status.
knowingly or recklessly misrepresenting accreditation or provider status carries maximum fines of NZD 50,000 for individuals
Part 6Critical
2Providers seeking to operate an accredited digital identity service.Submit application with key and specified information to become an accredited service.
Accreditation application: Submit application with key and specified information per sections 23–25
Before operating an accredited servicesections 23–25Critical
3Accredited providers of digital identity services.Implement technical, security and privacy measures required by Trust Framework rules and regulations.
Comply with TF rules: Implement technical, security and privacy measures required by TF rules and regulations
OngoingCritical
4TF providers operating accredited services.Take reasonable steps to protect personal and organisational information when operating accredited services.
requires providers to take reasonable steps to protect personal or organisational information when operating accredited services.
OngoingCritical
5Accredited providers of digital identity services.Only use approved accreditation marks consistent with the TF authority's terms of use.
Use of accreditation mark: Only use approved mark consistent with TF authority terms of use
Part 6Critical
6Third-party assessors of digital identity services.Obtain certification from the TF authority to operate as a third-party assessor.
mandates certification of assessors
Before conducting assessmentsCritical
7Accredited providers of digital identity services.Maintain records and file reports as required by Trust Framework rules and the Act.
Record-keeping and reporting: Maintain records and file reports as required by TF rules and section 42
Ongoingsection 42Important
8Accredited providers of digital identity services.Notify the TF authority of changes to key or specified information.
Notification of changes: Notify TF authority of changes to key or specified information under section 33
Upon changesection 33Important
9TF providers and other relevant parties.Provide documents and information as required by the TF authority during investigations.
The TF authority has powers to investigate breaches, require documents and information
Upon requestImportant
10TF board and TF authority.Ensure governance arrangements incorporate te ao Māori approaches to identity.
requires governance arrangements to incorporate te ao Māori approaches to identity.
OngoingImportant

© Regulations.AI · updated on 13-Jun-2026